POWERSHELL COMMAND
Get-XdrAdvancedHuntingUserHistory
Retrieves Advanced Hunting user history from Microsoft Defender XDR.
Gets the user’s Advanced Hunting query history from the Microsoft Defender XDR portal. By default, retrieves the last 28 days of history with a maximum of 30 results.
Syntax
Get-XdrAdvancedHuntingUserHistory [-Days <int>] [-MaxResults <int>] [<CommonParameters>]
Get-XdrAdvancedHuntingUserHistory [-StartTime <datetime>] [-MaxResults <int>] [<CommonParameters>]
Parameters
-StartTime
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The start time for retrieving user history. Cannot be used together with Days parameter.
-Days
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 28 |
The number of days to look back from the current date. Cannot be used together with StartTime parameter. Defaults to 28 days if neither StartTime nor Days is specified.
-MaxResults
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 30 |
The maximum number of results to return. Defaults to 30.
Examples
Get-XdrAdvancedHuntingUserHistory
Retrieves the last 28 days of Advanced Hunting user history with up to 30 results.
Get-XdrAdvancedHuntingUserHistory -Days 7 -MaxResults 50
Retrieves the last 7 days of user history with up to 50 results.
Get-XdrAdvancedHuntingUserHistory -StartTime "2025-10-18T18:36:11.482Z"
Retrieves user history from the specified start time with up to 30 results.
Output
Type: Object
Returns the Advanced Hunting user history from the hunting service.