Skip to content

Commit 6b4b724

Browse files
Merge pull request #246872 from shlipsey3/enriched-logs-073123
enriched-logs-073123
2 parents 160ba33 + 82e8571 commit 6b4b724

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

articles/global-secure-access/how-to-view-enriched-logs.md

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ ms.custom:
1212

1313
# How to use the Global Secure Access (preview) enriched Microsoft 365 logs
1414

15-
With your Microsoft 365 traffic flowing through the Microsoft Entra Private Access service, you want to gain insights into the performance, experience, and availability of the Microsoft 365 apps your organization uses. The enriched Microsoft 365 logs provide you with the information you need to gain these insights. You can integrate the logs with a third-party security information and event management (SIEM) tool for further analysis.
15+
With your Microsoft 365 traffic flowing through the Microsoft Entra Private Internet service, you want to gain insights into the performance, experience, and availability of the Microsoft 365 apps your organization uses. The enriched Microsoft 365 logs provide you with the information you need to gain these insights. You can integrate the logs with a third-party security information and event management (SIEM) tool for further analysis.
1616

1717
This article describes the information in the logs and how to export them.
1818

@@ -31,18 +31,19 @@ You must configure the endpoint for where you want to route the logs prior to co
3131
The enriched Microsoft 365 logs provide information about Microsoft 365 workloads, so you can review network diagnostic data, performance data, and security events relevant to Microsoft 365 apps. For example, if access to Microsoft 365 is blocked for a user in your organization, you need visibility into how the user's device is connecting to your network.
3232

3333
These logs provide:
34-
- Improved latency and predictability
34+
- Improved latency
3535
- Additional information added to original logs
3636
- Accurate IP address
3737

38-
These logs are a subset of the logs available in the [Microsoft 365 audit logs](/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=0365-worldwide&preserve-view=true). The logs are enriched with additional information, such as the user's IP address, device name, and device type. The enriched logs also contain information about the Microsoft 365 app, such as the app name, app ID, and app version.
38+
These logs are a subset of the logs available in the [Microsoft 365 audit logs](/microsoft-365/compliance/search-the-audit-log-in-security-and-compliance?view=0365-worldwide&preserve-view=true). The logs are enriched with additional information, including the device ID, operating system, and original IP address. Enriched SharePoint logs provide information on files that were downloaded, uploaded, deleted, modified, or recycled. Deleted or recycled list items are also included in the enriched logs.
3939

4040
## How to view the logs
4141

4242
Viewing the enriched Microsoft 365 logs is a two-step process. First, you need to enable the log enrichment from Global Secure Access. Second, you need to configure Microsoft Entra ID Diagnostic settings to route the logs to an endpoint, such as a Log Analytics workspace.
4343

4444
> [!NOTE]
4545
> At this time, only SharePoint Online logs are available for log enrichment.
46+
4647
### Enable the log enrichment
4748

4849
To enable the Enriched Microsoft 365 logs:

0 commit comments

Comments
 (0)