← All XDRInternals commands

POWERSHELL COMMAND

Set-XdrAzureDataExplorerConnection

Configures Azure Data Explorer connection settings for export cmdlets.

View source ↗

Stores the Azure Data Explorer cluster, ingestion endpoint, database, and auth settings used by Export-XdrAzureDataExplorer and Get-XdrAzureDataExplorerIngestionStatus.

When ClusterUri and Database are omitted, the cmdlet auto-discovers accessible clusters, prompts you to choose a cluster when multiple matches exist, and then prompts you to choose a database when the selected cluster has more than one available database.

If IngestionUri is omitted, the cmdlet derives it from the cluster URI by using the standard ingest-<cluster> hostname convention.

Syntax

Set-XdrAzureDataExplorerConnection [-SubscriptionId <string[]>] [-ClusterName <string>] [-DatabaseName <string>] [-TenantId <string>] [-ManagedIdentityClientId <string>] [-RequestTimeout <int>] [-NonInteractive] [-AllowPartialDiscovery] [-WhatIf] [-Confirm] [<CommonParameters>]

Set-XdrAzureDataExplorerConnection -ClusterUri <uri> -Database <string> [-IngestionUri <uri>] [-TenantId <string>] [-ManagedIdentityClientId <string>] [-AccessToken <string>] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-ClusterUri

Property Value
Type Uri
Required Yes
Position named
Pipeline input No
Default Not documented

The Azure Data Explorer cluster URI. You can supply either the engine endpoint or the ingestion endpoint. If omitted, the cmdlet discovers accessible clusters and prompts for a selection when needed.

-Database

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The database name to target for table bootstrap and queued ingestion.

-SubscriptionId

Property Value
Type String[]
Required No
Position named
Pipeline input No
Default Not documented

Optional subscription IDs used to narrow cluster discovery when ClusterUri is omitted.

-ClusterName

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional cluster name filter used during discovery when ClusterUri is omitted. Wildcards are supported.

-DatabaseName

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional database name filter used during discovery when ClusterUri is omitted. Wildcards are supported.

-IngestionUri

Property Value
Type Uri
Required No
Position named
Pipeline input No
Default Not documented

Optional explicit data ingestion URI. If omitted, it is derived from ClusterUri.

-TenantId

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional tenant ID used when obtaining a token through Az.Accounts or Azure CLI.

-ManagedIdentityClientId

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional user-assigned managed identity client ID for IMDS token acquisition.

-AccessToken

Property Value
Type String
Required No
Position named
Pipeline input No
Default Not documented

Optional Azure Data Explorer access token to use directly instead of acquiring a token dynamically. This applies only when ClusterUri and Database are supplied explicitly.

-RequestTimeout

Property Value
Type Int32
Required No
Position named
Pipeline input No
Default 60

Optional HTTP timeout for discovery requests when ClusterUri is omitted. Default is 60 seconds.

-NonInteractive

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Prevents interactive cluster or database prompts during discovery. If discovery is ambiguous, the cmdlet throws and asks you to narrow the match or specify the connection explicitly.

-AllowPartialDiscovery

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Allows automatic connection selection when one or more discovery providers or database enumeration requests failed. By default, discovery fails closed rather than selecting from an incomplete result set.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs without updating the module’s Azure Data Explorer connection settings.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before updating the module’s Azure Data Explorer connection settings.

Examples

Set-XdrAzureDataExplorerConnection -ClusterUri "https://mycluster.westeurope.kusto.windows.net" -Database "Investigations"

Configures the connection and derives the ingestion endpoint automatically.

Set-XdrAzureDataExplorerConnection

Discovers accessible clusters, prompts for a cluster if more than one is available, and prompts for a database if the chosen cluster has more than one database.

Set-XdrAzureDataExplorerConnection -ClusterName 'nm-test-cluster' -DatabaseName 'Investigations' -NonInteractive

Discovers a single matching cluster and database without prompting. If multiple matches remain, the cmdlet throws instead of waiting for user input.

$token = az account get-access-token --resource https://api.kusto.windows.net --query accessToken -o tsv
Set-XdrAzureDataExplorerConnection -ClusterUri "https://mycluster.westeurope.kusto.windows.net" -Database "Investigations" -AccessToken $token

Configures the connection with an explicit bearer token.

View source