Exchange Admin Audit Log Event ID 25394
25394: Set-InboxRule Exchange cmdlet issued
This is an event from
Exchange
audit event from
LOGbinder EX
generated by
.
On this page
See also the TechNet article on the cmdlet Set-InboxRule
Free Security Log Resources by Randy
Field | Description |
Occurred | Date and time when Exchange registered the cmdlet. |
Cmdlet | The cmdlet that was issued. |
Performed by | The user who issued the cmdlet. |
Succeeded | "Yes", if succeeded, "No", otherwise. |
Error | "None", if the cmdlet resulted in no error, the error message otherwise. |
Originating server | The host name of the server. |
Object modified | The object that was modified by the cmdlet. |
Parameters | The list of parameters, listing them by the parameter's Name and Value. |
Modified properties | Modified properties, if any (otherwise "n/a"). |
Additional information | Additional information, if any (otherwise "n/a"). |
Setup PowerShell Audit Log Forwarding in 4 Minutes
This Event Is Produced By

Which Integrates with Your SIEM
Set-InboxRule Exchange cmdlet issued
Occurred: 12/23/2012 3:27:18 PM
Cmdlet: Set-InboxRule
Performed by: sp2010.com/Users/Joe Taylor
Succeeded: Yes
Error: None
Originating server: SP2010-EX1 (14.02.0328.009)
Object modified: sp2010.com/Users/Bill Smith\13968922646776127335
Parameters
Name: Mailbox, Value: [BillSmith@sp2010.com]
Name: Identity, Value: [CheckActionRequired]
Name: MarkImportance, Value: [Low]
Modified Properties
Name: MarkImportance, Old Value: [High], New Value: [Low]
Additional information: CmdletParameters/Parameter/Name= [Mailbox]; CmdletParameters/Parameter/Value= [BillSmith@sp2010.com]; CmdletParameters/Parameter/Name= [Identity]; CmdletParameters/Parameter/Value= [CheckActionRequired]; CmdletParameters/Parameter/Name= [MarkImportance]; CmdletParameters/Parameter/Value= [Low]; ModifiedProperties/Property/Name= [MarkImportance]; ModifiedProperties/Property/OldValue= [High]; ModifiedProperties/Property/NewValue= [Low]
For more information, see http://logbinder.com/support
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection