Skip to content

Commit 9380496

Browse files
Merge pull request #5408 from MicrosoftDocs/main
[AutoPublish] main to live - 10/29 13:32 PDT | 10/30 02:02 IST
2 parents 2a44526 + 1a46ee2 commit 9380496

18 files changed

+76
-16
lines changed

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ ms.topic: concept-article
2323
appliesto:
2424
- Microsoft Defender XDR
2525
- Microsoft Sentinel in the Microsoft Defender portal
26-
ms.date: 09/08/2025
26+
ms.date: 10/30/2025
2727
---
2828

2929
# Advanced hunting with Microsoft Sentinel data in Microsoft Defender portal
@@ -88,10 +88,8 @@ In the unified portal, in addition to viewing the schema column names and descri
8888
- The Microsoft Sentinel `SecurityAlert` table is replaced by `AlertInfo` and `AlertEvidence` tables, which both contain all the data on alerts. While SecurityAlert isn't available in the schema tab, you can still use it in queries using the advanced hunting editor. This provision is made so as not to break existing queries from Microsoft Sentinel that use this table.
8989
- Guided hunting mode and take actions capabilities are supported for Defender XDR data only.
9090
- Custom detections have the following limitations:
91-
- Custom detections aren't available for KQL queries that don't include Defender XDR data.
9291
- Near real-time detection frequency isn't available for detections that include Microsoft Sentinel data.
9392
- Custom functions that were created and saved in Microsoft Sentinel aren't supported.
94-
- Defining entities from Sentinel data isn't yet supported in custom detections.
9593
- Bookmarks aren't supported in the advanced hunting experience. They're supported in the **Microsoft Sentinel > Threat management > Hunting** feature. Alternatively, you can use the [Link to incident](advanced-hunting-defender-results.md#link-query-results-to-an-incident) feature to link query results to new or existing incidents.
9694
- If you're streaming Defender XDR tables to Log Analytics, there might be a difference between the`Timestamp` and `TimeGenerated` columns. In case the data arrives to Log Analytics after 48 hours, it's being overridden upon ingestion to `now()`. Therefore, to get the actual time the event happened, we recommend relying on the `Timestamp` column.
9795
- When prompting [Security Copilot](advanced-hunting-security-copilot.md) for advanced hunting queries, you might find that not all Microsoft Sentinel tables are currently supported. However, support for these tables can be expected in the future.

defender-xdr/advanced-hunting-query-results.md

Lines changed: 75 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.custom:
1818
- cx-ti
1919
- cx-ah
2020
ms.topic: how-to
21-
ms.date: 08/04/2025
21+
ms.date: 10/27/2025
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
@@ -32,10 +32,11 @@ appliesto:
3232

3333
While you can construct your [advanced hunting](advanced-hunting-overview.md) queries to return precise information, you can also work with the query results to gain further insight and investigate specific activities and indicators. You can take the following actions on your query results:
3434

35-
- View results as a table or chart
36-
- Export tables and charts
37-
- Drill down to detailed entity information
38-
- Tweak your queries directly from the results
35+
- [View results as a table or chart](#view-query-results-as-a-table-or-chart)
36+
- [Export tables and charts](#export-tables-and-charts)
37+
- [Drill down to detailed entity information](#drill-down-from-query-results)
38+
- [Tweak your queries directly from the results](#tweak-your-queries-from-the-results)
39+
- [View timeline of events](#automatic-timeline-rendering-preview)
3940

4041
## View query results as a table or chart
4142

@@ -109,7 +110,6 @@ The line chart below clearly highlights time periods with more activity involvin
109110

110111
:::image type="content" source="/defender/media/line-chart-a.png" alt-text="The line chart that displays advanced hunting results in the Microsoft Defender portal" lightbox="/defender/media/line-chart-a.png":::
111112

112-
113113
## Export tables and charts
114114

115115
After running a query, select **Export** to save the results to local file. Your chosen view determines how the results are exported:
@@ -135,30 +135,28 @@ This opens a dropdown showing the possible filters you can use further. Select o
135135

136136
:::image type="content" source="/defender/media/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="/defender/media/add-filter4.png":::
137137

138-
Confirm that you have added the filters that you wanted by checking the Filters section.
138+
Confirm that you have added the filters that you wanted by checking the Filters section.
139139

140140
:::image type="content" source="/defender/media/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="/defender/media/add-filter5.png":::
141141

142142
## Drill down from query results
143143

144144
You can also explore the results in-line with the following features:
145+
145146
- Expand a result by selecting the dropdown arrow at the left of each result
146147
- Where applicable, expand details for results that are in JSON and array formats by selecting the dropdown arrow at the left of applicable column names for added readability
147148
- Open the side pane to see a record's details (concurrent with expanded rows)
148149

149-
150-
151150
:::image type="content" source="/defender/media/advanced-hunting-query-results-expand.png" alt-text="Screenshot of expanding results to drill down" lightbox="/defender/media/advanced-hunting-query-results-expand.png":::
152151

153-
You can also right-click on any result value in a row so that you can use it to add more filters to the existing query or copy the value for use in further investigation.
152+
You can also right-click on any result value in a row so that you can use it to add more filters to the existing query or copy the value for use in further investigation.
154153

155154
:::image type="content" source="/defender/media/advanced-hunting-query-results-rightclick.png" alt-text="Screenshot of options upon right-clicking an option" lightbox="/defender/media/advanced-hunting-query-results-rightclick.png":::
156155

157156
Furthermore, for JSON and array fields, you can right-click and update the existing query to include or exclude the field, or to extend the field to a new column.
158157

159158
:::image type="content" source="/defender/media/advanced-hunting-query-results-json-right.png" alt-text="Screenshot of options upon right-clicking an option for JSON and array fields" lightbox="/defender/media/advanced-hunting-query-results-json-right.png":::
160159

161-
162160
To quickly inspect a record in your query results, select the corresponding row to open the **Inspect record** panel. The panel provides the following information based on the selected record:
163161

164162
- **Assets**—Summarized view of the main assets (mailboxes, devices, and users) found in the record, enriched with available information, such as risk and exposure levels
@@ -178,9 +176,8 @@ Select the three dots to the right of any column in the **Inspect record** panel
178176

179177
:::image type="content" source="/defender/media/work-with-query-tweak-query.png" alt-text="Screenshot of the Action Type pane on the Inspect record page in the Microsoft Defender portal." lightbox="/defender/media/work-with-query-tweak-query.png":::
180178

181-
182-
183179
## Add items to Favorites
180+
184181
You can add your frequently used schemas, functions, queries, and detection rules to the Favorites section of each tab in the advanced hunting page for quick access.
185182

186183
:::image type="content" source="media/faves-1.png" alt-text="Screenshot of the advanced hunting page with the Favorites section highlighted." lightbox="media/faves-1.png":::
@@ -198,6 +195,71 @@ You can do the same for your saved functions, queries, and custom detections in
198195
> [!NOTE]
199196
> Some tables in this article might not be available at Microsoft Defender for Endpoint. [Turn on Microsoft Defender XDR](m365d-enable.md) to hunt for threats using more data sources. You can move your advanced hunting workflows from Microsoft Defender for Endpoint to Microsoft Defender XDR by following the steps in [Migrate advanced hunting queries from Microsoft Defender for Endpoint](advanced-hunting-migrate-from-mde.md).
200197
198+
## Automatic timeline rendering (preview)
199+
200+
By default, a timeline appears above the advanced hunting results that displays event counts over time. The timeline is automatically rendered based on the `Timestamp` or `timeGenerated` column in the query results. It automatically updates when you apply filters and can help you quickly identify abnormal behavior and trends and focus on interesting results.
201+
202+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="./media/advanced-hunting-query-results/advanced-hunting-query-results-timeline.png":::
203+
204+
You can select whether or not the timeline is displayed by default in the **Chart preferences** settings.
205+
206+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-chart-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="./media/advanced-hunting-query-results/advanced-hunting-chart-preferences.png":::
207+
208+
The timeline automatically adjusts its resolution based on the range of results.
209+
210+
### Filter the timeline results
211+
212+
Select any point on the timeline to filter both the results and the timeline to that specific time range. The timeline also updates its scale to match the selected time period, so when you filter by a specific range, it zooms in to show event distribution in high resolution.
213+
214+
#### [Unfiltered timeline](#tab/unfiltered)
215+
216+
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is unfiltered, so it displays the full range of results with a timestamp for each day. Select a day or range of days to filter the results for that time period.
217+
218+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-unfiltered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with all the results unfiltered." lightbox="./media/advanced-hunting-query-results/advanced-hunting-unfiltered-results.png":::
219+
220+
#### [Filtered timeline](#tab/filtered)
221+
222+
The following screenshot shows the zoomed in results of a query filtered to a specific date.
223+
224+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-filtered-results.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results filtered to a specific date." lightbox="./media/advanced-hunting-query-results/advanced-hunting-filtered-results.png":::
225+
226+
---
227+
228+
### Split the timeline by values
229+
230+
You can split the results in the timeline by any column that has at least two but less than 50 unique values.
231+
232+
#### [Ungrouped timeline](#tab/ungrouped)
233+
234+
The following screenshot shows the results of a query that returns 1,000 email events. The timeline is ungrouped, so it displays all the results in a single line.
235+
236+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-ungrouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results all together in one line." lightbox="./media/advanced-hunting-query-results/advanced-hunting-ungrouped.png":::
237+
238+
#### [Grouped timeline](#tab/grouped)
239+
240+
The following screenshot shows the results grouped by last email action with a separate line for each action.
241+
242+
:::image type="content" source="./media/advanced-hunting-query-results/advanced-hunting-grouped.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results grouped by last email action." lightbox="./media/advanced-hunting-query-results/advanced-hunting-grouped.png":::
243+
244+
---
245+
246+
### Change chart type
247+
248+
You can change the chart type of the timeline by selecting a different option from the chart type dropdown menu. The available chart types include:
249+
250+
- Line chart
251+
- Column chart
252+
- Pie chart
253+
254+
:::image type="content" source="/defender/media/advanced-hunting-column-chart.png" alt-text="Screenshot of an advanced hunting query of 1,000 email events with the results displayed in a column chart." lightbox="/defender/media/advanced-hunting-column-chart.png":::
255+
256+
### Rendering conditions
257+
258+
The timeline only appears if the following conditions are met:
259+
260+
- There are more than 40 events in your results.
261+
- There's `Timestamp` or `timeGenerated` column.
262+
201263
## Related topics
202264

203265
- [Advanced hunting overview](advanced-hunting-overview.md)

defender-xdr/image-1.png

-215 KB
Binary file not shown.

defender-xdr/image.png

-215 KB
Binary file not shown.
97 KB
Loading
76.2 KB
Loading
101 KB
Loading
44.5 KB
Loading
98.5 KB
Loading
184 KB
Loading

0 commit comments

Comments
 (0)