Skip to main content
Skip table of contents

Exchange Email Messages

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
Exchange Email MessagesBase RuleGeneral Email Handling MessageInformation
Added Mailbox PermissionSub RuleConfiguration Enabled : ApplicationConfiguration
Enabled Address List PagingSub RuleConfiguration Enabled : ApplicationConfiguration
Enabled MailboxSub RuleConfiguration Enabled : ApplicationConfiguration
Installed Admin ConfigSub RuleConfiguration Enabled : SystemConfiguration
Installed Data ConfigSub RuleConfiguration Enabled : SystemConfiguration
Installed Default PolicySub RuleConfiguration Deleted : ApplicationConfiguration
Installed Resource ConfigSub RulePolicy Enabled : ObjectPolicy
New Exchange ConfigSub RuleConfiguration Enabled : SystemConfiguration
Set Admin ConfigSub RuleConfiguration Loaded : Network AccessConfiguration
Set Exchange ConfigSub RuleConfiguration Enabled : ApplicationConfiguration
Set MailboxSub RuleConfiguration Enabled : ApplicationConfiguration
Set Owa PolicySub RuleConfiguration Enabled : ApplicationConfiguration
Set Recipient PolicySub RulePolicy Enabled : User/PasswordPolicy
Set Tenant VersionSub RulePolicy Enabled : AuditingPolicy
Set Transport ConfigSub RuleConfiguration Enabled : SystemConfiguration
Add Recipient PermissionSub RulePrivilege GrantedAccess Granted
Add Role Group MemberSub RulePrivilege GrantedAccess Granted
Mailbox Folder AccessedSub RuleObject AccessedAccess Success
New Mailbox SearchSub RuleConfiguration Modified : Directory ServicesConfiguration
New Mailbox CreatedSub RuleConfiguration Enabled : Directory ServicesConfiguration
New Mail ContactSub RuleConfiguration Modified : Directory ServicesConfiguration
Cancel Folder Move RequestSub RuleConfiguration Disabled : DatabaseConfiguration
Remove Unified GroupSub RuleGroup DeletedAccount Deleted
Send on BehalfSub RuleEmail Message SentInformation
Set ContactSub RuleConfiguration Modified : Directory ServicesConfiguration
Mailbox Search ModifiedSub RuleConfiguration Modified : Directory ServicesConfiguration
Unified Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
Unified Group AddedSub RuleGroup CreatedAccount Created
User Added to GroupSub RulePrivilege GrantedAccess Granted
Mailbox LoginSub RuleUser LogonAuthentication Success
User Account ModifiedSub RuleUser Account Attribute ModifiedAccount Modified
Email Marked for DeletionSub RuleEmail DeletedInformation
Email DeletedSub RuleEmail DeletedInformation
User Granted SendAs PermissionsSub RulePrivilege GrantedAccess Granted

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/AN/AN/A
SESSID<session>Text/StringSession information
COMMAND<command>Text/StringCommand name
USERTYPEN/AN/AType of user
USERKEYN/AN/AUser key informations hexadecimal value
WORKLOAD

<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODE<result>Text/StringResults
OBJECT<object>Text/StringObject name
USER<login>
<domainorigin>
<account>
<domainimpacted>
Text/StringSource user name
SIPN/AN/ASource IP address
OBJECTNAMEN/AN/AN/A
PARAMETERS<sessiontype>
<domainimpacted>
<account>
Text/StringN/A
MODIFIEDPROPERTIESN/AN/AN/A
EXTERNALACCESSN/AN/AN/A
ORIGINATINGSERVER<sender>Text/StringN/A
ORGANIZATIONNAMEN/AN/AN/A
LOGONTYPE<group>Text/StringN/A
MAILBOXOWNER<account>Text/StringN/A
MAILBOXMASTERN/AN/AN/A
LOGONUSERSIDN/AN/AN/A
LOGONUSERDISPLAYNAMEN/AN/AN/A
USERAGENT<useragent>Text/StringN/A
CLIENTIPADDRESS<sipv4>
<sipv6>
<sip>
<sport>

IP Address


Number

N/A
CLIENTPROCESSNAMEN/AN/AN/A
CLIENTVERSION<version>NumberN/A
FOLDER<subject>Text/StringN/A
CROSSMAILBOXOPERATIONSN/AN/AN/A
DESTMAILBOXN/AN/AN/A
DESTMAILBOXOWNERN/AN/AN/A
DESTMAILBOXMASTERN/AN/AN/A
DESTFOLDERN/AN/AN/A
FOLDERSN/AN/AN/A
AFFECTEDITEMSN/AN/AN/A
ITEM<objectname>Text/StringN/A
ITEM<subject>Text/StringN/A
SENDASUSER<sender>Text/StringN/A
SENDONBEHALFOFUSER<sender>Text/StringN/A
"Subject":"N/AN/AN/A
"Subject":"N/AN/AN/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.