Backup Data Searched

Sent when a user searches backed-up data.

General Information

Event ID: vdc.workload_v0.tenant_v0.audit_v0.microsoft.search_v0

Event message details: Sent with data.audit.action set to Backup Data Searched.

Severity: Info

Workloads: Veeam Data Cloud for Microsoft 365

Parameters

Parameters

Parameter Name

Description

Example

specversion

Event schema version.

20250815

source

System that sent the event. Possible values: CONTROLPLANE, M365.

M365

timestamp

Time when the event happened, in RFC3339Nano format and the UTC time zone.

2026-08-04T09:18:42Z

type

Event ID.

vdc.workload_v0.tenant_v0.audit_v0.microsoft.search_v0

actor.kind

Actor type that triggered the event. Possible values: user, system, service_account.

user

actor.identifier

Actor identifier.

alice@example.com

organizationReference.workloadTenantId

Workload tenant ID.

tenant_12345

data.audit.action

Action that represents the event.

Backup Data Searched

data.audit.actionGroup

High-level classification of the action category. Possible values: DATA_ACCESS, ACCESS_MANAGEMENT, DATA_MANAGEMENT, PROTECTION_MANAGEMENT.

DATA_ACCESS

data.audit.targetDisplayName

Display name of the target of this event. If the target is unknown or not applicable, the value is Unknown or N/A.

alice@contoso.com

data.search.application

Microsoft 365 application that the search was scoped to. Possible values: OUTLOOK, SHAREPOINT, ONEDRIVE, TEAMS.

OUTLOOK

data.search.target

Display name of the searched scope or the root, for example a mailbox name or a SharePoint site title.

alice@contoso.com

data.search.searchValue

Free-text search query entered by the user. Populated only for basic searches.

Q4 budget

data.search.restorePoint

Restore point the search was run against, as an ISO-8601 UTC timestamp.

2025-09-18T14:33:20Z

data.search.criteria[].field

Label of the searched field, for example Subject or From.

Subject

data.search.criteria[].condition

Condition operator. Possible values: Equal, NotEqual, Contains, NotContain.

Equal

data.search.criteria[].value

Condition value.

Q4 budget

data.tenant.id

Tenant ID.

tenant_12345

data.workload.type

Workload type.

M365

Event Example

{
  "specversion": "20250815",
  "source": "M365",
  "timestamp": "2026-08-04T09:18:42Z",
  "type": "vdc.workload_v0.tenant_v0.audit_v0.microsoft.search_v0",
  "actor": {
    "identifier": "alice@example.com",
    "kind": "user"
  },
  "organizationReference": {
    "workloadTenantId": "tenant_12345"
  },
  "data": {
    "audit": {
      "action": "Backup Data Searched",
      "actionGroup": "DATA_ACCESS",
      "targetDisplayName": "alice@contoso.com"
    },
    "search": {
      "application": "OUTLOOK",
      "target": "alice@contoso.com",
      "searchValue": "Q4 budget",
      "restorePoint": "2025-09-18T14:33:20Z"
    },
    "tenant": {
      "id": "tenant_12345"
    },
    "workload": {
      "type": "M365"
    }
  }
}