You got an error message "Unsupported_Expression" in Endpoint Activity Recorder by performing and Endpoint search with below query
- file.md5:<md5_hash>
Symantec EDR supports searches for PE and non-PE files. For Endpoint Activity Recorder searches, Symantec EDR only supports searches that are for SHA2.
EDR is working by design.