Shared Mailbox audit

%3CLINGO-SUB%20id%3D%22lingo-sub-177146%22%20slang%3D%22en-US%22%3EShared%20Mailbox%20audit%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177146%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%0A%3CP%3EI%20am%20having%20trouble%20auditing%20a%20shared%20mailbox.%26nbsp%3B%20I%20have%20enabled%20auditing%20on%20a%20shared%20mailbox.%20When%20viewing%20the%20audit%20logs%20via%20the%20Compliance%20Manager%20the%20only%20audited%20event%20I%20have%20are%20from%26nbsp%3Ba%20user%20working%20in%26nbsp%3BOWA.%20I%20do%20not%20see%20any%20events%20logged%20from%20any%20users%20using%20outlook.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHere%20is%20the%20status%20of%20the%20mailbox%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CPRE%3EPS%20C%3A%5CWINDOWS%5Csystem32%26gt%3B%20Get-Mailbox%20MAILBOXNAME%20%7C%20fl%20au*%0A%0A%0AAutoExpandingArchiveEnabled%20%3A%20False%0AAuditEnabled%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%3A%20True%0AAuditLogAgeLimit%20%20%20%20%20%20%20%20%20%20%20%20%3A%2060.00%3A00%3A00%0AAuditAdmin%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%3A%20%7BUpdate%2C%20Move%2C%20MoveToDeletedItems%2C%20SoftDelete...%7D%0AAuditDelegate%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%3A%20%7BUpdate%2C%20Move%2C%20MoveToDeletedItems%2C%20SoftDelete...%7D%0AAuditOwner%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%20%3A%20%7BUpdate%2C%20Move%2C%20MoveToDeletedItems%2C%20SoftDelete...%7D%3C%2FPRE%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-177146%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177511%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20Mailbox%20audit%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177511%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20theory%2C%20yes.%20In%20practice...%20not%20as%20reliable%20as%20you%20might%20think.%20Did%20you%20find%20the%20events%20in%20the%20mailbox%20log%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177350%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20Mailbox%20audit%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177350%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20sharing.%20I%20thought%20all%20the%20audit%20logs%20are%20available%20in%20SCC!.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-177274%22%20slang%3D%22en-US%22%3ERe%3A%20Shared%20Mailbox%20audit%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-177274%22%20slang%3D%22en-US%22%3E%3CP%3EHave%20you%20checked%20the%20actual%20mailbox%20audit%20logs%2C%20the%20ones%20stored%20in%20the%20mailbox%20not%20the%20SCC%20console%3F%20In%20other%20words%2C%20run%20this%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESearch-MailboxAuditLog%20-Identity%20shared%20-ShowDetails%20-LogonTypes%20Delegate%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

Hello,

I am having trouble auditing a shared mailbox.  I have enabled auditing on a shared mailbox. When viewing the audit logs via the Compliance Manager the only audited event I have are from a user working in OWA. I do not see any events logged from any users using outlook.

 

 

Here is the status of the mailbox

 

PS C:\WINDOWS\system32> Get-Mailbox MAILBOXNAME | fl au*


AutoExpandingArchiveEnabled : False
AuditEnabled                : True
AuditLogAgeLimit            : 60.00:00:00
AuditAdmin                  : {Update, Move, MoveToDeletedItems, SoftDelete...}
AuditDelegate               : {Update, Move, MoveToDeletedItems, SoftDelete...}
AuditOwner                  : {Update, Move, MoveToDeletedItems, SoftDelete...}
3 Replies
Highlighted

Have you checked the actual mailbox audit logs, the ones stored in the mailbox not the SCC console? In other words, run this:

 

Search-MailboxAuditLog -Identity shared -ShowDetails -LogonTypes Delegate

Highlighted

Thanks for sharing. I thought all the audit logs are available in SCC!.

Highlighted

In theory, yes. In practice... not as reliable as you might think. Did you find the events in the mailbox log?