← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrAzureDataExplorerCluster

Discovers accessible Azure Data Explorer clusters and databases.

View source ↗

Enumerates Azure Data Explorer (Microsoft.Kusto) clusters visible to the current Azure auth context through Azure Resource Manager, and also includes Azure Data Explorer free clusters exposed through the web control plane. When requested, it also lists databases for each cluster so you can quickly bootstrap Set-XdrAzureDataExplorerConnection without hunting for portal details manually.

Authentication uses the module’s standard Azure token flow: explicit token, Az.Accounts, Azure CLI, browser-derived ESTS bridge, or managed identity.

Each returned cluster includes DiscoveryStatus metadata. IsComplete is false when a provider or requested database enumeration failed, and Failures identifies the provider, scope, and error. Partial results are returned with a warning. Supplying -SubscriptionId intentionally scopes discovery to Azure Resource Manager and does not count skipped free-cluster discovery as a failure.

Syntax

Get-XdrAzureDataExplorerCluster [[-SubscriptionId] <string[]>] [[-ClusterName] <string>] [[-DatabaseName] <string>] [[-TenantId] <string>] [[-ManagedIdentityClientId] <string>] [[-AccessToken] <string>] [[-RequestTimeout] <int>] [-IncludeDatabases] [<CommonParameters>]

Parameters

-SubscriptionId

Property Value
Type String[]
Required No
Position 1
Pipeline input No
Default Not documented

Optional subscription IDs to query. When omitted, all accessible subscriptions are enumerated.

-ClusterName

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional cluster name filter. Wildcards are supported.

-DatabaseName

Property Value
Type String
Required No
Position 3
Pipeline input No
Default Not documented

Optional database name filter. Wildcards are supported and imply -IncludeDatabases.

-IncludeDatabases

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Includes Azure Data Explorer databases for each returned cluster.

-TenantId

Property Value
Type String
Required No
Position 4
Pipeline input No
Default Not documented

Optional tenant ID used during Azure token acquisition.

-ManagedIdentityClientId

Property Value
Type String
Required No
Position 5
Pipeline input No
Default Not documented

Optional user-assigned managed identity client ID for token acquisition via IMDS.

-AccessToken

Property Value
Type String
Required No
Position 6
Pipeline input No
Default Not documented

Optional explicit Azure Resource Manager bearer token.

-RequestTimeout

Property Value
Type Int32
Required No
Position 7
Pipeline input No
Default 60

Optional HTTP timeout for discovery requests. Default is 60 seconds.

Examples

Get-XdrAzureDataExplorerCluster

Lists Azure Data Explorer clusters visible to the current Azure auth context, including accessible free clusters.

Get-XdrAzureDataExplorerCluster -IncludeDatabases

Lists clusters together with their databases.

Get-XdrAzureDataExplorerCluster -ClusterName 'my*' -DatabaseName 'Investigations'

Finds clusters whose names match “my*” and includes only databases matching “Investigations”.

Output

Type: XdrAzureDataExplorerCluster

View source