Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 4 Next »

Description

Events from an Exchange mailbox audit log for actions that can be performed on multiple items, such as moving or deleted one or more email messages.

Log Structure

 Sample of Office365ExchangeItemGroup Event (in JSON format)
[
{
"CreationTime": "2022-03-15T10:56:33",
"Id": "80c76bd2-9d81-4c57-a97a-accfc3443dca",
"Operation": "SoftDelete",
"OrganizationId": "41463f53-8812-40f4-890f-865bf6e35190",
"RecordType": 3,
"ResultStatus": "Succeeded",
"UserKey": "1153977025279851686@contoso.onmicrosoft.com",
"UserType": 0,
"Version": 1,
"Workload": "Exchange",
"ClientIP": "134.170.188.221",
"UserId": "admin@contoso.onmicrosoft.com",
"AppId": "00012343-1111-0ff1-ef22-000000000000",
"ClientIPAddress": "134.170.188.221",
"ClientInfoString": "Client=OWA;Action=ViaProxy",
"ExternalAccess": false,
"InternalLogonType": 0,
"LogonType": 0,
"LogonUserSid": "S-1-5-44-1234564413-1234536233-543218302-42844876",
"MailboxGuid": "9a8cf76d-d754-3e2e-b10d-9bb87654f3b2",
"MailboxOwnerSid": "S-1-5-44-1234564413-1234536233-543218302-42844876",
"MailboxOwnerUPN": "admin@contoso.onmicrosoft.com",
"OrganizationName": "contoso.onmicrosoft.com",
"OriginatingServer": "DEFPR01MB5223 (15.16.5500.000)\r\n",
"SessionId": "9a8cf76d-d754-3e2e-b10d-9bb87654f3b2",
"AffectedItems": [
{
"Id": "RgXXXXBfilsyPsriQIl0rq3TWIlUBwBgU5LBEA0rTKAxHEa3YAjjBBBCCCEKDDBgU5LBEA5rTKAxHEa3YAjjAABk0FUNAAAJ",
"InternetMessageId": "b27f25405d1749f98679999cb1a2dccb-ABCDEFKQOJXWILKNK4YVA7CPGM3LMNOPONZWCZ3FINSW45DFOJ6E8Q2ENFTWK43UL4YDGMBWGIZHYU3SORRY====@microsoft.com",
"ParentFolder": {
"Id": "LgCCCCBfilsyPsriQIl0rq9TWIlUARXgU5LBEA9rTKAxHEa3YAjjAAAY2qUXBBBC",
"Path": "\Deleted Items"
},
"Subject": "Weekly digest: Microsoft service updates"
}
],
"CrossMailboxOperation": false,
"Folder": {
"Id": "LgCCCCBfilsyPsriQIl0rq9TWIlUARXgU5LBEA9rTKAxHEa3YAjjAAAY2qUXBBBC",
"Path": "\Deleted Items"
}
}
]

Table Fields

Field

Description

TABLE

Office365ExchangeItemGroup

RECORDTYPE

Based on RecordType, where this field indicates the operation performed by the record.
For this log type its value is 3.
See more details about RecordType here.

APPID

Based on AppId, there’s no available documentation for this field.

CLIENTAPPDID

Based on ClientAppId, there’s no available documentation for this field.

LOGONTYPE

Based on LogonType, where this field indicates the type of user who accessed the mailbox and performed the operation that was logged.

INTERNALLOGONTYPE

Based on InternalLogonType, where this field indicates where it is for internal use.

MAILBOXGUID

Based on MailboxGuid, where this field contains the Exchange GUID of the mailbox that was accessed.

MAILBOXOWNERUPN

Based on MailboxOwnerUPN, where this field contains the email address of the person who owns the mailbox that was accessed.

MAILBOXOWNERSID

Based on MailboxOwnerSid, where this field contains the SID of the mailbox owner.

MAILBOXOWNERMASTERSID

Based on MailboxOwnerMasterAccountSid, where this field contains the Mailbox owner account's master account SID.

LOGONUSERSID

Based on LogonUserSid, where this field contains the SID of the user who performed the operation.

LOGONUSERNAME

Based on LogonUserDisplayName, where this field contains the user-friendly name of the user who performed the operation.

EXTERNALACCESS

Based on ExternalAccess, where this field when set to true means that the logon user's domain is different from the mailbox owner's domain.

ORIGINATINGSERVER

Based on OriginatingServer, where this field contains the details where the operation originated.

ORGNAME

Based on OrganizationName, where this field contains the name of the tenant.

CLIENTINFO

Based on ClientInfoString, where this field contains the information about the email client that was used to perform the operation, such as a browser version, Outlook version, and mobile device information.

CLIENTADDR

Based on ClientIPAddress, where this field contains the IP address of the device that was used when the operation was logged.
The IP address is displayed in either an IPv4 or IPv6 address format.

CLIENTMACHINE

Based on ClientMachineName, where this field contains the machine name that hosts the Outlook client.

CLIENTPROCESS

Based on ClientProcessName, where this field contains the email client that was used to access the mailbox.

CLIENTVERSION

Based on ClientVersion, where this field contains the version of the email client.

CLIENTREQID

Based on ClientRequestId, there’s no available documentation for this field.

SESSIONID

Based on SessionId, there’s no available documentation for this field.

DIR

Based on Folder, where this field contains the folder where a group of items is located.

CROSSMBOPERATION

Based on CrossMailboxOperation, where this field indicates if the operation involved more than one mailbox.

DESTMBID

Based on DestMailboxId, where this field specifies the target mailbox GUID.

DESTMBUPN

Based on DestMailboxOwnerUPN, where this field specifies the UPN of the owner of the target mailbox.

DESTMBSID

Based on DestMailboxOwnerSid, where this field contains the specifies the SID of the target mailbox.

DESTMBMASTERSID

Based on DestMailboxOwnerMasterAccountSid, where this field contains the specifies the SID for the master account SID of the target mailbox owner.

DESTDIR

Based on DestFolder, where this field contains the destination folder, for operations such as Move.

SRCDIRS

Based on ClientProcessName, where this field contains the information about the source folders involved in an operation

AFFECTEDITEMS

Based on AffectedItems, where this field contains the information about affected item(s) in the group.

SNAREDATAMAP

All unclassified field(s) parsed from this log type will be pushed into the SNAREDATAMAP.

Notes

https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema#exchange-mailbox-schema

https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-schema?view=o365-worldwide#exchangemailboxauditgrouprecord-schema

  • No labels