StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

KQL basics: where, project, extend, summarize, count, bin, ago(), order by, take, render

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Kusto Query Language (KQL) is the read-only query language used in Microsoft Sentinel, Azure Monitor Log Analytics and Defender XDR advanced hunting. A query starts with a table name and passes rows through a pipeline of operators separated by the pipe character. Each operator takes the rows from the previous one and returns a new set. Reading top to bottom is reading the order of processing, which makes KQL easy to build one step at a time. Because it cannot change data, you can experiment freely.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan