Professional Documents
Culture Documents
The message tracking log is a detailed record of all activity as mail flows
through the transport pipeline on Mailbox servers and Edge Transport servers.
You can use message tracking for message forensics, mail flow analysis,
reporting, and troubleshooting.
By default, Exchange uses circular logging to limit the message tracking log
based on file size and file age to help control the hard disk space that's
used by the log files. To configure the message tracking log, see Configure
message tracking.
The other placeholders in the log file names represent the following
information:
yyyymmdd is the coordinated universal time (UTC) date when the log file
was created. yyyy = year, mm = month, and dd = day.
nnnn is an instance number that starts at the value 1 every day for each
log.
Information is written to the log file until the file reaches its maximum
size. Then, a new log file that has an incremented instance number is opened
(the first log file is -1, the next is -2, and so on). Circular logging
deletes the oldest log files for a service when either of the following
conditions are true:
Notes:
The message tracking log files are text files that contain data in the comma-
separated value (CSV) format. Each message tracking log file has a header
that contains the following information:
#Software: The value is Microsoft Exchange Server.
#Version: Version number of the Exchange server that created the message
tracking log file. The value uses the format 15.01.nnnn.nnn.
#Log-Type: The value is Message Tracking Log.
#Date: The UTC date-time when the log file was created. The UTC date-
time is represented in the ISO 8601 date-time format: yyyy-mm-
ddThh:mm:ss.fffZ, where yyyy = year, mm = month, dd = day, T indicates
the beginning of the time component, hh = hour, mm = minute, ss =
second, fff = fractions of a second, and Z signifies Zulu, which is
another way to denote UTC.
#Fields: Comma-delimited field names that are used in the message
tracking log files.
This is an example of the message tracking log entries created when the user
chris@contoso.com successfully sends a test message to the user
michelle@contoso.com. Both users have mailboxes on the same server.
Copy
EventId Source Sender Recipients MessageSubject
------- ------ ------ ---------- --------------
NOTIFYMAPI STOREDRIVER {}
RECEIVE STOREDRIVER chris@contoso.com {michelle@contoso.com} test
SUBMIT STOREDRIVER chris@contoso.com {michelle@contoso.com} test
HAREDIRECT SMTP chris@contoso.com {michelle@contoso.com} test
RECEIVE SMTP chris@contoso.com {michelle@contoso.com} test
AGENTINFO AGENT chris@contoso.com {michelle@contoso.com} test
SEND SMTP chris@contoso.com {michelle@contoso.com} test
DELIVER STOREDRIVER chris@contoso.com {michelle@contoso.com} test