logo

Wrangling the M365 UAL with PowerShell and SOF-ELK (Part 1 of 3)

ID: 01d7b037-b6fa-55df-bec6-7097b18818fb

STIX ID: report--01d7b037-b6fa-55df-bec6-7097b18818fb

Feed Name: Black Hills Infosec Blog

Date Published: 2023-08-10

Date Updated: 2026-04-27

Author: BHIS

...
...

This post provides a practical guide to collecting and analyzing Microsoft 365 Unified Audit Log (UAL) data using the Exchange Online Management PowerShell module and the SOF-ELK stack, including environment setup, authentication, sample searches and filtering (operations and user agents), exporting results to JSON, a PowerShell script that queries in hourly increments to bypass the 5K-per-query limit, and steps to ingest and explore the data in SOF-ELK/Kibana for investigation workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.