Any cloud administrator managing Azure should be acquainted with Azure Active Directory. It helps in the hybrid environment where your directory is synchronized with the cloud environment and facilitates the process to provision users and groups and keep consistency among environments. Azure Active Directory is a huge service and it has tons of functionalities and can be configured to meet your enterprise requirements. In today’s article, we are going to cover just a small but powerful portion — the Active Directory audit logs, where we can check all activity on any given Azure Active Directory using the Azure Portal, export to a CSV file, archive in a storage account, integrate with your SIEM (Security Information and Event Management) solution.
Reference: http://techgenix.com/step-by-step-guide-managing-azure-active-directory-audit-logs/