← All XDRInternals commands

POWERSHELL COMMAND

Set-XdrAdvancedHuntingFunction

Updates an existing Advanced Hunting function in Microsoft Defender XDR.

View source ↗

Updates a saved function for Advanced Hunting queries in Microsoft Defender XDR. The function must exist before it can be updated. The cmdlet will verify the function exists before attempting the update.

Syntax

Set-XdrAdvancedHuntingFunction -Id <int> [-Name <string>] [-KQLQuery <string>] [-Description <string>] [-IsShared] [-FolderPath <string>] [-WhatIf] [-Confirm] [<CommonParameters>]

Set-XdrAdvancedHuntingFunction -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-Id

Property Value
Type Int32
Required Yes
Position named
Pipeline input No
Default 0

The ID of the function to update. This is mandatory to ensure the correct function is updated.

-Name

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The new name of the function. If not specified, the existing name is preserved.

-KQLQuery

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The new KQL (Kusto Query Language) body of the function. If not specified, the existing query is preserved.

-Description

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The new description of the function. If not specified, the existing description is preserved.

-IsShared

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Switch to make the function shared with the organization. If not specified, the existing sharing status is preserved.

-FolderPath

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

The new folder path for organizing the function. Use forward slashes (/) or backslashes () - they will be automatically converted to double backslashes. If not specified, the existing path is preserved.

-InputObject

Property Value
Type Object
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

PSObject containing the function to update. The object must include an Id property. Typically obtained from Get-XdrAdvancedHuntingFunction.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The function is not created.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts you for confirmation before running the cmdlet.

Examples

Set-XdrAdvancedHuntingFunction -Id 6 -Name "UpdatedFunctionName"
Updates the name of function with ID 6.
Set-XdrAdvancedHuntingFunction -Id 6 -KQLQuery $newQuery -Description "Updated description"
Updates the query and description of a function.
$function = Get-XdrAdvancedHuntingFunction -Id 6
$function.IsShared = $false
Set-XdrAdvancedHuntingFunction -InputObject $function
Gets a function, modifies it, and updates it.
Set-XdrAdvancedHuntingFunction -Id 6 -IsShared -FolderPath "NewFolder/SubFolder"
Makes a function shared and moves it to a new folder path.

Output

Type: Object

Returns the updated function object from the API.

View source