Open rugenl opened 1 month ago
Pinging @elastic/sec-windows-platform (Team:Security-Windows Platform)
I am having this issue as well.
microsoft.exchange.relatedrecipientaddress contains an email address but is mapped as an IP.
Microsoft's documentation (https://learn.microsoft.com/en-us/exchange/mail-flow/transport-logs/message-tracking?view=exchserver-2019#fields-in-the-message-tracking-log-files) describes the related-recipient-address field as: "This field is used with EXPAND, REDIRECT, and RESOLVE events to display other recipient email addresses that are associated with the message."
Field is mapped as IP but contains email address, so it's not searchable. Probably should be keyword.