POWERSHELL COMMAND
Set-XdrAzureDataExplorerConnection
Configures Azure Data Explorer connection settings for export cmdlets.
Stores the Azure Data Explorer cluster, ingestion endpoint, database, and auth settings used by Export-XdrAzureDataExplorer and Get-XdrAzureDataExplorerIngestionStatus.
When ClusterUri and Database are omitted, the cmdlet auto-discovers accessible clusters, prompts you to choose a cluster when multiple matches exist, and then prompts you to choose a database when the selected cluster has more than one available database.
If IngestionUri is omitted, the cmdlet derives it from the cluster URI by using the
standard ingest-<cluster> hostname convention.
Syntax
Set-XdrAzureDataExplorerConnection [-SubscriptionId <string[]>] [-ClusterName <string>] [-DatabaseName <string>] [-TenantId <string>] [-ManagedIdentityClientId <string>] [-RequestTimeout <int>] [-NonInteractive] [-AllowPartialDiscovery] [-WhatIf] [-Confirm] [<CommonParameters>]
Set-XdrAzureDataExplorerConnection -ClusterUri <uri> -Database <string> [-IngestionUri <uri>] [-TenantId <string>] [-ManagedIdentityClientId <string>] [-AccessToken <string>] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-ClusterUri
| Property | Value |
|---|---|
| Type | Uri |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The Azure Data Explorer cluster URI. You can supply either the engine endpoint or the ingestion endpoint. If omitted, the cmdlet discovers accessible clusters and prompts for a selection when needed.
-Database
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The database name to target for table bootstrap and queued ingestion.
-SubscriptionId
| Property | Value |
|---|---|
| Type | String[] |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional subscription IDs used to narrow cluster discovery when ClusterUri is omitted.
-ClusterName
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional cluster name filter used during discovery when ClusterUri is omitted. Wildcards are supported.
-DatabaseName
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional database name filter used during discovery when ClusterUri is omitted. Wildcards are supported.
-IngestionUri
| Property | Value |
|---|---|
| Type | Uri |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional explicit data ingestion URI. If omitted, it is derived from ClusterUri.
-TenantId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional tenant ID used when obtaining a token through Az.Accounts or Azure CLI.
-ManagedIdentityClientId
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional user-assigned managed identity client ID for IMDS token acquisition.
-AccessToken
| Property | Value |
|---|---|
| Type | String |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Optional Azure Data Explorer access token to use directly instead of acquiring a token dynamically. This applies only when ClusterUri and Database are supplied explicitly.
-RequestTimeout
| Property | Value |
|---|---|
| Type | Int32 |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | 60 |
Optional HTTP timeout for discovery requests when ClusterUri is omitted. Default is 60 seconds.
-NonInteractive
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Prevents interactive cluster or database prompts during discovery. If discovery is ambiguous, the cmdlet throws and asks you to narrow the match or specify the connection explicitly.
-AllowPartialDiscovery
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Allows automatic connection selection when one or more discovery providers or database enumeration requests failed. By default, discovery fails closed rather than selecting from an incomplete result set.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs without updating the module’s Azure Data Explorer connection settings.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before updating the module’s Azure Data Explorer connection settings.
Examples
Set-XdrAzureDataExplorerConnection -ClusterUri "https://mycluster.westeurope.kusto.windows.net" -Database "Investigations"
Configures the connection and derives the ingestion endpoint automatically.
Set-XdrAzureDataExplorerConnection
Discovers accessible clusters, prompts for a cluster if more than one is available, and prompts for a database if the chosen cluster has more than one database.
Set-XdrAzureDataExplorerConnection -ClusterName 'nm-test-cluster' -DatabaseName 'Investigations' -NonInteractive
Discovers a single matching cluster and database without prompting. If multiple matches remain, the cmdlet throws instead of waiting for user input.
$token = az account get-access-token --resource https://api.kusto.windows.net --query accessToken -o tsv
Set-XdrAzureDataExplorerConnection -ClusterUri "https://mycluster.westeurope.kusto.windows.net" -Database "Investigations" -AccessToken $token
Configures the connection with an explicit bearer token.