Windows Security Log Event ID 4937

Operating Systems Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
 • Subcategory
Directory Service
 • Directory Service Replication
Type Success
Corresponding events
in Windows 2003
and before

4937: A lingering object was removed from a replica

On this page

Directory Service replication has little to no security relevance.  I recommend disabling these 2 subcategories: 

  • Directory Service Replication
  • Detailed Directory Service Replication

Since DCSync and DCShadow have come out I've changed my mind about the above statement.  Check out this webinar AD Attack Deep Dive: Gaining Persistence using DCSync and DCShadow with Mimikatz

Free Security Log Resources by Randy

Supercharger Free Edition


Examples of 4937

A lingering object was removed from a replica.

Destination DRA: %1
Source DRA: %2
Object: %3
Options: %4
Status Code: %5

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources