This is a phenomenal blog post that describes EVERYTHING about Microsoft 365 logs.
- What logs exist
- How to enable logging
- What levels of audit exist
(And the licensing requirements for each) - Who can access logs
- What kind of lag time exists for different events
- How can data be accessed?
- Office Management API
- Using Azure Sentinel to ingest logs
And this is just Part 1. If you need to collect & hunt through Microsoft 365 logs, you need to go through this post.
- Discovering Microsoft 365 Logs within your Organization [ Part 1]
https://techcommunity.microsoft.com/t5/public-sector-blog/discovering-microsoft-365-logs-within-your-organization-part-1/ba-p/2823682