Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
Also called Kusto Query Language.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-305AZ-104AZ-700SC-500AI-300AZ-900AI-200DP-900DP-750SC-900SC-200SC-300AZ-400AZ-802DP-600DP-700PL-300MD-102DP-800ALZ
Each book explains KQL in context, with comparison tables and the common traps.
Terms in this definition
- ADX
Azure Data Explorer is Microsoft's KQL-based service for analysing large volumes of data. Log Analytics can reach it through the adx() function, though queries and jobs in the Sentinel data lake cannot.
- Dedicated cluster
To encrypt Azure Monitor Logs with your own keys, the Log Analytics workspace must be linked to this cluster tier. Setting a CMK on a storage account gives Log Analytics no such protection.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- Log alert
Type of Azure Monitor alert driven by a KQL query over Log Analytics data. Logs that exist only in Event Hubs or storage accounts are out of its reach.
Related terms
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- ARG
Azure Resource Graph lets you run KQL over deployed resources in many subscriptions at once. Log Analytics and advanced hunting can call it with arg(), while analytics rules and lake queries cannot.
- ASIM parsers
Short for Advanced Security Information Model parsers: KQL functions that map Microsoft Sentinel data onto shared schemas when queried. That happens after ingestion has been charged, so ingestion costs are unaffected.
- Azure Monitor Logs
Within Azure Monitor, the store for log data: records of logs and performance counters are kept in Log Analytics workspaces, where KQL queries retrieve them.
- Azure Monitor workbooks
Reports in Azure that you can interact with, mixing KQL queries, metrics, parameters and text. Send Intune logs to Log Analytics and you can build them on that data.
- Basic
Low-cost Log Analytics table plan where ingestion is cheap but each query is charged per GB and runs at workspace scope. Full KQL and simple log search alerts are supported; standard log search alerts are not.
- bin()
A KQL function that groups values by rounding numbers, timespans or datetimes down to the nearest multiple of a chosen size; paired with
summarize,bin(Timestamp, 1h)gives hourly buckets.floor()behaves the same way, andbin_at()lets you pick where the buckets start. - Copilot in Fabric
Built on Azure OpenAI, this AI assistant in Power BI and Fabric takes plain-language prompts and produces KQL, SQL or DAX code, summaries and visuals. Whatever it does is charged against Fabric capacity CUs.