Official agent skill

Azure Kusto

by microsoft in microsoft/GitHub-Copilot-for-Azure

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

OfficialMITAuto-check passedData & Analytics

Install Azure Kusto

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kusto .claude/skills/azure-kusto && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-kusto
GitHub stars
255
Used in
1 other repo
Token cost
~2.1k tokens
SKILL.md length
940 words
Files
2
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

  • Works in 4 steps: Discover Resources: List available… → Explore Schema: Retrieve table… → Query Data: Execute KQL queries for… → …
  • Tasks that involve Forecasting and time series
  • SKILL.md covers Overview, Core Workflow, Query Patterns and Key Data Fields, plus 7 more sections
  • Calls az

What it does

Azure Kusto is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. WHEN: KQL queries, Kusto database queries, Azure Data Explorer, ADX clusters, log analytics, time series data, IoT telemetry, anomaly detection.

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `version.json`).

It sits in Data & Analytics, covering Forecasting and time series, Data analysis and Anomaly detection. It works with Microsoft Azure and Microsoft Sentinel. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • Tasks that involve Forecasting and time series
  • Tasks that involve Data analysis
  • Tasks that involve Anomaly detection

Example prompts

  • “/azure-kusto”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Discover Resources: List available clusters and databases in subscription. If the target table's location is unknown and multiple…
  2. Explore Schema: Retrieve table structures to understand data model
  3. Query Data: Execute KQL queries for analysis, filtering, aggregation
  4. Analyze Results: Process query output for insights and reporting

What it can do on your machine

Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Kusto loads about 2.1k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 940 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 940 words, ~2,141 tokens.

Download SKILL.mdSave it as .claude/skills/azure-kusto/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
azure-kusto
description
Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. WHEN: KQL queries, Kusto database queries, Azure Data Explorer, ADX clusters, log analytics, time series data, IoT telemetry, anomaly detection.
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Azure Data Explorer (Kusto) Query & Analytics

Execute KQL queries and manage Azure Data Explorer resources for fast, scalable big data analytics on log, telemetry, and time series data.

Overview

This skill enables querying and managing Azure Data Explorer (Kusto), a fast and highly scalable data exploration service optimized for log and telemetry data. Azure Data Explorer provides sub-second query performance on billions of records using the Kusto Query Language (KQL).

Key capabilities:

  • Query Execution: Run KQL queries against massive datasets
  • Schema Exploration: Discover tables, columns, and data types
  • Resource Management: List clusters and databases
  • Analytics: Aggregations, time series, anomaly detection, machine learning

Core Workflow

  1. Discover Resources: List available clusters and databases in subscription. If the target table's location is unknown and multiple candidate clusters, databases, or Log Analytics workspaces exist, batch the search (see Pattern 6) and only report "not found" after all candidates are checked.
  2. Explore Schema: Retrieve table structures to understand data model
  3. Query Data: Execute KQL queries for analysis, filtering, aggregation
  4. Analyze Results: Process query output for insights and reporting

Query Patterns

Pattern 1: Basic Data Retrieval

Fetch recent records from a table with simple filtering.

Example KQL:

kql
Events
| where Timestamp > ago(1h)
| take 100

Use for: Quick data inspection, recent event retrieval

Pattern 2: Aggregation Analysis

Summarize data by dimensions for insights and reporting.

Example KQL:

kql
Events
| summarize count() by EventType, bin(Timestamp, 1h)
| order by count_ desc

Use for: Event counting, distribution analysis, top-N queries

Pattern 3: Time Series Analytics

Analyze data over time windows for trends and patterns.

Example KQL:

kql
Telemetry
| where Timestamp > ago(24h)
| summarize avg(ResponseTime), percentiles(ResponseTime, 50, 95, 99) by bin(Timestamp, 5m)
| render timechart

Use for: Performance monitoring, trend analysis, anomaly detection

Pattern 4: Join and Correlation

Combine multiple tables for cross-dataset analysis.

Example KQL:

kql
Events
| where EventType == "Error"
| join kind=inner (
    Logs
    | where Severity == "Critical"
) on CorrelationId
| project Timestamp, EventType, LogMessage, Severity

Use for: Root cause analysis, correlated event tracking

Pattern 5: Schema Discovery

Explore table structure before querying.

Tools: kusto_table_schema_get

Use for: Understanding data model, query planning

Pattern 6: Batch Search Across Candidate Sources

When a table's location is unknown and there are several candidate clusters, databases, or workspaces, batch read-only metadata discovery instead of querying candidates one at a time. List tables in each candidate database or workspace and match the exact table name before querying data.

After confirming which sources contain the table, query those sources together when needed:

kql
union workspace('ws1').Requests, workspace('ws2').Requests
| take 1

Use for: Locating a table among many candidate resources without confusing an empty result with a missing table

Key Data Fields

When executing queries, common field patterns:

  • Timestamp: Time of event (datetime) - use ago(), between(), bin() for time filtering
  • EventType/Category: Classification field for grouping
  • CorrelationId/SessionId: For tracing related events
  • Severity/Level: For filtering by importance
  • Dimensions: Custom properties for grouping and filtering

Result Format

Query results include:

  • Columns: Field names and data types
  • Rows: Data records matching query
  • Statistics: Row count, execution time, resource utilization
  • Visualization: Chart rendering hints (timechart, barchart, etc.)

KQL Best Practices

🔵 Query Patterns:

  • Use summarize for aggregations instead of count() alone
  • Use bin() for time bucketing in time series
  • Use project to select only needed columns
  • Use extend to add calculated fields

🟡 Common Functions:

  • ago(timespan): Relative time (ago(1h), ago(7d))
  • between(start .. end): Range filtering
  • startswith(), contains(), matches regex: String filtering
  • parse, extract: Extract values from strings
  • percentiles(), avg(), sum(), max(), min(): Aggregations

Best Practices

  • Filter early with time range filters to optimize query performance and use indexed columns first
  • Use take or limit for exploratory queries to avoid large result sets
  • Leverage summarize for aggregations instead of client-side processing
  • Store frequently-used queries as functions in the database
  • Use materialized views for repeated aggregations
  • Monitor query performance and resource consumption
  • Apply data retention policies to manage storage costs
  • Use streaming ingestion for real-time analytics (< 1 second latency)
  • Integrate with Azure Monitor for operational insights
Show full SKILL.md (353 more words)Show less

MCP Tools Used

ToolPurpose
kusto_cluster_listList all Azure Data Explorer clusters in a subscription
kusto_database_listList all databases in a specific Kusto cluster
kusto_queryExecute KQL queries against a Kusto database
kusto_table_schema_getRetrieve schema information for a specific table

Required Parameters:

  • subscription: Azure subscription ID or display name
  • cluster: Kusto cluster name (e.g., "mycluster")
  • database: Database name
  • query: KQL query string (for query operations)
  • table: Table name (for schema operations)

Optional Parameters:

  • resource-group: Resource group name (for listing operations)
  • tenant: Azure AD tenant ID

Fallback Strategy: Azure CLI Commands

If Azure MCP Kusto tools fail, timeout, or are unavailable, use Azure CLI commands as fallback.

CLI Command Reference
OperationAzure CLI Command
List clustersaz kusto cluster list --resource-group <rg-name>
List databasesaz kusto database list --cluster-name <cluster> --resource-group <rg-name>
Show clusteraz kusto cluster show --name <cluster> --resource-group <rg-name>
Show databaseaz kusto database show --cluster-name <cluster> --database-name <db> --resource-group <rg-name>
KQL Query via Azure CLI

For queries, use the Kusto REST API or direct cluster URL:

bash
az rest --method post \
  --url "https://<cluster>.<region>.kusto.windows.net/v1/rest/query" \
  --body "{ \"db\": \"<database>\", \"csl\": \"<kql-query>\" }"
When to Fallback

Switch to Azure CLI when:

  • MCP tool returns timeout error (queries > 60 seconds)
  • MCP tool returns "service unavailable" or connection errors
  • Authentication failures with MCP tools
  • Empty response when database is known to have data

Common Issues

  • Access Denied: Verify database permissions (Viewer role minimum for queries)
  • Query Timeout: Optimize query with time filters, reduce result set, or increase timeout
  • Syntax Error: Validate KQL syntax - common issues: missing pipes, incorrect operators
  • Empty Results: Check time range filters (may be too restrictive), verify table name
  • Table Location Unknown: Use Pattern 6 to batch-search all candidate sources before concluding the data does not exist
  • Cluster Not Found: Check cluster name format (exclude ".kusto.windows.net" suffix)
  • High CPU Usage: Query too broad - add filters, reduce time range, limit aggregations
  • Ingestion Lag: Streaming data may have 1-30 second delay depending on ingestion method

Use Cases

  • Log Analytics: Application logs, system logs, audit logs
  • IoT Analytics: Sensor data, device telemetry, real-time monitoring
  • Security Analytics: SIEM data, threat detection, security event correlation
  • APM: Application performance metrics, user behavior, error tracking
  • Business Intelligence: Clickstream analysis, user analytics, operational KPIs

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugins/azure-skills/skills/azure-kusto of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • version.json

Open the folder on GitHubat commit ce94fce

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Kusto next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Kusto compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Kusto this skillmicrosoft/GitHub-Copilot-for-Azure2551 repos~2.1kAutomated safety check: PassMIT
Kqlmicrosoft/fabric-rti-mcp131—~6.2kAutomated safety check: PassMIT
Kqlmicrosoft/skills3.1k—~4.7kAutomated safety check: PassMIT
Apex Azure Kustojonathan-vella/apex217—~984Automated safety check: PassMIT
Azure AI Anomalydetector Javamicrosoft/skills3.1k5 repos~2.3kAutomated safety check: PassMIT
Analyzing Cloud Storage Access Patternsmukul975/Anthropic-Cybersecurity-Skills34k—~599Automated safety check: PassApache-2.0

Similar skills

  • Kql

    microsoft/fabric-rti-mcp

    Official

    KQL language expertise for writing correct, efficient Kusto queries using the Fabric RTI MCP tools.

    131 GitHub stars~6.2k tokensUpdated 8 days ago
    Data & AnalyticsAuto-check passed
  • Kql

    microsoft/skills

    Official

    KQL language expertise for writing correct, efficient Kusto Query Language queries.

    3.1k GitHub stars~4.7k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Apex Azure Kusto

    jonathan-vella/apex

    ANALYSIS SKILL — Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL.

    217 GitHub stars~984 tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Official

    Build anomaly detection applications with Azure AI Anomaly Detector SDK for Java.

    3.1k GitHub starsUsed in 5 repos~2.3k tokens
    Data & AnalyticsAuto-check passed
  • Analyzing Cloud Storage Access Patterns

    mukul975/Anthropic-Cybersecurity-Skills

    Detect abnormal access in AWS S3, GCS, and Azure Blob Storage by analyzing CloudTrail Data Events, GCS audit logs, and Azure Storage Analytics for after-hours bulk downloads, new-IP access, and…

    34k GitHub stars~599 tokensUpdated 1 mo ago
    Data & AnalyticsAuto-check passed
  • Kql Query Authoring

    SCStelz/security-investigator

    A skill your agent uses when asked to write, create, or help with KQL (Kusto Query Language) queries for Microsoft Sentinel, Defender XDR, or Azure Data Explorer.

    250 GitHub stars~5.7k tokensUpdated today
    Data & AnalyticsAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 61 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Auto-check passed
  • Azure Kubernetes Automatic Readiness

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.

    255 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed

Questions about Azure Kusto

What does Azure Kusto do?

Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis. Azure Kusto is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Query and analyze data in Azure Data Explorer (Kusto/ADX) using KQL for log analytics, telemetry, and time series analysis.

When should I use Azure Kusto?

Azure Kusto fits situations like: tasks that involve Forecasting and time series; tasks that involve Data analysis; tasks that involve Anomaly detection.

How do I install Azure Kusto in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-kusto in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-kusto in your project. Claude Code loads it when a task matches its description.

How do I install Azure Kusto in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-kusto in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-kusto in your project. Codex loads it when a task matches its description.

Can I use Azure Kusto in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-kusto, .gemini/skills/azure-kusto, .github/skills/azure-kusto and .opencode/skills/azure-kusto in your project.

What does Azure Kusto need to run?

Going by SKILL.md and its folder, Azure Kusto needs the command-line tools its instructions call (az).

Does Azure Kusto access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azure Kusto safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Kusto use?

Azure Kusto is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Kusto use?

About 2.1k tokens (SKILL.md is roughly 8.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Kusto?

Skills that share tags, products or a category with Azure Kusto: Kql (microsoft/fabric-rti-mcp, 131 stars), Kql (microsoft/skills, 3.1k stars), Apex Azure Kusto (jonathan-vella/apex, 217 stars) and Azure AI Anomalydetector Java (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Kusto?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.