Fix Purview Audit Search Not Finding Text in SharePoint Documents
Question details
Microsoft Purview Audit Search returns zero results when trying to locate specific words or text hidden inside Word documents stored in a SharePoint Online library.
- Product
- Microsoft Purview
- Device & OS
- not provided
- Scenario
- An administrator or compliance officer is attempting to use the Purview audit keyword field to search the internal contents of documents across SharePoint.
- Observed behavior
- The search fails to find the expected documents because the audit keyword field primarily indexes activity data, metadata, and file names, rather than arbitrary text within the document body.
Verify that you have the appropriate Audit or eDiscovery administrator permissions in the Microsoft Purview compliance portal, and note that recently uploaded or modified SharePoint files may take up to 24 hours to be fully indexed.
Search by File Name and Metadata Instead of Document Content
Because Purview audit searches do not reliably parse arbitrary text inside document bodies, you should alter your search strategy to query file names, prefix wildcards, and indexed metadata.
The Purview audit log is designed to track user activities and system events. Its keyword field is optimized for finding file names, specific metadata phrases, and supported indexed properties, not deep content discovery. For finding text inside files, Content Search or eDiscovery tools are the proper Microsoft solutions.
Navigate to the Microsoft Purview compliance portal and select 'Audit' from the left-hand navigation pane.
In the 'Search' box, type the prefix of the file name you are looking for and append an asterisk (*) as a wildcard. For example, type 'Dakota*' or 'test*'.
Click the 'Search' button and review the activity logs. The results will display matched file names and related SharePoint activities rather than highlighting internal document text.

Allow Sufficient Time for SharePoint Indexing
If you recently renamed a file in SharePoint to make it searchable via the Purview Audit log, you must wait for the background indexing process to complete before the search yields results.
Experience Seamless Document Management with WPS Office
While Microsoft Purview handles complex enterprise compliance and audit logs, everyday document creation and editing should remain straightforward. WPS Office is a highly compatible, lightweight, and free alternative to Microsoft Office, offering an intuitive experience for managing Word, Excel, and PowerPoint files without the heavy enterprise overhead.
- 1. Download and install WPS Office: Visit the official WPS website and download the free installation package for your operating system.
- 2. Open your existing documents: Launch WPS Office and drag-and-drop your existing Word, Excel, or PowerPoint files directly into the application.
- 3. Save in standard formats: Edit your documents and save them in standard Microsoft formats to ensure smooth sharing with colleagues and compliance systems.

Frequently Asked Questions
Why doesn't Microsoft Purview Audit search inside document text?
The Purview audit log keyword field is primarily engineered to track user activities, file names, and indexed metadata properties. It does not perform deep crawling of text within ordinary document contents. To search inside documents, you should use Content Search or eDiscovery tools.
Can I use wildcards in Purview Audit Search?
Yes, you can use an asterisk (*) as a wildcard in the search field. It is most effective when used for prefix matching against file names, such as typing 'project*' to find any file names starting with the word 'project'.
How long does it take for renamed SharePoint files to become searchable in Purview?
After renaming or modifying a file in SharePoint Online, it can take up to 24 hours for the background search indexing process to update. Audit logs will not reflect searches for the new name until this indexing is fully completed.




