KQL Basics
Goal: Learn enough KQL to read and edit Azi's proposals.
What is KQL?
Kusto Query Language (KQL) is Azure Data Explorer's query language:
- Pipe-based (like Unix)
- Read left-to-right, top-to-bottom
- Designed for time-series data
- Very fast on large datasets
Basic Structure
TableName
| where condition
| summarize aggregation by grouping
| order by field
Each line pipes (|) into the next.
Common Operators
where - Filter rows
Telemetry
| where temperature > 70
| where deviceId == "sensor-01"
project - Select columns
Telemetry
| project timestamp, temperature, deviceId
summarize - Aggregate
Telemetry
| summarize avg_temp = avg(temperature) by deviceId
order by - Sort
Telemetry
| order by timestamp desc
Time Functions
| Function | Example | Result |
|---|---|---|
ago(1h) | where timestamp > ago(1h) | Last hour |
ago(24h) | where timestamp > ago(24h) | Last day |
ago(7d) | where timestamp > ago(7d) | Last week |
bin(ts, 1h) | by bin(timestamp, 1h) | Group by hour |
Aggregation Functions
| Function | Purpose |
|---|---|
count() | Number of rows |
avg(field) | Average value |
sum(field) | Total |
min(field) | Minimum |
max(field) | Maximum |
stdev(field) | Standard deviation |
Example: Complete Query
Goal: Average temperature by device for the last 24 hours, sorted by temperature descending.
Telemetry
| where timestamp > ago(24h)
| summarize avg_temp = avg(temperature) by deviceId
| order by avg_temp desc
Reading Azi's Proposals
When Azi proposes a query, read it like this:
- Table - What data source?
- where - What filters?
- summarize - What aggregation?
- project - What fields returned?
- order - What sort order?
Common Edits
| To do this | Change this |
|---|---|
| Different time range | ago(24h) → ago(7d) |
| Different device | "sensor-01" → "sensor-02" |
| Different aggregation | avg() → max() |
| Different grouping | by deviceId → by bin(timestamp, 1h) |
Thinking Tip:
Most edits are small changes to numbers, names, or functions. You rarely need to rewrite entire queries.
Learn More
Next Steps
| If you want to... | Go to... |
|---|---|
| Expose queries as APIs | APIs Guide → |
| Work with Azi on complex queries | Working with Azi → |