← All XDRInternals commands

POWERSHELL COMMAND

Export-XdrAzureDataExplorer

Exports pipeline data to Azure Data Explorer using queued ingestion.

View source ↗

Accepts pipeline input, stages records as newline-delimited JSON, compresses the staged files with gzip, uploads them to the Azure Data Explorer-managed staging container, and submits queued-ingestion requests.

When used with -TableName alone, the cmdlet uses a raw-table pattern with a single Event:dynamic column. When used with -Source, the cmdlet automatically routes events to typed tables based on their ActionType or SourceTable, creating typed schemas with the appropriate column definitions and JSON ingestion mappings.

Queued ingestion is asynchronous. After this cmdlet uploads blobs and submits ingestion requests, Azure Data Explorer may still take several minutes before the data is queryable. Use -TrackIngestion together with Get-XdrAzureDataExplorerIngestionStatus, or use -WaitForIngestion when you want the cmdlet to wait for queued ingestion to finish.

If a later batch or pipeline stage fails, queued batches that were already submitted cannot be rolled back. Pipeline cancellation closes local writers and removes staging files without uploading or submitting the buffered, unclosed batch.

Requires Set-XdrAzureDataExplorerConnection to be called first.

Syntax

Export-XdrAzureDataExplorer -Data <Object> -TableName <string> [-MappingName <string>] [-MaxBlobSizeMB <int>] [-TempPath <string>] [-KeepTempFiles] [-SkipBootstrap] [-DisableCompression] [-TrackIngestion] [-WaitForIngestion] [-WaitTimeoutMinutes <int>] [-StatusPollingIntervalSeconds <int>] [-PassThru] [<CommonParameters>]

Export-XdrAzureDataExplorer -Data <Object> -Source <string> [-TableName <string>] [-MaxBlobSizeMB <int>] [-TempPath <string>] [-KeepTempFiles] [-SkipBootstrap] [-DisableCompression] [-TrackIngestion] [-WaitForIngestion] [-WaitTimeoutMinutes <int>] [-StatusPollingIntervalSeconds <int>] [-PassThru] [<CommonParameters>]

Parameters

-Data

Property Value
Type Object
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

The objects to export. Accepts pipeline input.

-TableName

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The target Azure Data Explorer table name. Mandatory when -Source is not specified. When -Source is specified, -TableName is optional and serves as a fallback table for events that don’t match any typed table profile.

-Source

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

Enables typed table routing. Events are automatically routed to the appropriate typed ADX table based on their ActionType or SourceTable. Each unique table gets its own staging file, blob upload, and ingestion submission.

-MappingName

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional mapping name. Defaults to _EventMapping. Only valid when -Source is not specified.

-MaxBlobSizeMB

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1024

Maximum uncompressed staging size, in MB, before the cmdlet rolls over to a new blob. The value is capped by the service’s reported queued-ingestion maxDataSize.

-TempPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional root path for temporary staging files.

-KeepTempFiles

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Keeps temporary staging files instead of deleting them after upload.

-SkipBootstrap

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Skips the create-if-missing table and mapping bootstrap logic.

-DisableCompression

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Disables gzip compression for uploaded staging files.

-TrackIngestion

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Requests ADX ingestion operation IDs for each queued ingestion request. Leave this disabled for high-volume exports unless you specifically need per-request tracking.

-WaitForIngestion

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Waits for all queued ingestion requests submitted by this invocation to finish. This automatically enables tracking for the current export.

-WaitTimeoutMinutes

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 30

Maximum number of minutes to wait when -WaitForIngestion is specified.

-StatusPollingIntervalSeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 15

Number of seconds between ingestion-status polls when -WaitForIngestion is specified.

-PassThru

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Outputs the original input objects after staging them for ingestion.

Examples

Set-XdrAzureDataExplorerConnection -ClusterUri "https://mycluster.westeurope.kusto.windows.net" -Database "Investigations"
Get-XdrEndpointDeviceTimeline -DeviceId "2bec169acc9def3ebd0bf8cdcbd9d16eb37e50e2" | Export-XdrAzureDataExplorer -TableName "DeviceTimeline"

Exports a device timeline to Azure Data Explorer using queued ingestion with a single dynamic table.

Get-XdrIdentityUser -Upn "user@contoso.com" | Get-XdrIdentityUserTimeline -LastNDays 30 | Export-XdrAzureDataExplorer -TableName "IdentityTimeline" -PassThru

Queues identity timeline data for ingestion and also passes the records through the pipeline.

Get-XdrEndpointDeviceTimeline -DeviceId "2bec169acc9def3ebd0bf8cdcbd9d16eb37e50e2" -LastNDays 7 | Export-XdrAzureDataExplorer -TableName "DeviceTimeline" -TrackIngestion -Verbose

Queues device timeline data for ingestion and asks ADX to return queued-ingestion operation IDs.

Get-XdrEndpointDeviceTimeline -DeviceId "2bec169acc9def3ebd0bf8cdcbd9d16eb37e50e2" -LastNDays 7 | Export-XdrAzureDataExplorer -TableName "DeviceTimeline" -WaitForIngestion -Verbose

Queues a device timeline export and waits until the queued-ingestion operations finish.

Get-XdrEndpointDeviceTimeline -DeviceId "2bec169acc9def3ebd0bf8cdcbd9d16eb37e50e2" -LastNDays 7 | Export-XdrAzureDataExplorer -Source DeviceTimeline -Verbose

Exports a device timeline using typed table routing. Events are automatically split across tables like XDRDeviceTimelineProcessEvents, XDRDeviceTimelineNetworkEvents, etc. based on their ActionType.

Get-XdrEndpointDeviceTimeline -DeviceId "2bec169acc9def3ebd0bf8cdcbd9d16eb37e50e2" -LastNDays 7 | Export-XdrAzureDataExplorer -Source DeviceTimeline -TableName "DeviceTimelineFallback" -WaitForIngestion -Verbose

Exports a device timeline using typed table routing with a fallback table for unrecognized event types, and waits for all queued ingestion operations to complete.

View source