06 Cloudappevents Agent Execution Spans
Query
CloudAppEvents
| where Timestamp > ago(LookbackWindow)
| where ActionType in (AgentSpanActionTypes)
| where isnotempty(RawEventData)
| extend Operation = tostring(RawEventData.Operation)
| extend AgentIdentityId = coalesce(tostring(RawEventData.TargetAgentId), tostring(RawEventData.AgentId), tostring(RawEventData.AgentId))
| extend AgentBlueprintId = coalesce(tostring(RawEventData.TargetAgentBlueprintID), tostring(RawEventData.AgentBlueprintId))
| extend ConversationId = tostring(RawEventData.ConversationId)
| extend ChannelName = tostring(RawEventData.ChannelName)
| extend ToolName = tostring(RawEventData.ToolName)
| extend ToolType = tostring(RawEventData.ToolType)
| extend ToolId = tostring(RawEventData.ToolId)
| extend ClientIP = tostring(RawEventData.ClientIP)
| extend UserKey = tostring(RawEventData.UserKey)
| extend UserId = tostring(RawEventData.UserId)
| extend SpanId = tostring(RawEventData.OpId)
| extend ParentSpanId = tostring(RawEventData.ParentId)
| extend CompletionTime = todatetime(RawEventData.CompletionTime)
| extend ErrorMessage = tostring(RawEventData.ErrorMessage)
| extend ErrorType = tostring(RawEventData.ErrorType)
| extend ResultType = case(
isnotempty(ErrorType) or isnotempty(ErrorMessage), "error",
"success"
// NOTE: there is no confirmed "denied" (authorization-failure) signal in
// this attribute set today -- ErrorType is a free-form OTel status
// category, not an HTTP-style status code. Do not assume ErrorType values
// map to "denied" without inspecting real ErrorType values in your tenant first.
)
| extend PermissionUsed = iff(Operation == "execute_tool" and isnotempty(ToolName), strcat(ToolType, ":", ToolName), "")
| project
Timestamp,
AgentIdentityId,
AgentBlueprintId,
Operation,
ConversationId,
ChannelName,
ToolName, ToolType, ToolId,
PermissionUsed,
ClientIP,
UserKey, UserId,
SpanId, ParentSpanId,
CompletionTime,
ResultType,
ErrorType, ErrorMessage
| order by Timestamp descAbout this query
Explanation
This query is designed to analyze and extract information about agent execution spans from the CloudAppEvents table, which contains telemetry data from Microsoft Agent 365. Here's a simplified breakdown of what the query does:
-
Initial Setup:
- The query is part of a series of queries (Phase 3, query 6 of 7) aimed at analyzing agent execution data.
- It uses data from the
CloudAppEventstable, which requires Microsoft Agent 365 telemetry to be configured.
-
Step 1 - Schema Discovery:
- Before filtering the data, it first identifies which
ActionTypevalues in your tenant contain the relevant agent span data. This is done by checking for specific field names (AgentBlueprintIdorTargetAgentBlueprintID) within theRawEventData. - The result of this step helps determine the correct
ActionTypevalues to use in the main query.
- Before filtering the data, it first identifies which
-
Main Query:
- Lookback Window: The query looks at data from the past 90 days (or another specified period).
- Filter by ActionType: It filters events based on the
ActionTypevalues identified in Step 1. - Extract and Transform Data: The query extracts various fields from theRawEventDataJSON, such asOperation,AgentIdentityId,AgentBlueprintId,ConversationId,ChannelName,ToolName,ToolType,ToolId,ClientIP,UserKey,UserId,SpanId,ParentSpanId,CompletionTime,ErrorMessage, andErrorType. - Determine Result Type: It classifies the result as "error" if there is an
ErrorTypeorErrorMessage, otherwise as "success". - Permission Used: For operations labeled as "execute_tool", it constructs a
PermissionUsedfield usingToolTypeandToolName.
-
Output:
- The query projects a set of fields to display, including
Timestamp,AgentIdentityId,AgentBlueprintId,Operation,ConversationId,ChannelName,ToolName,ToolType,ToolId,PermissionUsed,ClientIP,UserKey,UserId,SpanId,ParentSpanId,CompletionTime,ResultType,ErrorType, andErrorMessage. - The results are ordered by
Timestampin descending order.
- The query projects a set of fields to display, including
In summary, this query is used to extract and analyze detailed information about agent execution activities from the CloudAppEvents table, focusing on specific telemetry data related to Microsoft Agent 365.