Skip to content

Latest commit

 

History

History
64 lines (47 loc) · 2.23 KB

advanced-hunting-query-builder-results.md

File metadata and controls

64 lines (47 loc) · 2.23 KB
title description search.appverid ms.service ms.subservice f1.keywords ms.author author ms.localizationpriority manager audience ms.collection ms.custom ms.topic ms.date
Work with query results in guided mode for hunting in Microsoft Defender XDR
Use and customize query results in guided mode for advanced hunting in Microsoft Defender XDR
met150
defender-xdr
adv-hunting
NOCSH
maccruz
schmurky
medium
dansimp
ITPro
m365-security
tier2
cx-ti
cx-ah
how-to
04/22/2024

Work with query results in guided mode

[!INCLUDE Microsoft Defender XDR rebranding]

Applies to:

  • Microsoft Defender XDR

Important

Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.

In hunting using guided mode, the results of the query appear in the Results tab.

Screenshot of results tab

You can work on the results further by exporting them to a CSV file by selecting Export. This downloads the CSV file for your use.

You can view other information in the Results view:

  • Number of records in the results list (beside the Search button)
  • Duration of the query run time
  • Resource usage of the query

View more columns

A few standard columns are included in the results for easy viewing.

To view more columns:

  1. Select Customize columns in the upper right-hand portion of the results view.

  2. From here, select the columns to include in the results view and deselect columns to hide.

    Screenshot of list of columns you can add to the results view

  3. Select Apply to view results with the added columns. Use the scroll bars if necessary.

See also