Skip to content

Releases: ChrisHuber1/KustoForge

v1.1.0 — Raw KQL mode

Choose a tag to compare

@ChrisHuber1 ChrisHuber1 released this 22 Jun 15:16

v1.1.0 — Raw KQL mode

KustoForge can now both build queries via the form and accept full free-form KQL.

New

  • Raw KQL mode — toggle "Edit / paste raw KQL" to write or paste queries the form can't express (mv-expand, summarize, join, let), then save them to the library.
  • Library now stores both kinds — form-built (structured) and raw. Raw entries load straight into the editor and show in orange. Legacy entries load as structured with no migration.

Fixed

  • Highlighter no longer mis-colors the first line of multi-statement / comment-led queries.

Full changelog: d51b4aa...v1.1.0

KustoForge v1.0.0

Choose a tag to compare

@ChrisHuber1 ChrisHuber1 released this 03 Jun 19:40

KustoForge v1.0.0 — Initial Release

Desktop KQL query builder for Microsoft security and Azure services.

Features

  • Form-based query building with smart operators per data type
  • 52 tables across 9 categories (Defender, Sentinel, Entra ID, Azure Monitor, App Insights, Resource Graph, Cloud Apps)
  • Live query preview with KQL syntax highlighting
  • Query library — save, load, and manage named queries
  • Copy to clipboard
  • Dark theme with Microsoft blue accents
  • in / !in operators for filtering value lists
  • Alphabetically sorted columns for easy browsing

Install

git clone https://github.com/ChrisHuber1/KustoForge.git
cd KustoForge
pip install -r requirements.txt
python main.py

Requirements

  • Python 3.10+
  • PySide6