← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrAlert

Retrieves alerts from Microsoft Defender XDR.

View source ↗

Gets alerts from Microsoft Defender XDR with support for filtering by time range and pagination. Alerts can be retrieved with automatic pagination using the -All parameter or with manual page control.

Syntax

Get-XdrAlert [-DaysAgo <int>] [-Order <string>] [-PageNumber <int>] [-PageSize <int>] [-Severity <string[]>] [-Status <string[]>] [<CommonParameters>]

Get-XdrAlert [-DaysAgo <int>] [-Order <string>] [-PageSize <int>] [-Severity <string[]>] [-Status <string[]>] [-All] [<CommonParameters>]

Parameters

-DaysAgo

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 7

Number of days to look back for alerts. Default is 7 days.

-Order

Property Value
Type String
Required No
Position named
Pipeline input No
Default desc

Sort order for results. Valid values are “desc” (descending, newest first) or “asc” (ascending, oldest first). Default is “desc”.

-PageNumber

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 1

Specific page number to retrieve. Cannot be used with -All parameter. Default is 1.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 60

Number of alerts to retrieve per page. Default is 60. Maximum value depends on API limits.

-Severity

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Filter alerts by severity. Valid values are “Informational”, “Low”, “Medium”, “High”. Multiple values can be specified as an array.

-Status

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Filter alerts by status. Valid values are “New”, “InProgress”, “Resolved”. Multiple values can be specified as an array.

-All

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Automatically retrieves all pages of alerts for the specified time range. Cannot be used with -PageNumber parameter.

Examples

Get-XdrAlert
Retrieves the first page of alerts from the last 7 days, sorted by newest first.
Get-XdrAlert -DaysAgo 30
Retrieves alerts from the last 30 days.
Get-XdrAlert -Order asc
Retrieves alerts sorted by oldest first.
Get-XdrAlert -PageNumber 2 -PageSize 100
Retrieves the second page with 100 alerts per page.
Get-XdrAlert -All
Automatically retrieves all alerts from the last 7 days across all pages.
Get-XdrAlert -DaysAgo 14 -All
Retrieves all alerts from the last 14 days with automatic pagination.
Get-XdrAlert -Severity High, Medium
Retrieves only high and medium severity alerts from the last 7 days.
Get-XdrAlert -Status New, InProgress
Retrieves only new and in-progress alerts.
Get-XdrAlert -Severity High -Status New -DaysAgo 30
Retrieves high severity new alerts from the last 30 days.
Get-XdrAlert | Where-Object { $_.severity -eq "High" }
Retrieves alerts and filters for high severity only.

Output

Type: Object[]

Returns an array of alert objects containing:

  • alertId: Unique identifier for the alert
  • alertDisplayName: Display name of the alert
  • providerName: Source provider (e.g., Microsoft Sentinel, Microsoft Defender)
  • status: Alert status (New, InProgress, Resolved)
  • severity: Alert severity (Informational, Low, Medium, High)
  • classification: Alert classification if set
  • determination: Alert determination if set
  • assignedTo: User assigned to the alert
  • incidentId: Associated incident ID
  • startTimeUtc: Alert start time
  • endTimeUtc: Alert end time
  • timeGenerated: Alert generation time
  • impactedEntities: List of impacted entities
  • mitreAttackCategory: MITRE ATT&CK category
  • mitreAttackTechnique: MITRE ATT&CK technique IDs And many other properties depending on the alert type.

View source