Using traditional SQL for long time, used to order by and limit, top is MS own "limit" but more intuitive.
Here two Kusto queries share the same condition and order by (sorting, right?), only difference is return how many, 20 vs. 200. Result is surprising:
AzureDiagnostics | where Category contains "postgresql" | take 20 | order by TimeGenerated desc
AzureDiagnostics | where Category contains "postgresql" | take 200 | order by TimeGenerated desc
top is more consistence
AzureDiagnostics | where Category contains "postgresql" | top 2 by TimeGenerated desc
AzureDiagnostics | where Category contains "postgresql" | top 20 by TimeGenerated desc
Update, thanks to @Yoni L, here is the summary:
- Sequence of each
|section matters. For instance,|take 10 | order by xwill sort AFTERtakewhich is random. take=limitin terms of usagetopis same except it must be used withsort by x [asc/desc], or in shorttop 10 by x desc.

