Forum Discussion
BM-HV
Jan 20, 2026Copper Contributor
How do I import Purview Unified Audit Log data related to the use of the Audit Log into Sentinel?
Dear Community, I would like to implement the following scenario in an environment with Microsoft 365 E5 licenses: Scenario: I want to import audit activities into an Azure Log Analytics workspace l...
VasilMichev
Jan 20, 2026MVP
The Microsoft 365 connector is what you need, see for example https://learn.microsoft.com/en-us/azure/sentinel/connect-services-api-based
There are few additional connectors that cover Entra ID data, Defender, Information protection and so on. It all boils down to what data you need.
BM-HV
Jan 21, 2026Copper Contributor
Thanks, VasilMichev!
The "Microsoft 365" connector was my first shot, and I'm importing data for SPO and EXO through that. However, it seems like it covers no Purview activities at all. What I need: Which user conducted when an audit log search and with what kind of search query.