POWERSHELL COMMAND
Remove-XdrAdvancedHuntingFunction
Removes an Advanced Hunting function from Microsoft Defender XDR.
Deletes a saved function for Advanced Hunting queries in Microsoft Defender XDR. The function must exist before it can be removed. The cmdlet will verify the function exists before attempting deletion.
Syntax
Remove-XdrAdvancedHuntingFunction [-Id] <int> [-WhatIf] [-Confirm] [<CommonParameters>]
Remove-XdrAdvancedHuntingFunction -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-Id
| Property | Value |
|---|---|
| Type | Int32 |
| Required | Yes |
| Position | 1 |
| Pipeline input | No |
| Default | 0 |
The ID of the function to remove. This is mandatory to ensure the correct function is deleted.
-InputObject
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
PSObject containing the function to remove. The object must include an Id property. Typically obtained from Get-XdrAdvancedHuntingFunction.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The function is not created.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
Remove-XdrAdvancedHuntingFunction -Id 6
Removes the function with ID 6.
Get-XdrAdvancedHuntingFunction -Id 6 | Remove-XdrAdvancedHuntingFunction
Gets a function and removes it through the pipeline.
Get-XdrAdvancedHuntingFunction | Where-Object { $_.Name -eq "OldFunction" } | Remove-XdrAdvancedHuntingFunction
Finds a function by name and removes it.
Output
Type: None
This cmdlet does not return any output upon successful deletion.