SQL Server Audit Log Event ID 24048

SourceSQL Server (LOGbinder SQL)
Action GroupAUDIT_CHANGE_GROUP
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

24048: Issued a create database audit specification command (action_id CR class_type DA)

This is an event from SQL Server audit event from LOGbinder SQL generated by Action Group  AUDIT_CHANGE_GROUP.

On this page

A create database audit specification command was issued

Free Security Log Resources by Randy

Description Fields in 24048

Field Description
Occurred When event was reported by SQL Server
Authorization result If the command passed authorization checks
Session ID ID of the session on which the event occurred
User  
Server  
Database Database affected by the event
Audit Specification Name Defines which Audit Action Groups will be audited for the entire server (Server Audit Specification) or database (Database Audit Specification). See SQL Server Audit Policy .
Statement Transact-SQL statement

Supercharger Free Edition

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 24048

Issued a created database audit specification command
A create database audit specification command was issued
Action Group: AUDIT_CHANGE_GROUP
Occurred: 9/16/2013 1:26:41.0000000 AM
Authorization result: Access allowed
Session ID: 60
User: LB\Administrator
Server: DEV2
Database: master
Audit Specification Name: TestDBAuditSpec
Statement: CREATE DATABASE AUDIT SPECIFICATION TestDBAuditSpec ; FOR SERVER AUDIT TestServerAudit ; -- ADD (APPLICATION_ROLE_CHANGE_PASSWORD_GROUP),; -- ADD (AUDIT_CHANGE_GROUP),; -- ADD (BACKUP_RESTORE_GROUP),; -- ADD (DATABASE_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_ACCESS_GROUP),; -- ADD (DATABASE_OBJECT_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_OWNERSHIP_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_PERMISSION_CHANGE_GROUP),; -- ADD (DATABASE_OPERATION_GROUP),; -- ADD (DATABASE_OWNERSHIP_CHANGE_GROUP),; -- ADD (DATABASE_PERMISSION_CHANGE_GROUP),; -- ADD (DATABASE_PRINCIPAL_CHANGE_GROUP),; -- ADD (DATABASE_PRINCIPAL_IMPERSONATION_GROUP),; -- ADD (DATABASE_ROLE_MEMBER_CHANGE_GROUP),; -- ADD (DBCC_GROUP),; -- ADD (SCHEMA_OBJECT_ACCESS_GROUP),; -- ADD (SCHEMA_OBJECT_CHANGE_GROUP),; -- ADD (SCHEMA_OBJECT_OWNERSHIP_CHANGE_GROUP),; -- ADD (SCHEMA_OBJECT_PERMISSION_CHANGE_GROUP); ADD ( SELECT, UPDATE, INSERT, DELETE, EXECUTE, RECEIVE, REFERENCES; ON TestDatabase BY dbo ); WITH (STATE=ON)

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24048

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!