Event Details
Operating System->Microsoft Windows->Application logs->Quest->Active Roles 7 or higher->EventID 1517 - Attribute is modified.
EventID 1517 - Attribute is modified.
 Sample:
Log Name:      ARAdminService
Source:        ARAdminSvc
Date:          11/22/2016 10:11:51 AM
Event ID:      1517
Task Category: ObjectSetInfo
Level:         Information
Keywords:      Classic,Audit Success
User:          ITSS\igor.ilyin
Computer:      IIZHU1.itss.wm.zhu.cn.qsft
Description:
Attribute is modified. 
Operation GUID: b1656271-9984-4b80-8ec5-2eac47aed1cc 
Attribute name: givenName 
Attribute value: Shawn 
Action: Replace
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: ARAdminService
Filtering Field Equals to Value
Source ARAdminSvc
EventId 1517
Field Matching
FieldDescriptionStored inSample Value
DateTime Date/Time of event origination in GMT format. DateTime 10.10.2000 19:00:00
Source Name of an Application or System Service originating the event. Source Security
Type Warning, Information, Error, Success, Failure, etc. Type Success
User Domain\Account name of user/service/computer initiating event. User RESEARCH\Alebovsky
Computer Name of server workstation where event was logged. Computer DC1
EventID Numerical ID of event. Unique within one Event Source. EventId 576
Description The entire unparsed event message. Description Special privileges assigned to new logon.
Log Name The name of the event log (e.g. Application, Security, System, etc.) LogName Security
Category A name for a subclass of events within the same Event Source. Category AttestationReview
Whom -
Operation GUID InsertionString1 b1656271-9984-4b80-8ec5-2eac47aed1cc
Attribute name InsertionString2 givenName
Attribute value InsertionString3 Shawn
Action InsertionString4 Replace
Comments
You must be logged in to comment