Skip to main content
Skip table of contents

MailBox Search

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
MailBox SearchBase RuleGeneral MS Exchange Mailbox Store InformationInformation
Set - Admin Audit Log ConfigSub RuleGeneral AuditOther Audit Success
Remove - Mailbox PermissionSub RuleUser Account Attribute ModifiedAccount Modified
Admin Added Mailbox PermissionSub RuleFile Monitoring Event - PermissionsAccess Success
New - Migration BatchSub RuleKey Migration OperationOther Audit Success
Set - Mailbox SearchSub RuleGeneral MS Exchange InformationInformation
Admin Add Recipient PermissionSub RuleGeneral CLOUD MessageInformation
Set - CAS MailboxSub RuleGeneral MS Exchange WarningWarning

Mapping with LogRhythm Schema

Device Key in Log MessageLogRhythm SchemaData TypeSchema Description
TSN/AN/AN/A
SESSID<session>Text/StringSession information
COMMAND<command>
<tag1>
Text/StringCommand name
USERTYPE<tag2>Text/StringType of user
USERKEY<sender>Text/StringUser key informations hexadecimal value
WORKLOAD

<process>

<vendorinfo>

Text/StringAudit log record type
RESULTCODE<result>Text/StringResults
OBJECT<object>Text/StringObject name
USER<login>Text/StringSource user name
SIP<sip>
<sport>

IP Address

Number

Source IP address
OBJECTNAMEN/AN/AN/A
PARAMETERS<sessiontype>Text/StringN/A
MODIFIEDPROPERTIESN/AN/AN/A
EXTERNALACCESSN/AN/AN/A
ORIGINATINGSERVER<sname>Text/StringN/A
ORGANIZATIONNAME<domain>Text/StringN/A
LOGONTYPEN/AN/AN/A
MAILBOXOWNERN/AN/AN/A
MAILBOXMASTERN/AN/AN/A
LOGONUSERSIDN/AN/AN/A
LOGONUSERDISPLAYNAMEN/AN/AN/A
USERAGENTN/AN/AN/A
CLIENTIPADDRESSN/AN/AN/A
CLIENTPROCESSNAMEN/AN/AN/A
CLIENTVERSIONN/AN/AN/A
FOLDERN/AN/AN/A
CROSSMAILBOXOPERATIONSN/AN/AN/A
DESTMAILBOXN/AN/AN/A
DESTMAILBOXOWNERN/AN/AN/A
DESTMAILBOXMASTERN/AN/AN/A
DESTFOLDERN/AN/AN/A
FOLDERSN/AN/AN/A
AFFECTEDITEMSN/AN/AN/A
ITEMN/AN/AN/A
SENDASUSERN/AN/AN/A
SENDONBEHALFOFUSERN/AN/AN/A

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.