Microsoft 365

Download 27
Last updated May 22, 2022

o365-exchange-logs

Fetch exchange logs using Office 365 Management API

o365-exchange-logs [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss]
profile=PROFILE
Office 365 connect profile name
duration=NUM{mon|w|d|h|m|s}
Scan only recent data. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.

Output Fields

FieldTypeNameDescription
_timeDateTime
profileStringConnect profileThe identifier of Office 365 connect profile
workloadStringWorkloade.g. Exchange
org_nameString주 도메인e.g. acme.onmicrosoft.com
origin_serverStringOrigin server
client_ipIP addressClient IP
user_idStringUser IDe.g. S-1-5-18
operationStringOperatione.g. Add-MailboxPermission, ModifyFolderPermissions, Set-OwaMailboxPolicy
object_idStringObject IDe.g. acme.onmicrosoft.com\Admin Audit Log Settings
result_statusStringResult statuse.g. Succeeded, True
external_accessBoolExternal access
parametersListParametersElements with name and value properties
record_typeIntegerRecord typee.g. 1, 2
user_typeIntegerUser typee.g. 2, 3
user_keyStringUser keye.g. S-1-5-18, NT AUTHORITY\SYSTEM (Microsoft.Exchange.Servicehost)
versionIntegerVersione.g. 1
idStringIDGUID
org_idStringTenant IDGUID format
app_idStringApp IDGUID format