Query Returns Empty

Your KQL query runs without errors but returns no results. Here's how to diagnose why.


Quick Diagnosis

Check these first:

  1. Does data exist? Check the surface shows incoming data
  2. Is filter too restrictive? Try removing WHERE clauses one at a time
  3. Are field names correct? Check for typos or case sensitivity

Step-by-Step Diagnosis

1. Start with the Simplest Query

Remove all filters to see if any data exists:

// Start simple - just get all data
YourTable
| take 100

If this returns data, the issue is with your filters. If this returns nothing, check your data connection.

2. Check Time Window

The most common cause of empty results is a time window that doesn't contain data:

// Try a wider time range
YourTable
| where timestamp > ago(7d)
| take 100
Thinking Tip:

Data might have arrived at a different time than expected. Start with a week-long window, then narrow down once you find data.

3. Verify Field Names

Field names are case-sensitive. Check for typos:

// If this fails:
| where Temperature > 70

// Try checking actual field names:
YourTable
| take 1
| project *

This shows all available fields with their exact names.

4. Check Filter Logic

Each filter can eliminate data. Test filters one at a time:

// Step 1: No filter
YourTable | count

// Step 2: Add first filter
YourTable | where field1 == "value" | count

// Step 3: Add second filter
YourTable | where field1 == "value" | where field2 > 100 | count

When the count drops to zero, you've found the problematic filter.


Common Causes

CauseSymptomSolution
Time window too narrowData exists but filtered outExpand time range
Field name typoField not foundCheck exact field names
Case sensitivityNo matching valuesUse =~ for case-insensitive
Wrong data typeComparison failsCheck data types match
Empty source dataNo data at allCheck connection first

KQL Debugging Tips

Case-Insensitive Comparison

// Case-sensitive (default)
| where status == "Active"

// Case-insensitive
| where status =~ "active"

Check for Null Values

// Nulls might be excluded
| where isnotnull(temperature)
| where temperature > 70

String Contains

// Exact match might be too strict
| where message == "error"

// Try contains instead
| where message contains "error"

Ask Azi for Help

In the chat panel, try:

  • "Why is this query returning empty results?"
  • "Help me debug this KQL"
  • "Show me what data exists in this table"

On this page