ShareMaster V2 is in beta, a complete rebuild. See what is new and request access →
  1. Home
  2. Guides
  3. Export SharePoint Audit Log to Excel

Export the SharePoint Audit Log to Excel (Step-by-Step)

Illustration: a site map with unowned nodes highlighted.
Export the SharePoint Audit Log to Excel (Step-by-Step)

Updated: 4 October 2026  |  Category: Auditing and Compliance

Microsoft Purview Audit logs every file access, permission change, and sharing event across your SharePoint Online environment. Getting that data out follows a short sequence: run a search, wait for results, download a CSV. The catch is that each search spans at most 180 days and each export is capped at 50,000 records with Audit (Standard), which surprises admins the first time they try to pull a large dataset for a compliance review.

This guide walks through the full export process, explains how to work with the resulting file in Excel, and identifies the scenarios where the native export is not the right tool for the job.

What the SharePoint Online audit log captures

Microsoft Purview records SharePoint activity across several broad categories. Knowing which category an event falls under helps you narrow your search query rather than pulling every activity type and filtering in Excel afterward.

Category Example activities recorded
File and folder operations FileAccessed, FileDownloaded, FileDeleted, FileModified, FileMoved, FolderCreated
Sharing and permission changes SharingInvitationCreated, CompanyLinkCreated, AnonymousLinkCreated, PermissionLevelAdded, AddedToGroup, SharingRevoked
Site and list administration SiteCollectionAdminAdded, SiteCollectionAdminRemoved, ListCreated, ListDeleted, ListContentTypeCreated
Page and search events PageViewed, PageViewedExtended, SearchQueryPerformed
Recycle bin events FileRecycled, FileRestored, FileDeletedFirstStageRecycleBin, FileDeletedSecondStageRecycleBin

Purview records hundreds of distinct event types; the table covers the ones most SharePoint administrators query during a typical audit or incident investigation.

Permissions required to run an audit search

Audit log access lives in the Microsoft Purview portal, not the SharePoint admin center. You need one of the following roles assigned in Purview:

  • View-Only Audit Logs - read and export access, no ability to enable or manage auditing.
  • Audit Logs - full access, including the ability to start auditing if it has not yet been enabled in the tenant.

Global Administrators and Compliance Administrators receive these roles by default. SharePoint Administrators do not, unless a Global Admin explicitly grants them a Purview role.

Tip: If you are a SharePoint Administrator who needs audit data but cannot open Audit in the Purview portal, ask your Microsoft 365 Global Admin to assign you the View-Only Audit Logs role in Purview. For permission-specific data (who can access what on a site, including guests and sharing links), the Security Matrix in ShareMaster's Report Master exports that directly from SharePoint without any Purview role; it needs site collection administrator access instead.

How to export SharePoint audit events to Excel

The steps below apply to the Audit search in the Microsoft Purview portal.

  1. Sign in to purview.microsoft.com. Use an account with the View-Only Audit Logs or Audit Logs role assigned in Purview.
  2. Navigate to Audit. Select the Audit solution card, or select View all solutions and then Audit. If you can open Audit but searches fail with an access error, your account likely lacks the required Purview role.
  3. Set the date range. Enter a start and end date and time (UTC). One search covers at most 180 days. For large investigations, run multiple searches with non-overlapping windows so each export stays under the row limit, and combine the CSV exports in Excel afterward.
  4. Select SharePoint activities. In Activities - friendly names, use the search box to find and select the SharePoint activities you need, or type exact operation names such as FileDeleted into Activities - operations names. Leave both empty to return all activity types across all Microsoft 365 workloads.
  5. Add optional scope filters. Select one or more people in the Users field to limit results to specific accounts. Use the File, folder, or site field to filter by a name or URL; a trailing * works as a wildcard, for example https://contoso.sharepoint.com/sites/finance*.
  6. Run the search. Click Search. Purview runs it as a search job with a progress percentage, and the job keeps running if you close the browser. Microsoft notes that broadly scoped searches in large tenants can take up to 48 hours.
  7. Check the result count before exporting. When the search completes, note the total records returned. If the count exceeds 50,000 (Audit Standard) or 1,000,000 (Audit Premium), narrow the date range or add filters before proceeding, because the export will leave records out.
  8. Export to CSV. Open the completed search job and select Export. Purview prepares a CSV file, which can take a while for a large search, and you can open it in Excel.

Working with the exported CSV in Excel

Microsoft's guidance describes four core columns in the export: CreationDate, UserIds, Operations and AuditData. Most of the detail you need for a SharePoint audit, including the file URL and site, sits inside AuditData:

Column What it contains Common uses
CreationDate UTC timestamp of the event Filter by date range, sort chronologically
UserIds UPN of the account that performed the action Pivot by user to see who was most active, or isolate a specific account
Operations Event type (FileDeleted, SharingLinkCreated, etc.) Filter to specific event types for targeted investigation
AuditData JSON blob with extended event details: ObjectId (full URL of the file, folder or site), SiteUrl, ClientIP, UserAgent, and the target user for sharing events Requires JSON parsing; use Power Query for large exports

Filtering quickly without parsing AuditData

For most investigations, filtering on Operations and UserIds answers the key questions: who deleted this file, who created an external sharing link, which account removed a user from a group. Apply a column AutoFilter, select the event type you are investigating, and sort by CreationDate to read the sequence of events chronologically. This takes under two minutes on a typical 10,000-row export.

Parsing AuditData in Excel using Power Query

In a blank workbook, use Data > From Text/CSV to open the export and select Transform Data. In the Power Query Editor, right-click the AuditData column header, choose Transform > JSON, then use the expand icon to split it into one column per property, such as ObjectId, SiteUrl, ClientIP and UserAgent. Power Query offers the properties it finds in the first 1,000 rows, so filter the Operations column first if you are after a property that only rare events carry.

Limitations to plan around

The 50,000-record export cap

An export from Audit (Standard) holds at most 50,000 rows, and from Audit (Premium) at most 1,000,000. If your search returns more, the CSV leaves records out, so check the result count against the limit before you export. The fix is to split the date range into shorter windows, each producing a separate CSV, then append them in Excel using Power Query's Append Queries function.

The 180-day window per search, and your retention period

Each search covers at most 180 days. Separately, records are only kept for your retention period: 180 days for users without an E5 licence, and one year for SharePoint activity by users with E5 (longer with an audit retention policy and add-on). Events older than that are permanently unavailable. For the full retention defaults by plan, see the SharePoint audit log retention reference.

Retiring workloads need two exports, not one

A deadline changes what "export the audit log" has to mean. The audit log records events: who opened, edited, shared or deleted something. It never contains the item itself. So when a workload is being retired, an audit export preserves the history of what happened and nothing of what was there, and the content has to be extracted separately and before the cut-off. Project Online is the recent example: it retired on 30 September 2026 with no published read-only period. How to export Project Online data before retirement covers the content half of that job. Note also that the retention limits above are your own plan's, not the retiring workload's, so pull the audit evidence inside your 180-day or one-year window regardless of the workload's date.

When the audit log is the wrong tool

Purview audit search is designed for compliance and security investigations involving specific events and timelines. It is not designed for routine administration tasks: generating a permission matrix for a site's libraries, finding where guests have access, or reporting the sharing links on a site. Those tasks belong in ShareMaster's Report Master, whose Security Matrix produces structured permission and sharing reports from SharePoint directly, one site at a time, and exports them to Excel without requiring Purview access.

Frequently Asked Questions

How long does Microsoft Purview keep SharePoint audit records?

For users without an E5 licence, records are kept for 180 days. For users with Office 365 or Microsoft 365 E5, or an E5 compliance add-on, SharePoint records are kept for one year by default, and an audit log retention policy with a further add-on can keep them longer. Records beyond the retention window are permanently gone.

What is the maximum number of records I can export at once?

A single Purview audit export is capped at 50,000 rows with Audit (Standard) and 1,000,000 rows with Audit (Premium). If your search returns more results, split the query into shorter date ranges or narrow by user or URL, then combine the resulting CSV files in Excel.

Do I need Global Admin access to export the SharePoint audit log?

No. The View-Only Audit Logs or Audit Logs role in Microsoft Purview is sufficient. Global Administrators and Compliance Administrators have these roles by default. A SharePoint Administrator alone does not have access to Purview audit search without an explicit Purview role assignment.

Can I export SharePoint permission data to Excel without using Purview?

Yes. The Security Matrix in ShareMaster's Report Master exports a site's permissions, SharePoint groups, sharing links and uniquely permissioned items to Excel, with no Purview or Compliance Admin access required. It needs site collection administrator access to the site you report on.

Learn more about Report Master's Excel permission exports

Try ShareMaster free for 14 days