← All XDRInternals commands

POWERSHELL COMMAND

Export-XdrToSentinel

Exports XDR data to a Microsoft Sentinel (Log Analytics) custom table.

View source ↗

Sends data to a Log Analytics workspace using the HTTP Data Collector API. Data appears in the workspace as a custom log table with the “_CL” suffix.

Requires Set-XdrSentinelConnection to be called first with workspace credentials.

Accepts pipeline input from any XDRInternals Get-* cmdlet or any PowerShell object array. Objects are serialized to JSON and posted in batches (max 30 MB per batch).

Syntax

Export-XdrToSentinel [-Data] <Object> [-LogType] <string> [[-TimestampField] <string>] [[-BatchSize] <int>] [-PassThru] [<CommonParameters>]

Parameters

-Data

Property Value
Type Object
Required Yes
Position 1
Pipeline input true (ByValue)
Default Not documented

The data to export. Accepts pipeline input or an explicit array of objects.

-LogType

Property Value
Type String
Required Yes
Position 2
Pipeline input No
Default Not documented

The custom log type name. This becomes the table name in Log Analytics with “_CL” appended. Example: “XdrSuppressionRules” becomes “XdrSuppressionRules_CL”. Must contain only letters, numbers, and underscores, max 100 characters.

-TimestampField

Property Value
Type String
Required No
Position 3
Pipeline input No
Default Not documented

Optional field name in the data that contains a timestamp. If specified, Log Analytics uses this as the TimeGenerated field instead of ingestion time.

-BatchSize

Property Value
Type Int32
Required No
Position 4
Pipeline input No
Default 500

Maximum number of records per API call. Defaults to 500.

-PassThru

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

When specified, outputs the original data to the pipeline after exporting.

Examples

Get-XdrSuppressionRule | Export-XdrToSentinel -LogType "XdrSuppressionRules"

Exports all suppression rules to the XdrSuppressionRules_CL table.

Get-XdrEndpointAdvancedFeatures | Export-XdrToSentinel -LogType "XdrAdvancedFeatures"
Get-XdrAlert -Top 100 | Export-XdrToSentinel -LogType "XdrAlerts" -TimestampField "CreationTime" -PassThru | Format-Table

Exports alerts and also passes them through for display.

$devices = Get-XdrEndpointDevice
Export-XdrToSentinel -Data $devices -LogType "XdrDevices"

Output

Type: None by default. With -PassThru, outputs the original input objects.

View source