POWERSHELL COMMAND
Set-XdrAdvancedHuntingFunction
Updates an existing Advanced Hunting function in Microsoft Defender XDR.
Updates a saved function for Advanced Hunting queries in Microsoft Defender XDR. The function must exist before it can be updated. The cmdlet will verify the function exists before attempting the update.
Syntax
Set-XdrAdvancedHuntingFunction -Id <int> [-Name <string>] [-KQLQuery <string>] [-Description <string>] [-IsShared] [-FolderPath <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Set-XdrAdvancedHuntingFunction -InputObject <Object> [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-Id
| Property | Value |
|---|---|
| Type | Int32 |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | 0 |
The ID of the function to update. This is mandatory to ensure the correct function is updated.
-Name
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The new name of the function. If not specified, the existing name is preserved.
-KQLQuery
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The new KQL (Kusto Query Language) body of the function. If not specified, the existing query is preserved.
-Description
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The new description of the function. If not specified, the existing description is preserved.
-IsShared
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Switch to make the function shared with the organization. If not specified, the existing sharing status is preserved.
-FolderPath
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The new folder path for organizing the function. Use forward slashes (/) or backslashes () - they will be automatically converted to double backslashes. If not specified, the existing path is preserved.
-InputObject
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
PSObject containing the function to update. The object must include an Id property. Typically obtained from Get-XdrAdvancedHuntingFunction.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The function is not created.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts you for confirmation before running the cmdlet.
Examples
Set-XdrAdvancedHuntingFunction -Id 6 -Name "UpdatedFunctionName"
Updates the name of function with ID 6.
Set-XdrAdvancedHuntingFunction -Id 6 -KQLQuery $newQuery -Description "Updated description"
Updates the query and description of a function.
$function = Get-XdrAdvancedHuntingFunction -Id 6
$function.IsShared = $false
Set-XdrAdvancedHuntingFunction -InputObject $function
Gets a function, modifies it, and updates it.
Set-XdrAdvancedHuntingFunction -Id 6 -IsShared -FolderPath "NewFolder/SubFolder"
Makes a function shared and moves it to a new folder path.
Output
Type: Object
Returns the updated function object from the API.