Microsoft 365

Download 27
Last updated May 22, 2022

o365-sharepoint-logs

Fetch sharepoint logs using Office 365 Management API

o365-sharepoint-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Office 365 connect profile name
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
profileStringConnect profileThe identifier of Office 365 connect profile
workloadStringWorkloade.g. OneDrive, SharePoint
client_ipIP addressClient IP
user_idStringUser ID
operationStringOperatione.g. FileUploaded, FileAccessed, FilePreviewed, FolderCreated, FileSyncUploadedFull
object_idStringObject IDe.g. https://acme-my.sharepoint.com/personal/scott/Documents/path/to/file.png
item_typeStringItem typee.g. File, Folder, Field, Web, Site, List
user_agentStringUser agente.g. Microsoft SkyDriveSync 22.089.0426.0003 ship; Windows NT 10.0 (19044)
event_sourceStringEvent sourcee.g. SharePoint
source_relative_urlStringSource relative URLe.g. /Documents/path/to
source_file_nameStringSource file namee.g. file.png
source_file_extensionStringSource file extensione.g. png, xlsx, pdf, pptx, zip
versionIntegerVersione.g. 1
idStringIDGUID format
list_idStringList IDGUID format
list_item_idStringList item IDGUID format
org_idStringTenant IDGUID format
web_idStringWeb IDGUID format
siteStringSiteGUID format
site_urlStringSite URLe.g. https://acme-my.sharepoint.com/personal/scott
record_typeIntegerRecord typee.g. 6 (File, Folder), 14 (Group), 56 (List column), 4 (Site), 36 (List)
user_typeIntegerUser typee.g. 0
user_keyStringUser keye.g. i:0h.fmembership1000000000000000@live.com
correlation_idStringCorrelation IDGUID format
app_idStringApp IDGUID format
app_display_nameStringApp display namee.g. Microsoft Teams, OneNote