{"id":789,"date":"2020-04-11T10:12:00","date_gmt":"2020-04-11T08:12:00","guid":{"rendered":"https:\/\/itblogwildi.wordpress.com\/?p=789"},"modified":"2020-04-11T10:12:00","modified_gmt":"2020-04-11T08:12:00","slug":"verbindungsdaten-mail-aus-exchange-exportieren","status":"publish","type":"post","link":"https:\/\/itblog.wildi.dk\/?p=789","title":{"rendered":"Verbindungsdaten (Mail) aus Exchange exportieren"},"content":{"rendered":"\n<p>In einem komplexeren Fall musste ich die gesamten Verbindungsdaten des ganzen Mailservers untersuchen, um einige spezielle Mails zu identifizieren. Im konkreten Fall ging es darum, festzustellen, ob noch \u00fcber eine spezifische Inboud-Connector-IP Mails versendet werden.<\/p>\n\n\n\n<p>Normalerweise verwende ich PowerShell und exportiere in csv. Diese Files importiere ich dann in Excel. In Excel kann ich dessen potenten Sortier- und Filterfunktionen nutzen.<\/p>\n\n\n\n<p>Doch hier stiess ich an eine Grenze. Ich musste den Wert &#171;EventData&#187; exportieren. In Excel (via Export-Csv) erhielt ich nur unsinnige Daten:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">System.Collections.Generic.KeyValuePair`2[System.String,System.Object][]<\/pre>\n\n\n\n<p>Also wechselte ich auf<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">ConvertTo-Html<\/pre>\n\n\n\n<p>und<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Out-File<\/pre>\n\n\n\n<p>Da sich in diesem Fall die Info \u00fcber die Server-IP nur in den Logs mit &#171;EventID = RECEIVE&#187; befand, habe ich noch danach gefiltert:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">Get-MessageTrackingLog -Start (Get-Date).AddDays(-5) -ResultSize Unlimited | Where-Object {$_.EventID -match \"RECEIVE\"} | convertto-HTML TimeStamp,Sender,{$_.recipients},MessageSubject,{$_.EventData} | out-file C:\\Temp\\ExportLog_01.html<\/pre>\n\n\n\n<p>Das ergibt ein &#171;sch\u00f6nes&#187; HTML File, welches auch problemlos durchsucht werden kann.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In einem komplexeren Fall musste ich die gesamten Verbindungsdaten des ganzen Mailservers untersuchen, um einige spezielle Mails zu identifizieren. Im&#8230; <a class=\"read-more\" href=\"https:\/\/itblog.wildi.dk\/?p=789\">Read more<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,29],"tags":[],"class_list":["post-789","post","type-post","status-publish","format-standard","hentry","category-exchange","category-powershell"],"_links":{"self":[{"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=\/wp\/v2\/posts\/789","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=789"}],"version-history":[{"count":0,"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=\/wp\/v2\/posts\/789\/revisions"}],"wp:attachment":[{"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=789"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=789"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itblog.wildi.dk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=789"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}