Formats a KQL query in the standard layout, with each pipe operator on its own line
Use this endpoint to tidy a query before reading, sharing, or running it with POST workbench/query. It uses the
standard Kusto formatter: every pipe operator starts a new line, nested queries (such as a join’s right side)
are indented, and spacing is normalized. Only whitespace changes, except that
[Name With Spaces]
identifiers are written as ['Name With Spaces']. The query is not validated or run, so incomplete
queries can be formatted; one that can’t be laid out without changing more than whitespace is returned as it
was. Restricted to ENC staff.
Request Headers
| Header | Value | Required | Description |
|---|---|---|---|
| ECI-ApiKey | string | Yes | Your API key. See Authentication. |
| Content-Type | application/json | Yes | All requests must specify JSON content type, including the request body. |
Request Body
WorkbenchFormatKqlRequestV202609
| Property | Description | Type |
|---|---|---|
| kql | The KQL query to format. It does not need to be complete or valid. Maximum length: 100,000 characters. Max length of 100000 | string |
Example Request Body
{ "kql": "string"
}
Responses
200
OK
The request succeeded and the response body contains the requested data.
Response Body Parameters
WorkbenchFormatKqlResponseV202609
| Property | Description | Type |
|---|---|---|
| kql | The formatted query: each pipe operator starts a new line and nested queries are indented. Only whitespace
changes, except that [Name With Spaces] identifiers are written in their standard form,
['Name With Spaces']. A query that can’t be formatted that way is returned unchanged. |
string |
Example Response
{ "kql": "string"
}