Solved

Search Exchange Logs

Posted on 2010-11-15
3
284 Views
Last Modified: 2012-05-10
I am using Exchange 2010 on Windows Server 2008.  I have been asked to prove that an item (two contacts to be exact) was deleted and if possible who deleted it.  My guess is that they deleted it on the user's workstation that they belonged to.  So the who is probably impossible.  But I am trying to narrow down the time frame.  I am guessing there is some kind of log that should store this.  And I am guessing it is the transaction log.  But I am not sure if there is a good way to "read" them and better yet, filter them.  I have checked the security logs in Windows, but they are overwritten.  Or if I am looking in the wrong place, I would really appreciate some help.  Thanks.
0
Comment
Question by:wlramsey
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 6

Accepted Solution

by:
essaydave earned 250 total points
ID: 34141980
Hi mate

Have you tried using MFCMAPI?   You can download it from http://mfcmapi.codeplex.com/.  Once you've got it extracted, the following steps should show you what contacts have been recently deleted:

Open MFCMAPI and select Logon and Display Store Table (You'll need the user's profile configured for this) and select the profile you want to show.

Expand the Mailbox item, then Root Container, then Top of Information Store
Select Deleted Items, then right click on it and select Open Contents Table
Scroll across to the Message Class column, and sort by that column
Find the IPM.Contact type and see if the contact you're after shows up there, if they do:
In the bottom pane, look for the PR_LAST_MODIFIER_NAME property to find who deleted the contact.
The PR_MESSAGE_DELIVERY_TIME should then tell you when that contact was deleted (in GMT)
0
 
LVL 1

Author Comment

by:wlramsey
ID: 34142204
That is an awesome tool!  Unfortunately it looks like the user has already put the contact back which would have altered the Last Modifier name and timestamp.  I am really grateful for this information.  But is there any other place that I might be able to find this information?  I am going to check and see if it is on my backup tomorrow morning or see if he moved it back before the backup.  (I really wish I would have been made aware of this a lot sooner).  Thanks again.
0
 
LVL 1

Author Closing Comment

by:wlramsey
ID: 34152686
Awesome info!  I really like the software that you showed me.  Unfortunately my employee had already modified the contact again so that last time and last modifier fields had changed.  I was hoping for more of a log.  But this is better than nothing.  Thanks!
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Emails sent from iPhone rejected as spam 29 107
Distinguished username as email address 4 40
Configuring DNS Round Robin in Windows DNS server ? 8 65
Purge \Deleted Items? 2 27
This article aims to explain the working of CircularLogArchiver. This tool was designed to solve the buildup of log file in cases where systems do not support circular logging or where circular logging is not enabled
This article explains how to install and use the NTBackup utility that comes with Windows Server.
In this video we show how to create an Address List in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Organization >> Ad…
In this video we show how to create an Accepted Domain in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: First we need to log into the Exchange Admin Center. Navigate to the Mail Flow >> Ac…

740 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question