For query assistance, please see the following Best Practices guide
We have enabled the ability to add the Office 365 Audit log information into the Sophos XDR Data Lake.
This capability is available for ALL XDR customers at NO ADDITIONAL CHARGE. To access to the capability you should join the XDR Detections and Investigations EAP then configure the connector.
We will pull information from about 33 of the audit tables available in the Azure Audit logs. Check out the 10 min video on the capability that covers enrolling in the EAP, configuring the adaptor and getting started with queries. https://vimeo.com/manage/videos/652159242
The Features for this will turn on in MID December 2021 and be generally available in late January 2022. For those that want a head start you can load in the demonstration queries into central now and ensure auditing is enabled in 365 Azure.
Full details on the MS Schema for audit logs are available from MS here: https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema
Check out the demonstration queries available in the ZIP file below