Skip to content

Read and reuse your results

Any command that can return a lot of data prints a receipt followed by at most two preview rows, and saves the complete result as JSONL under ~/.xdr-cli/results/. When there are more rows than previews, the receipt’s context.results_command is the exact command to page through them:

{"status":"success","schema_version":1,"run_id":"20261004T015710757111Z-41a96c5113e3","data_path":"/home/me/.xdr-cli/results/2026-10-04/20261004T015710757111Z-41a96c5113e3.jsonl","meta_path":"/home/me/.xdr-cli/results/2026-10-04/20261004T015710757111Z-41a96c5113e3.meta.json","rows":2,"server_truncation_state":"unknown","execution_time_ms":1537,"session_id":null,"session_label":null,"session_attachment":"unattached","incident_id":null,"alert_id":null,"context":{"shown":2,"total":2,"has_more":false}}
{"id":"2","severity":"high","status":"active","displayName":"Multi-stage incident involving Credential access & Lateral movement on multiple endpoints", …}
{"id":"1","severity":"high","status":"active","displayName":"'Ceprolad' detected on one endpoint", …}

The preview rows above are abridged; real rows are the full API objects (previews larger than 4 KB are replaced by a preview_omitted marker).

Work with the artifact using whatever you already use — jq, rg, Python — or the built-in xdr results commands. incidents show, alerts show, and investigate split their output into typed rows (record_type of incident, alert, evidence, entity, …), so one kind can be selected directly:

Terminal window
xdr incidents show 42 --expand alerts # note the receipt's data_path
jq -r 'select(.record_type=="alert") | "\(.severity)\t\(.title)"' "$DATA_PATH"
xdr results shape <run-id> # which fields exist, with types and counts
xdr results rows <run-id> --type evidence
xdr results query <run-id> # the KQL behind a hunt or library run

Artifacts are never deleted automatically. xdr results prune --older-than 30 --yes removes eligible old results and retires automatic discovery evidence for them; explicit observation and proposal evidence remains protected. See evidence retention.