I've tried this but seems not working.
Original Message:
Sent: Fri December 25, 2020 01:35 AM
From: Caglar Durmaz
Subject: Microsoft Exchange Audit and Admin Logs
Hi Ahmed;
First
1- Build your own DSM named Exchange Audit
2- Bind Wincollect as a protocol for this source
3- Add XPATH Query; Path can e changeable according to your own path.
<QueryList>
<Query Id="0" Path="MSExchange Management">
<Select Path="MSExchange Management">*</Select>
</Query>
</QueryList>
------------------------------
Caglar Durmaz
Original Message:
Sent: Thu December 24, 2020 10:07 AM
From: Dusan VIDOVIC
Subject: Microsoft Exchange Audit and Admin Logs
I think I noticed searching mentions of powershell scripts for the purpose of exporting Exchange audit logs/data. Maybe it could be viable to get a text/csv/xml this way and then you can pick it up and create your own parsing.
------------------------------
Dusan VIDOVIC
Original Message:
Sent: Tue December 22, 2020 05:46 PM
From: Ahmed Elsayed
Subject: Microsoft Exchange Audit and Admin Logs
Hi Karl,
Thank you for your reply.
I am talking about Microsoft exchange server administrator audit logs, these logs are stored locally in a mailbox within the application itself and only accessible through cmdlets, there are softwares like (LOGbinder for Exchange) that pull the logs from the mailbox parse them and forward them to Qradar.
the problem is that these softwares aren't free to use, I was thinking of extracting the logs and pull them from qradar, but not sure if this is the most suitable way to proceed with that.
Thanks
------------------------------
Ahmed Elsayed
Original Message:
Sent: Tue December 22, 2020 02:02 PM
From: karl jaeger
Subject: Microsoft Exchange Audit and Admin Logs
Ahmed
very generic question. What about using wincollect? Pls outline how far you got with onboarding your windows logsource.
br Karl
------------------------------
[Karl] [Jaeger] [Business Partner]
[QRadar Specialist]
[pro4bizz]
[Karlsruhe] [Germany]
[4972190981722]
Original Message:
Sent: Tue December 22, 2020 10:00 AM
From: Ahmed Elsayed
Subject: Microsoft Exchange Audit and Admin Logs
Hello all,
I am having problems to pull audit and admin logs of exchange, do anyone know how to proceed with such integration.
Best Regards,
Ahmed Elsayed
SIOC Analyst MEA
IBM Egypt