Event Details
User Activity->Object Access->Active Directory Object Access->Change Auditor for Active Directory->Group Object Changes->EventID 3 - Member added to group.
EventID 3 - Member added to group.
 Sample:
Event Type:     Information
Event Source:   ITAD Directory Changes
Event Category: None
Event ID:       3
Date:           10/29/2009
Time:           06:47:52
User:           RESEARCH\CBrown
Computer:       DC1
Description:    
AD object was successfully modified.

	Client Computer : 10.0.0.1

	Object DN : CN=Machine,CN={CABC510B-5D32-4202-A000-36ED89222065},CN=Policies,CN=System,DC=research,DC=corp

	Object Class : container

	Object GUID : {886E0C56-E877-40DE-8800-E4EA865FDD13}

	Attribute Name : CN

	Action : Add

	Old Value : <not set>

	New Value : Machine

	Request ID : {F9D500F9-3BEB-4B2C-BCEB-BA4D77A7025D}
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: InTrust for AD
Filtering Field Equals to Value
Source ITAD Directory Changes
EventId 3
InsertionString2 group
InsertionString4 member
InsertionString5 Append
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 1/1/2000
Who Account or user name under which the activity occured. User SomeUser
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Group Member Added" Group Member Added
Where The name of the workstation/server where the activity was logged. Computer 10.10.10.10
Where From The name of the workstation/server where the activity was initiated from. Client Computer 10.0.0.2
Severity Specify the seriousness of the event. "Medium" Medium
WhoDomain -
WhereDomain -
Result Successful or Failed "Successful" Successful
Object Name Object DN CN=Machine,CN={CABC510B-5D32-4202-A000-36ED89222065},CN=Policies,CN=System,DC=research,DC=corp
Object Type Object Class container
Whom New Value Machine
Property Name LDAP DisplayName of the AD object property Attribute Name CN
Value Before Property value before the change Old Value <not set>
Value After Property value after the change InsertionString7 Machine
Whom Target group -
Group Name Group Name InsertionString1 CN=Machine,CN={CABC510B-5D32-4202-A000-36ED89222065},CN=Policies,CN=System,DC=research,DC=corp
Member Name Member Name InsertionString7 Machine
Whom Account or user name being managed. -
Comments
You must be logged in to comment