Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Hands On: Kusto Query Language(KQL)
Rating: 3.6 out of 5(11 ratings)
71 students

Hands On: Kusto Query Language(KQL)

Learn KQL to excel in you Sentinel, Log Analytics, ADX Defender for Cloud journey.
Created byVipul Dabhi
Last updated 4/2026
English

What you'll learn

  • Understand What Kusto Query Language and where it is used
  • Understand Kusto Query Language Commands, Statement, Clause
  • Combining all Commands, Statements for a Use Case based understanding
  • Learn how to leverage Sentinel, MDC & Log Analytics Effectively

Course content

4 sections19 lectures5h 2m total length
  • Introduction12:12
  • 2. KQL LA demo Continued (Schema, Workflow of a Query, Pipe Operator)9:43

Requirements

  • Zeal to learn KQL

Description

In this Hands On: Kusto Query Language course we will do hands on KQL and understand various Commands, Clauses, Statements to build a good Foundation.

KQL has many Applications Across Microsoft Sentinel, Micrsoft Defender for Cloud, Azure Data Explorer and it enables in Querying the Data which is Stored in Log Analytics Workspace.

We Will start from Portal Walkthrough provisioned by MS for practicing KQL effectively, we will start with basic commands like getSchema, let, print, and will reach to complex aspect of join, union, data tables, mv-expand, Aggregate functions.

We will understand case-sensitive and case-insensitive aspect of KQL and how commands can be Molded respectively for querying data from Log Analytics.

Kusto Query Language is a powerful tool to explore your data and discover patterns, identify anomalies and outliers, create statistical modeling, and more. The query uses schema entities that are organized in a hierarchy similar to SQL's: databases, tables, and columns.

A Kusto query is a read-only request to process data and return results. The request is stated in plain text, using a data-flow model that is easy to read, author, and automate. Kusto queries are made of one or more query statements.


Brief on What we will do Hands on KQL in this Course:

1. Kusto Query Language

2. KQL LA demo Continued( Schema, Workflow of a Query, Pipe Operator)

3. KQL Operator Search

4. KQL Operator Where

5. KQL Operator distinct,summarize

6. KQL Operator sort,ago

7. KQL Operator iif,strcat,case

8. KQL Operator arg_max,arg_min,Count,mv-expand

9. KQL Operator join,range,union,Custom log creation

10.Kusto Rookie

11. Updating..


Who this course is for:

  • Cloud Security
  • Microsoft SIEM & SOAR
  • SOC Engineers