Alert queries fail with "input data must be wide series but got type not (input refid)"

What Grafana version and what operating system are you using?

Are you using Grafana Cloud or self-hosted Grafana?
Self Hosted

Are you using legacy alerting or Unified Alerting?
Unified Alerting

Was the alert in question migrated from the legacy platform into Unified Alerting, or did you first create it inside the new platform?
Create on new platform

Please list ALL configuration options related to alerting. You can find these in the Alerting and Unified Alerting sections of Grafana’s config file. If you are now using or have previously used the beta version of ngalert (released with Grafana 8), please note that too.

Rule type : Grafana Managed ALERT
KQL query created to alert
Type of query : Time series


| where $__timeFilter(TimeStamp)

| where RecordType == “NetworkResponse”

| extend ParsedURL = parse_url(tostring(NetworkURL))

| extend Hostname = tostring(ParsedURL.Host)

| extend Path = tostring(ParsedURL.Path)

| extend StatusCode = tostring(Event)

| where Path contains “/identifier/repository”

| where StatusCode startswith “5”

| summarize ErrorCount = count() by bin(TimeStamp, 5m), Hostname, applicationID, path

What are you trying to achieve?
Alert based on 5XX errors count returned and categorize them by hostname, applicationID, path to be used as labels when alerting

How are you trying to achieve it?
Configuring a kql based alert on Azure Data explorer database.

What happened?
Query returns the necessary columns(hostname, applicationID, path) with respective error count when i execute the same in a dashboard panel but fails when i use the same as alert query with error
"Failed to evaluate queries and expressions: failed to execute conditions: input data must be a wide series but got type long (input refid)"

What did you expect to happen?
The data that is returned is similar to what is mentioned in the documentation, however the alert query still fails.

Query result in alert panel

Query result in dashboard panel

Did you receive any errors in the Grafana UI or in related logs? If so, please tell us exactly what they were.
Failed to evaluate queries and expressions: failed to execute conditions: input data must be a wide series but got type long (input refid)

@sowdenraymond. I’ve seen the issue you shared with me, but in my case as you can see from the screenshots shared above there is numeric data(ErrorCount) that is being output and the rest all fields are converted to string as required from the documentation. I don’t understand why it fails to summarize still

can you try without the status code and see?

I’ve removed everything except for ErrorCount and Hostname. I still see the same error

The query returns without any error if i remove the hostname field along with other string fields when summarizing but i’d at a minimum need the hostname field to have it available as a label when sending alerts.

if you run the same query in a panel, do you get actual data back?

Yes, the same query with all the fields included (ErrorCount, Hostname, path, applicationId, status code) returns data when i do it from the dashboard panel, only problem with configuring alert

can you simplify it down to timestamp, count and hostname just to check?

Dashboard panel with just timestamp, count and hostname

does this work for the alert?

unfortunately no, when i use the same query for alert i get the error