elastic / elastic/integrations

[microsoft_exchange]: Add support for exchange admin/activity logs

Open
#14,418 2 comments 0 reactions 0 assignees View on GitHub
enhancement Integration:microsoft_exchange_server maintainer:Community needs:triage Team:Security-Service Integrations
Dominant language
Handlebars
Stars
333
Forks
647
Avg merge
3d 4h
Merged PRs (30d)
209

Description

### Integration Name

Microsoft Exchange Server [microsoft_exchange_server]

### Dataset Name

microsoft_exchange_server.adminactivity, microsoft_exchange_server.adminaudit

### Integration Version

1.4.0

### Agent Version

8.18.0

### OS Version and Architecture

Windows

### User Goal

Requesting the addition of of MSExchange Management evtx logs for enhanced monitoring and security auditing capabilities. This would allow automated collection and analysis of Exchange Server admin activities, improving security posture and compliance monitoring.

Additional information on the source events from the Windows Event Log:

- [Exchange Server Admin Audit Logs documentation](https://learn.microsoft.com/en-us/exchange/policy-and-compliance/admin-audit-logging/admin-audit-logging)
- [Hunting for APT abuse of Exchange: Step 1: MS Exchange Management.evtx](https://www.inversecos.com/2022/07/hunting-for-apt-abuse-of-exchange.html)
- [LogRhythm Event Channel Info](https://docs.logrhythm.com/devices/docs/ms-windows-event-logging-msexchange-management)
- Microsoft Sentinel:
- [Microsoft Exchange Admin Audit Logs by Event Logs](https://learn.microsoft.com/nb-no/azure/sentinel/data-connectors-reference#microsoft-exchange-admin-audit-logs-by-event-logs)
- [Sentinel Docs](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Exchange%20Security%20-%20Exchange%20On-Premises/%23%20-%20General%20Content/README.md)
- [Sentinel Deployment Docs](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Exchange%20Security%20-%20Exchange%20On-Premises/%23%20-%20General%20Content/Documentations/Deployment-MES-OnPremises.md#option-1-----msexchange-management-log-collection)

### Existing Features

Currently only file-based logs are collected, not the Windows event log entries

### What did you see?

The admin logs are not currently being ingested.

### Anything else?

_No response_

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.