Sentinel not ingesting all Office 365 logs from Exchange

Copper Contributor

Recently starting using Sentinel and we're ingesting Office 365 logs using the Microsoft 365 (formerly, Office 365) version 2.0 connector.

 

We're getting LOTS of data from Exchange but not all of it.   We don't seem to be getting any 'Receive' data which should be logging incoming messages to a user's mailbox.

We can see the 'Create' and 'Send' and many other operations... but nothing related to 'Receive'.

Additionally, on the 'Send' operations, we can't see the To: address of where our user's are sending outbound messages.

 

Where do I begin troubleshooting this?

 

0 Replies