There are two "sets" of JSON code for integrating Admin By Request with Microsoft Sentinel:
Auditlog JSON code
Events JSON code