What is a cloud audit log?¶
A cloud audit log is a provider or customer record of selected actions within an account, service or tenant. It can reconstruct who or what acted on which resource, when, through which route and with what outcome - at the level the system recorded.
An event has several useful parts¶
event_id=EVT-9041
time=2026-08-12T14:22:08Z
actor=C-77503
action=file.version.update
target=OBJ-4407
session=SES-41C2
client=web-editor
outcome=success
Stable event, object, session and request IDs can connect audit entries with authentication, device or application records more reliably than timestamps alone.
Coverage and vocabulary are provider-specific¶
Logging can vary by product, subscription and configuration. Some actions are detailed, others summarised or absent. “Accessed”, “created” and “updated” may describe narrow technical events rather than ordinary human behaviour.
Preserve the raw event and field definitions. Check whether logging was enabled, what systems feed it, retention and whether the result is a complete export or filtered interface view.
Audit actor is not automatically a person¶
The actor may be a user account, administrator, service account, application or provider process. Sessions can be shared or stolen. Use authentication, client, device and wider records to make the personal connection.
Access logs answer a related but narrower question about requests reaching a service or resource.
In OneDrive, audit event EVT-9041 records account C-77503, operation FileModified, object OBJ-4407, version V-19, session SES-41C2, client OD-77, UTC time 14:22:08 and outcome success. Joined to authentication record AUTH-1882, it can establish that a defined account session successfully caused the recorded service action. It does not by itself establish that Dave controlled the session, authored every changed word or intended the result.
The next useful comparison is the raw EVT-9041 record and field definitions against AUTH-1882, session lifecycle, exact V-19 change, device/application activity and neighbouring audit events.
Current Microsoft audit-record example - checked 3 September 2026
Microsoft Purview audit records expose workload-defined operations and detailed properties that may include users, objects, clients, sessions or correlation values. Coverage and fields vary by workload, licensing and configuration, so preserve the raw export and the applicable definitions.
The point to remember
A cloud audit log records selected service actions. Understand its coverage and event definitions, then use stable identifiers and corroboration to reconstruct and attribute the sequence.