Backup Data Browsed
Sent when a user browses backed-up data.
General Information
Event ID: vdc.workload_v0.tenant_v0.audit_v0.microsoft.browse_v0
Event message details: Sent with data.audit.action set to Backup Data Browsed.
Severity: Info
Workloads: Veeam Data Cloud for Microsoft 365
Parameters
|
Parameter Name |
Description |
Example |
|---|---|---|
|
specversion |
Event schema version. |
20250815 |
|
source |
System that sent the event. Possible values: CONTROLPLANE, M365. |
M365 |
|
timestamp |
Time when the event happened, in RFC3339Nano format and the UTC time zone. |
2026-08-04T09:18:42Z |
|
type |
Event ID. |
vdc.workload_v0.tenant_v0.audit_v0.microsoft.browse_v0 |
|
actor.kind |
Actor type that triggered the event. Possible values: user, system, service_account. |
user |
|
actor.identifier |
Actor identifier. |
alice@example.com |
|
organizationReference.workloadTenantId |
Workload tenant ID. |
tenant_12345 |
|
data.audit.action |
Action that represents the event. |
Backup Data Browsed |
|
data.audit.actionGroup |
High-level classification of the action category. Possible values: DATA_ACCESS, ACCESS_MANAGEMENT, DATA_MANAGEMENT, PROTECTION_MANAGEMENT. |
DATA_ACCESS |
|
data.audit.targetDisplayName |
Display name of the target of this event. If the target is unknown or not applicable, the value is Unknown or N/A. |
Inbox |
|
data.browse.application |
Microsoft 365 application that was browsed. Possible values: OUTLOOK, SHAREPOINT, ONEDRIVE, TEAMS. |
OUTLOOK |
|
data.browse.outlook |
Label for the Outlook (mailbox) data that was browsed. Populated only when data.browse.application is OUTLOOK. |
(browse items) Inbox / Subfolder |
|
data.browse.sharePoint |
Label for the SharePoint data that was browsed. Populated only when data.browse.application is SHAREPOINT. |
(browse sites) Marketing / Documents |
|
data.browse.oneDrive |
Label for the OneDrive data that was browsed. Populated only when data.browse.application is ONEDRIVE. |
(browse files) alice@contoso.com / Documents |
|
data.browse.teams |
Label for the Microsoft Teams data that was browsed. Populated only when data.browse.application is TEAMS. |
(browse channels) Engineering / General |
|
data.tenant.id |
Tenant ID. |
tenant_12345 |
|
data.workload.type |
Workload type. |
M365 |
Event Example
|
{ |