Windows Security Log Events
All Sources
Windows Audit
SharePoint Audit
(
LOGbinder for SharePoint
)
SQL Server Audit
(
LOGbinder for SQL Server
)
Exchange Audit
(
LOGbinder for Exchange
)
Sysmon
(
MS Sysinternals Sysmon
)
Windows Audit Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
Subcategories:
All subcategories
Detailed Directory Service Replication
Directory Service Access
Directory Service Changes
Directory Service Replication
Windows Versions:
All events
Win2000, XP and Win2003 only
Win2008, Win2012R2, Win2016 and Win10+, Win2019
Required when sub-category selected.
Category:
Directory Service
Subcategory:
Detailed Directory Service Replication
Windows
4929
An Active Directory replica source naming context was removed
Windows
4930
An Active Directory replica source naming context was modified
Windows
4931
An Active Directory replica destination naming context was modified
Windows
4934
Attributes of an Active Directory object were replicated
Windows
4935
Replication failure begins
Stay up-to-date on the Latest in Cybersecurity
Sign up for the Ultimate IT Security newsletter to hear about the latest webinars, patches, CVEs, attacks, and more.
Work Email:
Upcoming Webinars
Identity as the Kill Chain: Stopping Lateral Movement Across AD, Cloud, and AI
Patching 3rd Party Apps on PCs Managed by Intune
Additional Resources
Encyclopedia
•
Event IDs
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Tweet
User name:
Password:
/
Forgot?
Register
March 2026
Patch Tuesday
"Patch Tuesday - Two Zero-Days for the Month " - sponsored by LOGbinder
Home
Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.