Glossary
AuditData
The JSON column of a Microsoft 365 audit log export that holds the full detail of each record: parameters, client IP, session and token identifiers.
AuditData is the column of a Unified Audit Log export that contains the complete audit record as a JSON string. The other CSV columns (date, user, operation) are only a summary; the evidence is inside AuditData.
Its fields depend on the workload. Exchange admin operations carry Parameters (for an inbox rule: Name, ForwardTo, MoveToFolder, DeleteMessage…); MailItemsAccessed carries OperationProperties, Folders and OperationCount; Entra ID events carry ModifiedProperties; SharePoint events carry SourceFileName and SiteUrl. Many records include ClientIP and AppAccessContext with AADSessionId and UniqueTokenId, the linkable identifiers that connect an action to an Entra sign-in.
Opening an export in a spreadsheet can damage long AuditData values; parse it programmatically. More in Unified Audit Log investigation.