Wondering if anyone here can help me to understand, in the Defender Portal (security.microsoft.com), when I'm using Advanced Hunting there, when am I and when am I not querying the streaming API vs the live table (for lack of knowing what else to call the "live table")? Specifically, I'm looking for EmailEvents table entries, filtering by LatestDeliveryLocation, but what I find here - EmailEvents table in the advanced hunting schema - Microsoft Defender XDR | Microsoft Learn - is this:
Note
* The LatestDeliveryLocation and LatestDeliveryAction columns are not available in the Streaming API.
Does it work like this: when I select the time range from the UI menu I'm searching the live table, and when I set timerange in my query, that is searching the streaming API?
Thanks in advance.