logo
search
Others

How to Replace the KQL Search Command in Microsoft Defender

Maira MehtabMaira Mehtab Sep 25, 2026 870 views

Question details

The user needs an alternative to the KQL search command in Microsoft Defender Advanced Hunting to resolve query-execution errors.

How to Replace the KQL Search Command in Microsoft Defender Advanced Hunting
Product
Microsoft Defender
Device & OS
not provided
Scenario
Running Kusto Query Language (KQL) scripts to search for events across tables.
Observed behavior
The KQL search command produces an unexpected query-execution error in Microsoft Defender Advanced Hunting, even though the exact same command works in Microsoft Sentinel.
Before you start

Identify the specific data tables, such as DeviceNetworkEvents or DeviceFileEvents, that contain the data you intend to search through.

Solution 1Recommended

Use the Find Command Instead of Search

Replace the search command with the find command to properly query data across tables in Microsoft Defender Advanced Hunting without triggering execution errors.

While the search command operates as expected in Microsoft Sentinel, Microsoft Defender Advanced Hunting utilizes a different KQL environment that does not support it in the same manner. To achieve similar global search functionality without encountering query-execution errors, you must adapt your script to use the find command instead.

1
Open Advanced Hunting

Log in to your Microsoft Defender portal and navigate to the Advanced Hunting query editor.

2
Remove the search command

Locate the script causing the execution error and delete the 'search' keyword from your query.

3
Apply the find command

Insert the 'find' command along with the 'in' clause to specify your target tables. For instance: find in (DeviceNetworkEvents, DeviceFileEvents) where FileName == "example.exe".

4
Execute the query

Click on the 'Run query' button to execute the updated KQL script and fetch the results successfully.

Use the Find Command Instead of Search
Targeted Searches: Explicitly stating the tables inside the parentheses with the 'in' clause significantly speeds up query execution and helps prevent query timeouts.
Free Microsoft Office alternative

Analyze Exported Security Logs with WPS Office

While WPS Office does not execute KQL scripts, it is a fantastic, lightweight alternative to Microsoft Office for analyzing exported CSV security logs and generating comprehensive reports. Enjoy full format compatibility without the high subscription fees.

  1. 1. Export logs from Defender: After running your successful find command, export your query results as a CSV file from Microsoft Defender.
  2. 2. Open with WPS Spreadsheets: Launch WPS Office and open the exported CSV file directly in WPS Spreadsheets.
  3. 3. Analyze the data: Use built-in filters, pivot tables, and conditional formatting in WPS Spreadsheets to review and analyze the security events.
Fully compatible with Microsoft Excel (.xlsx and .csv) formats for detailed log analysis.Lightweight and fast, utilizing minimal system resources while working with large datasets.Free to use with a familiar, easy-to-navigate tabbed interface.Built-in PDF tools to easily export professional security reports for your team.
microsoft office alternative - wps office

Frequently Asked Questions

Why does the search command work in Microsoft Sentinel but fail in Microsoft Defender?

Microsoft Sentinel and Microsoft Defender Advanced Hunting use different variations of the Kusto Query Language (KQL) environment. Defender restricts the global search command to optimize performance across its specific dataset, requiring the use of the find command instead.

Can I search across all tables using the find command in Defender?

Yes, you can search across multiple tables. However, for optimal query performance and to avoid potential timeouts, it is highly recommended to specify the exact tables you are querying using the 'in' clause, such as find in (DeviceFileEvents, DeviceNetworkEvents).

How do I filter by IP address using the KQL find command?

You can filter for a specific IP address by combining the find command with a where clause. For example, you can write: find in (DeviceNetworkEvents) where RemoteIP == '192.168.1.1' (ensure you adjust the column name to match the target table's schema).