# Ingest Microsoft Intune Audit Logs to Elastic

**URL:** https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633
**Category:** Elastic Observability
**Created:** [November 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633 "2023-11-07T15:13:14Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![momher](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@momher](https://discuss.elastic.co/u/momher)
#### Post date: [November 7, 2023, 3:13pm UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633/1 "2023-11-07T15:13:14Z")

</div>

Do any one have done ingesting their Microsoft Intune Audit Logs to elastic for alerting purposes? For example, if there's a specific Audit Logs on Intune it gets ingested to Elastic to create an alert ticket.

---

<div class="post-metadata">

### Author: ![transcend3nt](https://avatars.discourse-cdn.com/v4/letter/t/8e8cbc/32.png) [@transcend3nt](https://discuss.elastic.co/u/transcend3nt)
#### Post date: [November 23, 2023, 2:56am UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633/2 "2023-11-23T02:56:15Z")

</div>

I'm looking to do that - to ingest all the Intune logs to Elastic, and have Elastic match for alert rulesets on the ingested Intune data. Are these rules readily available?

---

<div class="post-metadata">

### Author: ![momher](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@momher](https://discuss.elastic.co/u/momher)
#### Post date: [November 23, 2023, 6:14am UTC](https://discuss.elastic.co/t/ingest-microsoft-intune-audit-logs-to-elastic/346633/3 "2023-11-23T06:14:32Z")

</div>

We haven't tried it and waiting for someone to confirm that they've done it.
