MCP KQL Server is an MCP server that connects AI assistants to Azure Data Explorer clusters using Azure CLI authentication. Used by cloud engineers, security operations analysts, and database administrators, it enables users to query telemetry, logs, and distributed data using both plain language and raw Kusto Query Language syntax. The server transforms natural language descriptions into valid KQL statements while handling direct query execution against specified databases. It incorporates an automated schema memory discovery engine that inspects, ranks, and caches database table definitions, which prevents redundant cluster discovery calls during repeated interactions. Queries undergo strict schema validation and grounded repairs against cached metadata before submission, preventing invalid column names or broken references from reaching the cluster. Results can be returned in multiple formats, such as JSON, CSV, or formatted tables, alongside contextual schema insights. Developed with the official Model Context Protocol Python SDK, the tool functions across major operating systems via standard input and output streams or shared HTTP endpoints. By operating through local Azure CLI credentials, it maintains existing enterprise identity boundaries without requiring hardcoded cloud secrets.
Category: Cloud & Infrastructure
Tags: azure, kql, kusto, log-analytics
az login. 2. Install the server package: bash pip install --upgrade mcp-kql-server 3. In Claude Desktop, open your configuration file (mcp_settings.json) and add the server definition: json { "mcpServers": { "mcpKqlServer": { "type": "stdio", "command": "python", "args": ["-m", "mcp_kql_server"] } } } 4. For VS Code with the MCP extension, add the configuration to mcp.json under servers using "command": "py" (Windows) or "python3" (macOS/Linux) with arguments ["-3", "-m", "mcp_kql_server", "--transport", "stdio"]. 5. Restart your MCP client to enable the query execution and schema memory tools.Part of MCP Servers
You can install MCP KQL Server by running pip install mcp-kql-server in a Python 3.10 or higher environment. Alternatively, clone the repository and run pip install -e . from the source folder. Ensure the Azure CLI is installed on your system, as the server checks your Azure authentication token on startup and prompts for az login if you are not already logged in.
The server provides two primary tools: execute_kql_query and kql_schema_memory. The query tool supports natural language to KQL conversion, direct query execution, schema validation, grounded column repairs, and data export in JSON, CSV, or table formats. The schema memory tool handles schema discovery, database table enumeration, schema cache clearing, and memory usage statistics.
MCP KQL Server works with any client supporting the Model Context Protocol over standard input and output or HTTP transports. Documented configurations include Claude Desktop and Visual Studio Code with the MCP extension. It can also operate as a persistent shared HTTP server for agents and command line tools like GitHub Copilot CLI.
The server relies directly on local Azure CLI authentication rather than hardcoded credentials or API keys. When starting up, it validates the current Azure token. If authentication is expired or missing, it triggers an interactive az login process, allowing tool executions to run under the active operator Azure identity and cluster access permissions.