curl --request POST \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query \
--header 'Content-Type: application/json' \
--data '
{
"query": "<string>",
"max_rows": 123
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query"
payload = {
"query": "<string>",
"max_rows": 123
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({query: '<string>', max_rows: 123})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'query' => '<string>',
'max_rows' => 123
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query"
payload := strings.NewReader("{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query")
.header("Content-Type", "application/json")
.body("{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"summary": "<string>",
"row_count": 123,
"truncated": true,
"columns": [
"<string>"
],
"rows": [
[
"<string>"
]
]
},
"meta": {
"requestId": "<string>",
"timestamp": "<string>"
}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Agent tool execute kql
curl --request POST \
--url https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query \
--header 'Content-Type: application/json' \
--data '
{
"query": "<string>",
"max_rows": 123
}
'import requests
url = "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query"
payload = {
"query": "<string>",
"max_rows": 123
}
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({query: '<string>', max_rows: 123})
};
fetch('https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'query' => '<string>',
'max_rows' => 123
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query"
payload := strings.NewReader("{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query")
.header("Content-Type", "application/json")
.body("{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/api/v2/workspaces/{workspaceId}/agent/tools/kql/query")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"query\": \"<string>\",\n \"max_rows\": 123\n}"
response = http.request(request)
puts response.read_body{
"data": {
"success": true,
"summary": "<string>",
"row_count": 123,
"truncated": true,
"columns": [
"<string>"
],
"rows": [
[
"<string>"
]
]
},
"meta": {
"requestId": "<string>",
"timestamp": "<string>"
}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}{
"type": "<string>",
"title": "<string>",
"status": 123,
"detail": "<string>",
"instance": "<string>",
"code": "<string>",
"requestId": "<string>",
"timestamp": "<string>",
"target": "<string>",
"errors": {}
}Path Parameters
Body
Request DTO for the agent's KQL execution tool. Trimmed for LLM consumption — the agent supplies a query string the schema-aware sub-agent has already generated, and we run it under the workspace's Log Analytics context.
KQL query to execute against the workspace's Log Analytics workspace. Ground the query in the real schema first by calling list-kql-tables and get-kql-table-columns — queries against non-existent tables or columns return a clear error. Prefer narrowly-scoped queries (specific table, time range, project clause) over broad scans to keep results inside the row cap.
Optional row cap. Defaults to 50 server-side; values above the hard maximum (200) are clamped silently. Set explicitly only when the default is too narrow for the investigation — the cap protects the LLM context window from runaway queries.
Response
OK
Standard v2 API response envelope for single-item responses.
Result of an agent KQL execution tool call. Returns true-columnar rows (parallel arrays indexed against the List<string> AgentToolKqlQueryResult.Columns header) — far more token-efficient than a per-row dictionary because column names are written exactly once.
Show child attributes
Show child attributes
Show child attributes
Show child attributes