Hi,
I am trying to search for a list of users who have not logged into the azure ad past 30 days
Can you please help
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/
You may have to ask Azure AD which users have not logged in.