SQL Server Audit Log Event ID 24406

SourceSQL Server (LOGbinder SQL)
Action GroupBATCH_COMPLETED_GROUP
Windows Security Log
Category
 • Subcategory
Object Access
 • Application Generated
Type Success

24406: RPC complete succeeded (action_id RCM; class_type DB)

This is an event from SQL Server audit event from LOGbinder SQL generated by Action Group  BATCH_COMPLETED_GROUP.

On this page

RPC complete succeeded

Free Security Log Resources by Randy

Description Fields in 24406

Field Description
Occurred When event was reported by SQL Server.
Authorization result If the command passed authorization checks.
Session ID ID of the session on which the event occurred.
User User
Server Server
Database Database affected by the event.
Target object  
  ID Target object ID
  Name Target object name
  Permission bitmask Target object permission bitmask
Statement Transact-SQL statement

Supercharger Free Edition


Centrally manage WEC subscriptions.

Free.

 

Where Does This Event Come From?

This Event Is Produced By

Which Integrates with Your SIEM

Examples of 24406

RPC complete succeeded
RPC complete succeeded
Action Group: BATCH_COMPLETED_GROUP
Occurred: 5/21/2026 11:12:25.0000000 PM
Authorization result: Access allowed
Session ID: 51
User: LAB\tuser
Server: lab-sql-13\SQLEXPRESS2025
Database: master
Original Context
  Server login: LAB\tuser
  Database user: dbo
Target Context
  ID: 1
  Database user: master
Statement: exec sp_executesql N'SELECT
''PolicyStore[@Name='' + quotename(CAST(serverproperty(N''Servername'') AS sysname),'''''''') + '']'' AS [Urn],
CAST(serverproperty(N''Servername'') AS sysname) AS [Name],
CAST(;         (SELECT current_value FROM msdb.dbo.syspolicy_configuration WHERE name = ''Enabled'');      AS bit) AS [Enabled],
CAST(;         (SELECT current_value FROM msdb.dbo.syspolicy_configuration WHERE name = ''HistoryRetentionInDays'');      AS int) AS [HistoryRetentionInDays],
CAST(; (SELECT current_value FROM msdb.dbo.syspolicy_configuration WHERE name = ''LogOnSuccess''); AS bit) AS [LogOnSuccess]
WHERE
(CAST(serverproperty(N''Servername'') AS sysname)=@_msparam_0)',N'@_msparam_0 nvarchar(4000)',@_msparam_0=N'lab-sql-13\SQLEXPRESS2025'

For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24406

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection

 

Additional Resources

    Go To Event ID:

    Security Log
    Quick Reference
    Chart
    Download now!