MicrosoftPolicyAndComplianceAuditLog
Use the integration to get logs from the O365 service.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Office365AndAzureAuditLog
Configuration parameters
- certificate — Certificate (required)
- organization — The organization used in app-only authentication. (required)
- app_id — The application ID from the Azure portal (required)
- insecure — Trust any certificate (not secure)
Commands (1)
- o365-auditlog-search — Use the o365-search-auditlog command to search the unified audit log. This log contains events from Exchange Online, SharePoint Online, OneDrive for Business, Entra ID, Microsoft Teams, Power BI, and other Microsoft 365 services. You can search for all events in a specified date range, or you can filter the results based on specific criteria, such as the action, the user who performed the action, or the target object.