Home » Exchange Server » How Much Database Storage Does Mailbox Audit Logging Consume?

How Much Database Storage Does Mailbox Audit Logging Consume?

Mailbox audit logging is a useful feature but some administrators become concerned when they learn that the audit logs are stored in the mailbox itself.

Does add a significant amount of data to the mailbox?

It really depends a lot on which audit options you’ve turned on, and how many mailbox in your organization are shared mailbox or have a lot of delegates performing actions on them.

What I can say is that my experience has been that mailbox audit logging, using the default 90 days retention and other audit settings, adds about 1-2% to the size of the mailbox. Of course, you should not take that as definitive and should perform some testing and analysis yourself, but I hope that my experience at least helps remove some of the uncertainty when it comes to storage impact of mailbox audit logging.

If you have turned on mailbox audit logging for a mailbox, and you know that actions are being logged already, you can check the size of the audits folder to see what kind of impact it is having.

In the example above the Audits folder is just 71KB in size, for a mailbox of about 1Gb in total size. This mailbox has just a small amount of delegate activity though. Other mailboxes in the same organization have upwards of 2-3MB of audit data, which is still not very much compared to total mailbox sizes of several gigabytes.

If mailbox audit logging has been widely deployed you can also use a simple script to collect these stats from all mailboxes. This example will list all mailboxes with their mailbox size and audit log size, and then export the stats for all of them to a CSV file at the end.

You can download the Get-AuditLogOverhead.ps1 script from the TechNet Script Gallery or from Github.

You could easily customize that for your own environment if you have the need.

Paul is a Microsoft MVP for Office Servers and Services. He works as a consultant, writer, and trainer specializing in Office 365 and Exchange Server. Paul is a co-author of Office 365 for IT Pros and several other books, and is also a Pluralsight author.
Category: Exchange Server

9 comments

  1. Brian says:

    I know this is an older post but was wondering if audit logging can be turned on for a Public Folder? Since these folders are usually shared, we would like to know how certain messages originated in a public folder. For example if a user drags a copy of a msg from their mailbox to a public folder. I cannot find a way to find that out without turning audit logging on.

    • I believe that turning up diagnostic logging for the public folders (in Exchange’s diagnostic logging settings) can cause audit logs to be written to the event logs for public folder deletions and other similar tasks, but I’ve never had to look into it closely.

  2. Geoff Morgan says:

    Hi,

    Hopefully you can help.
    We have an automated system that polls a mailbox and raises tickets from unread emails but some are not being picked up as they have been manually opened/read.
    Is it possible to determine who read an email in a shared mailbox.
    Messagebind is not an option when auditing for delegate access.

    geoff

  3. Charlie says:

    Hi Paul

    In your experience, is there any impact on the performance of the mailbox server when auditing is applied? We are looking into auditing about 10% of the users with all the features enabled. I’m not worried about the disk space consumed, but on the performance side.

    Cheers

Leave a Reply

Your email address will not be published. Required fields are marked *