mdangelo
Posts: 6
Score: 0
Joined: 31.Oct.2006
Status: offline
|
I'm having a strange problem specifically with event 5136 (which audits AD changes in Server 2008.) Other events for Server 2008 seem to be fine, but with this one, none of the custom fields are being populated. Compare the original XML event data
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>5136</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>14081</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="2009-08-06T14:08:23.199Z" />
<EventRecordID>154156063</EventRecordID>
<Correlation />
<Execution ProcessID="460" ThreadID="1748" />
<Channel>Security</Channel>
<Computer>dc3brc.pace.edu</Computer>
<Security />
</System>
- <EventData>
<Data Name="OpCorrelationID">{44008EE8-2D6E-4BD3-B543-0B2257E04723}</Data>
<Data Name="AppCorrelationID">-</Data>
<Data Name="SubjectUserSid">S-1-5-21-254494878-1253622069-3383492343-52130</Data>
<Data Name="SubjectUserName">mdangelo</Data>
<Data Name="SubjectDomainName">PACE</Data>
<Data Name="SubjectLogonId">0x39a619ea0</Data>
<Data Name="DSName">pace.edu</Data>
<Data Name="DSType">%%14676</Data>
<Data Name="ObjectDN">CN=Campion\, Marian F.,OU=Retiree Benefits Costs,OU=Retiree Benefits Costs,OU=University Benefits,OU=Total University,OU=People,DC=pace,DC=edu</Data>
<Data Name="ObjectGUID">{BA5EF6B0-6C22-4CB9-82CA-AC5B5427EAC8}</Data>
<Data Name="ObjectClass">user</Data>
<Data Name="AttributeLDAPDisplayName">cn</Data>
<Data Name="AttributeSyntaxOID">2.5.5.12</Data>
<Data Name="AttributeValue">Campion McDermott, Marian F.</Data>
<Data Name="OperationType">%%14674</Data>
</EventData>
</Event>
With the one stored in GFI Events Manager
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID Qualifiers="">5136</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>14081</Task>
<Opcode>0</Opcode>
<Keywords>0x8020000000000000</Keywords>
<TimeCreated SystemTime="08/06/09 10:08:23" />
<EventRecordID>154156053</EventRecordID>
<Correlation />
<Execution ProcessID="460" ThreadID="1748" />
<Channel>Security</Channel>
<Computer>dc3brc.pace.edu</Computer>
<Security />
</System>
- <EventData>
<Data Name="OpCorrelationID">%1</Data>
<Data Name="AppCorrelationID">%2</Data>
<Data Name="SubjectUserSid">%3</Data>
<Data Name="SubjectUserName">%4</Data>
<Data Name="SubjectDomainName">%5</Data>
<Data Name="SubjectLogonId">%6</Data>
<Data Name="DSName">%7</Data>
<Data Name="DSType">%8</Data>
<Data Name="ObjectDN">%9</Data>
<Data Name="ObjectGUID">%10</Data>
<Data Name="ObjectClass">%11</Data>
<Data Name="AttributeLDAPDisplayName">%12</Data>
<Data Name="AttributeSyntaxOID">%13</Data>
<Data Name="AttributeValue">%14</Data>
<Data Name="OperationType">%15</Data>
</EventData>
</Event>
|