How to correlate reverse Proxy server (windows ) server IIS logs and Exchange IIS logs for user access and mail send.

Rafiul islam 21 Reputation points
2024-04-26T05:22:41.61+00:00

Hi all,

I need help , regarding an analysis of event that took place in our organization. One email ID has send an email to all users inside the org. and we need to track it down. We have logs from exchange server (IIS) and message tracking and reverse Proxy server for external access.

Scenario:

  1. Exchange IIS logs and reverse proxy time stamp is not similar.
  2. Audit is enabled for the user but not showing any logs.
  3. Reverse proxy server showing multiple Device ID connection.

How we can corelate the logs from Which session the mail has been send and using which device device.

Need Help on this urgent.

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,358 questions
Microsoft Exchange
Microsoft Exchange
Microsoft messaging and collaboration software.
392 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Jake Zhang-MSFT 1,235 Reputation points Microsoft Vendor
    2024-04-26T09:09:42.1866667+00:00

    Hello @Rafiul islam,

    To track which session an email was sent from and which device was used to send the email through Exchange IIS logs, you need to capture and analyze specific log entries related to the send email action and session. It is recommended that you refer to the following links:

    https://serverfault.com/questions/947930/exchange-2016-how-to-audit-mailbox-user-access-to-get-their-ip

    Third-party contact disclaimer  

    Microsoft provides third-party contact information to help you find additional information about this topic. This contact information may change without notice. Microsoft does not guarantee the accuracy of third-party contact information.