Error when using Advanced Hunting

DG001 346 Reputation points Microsoft Employee
2024-04-23T20:11:31.1466667+00:00

Hello,

I have a customer that is getting the error below when using advanced hunting and is unable to search 'EmailEvents' and would like some insight on it?

 

Issue:

When using the Advanced Hunting option, the object 'EmailEvents' returns:

"Syntax error Error message The incomplete fragment is unexpected"

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. James Hamil 22,186 Reputation points Microsoft Employee
    2024-04-25T20:45:58.2166667+00:00

    Hi @DG001 , this typically indicates that there is a syntax error in the query that is being used to search for EmailEvents in Advanced Hunting. Do you have the exact query used?

    To resolve this issue, you can try the following steps:

    1. Check the query syntax: Make sure that the query being used to search for EmailEvents is correct and follows the correct syntax. You can refer to the Microsoft documentation for Advanced Hunting query syntax to ensure that the query is correct.
    2. Check the query for incomplete fragments: The error message indicates that there is an incomplete fragment in the query. Check the query to see if there are any incomplete fragments, such as missing parentheses or quotation marks. Make sure that all fragments in the query are complete and properly formatted.
    3. Check the permissions: Ensure that the user has the necessary permissions to search for EmailEvents in Advanced Hunting. The user must have the necessary permissions to access the EmailEvents table in order to search for EmailEvents.

    Please let me know if you have any questions and I can help you further.

    If this answer helps you please mark "Accept Answer" so other users can reference it.

    Thank you,

    James