Join us for an expert-led overview of the tools and concepts you'll need to pass exam PL-300. The first session starts on June 11th. See you there!
Get registeredFabric Ideas just got better! New features, better search, and direct team engagement. Learn more
Currently there is a tremendous amount of value in the M365 Audit log, but it is extremely difficult to access. Retention is low for API access and other methods are batch oriented at best. Apart from some work in Sentinel, there are no ways to react to events in near real time. This seems like an obvious data source for the RTA workload in Fabric. Kusto could allow for as much retention as desired, and streaming would allow for reactions in near real time.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Thanks for your input.
To support low latency events, Eventstream is planning to integrate with Microsoft Graph change notifications. This feature will enable multiple scenarios like event-driven applications, anomaly detection and real-time analysis on Microsoft Graph data.
If this is blocking you, please consider using LogicApp and connect to Eventstream (with customEndpoint as source) as a short term solution.