Configuring Microsoft Exchange Server Log Ingestion
Microsoft Exchange Server creates Message Tracking logs as email messages move through its transport pipeline. Each comma-separated log entry describes a message event and can include information such as the sender, recipients, timestamp, event type, server, connector, and message subject. These logs provide useful context for tracing mail flow, investigating phishing, identifying unusual external recipients, and hunting for possible data exfiltration.
To ingest Microsoft Exchange Server Message Tracking logs, install NXLog on each Exchange Mailbox server. NXLog collects entries from the Message Tracking log files and forwards them to parser port 5876 on a Stellar Cyber Modular Sensor, adding an RFC 3164 syslog header to each message. Most Message Tracking entries contain a structured CSV payload, although the parser also accepts non-CSV messages received through the same syslog stream.
On the Stellar Cyber side, the Microsoft Exchange Server parser processes the incoming logs and maps the structured CSV data to Exchange-specific fields. It then normalizes the data into Stellar Cyber Interflow records with msg_origin.category set to email and saves the resulting records in the Traffic or Syslog index.
These instructions apply to on-premises Microsoft Exchange Server 2016 and 2019. They do not apply to Exchange Online. For Microsoft 365, see Configuring Office 365 Connectors.
Message Tracking logs cover mail flow only. To extend coverage to host activity such as administrative changes, suspicious logons, and PowerShell activity, deploy a Windows Server Sensor on each Exchange server.
Before You Begin
You need the following:
-
A Modular Sensor that is connected and authorized to the Stellar Cyber Platform, with Log Forwarder enabled in the sensor profile.
-
Administrator access to each Exchange Mailbox server, including access to the Exchange Management Shell.
-
NXLog Community Edition or NXLog Enterprise Edition installed on each Exchange Mailbox server.
-
Network connectivity from each Exchange server to the Modular Sensor on TCP port 5876.
To configure Microsoft Exchange Server log ingestion:
Preparing the Modular Sensor
To prepare the Modular Sensor to receive Microsoft Exchange Server logs:
-
Select System | DATA SOURCE MANAGEMENT | Sensors | Sensors, locate the Modular Sensor that receives the Exchange logs, and note its Sensor Profile.
-
Select System | DATA SOURCE MANAGEMENT | Sensors | Sensor Profiles, edit the assigned Modular Sensor profile, and make sure the Log Forwarder option is enabled.
For more information about Modular Sensor profiles and Log Forwarder settings, see Configuring Modular Sensor Profiles.
-
For encrypted transport, enable Syslog TLS on the Modular Sensor.
Stellar Cyber recommends using TLS to protect Message Tracking logs in transit. See Ingesting Logs over TLS for information about configuring TLS and obtaining the CA certificate.
-
Record the IP address of the Modular Sensor.
You use this address in the NXLog configuration.
-
On any firewall between the Exchange servers and the Modular Sensor, allow TCP port 5876 from the Exchange server IP addresses.
For additional information about parser ports, see Log Parser Ports.
Confirming Message Tracking
Message Tracking is enabled by default on Microsoft Exchange Server. Confirm that it is enabled and note the log path on each Exchange Mailbox server.
-
In the Exchange Management Shell, run the following command to confirm whether Message Tracking is enabled and identify the log path:
Get-TransportService | Select-Object Name, MessageTrackingLogEnabled, MessageTrackingLogPath
-
If
MessageTrackingLogEnabledisFalse, enable Message Tracking by entering the following command:Set-TransportService -Identity <ServerName> -MessageTrackingLogEnabled $true
-
Note the value of
MessageTrackingLogPath.The following is the default path:
C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking\
If your Exchange server uses a different path, use that path when you configure NXLog.
Configuring NXLog
NXLog is a log collection agent that runs on each Exchange Mailbox server. In this configuration, NXLog monitors the Message Tracking log files, ignores the file header lines, formats each new log entry as RFC 3164 (BSD) syslog, and forwards the logs to the Modular Sensor.
To protect potentially sensitive information in Message Tracking logs while they are in transit, use TLS whenever possible. If Syslog TLS is enabled on the Modular Sensor, configure NXLog with the om_ssl output module and the Modular Sensor CA certificate, as shown in the following procedure. If Syslog TLS is not enabled, either enable it before continuing or use unencrypted TCP by changing the output module to om_tcp and removing the CAFile and AllowUntrusted lines from the sample configuration. Use unencrypted TCP only on a trusted network segment.
Use TCP or TLS rather than UDP because Message Tracking log entries with long message subjects can exceed UDP message-size limits and be truncated, which can prevent the parser from completely parsing the log and populating the expected fields in the resulting Interflow record.
The sample configuration uses ReadFromLast TRUE so NXLog begins reading at the end of the current log files and does not forward existing historical logs. Set this value to FALSE if you want to backfill existing logs. The MSGTRK*.LOG file pattern includes the Message Tracking transport (MSGTRK), agent (MSGTRKMA), delivery (MSGTRKMD), and submission (MSGTRKMS) logs.
To configure NXLog on each Exchange Mailbox server:
-
Install NXLog on the Exchange server if it is not already installed.
-
If you use TLS, copy the CA certificate for the Modular Sensor to the following location:
C:\Program Files\nxlog\cert\sensor-ca.pem
-
Open
C:\Program Files\nxlog\conf\nxlog.confand add the following configuration, replacing<MODULAR_SENSOR_IP>with the IP address of the Modular Sensor and updating theFilevalue if the Message Tracking log path differs from the default:<Extension _syslog> Module xm_syslog </Extension> <Input exchange_msgtrk> Module im_file File 'C:\Program Files\Microsoft\Exchange Server\V15\TransportRoles\Logs\MessageTracking\MSGTRK*.LOG' SavePos TRUE ReadFromLast TRUE # Drop the #Software/#Fields/#Version header lines (may start with a UTF-8 BOM) Exec if $raw_event =~ /^(\xEF\xBB\xBF)?#/ drop(); Exec $Message = $raw_event; to_syslog_bsd(); </Input> # Recommended: TLS <Output stellar_modular_sensor> Module om_ssl Host <MODULAR_SENSOR_IP> Port 5876 CAFile 'C:\Program Files\nxlog\cert\sensor-ca.pem' AllowUntrusted FALSE </Output> <Route exchange_to_stellar> Path exchange_msgtrk => stellar_modular_sensor </Route> -
Restart NXLog by entering the
Restart-Service nxlogcommand. -
Repeat this configuration on each Exchange Mailbox server in the organization.
Verifying Ingestion
To verify that the Stellar Cyber Platform is ingesting Microsoft Exchange Server logs and creating Interflow records:
-
Send a test email through Microsoft Exchange Server.
This causes Exchange to write new entries to the Message Tracking logs.
-
On the Modular Sensor CLI, enter the
show logforwardercommand and confirm that the input and output counters are increasing. -
In the Stellar Cyber Platform, select Investigate | Threat Hunting and run the following search:
msg_origin.source:microsoft_exchange
-
Open an Interflow record returned by the search and confirm that the expected Microsoft Exchange Server fields are populated.
For example:
-
microsoft_exchange.sender-address -
microsoft_exchange.recipient-address -
microsoft_exchange.event-id -
event.timestamp
-
Security Recommendations
Message Tracking logs can contain email addresses and message subjects, which can include personal or regulated data. Protect the logs in transit and on each Exchange server.
-
Use TLS with
AllowUntrusted FALSEso NXLog verifies the certificate presented by the Modular Sensor before forwarding logs. -
Restrict TCP port 5876 on the Modular Sensor to known Exchange server IP addresses to limit which systems can send logs to the parser.
-
Where your hardening standards allow, run the NXLog service under a dedicated account with read-only NTFS permissions on the Message Tracking folder instead of LocalSystem.
-
Restrict write access to
nxlog.confand the certificate folder to administrators to help prevent unauthorized changes to log forwarding or certificate validation.
Troubleshooting
Check C:\Program Files\nxlog\data\nxlog.log on the Exchange server first. NXLog records most collection and forwarding failures in this file.
| Symptom | Likely Cause | Action |
|---|---|---|
| No Microsoft Exchange Server Interflow records appear in the Stellar Cyber Platform, and the sensor counters do not increase. | A firewall is blocking the connection, or the Modular Sensor IP address or port is incorrect. | From the Exchange server, run Test-NetConnection <MODULAR_SENSOR_IP> -Port 5876 to test connectivity to the parser port. |
TLS handshake errors appear in nxlog.log. |
Syslog TLS is not enabled on the Modular Sensor, or NXLog is using the wrong CA certificate. | Enable Syslog TLS on the Modular Sensor and copy the correct CA certificate to the Exchange server, or configure NXLog to use unencrypted TCP on a trusted network segment. |
| NXLog is running but does not read the Message Tracking logs. | The log path is incorrect, or the NXLog service account cannot read the Message Tracking folder. | Confirm the path returned by Get-TransportService and verify that the NXLog service account has NTFS read permissions for the Message Tracking folder. |
| Microsoft Exchange Server logs reach the Stellar Cyber Platform, but the expected Interflow fields are not populated. | The logs are sent to the wrong parser port, or another tool modifies the CSV log entries before they reach the Modular Sensor. | Confirm that NXLog sends the logs to port 5876 and that no other tool rewrites the log entries. If the parser does not recognize a log, the unparsed text can appear in log.event_description. |
| Message Tracking log entries are truncated. | NXLog is forwarding the logs with UDP. | Configure NXLog to use TCP or TLS so the complete log entry reaches the parser. |
