Search Exchange 2016 Audit Logs

Anthony K O365
Anthony K O365 used Ask the Experts™
on
Need to search Audit log ALL mailboxes affected by an admin action on a particular date range... The csv Output should have the following columns:


Search-MailboxAuditLog -Id <  > -LogonTypes admin -ShowDetails -StartDate 11/23/2018 -EndDate 11/27/2018 | select logontype,lastaccessed,logondisplayname,operationresult,operation,logonUserdisplayname
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Anthony K O365Messaging Consulting

Author

Commented:
Also the LogonUserDisplayName should be 'AdminJones' as an example
Saif ShaikhServer engineer

Commented:
You can use the following command:

Search-MailboxAuditLog -Identity nelson -LogonTypes Owner -StartDate (Get-Date).AddHours(-2) -ShowDetails | fl operation*,logonuserdisplayname,sourceitemsubject* | Export-CSV C:\AdminAuditLogResults.csv
Saif ShaikhServer engineer

Commented:
my command as below:
#Set-Mailbox -Identity “andy” -AuditOwner Create, SoftDelete, HardDelete, Update, Move, MoveToDeletedItems -AuditEnabled $true

#Search-MailboxAuditLog -ShowDetails -Identity “andy” -LogonTypes owner

#Search-MailboxAuditLog -Identity andy -LogonTypes Owner -StartDate (Get-Date).AddHours(-1) -ShowDetails

#Search-MailboxAuditLog -Identity nelson -LogonTypes Owner -StartDate (Get-Date).AddHours(-2) -ShowDetails | fl operation*,logonuserdisplayname,sourceitemsubject* | Export-CSV C:\AdminAuditLogResults.csv
Anthony K O365Messaging Consulting

Author

Commented:
Saif,

the mailboxes are already set for auditing. I need a way to output ALL the mailboxes into a csv...not just one at a time.
Server engineer
Commented:
Try:


get-mailbox | Search-MailboxAuditLog -Identity nelson -LogonTypes Owner -StartDate (Get-Date).AddHours(-2) -ShowDetails | fl operation*,logonuserdisplayname,sourceitemsubject* | Export-CSV C:\AdminAuditLogResults.csv
Anthony K O365Messaging Consulting

Author

Commented:
What exactly will this do for me?
Anthony K O365Messaging Consulting

Author

Commented:
After looking at the command closer, this is what I was looking for!

Thanks!!

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial