Hi Paul,
To troubleshoot this issue, follow :
Verify that the filter syntax you are using is correct. Double-check the spelling and ensure that there are no typos or missing characters.
Check if the data.office365.subscription field is correctly populated for the events you are trying to filter. It's possible that the events you are expecting to see do not have the 'Audit.AzureActiveDirectory' value in the data.office365.subscription field.
Ensure that the data.office365.UserID field is correctly populated for the events related to ID you want to filter. It's possible that there is a discrepancy in the data or that the field is not populated as expected.
Verify that the events you are trying to filter are within the time range you have specified. It's possible that the events you are looking for occurred outside the specified time range.
If the issue persists after following these steps, please provide the version of Wazuh you are using.