Forum Discussion
KQL update policy
- Anonymous1 year ago
Hi chetanhiwale ,
Please try the following alternatives to see if they work:
1. Intermediate Table Approach
(1)Continue using `src_table` with streaming ingestion enabled to receive real-time data.
(2)Create an intermediate table (e.g., `intermediate_table`) without streaming ingestion.
(3)Set up an update policy on `intermediate_table` to transform and join data from `src_table` and `reference_table`, and then store the result in `target_table`..alter table intermediate_table policy update @'[{"IsEnabled": true, "Source": "src_table", "Query": "src_table | join kind=inner (reference_table) on id | project src_table.id, src_table.name, reference_table.additional_info", "IsTransactional": true}]'2.Use a scheduled query to periodically join `src_table` and `reference_table`, and insert the results into `target_table`. This way, you can keep streaming ingestion enabled on `src_table`.
```kql .create-or-alter function UpdateTargetTable() { src_table | join kind=inner (reference_table) on id | project src_table.id, src_table.name, reference_table.additional_info | into target_table } .create-or-alter function ScheduledUpdate() { UpdateTargetTable() } .create-or-alter function ScheduledUpdatePolicy() { .set-or-append target_table <| ScheduledUpdate() } .schedule function ScheduledUpdatePolicy() every 5m ```Best Regards,
Neeko Tang
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
Hi chetanhiwale ,
I apologize for ignoring some of the limitations.
I found some information for your reference:
.alter table src_table policy streamingingestion '{"IsEnabled": false}'
For more details, please refer:
Update policy overview - Kusto | Microsoft Learn
.alter table policy streamingingestion command - Kusto | Microsoft Learn
Best Regards,
Neeko Tang
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
By disabling streaming ingestion , we cant use src_table , as we will not get any data in src_table. Please share your thoughts on it.
- Anonymous1 year agoNot applicable
Hi chetanhiwale ,
Please try the following alternatives to see if they work:
1. Intermediate Table Approach
(1)Continue using `src_table` with streaming ingestion enabled to receive real-time data.
(2)Create an intermediate table (e.g., `intermediate_table`) without streaming ingestion.
(3)Set up an update policy on `intermediate_table` to transform and join data from `src_table` and `reference_table`, and then store the result in `target_table`..alter table intermediate_table policy update @'[{"IsEnabled": true, "Source": "src_table", "Query": "src_table | join kind=inner (reference_table) on id | project src_table.id, src_table.name, reference_table.additional_info", "IsTransactional": true}]'2.Use a scheduled query to periodically join `src_table` and `reference_table`, and insert the results into `target_table`. This way, you can keep streaming ingestion enabled on `src_table`.
```kql .create-or-alter function UpdateTargetTable() { src_table | join kind=inner (reference_table) on id | project src_table.id, src_table.name, reference_table.additional_info | into target_table } .create-or-alter function ScheduledUpdate() { UpdateTargetTable() } .create-or-alter function ScheduledUpdatePolicy() { .set-or-append target_table <| ScheduledUpdate() } .schedule function ScheduledUpdatePolicy() every 5m ```Best Regards,
Neeko Tang
If this post helps, then please consider Accept it as the solution to help the other members find it more quickly.
- Anonymous1 year agoNot applicable
I have error when i try:
.create-or-alter function ScheduledUpdatePolicy() { .set-or-append target_table <| ScheduledUpdate() }Also, ".schedule function ScheduledUpdate() every 5m" also doesn't work
I think .schedule is not a KQL command, also create an intermediate table that you never use, this solution doesn't work, I don't understand why it was marked correctly