Microsoft 365

Download 27
Last updated May 22, 2022

o365-general-logs

Fetch general logs using Office 365 Management API

o365-general-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Office 365 connect profile name
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
profileStringConnect profileThe identifier of Office 365 connect profile
workloadStringWorkloade.g. SecurityComplianceCenter, Mip
user_idStringUser IDGUID, email address, MIPContentExplorer, or NOT-FOUND
operationStringOperatione.g. SearchMtpStatus, MemberAdded, TeamSettingChanged
data_typeStringData typee.g. MtpStatus, DataInsightsSubscription, Alert
record_typeIntegerRecord typee.g. 18, 25, 52, 157
user_typeIntegerUser typee.g. 0, 2, 5
user_keyStringUser keyGUID, email address, MIPContentExplorer, or NOT-FOUND
versionIntegerVersione.g. 1
idStringIDGUID format
org_idStringTenant IDGUID format