Exchange Admin Audit Log Event ID 25240

SourceExchange (LOGbinder EX)
LogAdmin Audit
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success
Failure

25240: New-RetentionPolicyTag Exchange cmdlet issued

This is an event from Exchange audit event from LOGbinder EX generated by Log  Admin Audit.

On this page

See also the TechNet article on the cmdlet New-RetentionPolicyTag

Free Security Log Resources by Randy

Description Fields in 25240

Field Description
Occurred Date and time when Exchange registered the cmdlet.
Cmdlet The cmdlet that was issued.
Performed by The user who issued the cmdlet.
Succeeded "Yes", if succeeded, "No", otherwise.
Error "None", if the cmdlet resulted in no error, the error message otherwise.
Originating server The host name of the server.
Object modified The object that was modified by the cmdlet.
Parameters The list of parameters, listing them by the parameter's Name and Value.
Modified properties Modified properties, if any (otherwise "n/a").
Additional information Additional information, if any (otherwise "n/a").

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 25240

New-RetentionPolicyTag Exchange cmdlet issued
Occurred: 7/7/2014 6:24:57 PM
Cmdlet: New-RetentionPolicyTag
Performed by: lb.local/Users/Administrator
Succeeded: Yes
Error: n/a
Originating server: DEV1 (15.00.0516.025)
Object modified: 1 month premanent delete audit log search results
Parameters
  Name: Name, Value: [1 month premanent delete audit log search results]
Name: Type, Value: [DeletedItems]
Name: RetentionAction, Value: [PermanentlyDelete]
Name: RetentionEnabled, Value: [True]
Name: AgeLimitForRetention, Value: [31.00:00:00]
Name: Comment, Value: []
Modified Properties
  n/a
Additional information: CmdletParameters/Parameter/Name= [Name]; CmdletParameters/Parameter/Value= [1 month premanent delete audit log search results]; CmdletParameters/Parameter/Name= [Type]; CmdletParameters/Parameter/Value= [DeletedItems]; CmdletParameters/Parameter/Name= [RetentionAction]; CmdletParameters/Parameter/Value= [PermanentlyDelete]; CmdletParameters/Parameter/Name= [RetentionEnabled]; CmdletParameters/Parameter/Value= [True]; CmdletParameters/Parameter/Name= [AgeLimitForRetention]; CmdletParameters/Parameter/Value= [31.00:00:00]; CmdletParameters/Parameter/Name= [Comment]; CmdletParameters/Parameter/Value= []

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25240

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!