How to load the Azure IP address list for east us 2 into the hunting query "Detect Azure RemoteIP"

AustinBits 0 Reputation points
2025-04-28T17:08:05.2366667+00:00

in the Defender dashboard in Azure, under Hunding , advanced Hunting, Queries, General Queries, Detect Azure RemoteIP

I downloaded the .json file that is the list of all IP address ranges. I copied the ip address list for east us 2 and pasted it into the section (DeviceNetworkEvents | take 10000) as stated in the top instructions of : "replace the demo portion of the query (DeviceNetworkEvents | take 10000) with your query with the column name of the IP address"

This query fails after pasting in the ip address list from the json file.

It is giving the error of expecting a semicolon in "line 3, position 4" but line 3 is setting a variable let AzureSubnets = toscalar (

Or if it means the third line in the ip address list after the note //begin sample query// is just another ip address in the list, see bottom 2 pics. anyone have an idea where this semicolon can be inserted?

kql for remote ip addresses adv hunt1a

kql for remote ip addresses adv hunt1

kql for remote ip addresses adv hunt2

kql for remote ip addresses adv hunt5

kql for remote ip addresses adv hunt8

kql for remote ip addresses adv hunt9

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
255 questions
0 comments No comments
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.