Windows Event Logs Clea

ninessas 1 Reputation point
2021-04-02T10:44:50.357+00:00

Hi All,

I'm trying to find out why our MS Exchange server logs were cleared, but couldn't find why. Our SIEM indicated that it's triggered by Microsoft-Windows-Eventlog: EventID 104. Upon checking, event ID 104 is a normal condition and no further action is required (
https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc775044(v=ws.10)?redirectedfrom=MSDN). I have tried to check if there's any suspicious logins on the admin accounts but we didn't find anything. Can you advise?

Log is below the eventID 104 is below.

{
"hostIdentifier": "00000000-cbe8-42a1-b497-f6a538fdfc75",
"BackupPath": "",
"Channel": "Microsoft-Exchange-ManagedAvailability/ThrottlingConfig",
"LogFileCleared": "",
"SubjectDomainName": "NT AUTHORITY",
"SubjectUserName": "SYSTEM",
"datetime": "2021-04-02T10:16:39.436600800Z",
"eventid": "104",
"keywords": "-1",
"level": "4",
"provider_guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
"provider_name": "Microsoft-Windows-Eventlog",
"source": "System",
"task": "104",
"time": "1617358599"
}

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,345 questions
{count} votes

2 answers

Sort by: Most helpful
  1. ninessas 1 Reputation point
    2021-04-02T10:45:26.3+00:00

    Sorry the title is Windows Event Logs Cleared

    0 comments No comments

  2. Joyce Shen - MSFT 16,641 Reputation points
    2021-04-05T02:43:59.263+00:00

    Hi @ninessas

    What's you Exchange server version? Do you mean your event logs are cleared and you want to find 'who' deleted them?

    Please correct me if I have any misunderstanding about your question. If that's the case, we could refer to the below threads which discussed the similar issues:

    How to find out who deleted Event Viewer logs
    Windows event logs clears or delete itself??
    Audit Event logs clear Microsoft-Exchange Activemonitoring ManagedAvailability

    Also check that your system logs is not being overwritten by itselft due to maximum size let's say 10 MB or so
    Exchange server will not actively delete logs. If you make sure the logs was deleted, I would suggest you use other tool to monitor logs are deleted by which application.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
     

    0 comments No comments