Google
Search WWW Search msexchangetips.blogspot.com

Sunday, September 03, 2006

Exchange: Exporting and Querying Message Tracking Logs Using Log Parser

Summary:

Exchange Message Tracking utility is a great feature which enables administrators to track message flow for troubleshooting or verification. To enable message tracking, you must go into the properties of the server in Exchange System Manager. In ESM (Exchange System Manager) expand your administrative group, servers, highlight your server, right click properties. Here, you see the option to enable message tracking. In Exchange 2003 you can specify the directory on this pane as to where you want to store these message tracking log files. For 2000 these logs are stored in your Program Files\Exchsrvr\ExServer1.log directory. If you wish to change the location, follow the KB article at the end of this article. When using this tool from ESM, the information is gathered from these message tracking logs. If you were to open these log files, you can see that it is very difficult to read and the message tracking tool in ESM does not give you the option to pipe the results in a file. This article will go over how to export the contents of the message tracking log file to a more friendly text file using Log Parser utility.


Export Exchange Message Tracking Log to a CSV File using Log Parser

1. Download LogParser 2.2

http://www.microsoft.com/downloads/details.aspx?FamilyID=890cd06b-abf8-4c25-91b2-f8d975cf8c07&displaylang=en

Note: You can also use the Log Parser GUI but is very limited. You can download the GUI version from: http://www.logparser.com/simpleLPview00.zip

If you wish to use the GUI version, copy all DLLs and EXE files to the your system32 folder and run the LPview00.exe from the system32 folder. (The following steps below assume that you are working with the CLI version.

2. Once you have download Logparser 2.2, go to Start Menu, Programs, Log Parser 2.2, Log Parser 2.2. This will launch a command prompt.

3. Now you can run SQL statements against the message tracking log file. The example below will query any entry where the recipient address is user1@company.com and export it to a text file called export.txt

C:\Program Files\Log Parser 2.2>logparser -q -i:w3c "SELECT* FROM c:\temp2\log.log
WHERE Recipient-Address like `user1@company'" > c:\export.txt

I will have more sample SQL queries soon so check back! If you wish to request a specific SQL query, you can email from.

References:

LogParser References
www.logparser.com
http://www.securityfocus.com/infocus/1712.

How to change the location of the message tracking logs in Exchange 2000 Server
http://support.microsoft.com/kb/317700/



James Chong
MCSE M+, S+, MCTS, Security+
msexchangetips.blogspot.com


How useful was this article? Want to see a tip not listed? Please leave a comment.

11 Comments:

Anonymous Anonymous said...

Very helpful, sent me in the right direction. Thank you.

8:25 AM  
Anonymous Anonymous said...

Excellent tip, helped me a lot .. thanks Linus

10:50 PM  
Anonymous Anonymous said...

It sounded good, but all I get is syntax errors from the CLI and the GUI:

logparser -q -i:w3c SELECT* FROM "C:\Program Files\Exchsrvr\DCC1.log WHERE Recipient-Address like 'nicole@dcc.local'"> c:\export.txt

returns error: detected extra arguement "FROM" after Query

No amount of changing anything results in a valid response unfortunately. . . .

7:07 PM  
Anonymous Anonymous said...

logparser -q -i:W3C "SELECT * FROM C:\Progra~1\Exchsrvr\EX1000.log\20090319.log WHERE Recipient-Address like 'user@domain.com'" > C:\myuser.txt

8:26 AM  
Blogger Arturo said...

after type the query:

logparser -q -i:w3c SELECT* FROM "C:\Program Files\Exchsrvr\DCC1.log WHERE Recipient-Address like 'ralcant@qro.gov'"> c:\export.txt

and it returns error:
detected extra arguement "FROM" after Query

Could somebody help me with this?

12:13 PM  
Blogger longge said...

Still today, replica handbags is recognized for its high quality purse. At the factory level, if a purse does not meet the replica louis vuitton standards it is destroyed. replica handbags has been in business for an amazing 3 centuries and replica bags continues to be fore front in the hand bag industry.

6:44 PM  
Blogger Alex said...

My friend works with emails every weekend. But one day he applied for help to me and I quickly advised him tool which I found out on an one big soft blog. He was glad and thanked me a lot. Moreover it would be good choice in this condition - recovery edb.

5:12 AM  
Anonymous Georsad said...

I'm lost Here and I would Like that maybe you could help me to complete a task that i want to do.

I had backup several Exchange 2007 logs, those logs has the folowing format:
MSGTRK20100901-1
MSGTRK20100901-2
MSGTRK20100902-1
MSGTRK20100902-2 and so on...

By every day, I obtain two pairs of logs.

When I try to read them using LogParse, the logparse start to read the first log (MSGTRK20100901-1), everything goes well, but then finish with this error:
Error while reading from file "Z:\MSGTRK2010
0901-1.LOG": The parameter is incorrect.

I tryed several querys and all end allways with this error. Now I'm stuck here because it seems that logParser is capable to read the first part of the log file, but then when try to start the second part of the file simply stops and show me the error stated above.

Can you show me some light on this?

Btw: The query that I try to use is:
Logparser.exe -i:csv "select * into Z:\NewParsedFile.csv from Z:\*.log" -nSkipLines:4 -o:csv

Z: Directory has all the Exchange tracking log files that I want to read.

Best Regards.

1:53 PM  
Blogger Young said...

These onitsuka tiger online shop are buy asics tigers online awesome, tiger asics shoes but huge! I cheap onitsuka tiger had to asics tiger australia return twice cheap onitsuka tiger shoes because they onitsuka tiger zodiac were so big asics tiger I normally onitsuka tiger australia wear a 7.5 but ended up fitting asics onitsuka tiger mexico nicely into a tiger mexico 66. Other than that, onitsuka tiger shoes australia they look spiffy, seem onitsuka tiger mexico 66 black well made tiger mini cooper only had asics onitsuka so far, and they tiger shoes australia are still holding buy onitsuka tiger shoes online together mexico 66 perfectly, onitsuka tiger yellow black as they should be), and onitsuka tiger tokyo they came onitsuka tiger ultimate 81 with two asics onitsuka tiger trainers colors of laces asics kinsei. I onitsuka tiger mexico 66 yellow black would certainly tiger shoes onitsuka buy other onitsuka tiger sale colors of discount asics running shoes that I know onitsuka tiger mexico 66 my correct onitsuka tiger black white this brand buy onitsuka tiger shoes is a good asics international shipping best online onitsuka tiger online store

3:35 AM  
Blogger sping said...

It is pretty easy: “It is practically a true religion jeans sale,” Som says. “Ultimately there’s a very strict template and that’s appealing to almost everybody.”

2:11 AM  
Anonymous Computer said...

Wow! This can be one particular of the most beneficial blogs we have ever arrived across on this subject. Actually Magnificent. I am also a specialist in this topic so I can understand your hard work.

Computer Accessories | buy webcam

4:10 AM  

Post a Comment

<< Home

xml:lang="en" lang="en"> MS Exchange Tips: Exchange: Exporting and Querying Message Tracking Logs Using Log Parser