# Parsing o365.audit.Data filed for o365 Module

**URL:** <https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370>\
**Category:** SIEM\
**Created:** [September 11, 2020, 6:36pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370 "2020-09-11T18:36:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![opiedrah](https://avatars.discourse-cdn.com/v4/letter/o/5f9b8f/32.png) [@opiedrah](https://discuss.elastic.co/u/opiedrah)\
**Post date:** [September 11, 2020, 6:36pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370/1 "2020-09-11T18:36:02Z")

</div>

Hi folks,

I've had the o365 module for Filebeat working for a while. I've onboarded a new workload called:

o365.audit.Workload :"AirInvestigation"

The filed is composed of nested json objects just the same as the ExtendedProperties field.

Anyone know how to get this parsed correctly.

Thank you,

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 14, 2020, 1:46pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370/2 "2020-09-14T13:46:10Z")

</div>

(Moving to the SIEM category as that Elastic team maintains this module).

---

<div class="post-metadata">

**Author:** ![Marius\_Iversen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marius_iversen/32/68988_2.png) [@Marius\_Iversen](https://discuss.elastic.co/u/Marius_Iversen)\
**Post date:** [September 14, 2020, 6:21pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370/3 "2020-09-14T18:21:00Z")

</div>

Is it currently being ingested by the module?

Looking at the current content types we support it should grab these by default:

- Audit.AzureActiveDirectory
- Audit.Exchange
- Audit.SharePoint
- Audit.General
- DLP.All

The module itself has some underlying javascript to preprocess some of the content like these nested objects most likely, but it kinda depends on how the data looks like.

Is it a list of JSON objects like

```
[{
  "investigation": "1",
 "details": "somedetails"
},
{
  "investigation": "2",
  "details": "someotherdetails"
}].

```

It depends on the data and what you want to do with it. For example if you only want to create an array of investigation details, let's say usernames, then you can use the foreach processor to run through the list of objects and append them to something, you can also modify it with a script processor depending on your knowledge of programming.

If you could share maybe a sample of the data and a bit on how you want it to look like in the end then I could maybe help you further.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2020, 8:21pm UTC](https://discuss.elastic.co/t/parsing-o365-audit-data-filed-for-o365-module/248370/4 "2020-10-12T20:21:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
