Working with Azi
Goal: Master the art of collaborating with Azi to build powerful queries.
The Collaboration Loop
This is governed AI. I propose. You decide. Every interaction logged.
Example Queries
Aggregations
You say: "Show me the average temperature by hour for the last 24 hours"
Azi proposes:
Telemetry
| where timestamp > ago(24h)
| summarize avg_temperature = avg(temperature) by bin(timestamp, 1h)
| order by timestamp asc
Filtering
You say: "Find all temperature readings above 80 degrees"
Azi proposes:
Telemetry
| where temperature > 80
| project timestamp, deviceId, temperature
| order by timestamp desc
Cross-Device Comparison
You say: "Compare average temperature between sensor-01 and sensor-02"
Azi proposes:
Telemetry
| where deviceId in ("sensor-01", "sensor-02")
| summarize avg_temp = avg(temperature) by deviceId
Anomaly Detection
You say: "Find readings that are more than 2 standard deviations from the mean"
Azi proposes:
let stats = Telemetry | summarize mean = avg(temperature), stddev = stdev(temperature);
Telemetry
| extend anomaly = abs(temperature - toscalar(stats | project mean)) > 2 * toscalar(stats | project stddev)
| where anomaly == true
Tips for Better Results
| Tip | Example |
|---|---|
| Be specific about time | "last 24 hours" not "recently" |
| Name your fields | "temperature field" not "the data" |
| State the aggregation | "average by hour" not "summarize" |
| Mention ordering | "newest first" or "sorted by device" |
If Azi's first proposal isn't quite right, just describe what's different. "Same query but group by device instead."
Refining Proposals
When Azi's proposal needs adjustment:
| Say | Azi Does |
|---|---|
| "Add a filter for device sensor-01" | Adds WHERE clause |
| "Group by hour instead of day" | Changes bin() parameter |
| "Include humidity too" | Adds field to projection |
| "Sort newest first" | Adds ORDER BY desc |
When to Edit KQL Directly
Sometimes it's faster to edit:
- Minor tweaks to field names
- Adjusting numeric thresholds
- Copying patterns from other queries
- Complex joins Azi struggles with
See KQL Basics → for syntax reference.
Approval Flow
After Azi proposes:
| Option | Button | When to Use |
|---|---|---|
| Approve | ✓ checkmark | Query looks correct |
| Edit | ✏️ pencil | Small tweaks needed |
| Reject | 🗑️ trash | Start over |
To refine, simply describe what's different in the chat (e.g., "Same query but group by hour instead").
Nothing executes without your approval. Every proposal is logged with your decision.
Next Steps
| If you want to... | Go to... |
|---|---|
| Learn KQL syntax | KQL Basics → |
| Expose queries as APIs | APIs Guide → |