Documentation menu

Documentation

Raml KQL documentation

Run one KQL query against many Azure Log Analytics workspaces across tenants. Guides, reference and design documents.

Raml KQL is a free, open-source desktop app for macOS, Windows and Linux. It runs one KQL query against many Azure Log Analytics workspaces at once, across many Entra tenants and many signed-in accounts, and returns one merged result with the tenant and workspace on every row. It looks and feels like VS Code.

Raml KQL running one query across ten workspaces in five tenants

Start here

  • Getting started: install the app, sign in, run your first query, or try everything in demo mode without Azure access.

Using Raml KQL

GuideWhat you learn
Accounts and tenantsSigning in with several accounts, Lighthouse and guest access, re-authentication
Workspaces and targetsHow workspaces are found, choosing what a query runs on, groups, aliased names
Writing and running queriesThe editor, IntelliSense, the time range, what happens when workspaces fail
Working with resultsThe grid, group by tenant, charts, export, links to the portal and Defender
Saved queries, history and packsMy Queries, history, and shared query packs
Using extensionsInstalling extensions and what their permissions mean
Privacy and securityWhat stays on your machine, the audit log, crash reports
TroubleshootingSign-in problems, missing workspaces, platform notes

Reference

Extending and administering

Contributing

Privacy policy and terms of use. Raml KQL is MIT-licensed and not affiliated with, endorsed by or sponsored by Microsoft. Source code, releases and issues are on GitHub.

Search the docs