Wrangling the M365 UAL with SOF-ELK and CSV Data (Part 3 of 3)
ID: e06b8a46-2687-545d-a5fa-6d84a47c6018
STIX ID: report--e06b8a46-2687-545d-a5fa-6d84a47c6018
Feed Name: Black Hills Infosec Blog
This guide explains how to extract and reformat the Microsoft 365 Unified Audit Log (UAL) “AuditData” from CSV exports for automatic ingestion into SOF-ELK, using csvtool to handle quoted fields and preparing a JSON-ready file. It walks through copying the data to SOF-ELK, verifying index creation, and provides tips on updating MaxMind GeoLite2 geolocation data and SOF-ELK itself, highlighting ways to streamline UAL analysis workflows.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
