SQL Server Audit Log Event ID 24068

SourceSQL Server (LOGbinder SQL)
Action GroupSERVER_OBJECT_CHANGE_GROUP
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success
Discussions on Event ID 24068
Ask a question about this event

24068: Issued a delete server credential command (action_id DR class_type CD)

This is an event from SQL Server audit event from LOGbinder SQL generated by Action Group  SERVER_OBJECT_CHANGE_GROUP.

On this page

A command to delete a server credential was issued

Free Security Log Resources by Randy

Description Fields in 24068

FieldDescription
OccurredWhen event was reported by SQL Server
Authorization resultIf the command passed authorization checks
Session IDID of the session on which the event occurred
User
Server
NameTarget object name
StatementTransact-SQL statement

Supercharger Free Edition


Supercharger's built-in Xpath filters leave the noise behind.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 24068

Issued a delete server credential command
A command to delete a server credential was issued
Action Group: SERVER_OBJECT_CHANGE_GROUP
Occurred: 8/22/2013 6:07:53.0000000 PM
Authorization result: Access allowed
Session ID: 67
User: LB\Administrator
Server: DEV3
Audit Name: HFinnCred
Statement: DROP CREDENTIAL HFinnCred

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24068

Keep me up-to-date on the Windows Security Log.
Email*:
*We will NOT share this

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Additional Resources