# Filebeat Module O365 API URI?

**URL:** <https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [January 4, 2022, 6:46pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471 "2022-01-04T18:46:30Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticband](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Post date:** [January 4, 2022, 6:46pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/1 "2022-01-04T18:46:30Z")

</div>

I am trying to get some support from Microsoft because I am not seeing all the login data I see in the Azure AD Console via the O365 Module. They would like to know what URI the module is using for API calls and I am not seeing it listed, other than generically using [manage.office.com](http://manage.office.com).

Is that something someone could point me to, so I can use a Powershell script to test the audit data?

Much appreciated.

---

<div class="post-metadata">

**Author:** ![elasticband](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Post date:** [January 10, 2022, 3:29pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/2 "2022-01-10T15:29:24Z")

</div>

I kind of feel like this forum is kind of dead? Am I asking dumb questions, or is this where all my questions go to die?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 10, 2022, 5:22pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/3 "2022-01-10T17:22:07Z")

</div>

Hello,

Some questions get more traction than others for different reasons.

But to answer your question, the O365 Module uses the _Office 365 Management Activity API_, which from [Microsoft documentation](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference) uses the `manage.office.com`, that you already knew.

The [module documentation](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-o365.html#_advanced_configuration_options) also refers to the same endpoint, if you do not edit those configuration in your module it will use the default endpoint which is also `manage.office.com`, you can check it in the [code](https://github.com/elastic/beats/blob/6aec024e0ab8239791be20885d6d3c58697d18cd/x-pack/filebeat/input/o365audit/config.go#L114-L116).

So, the O365 uses the `manage.office.com` endpoint to collect data, there is no other URL for the API.

If you want to check further, the code for the input is [here](https://github.com/elastic/beats/tree/master/x-pack/filebeat/input/o365audit).

---

<div class="post-metadata">

**Author:** ![elasticband](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Post date:** [January 10, 2022, 6:40pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/4 "2022-01-10T18:40:44Z")

</div>

Thanks, I am sorry to be blunt, but I am trying to work with Microsoft to see why I am not getting all the login data via the Elastic Beat Module for O365. I used the Microsoft Management API and it is setup correctly from what I can see per documentation; however, I am missing out on Exchange Logins mostly.

Since we pay for support via them, I opened a ticket and wanted to see if they are shipping all relevant data and if I missed something on the oAuth App configure side. They would like me to get the API call URI so I can test output in Powershell, but I really do not know what you all are using. From your Code I guess I am not able to read it well enough.

I see this site from Microsoft:

> **[Troubleshooting the Office 365 Management Activity API](https://learn.microsoft.com/en-us/office/office-365-management-api/troubleshooting-the-office-365-management-activity-api)**
>
> Summarizes the most common questions Microsoft Support receives in supporting the Office 365 Management Activity API.

> Invoke-WebRequest -Method Post -Headers $headerParams -Uri "https://\<YOUR\_API\_ENDPOINT\>/api/v1.0/$tenantGUID/activity/feed/subscriptions/start?contentType=Audit.AzureActiveDirectory  
> So maybe this for Azure AD Audit? "[https://manage.office.com/api/v1.0/$tenantGUID/activity/feed/subscriptions/start?contentType=Audit.AzureActiveDirectory](https://manage.office.com/api/v1.0/$tenantGUID/activity/feed/subscriptions/start?contentType=Audit.AzureActiveDirectory)"

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 10, 2022, 7:11pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/5 "2022-01-10T19:11:14Z")

</div>

I'm not from Elastic, but looking into the code, it seems that the Request URL is built using the [following function](https://github.com/elastic/beats/blob/6aec024e0ab8239791be20885d6d3c58697d18cd/x-pack/filebeat/input/o365audit/listblobs.go#L83-L96).

```auto
// RequestDecorators returns the decorators used to perform a request.
func (l listBlob) RequestDecorators() []autorest.PrepareDecorator {
	return []autorest.PrepareDecorator{
		autorest.WithBaseURL(l.env.Config.Resource),
		autorest.WithPath("api/v1.0"),
		autorest.WithPath(l.env.TenantID),
		autorest.WithPath("activity/feed/subscriptions/content"),
		autorest.WithQueryParameters(
			map[string]interface{}{
				"contentType": l.env.ContentType,
				"startTime": l.startTime.Format(apiDateFormat),
				"endTime": l.endTime.Format(apiDateFormat),
			}),
	}
}

```

So the API endpoint that Filebeat use would be:

```auto
https://manage.office.com/api/v1.0/YOUR-TENANT-ID/activity/feed/subscriptions/content?contentType=CONTENT-TYPE&startTime=START-TIME&endTime=END-TIME

```

The Content Type available are in this part of the [code](https://github.com/elastic/beats/blob/6aec024e0ab8239791be20885d6d3c58697d18cd/x-pack/filebeat/input/o365audit/config.go#L99-L105)

```auto
		ContentType: []string{
			"Audit.AzureActiveDirectory",
			"Audit.Exchange",
			"Audit.SharePoint",
			"Audit.General",
			"DLP.All",
		}

```

So, the request created by filebeat is the same as the one in the microsoft [troubleshooting page](https://docs.microsoft.com/en-us/office/office-365-management-api/troubleshooting-the-office-365-management-activity-api#checking-content-availability) that you shared.

To query the Audit for Azure Active Directory for yesterday, you would need something like this:

```auto
 "https://manage.office.com/api/v1.0/YOUR-TENANT-ID/activity/feed/subscriptions/content?contentType=Audit.AzureActiveDirectory&startTime=2022-01-09T00:00&endTime=2012-01-09T23:59"

```

---

<div class="post-metadata">

**Author:** ![elasticband](https://avatars.discourse-cdn.com/v4/letter/e/977dab/32.png) [@elasticband](https://discuss.elastic.co/u/elasticband)\
**Post date:** [January 10, 2022, 7:23pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/6 "2022-01-10T19:23:15Z")

</div>

Amazing! Thank you very much for the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2022, 9:24pm UTC](https://discuss.elastic.co/t/filebeat-module-o365-api-uri/293471/7 "2022-02-07T21:24:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
