Raw Data Searchable in Activity Logs

%3CLINGO-SUB%20id%3D%22lingo-sub-305582%22%20slang%3D%22en-US%22%3ERaw%20Data%20Searchable%20in%20Activity%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-305582%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20Everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EActivity%20logs%20contain%20a%20button%20called%20'Raw%20Data'.%20I%20was%20wondering%20if%20I%20can%20apply%20filters%20and%20search%20for%20specific%20values%20in%20the%20field%20included%20in%20the%20Json%20raw%20data%3F%20Or%20if%20it%20possible%20to%20do%20it%20in%20any%20way%2C%20such%20as%20the%20Power%20Shell%20module%20or%20by%20sending%20the%20alert%20to%20the%20SIEM.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20look%20froward%20to%20hearing%20from%20you.%3C%2FP%3E%3CP%3EThank%20you.%3C%2FP%3E%3CP%3EMaria%20Y.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-305582%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECloud%20App%20Security%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-306106%22%20slang%3D%22en-US%22%3ERe%3A%20Raw%20Data%20Searchable%20in%20Activity%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-306106%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%0A%3CP%3ERaw%20data%20is%20not%20searchable%20in%20MCAS.%3C%2FP%3E%0A%3CP%3EYou%20can%20search%20on%20any%20of%20the%20formatted%20attributes%2C%20as%20well%20as%20the%20info%20located%20in%20Activity%20Objects.%3C%2FP%3E%0A%3CP%3EIf%20you%20have%20specific%20data%20that%20interest%20you%20in%20the%20raw%20data%20you%20can%20send%20an%20activity%20feedback%20and%20we'll%20look%20into%20adding%20it%20as%20an%20activity%20object.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ERegards%2C%3C%2FP%3E%0A%3CP%3EDima%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-305889%22%20slang%3D%22en-US%22%3ERe%3A%20Raw%20Data%20Searchable%20in%20Activity%20Logs%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-305889%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F112613%22%20target%3D%22_blank%22%3E%40Danny%20Kadyshevitch%3C%2FA%3E%20or%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F76512%22%20target%3D%22_blank%22%3E%40Dima%20Donhin%3C%2FA%3E%3A%20Do%20you%20have%20any%20insight%20on%20this%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hello Everyone,

 

Activity logs contain a button called 'Raw Data'. I was wondering if I can apply filters and search for specific values in the field included in the Json raw data? Or if it possible to do it in any way, such as the Power Shell module or by sending the alert to the SIEM.

 

I look froward to hearing from you.

Thank you.

Maria Y.

2 Replies

@Danny Kadyshevitch or @Dima Donhin: Do you have any insight on this?

Hi,

Raw data is not searchable in MCAS.

You can search on any of the formatted attributes, as well as the info located in Activity Objects.

If you have specific data that interest you in the raw data you can send an activity feedback and we'll look into adding it as an activity object.

 

Regards,

Dima