POWERSHELL COMMAND
Export-XdrToSentinel
Exports XDR data to a Microsoft Sentinel (Log Analytics) custom table.
Sends data to a Log Analytics workspace using the HTTP Data Collector API. Data appears in the workspace as a custom log table with the “_CL” suffix.
Requires Set-XdrSentinelConnection to be called first with workspace credentials.
Accepts pipeline input from any XDRInternals Get-* cmdlet or any PowerShell object array. Objects are serialized to JSON and posted in batches (max 30 MB per batch).
Syntax
Export-XdrToSentinel [-Data] <Object> [-LogType] <string> [[-TimestampField] <string>] [[-BatchSize] <int>] [-PassThru] [<CommonParameters>]
Parameters
-Data
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue) |
| Default | Not documented |
The data to export. Accepts pipeline input or an explicit array of objects.
-LogType
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
The custom log type name. This becomes the table name in Log Analytics with “_CL” appended. Example: “XdrSuppressionRules” becomes “XdrSuppressionRules_CL”. Must contain only letters, numbers, and underscores, max 100 characters.
-TimestampField
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | Not documented |
Optional field name in the data that contains a timestamp. If specified, Log Analytics uses this as the TimeGenerated field instead of ingestion time.
-BatchSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | 500 |
Maximum number of records per API call. Defaults to 500.
-PassThru
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
When specified, outputs the original data to the pipeline after exporting.
Examples
Get-XdrSuppressionRule | Export-XdrToSentinel -LogType "XdrSuppressionRules"
Exports all suppression rules to the XdrSuppressionRules_CL table.
Get-XdrEndpointAdvancedFeatures | Export-XdrToSentinel -LogType "XdrAdvancedFeatures"
Get-XdrAlert -Top 100 | Export-XdrToSentinel -LogType "XdrAlerts" -TimestampField "CreationTime" -PassThru | Format-Table
Exports alerts and also passes them through for display.
$devices = Get-XdrEndpointDevice
Export-XdrToSentinel -Data $devices -LogType "XdrDevices"
Output
Type: None by default. With -PassThru, outputs the original input objects.