Read and reuse your results
Reading results
Section titled “Reading results”Any command that can return a lot of data prints a receipt followed by at
most two preview rows, and saves the complete result as JSONL under
~/.xdr-cli/results/. When there are more rows than previews, the receipt’s
context.results_command is the exact command to page through them:
{"status":"success","schema_version":1,"run_id":"20261004T015710757111Z-41a96c5113e3","data_path":"/home/me/.xdr-cli/results/2026-10-04/20261004T015710757111Z-41a96c5113e3.jsonl","meta_path":"/home/me/.xdr-cli/results/2026-10-04/20261004T015710757111Z-41a96c5113e3.meta.json","rows":2,"server_truncation_state":"unknown","execution_time_ms":1537,"session_id":null,"session_label":null,"session_attachment":"unattached","incident_id":null,"alert_id":null,"context":{"shown":2,"total":2,"has_more":false}}{"id":"2","severity":"high","status":"active","displayName":"Multi-stage incident involving Credential access & Lateral movement on multiple endpoints", …}{"id":"1","severity":"high","status":"active","displayName":"'Ceprolad' detected on one endpoint", …}The preview rows above are abridged; real rows are the full API objects
(previews larger than 4 KB are replaced by a preview_omitted marker).
Work with the artifact using whatever you already use — jq, rg, Python —
or the built-in xdr results commands. incidents show, alerts show, and
investigate split their output into typed rows (record_type of incident,
alert, evidence, entity, …), so one kind can be selected directly:
xdr incidents show 42 --expand alerts # note the receipt's data_pathjq -r 'select(.record_type=="alert") | "\(.severity)\t\(.title)"' "$DATA_PATH"xdr results shape <run-id> # which fields exist, with types and countsxdr results rows <run-id> --type evidencexdr results query <run-id> # the KQL behind a hunt or library runArtifacts are never deleted automatically. xdr results prune --older-than 30 --yes
removes eligible old results and retires automatic discovery evidence for them;
explicit observation and proposal evidence remains protected. See
evidence retention.