> For the complete documentation index, see [llms.txt](https://docs.cipp.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cipp.app/user-documentation/tenant/administration/audit-logs/search-results.md).

# Search Results

Opening a manual search shows the audit records it returned, straight from the tenant. The heading is the name you gave the search, falling back to the search ID where no name was recorded. Records arrive unsorted, so use the table's own sorting and filtering to work through them.

{% hint style="info" %}
A search only has records once it has finished running. If the table is empty, check the search's status on the Manual Searches tab: anything still showing `notStarted` or `running` has not completed yet.
{% endhint %}

## Action Buttons

| Button           | Description                                                                                                                                          |
| ---------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- |
| Back to Searches | Returns you to the audit log searches list.                                                                                                          |
| Process Logs     | Runs these results through your alert rules after confirmation, generating alerts for anything that matches. Records that match no rule are ignored. |

## Table Details

The properties returned are for the Graph resource type `microsoft.graph.security.auditLogRecord`. For more information on the properties please see the [Graph documentation](https://learn.microsoft.com/en-us/graph/api/resources/security-auditlogrecord?view=graph-rest-1.0#properties).

## Audit Log Details

Selecting a row opens a flyout with the full record laid out in two sections. The first covers the record itself, and the second expands the audit data payload, which is where the detail specific to that operation lives.

CIPP does some work to make the record readable. Object IDs are resolved to the display names of the directory objects they refer to, both as property values and where they appear inside longer strings, with the original identifier available on hover. Any identifier that cannot be resolved is marked as such rather than silently left raw. Where the record carries a client IP address, an approximate geographic location is shown alongside it.

## Table Actions

<table><thead><tr><th>Action</th><th>Description</th><th data-type="checkbox">Bulk Action Available</th></tr></thead><tbody><tr><td>More Info</td><td>Opens the Extended Info flyout with the full details for the selected row.</td><td>false</td></tr></tbody></table>

***

## Feature Requests / Ideas

We value your feedback and ideas. Please raise any [feature requests](https://github.com/CyberDrain/CIPP/issues/new?template=feature.yml) on GitHub.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.cipp.app/user-documentation/tenant/administration/audit-logs/search-results.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
