Forum Discussion

VaibhavBhosle's avatar
VaibhavBhosle
New Member
1 year ago
Solved

KQL embedded in Power Query to query Defender Log through Advanced Hunting

let
AdvancedHuntingQuery = "
DeviceTvmSoftwareVulnerabilitiesKB
| where VulnerabilitySeverityLevel == "High"
",
HuntingUrl = "https://api.securitycenter.microsoft.cxxxxxxxxxxxxxxxx",
Response = Json.Document(Web.Contents(HuntingUrl, [Query=[key=AdvancedHuntingQuery]])),
TypeMap = #table(
{ "Type", "PowerBiType" },
{
{ "Double", Double.Type },
{ "Int64", Int64.Type },
{ "Int32", Int32.Type },
{ "Int16", Int16.Type },
{ "UInt64", Number.Type },
{ "UInt32", Number.Type },
{ "UInt16", Number.Type },
{ "Byte", Byte.Type },
{ "Single", Single.Type },
{ "Decimal", Decimal.Type },
{ "TimeSpan", Duration.Type },
{ "DateTime", DateTimeZone.Type },
{ "String", Text.Type },
{ "Boolean", Logical.Type },
{ "SByte", Logical.Type },
{ "Guid", Text.Type }
}),
Schema = Table.FromRecords(Response[Schema]),
Results = Response[Results],
Rows = Table.FromRecords(Results, Schema[Name])
in
Rows

2 Replies