Flat File - Microsoft Exchange Tracking Logs
The message tracking log is a detailed record of all activity as mail flows through the transport pipeline on Mailbox servers and Edge Transport servers. You can use message tracking for message forensics, mail flow analysis, reporting, and troubleshooting.
On the Exchange server, enable tracking logs.
You must enable this feature on each server where you want to track messages. To enable message tracking for multiple servers, you can use a server policy. The size of the message tracking logs can increase quickly on bridgehead servers that process many inbound and outbound messages. Ensure that you have adequate disk space for tracking log files.
- Start Exchange System Manager and display the properties of the server where you want to enable message tracking.
- On the General tab, select the Enable message tracking check box.
- To track the subject line for each message, select the Enable subject logging and display check box. This also tracks envelope information, such as To, From, and Date Sent.
- Ensure the default log file directory, C:\Program Files\ExchSrvr\<SERVERNAME> is what you want for your site.
- Create a host record for the Exchange server's system. See the Host Records topic in the LogRhythm SIEM Help.
- Install and configure a System Monitor Agent on the Exchange server.
- Establish a Log Processing (MPE) Policy for the Microsoft Exchange Message Tracking Log Log Source Type, or use the default.
After you configure the device, you must also configure LogRhythm according to the instructions provided on the overview page of this guide. Only Global Admins or Restricted Admins with elevated View and Manage privileges can take this action.
The name of the log message source is Flat File - Microsoft Exchange Message Tracking Log. In addition, when configuring this log source:
- For Log Message Processing Engine (MPE) Policy, select LogRhythm Default.
- On the Flat File Settings tab, enter the following:
- File Path. <path to log file, including the file name and extension>
- Date Parsing Format. Defines regular expression (regex) patterns to be used by a System Monitor Agent for parsing date information from log files.
Example: ExchangeLog where ExchangeLog is a Date Format defined as<UTC><yy>-<M>-<d> <h>:<m>:<s>
Configure LogRhythm for Microsoft Exchange Tracking
Only Global Admins or Restricted Admins with elevated View and Manage privileges can take this action.
- In the Client Console on the main toolbar, click Deployment Manager.
- Click the System Monitors tab.
- Double-click the System Monitor Agent that will collect the information.
The System Monitor Agent Properties dialog box appears. - Click the Agent Settings tab.
- Right-click anywhere in the Log Message Sources Collected by this Agent grid, and then click New.
- Click the Basic Configuration tab.
- For Log Message Source Type, select Flat File - Microsoft Exchange Message Tracking Log.
- For Log Message Processing Engine (MPE) Policy, select LogRhythm Default.
Click the Flat File Settings tab.
Populate the flat file boxes with the following information:
File Path. Define the PATH to the log file or directory. If you chose directory, ensure the file extension is specified (for example,
\PATH\*.log
). Example:C:\Program Files\Exchsrvr\MYSERVER.log\*.log
Date Parsing Format. Defines regular expression (regex) patterns to be used by a System Monitor Agent for parsing date information from log files.
Example: ExchangeLog where ExchangeLog is a Date Format defined as<UTC><yy>-<M>-<d> <h>:<m>:<s>
- To save the configuration, click OK, and then click OK again.