Documentation
Settings reference
Every Raml KQL setting, with its type, default and what it does.
Settings live in settings.jsonc in the configuration folder and can be changed in the Settings editor (Ctrl/Cmd+,). The file is JSON with comments, and changes apply as soon as you save it.
Accounts
auth.provider
The sign-in method offered first when adding an account.
- Type: one of
"builtin","custom","azureCli" - Default:
"builtin""builtin": Microsoft sign-in with the Raml KQL app registration."custom": Microsoft sign-in with your organisation’s own app registration (client ID)."azureCli": Use the accounts you signed in to with Azure CLI (az login).
auth.sessionOnly
Keep sign-ins in memory only, so you sign in again after every restart. Use this when no OS keyring is available (e.g. Linux without GNOME Keyring or KWallet). Takes effect after a restart.
- Type: boolean
- Default:
false
accounts.showTenantsWithoutAccess
Show tenants where the account has no Azure access in the Accounts view.
- Type: boolean
- Default:
false
Application › Update
update.channel
stable installs released versions only; beta also installs pre-releases (-beta.N).
- Type: one of
"stable","beta" - Default:
"stable""stable": Released versions only."beta": Released versions and pre-releases.
update.checkAutomatically
Check GitHub Releases for a new version 30 seconds after start and every 6 hours. Turn this off to stop all update traffic; "Check for Updates…" still works.
- Type: boolean
- Default:
true
Extensions
extensions.permissions.defaultScope
The button focused in extension permission prompts: allow for the current query run (default), the session, or always.
- Type: one of
"run","session","always" - Default:
"run"
extensions.checkForUpdates
Check extensions installed from git for newer releases on startup. Updates are shown, not installed.
- Type: boolean
- Default:
true
extensions.catalog.enabled
Let the Extensions view's Browse tab list extensions from the catalogs below. Nothing is fetched until you open Browse. Turn this off to remove the feature and its network request.
- Type: boolean
- Default:
true
extensions.catalog.urls
Extension catalogs (JSON files) that Browse reads, for example an organization's own list. The first catalog that lists an extension id wins.
- Type: JSON (edit it in
settings.jsonc) - Default:
["https://raw.githubusercontent.com/luca-ramseyer/raml-kql-extensions/main/catalog.json"]
extensions.autoUpdate
Update extensions without asking. Off by default: updates show their changelog and any new permissions first.
- Type: boolean
- Default:
false
Library › Sources
sources.checkForUpdates
Check git query pack sources for new commits on startup (at most once a day per source).
- Type: boolean
- Default:
true
sources.autoUpdate
Apply query pack updates without reviewing them first. Off by default: updates are shown with their changes, and you apply them.
- Type: boolean
- Default:
false
Privacy
privacy.aliasing.enabled
Master switch for aliasing (presentation privacy). When off, real names are always shown and the quick toggle is hidden.
- Type: boolean
- Default:
true
privacy.aliasing.activeOnStartup
Start with customer names aliased, so opening the app on a call is safe by default.
- Type: boolean
- Default:
true
privacy.aliasing.confirmReveal
Ask for confirmation before switching from aliases to real names.
- Type: boolean
- Default:
true
privacy.aliasing.autoAliasFormat
Alias for tenants without one you set. {nn} is a stable two-digit number ({n}, {nnn} also work).
- Type: string
- Default:
"Customer {nn}"
privacy.aliasing.scope
Which names are aliased: any of tenant, subscription, workspace, account.
- Type: JSON (edit it in
settings.jsonc) - Default:
["tenant","subscription","workspace","account"]
crashReporting.mode
After a crash: ask offers a sanitized report you can review and file on GitHub yourself; off keeps crash records on this machine only; auto sends sanitized reports automatically (only in builds with a reporting endpoint).
- Type: one of
"ask","off","auto" - Default:
"ask"
privacy.maskingRules
Text to replace in result cells while presentation mode is on, e.g. { "match": "fabrikam", "replace": "customer01" } (isRegex and caseSensitive optional). Use "Privacy: Generate Masking Rules from Tenant Domains" to start.
- Type: JSON (edit it in
settings.jsonc) - Default:
[]
privacy.aliasing.applyToExports
Whether exported files use aliases for tenant, subscription, workspace and account names. Clipboard copies always match the screen.
- Type: one of
"ask","always","never" - Default:
"ask""ask": Ask on each export (defaults to what is on screen)."always": Always export aliases."never": Always export real names.
Privacy › Audit
audit.enabled
Keep a local, tamper-evident log of which workspaces were queried, when and by which account (never results).
- Type: boolean
- Default:
true
audit.includeQueryText
Store the query text in the audit log. When off, only its hash is stored.
- Type: boolean
- Default:
true
audit.retentionMonths
Months of audit log to keep.
- Type: integer, at least 1, at most 120
- Default:
12
Query › Execution
query.maxConcurrentPerAccount
Queries running at once per account. Log Analytics allows 5 per user; 4 leaves one for the portal.
- Type: integer, at least 1, at most 5
- Default:
4
query.maxConcurrentTotal
Queries running at once across all accounts.
- Type: integer, at least 1, at most 64
- Default:
16
query.timeoutSeconds
How long each workspace may take (10 to 600 seconds).
- Type: integer, at least 10, at most 600
- Default:
180
query.failFastOnSemanticError
Stop the remaining workspaces when the first one reports a query error (except a table or column missing there), and ask before running the rest.
- Type: boolean
- Default:
true
query.fallbackAccessPaths
When a workspace refuses access (403), try the next account that can reach it.
- Type: boolean
- Default:
true
Query › History
history.maxEntries
How many runs the History view keeps (query text and targets only, never results). 0 keeps no history.
- Type: integer, at least 0, at most 100000
- Default:
5000
Query › Schema
schema.cacheHours
How long a workspace schema (tables and columns, never data) is cached on disk before it is fetched again. 0 always fetches.
- Type: integer, at least 0, at most 720
- Default:
24
schema.hideTablesMissingEverywhere
Hide tables from IntelliSense that exist in none of the selected workspaces (e.g. tables known only from the built-in descriptions).
- Type: boolean
- Default:
true
Query › Time
time.displayZone
Time zone used to show and enter times, e.g. in the custom time range.
- Type: one of
"utc","local" - Default:
"utc""utc": Coordinated Universal Time (recommended for SOC work)."local": The time zone of this computer.
Results
results.maxMergedRows
Maximum rows of one merged result; later rows are dropped with a warning.
- Type: integer, at least 1000, at most 10000000
- Default:
1000000
results.memoryBudgetMB
Memory for results. Above it, older results move to an encrypted session cache on disk that is deleted on quit.
- Type: integer, at least 64, at most 65536
- Default:
1024
results.attributionColumns
Attribution columns shown in results: any of _TenantName, _TenantId, _SubscriptionName, _WorkspaceName, _WorkspaceId, _Account.
- Type: JSON (edit it in
settings.jsonc) - Default:
["_TenantName","_WorkspaceName"]
results.copyWithHeaders
Include column headers when copying selected rows (Ctrl/Cmd+C).
- Type: boolean
- Default:
true
results.cellFilterMode
"Filter to this value" / "Exclude this value" filter the grid, or add a where line to the query (portal behaviour).
- Type: one of
"grid","query" - Default:
"grid""grid": Filter the results grid."query": Append awhereline to the query.
links.enabled
Offer "Open in Azure Portal" and row links (incidents, alerts, devices) in results. Links open in your browser.
- Type: boolean
- Default:
true
Results › Export
export.csv.delimiter
Field delimiter for CSV exports (; suits Excel in many European locales).
- Type: one of
",",";","\t","|" - Default:
","
export.csv.bom
Start CSV files with a UTF-8 byte order mark, so Excel reads accented characters correctly.
- Type: boolean
- Default:
true
Text Editor
editor.wordWrap
Controls how lines should wrap.
- Type: one of
"off","on" - Default:
"off"
editor.runScope
What Shift+Enter runs: the query block under the cursor (statements separated by blank lines, like the Log Analytics portal) or the whole editor. A selection always runs as is.
- Type: one of
"block","all" - Default:
"block""block": The block under the cursor."all": Everything in the editor.
Text Editor › Font
editor.fontFamily
Controls the font family of the query editor. Empty uses the platform default (Menlo on macOS, Consolas on Windows, Droid Sans Mono on Linux).
- Type: string
- Default:
""
editor.fontSize
Controls the font size in pixels of the query editor. 0 uses the platform default (12 on macOS, 14 elsewhere).
- Type: integer, at least 0, at most 100
- Default:
0
Text Editor › Minimap
editor.minimap.enabled
Controls whether the minimap is shown.
- Type: boolean
- Default:
false
Workbench › Appearance
workbench.colorTheme
Specifies the color theme used in the workbench when window.autoDetectColorScheme is off.
- Type: string (the name of a colour theme)
- Default:
"Raml Dark"
window.autoDetectColorScheme
If set, automatically switch to the preferred dark or light color theme based on the OS appearance.
- Type: boolean
- Default:
true
workbench.preferredDarkColorTheme
Specifies the color theme used when the OS is in dark mode and window.autoDetectColorScheme is on.
- Type: string (the name of a colour theme)
- Default:
"Raml Dark"
workbench.preferredLightColorTheme
Specifies the color theme used when the OS is in light mode and window.autoDetectColorScheme is on.
- Type: string (the name of a colour theme)
- Default:
"Raml Light"
window.autoDetectHighContrast
If set, automatically switch to a high contrast theme when the OS uses a high contrast theme.
- Type: boolean
- Default:
true
workbench.preferredHighContrastColorTheme
Specifies the dark high contrast color theme used in high contrast mode.
- Type: string (the name of a colour theme)
- Default:
"Default High Contrast"
workbench.preferredHighContrastLightColorTheme
Specifies the light high contrast color theme used in high contrast mode.
- Type: string (the name of a colour theme)
- Default:
"Default High Contrast Light"
workbench.statusBar.visible
Controls the visibility of the status bar at the bottom of the workbench.
- Type: boolean
- Default:
true
Workbench › General
workbench.startupEditor
Controls which editor is shown at startup when no editors are restored.
- Type: one of
"welcomePage","none" - Default:
"welcomePage""welcomePage": Open the Welcome page."none": Start without an editor.
workbench.commandPalette.history
Controls the number of recently used commands to keep in history for the command palette. Set to 0 to disable command history.
- Type: integer, at least 0, at most 500
- Default:
50
Workspaces
workspaces.newWorkspaceDefault
Whether newly discovered workspaces are enabled (shown in Targets) or disabled.
- Type: one of
"enabled","disabled" - Default:
"enabled"
targets.groupBySubscription
Show subscriptions as a level in the Targets tree instead of as secondary text.
- Type: boolean
- Default:
false