← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrActionsCenterHistory

Retrieves historical actions from the Microsoft Defender XDR Action Center.

View source ↗

Gets a list of historical actions from the Microsoft Defender XDR Action Center with options to filter by date range, sort, and paginate the results.

Syntax

Get-XdrActionsCenterHistory [-SortByField <string>] [-SortOrder <string>] [-PageIndex <int>] [-PageSize <int>] [-ToDate <datetime>] [-Months <int>] [-UseMtpApi <bool>] [<CommonParameters>]

Get-XdrActionsCenterHistory [-SortByField <string>] [-SortOrder <string>] [-PageIndex <int>] [-PageSize <int>] [-ToDate <datetime>] [-FromDate <datetime>] [-UseMtpApi <bool>] [<CommonParameters>]

Parameters

-SortByField

Property Value
Type String
Required No
Position named
Pipeline input No
Default ActionUpdateTime

The field to sort actions by. Valid values are: InvestigationId, ApprovalId, ActionType, EntityType, Asset, Decision, DecidedBy, ActionSource, Status, ActionUpdateTime. Defaults to ‘ActionUpdateTime’.

-SortOrder

Property Value
Type String
Required No
Position named
Pipeline input No
Default Descending

The sort order for results. Valid values are ‘Ascending’ or ‘Descending’. Defaults to ‘Descending’.

-PageIndex

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1

The page index for pagination. Defaults to 1.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 100

The number of actions to return per page. Defaults to 100.

-ToDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default (Get-Date)

The end date for the history query. Defaults to current time.

-FromDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default Not documented

The start date for the history query. Defaults to 6 months before ToDate.

-Months

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 6

The number of months to look back from the current date. Cannot be used together with FromDate parameter. Defaults to 6 months if neither FromDate nor Months is specified.

-UseMtpApi

Property Value
Type Boolean
Required No
Position named
Pipeline input No
Default True

Whether to use the MTP API. Defaults to $true.

Examples

Get-XdrActionsCenterHistory
Retrieves the last 6 months of action center history with default settings.
Get-XdrActionsCenterHistory -PageSize 50 -PageIndex 2
Retrieves the second page of 50 historical actions.
Get-XdrActionsCenterHistory -Months 3
Retrieves the last 3 months of action center history.
Get-XdrActionsCenterHistory -FromDate (Get-Date).AddDays(-30) -ToDate (Get-Date)
Retrieves the last 30 days of action center history.
Get-XdrActionsCenterHistory -SortByField "ActionUpdateTime" -SortOrder "Ascending"
Retrieves actions sorted by action update time in ascending order.

Output

Type: Object

Returns the historical actions from the Action Center.

View source