Event Details
User Activity->Object Access->Active Directory Object Access->Windows 2008->EventID 5141 - A directory service object was deleted.
EventID 5141 - A directory service object was deleted.
 Sample:
A directory service object was deleted.
	
Subject:
	Security ID:		YDOM\jr
	Account Name:		jr
	Account Domain:		YDOM
	Logon ID:		0x2de7f8
	
Directory Service:
	Name:	YDOM.spb.qsft
	Type:	Active Directory Domain Services

	
Object:
	DN:	CN=AServer,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
	GUID:	{0D9E0E56-683A-4B50-8E87-CB2FB661B351}
	Class:	server
	
Operation:
	Tree Delete:	No

	Correlation ID:	{9913DEFE-0D70-4429-B013-EF3C00E243F2}
	Application Correlation ID:	-
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category DS Access
Source Microsoft-Windows-Security-Auditing
TaskCategory Directory Service Changes
EventId 5141
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime
Who Account or user name under which the activity occured. Subject: Account Name -
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "AD Object Access Exercised" AD Object Access Exercised
Where The name of the workstation/server where the activity was logged. Computer
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. "High" High
WhoDomain Subject: Account Domain -
WhereDomain -
Result Successful or Failed -
Object Name Object: DN
Object Type Object: Class groupPolicyContainer
Whom -
Object DN The X.400 distinguished name of the object InsertionString9 CN=ServerModified,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Object GUID The globally unique identifier of the object, or the DN Object: GUID CN=ServerModified,CN=Servers,CN=ASite,CN=Sites,CN=Configuration,DC=YDOM,DC=spb,DC=qsft
Comments
You must be logged in to comment