KQL query, run once or on a schedule, against the Microsoft Sentinel data lake, reaching back as far as 12 years; its results can be promoted into the analytics tier.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains KQL job in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Data lake tier
Sentinel storage option priced low for logs you rarely touch. You can still query it via search jobs, KQL jobs and ordinary KQL, and keep data for as long as 12 years in total.
- Promoted
Anyone who can write to a Fabric or Power BI item (dashboards excepted) can endorse it this way to signal it is ready to share and reuse. Certified and Master data, by contrast, require reviewers that a Fabric administrator has authorised.
- Analytics tier
Hot data tier of Microsoft Sentinel supporting hunting, detections and every Sentinel feature; its analytics retention can be extended to as much as two years.