← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrCloudAppsActivityTimeline

Retrieves Microsoft Defender for Cloud Apps activity timeline data.

View source ↗

Retrieves Cloud Apps activity events with reliable chunking, retry handling, recent/archived API routing, export support, and typed admin-friendly output.

Syntax

Get-XdrCloudAppsActivityTimeline [-FromDate <datetime>] [-ToDate <datetime>] [-LastNDays <int>] [-PageSize <int>] [-Filters <hashtable>] [-IncludeThreatScores] [-ThrottleLimit <int>] [-ChunkHours <int>] [-Aggressive] [-TimeoutSeconds <int>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-RequestTimeoutSeconds <int>] [-OutputPath <string>] [-KeepTempFiles] [-ExportPath <string>] [-ExportFormat <string>] [-PassThru] [-Compress] [-AllowPartial] [-Force] [<CommonParameters>]

Get-XdrCloudAppsActivityTimeline -Metadata [-Raw] [-Force] [<CommonParameters>]

Get-XdrCloudAppsActivityTimeline -ArchivedMetadata [-Raw] [-Force] [<CommonParameters>]

Get-XdrCloudAppsActivityTimeline -CountOnly [-FromDate <datetime>] [-ToDate <datetime>] [-LastNDays <int>] [-Filters <hashtable>] [-MaxRetries <int>] [-RetryDelaySeconds <int>] [-Force] [<CommonParameters>]

Parameters

-Metadata

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Returns filter metadata for the recent activities API.

-ArchivedMetadata

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Returns filter metadata for the archived activities API.

-Raw

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns raw API metadata or response data when supported.

-CountOnly

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Returns activity counts without retrieving full activity records.

-FromDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default Not documented

Start of the timeline range.

-ToDate

Property Value
Type DateTime
Required No
Position named
Pipeline input No
Default Not documented

End of the timeline range.

-LastNDays

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 0

Retrieves activity from the last specified number of days.

-PageSize

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 250

Number of activities to request per page.

-Filters

Property Value
Type Hashtable
Required No
Position named
Pipeline input No
Default @{}

Cloud Apps activity filters to include in the query body.

-IncludeThreatScores

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Adds threat score data for recent activities when available.

-ThrottleLimit

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 8

Maximum number of chunks to retrieve concurrently.

-ChunkHours

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 6

Maximum hours represented by each activity chunk.

-Aggressive

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Uses higher concurrency and smaller chunks for incident response investigations.

-TimeoutSeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 3600

Maximum total runtime for chunk retrieval.

-MaxRetries

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 5

Maximum retry attempts for each page request.

-RetryDelaySeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 5

Base delay used for retry backoff.

-RequestTimeoutSeconds

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 60

Timeout for each individual HTTP request.

-OutputPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Directory used for temporary chunk files.

-KeepTempFiles

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Keeps temporary chunk files after the command completes.

-ExportPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Writes retrieved activity events to a JSON file.

-ExportFormat

Property Value
Type String
Required No
Position named
Pipeline input No
Default Json

Export file format. Json preserves the existing array output; Ndjson streams one event per line and is preferred for large incident response exports.

-PassThru

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns activity events after writing ExportPath.

-Compress

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Writes compressed JSON when ExportPath is used.

-AllowPartial

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Returns completed chunks instead of terminating when one or more chunks fail.

-Force

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses cache-backed metadata requests.

Examples

Get-XdrCloudAppsActivityTimeline -LastNDays 1

Retrieves the last day of Cloud Apps activity.

Get-XdrCloudAppsActivityTimeline -LastNDays 7 -Aggressive -ExportPath .\cloud-apps-activity.json

Retrieves seven days of activity using aggressive incident response settings and exports to JSON.

Output

Type: System.Management.Automation.PSObject[]

View source