POWERSHELL COMMAND
Invoke-XdrAzureDataExplorerQuery
Executes a KQL query or management command against an Azure Data Explorer cluster.
Runs a Kusto Query Language (KQL) query or management command against the configured Azure Data Explorer cluster and returns the results as PowerShell objects.
Regular KQL queries are sent to the v2/rest/query endpoint. Management commands (queries starting with ‘.’) are sent to the v1/rest/mgmt endpoint.
Connection settings must be configured first using Set-XdrAzureDataExplorerConnection.
Syntax
Invoke-XdrAzureDataExplorerQuery [-Query] <string> [[-Database] <string>] [[-ServerTimeout] <timespan>] [[-RequestTimeout] <int>] [-Raw] [<CommonParameters>]
Parameters
-Query
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | Not documented |
The KQL query or management command to execute.
-Database
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | Not documented |
Optional database name to override the database from connection settings.
-ServerTimeout
| Property | Value |
|---|---|
| Type | TimeSpan |
| Required | No |
| Position | 3 |
| Pipeline input | No |
| Default | [timespan]::FromMinutes(4) |
Server-side query timeout as a TimeSpan. Default is 4 minutes.
-RequestTimeout
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | 4 |
| Pipeline input | No |
| Default | 300 |
Client-side HTTP timeout in seconds. Default is 300 seconds. Currently only server-side timeout is enforced via the request body.
-Raw
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Return the raw API response instead of converting to PSCustomObject output.
Examples
Invoke-XdrAzureDataExplorerQuery -Query 'XDRAlerts | take 10'
Runs a KQL query and returns the first 10 alerts as objects.
Invoke-XdrAzureDataExplorerQuery -Query '.show tables'
Runs a management command to list all tables.
Invoke-XdrAzureDataExplorerQuery -Query 'StormEvents | count' -Database 'Samples' -ServerTimeout ([timespan]::FromMinutes(10))
Runs a query against a specific database with a custom server timeout.
Output
Type: System.Management.Automation.PSObject[]