Searching the log

Once audit logging has been enabled, events should begin appearing for activities. With regards to SharePoint and OneDrive sharing activity, items will have the following properties that are available for examination:

  • TargetUserOrGroupType: This identifies the object type of the target being shared (valid options are Member, Guest, SharePointGroup, SecurityGroup, and Partner).
  • TargetUserOrGroupName: This displays the identity of the object a resource was shared with.
  • AuditData: This stores information about sharing events.
  • Sharing Events: The following event activities will go into the audit data:
    • SharingInvitationCreatedA user tried to share a resource.
    • SharingInvitationAcceptedThe user has accepted a sharing invitation.
    • AnonymousLinkCreated: A user has created an anonymous link (also called an "Anyone" link).
    • AnonymousLinkUsed: A previously created anonymous link has been used to access a resource.
    • SecureLinkCreatedA user has created a "specific people link." The recipient is identified in the AddedToSecureLink event.
    • AddedToSecureLinkA recipient, specified in TargetUserOrGroupName, was added to a "specific people link."

These activities can be discovered via the Security & Compliance Center Audit Log Search or PowerShell. An example of this can be seen in the following audit log entry:

You can export the records and manipulate them via Excel, Power BI, or other data analytics tools.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.145.131.238