Home > Microsoft Exchange Tips > Exchange Security Tips > Enabling protocol logging for Exchange Server
Exchange Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

EXCHANGE SECURITY TIPS

Enabling protocol logging for Exchange Server


Brien Posey
11.29.2006
Rating: -4.00- (out of 5)


Exchange Server tips, tutorials and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Email servers are under constant attack from a variety of sources, so it's important to be proactive about email security. One way of doing so is to enable protocol logging for Exchange Server.

Protocol logging lets you see the commands that clients are sending to your Exchange server. If you detect suspicious SMTP, NNTP or HTTP traffic patterns, you can take action before they become a problem. Protocol logs are also an excellent forensic tool for analyzing attacks that occur without warning or detection.

Protocol logging caveats

Enabling SMTP and NNTP protocol logging

By default, your log files will be saved to the C:\WINDOWS\System32\LogFiles folder on the server that's being monitored.

Other logging options

The W3C Extended Log File Format is not the only format available to you. You also have the option of using the Microsoft IIS Log File Format, the NCSA Common Log File Format and ODBC Logging.

The Microsoft IIS Log File Format and the NCSA Common Log File Format are both ASCII log file formats similar to the W3C Extended Log File Format. Given a choice among them, you are usually best off using the W3C Extended Log File Format (unless you have a compelling reason to use one of the other formats). It offers the highest level of logging detail.

The ODBC Logging File Format is completely different from the other three log file formats. It allows you to insert log data into a SQL Server or Microsoft Access database. This allows you to perform complex queries against the database and more easily find specific information within the logs.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Microsoft Exchange Server Monitoring and Logging
Analyzing Exchange ActiveSync data from .CSV report files
Top Exchange Server performance monitoring and troubleshooting tools
Extracting Exchange ActiveSync data from IIS log files
How effective is tracking the IP address of an email hacker?
Error message: 'ID no: 8004100e Exchange System Manager'
How to generate HTML reports with the Exchange Management Shell (EMS)
IMAP list command only returns a list of Exchange public folders
A network connection problem or an offline server prevented delivery of the message
Monitor and search Exchange mailboxes for music and video files
How much bandwidth is required to send email in Exchange 2003?

Email Protocols
How Exchange Server performs Active Directory LDAP queries
How HTTP verbs can 'hang' Outlook Web Access
Establishing a direct Microsoft Outlook connection using RPC over HTTP
Should I be concerned with a large number of user HTTP logons?
Receiving MAPI error after uninstalling Outlook on SBS and Exchange
Why HTTP can hurt Exchange ActiveSync attachments
Exchange Server mailbox-level MAPI backups
A primer on messaging standards: NNTP, X.400 and LDAP
8004010F MAPI not found error with Exchange 2003
A primer on messaging standards: SMTP, POP and IMAP

Exchange Server Security
OWA 'Loading' problems with Internet Explorer security zones
New Exchange Server tools named as Products of the Year
Beware of bare linefeeds in Exchange Server email
Top 10 Exchange Server administration tips of 2006
Eliminate annoying Microsoft Outlook security warnings with ClickYes Pro
Forefront beta secures SharePoint collaboration
Dell, Symantec simplify Secure Exchange for SMBs
Tutorial: How to determine which ports Exchange Server is using
Unsecured devices worry IT professionals
Dell and Symantec bundle hardware, security
Exchange Server Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Automatic Private IP Addressing  (SearchExchange.com)
IMAP  (SearchExchange.com)
MAPI  (SearchExchange.com)
POP3  (SearchExchange.com)
SMTP  (SearchExchange.com)
X.400  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


>Enabling HTTP logging for the Exchange virtual server

The log file format and the corresponding options are identical to the ones that I showed you earlier for logging the SMTP and NNTP protocols.

All protocol logs are created as text files with the .LOG extension and placed in the %SYSTEMROOT%\System32\LogFiles folder.

About the author: Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Exchange Server, and has previously received Microsoft's MVP award for Windows Server and Internet Information Server (IIS). Brien has served as CIO for a nationwide chain of hospitals and was once responsible for the Department of Information Management at Fort Knox. As a freelance technical writer, Brien has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies. You can visit Brien's personal Web site at http://www.brienposey.com.

Do you have comments on this tip? Let us know.

Related information from SearchExchange.com:

  • Tip: Free log reporting tool for HTTP and Exchange Server
  • Tip: How to automatically purge Exchange-related logs
  • Exchange Server diagnostics: An introduction to application and system logs
  • Exchange Server diagnostics: Digging into IIS logs
  • Reference Center: Exchange Server monitoring and logging tips

    Please let others know how useful this tip was via the rating scale below. Do you have a useful Exchange Server or Microsoft Outlook tip, timesaver or workaround to share? Submit it to SearchExchange.com. If we publish it, we'll send you a nifty thank-you gift.

    Rate this Tip
    To rate tips, you must be a member of SearchExchange.com.
    Register now to start rating these tips. Log in if you are already a member.




    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Email Server Solutions: Exchange 2007, Exchange 2003, Exchange 2000, SharePoint
    HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts