How to Generate SharePoint Online Audit Log Reports
Question details
Administrators need to generate audit log reports to track SharePoint document and item activity, such as views, edits, and deletions, but are encountering issues where the reports fail to generate or logs are missing.
- Product
- SharePoint Online
- Device & OS
- not provided
- Scenario
- Tracking document and item views, edits, and deletions for compliance and administrative auditing purposes.
- Observed behavior
- The generated audit logs return empty or missing events despite auditing being seemingly enabled.
Ensure you have the necessary administrator permissions in the Microsoft Purview compliance portal and verify that auditing was turned on for your organization before the events you wish to track occurred.
Troubleshoot Missing SharePoint Audit Log Reports
Follow these diagnostic steps to resolve issues where SharePoint Online audit logs fail to generate or return empty search results.
Audit logs rely on accurate timeframes and pre-configured organizational settings. If reports are missing data, it is typically related to search parameters, browser caching, or backend synchronization delays.
Adjust the date range in your audit log search query to encompass a wider time frame. This ensures that the specific document or item events fall within the selected dates, accounting for timezone differences or processing delays.
Browser cache can sometimes interfere with the Microsoft Purview compliance portal interface. Clear your current browser cache and cookies, or attempt to run the audit log report using a completely different web browser.
Confirm that audit logging was actively enabled for your Microsoft 365 organization before the tracked events occurred. Logs cannot be generated retroactively; if auditing was turned on after a file was deleted, that deletion will not appear.
If you have confirmed that relevant events occurred after auditing was enabled and changing browsers did not resolve the issue, contact Microsoft 365 Support. The backend team may need to investigate the tenant and collect server logs to restore functionality.
Manage Your Daily Documents Effortlessly with WPS Office
While Microsoft 365 and SharePoint handle complex enterprise compliance and audit logs, WPS Office provides a free, lightweight, and highly compatible alternative for your everyday document creation and editing needs.
- 1. Download the software: Visit the official WPS website and download the installation package for your operating system.
- 2. Install WPS Office: Run the installer and follow the on-screen prompts to complete the lightweight installation process.
- 3. Open your Microsoft formats: Launch WPS Office and directly open your existing .docx, .xlsx, or .pptx files to begin editing immediately.

Frequently Asked Questions
Why are my SharePoint audit log reports returning empty results?
Reports often return empty if auditing was not enabled in the Microsoft Purview compliance portal prior to the events occurring, if the selected search date range is too narrow, or if there is a localized browser caching issue.
How do I turn on auditing for SharePoint Online?
Auditing is enabled within the Microsoft Purview compliance portal. Navigate to the 'Audit' section; if auditing is not currently turned on for your organization, a banner will prompt you to start recording user and admin activity.
How long does it take for SharePoint events to show up in the audit log?
After an event (like a document view or edit) occurs in SharePoint Online, it can typically take anywhere from 15 minutes up to 24 hours for the corresponding record to be processed and appear in the audit log search results.
Who has permission to generate audit log reports in SharePoint Online?
Only users assigned the appropriate permissions, such as Global Administrators or users granted the 'Audit Logs' role in the Microsoft Purview compliance portal, can search and generate these reports.




