skill

Azure Kusto

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. WHEN: KQL queries, Kusto database queries, Azure Data Explorer, ADX clusters, log analytics, time series data, IoT telemetry, anomaly detection.

Microsoft0+ installsVetted

About

# Azure Data Explorer (Kusto) Query & Analytics

Execute KQL queries and manage Azure Data Explorer resources for fast, scalable big data analytics on log, telemetry, and time series data.

## Skill Activation Triggers

**Use this skill immediately when the user asks to:** - "Query my Kusto database for [data pattern]" - "Show me events in the last hour from Azure Data Explorer" - "Analyze logs in my ADX cluster" - "Run a KQL query on [database]" - "What tables are in my Kusto database?" - "Show me the schema for [table]" - "List my Azure Data Explorer clusters" - "Aggregate telemetry data by [dimension]" - "Create a time series chart from my logs"

**Key Indicators:** - Mentions "Kusto", "Azure Data Explorer", "ADX", or "KQL" - Log analytics or telemetry analysis requests - Time series data exploration - IoT data analysis queries - SIEM or security analytics tasks - Requests for data aggregation on large datasets - Performance monitoring or APM queries

## Overview

This skill enables querying and managing Azure Data Explorer (Kusto), a fast and highly scalable data exploration service optimized for log and telemetry data. Azure Data Explorer provides sub-second query performance on billions of records using the Kusto Query Language (KQL).

Key capabilities: - **Query Execution**: Run KQL queries against massive datasets - **Schema Exploration**: Discover tables, columns, and data types - **Resource Management**: List clusters and databases - **Analytics**: Aggregations, time series, anomaly detection, machine learning

## Core Workflow

1. **Discover Resources**: List available clusters and databases in subscription 2. **Explore Schema**: Retrieve table structures to understand data model 3. **Query Data**: Execute KQL queries for analysis, filtering, aggregation 4. **Analyze Results**: Process query output for insights and reporting

## Query Patterns

### Pattern 1: Basic Data Retrieval Fetch recent records from a table with simple filtering.

**Example KQL**: ```kql Events | where Timestamp > ago(1h) | take 100 ```

**Use for**: Quick data inspection, recent event retrieval

### Pattern 2: Aggregation Analysis Summarize data by dimensions for insights and reporting.

**Example KQL**: ```kql Events | summarize count() by EventType, bin(Timestamp, 1h) | order by count_ desc ```

**Use for**: Event counting, distribution analysis, top-N queries

### Pattern 3: Time Series Analytics Analyze data over time windows for trends and patterns.

**Example KQL**: ```kql Telemetry | where Timestamp > ago(24h) | summarize avg(ResponseTime), percentiles(ResponseTime, 50, 95, 99) by bin(Timestamp, 5m) | render timechart ```

**Use for**: Performance monitoring, trend analysis, anomaly detection

### Pattern 4: Join and Correlation Combine multiple tables for cross-dataset analysis.

**Example KQL**: ```kql Events | where EventType == "Error" | join kind=inner ( Logs | where Severity == "Critical" ) on CorrelationId | project Timestamp, EventType, LogMessage, Severity ```

**Use for**: Root cause analysis, correlated event tracking

### Pattern 5: Schema Discovery Explore table structure before querying.

**Tools**: `kusto_table_schema_get`

**Use for**: Understanding data model, query planning

## Key Data Fields

When executing queries, common field patterns: - **Timestamp**: Time of event (datetime) - use `ago()`, `between()`, `bin()` for time filtering - **EventType/Category**: Classification field for grouping - **CorrelationId/SessionId**: For tracing related events - **Severity/Level**: For filtering by importance - **Dimensions**: Custom properties for grouping and filtering

## Result Format

Query results include: - **Columns**: Field names and data types - **Rows**: Data records matching query - **Statistics**: Row count, execution time, resource utilization - **Visualization**: Chart rendering hints (timechart, barchart, etc.)

## KQL Best Practices

**🟢 Performance Optimized:** - Filter early: Use `where` before joins and aggregations - Limit result size: Use `take` or `limit` to reduce data transfer - Time filters: Always filter by time range for time series data - Indexed columns: Filter on indexed columns first

**🔵 Query Patterns:** - Use `summarize` for aggregations instead of `count()` alone - Use `bin()` for time bucketing in time series - Use `project` to select only needed columns - Use `extend` to add calculated fields

**🟡 Common Functions:** - `ago(timespan)`: Relative time (ago(1h), ago(7d)) - `between(start .. end)`: Range filtering - `startswith()`, `contains()`, `matches regex`: String filtering - `parse`, `extract`: Extract values from strings - `percentiles()`, `avg()`, `sum()`, `max()`, `min()`: Aggregations

## Best Practices

- Always include time range filters to optimize query performance - Use `take` or `limit` for exploratory queries to avoid large result sets - Leverage `summarize` for aggregations instead of client-side processing - Store frequently-used queries as fu

Install

Run this command

git clone https://github.com/microsoft/azure-skills && cp -r azure-skills/skills/azure-kusto ~/.claude/skills/

Works with

claude appclaude codeclaude apicursorcodexwindsurfclinezed

Manual steps

Clone the repository and copy the `skills/azure-kusto` folder into your Claude skills directory. Compatible with Claude Code, Cursor, Codex, and any Agent Skills-compatible agent.

View source
License: MITBy Microsoft

Frequently asked questions

What is the Azure Kusto skill?

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. WHEN: KQL queries, Kusto database queries, Azure Data Explorer, ADX clusters, log analytics, time series data, IoT telemetry, anomaly detection.

How do I install Azure Kusto?

Run this in your terminal:

git clone https://github.com/microsoft/azure-skills && cp -r azure-skills/skills/azure-kusto ~/.claude/skills/
Which AI tools does Azure Kusto work with?

It works with claude_app, claude_code, claude_api, cursor, codex, windsurf, cline, zed.

Who made Azure Kusto?

Microsoft, released under the MIT license.

Is Azure Kusto free?

Yes, it is free to use under the MIT license.

Related assets

More curated picks in Data & Analytics.

All Azure Kusto alternatives →
skillclaude_appclaude_codeclaude_api
npx skills add google/agents-cli
Google Agents Cli Observability
This skill should be used when the user wants to "set up tracing", "monitor my agent", "configure logging", "add observability", "debug production tra…357,631+
skillclaude_appclaude_codeclaude_api
npx skills add prisma/skills
Prisma Driver Adapter Implementation
Required reference for Prisma ORM 7 SQL driver adapter work. Use when implementing or modifying adapters, adding database drivers, or touching SqlDriv…300,037+
skillclaude_appclaude_codeclaude_api
npx skills add neondatabase/agent-skills
Neon Postgres
Guides and best practices for working with Lakebase Postgres on Neon: connections, pooled vs direct, schema migrations, branching, autoscaling, scale-…187,765+
skillclaude_appclaude_codeclaude_api
npx skills add firebase/agent-skills
Firebase Basics
Provides foundational Firebase CLI setup, CLI installation, version checks (`firebase-tools@latest --version`), CLI login (including --no-localhost),…158,802+
skillclaude_appclaude_codeclaude_api
npx skills add firebase/agent-skills
Firebase Auth Basics
Guide for setting up and using Firebase Authentication. Use this skill when the user's app requires user sign-in, user management, or secure data acce…157,711+
skillclaude_appclaude_codeclaude_api
npx skills add firebase/agent-skills
Firebase Hosting Basics
Deploys and configures classic Firebase Hosting for static websites, single-page apps (SPAs), and microservices. Use when deploying static sites/SPAs,…153,880+

Audit before you install

Run any source through our checks - AI visibility, security, performance, and stack detection.

More in Data & Analytics