Microsoft Defender XDR
Hunting and detection

Advanced Hunting Query History

In brief

The Query history section was reworded for clarity, with an updated date and new section anchor. It continues to describe rerunning past queries, retaining up to 30 queries from the last 28 days, and using or editing queries.

What Defender admins need to know

No administrator action is indicated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Query history overview

Your previous queries appear in the Query history tab in the lower half of the advanced hunting page. You can rerun past queries even after closing the tab where they ran.

View the query history tab

:::image type="content" source="media/advanced-hunting-query-history/advanced-hunting-query-history.png" alt-text="Screenshot of the query history pane in advanced hunting" lightbox="media/advanced-hunting-query-history/advanced-hunting-query-history.png":::

Recent queries appear with the newest first. The list keeps up to 30 queries from the last 28 days.

By default, Query history shows these columns:

  • Time - when the query started
  • Query time - how long the query took
  • State - whether the query finished, failed, or was throttled

To hide columns, select Customize columns.

:::image type="content" source="media/advanced-hunting-query-history/advanced-hunting-query-history-functions.png" alt-text="Screenshot of the query history functions in advanced hunting" lightbox="media/advanced-hunting-query-history/advanced-hunting-query-history-functions.png":::

Select Run query to run it right away, or select Use in editor to edit it first.