Symantec Vault and Microsoft Exchange Journaling Email Auditing

Posted on 2009-12-18
Last Modified: 2012-05-08
I'm sure this has been done, I'm just facing difficulties locating an answer.

I'm using Exchange 2003 and Symantec Vault 9.0.  The vault mailbox archiving has been excellent and I'm happy with the results, but now I have added Journaling to the Exchange Server and the Vault server and I'm a bit stumped.

I need to be able to search the Journaling Mailbox on the Vault for quarterly audits based on keywords.

I can see the Journal Mailbox using OWA, but the problem is that the Journaled emails are all attachments and therefore the message bodies cannot be search via OWA.

I cannot attach to the Journal mailbox in Enterprise Vault, I just get a message, "You can not search as you are not subscribed to any vaults".

I did use the "Journaling Task" on Vault for the Journal mailbox.  I don't know if this has different rules for search and recovery than normal user mailboxes.

I'm already getting nervous about the size.  Journaling has been on for 1 day and the mailbox is 150MB with the EV task running.  That would put me at 1 GB/week and I can't sustain that on the exchange server.  I'll need to purge the journal messages from Exchange when the EV task runs.

I was thinking that maybe I should redo the journaling as a normal mailbox in Enterprise Vault to make it easier to search.  What do you think?

I apologize for not putting Enterprise Vault in the "zones" but it wasn't listed.

Question by:ShopLiftin
    LVL 33

    Expert Comment

    Journaling and auditing feature are not done in Exchange unless oyu use Exchange 2010, those features are builtin in Exchange 2010, if you want to do it in Exchange 2003 then you must use other third party solution.
    LVL 42

    Accepted Solution

    You're probably using EV 2007 or 8.0.

    Here's what you need to do:

    Go into the EV Admin Console -> Archives -> Journal Archive

    Give your account access to the archive. This will give you basic search capability.  To provide extensive search capabilities take a look at EV Compliance Acclerator and/or Discovery Accelerator (used for EDiscovery)

    With regards to the size this is normal since it gets every email inbound/outbound/internal.  Make sure you have EV 8.0, if you are using separate vaults for archive and journaling make sure you configure ISIS (single instance) so that you're not duplicating data.

    EV uses the Exchange journal task so you can only journal by mailstore.  If you want to keep the storage down you can do several things.

    1.  Move only needed users to a different mail store and journal only this mailstore
    2.  Purchase a NAS device that is supported and create a NTFS share, set a vault store parition to rollover to this mailsotre after a certain date/size.
    Let me know if you need any further assistance

    Author Comment


    You are right.  It is 8, the 9.0 was a type error.

    Thanks, adding permissions to the Archive itself was certainly the answer I was looking for.

    I'm in a ESX environment and have plenty of space, but I will eventually lock down the partition, create a new one and make a disk backup of the current partition.

    Thanks for the assist!

    LVL 42

    Expert Comment

    No problem.  90% of our installs are on VI3/vSphere.   Just keep in mind that the ingestion rate is a little slower but retrieval is about the same.  Once everyone is ingested your delta is only 1 day worth.

    Setup ISIS, (vault store sharing), it will save you a lot of space in the long run.

    Author Closing Comment

    Paulsolov was right on the money with his answer.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Better Security Awareness With Threat Intelligence

    See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

    Set OWA language and time zone in Exchange for individuals, all users or per database.
    Check out this infographic on what you need to make a good email signature that will work perfectly for your organization.
    In this video we show how to create a User Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Recipients >> Mailb…
    The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    18 Experts available now in Live!

    Get 1:1 Help Now