The goal is to find the delay between the time sender sents the mail and recipient receive the mail , if the delay is more than 10 mins then alert
Message tracking logs C:\Program Files\Microsoft\Exchange Server\V14\TransportRoles\Logs\MessageTracking in exchange server2010. But the logs didn provide the actual time when the user sent the email, also the original IP of the sender is replaced with LB/Exchange server/relay server/firewall.
So now I looking for other options. One of them is using Splunk stream.