Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Microsoft Exchange

Microsoft Exchange consists of security analytics components that normalize Microsoft Exchange events, enabling you to analyze Microsoft Exchange data. Logpoint aggregates and normalizes logs related to log types, log volume, mail receivers, mail senders, mail activity, SMTP AQ failures, and SMTP bad emails from Microsoft Exchange systems so you can analyze the information through a dashboard and security report. 

Release Details

Version: 5.5.0
Release date: July 22, 2026
Supported On: Logpoint v7.4.0 and later
SHA 256: 5083712322d85c1a6f73293a3b8194fa15842566c1f4a5ee869bc069897fcd83
Microsoft Exchange user guide
Download

Key Information

MSExchangeOnlineMT is a new log source template, introduced in this release, that collects Exchange Online Message Trace logs through the Microsoft Graph Message Trace API. It was added since Microsoft retired the legacy Reporting Web Service that ExchangeOnlineMT template depends on. ExchangeOnlineMT remains supported; however, we recommend moving to MSExchangeOnlineMT by granting the ExchangeMessageTrace.Read.All Microsoft Graph permission. Existing dashboards, alerts, and reports keep working.

Enhancement

PLUG-17849
Added a new MSExchangeOnlineMT log source to collect Exchange Online Message Trace logs, after Microsoft retired the Reporting Web Service the previous log source relied on. Your existing dashboards, alerts, and reports built on Exchange Message Trace data continue to work as is. No rebuild is needed after moving to the new log source.

Past Releases

Microsoft Exchange v5.4.0 ▾
Version: 5.4.0
Release date: December 19, 2024
Supported On: Logpoint v7.4.0 or later
SHA 256: 906d34e02869244be3e8bb0fc81bec8f2ab467431ee4257af8255910b302aaa1
Download

Enhancement

KB-23762
Added Universal Rest API Fetcher based ExchangeOnlineMT log source template to simplify the log source configuration process. Go to Creating Log Source via a Template to learn more. 
Key Information
  • When selecting the initial fetch date of logs, select no more than 2-3 days ago. Choosing an earlier date may prevent logs from being fetched successfully.
  • For ExchangeOnlineMT, you no longer need to use the PowerShell script zipped with Office365.
Microsoft Exchange v5.3.0 ▾
Version: 5.3.0
Release date: May 08, 2024
Supported On: Logpoint v7.4.0 or later
SHA 256: c0b726487946c781a43bb80c4b9401e27123beb4753d62e3f1da458db41af041
Download

Enhancement

KB-22748
Added Syslog Collector based Microsoft Exchange Server log source template to simplify the log source configuration process. Go to Creating Log Source via a Template to learn more. 
Microsoft Exchange v5.2.2 ▾
Version: 5.2.2
Release date: July 03, 2023
Supported On: Logpoint v6.7.0 or later
SHA 256: f7e6bd12ac7055365f06470f5e6461113c3d295a20859dbb2f67dd27254d7fce
Download

Bug Fixes

KB-20529, KB-20248
Some Symantec Mail Security and MS Exchange logs were not normalized by MSExchangeCompiledNormalizer.
KB-21363, KB-18174
Some Microsoft Exchange and Exchange MT logs were not normalized by ExchangeHTTPProxyCompiledNormalizer and LP_Exchange MT 2016. 
KB-18960, KB-19426
The DefaultFolderType and LED fields were not properly normalized by ExchangeMTCompiledNormalizer. 

Support

If you have any questions or require assistance, create a support ticket.

  • MicrosoftExchange.zip (2 MB)

Comments

Article is closed for comments.

Follow

Related articles

  • Universal REST API Fetcher
  • Windows
  • ChatGPT Integration
  • CheckPoint Firewall
  • AWSServices
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.