Skip to content

Commit 425b296

Browse files
authored
Add example query for PnPDeviceConnected action
1 parent d36ea16 commit 425b296

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

defender-endpoint/device-control-walkthroughs.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -37,6 +37,7 @@ By default, [device control](device-control-overview.md) is disabled and there a
3737
Device control in Defender for Endpoint identifies a device based on its properties. Device properties are visible by selecting an entry in the report.
3838

3939
The **Device ID**, **Vendor ID** (VID), **Serial number**, and **Bus type** can all be used to identify a device (see [Device control policies in Microsoft Defender for Endpoint](device-control-policies.md)). Data is also available in [Advanced Hunting](/defender-xdr/advanced-hunting-overview), by searching for the Plug and Play Device Connected action (`PnPDeviceConnected`), as shown in the following example query:
40+
4041
```kusto
4142
4243
DeviceEvents

0 commit comments

Comments
 (0)