You are prompted to indicate a start date and end date for the search. In Office 365, mailbox audit logging entries are retained in the mailbox for 90 days. Step 2: Customize a mailbox audit log search For example, if the current date is, and you want to include the current day in your search, enter as the end date.
#OFFICE 365 MAIL LOGIN WINDOWS#
Start Windows PowerShell, and then connect to Windows Remote PowerShell. In the File name box, type Run-MailboxAuditLogSearcher.ps1, and then click Save. $SearchResults = | select $LogParameters) Write-host -fore green 'Filtered to $($SearchREsults.Count) Entries' Write-host -fore green 'Removing FolderBind operations.' Write-host -fore green '$($SearchREsults.Count) Total entries Found' $SearchResults = $Mailbox -StartDate $StartDate -EndDate $EndDate -LogonTypes Owner, Admin, Delegate -ShowDetails -resultsize 50000) Write-host -fore green 'Searching Mailbox Audit Logs.' $SearchResults | export-csv $OutFileName -notypeinformation -encoding UTF8 Write-host -fore green "Posting results to file: $OutfileName" $OutFileName = "AuditLogResults$Date.csv" ]$LogParameters = 'LogonUserDisplayName', 'LastAccessed', 'DestFolderPathName', 'FolderPathName', 'ClientInfoString', 'ClientIPAddress', 'ClientMachineName', 'ClientProcessName', 'ClientVersion', 'LogonType', 'MailboxResolvedOwnerName', 'OperationResult')
#OFFICE 365 MAIL LOGIN CODE#
The code uses the search-mailboxAuditLog command that is part of Microsoft Exchange Server. Start Notepad, and then copy the following code into the file. Microsoft Online Services provides the script as a convenience to Office 365 customers without warranty, expressed or implied. If errors occur when a script is run, the content of the script should be used as an example to create a customized script for a particular customer environment.
Microsoft Online Services scripts are generic, and they should be usable in all customer environments. Customers are encouraged to use the script that's provided by Microsoft Online Services to help in certain investigations.