Customise Exchange 2016/9 tracking logs to include values from X-headers

NASH Martyn 6 Reputation points
2020-11-26T16:01:44.303+00:00

Hi,

Does anyone know how to I can enhance the message tracking logs of Exchange 2016/9 to include the value of a custom X-Header in the emails?

For example, my customer has Outlook automatically put an x-header in every message. They have now asked me to produce audit data of all mails, to, from date, time etc, but to also include the value of this X-header.

Message tracking Logs contain all the other values they want audited.

Thanks in advance.

Martyn

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,494 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Andy David - MVP 145.1K Reputation points MVP
    2020-11-26T16:19:39.08+00:00

    You arent going to be able to grab those from the message logs
    If you were in Exchange Online, you could see what rules were triggered for a message in message tracking, but that funcationality doesnt exist on-prem

    https://learn.microsoft.com/en-us/archive/blogs/eopfieldnotes/auditing-transport-rules

    (Even though in on-prem EAC the option is there, that option on-prem is for incident report generation and that gets stamped in the message tracking logs. )

    0 comments No comments

  2. Joyce Shen - MSFT 16,651 Reputation points
    2020-11-27T02:46:34.143+00:00

    Hi @NASH Martyn

    I agree with Andy, your requirement is hard to achieve. X-header is not recorded in the message tracking log.

    And the information recorded in the message tracking log here: Fields in the message tracking log files

    We are not able to customize the fields in message tracking log.


    If an Answer is helpful, please click "Accept Answer" and upvote it.

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.
     

    0 comments No comments