Exchange Admin Audit Log Event ID 25110

SourceExchange (LOGbinder EX)
LogAdmin Audit
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success
Failure
Discussions on Event ID 25110
Ask a question about this event

25110: Add-IPBlockListProvider Exchange cmdlet issued

This is an event from Exchange audit event from LOGbinder EX generated by Log  Admin Audit.

On this page

See also the TechNet article on the cmdlet Add-IPBlockListProvider

Free Security Log Resources by Randy

Description Fields in 25110

Field Description
Occurred Date and time when Exchange registered the cmdlet.
Cmdlet The cmdlet that was issued.
Performed by The user who issued the cmdlet.
Succeeded "Yes", if succeeded, "No", otherwise.
Error "None", if the cmdlet resulted in no error, the error message otherwise.
Originating server The host name of the server.
Object modified The object that was modified by the cmdlet.
Parameters The list of parameters, listing them by the parameter's Name and Value.
Modified properties Modified properties, if any (otherwise "n/a").
Additional information Additional information, if any (otherwise "n/a").

Supercharger Free Edition

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 25110

Add-IPBlockListProvider Exchange cmdlet issued
Occurred: 12/23/2012 3:29:20 PM
Cmdlet: Add-IPBlockListProvider
Performed by: sp2010.com/Users/Joe Taylor
Succeeded: Yes
Error: None
Originating server: SP2010-EX1 (14.02.0328.009)
Object modified: TestIpBlockListProvider
Parameters
  Name: Name, Value: [TestIpBlockListProvider]
Name: LookupDomain, Value: [anotherdomain.com]
Name: RejectionResponse, Value: [Originating IP address matched to IP Block List provider service]
Modified Properties
  Name: LookupDomain, Old Value: [], New Value: [anotherdomain.com]
Name: Rejectionmessage, Old Value: [], New Value: [Originating IP address matched to IP Block List provider service]
Name: Id, Old Value: [], New Value: [TestIpBlockListProvider]
Name: RawName, Old Value: [], New Value: [TestIpBlockListProvider]
Name: OrganizationId, Old Value: [], New Value: []
Additional information: CmdletParameters/Parameter/Name= [Name]; CmdletParameters/Parameter/Value= [TestIpBlockListProvider]; CmdletParameters/Parameter/Name= [LookupDomain]; CmdletParameters/Parameter/Value= [anotherdomain.com]; CmdletParameters/Parameter/Name= [RejectionResponse]; CmdletParameters/Parameter/Value= [Originating IP address matched to IP Block List provider service]; ModifiedProperties/Property/Name= [LookupDomain]; ModifiedProperties/Property/OldValue= []; ModifiedProperties/Property/NewValue= [anotherdomain.com]; ModifiedProperties/Property/Name= [Rejectionmessage]; ModifiedProperties/Property/OldValue= []; ModifiedProperties/Property/NewValue= [Originating IP address matched to IP Block List provider service]; ModifiedProperties/Property/Name= [Id]; ModifiedProperties/Property/OldValue= []; ModifiedProperties/Property/NewValue= [TestIpBlockListProvider]; ModifiedProperties/Property/Name= [RawName]; ModifiedProperties/Property/OldValue= []; ModifiedProperties/Property/NewValue= [TestIpBlockListProvider]; ModifiedProperties/Property/Name= [OrganizationId]; ModifiedProperties/Property/OldValue= []; ModifiedProperties/Property/NewValue= []

For more information, see http://logbinder.com/support

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources