A clerk's mailbox grew a hidden forwarding rule. Separately, the SOC needs the path of one phishing message through Exchange Online. Which sourcetype split is correct?
Select an answer to reveal the explanation.
Short Explanation
Two different mail cameras: the audit log sees someone plant a forwarding rule, and message trace sees where one letter traveled. Mixing them—or substituting CloudTrail or Windows logs—is how the story falls apart. Pick the sourcetype that holds that fact.
Full Explanation
Office 365 Management Activity and related mailbox-audit sourcetypes record configuration persistence such as inbox rules. Exchange Online message trace, or equivalent mail-flow logs, records the path of a specific message. SSE and ES content is sourcetype-specific, so those feeds are not interchangeable. CloudTrail and local Windows security do not replace either Microsoft 365 mail sourcetype.