elastic / elastic/integrations
[microsoft_exchange]: Add support for exchange admin/activity logs
- Dominant language
- Handlebars
- Stars
- 333
- Forks
- 647
- Avg merge
- 3d 4h
- Merged PRs (30d)
- 209
Description
### Integration Name
Microsoft Exchange Server [microsoft_exchange_server]
### Dataset Name
microsoft_exchange_server.adminactivity, microsoft_exchange_server.adminaudit
### Integration Version
1.4.0
### Agent Version
8.18.0
### OS Version and Architecture
Windows
### User Goal
Requesting the addition of of MSExchange Management evtx logs for enhanced monitoring and security auditing capabilities. This would allow automated collection and analysis of Exchange Server admin activities, improving security posture and compliance monitoring.
Additional information on the source events from the Windows Event Log:
- [Exchange Server Admin Audit Logs documentation](https://learn.microsoft.com/en-us/exchange/policy-and-compliance/admin-audit-logging/admin-audit-logging)
- [Hunting for APT abuse of Exchange: Step 1: MS Exchange Management.evtx](https://www.inversecos.com/2022/07/hunting-for-apt-abuse-of-exchange.html)
- [LogRhythm Event Channel Info](https://docs.logrhythm.com/devices/docs/ms-windows-event-logging-msexchange-management)
- Microsoft Sentinel:
- [Microsoft Exchange Admin Audit Logs by Event Logs](https://learn.microsoft.com/nb-no/azure/sentinel/data-connectors-reference#microsoft-exchange-admin-audit-logs-by-event-logs)
- [Sentinel Docs](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Exchange%20Security%20-%20Exchange%20On-Premises/%23%20-%20General%20Content/README.md)
- [Sentinel Deployment Docs](https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Exchange%20Security%20-%20Exchange%20On-Premises/%23%20-%20General%20Content/Documentations/Deployment-MES-OnPremises.md#option-1-----msexchange-management-log-collection)
### Existing Features
Currently only file-based logs are collected, not the Windows event log entries
### What did you see?
The admin logs are not currently being ingested.
### Anything else?
_No response_
Contributor guide
Assessment
This issue has not been assessed yet.