<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft 365 defender advance hunting query in Cortex XSOAR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541478#M2110</link>
    <description>&lt;P&gt;Ass!uming you're running this manually, try using the back ticks on the query argument instead of quotes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!microsoft-365-defender-advanced-hunting query=`AlertInfo | where alert...`&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, you can add the argument debug-mode=true to have it throw the debug of the request and see the body that is being sent etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 08 May 2023 19:30:07 GMT</pubDate>
    <dc:creator>MBeauchamp2</dc:creator>
    <dc:date>2023-05-08T19:30:07Z</dc:date>
    <item>
      <title>Microsoft 365 defender advance hunting query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541462#M2107</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm trying to build an advance hunting query in Microsoft 365 defender integration, but still giving me error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;!microsoft-365-defender-advanced-hunting limit=10 query="""AlertInfo | where alertId = fa85caf1c0-b9b9-bc29-f600-08db44a419b9"""&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Reason
Failed to execute microsoft-365-defender-advanced-hunting command.
Error:
Error in API call [400] - Bad Request
{"error": {"code": "BadRequest", "message": "Scalar is not expected in the current context. Fix semantic errors in your query.", "target": "|2528f983-4c3b7ab3bc866db1."}}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you help pls&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 17:32:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541462#M2107</guid>
      <dc:creator>FabioFerreira</dc:creator>
      <dc:date>2023-05-08T17:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft 365 defender advance hunting query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541478#M2110</link>
      <description>&lt;P&gt;Ass!uming you're running this manually, try using the back ticks on the query argument instead of quotes:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!microsoft-365-defender-advanced-hunting query=`AlertInfo | where alert...`&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Alternatively, you can add the argument debug-mode=true to have it throw the debug of the request and see the body that is being sent etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 19:30:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541478#M2110</guid>
      <dc:creator>MBeauchamp2</dc:creator>
      <dc:date>2023-05-08T19:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft 365 defender advance hunting query</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541487#M2111</link>
      <description>&lt;P&gt;Got it.&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;!microsoft-365-defender-advanced-hunting limit=5 query=`AlertInfo |  where AlertId == 'fa85caf1c0-b9b9-bc29-0000-08db40c26d06'`&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps someone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 21:26:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/microsoft-365-defender-advance-hunting-query/m-p/541487#M2111</guid>
      <dc:creator>FabioFerreira</dc:creator>
      <dc:date>2023-05-08T21:26:25Z</dc:date>
    </item>
  </channel>
</rss>

