Build a great reporting interface using Splunk, one of the leaders in the Security Information and Event Management (SIEM) field, linking the collected Windows events to www.eventid.net. The EventId.Net for Splunk Add-on assumes that Splunk is collecting information from Windows servers and workstation via the Splunk Universal Forwarder.
A directory service object was modified.
Security ID: NULL SID
Account Name: -
Account Domain: -
Logon ID: <logon ID>
|English: Request a translation of the event description in plain English.|
As per ME975696, even though you enable granular auditing for "Directory Services Changes", the corresponding 5136 event is not populated with the required information (such as Security ID, Account Name or Account Domain). A hotfix is available for this (see the article).
|Private comment: Subscribers only. See example of private comment|
|Search: Google - Bing - Microsoft - Yahoo - EventID.Net Queue (0) - More links...|
|Custom search for *****: Google - Bing - Microsoft - Yahoo|
Send comments or solutions
- Notify me when updated