How to Replace the KQL Search Command in Microsoft Defender
Question details
The user needs an alternative to the KQL search command in Microsoft Defender Advanced Hunting to resolve query-execution errors.

- Product
- Microsoft Defender
- Device & OS
- not provided
- Scenario
- Running Kusto Query Language (KQL) scripts to search for events across tables.
- Observed behavior
- The KQL search command produces an unexpected query-execution error in Microsoft Defender Advanced Hunting, even though the exact same command works in Microsoft Sentinel.
Identify the specific data tables, such as DeviceNetworkEvents or DeviceFileEvents, that contain the data you intend to search through.
Use the Find Command Instead of Search
Replace the search command with the find command to properly query data across tables in Microsoft Defender Advanced Hunting without triggering execution errors.
While the search command operates as expected in Microsoft Sentinel, Microsoft Defender Advanced Hunting utilizes a different KQL environment that does not support it in the same manner. To achieve similar global search functionality without encountering query-execution errors, you must adapt your script to use the find command instead.
Log in to your Microsoft Defender portal and navigate to the Advanced Hunting query editor.
Locate the script causing the execution error and delete the 'search' keyword from your query.
Insert the 'find' command along with the 'in' clause to specify your target tables. For instance: find in (DeviceNetworkEvents, DeviceFileEvents) where FileName == "example.exe".
Click on the 'Run query' button to execute the updated KQL script and fetch the results successfully.

Analyze Exported Security Logs with WPS Office
While WPS Office does not execute KQL scripts, it is a fantastic, lightweight alternative to Microsoft Office for analyzing exported CSV security logs and generating comprehensive reports. Enjoy full format compatibility without the high subscription fees.
- 1. Export logs from Defender: After running your successful find command, export your query results as a CSV file from Microsoft Defender.
- 2. Open with WPS Spreadsheets: Launch WPS Office and open the exported CSV file directly in WPS Spreadsheets.
- 3. Analyze the data: Use built-in filters, pivot tables, and conditional formatting in WPS Spreadsheets to review and analyze the security events.

Frequently Asked Questions
Why does the search command work in Microsoft Sentinel but fail in Microsoft Defender?
Microsoft Sentinel and Microsoft Defender Advanced Hunting use different variations of the Kusto Query Language (KQL) environment. Defender restricts the global search command to optimize performance across its specific dataset, requiring the use of the find command instead.
Can I search across all tables using the find command in Defender?
Yes, you can search across multiple tables. However, for optimal query performance and to avoid potential timeouts, it is highly recommended to specify the exact tables you are querying using the 'in' clause, such as find in (DeviceFileEvents, DeviceNetworkEvents).
How do I filter by IP address using the KQL find command?
You can filter for a specific IP address by combining the find command with a where clause. For example, you can write: find in (DeviceNetworkEvents) where RemoteIP == '192.168.1.1' (ensure you adjust the column name to match the target table's schema).




