Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. Generates Lift_To_Graph mappings and composes Graph_Render_View, Graph_Fold_By_Property, Extract_Node_*, Enrich_Node_*, and Enrich_Graph_* calls. Accepts a supplied query or limited basic natural-language source request; it is not a general natural-language-to-KQL/IRQL skill. WHEN: Lift_To_Graph, Graph_Render_View, Graph_Fold_By_Property, IRQL graph enrichment, graph mapping for existing query results, icon-decorated graph, fold graph nodes. Use azure-kusto-graph for native make-graph analysis, graph-match, shortest paths, components, or persistent graphs.
Instrucciones de origen · Vista previa de solo lectura
name
azure-kusto-irql-graph
description
Apply IRQL graph functions to KQL or IRQL query results for Kusto Explorer visualization. Generates Lift_To_Graph mappings and composes Graph_Render_View, Graph_Fold_By_Property, Extract_Node_*, Enrich_Node_*, and Enrich_Graph_* calls. Accepts a supplied query or limited basic natural-language source request; it is not a general natural-language-to-KQL/IRQL skill. WHEN: Lift_To_Graph, Graph_Render_View, Graph_Fold_By_Property, IRQL graph enrichment, graph mapping for existing query results, icon-decorated graph, fold graph nodes. Use azure-kusto-graph for native make-graph analysis, graph-match, shortest paths, components, or persistent graphs.
license
MIT
metadata
{"author":"Microsoft","version":"1.2.1"}
IRQL Graph Functions -- Query Results to Visualization
Apply the IRQL graph function family to tabular results. Given a KQL or IRQL query and the user's graph description, generate a Lift_To_Graph mapping and compose only the stored graph functions needed to visualize, fold, extract, or enrich the graph in Kusto Explorer. The source query does not need to use IRQL.
Scope and Routing
Request
Use
Turn supplied KQL/IRQL rows into an icon-decorated visual graph
This skill: Lift_To_Graph + Graph_Render_View
Fold nodes or apply Extract_Node_*, , or
Enrich_Node_*
Enrich_Graph_*
This skill
Use make-graph, graph-match, shortest paths, connected components, graph models, or snapshots
azure-kusto-graph
Author a non-trivial KQL/IRQL investigation from natural language
A Kusto or IRQL query-generation skill, then this skill
If a request mixes visualization and native graph analysis, use this skill for the lift/render portion and azure-kusto-graph for operator semantics. Do not replace graph-lift functions with a hand-built edges-first graph unless the user asks for native graph operators.
Input Contract
Preferred input: a working KQL/IRQL query that produces tabular results, plus a natural-language description of the desired nodes, edges, labels, icons, extracts, enrichments, or folds.
This skill is not a natural-language-to-KQL or NL-to-IRQL converter. It transforms existing query results into graph visualizations. For general NL-to-KQL or NL-to-IRQL conversion, use a dedicated query-generation skill (available separately).
Preserve the supplied query's retrieval, joins, filters, and aggregations. Add only projections or synthetic IDs required by the graph mapping.
A basic natural-language source request is supported only when it maps directly to one known table or IRQL Get_* selector with obvious columns and simple filters. State the assumed source, and do not invent joins, schema, or investigation logic.
For non-trivial query construction, use a separate Kusto/IRQL query-generation skill first, then apply this skill to its output.
If no query or output schema is available and the source is not trivial, request the KQL query or its result columns before generating a mapping.
Activation Triggers
Use this skill when the user:
Supplies KQL/IRQL results and asks for an IRQL graph visualization or mapping
Mentions Lift_To_Graph, Graph_Render_View, or Graph_Fold_By_Property
Asks for icon-decorated node/edge mappings in Kusto Explorer
Wants to fold/collapse nodes by a shared property
Requests graph extraction or enrichment through Extract_Node_*, Enrich_Node_*, or Enrich_Graph_*
Do not activate this skill solely for graph-match, graph paths/components, persistent graphs, or generic make-graph construction; those belong to azure-kusto-graph.
Not a natural-language-to-KQL/IRQL converter. The input should generally be a working KQL or IRQL query whose results need graph visualization. Basic NL source requests work only for trivial single-table/selector cases. For general NL-to-KQL or NL-to-IRQL, use a dedicated query-generation skill (available separately).
Rendering: Kusto Explorer desktop app (make-graph visualization window)
Tool: kusto_query (via Azure MCP Server)
Function Preflight
Lift_To_Graph and Graph_Render_View are stored functions, not built-in Kusto operators. Before generating or running a lift pipeline against a target database, check what is deployed:
.show functions
| where Name in~ ("Lift_To_Graph", "Graph_Render_View", "Graph_Fold_By_Property")
| project Name
Lift_To_Graph and Graph_Render_View are required.
Graph_Fold_By_Property is required only when folding is requested.
Check any Extract_Node_*, Enrich_Node_*, or Enrich_Graph_* function before using it; omit optional enrichment when unavailable unless the user wants it deployed.
If a required function is missing and you have permission to alter the database, ask the user for confirmation before deploying. Then use the .create-or-alter function definitions in references/DEPLOY_IRQL_FUNCTIONS.md. Run the relevant .create-or-alter block, then rerun the preflight check to confirm.
If you do not have alter permissions, tell the user which functions are missing and point them to references/DEPLOY_IRQL_FUNCTIONS.md for manual deployment.
IRQL Graph Function Family
Lift_To_Graph(T, mappingJson)
Transforms any tabular KQL result into a unified node + edge table.
Input: Any table T + a JSON mapping string.
Output: Rows with EntityType = "node" or "edge", ready for make-graph.
Graph_Render_View(T)
Takes Lift_To_Graph output, splits nodes/edges, and calls make-graph to open Kusto Explorer's graph window.
Graph_Fold_By_Property(T, NodeType, PropertyName)
Collapses nodes of a given type sharing a property value into a single node. Rewires edges automatically.
Graph Extraction and Enrichment Functions
These are additional stored functions that must already be deployed on the target database. They are not bundled in references/DEPLOY_IRQL_FUNCTIONS.md. Use .show functions to verify availability before including in a pipeline.
Process execution graph: User -> Process -> ParentProcess
Input query: Get_Event_Process_All | where ProcessCommandLine has "powershell" | take 300
Graph request: "Visualize process, parent process, host, and user relationships."
let proc_mapping = '{"node_types":[{"type":"Process","id":"Proc","key":"ProcessName","props":["ProcessName","ProcessCommandLine","ProcessHash"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/App-Services.svg"},{"type":"ParentProcess","id":"Proc","key":"ParentProcessName","props":["ParentProcessName","ParentProcessHash"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/App-Services.svg"},{"type":"Host","id":"Host","key":"Hostname","props":["Hostname"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Virtual-Machine.svg"},{"type":"User","id":"User","key":"Username","props":["Username"],"defaults":{},"defIcon":"https://raw.githubusercontent.com/benc-uk/icon-collection/master/azure-icons/Users.svg"}],"edges":[{"type":"SpawnedBy","source":{"id":"Proc","type":"Process"},"target":{"id":"Proc","type":"ParentProcess"},"props":["EnvTime"]},{"type":"RanOn","source":{"id":"Proc","type":"Process"},"target":{"id":"Host","type":"Host"},"props":["EnvTime"]},{"type":"ExecutedBy","source":{"id":"Proc","type":"Process"},"target":{"id":"User","type":"User"},"props":["EnvTime"]}]}';
Get_Event_Process_All
| where ProcessCommandLine has "powershell"
| take 300
| invoke Lift_To_Graph(proc_mapping)
| invoke Graph_Render_View()
Query Results -> Mapping Translation
When the user supplies a query and describes the graph:
Inspect the query's final output columns
Parse the entity nouns and relationship verbs
Generate the mapping JSON using only those columns
Preserve the supplied pipeline and append Lift_To_Graph()
Include Graph_Render_View() at the end
If the user mentions grouping/collapsing and the function exists, add Graph_Fold_By_Property()
Output the complete KQL -- the supplied query plus mapping JSON inline as a string let binding -- after the required-function preflight passes. Clearly mark unverified function dependencies when the target database cannot be checked.
Opening Queries in Kusto Explorer (Windows Only)
Optional convenience feature. The default workflow is to output the KQL in chat and let the user copy it into Kusto Explorer or the VS Code Kusto extension manually. Auto-launch is opt-in only.
Always output the complete KQL query in the chat response with Step 1 (connect) and Step 2 (query) clearly labeled:
// Step 1: Connect to your cluster (skip if already connected)
// Example: uncomment to connect to the KC7 training cluster
// #connect cluster('kc7001.eastus.kusto.windows.net').database('ValdyTimes')
// Or replace with your own cluster:
// #connect cluster('<YOUR_CLUSTER>').database('<YOUR_DATABASE>')
// Step 2: Run the query below
<KQL_QUERY>