Query Returns Empty
Your KQL query runs without errors but returns no results. Here's how to diagnose why.
Quick Diagnosis
Check these first:
- Does data exist? Check the surface shows incoming data
- Is filter too restrictive? Try removing WHERE clauses one at a time
- Are field names correct? Check for typos or case sensitivity
Step-by-Step Diagnosis
1. Start with the Simplest Query
Remove all filters to see if any data exists:
// Start simple - just get all data
YourTable
| take 100
If this returns data, the issue is with your filters. If this returns nothing, check your data connection.
2. Check Time Window
The most common cause of empty results is a time window that doesn't contain data:
// Try a wider time range
YourTable
| where timestamp > ago(7d)
| take 100
Thinking Tip:
Data might have arrived at a different time than expected. Start with a week-long window, then narrow down once you find data.
3. Verify Field Names
Field names are case-sensitive. Check for typos:
// If this fails:
| where Temperature > 70
// Try checking actual field names:
YourTable
| take 1
| project *
This shows all available fields with their exact names.
4. Check Filter Logic
Each filter can eliminate data. Test filters one at a time:
// Step 1: No filter
YourTable | count
// Step 2: Add first filter
YourTable | where field1 == "value" | count
// Step 3: Add second filter
YourTable | where field1 == "value" | where field2 > 100 | count
When the count drops to zero, you've found the problematic filter.
Common Causes
| Cause | Symptom | Solution |
|---|---|---|
| Time window too narrow | Data exists but filtered out | Expand time range |
| Field name typo | Field not found | Check exact field names |
| Case sensitivity | No matching values | Use =~ for case-insensitive |
| Wrong data type | Comparison fails | Check data types match |
| Empty source data | No data at all | Check connection first |
KQL Debugging Tips
Case-Insensitive Comparison
// Case-sensitive (default)
| where status == "Active"
// Case-insensitive
| where status =~ "active"
Check for Null Values
// Nulls might be excluded
| where isnotnull(temperature)
| where temperature > 70
String Contains
// Exact match might be too strict
| where message == "error"
// Try contains instead
| where message contains "error"
Ask Azi for Help
In the chat panel, try:
- "Why is this query returning empty results?"
- "Help me debug this KQL"
- "Show me what data exists in this table"