Microsoft Defender XDR
Hunting and detection

Work with query results in guided mode for hunting in Microsoft Defender XDR

In brief

The article now covers reviewing, exporting, and customizing query results, including runtime and resource usage information and the Customize columns pane.

What Defender admins need to know

Administrators can use the clearer guidance when working with guided-mode query results. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

This article explains how to view and work with query results in guided mode for advanced hunting, including exporting results, reviewing runtime and resource usage information, and customizing which columns appear.

In hunting using guided mode, the results of the query appear in the Results tab.

Screenshot of the Results tab showing query output in guided mode for advanced hunting

You can work on the results further by exporting them to a CSV file. Selecting Export downloads the CSV file for your use.

You can view other information in the Results view:

To view more columns:

  1. Select Customize columns in the upper right-hand portion of the results view.

  2. In the Customize columns pane, select the columns to include in the results view and clear the columns to hide.

    Screenshot of the Customize columns picker showing available columns to control which fields appear in query results

  3. Select Apply to view results with the added columns. Use the scroll bars if necessary.

Related content