Skip to content

Commit b59063b

Browse files
committed
new timeline feature
1 parent b4cb159 commit b59063b

File tree

4 files changed

+14
-2
lines changed

4 files changed

+14
-2
lines changed

defender-xdr/advanced-hunting-query-results.md

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.custom:
1818
- cx-ti
1919
- cx-ah
2020
ms.topic: how-to
21-
ms.date: 08/04/2025
21+
ms.date: 08/13/2025
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
@@ -37,6 +37,17 @@ While you can construct your [advanced hunting](advanced-hunting-overview.md) qu
3737
- Drill down to detailed entity information
3838
- Tweak your queries directly from the results
3939

40+
41+
## Automatic timeline rendering
42+
43+
By default, a timeline appears above the advanced hunting results that displays event counts over time. The timeline is automatically rendered based on the `Timestamp` column in the query results. It automatically updates when you apply filters and can help you quickly identify abnormal behavior and trends and focus on interesting results.
44+
45+
::::image type="content" source="/defender/media/advanced-hunting-query-results-timeline.png" alt-text="Screenshot of the timeline above the query results in advanced hunting." lightbox="/defender/media/advanced-hunting-query-results-timeline.png":::
46+
47+
You can select whether or not the timeline is displayed by default in the **Page preferences** settings.
48+
49+
::::image type="content" source="/defender/media/advanced-hunting-page-preferences.png" alt-text="Screenshot of the Page preferences settings in advanced hunting." lightbox="/defender/media/advanced-hunting-page-preferences.png":::
50+
4051
## View query results as a table or chart
4152

4253
By default, advanced hunting displays query results as tabular data. You can also display the same data as a chart. Advanced hunting supports the following views:
@@ -135,13 +146,14 @@ This opens a dropdown showing the possible filters you can use further. Select o
135146

136147
:::image type="content" source="/defender/media/add-filter4.png" alt-text="Screenshot of new filter's dropdown in advanced hunting." lightbox="/defender/media/add-filter4.png":::
137148

138-
Confirm that you have added the filters that you wanted by checking the Filters section.
149+
Confirm that you have added the filters that you wanted by checking the Filters section.
139150

140151
:::image type="content" source="/defender/media/add-filter5.png" alt-text="Screenshot of filters added advanced hunting." lightbox="/defender/media/add-filter5.png":::
141152

142153
## Drill down from query results
143154

144155
You can also explore the results in-line with the following features:
156+
145157
- Expand a result by selecting the dropdown arrow at the left of each result
146158
- Where applicable, expand details for results that are in JSON and array formats by selecting the dropdown arrow at the left of applicable column names for added readability
147159
- Open the side pane to see a record's details (concurrent with expanded rows)

defender-xdr/image-1.png

-215 KB
Binary file not shown.

defender-xdr/image.png

-215 KB
Binary file not shown.
164 KB
Loading

0 commit comments

Comments
 (0)