POWERSHELL COMMAND
Get-XdrCloudAppsActivityTimeline
Retrieves Microsoft Defender for Cloud Apps activity timeline data.
Retrieves Cloud Apps activity events with reliable chunking, retry handling, recent/archived API routing, export support, and typed admin-friendly output.
Syntax
Get-XdrCloudAppsActivityTimeline [-FromDate <datetime>] [-ToDate <datetime>] [-LastNDays <int>] [-PageSize <int>] [-Filters <hashtable>] [-IncludeThreatScores] [-ThrottleLimit <int>] [-ChunkHours <int>] [-Aggressive] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [-ExportFormat <string>] [-PassThru] [-Compress] [-AllowPartial] [-Force] [<CommonParameters>]
Get-XdrCloudAppsActivityTimeline -Metadata [-Raw] [-Force] [<CommonParameters>]
Get-XdrCloudAppsActivityTimeline -ArchivedMetadata [-Raw] [-Force] [<CommonParameters>]
Get-XdrCloudAppsActivityTimeline -CountOnly [-FromDate <datetime>] [-ToDate <datetime>] [-LastNDays <int>] [-Filters <hashtable>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-Force] [<CommonParameters>]
Parameters
-Metadata
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns filter metadata for the recent activities API.
-ArchivedMetadata
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns filter metadata for the archived activities API.
-Raw
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns raw API metadata or response data when supported.
-CountOnly
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns activity counts without retrieving full activity records.
-FromDate
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Start of the timeline range.
-ToDate
| Property | Value |
|---|---|
| Type | DateTime |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
End of the timeline range.
-LastNDays
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 0 |
Retrieves activity from the last specified number of days.
-PageSize
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 250 |
Number of activities to request per page.
-Filters
| Property | Value |
|---|---|
| Type | Hashtable |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | @{} |
Cloud Apps activity filters to include in the query body.
-IncludeThreatScores
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Adds threat score data for recent activities when available.
-ThrottleLimit
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 8 |
Maximum number of chunks to retrieve concurrently.
-ChunkHours
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 6 |
Maximum hours represented by each activity chunk.
-Aggressive
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Uses higher concurrency and smaller chunks for incident response investigations.
-TimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 3600 |
Maximum total runtime for chunk retrieval.
-MaxRetries
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 5 |
Maximum retry attempts for each page request.
-RetryDelaySeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 5 |
Base delay used for retry backoff.
-RequestTimeoutSeconds
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 60 |
Timeout for each individual HTTP request.
-OutputPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Directory used for temporary chunk files.
-KeepTempFiles
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Keeps temporary chunk files after the command completes.
-ExportPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Writes retrieved activity events to a JSON file.
-ExportFormat
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Json |
Export file format. Json preserves the existing array output; Ndjson streams one event per line and is preferred for large incident response exports.
-PassThru
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns activity events after writing ExportPath.
-Compress
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Writes compressed JSON when ExportPath is used.
-AllowPartial
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Returns completed chunks instead of terminating when one or more chunks fail.
-Force
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses cache-backed metadata requests.
Examples
Get-XdrCloudAppsActivityTimeline -LastNDays 1
Retrieves the last day of Cloud Apps activity.
Get-XdrCloudAppsActivityTimeline -LastNDays 7 -Aggressive -ExportPath .\cloud-apps-activity.json
Retrieves seven days of activity using aggressive incident response settings and exports to JSON.
Output
Type: System.Management.Automation.PSObject[]