Fix Missing SearchQueryPerformed Records in SharePoint Audit API
Question details
The user is unable to find SearchQueryPerformed records within the SharePoint Online Audit Log subscription API.

- Product
- SharePoint Online
- Device & OS
- not provided
- Scenario
- Querying the SharePoint Online Audit Log subscription API to retrieve search query operations.
- Observed behavior
- The API returns various operations, but SearchQueryPerformed records are unexpectedly missing.
Ensure you have the necessary global administrator or SharePoint administrator roles to access the Microsoft 365 Audit Log, and that audit logging is currently enabled for your tenant.
Verify Audit Log and SharePoint Activity API Settings
Check for changes in Microsoft's API schema, ensure correct permissions, and confirm event availability.
Review the latest Microsoft 365 Audit Log and SharePoint Activity API documentation to see if the SearchQueryPerformed event schema or retention policies have been updated or deprecated.
Confirm your tenant permissions and ensure the content subscription type is correctly configured to receive SearchQueryPerformed events.
Adjust the time range in your API request to ensure the events you are looking for fall within the currently retained data window.

Seek Assistance in the Microsoft Q&A Community
Since this is a specific Microsoft API issue, reaching out to Microsoft Graph and SharePoint experts is highly recommended.
Looking for a Lightweight and Compatible Office Solution?
While troubleshooting SharePoint API integrations, if you need a reliable desktop office suite, WPS Office provides a free, lightweight, and easy-to-use alternative. It offers full compatibility with Microsoft Office file formats and a familiar user interface.
- 1. Download the installer: Visit the official WPS Office website and download the free version for your operating system.
- 2. Install WPS Office: Run the setup file and follow the quick installation wizard.
- 3. Open existing files: Launch WPS Office and open your .docx, .xlsx, or .pptx files directly without losing formatting.

Frequently Asked Questions
Why do some events disappear from the Microsoft 365 Audit Log?
Events can disappear if Microsoft deprecates an operation, changes the event schema, or if the data exceeds your tenant's retention policy limit.
How long are SharePoint audit logs retained?
By default, audit records are retained for 180 days for users with standard Microsoft 365 licenses, though this can vary based on your specific licensing and customized retention policies.
Can WPS Office integrate directly with SharePoint?
Yes, WPS Office can open documents stored in cloud services like SharePoint and OneDrive, allowing you to edit and save files seamlessly while acting as a Microsoft Office alternative.
What permissions are required to access the SharePoint Activity API?
To access the API, you typically need to be assigned the Global Administrator or SharePoint Administrator role, and the application requires specific Microsoft Graph API permissions such as AuditLog.Read.All.




