Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 6/11/2015 6:42:54 PM
Event ID: 5139
Task Category: Directory Service Changes
Level: Information
Keywords: Audit Success
User: N/A
Computer: YR2U1DC.YDOM.spb.qsft
Description:
A directory service object was moved.
Subject:
Security ID: YDOM\jr
Account Name: jr
Account Domain: YDOM
Logon ID: 0x2DE7F8
Directory Service:
Name: YDOM.spb.qsft
Type: Active Directory Domain Services
Object:
Old DN: CN=NewServer5139,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
New DN: CN=NewServer5139,CN=Servers,CN=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
GUID: CN=NewServer5139,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Class: server
Operation:
Correlation ID: {7bc782ad-8e62-4a87-a2dd-fa65cbafbca4}
Application Correlation ID: -
|
When
|
At what date and time a user activity originated in the system.
|
-
|
1/1/2000
|
Who
|
Account or user name under which the activity occured.
|
-
|
SomeUser
|
What
|
The type of activity occurred (e.g. Logon, Password Changed, etc.)
|
"AD Object was moved"
|
AD Object was moved
|
Where
|
The name of the workstation/server where the activity was logged.
|
-
|
10.10.10.10
|
Where From
|
The name of the workstation/server where the activity was initiated from.
|
-
|
10.10.10.10
|
Severity
|
Specify the seriousness of the event.
|
"Medium"
|
Medium
|
WhoDomain
|
|
-
|
|
WhereDomain
|
|
-
|
|
Result
|
Successful or Failed
|
-
|
|
Object Name
|
|
-
|
|
Object Type
|
|
-
|
|
Whom
|
|
-
|
|
Object Old DN
|
|
Object: Old DN
|
CN=NewServer5139,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
|
Object New DN
|
|
Object: New DN
|
CN=NewServer5139,CN=Servers,CN=AnotherSite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
|
Object GUID
|
The globally unique identifier of the object, or the DN
|
Object: GUID
|
CN=NewServer5139,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
|
|