Documentation menu

Documentation

Settings reference

Every Raml KQL setting, with its type, default and what it does.

Settings live in settings.jsonc in the configuration folder and can be changed in the Settings editor (Ctrl/Cmd+,). The file is JSON with comments, and changes apply as soon as you save it.

Accounts

auth.provider

The sign-in method offered first when adding an account.

  • Type: one of "builtin", "custom", "azureCli"
  • Default: "builtin"
    • "builtin": Microsoft sign-in with the Raml KQL app registration.
    • "custom": Microsoft sign-in with your organisation’s own app registration (client ID).
    • "azureCli": Use the accounts you signed in to with Azure CLI (az login).

auth.sessionOnly

Keep sign-ins in memory only, so you sign in again after every restart. Use this when no OS keyring is available (e.g. Linux without GNOME Keyring or KWallet). Takes effect after a restart.

  • Type: boolean
  • Default: false

accounts.showTenantsWithoutAccess

Show tenants where the account has no Azure access in the Accounts view.

  • Type: boolean
  • Default: false

Application › Update

update.channel

stable installs released versions only; beta also installs pre-releases (-beta.N).

  • Type: one of "stable", "beta"
  • Default: "stable"
    • "stable": Released versions only.
    • "beta": Released versions and pre-releases.

update.checkAutomatically

Check GitHub Releases for a new version 30 seconds after start and every 6 hours. Turn this off to stop all update traffic; "Check for Updates…" still works.

  • Type: boolean
  • Default: true

Extensions

extensions.permissions.defaultScope

The button focused in extension permission prompts: allow for the current query run (default), the session, or always.

  • Type: one of "run", "session", "always"
  • Default: "run"

extensions.checkForUpdates

Check extensions installed from git for newer releases on startup. Updates are shown, not installed.

  • Type: boolean
  • Default: true

extensions.catalog.enabled

Let the Extensions view's Browse tab list extensions from the catalogs below. Nothing is fetched until you open Browse. Turn this off to remove the feature and its network request.

  • Type: boolean
  • Default: true

extensions.catalog.urls

Extension catalogs (JSON files) that Browse reads, for example an organization's own list. The first catalog that lists an extension id wins.

  • Type: JSON (edit it in settings.jsonc)
  • Default: ["https://raw.githubusercontent.com/luca-ramseyer/raml-kql-extensions/main/catalog.json"]

extensions.autoUpdate

Update extensions without asking. Off by default: updates show their changelog and any new permissions first.

  • Type: boolean
  • Default: false

Library › Sources

sources.checkForUpdates

Check git query pack sources for new commits on startup (at most once a day per source).

  • Type: boolean
  • Default: true

sources.autoUpdate

Apply query pack updates without reviewing them first. Off by default: updates are shown with their changes, and you apply them.

  • Type: boolean
  • Default: false

Privacy

privacy.aliasing.enabled

Master switch for aliasing (presentation privacy). When off, real names are always shown and the quick toggle is hidden.

  • Type: boolean
  • Default: true

privacy.aliasing.activeOnStartup

Start with customer names aliased, so opening the app on a call is safe by default.

  • Type: boolean
  • Default: true

privacy.aliasing.confirmReveal

Ask for confirmation before switching from aliases to real names.

  • Type: boolean
  • Default: true

privacy.aliasing.autoAliasFormat

Alias for tenants without one you set. {nn} is a stable two-digit number ({n}, {nnn} also work).

  • Type: string
  • Default: "Customer {nn}"

privacy.aliasing.scope

Which names are aliased: any of tenant, subscription, workspace, account.

  • Type: JSON (edit it in settings.jsonc)
  • Default: ["tenant","subscription","workspace","account"]

crashReporting.mode

After a crash: ask offers a sanitized report you can review and file on GitHub yourself; off keeps crash records on this machine only; auto sends sanitized reports automatically (only in builds with a reporting endpoint).

  • Type: one of "ask", "off", "auto"
  • Default: "ask"

privacy.maskingRules

Text to replace in result cells while presentation mode is on, e.g. { "match": "fabrikam", "replace": "customer01" } (isRegex and caseSensitive optional). Use "Privacy: Generate Masking Rules from Tenant Domains" to start.

  • Type: JSON (edit it in settings.jsonc)
  • Default: []

privacy.aliasing.applyToExports

Whether exported files use aliases for tenant, subscription, workspace and account names. Clipboard copies always match the screen.

  • Type: one of "ask", "always", "never"
  • Default: "ask"
    • "ask": Ask on each export (defaults to what is on screen).
    • "always": Always export aliases.
    • "never": Always export real names.

Privacy › Audit

audit.enabled

Keep a local, tamper-evident log of which workspaces were queried, when and by which account (never results).

  • Type: boolean
  • Default: true

audit.includeQueryText

Store the query text in the audit log. When off, only its hash is stored.

  • Type: boolean
  • Default: true

audit.retentionMonths

Months of audit log to keep.

  • Type: integer, at least 1, at most 120
  • Default: 12

Query › Execution

query.maxConcurrentPerAccount

Queries running at once per account. Log Analytics allows 5 per user; 4 leaves one for the portal.

  • Type: integer, at least 1, at most 5
  • Default: 4

query.maxConcurrentTotal

Queries running at once across all accounts.

  • Type: integer, at least 1, at most 64
  • Default: 16

query.timeoutSeconds

How long each workspace may take (10 to 600 seconds).

  • Type: integer, at least 10, at most 600
  • Default: 180

query.failFastOnSemanticError

Stop the remaining workspaces when the first one reports a query error (except a table or column missing there), and ask before running the rest.

  • Type: boolean
  • Default: true

query.fallbackAccessPaths

When a workspace refuses access (403), try the next account that can reach it.

  • Type: boolean
  • Default: true

Query › History

history.maxEntries

How many runs the History view keeps (query text and targets only, never results). 0 keeps no history.

  • Type: integer, at least 0, at most 100000
  • Default: 5000

Query › Schema

schema.cacheHours

How long a workspace schema (tables and columns, never data) is cached on disk before it is fetched again. 0 always fetches.

  • Type: integer, at least 0, at most 720
  • Default: 24

schema.hideTablesMissingEverywhere

Hide tables from IntelliSense that exist in none of the selected workspaces (e.g. tables known only from the built-in descriptions).

  • Type: boolean
  • Default: true

Query › Time

time.displayZone

Time zone used to show and enter times, e.g. in the custom time range.

  • Type: one of "utc", "local"
  • Default: "utc"
    • "utc": Coordinated Universal Time (recommended for SOC work).
    • "local": The time zone of this computer.

Results

results.maxMergedRows

Maximum rows of one merged result; later rows are dropped with a warning.

  • Type: integer, at least 1000, at most 10000000
  • Default: 1000000

results.memoryBudgetMB

Memory for results. Above it, older results move to an encrypted session cache on disk that is deleted on quit.

  • Type: integer, at least 64, at most 65536
  • Default: 1024

results.attributionColumns

Attribution columns shown in results: any of _TenantName, _TenantId, _SubscriptionName, _WorkspaceName, _WorkspaceId, _Account.

  • Type: JSON (edit it in settings.jsonc)
  • Default: ["_TenantName","_WorkspaceName"]

results.copyWithHeaders

Include column headers when copying selected rows (Ctrl/Cmd+C).

  • Type: boolean
  • Default: true

results.cellFilterMode

"Filter to this value" / "Exclude this value" filter the grid, or add a where line to the query (portal behaviour).

  • Type: one of "grid", "query"
  • Default: "grid"
    • "grid": Filter the results grid.
    • "query": Append a where line to the query.

links.enabled

Offer "Open in Azure Portal" and row links (incidents, alerts, devices) in results. Links open in your browser.

  • Type: boolean
  • Default: true

Results › Export

export.csv.delimiter

Field delimiter for CSV exports (; suits Excel in many European locales).

  • Type: one of ",", ";", "\t", "|"
  • Default: ","

export.csv.bom

Start CSV files with a UTF-8 byte order mark, so Excel reads accented characters correctly.

  • Type: boolean
  • Default: true

Text Editor

editor.wordWrap

Controls how lines should wrap.

  • Type: one of "off", "on"
  • Default: "off"

editor.runScope

What Shift+Enter runs: the query block under the cursor (statements separated by blank lines, like the Log Analytics portal) or the whole editor. A selection always runs as is.

  • Type: one of "block", "all"
  • Default: "block"
    • "block": The block under the cursor.
    • "all": Everything in the editor.

Text Editor › Font

editor.fontFamily

Controls the font family of the query editor. Empty uses the platform default (Menlo on macOS, Consolas on Windows, Droid Sans Mono on Linux).

  • Type: string
  • Default: ""

editor.fontSize

Controls the font size in pixels of the query editor. 0 uses the platform default (12 on macOS, 14 elsewhere).

  • Type: integer, at least 0, at most 100
  • Default: 0

Text Editor › Minimap

editor.minimap.enabled

Controls whether the minimap is shown.

  • Type: boolean
  • Default: false

Workbench › Appearance

workbench.colorTheme

Specifies the color theme used in the workbench when window.autoDetectColorScheme is off.

  • Type: string (the name of a colour theme)
  • Default: "Raml Dark"

window.autoDetectColorScheme

If set, automatically switch to the preferred dark or light color theme based on the OS appearance.

  • Type: boolean
  • Default: true

workbench.preferredDarkColorTheme

Specifies the color theme used when the OS is in dark mode and window.autoDetectColorScheme is on.

  • Type: string (the name of a colour theme)
  • Default: "Raml Dark"

workbench.preferredLightColorTheme

Specifies the color theme used when the OS is in light mode and window.autoDetectColorScheme is on.

  • Type: string (the name of a colour theme)
  • Default: "Raml Light"

window.autoDetectHighContrast

If set, automatically switch to a high contrast theme when the OS uses a high contrast theme.

  • Type: boolean
  • Default: true

workbench.preferredHighContrastColorTheme

Specifies the dark high contrast color theme used in high contrast mode.

  • Type: string (the name of a colour theme)
  • Default: "Default High Contrast"

workbench.preferredHighContrastLightColorTheme

Specifies the light high contrast color theme used in high contrast mode.

  • Type: string (the name of a colour theme)
  • Default: "Default High Contrast Light"

workbench.statusBar.visible

Controls the visibility of the status bar at the bottom of the workbench.

  • Type: boolean
  • Default: true

Workbench › General

workbench.startupEditor

Controls which editor is shown at startup when no editors are restored.

  • Type: one of "welcomePage", "none"
  • Default: "welcomePage"
    • "welcomePage": Open the Welcome page.
    • "none": Start without an editor.

workbench.commandPalette.history

Controls the number of recently used commands to keep in history for the command palette. Set to 0 to disable command history.

  • Type: integer, at least 0, at most 500
  • Default: 50

Workspaces

workspaces.newWorkspaceDefault

Whether newly discovered workspaces are enabled (shown in Targets) or disabled.

  • Type: one of "enabled", "disabled"
  • Default: "enabled"

targets.groupBySubscription

Show subscriptions as a level in the Targets tree instead of as secondary text.

  • Type: boolean
  • Default: false
Search the docs