Recover Deleted Emails from the Exchange 2003 Transaction Logs.

Posted on 2004-08-10
Last Modified: 2011-10-03
I need to collect all the email sent to and from a specific user.

Exchange was setup to save deleted items for 7 days. I need the information from the last 30 days. I have the transaction logs for that time period. If I do a search of all the logs for "", I can see all the emails but they are not readable. I guess they are  saved in some other format. Their should be only about 15 emails scattered in 9-10 log files.

My questions are?
1. What format are they saved in?
2. How can I get to the point of actually reading these emails, and seeing attachments if their are any?
3. Is their a utility that I can say suck all the email for "" from the transaction logs and put them in this directory?

Question by:jeffreywfinch
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
LVL 104

Accepted Solution

Sembee earned 250 total points
ID: 11772691
The transaction logs are not designed to be read by anything other than Exchange.

The only way that I can think you will be able to do this is to build another Exchange server, create mailboxes for all the clients that are on the server then replay the Transaction logs.

That is pure theory BTW - I have never done it.

Depending on how critical it is, I would seriously consider going to Microsoft for advice.


Author Comment

ID: 11811997
This exchange server actually exists in VMware so a restore of the log file wouldn't be too difficult but it really isn’t worth the effort. I did find out however that the actual email body exist in the log files as text and is easily decoded. So if you open the log in Internet explorer you can scroll through and read all the emails. IE will decode text, rich text, or HTML. The attachments are encoded as they were transmitted with SMTP so you can manually decode them with mime, or whatever format they were moved from server to server in.  As far as I can tell, all the exchange server control messages are in a proprietary Microsoft format. To me the control messages were garbage so I just ignored them.

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn to move / copy / export exchange contacts to iPhone without using any software. Also see the issues in configuration of exchange with iPhone to migrate contacts.
A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
In this video we show how to create a Contact in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Contact ta…
how to add IIS SMTP to handle application/Scanner relays into office 365.
Suggested Courses
Course of the Month3 days, 17 hours left to enroll

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question