question

Marc-8505 avatar image
0 Votes"
Marc-8505 asked Marc-8505 answered

View EOP logs

Is there a way to view and consult EOP logs to find out information such as knowing who released (not if it has been released) an email in quarantine or retrieve an email deleted from the quarantine by mistake by an user?
Thanks

office-exchange-online-itprooffice-exchange-server-mailflow
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
1 Vote"
michev answered YukiSun-MSFT commented
· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi @Marc-8505,

Agree with michev that Quarantine activities are included in the audit logs so you can check it using Audit log assuming that audit log has been enabled:

 Get-AdminAuditLogConfig | FL UnifiedAuditLogIngestionEnabled

141226-1.png

You can go to the audit search tab via https://security.microsoft.com/auditlogsearch, then specify the time range and activities, etc.:
141292-2.png

Then we can see the search results after pressing Search:
141341-3.png


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·
1.png (3.7 KiB)
2.png (33.3 KiB)
3.png (30.5 KiB)
Marc-8505 avatar image
0 Votes"
Marc-8505 answered michev commented

I have started the Audit and searched for "released quarantine" but not result are displayed?
Do I need to setup something else ?
Could be a license problem? We are using EOP.

· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

If you have just activated the log ingestion, it will take a while for records to start appearing. Entries from before the ingestion was activated will not be backfilled, only new events.

0 Votes 0 ·

Thank you Michev.
Just for reference, do you know approximately how long it will take to be ready?
Once stopped do we need to delete all data generated or the system wiil do for us automaticcaly?
Apart via powershell do we have another way to stop it?

0 Votes 0 ·

If you don't see any events after a day, best open a support case.

0 Votes 0 ·
Show more comments