Run a query against the Sophos Data Lake, passing the SQL code as the value of a field in the request JSON. The schema reference is available here (
New-SophosXdrQueriesDataLakeRun [-Token] <String> [-TenantId] <String> [-ApiHost] <String> [-Query] <String>
[-StartDate] <DateTime> [-EndDate] <DateTime> [-ProgressAction <ActionPreference>] [-WhatIf] [-Confirm]
Run a query against the Sophos Data Lake, passing the SQL code as the value of a field in the request JSON. The schema reference is available here (
$token = Get-SophosAccessToken -ClientID "xxxxxxxxxxxxxxxx" -ClientS "xxxxxxxxxxxxxxxxx"
PS>$partnerId = Get-SophosPartnerId -Token $token
PS>$tenant = Get-SophosPartnerTenants -PartnerId $partnerId.PartnerId -Token $token | Where-Object {$_.Name -eq 'MyTenant'}
ps>$query = 'select * from \"xdr_data\" limit 10'
PS>New-SophosXdrQueriesDataLakeRun -Token $token -TenantId $ -ApiHost $tenant.apiHost -Query $query -StartDate $(Get-Date).Adddays(-30) -EndDate $(Get-Date).Adddays(-1)
JWT token from oauth API
Type: String
Parameter Sets: (All)
Required: True
Position: 1
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
Tenant ID
Type: String
Parameter Sets: (All)
Required: True
Position: 2
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
API host location URL of the tenant
Type: String
Parameter Sets: (All)
Required: True
Position: 3
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
ADHoc Query
Type: String
Parameter Sets: (All)
Required: True
Position: 4
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
Start lookup date
Type: DateTime
Parameter Sets: (All)
Required: True
Position: 5
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
End lookup date
Type: DateTime
Parameter Sets: (All)
Required: True
Position: 6
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
Shows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
Prompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
{{ Fill ProgressAction Description }}
Type: ActionPreference
Parameter Sets: (All)
Aliases: proga
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False
This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.