Apr 24 2023 06:02 AM
Hello. I'm struggling to build out a query and am getting lost. I have never used KQL and am hoping someone may be able to help me figure out how to write queries for the following 2 scenarios in eDiscovery search. I've tried building out the query for the first search since it seems to me that it would be the less complex of the two, but keep getting failures. I appreciate any assistance!
Search 1:
Exchange content timeframe: 1/1/2019-3/31/2019
Custodian: Bugs Bunny (source of exchange content)
Exclude exchange content between Bugs Bunny and Daffy Duck, but include all other content between Bugs Bunny and other parties; and exclude exchange content (including attachments) pertaining to ACME Operations Manager or Petunia Pig
Search 2:
Exchange content timeframe: 1/1/2019-3/31/2019
Custodian: Elmer Fudd (source of exchange content)
Exclude exchange content between Bugs Bunny and Daffy Duck, but include all other content between Bugs Bunny and other parties; and exclude exchange content (including attachments) pertaining to ACME Operations Manager or Petunia Pig
May 08 2023 11:08 AM - edited May 08 2023 11:15 AM
Did you ever resolve this?
I am in the process of doing something similar and the results of my searches are not making sense. The first search I attempt to get everything, then the 2nd is just privileged stuff and a 3rd only non privileged. The logic being if S1 is the same size as S2+S3 I have good results. This does not seem to work out, ever.
Here was my post, did not see yours until after i made it: eDiscovery KQL assistance
May 08 2023 11:38 AM