Intermediate2 days

Azure Data Explorer & KQL

Interactive analytics on telemetry, logs, and time-series data at scale

Overview

Azure Data Explorer (ADX) is an ultra-fast, fully managed analytics service built for exploring massive volumes of diverse data — logs, telemetry, IoT streams, and time-series data — in near real-time. At its core is the Kusto Query Language (KQL), a powerful and expressive query language also used in Azure Monitor and Microsoft Sentinel. This training takes you from cluster architecture and data ingestion through to advanced KQL, time-series analysis, anomaly detection, and integrations with Azure services and Power BI.

What you'll learn

  • Provision and configure Azure Data Explorer clusters and databases
  • Ingest data using batch, streaming, and event-driven ingestion patterns
  • Write efficient KQL queries for filtering, aggregation, joins, and transformations
  • Perform time-series analysis and anomaly detection using built-in KQL ML plugins
  • Visualise ADX data in Power BI, Grafana, and the ADX Web UI dashboards
  • Integrate ADX with Event Hubs, Azure Data Factory, and Microsoft Fabric

Programme

Day 1 — Architecture, ingestion & KQL fundamentals
  • Azure Data Explorer overview: architecture, use cases, and cluster components
  • Creating clusters and databases: sizing, SKUs, and cost optimisation
  • Data ingestion methods: batch, streaming, LightIngest, and Event Hubs integration
  • KQL fundamentals: where, project, extend, summarize, join, and render operators
  • Working with time: datetime arithmetic, bin(), and time-series bucketing
  • Hands-on: ingest a telemetry dataset from Event Hubs and run exploratory KQL queries
Day 2 — Advanced KQL, time-series & integrations
  • Advanced KQL: parse, extract, mv-expand, and handling JSON and dynamic fields
  • Time-series analysis: make-series, series_decompose, and seasonal trend detection
  • Anomaly detection with series_decompose_anomalies and machine-learning plugins
  • Visualisation: Power BI connector, Grafana integration, and ADX dashboards
  • Integrating ADX with Azure Data Factory, Azure Monitor, and Microsoft Fabric
  • Hands-on: build an end-to-end IoT analytics dashboard with real-time anomaly detection

Who is this for?

  • Data engineers and analysts working with log, telemetry, or IoT data
  • Operations teams exploring ADX for infrastructure and security analytics
  • Developers building real-time monitoring and alerting solutions
  • Teams using Azure Monitor or Microsoft Sentinel who want to master KQL

Prerequisites

  • Basic SQL knowledge — KQL uses similar concepts but a distinct syntax
  • Familiarity with cloud concepts and data ingestion pipelines
  • No prior KQL or ADX experience required

Tools & technologies covered

Azure Data ExplorerKusto Query Language (KQL)ADX Web UIAzure Event HubsPower BIGrafanaAzure Data Factory
Not sure which course fits your team?
Talk to us — we'll match you to the right training path.
Get in touch