Forum Discussion

BM-HV's avatar
BM-HV
Copper Contributor
Jan 22, 2026

How do I import Purview Unified Audit Log data related to the use of the Audit Log into Sentinel?

Dear Community, I would like to implement the following scenario on an environment with Microsoft 365 E5 licenses:

Scenario: I want to import audit activities into an Azure Log Analytics workspace linked to Sentinel to generate alerts/incidents as soon as a search is performed in the Microsoft 365 Purview Unified Audit Log (primarily for IRM purposes).

Challenge: Neither the "Microsoft 365" connector, nor the "Defender XDR" or "Purview" (which appear to be exclusively Azure Purview) connectors are importing the necessary data.

Question: Which connector do I have to use in order to obtain Purview Unified Audit Log activities about the use of the Purview Unified Audit Log so that I can identify... 

...which user conducted when an audit log search and with what kind of search query.

Thank you!

No RepliesBe the first to reply

Resources