← cd ~/learn
azureblog.co.uk · cheat sheet
KQL basics for admins
The handful of Kusto operators that cover most Log Analytics, Sentinel and Defender queries, with sign-in log examples.
Fits on one A4 page. Checked 9 Oct 2026.
Operators you'll use most
| Operator | What it does | Example |
|---|---|---|
| where | Filter rows | | where ResultType != "0" |
| project | Pick and rename columns | | project TimeGenerated, User = UserPrincipalName |
| extend | Add a calculated column | | extend Country = tostring(LocationDetails.countryOrRegion) |
| summarize | Group and aggregate | | summarize count() by AppDisplayName |
| top / order by | Sort, optionally limit | | top 10 by count_ |
| distinct | Unique values | | distinct UserPrincipalName |
| bin() | Bucket times for trends | | summarize count() by bin(TimeGenerated, 1h) |
| let | Name a value or subquery | let since = ago(7d); |
| join | Combine two tables | | join kind=leftanti known on UserPrincipalName |
| render | Draw a chart | | render timechart |
Matching text
==exact, case-sensitive;=~exact, case-insensitivehasmatches whole terms and is fast;containsmatches any substring and is slowerstartswith,endswith,matches regexin ("a","b")and!infor lists
Useful functions
ago(1d),now(),between (a .. b)count(),dcount(),countif()make_set()andmake_list()to collect valuesarg_max(TimeGenerated, *)for the latest row per grouptostring()andparse_json()for dynamic columns
Example: failures by error, last day
SigninLogs
| where TimeGenerated > ago(1d) // filter on time first: it's the fastest win
| where ResultType != "0"
| summarize Failures = count(), Users = dcount(UserPrincipalName) by ResultType, ResultDescription
| top 10 by Failures
Build your own with the sign-in KQL builder, or copy from the KQL library.