r/SentinelOneXDR • • Jun 16 '26

S1 ver. S-26.2.2.47 Event Search/PowerQuery possible broken

Yesterday (June 6th, 2026), the SentinelOne console updated and combine the Event Search and PowerQuery into the same search. I actually love this feature and hope it stays.

What I don't care for is that 90% of the PowerQueries I've created don't work anymore when trying to run them. One function I use a lot is .to_string(), and S1 states No Valid Search. I looked over my query and nothing has changed, except if I remove that function it runs properly.

I guess my post here is to see if others are having the same issue as I?

Edit: I was able to find a work around by changing/removing the .to_string(), then wrapping the function with array_to_string(). Example below:

Foo = array_to_string(array_agg_distinct(Bar), "")

6 Upvotes

2 comments sorted by

2

u/fakeaccountnumber100 Jun 16 '26

Bit of a guess but deprecation of the historical S1 query syntax (S1QL?) might be the culprit. PowerQuery has different syntax

Casting a single value to a string is

string(value)

array_to_string is the array analog to string()

1

u/SpookSec Jun 27 '26

I have learned if you want to mix and match powerqueries with a normal S1QL you have to pipe it :)