cancel
Showing results for 
Search instead for 
Did you mean: 

E-discovery not finding all items

mstawchansky
Level 4
Ok, so doing a very simple search in E-Discovery for a 2 week time frame yields approximately 50 items. By simple search, I mean just doing a To/From for a single email address. As I knew this user should have significantly more information, I browsed our Journal_Archive that is attached to that users mail server. This showed approximately 500 items for that email address for the same time frame. So, I'm not too pleased that it appears the discovery specific product appears to be producing worse results than a simple Web GUI search of the archive in question. Any ideas where I should start on this? Mike
1 ACCEPTED SOLUTION

Accepted Solutions

TonySterling
Moderator
Moderator
Partner    VIP    Accredited Certified

Did you check the box to included items already in review?

View solution in original post

6 REPLIES 6

TonySterling
Moderator
Moderator
Partner    VIP    Accredited Certified

Sounds like the search isn't configured correctly.

Is this the first search you are running in this case?

Do you have the address entered in a To field and From field or a To/From field?

Are you searching the user archive or the journal archive?

 

mstawchansky
Level 4

Nope, run several searches for this case. We have 2 Vault stores, the first several searches allowed all Vault's to be searched.

 

To try to narrow it down, I modified the search to only look in the Journal Archive for the server the user is located on ( the one I manually searched with the Web GUI for EV ) and found nothing.

 

I had the address entered in a To/From field; this was the only search item I set.

 

Initiallly searched all archives (including the user's archive), then narrowed it down to just the Journal as I knew all items To/From this user should be captured in there.

TonySterling
Moderator
Moderator
Partner    VIP    Accredited Certified

Did you check the box to included items already in review?

Liam_Finn1
Level 6
Employee Accredited Certified

When you do the to or from do you only use one description of the user?

 

Example User name Joe Blogs

So you should search for "Joe, Blogs" "Blogs, Joe" and then the SMTP address eg "jblogs@ xyz.com"

 

this covers all your bases

 

mstawchansky
Level 4

And the winner is....

 

Thanks much - that was the issue. There were 3 or 4 other searches that had already gathered some of that info, adding that allowed the search to find it all.

mstawchansky
Level 4

Thanks.

 

Definitely good to know, I've always tried searching on multiple avenues but it is good to have a reminder to hit all the permutations that may show up.