Description
...
Expand | ||
---|---|---|
| ||
[ |
Table Fields
Field | Description |
---|---|
TABLE | Office365ExchangeItemAggregated |
RECORDTYPE | RecordType is “50” |
, more details about RecordType here. | |
APPID | AppId - No available documentation for this field. |
CLIENTAPPDID | ClientAppId - No available documentation for this field. |
LOGONTYPE | LogonType - Indicates the type of user who accessed the mailbox and performed the operation that was logged. |
INTERNALLOGONTYPE | InternalLogonType - Reserved for internal use. |
MAILBOXGUID | MailboxGuid - The Exchange GUID of the mailbox that was accessed. |
MAILBOXOWNERUPN | MailboxOwnerUPN - The email address of the person who owns the mailbox that was accessed. |
MAILBOXOWNERSID | MailboxOwnerSid - The SID of the mailbox owner. |
MAILBOXOWNERMASTERSID | MailboxOwnerMasterAccountSid - Mailbox owner account's master account SID. |
LOGONUSERSID | LogonUserSid - The SID of the user who performed the operation. |
LOGONUSERNAME | LogonUserDisplayName - The user-friendly name of the user who performed the operation. |
EXTERNALACCESS | ExternalAccess - This is true if the logon user's domain is different from the mailbox owner's domain. |
ORIGINATINGSERVER | OriginatingServer - This is from where the operation originated. |
ORGNAME | OrganizationName - The name of the tenant. |
CLIENTINFO | ClientInfoString - Information about the email client that was used to perform the operation, such as a browser version, Outlook version, and mobile device information. |
CLIENTADDR | ClientIPAddress - The IP address of the device that was used when the operation was logged. |
CLIENTMACHINE | ClientMachineName - The machine name that hosts the Outlook client. |
CLIENTPROCESS | ClientProcessName - The email client that was used to access the mailbox. |
CLIENTVERSION | ClientVersion - The version of the email client. |
CLIENTREQID | ClientRequestId - No available documentation for this field. |
SESSIONID | SessionId - No available documentation for this field. |
OPERATIONPROP | OperationProperties - Contains information such as MailAccessType done in the audit record. |
FOLDERS | Folders - List of directories involved in the operation, contains fields:
|
OPERATIONCOUNT | OperationCount - The number of bind operations that were aggregated in the record. |
SNAREDATAMAP | All unclassified field/s in the log will be pushed into the SNAREDATAMAP. |
Notes
https://docs.microsoft.com/en-us/microsoft-365/compliance/mailitemsaccessed-forensics-investigations