Event Details
User Activity->Object Access->Active Directory Object Access->Windows 2008->EventID 5137 - A directory service object was created.
EventID 5137 - A directory service object was created.
 Sample:
A directory service object was created.
	
Subject:
	Security ID:		YDOM\jr
	Account Name:		jr
	Account Domain:		YDOM
	Logon ID:		0x2DE7F8
	
Directory Service:
	Name:	YDOM.spb.qsft
	Type:	Active Directory Domain Services
	
Object:
	DN:	cn=NTDS Site Settings,cn=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
	GUID:	CN=NTDS Site Settings,CN=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
	Class:	nTDSSiteSettings
	
Operation:
	Correlation ID:	{d4b6514f-b71f-4eff-ac00-64094db98c35}
	Application Correlation ID:	-
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category DS Access
Source Microsoft-Windows-Security-Auditing
TaskCategory Directory Service Changes
EventId 5137
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. - 1/1/2000
Who Account or user name under which the activity occured. - SomeUser
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "AD Object was created" AD Object was created
Where The name of the workstation/server where the activity was logged. - 10.10.10.10
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. - High
WhoDomain -
WhereDomain -
Result Successful or Failed -
Object Name -
Object Type Object: Class nTDSSiteSettings
Whom Object: DN cn=NTDS Site Settings,cn=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Object DN The X.400 distinguished name of the object InsertionString9 cn=NTDS Site Settings,cn=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Object ID The globally unique identifier of the object, or the DN Object: GUID CN=NTDS Site Settings,CN=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Object Class InsertionString11 nTDSSiteSettings
Comments
You must be logged in to comment