Audit Log Search Defender Portal
In brief
The page now links to guidance for searching audit log events in Microsoft Defender XDR.
What Defender admins need to know
Administrators have an additional reference for audit log searches; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- In the Microsoft Defender portal at https://security.microsoft.com, go to Audit. Or, to go directly to the Audit page, use https://security.microsoft.com/auditlogsearch.
- On the Audit page, create the audit log search. For instructions, see Audit New Search or Use a PowerShell script to search the audit log.
Related content
Search the audit log for events in Microsoft Defender XDR \ No newline at end of file
@@ -50,3 +50,7 @@ Review the following prerequisites before you search the audit log. 1. In the Microsoft Defender portal at <https://security.microsoft.com>, go to **Audit**. Or, to go directly to the **Audit** page, use <https://security.microsoft.com/auditlogsearch>. 2. On the **Audit** page, create the audit log search. For instructions, see [Audit New Search](/purview/audit-new-search) or [Use a PowerShell script to search the audit log](/purview/audit-log-search-script).++## Related content++[Search the audit log for events in Microsoft Defender XDR](/defender-xdr/microsoft-xdr-auditing)\ No newline at end of file 