← All XDRInternals commands

POWERSHELL COMMAND

Invoke-XdrAzureDataExplorerQuery

Executes a KQL query or management command against an Azure Data Explorer cluster.

View source ↗

Runs a Kusto Query Language (KQL) query or management command against the configured Azure Data Explorer cluster and returns the results as PowerShell objects.

Regular KQL queries are sent to the v2/rest/query endpoint. Management commands (queries starting with ‘.’) are sent to the v1/rest/mgmt endpoint.

Connection settings must be configured first using Set-XdrAzureDataExplorerConnection.

Syntax

Invoke-XdrAzureDataExplorerQuery [-Query] <string> [[-Database] <string>] [[-ServerTimeout] <timespan>] [[-RequestTimeout] <int>] [-Raw] [<CommonParameters>]

Parameters

-Query

Property Value
Type String
Required Yes
Position 1
Pipeline input No
Default Not documented

The KQL query or management command to execute.

-Database

Property Value
Type String
Required No
Position 2
Pipeline input No
Default Not documented

Optional database name to override the database from connection settings.

-ServerTimeout

Property Value
Type TimeSpan
Required No
Position 3
Pipeline input No
Default [timespan]::FromMinutes(4)

Server-side query timeout as a TimeSpan. Default is 4 minutes.

-RequestTimeout

Property Value
Type Int32
Required No
Position 4
Pipeline input No
Default 300

Client-side HTTP timeout in seconds. Default is 300 seconds. Currently only server-side timeout is enforced via the request body.

-Raw

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Return the raw API response instead of converting to PSCustomObject output.

Examples

Invoke-XdrAzureDataExplorerQuery -Query 'XDRAlerts | take 10'

Runs a KQL query and returns the first 10 alerts as objects.

Invoke-XdrAzureDataExplorerQuery -Query '.show tables'

Runs a management command to list all tables.

Invoke-XdrAzureDataExplorerQuery -Query 'StormEvents | count' -Database 'Samples' -ServerTimeout ([timespan]::FromMinutes(10))

Runs a query against a specific database with a custom server timeout.

Output

Type: System.Management.Automation.PSObject[]

View source