<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Exchange-Genie &#187; Message tracking</title>
	<atom:link href="http://www.exchange-genie.com/category/message-tracking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.exchange-genie.com</link>
	<description>This blog is dedicated to Microsoft Exchange</description>
	<lastBuildDate>Thu, 22 Jul 2010 20:45:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Exchange 2007 Message Tracking</title>
		<link>http://www.exchange-genie.com/2008/05/exchange-2007-message-tracking/</link>
		<comments>http://www.exchange-genie.com/2008/05/exchange-2007-message-tracking/#comments</comments>
		<pubDate>Sun, 11 May 2008 00:14:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Message tracking]]></category>
		<category><![CDATA[exchange 2007]]></category>
		<category><![CDATA[Exchange 2007 SP1]]></category>
		<category><![CDATA[Exchange Message tracking]]></category>
		<category><![CDATA[messsage tracking]]></category>

		<guid isPermaLink="false">http://www.exchange-genie.com/?p=44</guid>
		<description><![CDATA[Exchange 2007 Message Tracking At some point in time most messaging administrator have received the age-old complaint about mail not arriving or being delivered. I revert to the message tracking logs quite often on the systems that I manage. There are a number of logs available from the content agent logs for antispam, Protocol logs, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Exchange 2007 Message Tracking</strong></p>
<div>
<div>At some point in time most messaging administrator have received the age-old complaint about mail not arriving or being delivered. I revert to the message tracking logs quite often on the systems that I manage.</div>
<p>There are a number of logs available from the content agent logs for antispam, Protocol logs, Send/Receive logs but this article will focus on one of my favorites Message Tracking.</p>
<p>When working in mixed Exchange 2003 and Exchange 2007 you have to manage each logs separately as the tools provided will not allow us to parse logs from different versions of the products.</p>
<p>Another item I found out in early beta was the GUI provided in Exchange 2007 only searches the logs on the server we are running the query from, we must user EMS to query all our servers.</p></div>
<div><strong>Configuring Message Tracking</strong></div>
<div>By default Message Tracking is enabled on all servers running Hub, MBX, or Edge Server roles and Microsoft has added management features in SP1 to allow more configuration from EMC.</div>
<div style="font-weight: bold;">EMC</div>
<div>Lets open Exchange Management Conscole (EMC) and take a look at what we can see on our hub transport server</div>
<div><a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZAQ5Qd5JI/AAAAAAAAAwM/zSAVBnal3ms/s1600-h/mt1.jpg"><img id="BLOGGER_PHOTO_ID_5198913478837789842" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZAQ5Qd5JI/AAAAAAAAAwM/zSAVBnal3ms/s320/mt1.jpg" border="0" alt="" /></a></div>
<p>You can see the message tracking is ENABLED by defaultThe only 2 options we have from the EMC is :<br />
1. Enable message tracking<br />
2. specify the log path</p>
<p>If we look at the properties of the mailbox server we cannot manipulate any of the setting from<br />
<a href="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCZA0ZQd5KI/AAAAAAAAAwU/SpbLR4qZ_HA/s1600-h/mt2.jpg"><img id="BLOGGER_PHOTO_ID_5198914088723145890" src="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCZA0ZQd5KI/AAAAAAAAAwU/SpbLR4qZ_HA/s320/mt2.jpg" border="0" alt="" /></a></p>
<p><span style="font-weight: bold;">EMS</span><br />
We can use the <span style="font-style: italic;">get-transportserve</span>r and <span style="font-style: italic;">get-mailboxserver cmdlets </span>to show message tracking information.</p>
<p><span style="font-style: italic;">get-mailboxserver<br />
</span><a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZB95Qd5LI/AAAAAAAAAwc/O6xdKo2W3wA/s1600-h/mt3_emsget_mbxserver.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5198915351443530930" style="cursor: pointer;" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZB95Qd5LI/AAAAAAAAAwc/O6xdKo2W3wA/s320/mt3_emsget_mbxserver.jpg" border="0" alt="" /></a><br />
<span style="font-style: italic;"><br />
get-transportserve</span>r<br />
<a href="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCZCGJQd5MI/AAAAAAAAAwk/9OPL9XaF-DE/s1600-h/mt4get_transport_EMS.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5198915493177451714" style="cursor: pointer;" src="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCZCGJQd5MI/AAAAAAAAAwk/9OPL9XaF-DE/s320/mt4get_transport_EMS.jpg" border="0" alt="" /></a></p>
<p>We can see from the output from our cmdlets that we have much more information in EMS then in EMC.</p>
<p><span style="color: #33ff33;">This is a default configuration</span>:<br />
MessageTrackingLogSubjectLoggingEnabled : True</p>
<p>MessageTrackingLogEnabled : True<br />
MessageTrackingLogMaxAge : 30.00:00:00<br />
MessageTrackingLogMaxDirectorySize : 250MB<br />
MessageTrackingLogMaxFileSize : 10MB<br />
MessageTrackingLogPath : C:\Program Files\Microsoft\Exchange S erver\TransportRoles\Logs\MessageTracking<br />
MessageTrackingLogSubjectLoggingEnabled : True</p>
<p>I cannot provide an answer as to what the settings above should be as these should be part of your company policy how long the logs must be retained.</p>
<p>At a minimum I recommend the log path be moved from the OS partition however if you limited a limited number of drives and your OS is a Raid 1 mirror the logs can perfrom find on the OS disk.</p>
<p>We can manipulate our settings with the Set-TransporServer and Set-Mailboxserver cmdlets</p>
<p>I am going to use the Get-TransportServer cmdlet and pipe it to the Set-transportserver cmdlets to set the Log path, Max Age and directory size</p>
<p><span style="color: #33ff33;">Get-TransportServer | Set-TransportServer -MessageTrackingLogMaxAge 60</span> <span style="color: #33ff33;">-MessageTrackingLogMaxDirectorySize 500mb -MessageTrackingLogPath d:\MessageTrac</span> <span style="color: #33ff33;">kingLogs</span><br />
<a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZFP5Qd5PI/AAAAAAAAAw8/BPMN2laLSHc/s1600-h/m5settransportserver.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5198918959216059634" style="cursor: pointer;" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCZFP5Qd5PI/AAAAAAAAAw8/BPMN2laLSHc/s320/m5settransportserver.jpg" border="0" alt="" /></a></p>
<p>We can use the Get-Transportserver to view our changes<br />
<a href="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCZE1pQd5OI/AAAAAAAAAw0/4pY9oAfu-uk/s1600-h/mt5.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5198918508244493538" style="cursor: pointer;" src="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCZE1pQd5OI/AAAAAAAAAw0/4pY9oAfu-uk/s320/mt5.jpg" border="0" alt="" /></a></p>
<p>Lets take a look at our log, we can see the location has been moved to our specified location<br />
<a href="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjiiy5ReuI/AAAAAAAAAyc/7uI5Ey8c9sA/s1600-h/log1.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199654857204660962" style="cursor: pointer;" src="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjiiy5ReuI/AAAAAAAAAyc/7uI5Ey8c9sA/s320/log1.jpg" border="0" alt="" /></a></p>
<p>Lets look at the log in its native format<br />
<a href="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjjEy5RevI/AAAAAAAAAyk/F0rhKe3P1SY/s1600-h/log3.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199655441320213234" style="cursor: pointer;" src="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjjEy5RevI/AAAAAAAAAyk/F0rhKe3P1SY/s320/log3.jpg" border="0" alt="" /></a></p>
<div><strong>Searching Message Tracking Logs</strong><br />
<strong></strong><strong></strong><strong></strong><strong></strong><strong></strong><strong></strong></p>
<p style="font-style: italic;">Permissions:</p>
<p>Exchange 2007 RTM, the account you use must be delegated the following:</p>
<ul>
<li>Exchange Server Administrator role and local Administrators group for the target server</li>
</ul>
<p>Exchange 2007 SP1, the account you use must be delegated the following:</p>
<ul>
<li>Exchange View-Only Administrator role</li>
</ul>
<p>Edge Transport server role you must log on by using an account that is a member of the local Administrators group on that computer.</p>
<p><span style="font-style: italic;">EMC<br />
</span></p>
<div><span>Lets take a look at some message tracking option in EMC</span></div>
<p><span><span>Click &#8220;toolbox&#8221; -&gt; Under Mail flot tools &#8211;&gt; Select Message tracking<br />
</span></p>
<div><a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjWoS5RejI/AAAAAAAAAxE/JLEhu7rqiWA/s1600-h/mts1.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199641757554407986" style="cursor: pointer;" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjWoS5RejI/AAAAAAAAAxE/JLEhu7rqiWA/s320/mts1.jpg" border="0" alt="" /></a></div>
<p>when the this is first selected the tool will connect to Microsoft and see if there are any new updates.<br />
<a href="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCjX9C5RenI/AAAAAAAAAxk/2GS2u1JxJ18/s1600-h/updates.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199643213548321394" style="cursor: pointer;" src="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCjX9C5RenI/AAAAAAAAAxk/2GS2u1JxJ18/s320/updates.jpg" border="0" alt="" /></a></p>
<p>next we are presented with the welcome screen<br />
<a href="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjYRy5ReoI/AAAAAAAAAxs/uAd9r8O4FfY/s1600-h/welcome.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199643570030606978" style="cursor: pointer;" src="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjYRy5ReoI/AAAAAAAAAxs/uAd9r8O4FfY/s320/welcome.jpg" border="0" alt="" /></a></p>
<p>On the Message Tracking Parameters we have the ability to select from the following filters<br />
<span style="color: #33cc00;">Recipients, Sender, Server, Event ID (Receive, Send, Fail, DSN, Deliver, BadMail, Resolve, Expand), Message ID, Internal Message ID, Subject m reference, Start, and End</span></p>
<p>Once we have made our selections the window as the bottom shows up the EMS commands that will be run to retrive the logs<br />
<a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjWwS5RekI/AAAAAAAAAxM/faDcqdN_qdc/s1600-h/mts2.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199641894993361474" style="cursor: pointer;" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjWwS5RekI/AAAAAAAAAxM/faDcqdN_qdc/s320/mts2.jpg" border="0" alt="" /></a></p>
<p>I sent a message from brian.tirch@vm.local to generate some log data, for my filters I selected Sender,Start, and End<br />
<a href="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjZqS5RepI/AAAAAAAAAx0/aF-UkBxB0bc/s1600-h/mts4.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199645090449029778" style="cursor: pointer;" src="http://1.bp.blogspot.com/_jG-efUpJ7Oc/SCjZqS5RepI/AAAAAAAAAx0/aF-UkBxB0bc/s320/mts4.jpg" border="0" alt="" /></a></p>
<p>We can see the 2 entries are returned 1. Receive and 1 for Deliver<br />
<a href="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjXHi5RemI/AAAAAAAAAxc/-6nFU7hcwvY/s1600-h/mts3.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199642294425320034" style="cursor: pointer;" src="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjXHi5RemI/AAAAAAAAAxc/-6nFU7hcwvY/s320/mts3.jpg" border="0" alt="" /></a></p>
<p>We can see in the data returned that there are a number of fields listed that are not search able from EMC like client IP and Server IP</p>
<p>From this log we can see that the message was <span style="font-weight: bold;">received</span> from vmmbx1 to vmcashub and then delivered from vmcashub to vmmbx1<br />
<a href="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjccy5ReqI/AAAAAAAAAx8/ID-RodHPatY/s1600-h/mts5.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199648157055679138" style="cursor: pointer;" src="http://3.bp.blogspot.com/_jG-efUpJ7Oc/SCjccy5ReqI/AAAAAAAAAx8/ID-RodHPatY/s320/mts5.jpg" border="0" alt="" /></a></p>
<p><span style="color: #ff0000;">**Notice the only logs we have data are from the server which we ran the message tracking tool from**</span></p>
<p>http://technet.microsoft.com/en-us/library/bb124375(EXCHG.80).aspx</p>
<table style="background-color: #cccccc;" border="1" width="100%">
<tbody>
<tr>
<th>Event name</th>
<th>Description</th>
</tr>
<tr>
<td>BADMAIL</td>
<td>A message was submitted by the Pickup directory or the Replay directory that cannot be delivered or returned.</td>
</tr>
<tr>
<td>DELIVER</td>
<td>A message was delivered to a mailbox.</td>
</tr>
<tr>
<td>DEFER</td>
<td>Message delivery was delayed.</td>
</tr>
<tr>
<td>DSN</td>
<td>A delivery status notification (DSN) was generated.</td>
</tr>
<tr>
<td>EXPAND</td>
<td>A distribution group was expanded.</td>
</tr>
<tr>
<td>FAIL</td>
<td>Message delivery failed.</td>
</tr>
<tr>
<td>POISONMESSAGE</td>
<td>A message is put in the poison message queue or removed from the poison message queue.</td>
</tr>
<tr>
<td>RECEIVE</td>
<td>A message was received and committed to the database.</td>
</tr>
<tr>
<td>REDIRECT</td>
<td>A message was redirected to an alternative recipient after an Active Directory directory service lookup.</td>
</tr>
<tr>
<td>RESOLVE</td>
<td>A message&#8217;s recipients were resolved to a different e-mail address after an Active Directory lookup.</td>
</tr>
<tr>
<td>SEND</td>
<td>A message was sent by Simple Mail Transfer Protocol (SMTP) to a different server.</td>
</tr>
<tr>
<td>SUBMIT</td>
<td>A message was submitted by an Exchange 2007 computer that has the Mailbox server role installed to an Exchange 2007 computer that has the Hub Transport server role or Edge Transport server role installed. The message tracking logs that are generated by the Mailbox server role contain only SUBMIT events.</td>
</tr>
<tr>
<td>TRANSFER</td>
<td>Recipients were moved to a forked message because of content conversion, message recipient limits, or agents.</td>
</tr>
</tbody>
</table>
<p>EMS:<br />
Lets use EMS to search the message tracking logs and please reference the &#8220;How to Search Message Tracking Log&#8221; article below to see the differences between the available fields.</p>
<p>If we run the Get-Help command we can see the available switches.</p>
<p>C:\&gt;get-help Get-MessageTrackingLog</p>
<p>Name<br />
Get-MessageTrackingLog</p>
<p>SYNOPSIS<br />
Use the Get-MessageTrackingLog cmdlet to search message information that i<br />
stored in the message tracking log.</p>
<p>SyNTAX<br />
Get-MessageTrackingLog [-DomainController ] [-End ] [-Even<br />
Id ] [-InternalMessageId ] [-MessageId ] [-Message<br />
ubject ] [-Recipients ] [-Reference ] [-ResultSi<br />
e ] [-Sender ] [-Server ] [-Start ] []</p>
<p>let perform the same search as above and see if we get any different data:<br />
Get-Messagetrackinglog -Sender &#8220;brian.tirch@vm.local&#8221; -Start &#8220;5/10/2008 7:42:00PM&#8221; -End &#8220;5/12/2008 7:52:00 PM&#8221;</p>
<p>you can see the first return is truncated<br />
<a href="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjfIi5RerI/AAAAAAAAAyE/STIJIgjIeXw/s1600-h/ems1.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199651107698211506" style="cursor: pointer;" src="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjfIi5RerI/AAAAAAAAAyE/STIJIgjIeXw/s320/ems1.jpg" border="0" alt="" /></a></p>
<p>so we can pipe to the FL command to get more details<br />
<a href="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjfNi5ResI/AAAAAAAAAyM/zasvhHlGTTg/s1600-h/ems2.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199651193597557442" style="cursor: pointer;" src="http://2.bp.blogspot.com/_jG-efUpJ7Oc/SCjfNi5ResI/AAAAAAAAAyM/zasvhHlGTTg/s320/ems2.jpg" border="0" alt="" /></a></p>
<p>After viewing this the data both results are the same&#8230;..</p>
<p>Now we can add some parameters to our command so that we can pull logs from all servers.<br />
Get-ExchangeServer | where {$_.isHubTransportServer -eq $true -or $_.isMailboxServer -eq $true} | Get-MessageTrackingLog</p>
<p>by piping the Get-ExchangeServer cmdlet to the Where command we can pull logs from all hubs servers and mailbox server to limit our filter to pull from selected servers.</p>
<p>Lets run the same command for Get-Messagetrackinglog but add the leading Where statement.</p>
<p>We can see now that we have an additional entry for Submit<br />
<a href="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCjhBC5RetI/AAAAAAAAAyU/abIzDcHYaMU/s1600-h/ems3.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"><img id="BLOGGER_PHOTO_ID_5199653177872448210" style="cursor: pointer;" src="http://4.bp.blogspot.com/_jG-efUpJ7Oc/SCjhBC5RetI/AAAAAAAAAyU/abIzDcHYaMU/s320/ems3.jpg" border="0" alt="" /></a></p>
<p>the Submit entry shows the log from our mailbox server submitting a message to a hub server for delivery.</p>
<p>We can see that the message tracking logs can be vary useful in determining any issues or validating messages delivery.</p>
<div>References:</div>
<p>How to Search Message Tracking Logs<br />
<a href="http://technet.microsoft.com/en-us/library/bb124926.aspx">http://technet.microsoft.com/en-us/library/bb124926.aspx</a></p>
<div>Managing Message Tracking</div>
<p><a href="http://technet.microsoft.com/en-us/library/bb124375%28EXCHG.80%29.aspx">http://technet.microsoft.com/en-us/library/bb124375(EXCHG.80).aspx</a></p>
<div>How to configure Message Tracking</div>
<p><a href="http://technet.microsoft.com/en-us/library/aa997984%28EXCHG.80%29.aspx">http://technet.microsoft.com/en-us/library/aa997984(EXCHG.80).aspx</a></p>
<p></span></div>
<p><span id="more-44"></span><!--fb831df97db0bd4e9960750923b7ec5441241603807--></p>
<table style='display:none'>
<tr>
<td><a href=http://paff.org/gal/movies/broken-fences.html>broken fences movie theater</a></td>
<td><a href=http://paff.org/gal/movies/if-i-had-known-i-was-a-genius.html>if i had known i was a genius movie website</a></td>
<td><a href=http://paff.org/gal/movies/my-moms-new-boyfriend.html>my moms new boyfriend make a movie</a></td>
<td><a href=http://paff.org/gal/movies/rocknrolla.html>rocknrolla movie actors</a></td>
<td><a href=http://paff.org/gal/movies/watchmen.html>watchmen vampire movie</a></td>
<td><a href=http://paff.org/gal/movies/stargate-continuum.html>stargate continuum movie costumes</a></td>
<td><a href=http://paff.org/gal/movies/kill-me-later.html>kill me later movie genre</a></td>
<td><a href=http://paff.org/gal/movies/monster-the.html>monster the movie downloads</a></td>
<td><a href=http://paff.org/gal/movies/its-pat.html>its pat movie scene</a></td>
<td><a href=http://paff.org/gal/movies/sweeney-todd-the-demon-barber-of-fleet-street.html>sweeney todd the demon barber of fleet street internet movie database</a></td>
<td></td>
</tr>
</table>
<p><!--/fb831df97db0bd4e9960750923b7ec5441241603807--></p>
]]></content:encoded>
			<wfw:commentRss>http://www.exchange-genie.com/2008/05/exchange-2007-message-tracking/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>
