Windows Security Log Events
Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
All events
Win2000, XP and Win2003 only
Vista and Win2008 only
Required when sub-category selected.
Subcategories:
(Vista and Win2008 only)
All subcategories
Application Group Management
Computer Account Management
Distribution Group Management
Other Account Management Events
Security Group Management
User Account Management
Category:
Account Management
Subcategory:
User Account Management
4720
-
A user account was created
4722
-
A user account was enabled
4723
-
An attempt was made to change an account's password
4724
-
An attempt was made to reset an accounts password
4725
-
A user account was disabled
4726
-
A user account was deleted
4738
-
A user account was changed
4740
-
A user account was locked out
4765
-
SID History was added to an account
4766
-
An attempt to add SID History to an account failed
4767
-
A user account was unlocked
4780
-
The ACL was set on accounts which are members of administrators groups
4781
-
The name of an account was changed
4794
-
An attempt was made to set the Directory Services Restore Mode administrator password
5376
-
Credential Manager credentials were backed up
5377
-
Credential Manager credentials were restored from a backup
Upcoming Webinars
Absolute Power: Controlling the Risk of Domain Admins
Catching Intruders by Enriching Security Logs with Geolocation and Network Visualization
Additional Resources
Security Log Quick Reference Chart
Security Log Resource Kit
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
Encyclopedia
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Home
>
Security Log
>
Encyclopedia
User name:
Password:
/
Forgot?
Register
Home