Releases: Nico77600/ExchangeLogReport
Release list
Exchange Log Report 1.4.0
Exchange Log Report now finds where every Exchange server really writes its logs, and checks it at every collection.
-Mode Discoverreads the real log folders with the Exchange cmdlets, run in Windows PowerShell 5.1 (they are not supported in PowerShell 7): Exchange installed on another drive, SMTP logs moved per role, message tracking, POP/IMAP, and the IIS sites fromapplicationHost.config— including a second OWA/ECP site, recognised from its virtual directories. View-Only Organization Management is enough.- Every collection follows a moved IIS log folder at once, shows a missing folder, and warns when HttpProxy or IIS has stopped writing (stale source).
- Where to run it, and with which account (guide, chapter 4.1): SYSTEM on an Exchange server, or on an administration server a domain account that is local administrator of every Exchange server, with Log on as a batch job.
Download: ExchangeLogReport-1.4.0.zip contains only the files needed to run, with the HTML administrator guide (docs\ExchangeLogReport-Guide.html). There is no database in the package: the tool creates an empty one at the first collection. Requires PowerShell 7.4+ (and Windows PowerShell 5.1 for -Mode Discover, built into Windows Server).
Upgrading from 1.3.x: replace the files and keep your config, data and logs folders, then run -Mode Discover once. The database does not change.
Changes in 1.4.0
Added
-Mode Discover: finds where every Exchange server really writes its logs — installation folder, SMTP protocol logs per role and direction, message tracking, POP3/IMAP4 — with the Exchange cmdlets run in Windows PowerShell 5.1 (src\Get-ExlExchangeSettings.ps1: Exchange Management Shell on an Exchange server, Exchange remote PowerShell with Kerberos elsewhere,-ConnectTo,-Credential). View-Only Organization Management is enough. Folders on another drive are read through the administrative share of that drive. Every folder is checked from the collector; disabled message tracking, POP/IMAP and SMTP connector logging are reported. Result inconfig\ExchangeLogReport.paths.psd1.- IIS sites from
applicationHost.config(\\<server>\ADMIN$): log folder, format and target of Default Web Site, Exchange Back End and of every custom site hosting Exchange virtual directories (a second OWA/ECP site), recognised from its virtual directories alone. Custom front-end sites are read with the IIS front end, custom back-end sites with ActiveSync with the ActiveSync back end. - Checks at every collection:
applicationHost.configis read again, so a moved IIS log folder or a new/removed custom Exchange site is followed at once and reported until-Mode Discoverrecords it; an optional folder that does not exist (SMTP, MAPI, POP/IMAP, custom site) is shown as no folder; stale source warning when HttpProxy or IIS has no file newer thanCollection.StaleSourceHours(new setting, 24 h).-Mode Statusflags stale sources too. - Per-server path settings for each source (
FrontEndReceivePath,HubSendPath,IisFrontEndPath,MapiHttpPath...), which win over the paths file; unknown keys in aServersblock are rejected.
Changed
- Guide chapter 4: where to run the tool and with which account — SYSTEM on an Exchange server, or a domain account local administrator of every Exchange server (+ View-Only Organization Management for
-Mode Discover, Log on as a batch job on the administration server); why a local account does not work; network flows. Chapter 6.1 rewritten around-Mode Discover, chapter 7 with the task of both options, new troubleshooting entries, lab validation 14.2. - Exit code 2 now also means a stale source or IIS folders changed since
-Mode Discover. - The console shows where the paths of each server come from (Discover, configuration, defaults).
Full history: CHANGELOG.md
Package updated on 2026-10-02
Same version, same files, no change to what the tool does: the README and the guide now start with a note to unblock the files downloaded from the Internet (Get-ChildItem "C:\Chemin\Du\Dossier" -Recurse -File -Force | Unblock-File).
Exchange Log Report 1.3.1
First public release.
Exchange Log Report reads the IIS / HTTP Proxy, MAPI over HTTP, ActiveSync, POP/IMAP, SMTP protocol and message tracking logs of several Exchange Server SE servers into a local SQLite database, removes the noise (health mailboxes, Managed Availability probes, load balancer checks, SMTP connections without message) before storage, and produces usage and troubleshooting reports as CSV and HTML files: client sessions with their timeline across front-end and back-end logs, failed and slow requests with their resolution, one row per message with its full route, SMTP clients.
Download: ExchangeLogReport-1.3.1.zip contains only the files needed to run, with the HTML administrator guide (docs\ExchangeLogReport-Guide.html). There is no database in the package: the tool creates an empty one at the first collection. Requires PowerShell 7.4+.
Changes in 1.3.1
Added
tools\New-DocumentationImages.ps1: renders the graphics of the GitHub README (banner, why, how it works, noise, sessions and messages) in a light and a dark version, from the cards and flow blocks of the guide, with its CSS and icons.- HTML guide
docs\ExchangeLogReport-Guide.html, same format as the other tools (Purview DLP Report): self-contained (images inline), sidebar with parts and chapters, light/dark theme, copy buttons, print layout. Built from the Markdown guide by the newtools\Build-Documentation.ps1.
Changed
- Guide: what is removed before storage (chapter 3) and the client session and message correlation (chapter 11) are now shown as cards and flows.
- Guide reorganised in four parts (Understand, Set up, Use, Maintain) and annexes, with a quick start, cards, steps and callouts; content updated to 1.3 (six tabs, SMTP clients, refusals in Messages).
- The package ships the HTML guide only (rebuilt by
tools\New-ExchangeLogReportPackage.ps1before copying); the Markdown source and the images stay in the development folder. - Screenshots of the guide taken from the lab report with generated traffic, anonymised (Contoso names), and a capture of the console of a detailed report.
Fixed
- Detail dialogs: in the small tables (transactions of an SMTP client, client sessions of a user, clients and devices), times, servers, statuses and counters no longer wrap in the middle of a word.
- Console banner: the subtitle is shorter and can no longer push the right border of the frame.
Full history: CHANGELOG.md