← All XDRInternals commands

POWERSHELL COMMAND

Get-XdrEndpointDeviceActionResult

Gets device action results and download URIs from Microsoft Defender XDR.

View source ↗

Retrieves the latest device action results for a device, or downloads completed investigation package or support log collection results.

When called with just -DeviceId, returns the latest action results for each action type including status, requestor, timestamps, and request GUIDs.

When called with -DownloadInvestigationPackage or -DownloadSupportLogs, retrieves the download URI for completed collection results. You can provide either a DeviceId (which auto-resolves the latest RequestGuid from machine state) or a RequestGuid directly.

Syntax

Get-XdrEndpointDeviceActionResult -DeviceId <string> [-RequestGuid <string>] [<CommonParameters>]

Get-XdrEndpointDeviceActionResult -DeviceId <string> -DownloadSupportLogs [<CommonParameters>]

Get-XdrEndpointDeviceActionResult -DeviceId <string> -DownloadInvestigationPackage [<CommonParameters>]

Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -RequestGuid <string> [<CommonParameters>]

Get-XdrEndpointDeviceActionResult -DownloadSupportLogs -RequestGuid <string> [<CommonParameters>]

Parameters

-DeviceId

Property Value
Type String
Required Yes
Position named
Pipeline input true (ByPropertyName)
Default Not documented

The device identifier (SenseMachineId) to query action results for. Accepts pipeline input by property name and supports MachineId/SenseMachineId aliases.

-DownloadInvestigationPackage

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Retrieve the download URI for the latest investigation package (forensics) collection.

-DownloadSupportLogs

Property Value
Type SwitchParameter
Required Yes
Position named
Pipeline input No
Default False

Retrieve the download URI for the latest support logs collection.

-RequestGuid

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The GUID of a specific request. When used with -DeviceId (List mode), filters the results to the matching request. When used with -DownloadInvestigationPackage or -DownloadSupportLogs, specifies the completed request to download results for.

Examples

Get-XdrEndpointDeviceActionResult -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad"
Gets the latest action results for the specified device.
Get-XdrEndpointDeviceActionResult -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad" -RequestGuid "1b2010b8-143e-441b-b5e9-c0b56c090a24"
Gets the action result for a specific request on the device.
Get-XdrEndpointDevice -DeviceId $deviceId | Get-XdrEndpointDeviceActionResult
Gets action results for a device using pipeline input.
Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -DeviceId "55a5db7b474470725e0131dec38c07b2f54bf2ad"
Auto-resolves the latest investigation package request and returns its download URI.
Get-XdrEndpointDevice -DeviceId $deviceId | Get-XdrEndpointDeviceActionResult -DownloadSupportLogs
Gets the download URI for the latest support logs collection using pipeline input.
Get-XdrEndpointDeviceActionResult -DownloadInvestigationPackage -RequestGuid "b28b630c-d1a1-4b1d-9676-680c15366a52"
Downloads the investigation package for a specific request to the current working directory.
Get-XdrEndpointDeviceActionResult -DownloadSupportLogs -RequestGuid "abc12345-6789-0123-4567-890abcdef012"
Downloads the support logs for a specific request to the current working directory.

Output

Type: PSCustomObject[]

When listing: Returns an array of action result objects with Type, RequestStatus, Requestor, timestamps, etc.

System.IO.FileInfo When downloading: Returns a FileInfo object for the downloaded file in the current working directory.

View source