m365-exchange-mail-flows
Fetch Exchange mail flow message trace logs using the Microsoft Graph message trace API.
Note
App version 1.5.2609.0 and later use the Microsoft Graph message trace API. Earlier versions use the Office 365 Reporting Web Service and return a different set of output fields.
m365-exchange-mail-flows [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
- profile=PROFILE
- Microsoft 365 connect profile name
- duration=NUM{mon|w|d|h|m|s}
- Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example,
10smeans data from 10 seconds earlier. - from=yyyyMMddHHmmss
- Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
- to=yyyyMMddHHmmss
- End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
The query range is limited. Graph message trace keeps only the last 90 days of data, so specifying a start time older than 90 days returns an error. A longer range is split into 10 day chunks internally.
Output Fields
| Field | Type | Name | Description |
|---|---|---|---|
| _time | Date | Time | |
| profile | String | Connect profile | Microsoft 365 connect profile code |
| mail_from | String | Sender address | Email address format |
| mail_to | String | Recipient address | Email address format |
| mail_subject | String | Mail subject | |
| size | Long | Size | In bytes |
| status | String | Status | e.g. Delivered, Failed, Expanded, Quarantined, FilteredAsSpam |
| src_ip | IP address | Source IP | Sender mail server IP |
| dst_ip | IP address | Destination IP | Destination domain MX IP. Blank for incoming messages |
| index | Integer | Index | Not provided by Graph API. Reporting API compatibility field |
| msg_id | String | Massage ID | |
| msg_trace_id | String | Massage Trace ID | GUID format |
| organization | String | Organization name | Not provided by Graph API. Reporting API compatibility field |
| start_date | String | Start date | Not provided by Graph API. Reporting API compatibility field |
| end_date | String | End date | Not provided by Graph API. Reporting API compatibility field |