Kusto Graph Semantics
Build transient and persistent graphs from tabular data using KQL graph operators. This skill translates natural language into the edges-first graph construction pattern and graph query operators.
Activation Triggers
Use this skill when the user:
- Wants to build a graph from tabular data (
make-graph) - Asks to find patterns, paths, or relationships in data
- Mentions
graph-match,graph-shortest-paths,graph-to-table,graph-mark-components - Wants to create a persistent graph model or snapshot
- Says "build a graph", "find the shortest path", "find connected components", "show relationships"
- Asks about transient vs persistent graphs
Not a natural-language-to-KQL converter. The input should generally be a working KQL query whose results the user wants converted to a graph, plus a natural-language description of the desired graph structure. Basic NL source requests are supported only when they map directly to a known table with obvious columns. For general NL-to-KQL conversion, use a dedicated query-generation skill (available separately).
Complementary skills:
azure-kusto-irql-- composable security query primitives that produce the tabular inputs for graphsazure-kusto-irql-graph-- IRQL'sLift_To_GraphJSON mapping system for richly-typed, icon-decorated graphs in Kusto Explorer
The Edges-First Approach
The fundamental pattern for building graphs in Kusto:
This is how to think in make-graph. Edges are the relationships you care about. Nodes are lookup tables that give those IDs a face -- display names, types, properties.
Graph Operators Reference
make-graph -- Build a graph from tables
Edges: tabular source where each row is an edgeSourceId --> TargetId: columns containing source and target node IDswith Nodes on NodeId: optional node property table joined by ID- Supports multiple node tables:
with Nodes1 on Id1, Nodes2 on Id2 - Nodes appearing in edges but missing from the node table get empty properties
graph-match -- Find patterns
Pattern notation:
Multi-hop patterns: (a)-[e1]->(b)-[e2]->(c)
Star patterns: (a)--(center)--(b), (c)--(center)--(d)
Cycles control: cycles = all | none | unique_edges (default: unique_edges)
graph-shortest-paths -- Find shortest paths
- Requires at least one variable-length edge
output = any(default, one path per pair) oroutput = all(all equal-length shortest paths)- Variable-length edge properties returned as dynamic arrays
graph-to-table -- Export graph to tables
graph-mark-components -- Find connected components
Assigns a ComponentId to each node. Nodes in the same connected component share the same ID.
graph() function -- Query persistent graphs
Transient Graphs
Created dynamically during query execution. No setup required. Ideal for ad-hoc analysis, exploration, and prototyping.
Template: Basic two-entity graph
Template: Multi-relationship graph
Persistent Graphs
For large-scale, reusable graphs. Stored in database metadata. Support snapshots for historical comparison.
Safety: Creating or altering graph models and snapshots modifies the database. Always show the exact command and confirm with the user before executing
.create-or-alter graph_modelor.make graph_snapshot.
Step 1: Create a graph model
Step 2: Create a snapshot
Step 3: Query the snapshot
Management commands
Safety: All control commands below modify or delete database objects. Never execute
.drop,.create-or-alter graph_model, or.make graph_snapshotautomatically. Always show the exact command, cluster, database, and affected object, then require explicit user confirmation before execution.
Transient vs Persistent: When to Use Which
Security & Threat Hunting Examples
Authentication graph: who logged into what from where
Lateral movement detection: users sharing compromised hosts
Shortest attack path
Connected components: find isolated clusters
Visualize in Kusto Explorer
End a query at make-graph (without piping to graph-match) to trigger Kusto Explorer's interactive graph visualization window:
To flatten back to a table for dashboards or export, pipe through graph-match | project or graph-to-table.
Using with IRQL
When working with security data, consider using IRQL selectors (Get_*) from the azure-kusto-irql skill as the data source. IRQL gives you a unified schema without memorizing raw table names or column mappings. For rich visualization with icons and node folding, the azure-kusto-irql-graph skill's Lift_To_Graph is the faster path.
Note:
Lift_To_Graph,Graph_Render_View, andGraph_Fold_By_Propertyare stored functions, not built-in operators. They are pre-deployed on the kc7001 example cluster but may need deployment on other clusters. Seeazure-kusto-irql-graph/references/DEPLOY_IRQL_FUNCTIONS.mdfor function definitions and deployment instructions.
Example: IRQL selectors -> make-graph -> shortest path
IRQL handles the data retrieval; make-graph handles the graph analysis. This finds the shortest path from an external IP to a mail server through auth events:
Example: IRQL selectors -> make-graph -> connected components
Find clusters of IPs and domains that are interconnected -- potential C2 infrastructure:
Example: IRQL + make-graph integration
See references/EXAMPLES.md [blocked] for multi-source investigation graphs combining IRQL selectors with make-graph, and Lift_To_Graph visual graph examples.
Practical Usage Scenarios
See references/SCENARIOS.md [blocked] for full worked examples including:
- Reachability analysis (shortest paths to critical assets)
- Network segmentation validation (connected components)
- Blast radius of compromised accounts (variable-length path matching)
- Persistent graph models for SOC teams (graph_model + snapshots)
MCP Tools Used
Opening Queries in Kusto Explorer (Windows Only)
Optional convenience feature. The default workflow is to output the KQL in chat and let the user copy it into Kusto Explorer or the VS Code Kusto extension manually. Auto-launch is opt-in only.
Default: Output KQL in Chat
Always output the complete KQL with Step 1 (connect) and Step 2 (query) clearly labeled:
Then immediately below, output an ADX Web Explorer version that appends | graph-to-table nodes as N, edges as E since ADX Web Explorer cannot render make-graph directly:
This ensures the output works in both Kusto Explorer (graph visualization) and ADX Web Explorer (tabular results) without the user having to modify anything.
Optional: Save and Launch
If the user asks to save or open the query in Kusto Explorer, follow the procedure in references/KUSTO_EXPLORER_LAUNCH.md [blocked]. Key rules:
- Always use
ask_userto confirm before writing files or launching executables - Always display the file contents in chat so the user can review before opening
- Never use shell interpolation or here-strings — write files via
Set-Content/Add-Content - Never encode queries into browser URLs
- On macOS/Linux, save the
.kqlfile and suggest the VS Code Kusto extension or ADX Web Explorer
For make-graph visualization (the graph window), the query must end at make-graph — do not pipe to graph-match. Kusto Explorer only opens the graph visualization window when the output is a graph object, not a table.

