KQL Extensions
Understand Cribl KQL extensions and variations from the Kusto language.
Cribl Search KQL is built on top of the Microsoft Kusto Query Language, with additional extensions and operators.
This page lists known areas where Cribl KQL operators, functions, and types differ from their similarly named Kusto counterparts.
These differences might require changes when you programmatically manage Cribl Search using API requests (or other automation) that was originally written around those Kusto counterparts.
The
dayofweekfunction returns an integer between0and6, representing the day of the week, beginning on Sunday. This differs from the standard Kustodayofweekfunction, which returns a timespan.The
make_timespanfunction converts the specified time period into a number of seconds. This output format differs from the standard Kustomake_timespanfunction, which returns a timespan.The
timespandata type represents a time interval, in seconds. This representation differs from the standard Kustotimespantype, which represents a literal timespan.The
totimespanfunction converts the input expression into a time interval, in seconds. This output format differs from the standard Kustototimespanfunction, which returns a timespan.The
tostringfunction, when applied to anullinput value, returnsnull. This output format differs from the standard Kustotostringfunction, which returns an empty string fornullvalues.