Exchange provides the following journaling options:
- Premium journaling: [Suggested] Use journal rules to journal messages based on recipients (all recipients or specified recipients), and scope (internal messages, external messages, or all messages).
- Standard journaling: Journal all messages that are sent to and received by mailboxes on a specific mailbox database. To journal all messages in your organization, you need to configure journaling on all mailbox databases on all Exchange servers.
Premium Journaling
Premium journaling uses journal rules to record messages based on recipients (all recipients or specified recipients) and scope (internal messages, external messages, or all messages). Premium journaling requires Exchange Enterprise client access licenses (CALs) only for filtering .
For more information about CALs, see Exchange Server Licensing.
- Log on to the Exchange admin center of your Microsoft Exchange environment.
- Select the compliance management menu item.
- On the journal rules tab, click on + (New).
- The dialog window New Journal Rule opens:
- In the Send journal reports to: archiver@archiver_hostname where "archiver_hostname" is the FQDN of your LibraCyber Archiver appliance.
- Enter a name for the journal rule, e.g. Archiver Journaling.
- In the If the message is sent to or received from... section select whether the rule should apply to all messages or to specific users or groups.
- Under Journal the following messages..., choose whether to capture all messages, internally sent messages only, or only those messages with an external sender or recipient.
- Click on save to activate the rule.
Create a Send Connector
To create the Send Connector to forward journal traffic to the LibraCyber Archiver proceed as follows:
- Open the Exchange Management Console web page
- Click on Mail Flow
- Select Send Connector tab
- Click the “+” symbol to create a new connector.
- In Name field, enter LibraCyber Archiver
- Select Custom as Type
- Click Next
- Select Route mail through smart hosts
- Enter the IP address of the LibraCyber Archiver server. Click Save, then Next
- Leave smart host authentication settings as None. Click Next
- Click [+] in Address Space
- Enter fully qualified domain name (FQDN) of the LibraCyber Archiver (e.g. archiver.yourcompany.com). Leave defaults SMTP as Type and 1 as Cost.
- Choose the hub transport servers that apply (if you have only one Exchange server, choose it by clicking on + button)
- Click Finish.
LibraCyber Archiver Configuration On the LibraCyber Archiver you need to setup a SMTP Listener that will accept the journal traffic sent from your Exchange Server.
- Select menù Archiver->Mail Sources->SMTP Journaling and click on the green [+] to add a new listener:
Select IP Authentication and enter your Exchange IP Address. Select SMTP Journaling under Type Dropdown and make it Active.
- Check that emails are forwarded into your LibraCyber Archiver.
Setup Standard Journaling
Standard journaling records all messages that are sent to and received by all mailboxes on the specified mailbox database. You enable journaling by specifying the journaling mailbox for the database (the mailbox that stores the journaled messages). The steps required are:
- Create the Journaling Mailbox
- Setup the Standard Journaling
Step 1 - Journaling Mailbox If you already have a Journaling Mailbox you can go directly to Step 2
- Log on to the Exchange admin center of your Microsoft Exchange environment as an Exchange administrator.
- Choose the recipients menu item.
- In the mailboxes section, click on + (New) and choose User mailbox.
- Enter a valid Alias (e.g. journal).
- Select the option New user.
- Enter the necessary data to create a new user.
- Click on More options...
- Click on Browse to select a mailbox database.
- Click on save.
Step 2 - Standard Journaling Setup
- Log on to the Exchange admin center of your Microsoft Exchange environment.
- Select the servers menu item.
- On the databases tab, double-click on the mailbox database for which you want to set up journaling.
- Select the maintenance tab.
- Click on browse... next to the Journal recipient: box.
- Select the user that was created in step 1 from the recipient list and confirm with OK.
- Click on Save
LibraCyber Archiver Configuration You now have to configure the LibraCyber Archiver to retrieve these messages. Supported protocols are IMAP(S) and POP3(S).
- Take note of all the informations needed to access the journal mailbox defined above
- On the LibraCyber Archiver click the menù Archiver->Mail Sources->IMAP/POP3 Journaling
- Click on the green [+] to add a new entry
- Fill in all the informations to access the mailbox. Under Type dropdown select Forwaring and leave enabled Delete mails after indexing.
- Validate your settings and Save
- Check that emails are pulled into your LibraCyber Archiver.