question

dilannanayakkara-8008 avatar image
0 Votes"
dilannanayakkara-8008 asked MartinRublik-0301 commented

Monitor Content Search using Sentinel

Hi,

I have a requirement of monitor any eDiscovery/Content search has been done by Admins through Sentinel.

appreciate if anyone can share a KQL query or propose the way to achieve this through Sentinel.

Thanks,
Dilan

azure-monitorazure-sentinel
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MartinRublik-0301 avatar image
0 Votes"
MartinRublik-0301 answered MartinRublik-0301 commented

Hi,

please check following MS article:
https://docs.microsoft.com/en-us/answers/questions/470633/moniotr-content-search-using-sentinel.html

Unfortunatelly I was not able to find these in OfficeActivity log (especially I checked for SearchExportDownloaded event), as a workaround you could set-up a MCAS/OCAS alert and monitor these alerts in Sentinel.

Martin

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you very much!

0 Votes 0 ·

@MartinRublik-0301

the link will again redirect to this question. I you mean a different link. Appreciate if you can mention it again.

0 Votes 0 ·