I use fleet integration for collect o365 audit logs and i want to collect 1 month of logs.
The "Initial Interval" parameter has maximum value of 7 days.
Is it possible to extend this duration or is there a way to retrieve the logs manually and pass them through the ingest pipeline o365 ?
Thank you for your help
Thank you for your answer.
Is there another way to retrieve the logs in the right format and send them by logstash or filebeat to the o365 ingest pipeline ?
It is possible to do this via microsoft preview. But the format is in csv. What is the format expected by the ingest pipeline to be able to index logs ?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.