I am trying to use PowerShell and the Get-MgAuditLogDirectoryAudit cmdlet to monitor certain events, such as the following:
Get-MgAuditLogDirectoryAudit -Filter "LoggedByService eq 'PIM'" | Select -First 1 | FL
ActivityDateTime : 17/06/2022 08:54:10
ActivityDisplayName : Remove member from role (PIM activation expired)
AdditionalDetails : {RoleDefinitionOriginId, RoleDefinitionOriginType, TemplateId, Metadata}
Category : RoleManagement
CorrelationId : f998b539-74cc-4e27-9c33-800ddda42018
Id : PIM_f998b539-74cc-4e27-9c33-800ddda42018_0CH8K_7752548
InitiatedBy : Microsoft.Graph.PowerShell.Models.MicrosoftGraphAuditActivityInitiator
LoggedByService : PIM
OperationType : RemoveActivatedRole
Result : success
ResultReason :
TargetResources : {c4e39ds9-1100-34d3-8c65-fb160da0071f, 2ZgtrAAR00aMZfsWDaAHH-5TcmutkjtCiF12YUIjO4s-1, f7ddc610-e91d-4…}
AdditionalProperties : {}
However, I need to retrieve certain log entries that happened in the last x hours, but no matter how I try to filter on ActivityDateTime, I always get the following error (I've tried all possible combinations and formats!):
Get-MgAuditLogDirectoryAudit_List1: Invalid filter clause
If ActivityDateTime is not supported as a filter parameter, how can we search log entries after a certain date or within a certain timeframe? Thank you!
Best regards, Nuno