Forum Discussion
Qusai_Ismail
Aug 30, 2022Brass Contributor
UnifiedAuditLogs in sentinel
Hello, Where to find the unifiedauditlog in sentinel ? Which connector is required for that logs? BR,
- Aug 30, 2022
Do you mean the Unified Log mentioned mentioned in regards to Azure Purview?
https://docs.microsoft.com/en-us/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=o365-worldwideThe link above lists the Services (but there isn't a doc that maps them back to Sentinel Tables). I've not used it but the Insider Risk solution might be a good point to start
Azure-Sentinel/Solutions/Azure Purview at master · Azure/Azure-Sentinel (github.com)
Qusai_Ismail
Aug 30, 2022Brass Contributor
Thank you, that mean there are not tables related to that audits in Microsoft sentinel ?
Clive_Watson
Aug 30, 2022Bronze Contributor
Correct, as far as I know there isn't a 1:1 mapping, there are multiple tables and connectors needed.
But I haven't looked at the table created by the Insider Risk solution.
But I haven't looked at the table created by the Insider Risk solution.
- Qusai_IsmailAug 30, 2022Brass ContributorAh thanks.
My case: there is an incident called "eDiscovery search started or exported" come from vendor "Microsoft Defender for Office 365", and the incident is not have the efficient data, so we are trying to find the related data logs without access the "unified audit logs" in Compliance Security