Fix Microsoft Purview Audit Returning No Results for Folders
Question details
The user is trying to find audit log events for a specific document library folder in Microsoft Purview but gets zero results when using the folder's URL.
- Product
- Microsoft Purview
- Device & OS
- not provided
- Scenario
- Searching the Microsoft Purview Audit logs using a SharePoint document library folder URL in the 'File, folder, or site' field.
- Observed behavior
- The search successfully returns results for generic keywords and dates, but returns absolutely no results when a folder URL containing encoded characters or query parameters is used.
Ensure you are assigned the appropriate Audit Logs role in Microsoft Purview and that the folder URL you are copying exactly matches the SharePoint environment structure.
Use a plain site and folder path instead of an encoded URL
Remove URL encoding such as '%20' (spaces) and query parameters from the folder link to allow the Purview audit search engine to accurately match the folder path.
Microsoft Purview's audit search relies on exact string matching for file and folder paths. When you copy a folder link directly from a web browser, it often includes HTML-encoded characters (like %20 for spaces) and query parameters (like ?id=...). The audit search engine fails to translate these encoded URLs, resulting in zero matches.
Navigate to the folder in SharePoint. Instead of copying the entire web address from the browser bar, note the plain text path of the site and document library folder.
Paste the copied URL into a text editor. Replace any '%20' characters with standard space characters, and delete any query parameters starting with '?' at the end of the URL.
Go back to Microsoft Purview, paste the cleaned, plain text folder path into the 'File, folder, or site' field, and initiate your search.
Contact Microsoft Support for server-side investigation
If cleaning the folder path does not resolve the issue, the problem may lie in backend audit data synchronization, requiring Microsoft Support.
Enhance Your Daily Productivity with WPS Office
While Microsoft Purview handles enterprise compliance and backend auditing, managing your daily documents doesn't have to be complex or expensive. WPS Office is a lightweight, fully featured suite that provides seamless format compatibility with Microsoft Word, Excel, and PowerPoint files without the heavy subscription costs.
- 1. Download the installer: Visit the official WPS Office website and download the free installation package for your operating system.
- 2. Install the software: Run the installer and follow the quick on-screen instructions to set up the suite on your device.
- 3. Open your files instantly: Launch WPS Office and directly open your existing Microsoft Office files with perfect formatting retention.

Frequently Asked Questions
Why does my SharePoint folder URL contain %20?
The '%20' is an HTML-encoded character used by web browsers to represent a blank space. URLs cannot contain actual spaces, so browsers automatically convert spaces in your folder names into '%20'. Microsoft Purview searches often fail if these aren't converted back to normal spaces.
How long does it take for audit log events to appear in Microsoft Purview?
Audit log events are not always instantaneous. Depending on the Microsoft 365 service, it can take anywhere from 30 minutes to up to 24 hours for an event to be processed and appear in the Purview audit log search results.
Can I search for a specific file instead of an entire folder?
Yes. You can search for a specific file by entering the exact file name or the complete plain text path (including the file extension) into the 'File, folder, or site' search field in Microsoft Purview.
Why do keyword searches work but folder paths do not?
Keyword searches match broad metadata and text strings across your entire environment. Folder paths require exact directory matching, which is easily broken by URL query parameters (like '?view=...') or encoded characters that differ from the actual backend directory name.




