Skip to content
Skip to main content
Cloud Services Technical Explainer

What is a cloud audit log?

A cloud audit log is a provider or customer record of selected actions within an account, service or tenant. It can reconstruct who or what acted on which resource, when, through which route and with what outcome - at the level the system recorded.

An event has several useful parts

event_id=EVT-9041
time=2026-08-12T14:22:08Z
actor=C-77503
action=file.version.update
target=OBJ-4407
session=SES-41C2
client=web-editor
outcome=success

Stable event, object, session and request IDs can connect audit entries with authentication, device or application records more reliably than timestamps alone.

Coverage and vocabulary are provider-specific

Logging can vary by product, subscription and configuration. Some actions are detailed, others summarised or absent. “Accessed”, “created” and “updated” may describe narrow technical events rather than ordinary human behaviour.

Preserve the raw event and field definitions. Check whether logging was enabled, what systems feed it, retention and whether the result is a complete export or filtered interface view.

Audit actor is not automatically a person

The actor may be a user account, administrator, service account, application or provider process. Sessions can be shared or stolen. Use authentication, client, device and wider records to make the personal connection.

Access logs answer a related but narrower question about requests reaching a service or resource.

In OneDrive, audit event EVT-9041 records account C-77503, operation FileModified, object OBJ-4407, version V-19, session SES-41C2, client OD-77, UTC time 14:22:08 and outcome success. Joined to authentication record AUTH-1882, it can establish that a defined account session successfully caused the recorded service action. It does not by itself establish that Dave controlled the session, authored every changed word or intended the result.

Translate the audit row into one precise evidential proposition
EstablishedThe event establishes a successful provider-defined modification through the recorded account session and client.
Still openHuman control of the session, the precise authored change and the actor's knowledge or intent.

The next useful comparison is the raw EVT-9041 record and field definitions against AUTH-1882, session lifecycle, exact V-19 change, device/application activity and neighbouring audit events.

Current Microsoft audit-record example - checked 3 September 2026

Microsoft Purview audit records expose workload-defined operations and detailed properties that may include users, objects, clients, sessions or correlation values. Coverage and fields vary by workload, licensing and configuration, so preserve the raw export and the applicable definitions.

The point to remember

A cloud audit log records selected service actions. Understand its coverage and event definitions, then use stable identifiers and corroboration to reconstruct and attribute the sequence.

Reference: CLD-099Cloud Services