Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

6243 lines
137 KiB

  1. ;/*++ BUILD Version: 0001 // Increment this if a change has global effects
  2. ;
  3. ;Copyright (c) 1991 Microsoft Corporation
  4. ;
  5. ;Module Name:
  6. ;
  7. ; msaudite.mc
  8. ;
  9. ;Abstract:
  10. ;
  11. ; Constant definitions for the NT Audit Event Messages.
  12. ;
  13. ;Author:
  14. ;
  15. ; Jim Kelly (JimK) 30-Mar-1992
  16. ;
  17. ;Revision History:
  18. ;
  19. ;Notes:
  20. ;
  21. ; The .h and .res forms of this file are generated from the .mc
  22. ; form of the file (base\seaudit\msaudite\msaudite.mc).
  23. ; Please make all changes to the .mc form of the file.
  24. ;
  25. ; If you add a new audit category or make any change to the
  26. ; audit event id valid limits (0x200 ~ 0x5ff), please make a
  27. ; corresponding change to ntlsa.h
  28. ;
  29. ;--*/
  30. ;
  31. ;#ifndef _MSAUDITE_
  32. ;#define _MSAUDITE_
  33. ;
  34. ;/*lint -e767 */ // Don't complain about different definitions // winnt
  35. MessageIdTypedef=ULONG
  36. SeverityNames=(None=0x0)
  37. FacilityNames=(None=0x0)
  38. MessageId=0x0000
  39. Language=English
  40. Unused message ID
  41. .
  42. ;// Message ID 0 is unused - just used to flush out the diagram
  43. ;//
  44. ;// min/max limits on audit category-id and event-id of audit events
  45. ;//
  46. ;
  47. ;#define SE_ADT_MIN_CATEGORY_ID 1 // SE_CATEGID_SYSTEM
  48. ;#define SE_ADT_MAX_CATEGORY_ID 9 // SE_CATEGID_ACCOUNT_LOGON
  49. ;
  50. ;
  51. ;#define SE_ADT_MIN_AUDIT_ID 0x200 // see msaudite.h
  52. ;#define SE_ADT_MAX_AUDIT_ID 0x5ff // see msaudite.h
  53. ;///////////////////////////////////////////////////////////////////////////
  54. ;///////////////////////////////////////////////////////////////////////////
  55. ;// //
  56. ;// //
  57. ;// Audit Message ID Space: //
  58. ;// //
  59. ;// 0x0000 - 0x00FF : Reserved for future use. //
  60. ;// //
  61. ;// 0x0100 - 0x01FF : Categories //
  62. ;// //
  63. ;// 0x0200 - 0x05FF : Events //
  64. ;// //
  65. ;// 0x0600 - 0x063F : Standard access types and names for //
  66. ;// specific accesses when no specific names //
  67. ;// can be found. //
  68. ;// //
  69. ;// 0x0640 - 0x06FF : Well known privilege names (as we would //
  70. ;// like them displayed in the event viewer). //
  71. ;// //
  72. ;// 0x0700 - 0x0FFE : Reserved for future use. //
  73. ;// //
  74. ;// 0X0FFF : SE_ADT_LAST_SYSTEM_MESSAGE (the highest //
  75. ;// value audit message used by the system) //
  76. ;// //
  77. ;// //
  78. ;// 0x1000 and above: For use by Parameter Message Files //
  79. ;// //
  80. ;///////////////////////////////////////////////////////////////////////////
  81. ;///////////////////////////////////////////////////////////////////////////
  82. MessageId=0x0FFF
  83. SymbolicName=SE_ADT_LAST_SYSTEM_MESSAGE
  84. Language=English
  85. Highest System-Defined Audit Message Value.
  86. .
  87. ;
  88. ;/////////////////////////////////////////////////////////////////////////////
  89. ;// //
  90. ;// //
  91. ;// CATEGORIES //
  92. ;// //
  93. ;// Categories take up the range 0x1 - 0x400 //
  94. ;// //
  95. ;// Category IDs: //
  96. ;// //
  97. ;// SE_CATEGID_SYSTEM //
  98. ;// SE_CATEGID_LOGON //
  99. ;// SE_CATEGID_OBJECT_ACCESS //
  100. ;// SE_CATEGID_PRIVILEGE_USE //
  101. ;// SE_CATEGID_DETAILED_TRACKING //
  102. ;// SE_CATEGID_POLICY_CHANGE //
  103. ;// SE_CATEGID_ACCOUNT_MANAGEMENT //
  104. ;// SE_CATEGID_DS_ACCESS //
  105. ;// SE_CATEGID_ACCOUNT_LOGON //
  106. ;// //
  107. ;// //
  108. ;/////////////////////////////////////////////////////////////////////////////
  109. MessageId=0x0001
  110. SymbolicName=SE_CATEGID_SYSTEM
  111. Language=English
  112. System Event
  113. .
  114. MessageId=0x0002
  115. SymbolicName=SE_CATEGID_LOGON
  116. Language=English
  117. Logon/Logoff
  118. .
  119. MessageId=0x0003
  120. SymbolicName=SE_CATEGID_OBJECT_ACCESS
  121. Language=English
  122. Object Access
  123. .
  124. MessageId=0x0004
  125. SymbolicName=SE_CATEGID_PRIVILEGE_USE
  126. Language=English
  127. Privilege Use
  128. .
  129. MessageId=0x0005
  130. SymbolicName=SE_CATEGID_DETAILED_TRACKING
  131. Language=English
  132. Detailed Tracking
  133. .
  134. MessageId=0x0006
  135. SymbolicName=SE_CATEGID_POLICY_CHANGE
  136. Language=English
  137. Policy Change
  138. .
  139. MessageId=0x0007
  140. SymbolicName=SE_CATEGID_ACCOUNT_MANAGEMENT
  141. Language=English
  142. Account Management
  143. .
  144. MessageId=0x0008
  145. SymbolicName=SE_CATEGID_DS_ACCESS
  146. Language=English
  147. Directory Service Access
  148. .
  149. MessageId=0x0009
  150. SymbolicName=SE_CATEGID_ACCOUNT_LOGON
  151. Language=English
  152. Account Logon
  153. .
  154. ;
  155. ;/////////////////////////////////////////////////////////////////////////////
  156. ;// //
  157. ;// //
  158. ;// Messages for Category: SE_CATEGID_SYSTEM //
  159. ;// //
  160. ;// Event IDs: //
  161. ;// SE_AUDITID_SYSTEM_RESTART //
  162. ;// SE_AUDITID_SYSTEM_SHUTDOWN //
  163. ;// SE_AUDITID_AUTH_PACKAGE_LOAD //
  164. ;// SE_AUDITID_LOGON_PROC_REGISTER //
  165. ;// SE_AUDITID_AUDITS_DISCARDED //
  166. ;// SE_AUDITID_NOTIFY_PACKAGE_LOAD //
  167. ;// SE_AUDITID_SYSTEM_TIME_CHANGE //
  168. ;// SE_AUDITID_LPC_INVALID_USE //
  169. ;// //
  170. ;/////////////////////////////////////////////////////////////////////////////
  171. ;//
  172. ;//
  173. ;// SE_AUDITID_SYSTEM_RESTART
  174. ;//
  175. ;// Category: SE_CATEGID_SYSTEM
  176. ;//
  177. ;// Parameter Strings - None
  178. ;//
  179. ;//
  180. ;//
  181. MessageId=0x0200
  182. SymbolicName=SE_AUDITID_SYSTEM_RESTART
  183. Language=English
  184. Windows is starting up.
  185. .
  186. ;//
  187. ;//
  188. ;// SE_AUDITID_SYSTEM_SHUTDOWN
  189. ;//
  190. ;// Category: SE_CATEGID_SYSTEM
  191. ;//
  192. ;// Parameter Strings - None
  193. ;//
  194. ;//
  195. ;//
  196. MessageId=0x0201
  197. SymbolicName=SE_AUDITID_SYSTEM_SHUTDOWN
  198. Language=English
  199. Windows is shutting down.
  200. All logon sessions will be terminated by this shutdown.
  201. .
  202. ;//
  203. ;//
  204. ;// SE_AUDITID_SYSTEM_AUTH_PACKAGE_LOAD
  205. ;//
  206. ;// Category: SE_CATEGID_SYSTEM
  207. ;//
  208. ;// Parameter Strings -
  209. ;//
  210. ;// 1 - Authentication Package Name
  211. ;//
  212. ;//
  213. ;//
  214. MessageId=0x0202
  215. SymbolicName=SE_AUDITID_AUTH_PACKAGE_LOAD
  216. Language=English
  217. An authentication package has been loaded by the Local Security Authority.
  218. This authentication package will be used to authenticate logon attempts.
  219. %n
  220. Authentication Package Name:%t%1
  221. .
  222. ;//
  223. ;//
  224. ;// SE_AUDITID_SYSTEM_LOGON_PROC_REGISTER
  225. ;//
  226. ;// Category: SE_CATEGID_SYSTEM
  227. ;//
  228. ;// Parameter Strings -
  229. ;//
  230. ;// 1 - Logon Process Name
  231. ;//
  232. ;//
  233. ;//
  234. MessageId=0x0203
  235. SymbolicName=SE_AUDITID_SYSTEM_LOGON_PROC_REGISTER
  236. Language=English
  237. A trusted logon process has registered with the Local Security Authority.
  238. This logon process will be trusted to submit logon requests.
  239. %n
  240. %n
  241. Logon Process Name:%t%1
  242. .
  243. ;//
  244. ;//
  245. ;// SE_AUDITID_AUDITS_DISCARDED
  246. ;//
  247. ;// Category: SE_CATEGID_SYSTEM
  248. ;//
  249. ;// Parameter Strings -
  250. ;//
  251. ;// 1 - Number of audits discarded
  252. ;//
  253. ;//
  254. ;//
  255. MessageId=0x0204
  256. SymbolicName=SE_AUDITID_AUDITS_DISCARDED
  257. Language=English
  258. Internal resources allocated for the queuing of audit messages have been exhausted,
  259. leading to the loss of some audits.
  260. %n
  261. %tNumber of audit messages discarded:%t%1
  262. .
  263. ;//
  264. ;//
  265. ;// SE_AUDITID_AUDIT_LOG_CLEARED
  266. ;//
  267. ;// Category: SE_CATEGID_SYSTEM
  268. ;//
  269. ;// Parameter Strings -
  270. ;//
  271. ;// 1 - Primary user account name
  272. ;//
  273. ;// 2 - Primary authenticating domain name
  274. ;//
  275. ;// 3 - Primary logon ID string
  276. ;//
  277. ;// 4 - Client user account name ("-" if no client)
  278. ;//
  279. ;// 5 - Client authenticating domain name ("-" if no client)
  280. ;//
  281. ;// 6 - Client logon ID string ("-" if no client)
  282. ;//
  283. ;//
  284. ;//
  285. MessageId=0x0205
  286. SymbolicName=SE_AUDITID_AUDIT_LOG_CLEARED
  287. Language=English
  288. The audit log was cleared
  289. %n
  290. %tPrimary User Name:%t%1%n
  291. %tPrimary Domain:%t%2%n
  292. %tPrimary Logon ID:%t%3%n
  293. %tClient User Name:%t%4%n
  294. %tClient Domain:%t%5%n
  295. %tClient Logon ID:%t%6%n
  296. .
  297. ;//
  298. ;//
  299. ;// SE_AUDITID_SYSTEM_NOTIFY_PACKAGE_LOAD
  300. ;//
  301. ;// Category: SE_CATEGID_SYSTEM
  302. ;//
  303. ;// Parameter Strings -
  304. ;//
  305. ;// 1 - Notification Package Name
  306. ;//
  307. ;//
  308. ;//
  309. MessageId=0x0206
  310. SymbolicName=SE_AUDITID_NOTIFY_PACKAGE_LOAD
  311. Language=English
  312. An notification package has been loaded by the Security Account Manager.
  313. This package will be notified of any account or password changes.
  314. %n
  315. Notification Package Name:%t%1
  316. .
  317. ;//
  318. ;//
  319. ;// SE_AUDITID_LPC_INVALID_USE
  320. ;//
  321. ;// Category: SE_CATEGID_SYSTEM
  322. ;//
  323. ;// Parameter Strings -
  324. ;//
  325. ;// 1 - LPC call (e.g. "impersonation" | "reply")
  326. ;//
  327. ;// 2 - Server Port name
  328. ;//
  329. ;// 3 - Faulting process
  330. ;//
  331. ;// Event type: success
  332. ;//
  333. ;// Description:
  334. ;// SE_AUDIT_LPC_INVALID_USE is generated when a process uses an invalid LPC
  335. ;// port in an attempt to impersonate a client, reply or read/write from/to a client address space.
  336. ;//
  337. MessageId=0x0207
  338. SymbolicName=SE_AUDITID_LPC_INVALID_USE
  339. Language=English
  340. Invalid use of LPC port.%n
  341. %tProcess ID: %1%n
  342. %tImage File Name: %2%n
  343. %tPrimary User Name:%t%3%n
  344. %tPrimary Domain:%t%4%n
  345. %tPrimary Logon ID:%t%5%n
  346. %tClient User Name:%t%6%n
  347. %tClient Domain:%t%7%n
  348. %tClient Logon ID:%t%8%n
  349. %tInvalid use: %9%n
  350. %tServer Port Name:%t%10%n
  351. .
  352. ;//
  353. ;//
  354. ;// SE_AUDITID_SYSTEM_TIME_CHANGE
  355. ;//
  356. ;// Category: SE_CATEGID_SYSTEM
  357. ;//
  358. ;// Parameter Strings -
  359. ;//
  360. ;// Type: success
  361. ;//
  362. ;// Description: This event is generated when the system time is changed.
  363. ;//
  364. ;// Note: This will often appear twice in the audit log; this is an implementation
  365. ;// detail wherein changing the system time results in two calls to NtSetSystemTime.
  366. ;// This is necessary to deal with time zone changes.
  367. ;//
  368. ;//
  369. MessageId=0x0208
  370. SymbolicName=SE_AUDITID_SYSTEM_TIME_CHANGE
  371. Language=English
  372. The system time was changed.%n
  373. Process ID:%t%1%n
  374. Process Name:%t%2%n
  375. Primary User Name:%t%3%n
  376. Primary Domain:%t%4%n
  377. Primary Logon ID:%t%5%n
  378. Client User Name:%t%6%n
  379. Client Domain:%t%7%n
  380. Client Logon ID:%t%8%n
  381. Previous Time:%t%10 %9%n
  382. New Time:%t%12 %11%n
  383. .
  384. ;
  385. ;/////////////////////////////////////////////////////////////////////////////
  386. ;// //
  387. ;// //
  388. ;// Messages for Category: SE_CATEGID_LOGON //
  389. ;// //
  390. ;// Event IDs: //
  391. ;// SE_AUDITID_SUCCESSFUL_LOGON //
  392. ;// SE_AUDITID_UNKNOWN_USER_OR_PWD //
  393. ;// SE_AUDITID_ACCOUNT_TIME_RESTR //
  394. ;// SE_AUDITID_ACCOUNT_DISABLED //
  395. ;// SE_AUDITID_ACCOUNT_EXPIRED //
  396. ;// SE_AUDITID_WORKSTATION_RESTR //
  397. ;// SE_AUDITID_LOGON_TYPE_RESTR //
  398. ;// SE_AUDITID_PASSWORD_EXPIRED //
  399. ;// SE_AUDITID_NETLOGON_NOT_STARTED //
  400. ;// SE_AUDITID_UNSUCCESSFUL_LOGON //
  401. ;// SE_AUDITID_LOGOFF //
  402. ;// SE_AUDITID_ACCOUNT_LOCKED //
  403. ;// SE_AUDITID_NETWORK_LOGON //
  404. ;// SE_AUDITID_IPSEC_LOGON_SUCCESS //
  405. ;// SE_AUDITID_IPSEC_LOGOFF_MM //
  406. ;// SE_AUDITID_IPSEC_LOGOFF_QM //
  407. ;// SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST //
  408. ;// SE_AUDITID_IPSEC_AUTH //
  409. ;// SE_AUDITID_IPSEC_ATTRIB_FAIL //
  410. ;// SE_AUDITID_IPSEC_NEGOTIATION_FAIL //
  411. ;// SE_AUDITID_IPSEC_IKE_NOTIFICATION //
  412. ;// SE_AUDITID_DOMAIN_TRUST_INCONSISTENT //
  413. ;// //
  414. ;/////////////////////////////////////////////////////////////////////////////
  415. ;//
  416. ;//
  417. ;// SE_AUDITID_SUCCESSFUL_LOGON
  418. ;//
  419. ;// Category: SE_CATEGID_LOGON
  420. ;//
  421. ;// Parameter Strings -
  422. ;//
  423. ;// 1 - User account name
  424. ;//
  425. ;// 2 - Authenticating domain name
  426. ;//
  427. ;// 3 - Logon ID string
  428. ;//
  429. ;// 4 - Logon Type string
  430. ;//
  431. ;// 5 - Logon process name
  432. ;//
  433. ;// 6 - Authentication package name
  434. ;//
  435. ;// 7 - Workstation from which logon request came
  436. ;//
  437. ;// 8 - Globally unique logon ID
  438. ;//
  439. ;//
  440. MessageId=0x0210
  441. SymbolicName=SE_AUDITID_SUCCESSFUL_LOGON
  442. Language=English
  443. Successful Logon:%n
  444. %tUser Name:%t%1%n
  445. %tDomain:%t%t%2%n
  446. %tLogon ID:%t%t%3%n
  447. %tLogon Type:%t%4%n
  448. %tLogon Process:%t%5%n
  449. %tAuthentication Package:%t%6%n
  450. %tWorkstation Name:%t%7%n
  451. %tLogon GUID:%t%8
  452. .
  453. ;//
  454. ;//
  455. ;// SE_AUDITID_UNKNOWN_USER_OR_PWD
  456. ;//
  457. ;// Category: SE_CATEGID_LOGON
  458. ;//
  459. ;// Parameter Strings -
  460. ;//
  461. ;// 1 - User account name
  462. ;//
  463. ;// 2 - Authenticating domain name
  464. ;//
  465. ;// 3 - Logon Type string
  466. ;//
  467. ;// 4 - Logon process name
  468. ;//
  469. ;// 5 - Authentication package name
  470. ;//
  471. ;//
  472. MessageId=0x0211
  473. SymbolicName=SE_AUDITID_UNKNOWN_USER_OR_PWD
  474. Language=English
  475. Logon Failure:%n
  476. %tReason:%t%tUnknown user name or bad password%n
  477. %tUser Name:%t%1%n
  478. %tDomain:%t%t%2%n
  479. %tLogon Type:%t%3%n
  480. %tLogon Process:%t%4%n
  481. %tAuthentication Package:%t%5%n
  482. %tWorkstation Name:%t%6
  483. .
  484. ;//
  485. ;//
  486. ;// SE_AUDITID_ACCOUNT_TIME_RESTR
  487. ;//
  488. ;// Category: SE_CATEGID_LOGON
  489. ;//
  490. ;// Parameter Strings -
  491. ;//
  492. ;// 1 - User account name
  493. ;//
  494. ;// 2 - Authenticating domain name
  495. ;//
  496. ;// 3 - Logon Type string
  497. ;//
  498. ;// 4 - Logon process name
  499. ;//
  500. ;// 5 - Authentication package name
  501. ;//
  502. ;//
  503. MessageId=0x0212
  504. SymbolicName=SE_AUDITID_ACCOUNT_TIME_RESTR
  505. Language=English
  506. Logon Failure:%n
  507. %tReason:%t%tAccount logon time restriction violation%n
  508. %tUser Name:%t%1%n
  509. %tDomain:%t%2%n
  510. %tLogon Type:%t%3%n
  511. %tLogon Process:%t%4%n
  512. %tAuthentication Package:%t%5%n
  513. %tWorkstation Name:%t%6
  514. .
  515. ;//
  516. ;//
  517. ;// SE_AUDITID_ACCOUNT_DISABLED
  518. ;//
  519. ;// Category: SE_CATEGID_LOGON
  520. ;//
  521. ;// Parameter Strings -
  522. ;//
  523. ;// 1 - User account name
  524. ;//
  525. ;// 2 - Authenticating domain name
  526. ;//
  527. ;// 3 - Logon Type string
  528. ;//
  529. ;// 4 - Logon process name
  530. ;//
  531. ;// 5 - Authentication package name
  532. ;//
  533. ;//
  534. MessageId=0x0213
  535. SymbolicName=SE_AUDITID_ACCOUNT_DISABLED
  536. Language=English
  537. Logon Failure:%n
  538. %tReason:%t%tAccount currently disabled%n
  539. %tUser Name:%t%1%n
  540. %tDomain:%t%t%2%n
  541. %tLogon Type:%t%3%n
  542. %tLogon Process:%t%4%n
  543. %tAuthentication Package:%t%5%n
  544. %tWorkstation Name:%t%6
  545. .
  546. ;//
  547. ;//
  548. ;// SE_AUDITID_ACCOUNT_EXPIRED
  549. ;//
  550. ;// Category: SE_CATEGID_LOGON
  551. ;//
  552. ;// Parameter Strings -
  553. ;//
  554. ;// 1 - User account name
  555. ;//
  556. ;// 2 - Authenticating domain name
  557. ;//
  558. ;// 3 - Logon Type string
  559. ;//
  560. ;// 4 - Logon process name
  561. ;//
  562. ;// 5 - Authentication package name
  563. ;//
  564. ;//
  565. MessageId=0x0214
  566. SymbolicName=SE_AUDITID_ACCOUNT_EXPIRED
  567. Language=English
  568. Logon Failure:%n
  569. %tReason:%t%tThe specified user account has expired%n
  570. %tUser Name:%t%1%n
  571. %tDomain:%t%t%2%n
  572. %tLogon Type:%t%3%n
  573. %tLogon Process:%t%4%n
  574. %tAuthentication Package:%t%5%n
  575. %tWorkstation Name:%t%6
  576. .
  577. ;//
  578. ;//
  579. ;// SE_AUDITID_WORKSTATION_RESTR
  580. ;//
  581. ;// Category: SE_CATEGID_LOGON
  582. ;//
  583. ;// Parameter Strings -
  584. ;//
  585. ;// 1 - User account name
  586. ;//
  587. ;// 2 - Authenticating domain name
  588. ;//
  589. ;// 3 - Logon Type string
  590. ;//
  591. ;// 4 - Logon process name
  592. ;//
  593. ;// 5 - Authentication package name
  594. ;//
  595. ;//
  596. MessageId=0x0215
  597. SymbolicName=SE_AUDITID_WORKSTATION_RESTR
  598. Language=English
  599. Logon Failure:%n
  600. %tReason:%t%tUser not allowed to logon at this computer%n
  601. %tUser Name:%t%1%n
  602. %tDomain:%t%2%n
  603. %tLogon Type:%t%3%n
  604. %tLogon Process:%t%4%n
  605. %tAuthentication Package:%t%5%n
  606. %tWorkstation Name:%t%6
  607. .
  608. ;//
  609. ;//
  610. ;// SE_AUDITID_LOGON_TYPE_RESTR
  611. ;//
  612. ;// Category: SE_CATEGID_LOGON
  613. ;//
  614. ;// Parameter Strings -
  615. ;//
  616. ;// 1 - User account name
  617. ;//
  618. ;// 2 - Authenticating domain name
  619. ;//
  620. ;// 3 - Logon Type string
  621. ;//
  622. ;// 4 - Logon process name
  623. ;//
  624. ;// 5 - Authentication package name
  625. ;//
  626. ;//
  627. MessageId=0x0216
  628. SymbolicName=SE_AUDITID_LOGON_TYPE_RESTR
  629. Language=English
  630. Logon Failure:%n
  631. %tReason:%tThe user has not been granted the requested%n
  632. %t%tlogon type at this machine%n
  633. %tUser Name:%t%1%n
  634. %tDomain:%t%t%2%n
  635. %tLogon Type:%t%3%n
  636. %tLogon Process:%t%4%n
  637. %tAuthentication Package:%t%5%n
  638. %tWorkstation Name:%t%6
  639. .
  640. ;//
  641. ;//
  642. ;// SE_AUDITID_PASSWORD_EXPIRED
  643. ;//
  644. ;// Category: SE_CATEGID_LOGON
  645. ;//
  646. ;// Parameter Strings -
  647. ;//
  648. ;// 1 - User account name
  649. ;//
  650. ;// 2 - Authenticating domain name
  651. ;//
  652. ;// 3 - Logon Type string
  653. ;//
  654. ;// 4 - Logon process name
  655. ;//
  656. ;// 5 - Authentication package name
  657. ;//
  658. ;//
  659. MessageId=0x0217
  660. SymbolicName=SE_AUDITID_PASSWORD_EXPIRED
  661. Language=English
  662. Logon Failure:%n
  663. %tReason:%t%tThe specified account's password has expired%n
  664. %tUser Name:%t%1%n
  665. %tDomain:%t%t%2%n
  666. %tLogon Type:%t%3%n
  667. %tLogon Process:%t%4%n
  668. %tAuthentication Package:%t%5%n
  669. %tWorkstation Name:%t%6
  670. .
  671. ;//'
  672. ;//
  673. ;// SE_AUDITID_NETLOGON_NOT_STARTED
  674. ;//
  675. ;// Category: SE_CATEGID_LOGON
  676. ;//
  677. ;// Parameter Strings -
  678. ;//
  679. ;// 1 - User account name
  680. ;//
  681. ;// 2 - Authenticating domain name
  682. ;//
  683. ;// 3 - Logon Type string
  684. ;//
  685. ;// 4 - Logon process name
  686. ;//
  687. ;// 5 - Authentication package name
  688. ;//
  689. ;//
  690. MessageId=0x0218
  691. SymbolicName=SE_AUDITID_NETLOGON_NOT_STARTED
  692. Language=English
  693. Logon Failure:%n
  694. %tReason:%t%tThe NetLogon component is not active%n
  695. %tUser Name:%t%1%n
  696. %tDomain:%t%t%2%n
  697. %tLogon Type:%t%3%n
  698. %tLogon Process:%t%4%n
  699. %tAuthentication Package:%t%5%n
  700. %tWorkstation Name:%t%6
  701. .
  702. ;//
  703. ;//
  704. ;// SE_AUDITID_UNSUCCESSFUL_LOGON
  705. ;//
  706. ;// Category: SE_CATEGID_LOGON
  707. ;//
  708. ;// Parameter Strings -
  709. ;//
  710. ;// 1 - User account name
  711. ;//
  712. ;// 2 - Authenticating domain name
  713. ;//
  714. ;// 3 - Logon Type string
  715. ;//
  716. ;// 4 - Logon process name
  717. ;//
  718. ;// 5 - Authentication package name
  719. ;//
  720. ;//
  721. MessageId=0x0219
  722. SymbolicName=SE_AUDITID_UNSUCCESSFUL_LOGON
  723. Language=English
  724. Logon Failure:%n
  725. %tReason:%t%tAn error occurred during logon%n
  726. %tUser Name:%t%1%n
  727. %tDomain:%t%t%2%n
  728. %tLogon Type:%t%3%n
  729. %tLogon Process:%t%4%n
  730. %tAuthentication Package:%t%5%n
  731. %tWorkstation Name:%t%6%n
  732. %tStatus code:%t%7%n
  733. %tSubstatus code:%t%8
  734. .
  735. ;//
  736. ;//
  737. ;// SE_AUDITID_LOGOFF
  738. ;//
  739. ;// Category: SE_CATEGID_LOGON
  740. ;//
  741. ;// Event Type : success
  742. ;//
  743. ;// Description:
  744. ;// This event is generated when the logoff process is complete,
  745. ;// A logoff is considered complete when the associated logon session object
  746. ;// is deleted.
  747. ;//
  748. ;// Notes:
  749. ;// A logon session object is deleted only after all tokens
  750. ;// associated with it are closed. This can take arbitrarily long time.
  751. ;// Because of this, the time difference between SE_AUDITID_SUCCESSFUL_LOGON
  752. ;// and SE_AUDITID_LOGOFF does not accurately indicate the total logon duration
  753. ;// for a user. To calculate the logon duration, use the SE_AUDITID_BEGIN_LOGOFF
  754. ;// time instead.
  755. ;//
  756. ;// Parameter Strings -
  757. ;//
  758. ;// 1 - User account name
  759. ;//
  760. ;// 2 - Authenticating domain name
  761. ;//
  762. ;// 3 - Logon ID string
  763. ;//
  764. ;// 3 - Logon Type string
  765. ;//
  766. ;//
  767. ;//
  768. MessageId=0x021A
  769. SymbolicName=SE_AUDITID_LOGOFF
  770. Language=English
  771. User Logoff:%n
  772. %tUser Name:%t%1%n
  773. %tDomain:%t%t%2%n
  774. %tLogon ID:%t%t%3%n
  775. %tLogon Type:%t%4%n
  776. .
  777. ;//
  778. ;//
  779. ;// SE_AUDITID_ACCOUNT_LOCKED
  780. ;//
  781. ;// Category: SE_CATEGID_LOGON
  782. ;//
  783. ;// Parameter Strings -
  784. ;//
  785. ;// 1 - User account name
  786. ;//
  787. ;// 2 - Authenticating domain name
  788. ;//
  789. ;// 3 - Logon Type string
  790. ;//
  791. ;// 4 - Logon process name
  792. ;//
  793. ;// 5 - Authentication package name
  794. ;//
  795. ;//
  796. MessageId=0x021B
  797. SymbolicName=SE_AUDITID_ACCOUNT_LOCKED
  798. Language=English
  799. Logon Failure:%n
  800. %tReason:%t%tAccount locked out%n
  801. %tUser Name:%t%1%n
  802. %tDomain:%t%2%n
  803. %tLogon Type:%t%3%n
  804. %tLogon Process:%t%4%n
  805. %tAuthentication Package:%t%5%n
  806. %tWorkstation Name:%t%6
  807. .
  808. ;//
  809. ;//
  810. ;// SE_AUDITID_NETWORK_LOGON
  811. ;//
  812. ;// Category: SE_CATEGID_LOGON
  813. ;//
  814. ;// Description:
  815. ;// This event represents a successful logon of type Network(2) or
  816. ;// NetworkCleartext(8).
  817. ;//
  818. ;// [kumarp] I do not know why this event was created separately because
  819. ;// this was already covered by SE_AUDITID_SUCCESSFUL_LOGON with
  820. ;// the right logon types.
  821. ;//
  822. ;// Parameter Strings -
  823. ;//
  824. ;// 1 - User account name
  825. ;//
  826. ;// 2 - Authenticating domain name
  827. ;//
  828. ;// 3 - Logon ID string
  829. ;//
  830. ;// 4 - Logon Type string
  831. ;//
  832. ;// 5 - Logon process name
  833. ;//
  834. ;// 6 - Authentication package name
  835. ;//
  836. ;// 7 - Workstation from which logon request came
  837. ;//
  838. ;// 8 - Globally unique logon ID
  839. ;//
  840. MessageId=0x021c
  841. SymbolicName=SE_AUDITID_NETWORK_LOGON
  842. Language=English
  843. Successful Network Logon:%n
  844. %tUser Name:%t%1%n
  845. %tDomain:%t%t%2%n
  846. %tLogon ID:%t%t%3%n
  847. %tLogon Type:%t%4%n
  848. %tLogon Process:%t%5%n
  849. %tAuthentication Package:%t%6%n
  850. %tWorkstation Name:%t%7%n
  851. %tLogon GUID:%t%8
  852. .
  853. ;//
  854. ;//
  855. ;// SE_AUDITID_IPSEC_LOGON_SUCCESS
  856. ;//
  857. ;// Category: SE_CATEGID_LOGON
  858. ;//
  859. ;// Parameter Strings -
  860. ;//
  861. ;// 1 - Mode
  862. ;//
  863. ;// 2 - Peer Identity
  864. ;//
  865. ;// 3 - Filter
  866. ;//
  867. ;// 4 - Parameters
  868. ;//
  869. ;//
  870. MessageId=0x021d
  871. SymbolicName=SE_AUDITID_IPSEC_LOGON_SUCCESS
  872. Language=English
  873. IKE security association established.%n
  874. Mode: %n%1%n
  875. Peer Identity: %n%2%n
  876. Filter: %n%3%n
  877. Parameters: %n%4%n
  878. .
  879. ;//
  880. ;//
  881. ;// SE_AUDITID_IPSEC_LOGOFF_QM
  882. ;//
  883. ;// Category: SE_CATEGID_LOGON
  884. ;//
  885. ;// Parameter Strings -
  886. ;//
  887. ;// 1 - Filter
  888. ;//
  889. ;// 2 - Inbound SPI
  890. ;//
  891. ;// 3 - Outbound SPI
  892. ;//
  893. ;//
  894. MessageId=0x021e
  895. SymbolicName=SE_AUDITID_IPSEC_LOGOFF_QM
  896. Language=English
  897. IKE security association ended.%n
  898. Mode: Data Protection (Quick mode)
  899. Filter: %n%1%n
  900. Inbound SPI: %n%2%n
  901. Outbound SPI: %n%3%n
  902. .
  903. ;//
  904. ;//
  905. ;// SE_AUDITID_IPSEC_LOGOFF_MM
  906. ;//
  907. ;// Category: SE_CATEGID_LOGON
  908. ;//
  909. ;// Parameter Strings -
  910. ;//
  911. ;// 1 - Filter
  912. ;//
  913. MessageId=0x021f
  914. SymbolicName=SE_AUDITID_IPSEC_LOGOFF_MM
  915. Language=English
  916. IKE security association ended.%n
  917. Mode: Key Exchange (Main mode)%n
  918. Filter: %n%1%n
  919. .
  920. ;//
  921. ;//
  922. ;// SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST
  923. ;//
  924. ;// Category: SE_CATEGID_LOGON
  925. ;//
  926. ;// Parameter Strings -
  927. ;//
  928. ;// 1 - Peer Identity
  929. ;//
  930. ;// 2 - Filter
  931. ;//
  932. ;//
  933. MessageId=0x0220
  934. SymbolicName=SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST
  935. Language=English
  936. IKE security association establishment failed because peer could not authenticate.
  937. The certificate trust could not be established.%n
  938. Peer Identity: %n%1%n
  939. Filter: %n%2%n
  940. .
  941. ;//
  942. ;//
  943. ;// SE_AUDITID_IPSEC_AUTH_FAIL
  944. ;//
  945. ;// Category: SE_CATEGID_LOGON
  946. ;//
  947. ;// Parameter Strings -
  948. ;//
  949. ;// 1 - Peer Identity
  950. ;//
  951. ;// 2 - Filter
  952. ;//
  953. ;//
  954. MessageId=0x0221
  955. SymbolicName=SE_AUDITID_IPSEC_AUTH_FAIL
  956. Language=English
  957. IKE peer authentication failed.%n
  958. Peer Identity: %n%1%n
  959. Filter: %n%2%n
  960. .
  961. ;//
  962. ;//
  963. ;// SE_AUDITID_IPSEC_ATTRIB_FAIL
  964. ;//
  965. ;// Category: SE_CATEGID_LOGON
  966. ;//
  967. ;// Parameter Strings -
  968. ;//
  969. ;// 1 - Mode
  970. ;//
  971. ;// 2 - Filter
  972. ;//
  973. ;// 3 - Attribute Name
  974. ;//
  975. ;// 4 - Expected Value
  976. ;//
  977. ;// 5 - Received Value
  978. ;//
  979. ;//
  980. MessageId=0x0222
  981. SymbolicName=SE_AUDITID_IPSEC_ATTRIB_FAIL
  982. Language=English
  983. IKE security association establishment failed because peer
  984. sent invalid proposal.%n
  985. Mode: %n%1%n
  986. Filter: %n%2%n
  987. Attribute: %n%3%n
  988. Expected value: %n%4%n
  989. Received value: %n%5%n
  990. .
  991. ;//
  992. ;//
  993. ;// SE_AUDITID_IPSEC_NEGOTIATION_FAIL
  994. ;//
  995. ;// Category: SE_CATEGID_LOGON
  996. ;//
  997. ;// Parameter Strings -
  998. ;//
  999. ;// 1 - Mode
  1000. ;//
  1001. ;// 2 - Filter
  1002. ;//
  1003. ;// 3 - Failure Point
  1004. ;//
  1005. ;// 4 - Failure Reason
  1006. ;//
  1007. ;//
  1008. MessageId=0x0223
  1009. SymbolicName=SE_AUDITID_IPSEC_NEGOTIATION_FAIL
  1010. Language=English
  1011. IKE security association negotiation failed.%n
  1012. Mode: %n%1%n
  1013. Filter: %n%2%n
  1014. Peer Identity: %n%3%n
  1015. Failure Point: %n%4%n
  1016. Failure Reason: %n%5%n
  1017. Extra Status: %n%6%n
  1018. .
  1019. ;//
  1020. ;//
  1021. ;// SE_AUDITID_DOMAIN_TRUST_INCONSISTENT
  1022. ;//
  1023. ;// Category: SE_CATEGID_LOGON
  1024. ;//
  1025. ;// Event Type : failure
  1026. ;//
  1027. ;// Description:
  1028. ;// This event is generated by an authentication package when the
  1029. ;// quarantined domain SID filtering function in LSA returns
  1030. ;// STATUS_DOMAIN_TRUST_INCONSISTENT error code.
  1031. ;//
  1032. ;// In case of kerberos:
  1033. ;// If the server ticket info has a TDOSid then KdcCheckPacForSidFiltering
  1034. ;// function makes a check to make sure the SID from the TDO matches
  1035. ;// the client's home domain SID. A call to LsaIFilterSids
  1036. ;// is made to do the check. If this function fails with
  1037. ;// STATUS_DOMAIN_TRUST_INCONSISTENT then this event is generated.
  1038. ;//
  1039. ;// In case of netlogon:
  1040. ;// NlpUserValidateHigher function does a similar check by
  1041. ;// calling LsaIFilterSids.
  1042. ;//
  1043. ;// Notes:
  1044. ;//
  1045. MessageId=0x0224
  1046. SymbolicName=SE_AUDITID_DOMAIN_TRUST_INCONSISTENT
  1047. Language=English
  1048. Logon Failure:%n
  1049. %tReason:%t%tDomain sid inconsistent%n
  1050. %tUser Name:%t%1%n
  1051. %tDomain:%t%t%2%n
  1052. %tLogon Type:%t%3%n
  1053. %tLogon Process:%t%4%n
  1054. %tAuthentication Package:%t%5%n
  1055. %tWorkstation Name:%t%6
  1056. .
  1057. ;//
  1058. ;//
  1059. ;// SE_AUDITID_ALL_SIDS_FILTERED
  1060. ;//
  1061. ;// Category: SE_CATEGID_LOGON
  1062. ;//
  1063. ;// Event Type : failure
  1064. ;//
  1065. ;// Description:
  1066. ;// During a cross forest authentication, SIDS corresponding to untrusted
  1067. ;// namespaces are filtered out. If this filtering action results into
  1068. ;// removal of all sids then this event is generated.
  1069. ;//
  1070. ;// Notes:
  1071. ;// This is generated on the computer running kdc
  1072. ;//
  1073. MessageId=0x0225
  1074. SymbolicName=SE_AUDITID_ALL_SIDS_FILTERED
  1075. Language=English
  1076. Logon Failure:%n
  1077. %tReason: %tAll sids were filtered out%n
  1078. %tUser Name:%t%1%n
  1079. %tDomain:%t%2%n
  1080. %tLogon Type:%t%3%n
  1081. %tLogon Process:%t%4%n
  1082. %tAuthentication Package%t: %5%n
  1083. %tWorkstation Name:%t%6
  1084. .
  1085. ;//
  1086. ;//
  1087. ;// SE_AUDITID_IPSEC_IKE_NOTIFICATION
  1088. ;//
  1089. ;// Category: SE_CATEGID_LOGON
  1090. ;//
  1091. ;// Parameter Strings -
  1092. ;//
  1093. ;// 1 - Notification Message
  1094. ;//
  1095. MessageId=0x0226
  1096. SymbolicName=SE_AUDITID_IPSEC_IKE_NOTIFICATION
  1097. Language=English
  1098. %1%n
  1099. .
  1100. ;//
  1101. ;//
  1102. ;// SE_AUDITID_BEGIN_LOGOFF
  1103. ;//
  1104. ;// Category: SE_CATEGID_LOGON
  1105. ;//
  1106. ;// Event Type : success
  1107. ;//
  1108. ;// Description:
  1109. ;// This event is generated when a user initiates logoff.
  1110. ;//
  1111. ;// Notes:
  1112. ;// When the logoff process is complete, SE_AUDITID_LOGOFF event is generated.
  1113. ;// A logoff is considered complete when the associated logon session object
  1114. ;// is deleted. This happens only after all tokens associated with it are closed.
  1115. ;// This can take arbitrarily long time therefore there can be a substantial
  1116. ;// time difference between the two events.
  1117. ;//
  1118. ;//
  1119. ;// Parameter Strings -
  1120. ;//
  1121. ;// 1 - User account name
  1122. ;//
  1123. ;// 2 - Authenticating domain name
  1124. ;//
  1125. ;// 3 - Logon ID string
  1126. ;//
  1127. ;//
  1128. MessageId=0x0227
  1129. SymbolicName=SE_AUDITID_BEGIN_LOGOFF
  1130. Language=English
  1131. User initiated logoff:%n
  1132. %tUser Name:%t%1%n
  1133. %tDomain:%t%t%2%n
  1134. %tLogon ID:%t%t%3%n
  1135. .
  1136. ;//
  1137. ;//
  1138. ;// SE_AUDITID_LOGON_USING_EXPLICIT_CREDENTIALS
  1139. ;//
  1140. ;// Category: SE_CATEGID_LOGON
  1141. ;//
  1142. ;// Event Type : success
  1143. ;//
  1144. ;// Description:
  1145. ;// This event is generated when someone tries to logon using
  1146. ;// explicit credentials while already logged on as a different user.
  1147. ;//
  1148. ;// Notes:
  1149. ;// This is generated on the client machine from which logon request originates.
  1150. ;//
  1151. ;//
  1152. MessageId=0x0228
  1153. SymbolicName=SE_AUDITID_LOGON_USING_EXPLICIT_CREDENTIALS
  1154. Language=English
  1155. Logon attempt using explicit credentials:%n
  1156. Logged on user:%n
  1157. %tUser Name:%t%1%n
  1158. %tDomain:%t%2%n
  1159. %tLogon ID:%t%3%n
  1160. %tLogon GUID:%t%4%n
  1161. User whose credentials were used:%n
  1162. %tUser Name:%t%5%n
  1163. %tDomain:%t%6%n%n
  1164. %tLogon GUID:%t%7%n
  1165. .
  1166. ;
  1167. ;/////////////////////////////////////////////////////////////////////////////
  1168. ;// //
  1169. ;// //
  1170. ;// Messages for Category: SE_CATEGID_OBJECT_ACCESS //
  1171. ;// //
  1172. ;// Event IDs: //
  1173. ;// SE_AUDITID_OPEN_HANDLE //
  1174. ;// SE_AUDITID_CLOSE_HANDLE //
  1175. ;// SE_AUDITID_OPEN_OBJECT_FOR_DELETE //
  1176. ;// SE_AUDITID_DELETE_OBJECT //
  1177. ;// SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE //
  1178. ;// SE_AUDITID_OBJECT_OPERATION //
  1179. ;// SE_AUDITID_OBJECT_ACCESS //
  1180. ;// SE_AUDITID_HARDLINK_CREATION //
  1181. ;// //
  1182. ;// //
  1183. ;/////////////////////////////////////////////////////////////////////////////
  1184. ;//
  1185. ;//
  1186. ;// SE_AUDITID_OPEN_HANDLE
  1187. ;//
  1188. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1189. ;//
  1190. ;// Parameter Strings -
  1191. ;//
  1192. ;// 1 - Object Type string
  1193. ;//
  1194. ;// 2 - Object name
  1195. ;//
  1196. ;// 3 - New handle ID string
  1197. ;//
  1198. ;// 4 - Object server name
  1199. ;//
  1200. ;// 5 - Process ID string
  1201. ;//
  1202. ;// 6 - Primary user account name
  1203. ;//
  1204. ;// 7 - Primary authenticating domain name
  1205. ;//
  1206. ;// 8 - Primary logon ID string
  1207. ;//
  1208. ;// 9 - Client user account name ("-" if no client)
  1209. ;//
  1210. ;// 10 - Client authenticating domain name ("-" if no client)
  1211. ;//
  1212. ;// 11 - Client logon ID string ("-" if no client)
  1213. ;//
  1214. ;// 12 - Access names
  1215. ;//
  1216. ;//
  1217. ;//
  1218. ;//
  1219. MessageId=0x0230
  1220. SymbolicName=SE_AUDITID_OPEN_HANDLE
  1221. Language=English
  1222. Object Open:%n
  1223. %tObject Server:%t%1%n
  1224. %tObject Type:%t%2%n
  1225. %tObject Name:%t%3%n
  1226. %tHandle ID:%t%4%n
  1227. %tOperation ID:%t{%5,%6}%n
  1228. %tProcess ID:%t%7%n
  1229. %tImage File Name:%t%8%n
  1230. %tPrimary User Name:%t%9%n
  1231. %tPrimary Domain:%t%10%n
  1232. %tPrimary Logon ID:%t%11%n
  1233. %tClient User Name:%t%12%n
  1234. %tClient Domain:%t%13%n
  1235. %tClient Logon ID:%t%14%n
  1236. %tAccesses:%t%t%15%n
  1237. %tPrivileges:%t%t%16%n
  1238. %tRestricted Sid Count: %17%n
  1239. .
  1240. ;//
  1241. ;//
  1242. ;// SE_AUDITID_CLOSE_HANDLE
  1243. ;//
  1244. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1245. ;//
  1246. ;// Parameter Strings -
  1247. ;//
  1248. ;// 1 - Object server name
  1249. ;//
  1250. ;// 2 - Handle ID string
  1251. ;//
  1252. ;// 3 - Process ID string
  1253. ;//
  1254. ;//
  1255. ;//
  1256. ;//
  1257. MessageId=0x0232
  1258. SymbolicName=SE_AUDITID_CLOSE_HANDLE
  1259. Language=English
  1260. Handle Closed:%n
  1261. %tObject Server:%t%1%n
  1262. %tHandle ID:%t%2%n
  1263. %tProcess ID:%t%3%n
  1264. %tImage File Name:%t%4%n
  1265. .
  1266. ;//
  1267. ;//
  1268. ;// SE_AUDITID_OPEN_OBJECT_FOR_DELETE
  1269. ;//
  1270. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1271. ;//
  1272. ;// Parameter Strings -
  1273. ;//
  1274. ;// 1 - Object Type string
  1275. ;//
  1276. ;// 2 - Object name
  1277. ;//
  1278. ;// 3 - New handle ID string
  1279. ;//
  1280. ;// 4 - Object server name
  1281. ;//
  1282. ;// 5 - Process ID string
  1283. ;//
  1284. ;// 6 - Primary user account name
  1285. ;//
  1286. ;// 7 - Primary authenticating domain name
  1287. ;//
  1288. ;// 8 - Primary logon ID string
  1289. ;//
  1290. ;// 9 - Client user account name ("-" if no client)
  1291. ;//
  1292. ;// 10 - Client authenticating domain name ("-" if no client)
  1293. ;//
  1294. ;// 11 - Client logon ID string ("-" if no client)
  1295. ;//
  1296. ;// 12 - Access names
  1297. ;//
  1298. ;//
  1299. ;//
  1300. ;//
  1301. MessageId=0x0233
  1302. SymbolicName=SE_AUDITID_OPEN_OBJECT_FOR_DELETE
  1303. Language=English
  1304. Object Open for Delete:%n
  1305. %tObject Server:%t%1%n
  1306. %tObject Type:%t%2%n
  1307. %tObject Name:%t%3%n
  1308. %tHandle ID:%t%4%n
  1309. %tOperation ID:%t{%5,%6}%n
  1310. %tProcess ID:%t%7%n
  1311. %tPrimary User Name:%t%8%n
  1312. %tPrimary Domain:%t%9%n
  1313. %tPrimary Logon ID:%t%10%n
  1314. %tClient User Name:%t%11%n
  1315. %tClient Domain:%t%12%n
  1316. %tClient Logon ID:%t%13%n
  1317. %tAccesses%t%t%14%n
  1318. %tPrivileges%t%t%15%n
  1319. .
  1320. ;//
  1321. ;//
  1322. ;// SE_AUDITID_DELETE_OBJECT
  1323. ;//
  1324. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1325. ;//
  1326. ;// Parameter Strings -
  1327. ;//
  1328. ;// 1 - Object server name
  1329. ;//
  1330. ;// 2 - Handle ID string
  1331. ;//
  1332. ;// 3 - Process ID string
  1333. ;//
  1334. ;//
  1335. ;//
  1336. ;//
  1337. MessageId=0x0234
  1338. SymbolicName=SE_AUDITID_DELETE_OBJECT
  1339. Language=English
  1340. Object Deleted:%n
  1341. %tObject Server:%t%1%n
  1342. %tHandle ID:%t%2%n
  1343. %tProcess ID:%t%3%n
  1344. %tImage File Name:%t%4%n
  1345. .
  1346. ;//
  1347. ;//
  1348. ;// SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE
  1349. ;//
  1350. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1351. ;//
  1352. ;// Parameter Strings -
  1353. ;//
  1354. ;// 1 - Object Type string
  1355. ;//
  1356. ;// 2 - Object name
  1357. ;//
  1358. ;// 3 - New handle ID string
  1359. ;//
  1360. ;// 4 - Object server name
  1361. ;//
  1362. ;// 5 - Process ID string
  1363. ;//
  1364. ;// 6 - Primary user account name
  1365. ;//
  1366. ;// 7 - Primary authenticating domain name
  1367. ;//
  1368. ;// 8 - Primary logon ID string
  1369. ;//
  1370. ;// 9 - Client user account name ("-" if no client)
  1371. ;//
  1372. ;// 10 - Client authenticating domain name ("-" if no client)
  1373. ;//
  1374. ;// 11 - Client logon ID string ("-" if no client)
  1375. ;//
  1376. ;// 12 - Access names
  1377. ;//
  1378. ;// 13 - Object Type parameters
  1379. ;//
  1380. ;//
  1381. ;//
  1382. ;//
  1383. MessageId=0x0235
  1384. SymbolicName=SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE
  1385. Language=English
  1386. Object Open:%n
  1387. %tObject Server:%t%1%n
  1388. %tObject Type:%t%2%n
  1389. %tObject Name:%t%3%n
  1390. %tHandle ID:%t%4%n
  1391. %tOperation ID:%t{%5,%6}%n
  1392. %tProcess ID:%t%7%n
  1393. %tProcess Name:%t%8%n
  1394. %tPrimary User Name:%t%9%n
  1395. %tPrimary Domain:%t%10%n
  1396. %tPrimary Logon ID:%t%11%n
  1397. %tClient User Name:%t%12%n
  1398. %tClient Domain:%t%13%n
  1399. %tClient Logon ID:%t%14%n
  1400. %tAccesses%t%t%15%n
  1401. %tPrivileges%t%t%16%n%n
  1402. Properties:%n%17%18%19%20%21%22%23%24%25%26%n
  1403. .
  1404. ;
  1405. ;// SE_AUDITID_OBJECT_OPERATION
  1406. ;//
  1407. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1408. ;//
  1409. ;// Parameter Strings -
  1410. ;//
  1411. ;// 1 - Operation Name
  1412. ;//
  1413. ;// 2 - Object Type
  1414. ;//
  1415. ;// 3 - Object name
  1416. ;//
  1417. ;// 4 - Handle ID
  1418. ;//
  1419. ;// 5 - Primary user account name
  1420. ;//
  1421. ;// 6 - Primary authenticating domain name
  1422. ;//
  1423. ;// 7 - Primary logon ID string
  1424. ;//
  1425. ;// 8 - Client user account name ("-" if no client)
  1426. ;//
  1427. ;// 9 - Client authenticating domain name ("-" if no client)
  1428. ;//
  1429. ;// 10 - Client logon ID string ("-" if no client)
  1430. ;//
  1431. ;// 11 - Requested accesses to the object
  1432. ;//
  1433. ;// 12 - Object properties ("-" if none)
  1434. ;//
  1435. ;// 13 - additional information ("-" if none)
  1436. ;//
  1437. MessageId=0x0236
  1438. SymbolicName=SE_AUDITID_OBJECT_OPERATION
  1439. Language=English
  1440. Object Operation:%n
  1441. %tOperation Type%t%1%n
  1442. %tObject Type:%t%2%n
  1443. %tObject Name:%t%3%n
  1444. %tHandle ID:%t%4%n
  1445. %tPrimary User Name:%t%5%n
  1446. %tPrimary Domain:%t%6%n
  1447. %tPrimary Logon ID:%t%7%n
  1448. %tClient User Name:%t%8%n
  1449. %tClient Domain:%t%9%n
  1450. %tClient Logon ID:%t%10%n
  1451. %tAccesses%t%t%11%n
  1452. %tProperties:%n%12%n
  1453. %tAdditional Info:%t%13%n
  1454. .
  1455. ;//
  1456. ;//
  1457. ;// SE_AUDITID_OBJECT_ACCESS
  1458. ;//
  1459. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1460. ;//
  1461. ;// Parameter Strings -
  1462. ;//
  1463. ;// 1 - Object server name
  1464. ;//
  1465. ;// 2 - Handle ID string
  1466. ;//
  1467. ;// 3 - Process ID string
  1468. ;//
  1469. ;// 4 - List of Accesses
  1470. ;//
  1471. ;//
  1472. MessageId=0x0237
  1473. SymbolicName=SE_AUDITID_OBJECT_ACCESS
  1474. Language=English
  1475. Object Access Attempt:%n
  1476. %tObject Server:%t%1%n
  1477. %tHandle ID:%t%2%n
  1478. %tObject Type:%t%3%n
  1479. %tProcess ID:%t%4%n
  1480. %tImage File Name:%t%5%n
  1481. %tAccess Mask:%t%6%n
  1482. .
  1483. ;//
  1484. ;//
  1485. ;// SE_AUDITID_HARDLINK_CREATION
  1486. ;//
  1487. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1488. ;//
  1489. ;// Parameter Strings -
  1490. ;//
  1491. ;// 1 - Object server name
  1492. ;//
  1493. ;// 2 - Handle ID string
  1494. ;//
  1495. ;// 3 - Process ID string
  1496. ;//
  1497. ;//
  1498. ;//
  1499. ;//
  1500. MessageId=0x0238
  1501. SymbolicName=SE_AUDITID_HARDLINK_CREATION
  1502. Language=English
  1503. Hard link creation attempt:%n
  1504. %tPrimary User Name:%t%1%n
  1505. %tPrimary Domain:%t%2%n
  1506. %tPrimary Logon ID:%t%3%n
  1507. %tFile Name:%t%4%n
  1508. %tLink Name:%t%5%n
  1509. .
  1510. ;
  1511. ;/////////////////////////////////////////////////////////////////////////////
  1512. ;// //
  1513. ;// //
  1514. ;// Messages for Category: SE_CATEGID_PRIVILEGE_USE //
  1515. ;// //
  1516. ;// Event IDs: //
  1517. ;// SE_AUDITID_ASSIGN_SPECIAL_PRIV //
  1518. ;// SE_AUDITID_PRIVILEGED_SERVICE //
  1519. ;// SE_AUDITID_PRIVILEGED_OBJECT //
  1520. ;// //
  1521. ;// //
  1522. ;// //
  1523. ;/////////////////////////////////////////////////////////////////////////////
  1524. ;//
  1525. ;//
  1526. ;// SE_AUDITID_ASSIGN_SPECIAL_PRIV
  1527. ;//
  1528. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1529. ;//
  1530. ;// Description:
  1531. ;// When a user logs on, if any one of the following privileges is added
  1532. ;// to his/her token, this event is generated.
  1533. ;//
  1534. ;// - SeChangeNotifyPrivilege
  1535. ;// - SeAuditPrivilege
  1536. ;// - SeCreateTokenPrivilege
  1537. ;// - SeAssignPrimaryTokenPrivilege
  1538. ;// - SeBackupPrivilege
  1539. ;// - SeRestorePrivilege
  1540. ;// - SeDebugPrivilege
  1541. ;//
  1542. ;//
  1543. ;// Parameter Strings -
  1544. ;//
  1545. ;// 1 - User name
  1546. ;//
  1547. ;// 2 - domain name
  1548. ;//
  1549. ;// 3 - Logon ID string
  1550. ;//
  1551. ;// 4 - Privilege names (as 1 string, with formatting)
  1552. ;//
  1553. ;//
  1554. ;//
  1555. ;//
  1556. MessageId=0x0240
  1557. SymbolicName=SE_AUDITID_ASSIGN_SPECIAL_PRIV
  1558. Language=English
  1559. Special privileges assigned to new logon:%n
  1560. %tUser Name:%t%1%n
  1561. %tDomain:%t%t%2%n
  1562. %tLogon ID:%t%t%3%n
  1563. %tPrivileges:%t%t%4
  1564. .
  1565. ;//
  1566. ;//
  1567. ;// SE_AUDITID_PRIVILEGED_SERVICE
  1568. ;//
  1569. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1570. ;//
  1571. ;// Description:
  1572. ;// This event is generated when a user makes an attempt to perform
  1573. ;// a privileged system service operation.
  1574. ;//
  1575. ;// Parameter Strings -
  1576. ;//
  1577. ;// 1 - server name
  1578. ;//
  1579. ;// 2 - service name
  1580. ;//
  1581. ;// 3 - Primary User name
  1582. ;//
  1583. ;// 4 - Primary domain name
  1584. ;//
  1585. ;// 5 - Primary Logon ID string
  1586. ;//
  1587. ;// 6 - Client User name (or "-" if not impersonating)
  1588. ;//
  1589. ;// 7 - Client domain name (or "-" if not impersonating)
  1590. ;//
  1591. ;// 8 - Client Logon ID string (or "-" if not impersonating)
  1592. ;//
  1593. ;// 9 - Privilege names (as 1 string, with formatting)
  1594. ;//
  1595. ;//
  1596. ;//
  1597. ;//
  1598. MessageId=0x0241
  1599. SymbolicName=SE_AUDITID_PRIVILEGED_SERVICE
  1600. Language=English
  1601. Privileged Service Called:%n
  1602. %tServer:%t%t%1%n
  1603. %tService:%t%t%2%n
  1604. %tPrimary User Name:%t%3%n
  1605. %tPrimary Domain:%t%4%n
  1606. %tPrimary Logon ID:%t%5%n
  1607. %tClient User Name:%t%6%n
  1608. %tClient Domain:%t%7%n
  1609. %tClient Logon ID:%t%8%n
  1610. %tPrivileges:%t%9
  1611. .
  1612. ;//
  1613. ;//
  1614. ;// SE_AUDITID_PRIVILEGED_OBJECT
  1615. ;//
  1616. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1617. ;//
  1618. ;// Parameter Strings -
  1619. ;//
  1620. ;// 1 - object server
  1621. ;//
  1622. ;// 2 - object handle (if available)
  1623. ;//
  1624. ;// 3 - process ID string
  1625. ;//
  1626. ;// 4 - Primary User name
  1627. ;//
  1628. ;// 5 - Primary domain name
  1629. ;//
  1630. ;// 6 - Primary Logon ID string
  1631. ;//
  1632. ;// 7 - Client User name (or "-" if not impersonating)
  1633. ;//
  1634. ;// 8 - Client domain name (or "-" if not impersonating)
  1635. ;//
  1636. ;// 9 - Client Logon ID string (or "-" if not impersonating)
  1637. ;//
  1638. ;// 10 - Privilege names (as 1 string, with formatting)
  1639. ;//
  1640. ;//
  1641. MessageId=0x0242
  1642. SymbolicName=SE_AUDITID_PRIVILEGED_OBJECT
  1643. Language=English
  1644. Privileged object operation:%n
  1645. %tObject Server:%t%1%n
  1646. %tObject Handle:%t%2%n
  1647. %tProcess ID:%t%3%n
  1648. %tPrimary User Name:%t%4%n
  1649. %tPrimary Domain:%t%5%n
  1650. %tPrimary Logon ID:%t%6%n
  1651. %tClient User Name:%t%7%n
  1652. %tClient Domain:%t%8%n
  1653. %tClient Logon ID:%t%9%n
  1654. %tPrivileges:%t%10
  1655. .
  1656. ;
  1657. ;/////////////////////////////////////////////////////////////////////////////
  1658. ;// //
  1659. ;// //
  1660. ;// Messages for Category: SE_CATEGID_DETAILED_TRACKING //
  1661. ;// //
  1662. ;// Event IDs: //
  1663. ;// SE_AUDITID_PROCESS_CREATED //
  1664. ;// SE_AUDITID_PROCESS_EXIT //
  1665. ;// SE_AUDITID_DUPLICATE_HANDLE //
  1666. ;// SE_AUDITID_INDIRECT_REFERENCE //
  1667. ;// SE_AUDITID_DPAPI_BACKUP //
  1668. ;// SE_AUDITID_DPAPI_RECOVERY //
  1669. ;// SE_AUDITID_DPAPI_PROTECT //
  1670. ;// SE_AUDITID_DPAPI_UNPROTECT //
  1671. ;// SE_AUDITID_ASSIGN_TOKEN //
  1672. ;// //
  1673. ;// //
  1674. ;/////////////////////////////////////////////////////////////////////////////
  1675. ;//
  1676. ;//
  1677. ;// SE_AUDITID_PROCESS_CREATED
  1678. ;//
  1679. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1680. ;//
  1681. ;// Parameter Strings -
  1682. ;//
  1683. ;// 1 - process ID string
  1684. ;//
  1685. ;// 2 - Image file name (if available - otherwise "-")
  1686. ;//
  1687. ;// 3 - Creating process's ID
  1688. ;//
  1689. ;// 4 - User name (of new process)
  1690. ;//
  1691. ;// 5 - domain name (of new process)
  1692. ;//
  1693. ;// 6 - Logon ID string (of new process)
  1694. ;//
  1695. MessageId=0x0250
  1696. SymbolicName=SE_AUDITID_PROCESS_CREATED
  1697. Language=English
  1698. A new process has been created:%n
  1699. %tNew Process ID:%t%1%n
  1700. %tImage File Name:%t%2%n
  1701. %tCreator Process ID:%t%3%n
  1702. %tUser Name:%t%4%n
  1703. %tDomain:%t%t%5%n
  1704. %tLogon ID:%t%t%6%n
  1705. .
  1706. ;//
  1707. ;//
  1708. ;// SE_AUDITID_PROCESS_EXIT
  1709. ;//
  1710. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1711. ;//
  1712. ;// Parameter Strings -
  1713. ;//
  1714. ;// 1 - process ID string
  1715. ;//
  1716. ;// 2 - image name
  1717. ;//
  1718. ;// 3 - User name
  1719. ;//
  1720. ;// 4 - domain name
  1721. ;//
  1722. ;// 5 - Logon ID string
  1723. ;//
  1724. ;//
  1725. ;//
  1726. ;//
  1727. MessageId=0x0251
  1728. SymbolicName=SE_AUDITID_PROCESS_EXIT
  1729. Language=English
  1730. A process has exited:%n
  1731. %tProcess ID:%t%1%n
  1732. %tImage File Name:%t%2%n
  1733. %tUser Name:%t%3%n
  1734. %tDomain:%t%t%4%n
  1735. %tLogon ID:%t%t%5%n
  1736. .
  1737. ;//
  1738. ;//
  1739. ;// SE_AUDITID_DUPLICATE_HANDLE
  1740. ;//
  1741. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1742. ;//
  1743. ;// Parameter Strings -
  1744. ;//
  1745. ;// 1 - Origin (source) handle ID string
  1746. ;//
  1747. ;// 2 - Origin (source) process ID string
  1748. ;//
  1749. ;// 3 - New (Target) handle ID string
  1750. ;//
  1751. ;// 4 - Target process ID string
  1752. ;//
  1753. ;//
  1754. ;//
  1755. MessageId=0x0252
  1756. SymbolicName=SE_AUDITID_DUPLICATE_HANDLE
  1757. Language=English
  1758. A handle to an object has been duplicated:%n
  1759. %tSource Handle ID:%t%1%n
  1760. %tSource Process ID:%t%2%n
  1761. %tTarget Handle ID:%t%3%n
  1762. %tTarget Process ID:%t%4%n
  1763. .
  1764. ;//
  1765. ;//
  1766. ;// SE_AUDITID_INDIRECT_REFERENCE
  1767. ;//
  1768. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1769. ;//
  1770. ;// Parameter Strings -
  1771. ;//
  1772. ;// 1 - Object type
  1773. ;//
  1774. ;// 2 - object name (if available - otherwise "-")
  1775. ;//
  1776. ;// 3 - ID string of handle used to gain access
  1777. ;//
  1778. ;// 3 - server name
  1779. ;//
  1780. ;// 4 - process ID string
  1781. ;//
  1782. ;// 5 - primary User name
  1783. ;//
  1784. ;// 6 - primary domain name
  1785. ;//
  1786. ;// 7 - primary logon ID
  1787. ;//
  1788. ;// 8 - client User name
  1789. ;//
  1790. ;// 9 - client domain name
  1791. ;//
  1792. ;// 10 - client logon ID
  1793. ;//
  1794. ;// 11 - granted access names (with formatting)
  1795. ;//
  1796. ;//
  1797. MessageId=0x0253
  1798. SymbolicName=SE_AUDITID_INDIRECT_REFERENCE
  1799. Language=English
  1800. Indirect access to an object has been obtained:%n
  1801. %tObject Type:%t%1%n
  1802. %tObject Name:%t%2%n
  1803. %tProcess ID:%t%3%n
  1804. %tPrimary User Name:%t%4%n
  1805. %tPrimary Domain:%t%5%n
  1806. %tPrimary Logon ID:%t%6%n
  1807. %tClient User Name:%t%7%n
  1808. %tClient Domain:%t%8%n
  1809. %tClient Logon ID:%t%9%n
  1810. %tAccesses:%t%10%n
  1811. .
  1812. ;//
  1813. ;//
  1814. ;// SE_AUDITID_DPAPI_BACKUP
  1815. ;//
  1816. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1817. ;//
  1818. ;// Parameter Strings -
  1819. ;//
  1820. ;// 1 - Master key GUID
  1821. ;//
  1822. ;// 2 - Recovery Server
  1823. ;//
  1824. ;// 3 - GUID identifier of the recovery key
  1825. ;//
  1826. ;// 4 - Failure reason
  1827. ;//
  1828. MessageId=0x0254
  1829. SymbolicName=SE_AUDITID_DPAPI_BACKUP
  1830. Language=English
  1831. Backup of data protection master key.
  1832. %n
  1833. %tKey Identifier:%t%t%1%n
  1834. %tRecovery Server:%t%t%2%n
  1835. %tRecovery Key ID:%t%t%3%n
  1836. %tFailure Reason:%t%t%4%n
  1837. .
  1838. ;//
  1839. ;//
  1840. ;// SE_AUDITID_DPAPI_RECOVERY
  1841. ;//
  1842. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1843. ;//
  1844. ;// Parameter Strings -
  1845. ;//
  1846. ;// 1 - Master key GUID
  1847. ;//
  1848. ;// 2 - Recovery Server
  1849. ;//
  1850. ;// 3 - Reason for the backup
  1851. ;//
  1852. ;// 4 - GUID identifier of the recovery key
  1853. ;//
  1854. ;// 5 - Failure reason
  1855. ;//
  1856. MessageId=0x0255
  1857. SymbolicName=SE_AUDITID_DPAPI_RECOVERY
  1858. Language=English
  1859. Recovery of data protection master key.
  1860. %n
  1861. %tKey Identifier:%t%t%1%n
  1862. %tRecovery Reason:%t%t%3%n
  1863. %tRecovery Server:%t%t%2%n
  1864. %tRecovery Key ID:%t%t%4%n
  1865. %tFailure Reason:%t%t%5%n
  1866. .
  1867. ;//
  1868. ;//
  1869. ;// SE_AUDITID_DPAPI_PROTECT
  1870. ;//
  1871. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1872. ;//
  1873. ;// Parameter Strings -
  1874. ;//
  1875. ;//
  1876. ;// 1 - Master key GUID
  1877. ;//
  1878. ;// 2 - Data Description
  1879. ;//
  1880. ;// 3 - Protected data flags
  1881. ;//
  1882. ;// 4 - Algorithms
  1883. ;//
  1884. ;// 5 - failure reason
  1885. ;//
  1886. MessageId=0x0256
  1887. SymbolicName=SE_AUDITID_DPAPI_PROTECT
  1888. Language=English
  1889. Protection of auditable protected data.
  1890. %n
  1891. %tData Description:%t%t%2%n
  1892. %tKey Identifier:%t%t%1%n
  1893. %tProtected Data Flags:%t%3%n
  1894. %tProtection Algorithms:%t%4%n
  1895. %tFailure Reason:%t%t%5%n
  1896. .
  1897. ;//
  1898. ;//
  1899. ;// SE_AUDITID_DPAPI_UNPROTECT
  1900. ;//
  1901. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1902. ;//
  1903. ;// Parameter Strings -
  1904. ;//
  1905. ;//
  1906. ;// 1 - Master key GUID
  1907. ;//
  1908. ;// 2 - Data Description
  1909. ;//
  1910. ;// 3 - Protected data flags
  1911. ;//
  1912. ;// 4 - Algorithms
  1913. ;//
  1914. ;// 5 - failure reason
  1915. ;//
  1916. MessageId=0x0257
  1917. SymbolicName=SE_AUDITID_DPAPI_UNPROTECT
  1918. Language=English
  1919. Unprotection of auditable protected data.
  1920. %n
  1921. %tData Description:%t%t%2%n
  1922. %tKey Identifier:%t%t%1%n
  1923. %tProtected Data Flags:%t%3%n
  1924. %tProtection Algorithms:%t%4%n
  1925. %tFailure Reason:%t%t%5%n
  1926. .
  1927. ;//
  1928. ;//
  1929. ;// SE_AUDITID_ASSIGN_TOKEN
  1930. ;//
  1931. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1932. ;//
  1933. ;// Parameter Strings -
  1934. ;//
  1935. ;// 1. Current Process ID (the process doing the assignment
  1936. ;// 2. Current Image File Name
  1937. ;// 3. Current User Name
  1938. ;// 4. Current Domain
  1939. ;// 5. Current Logon ID
  1940. ;//
  1941. ;// 6. Process ID (of new process)
  1942. ;// 7. Image Name (of new process)
  1943. ;// 8. User name (of new process)
  1944. ;// 9. domain name (of new process)
  1945. ;// 10. Logon ID string (of new process)
  1946. ;//
  1947. MessageId=0x0258
  1948. SymbolicName=SE_AUDITID_ASSIGN_TOKEN
  1949. Language=English
  1950. A process was assigned a primary token.
  1951. %n
  1952. Assigning Process Information:%n
  1953. %tProcess ID:%t%1%n
  1954. %tImage File Name:%t%2%n
  1955. %tUser Name:%t%3%n
  1956. %tDomain:%t%t%4%n
  1957. %tLogon ID:%t%t%5%n
  1958. New Process Information:%n
  1959. %tProcess ID:%t%6%n
  1960. %tImage File Name:%t%7%n
  1961. %tUser Name:%t%8%n
  1962. %tDomain:%t%t%9%n
  1963. %tLogon ID:%t%t%10%n
  1964. .
  1965. ;
  1966. ;/////////////////////////////////////////////////////////////////////////////
  1967. ;// //
  1968. ;// //
  1969. ;// Messages for Category: SE_CATEGID_POLICY_CHANGE //
  1970. ;// //
  1971. ;// Event IDs: //
  1972. ;// SE_AUDITID_USER_RIGHT_ASSIGNED //
  1973. ;// SE_AUDITID_USER_RIGHT_REMOVED //
  1974. ;// SE_AUDITID_TRUSTED_DOMAIN_ADD //
  1975. ;// SE_AUDITID_TRUSTED_DOMAIN_REM //
  1976. ;// SE_AUDITID_TRUSTED_DOMAIN_MOD //
  1977. ;// SE_AUDITID_POLICY_CHANGE //
  1978. ;// SE_AUDITID_IPSEC_POLICY_START //
  1979. ;// SE_AUDITID_IPSEC_POLICY_DISABLED //
  1980. ;// SE_AUDITID_IPSEC_POLICY_CHANGED //
  1981. ;// SE_AUDITID_IPSEC_POLICY_FAILURE //
  1982. ;// SE_AUDITID_SYSTEM_ACCESS_CHANGE //
  1983. ;// SE_AUDITID_NAMESPACE_COLLISION //
  1984. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD //
  1985. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM //
  1986. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD //
  1987. ;// //
  1988. ;// //
  1989. ;/////////////////////////////////////////////////////////////////////////////
  1990. ;//
  1991. ;//
  1992. ;// SE_AUDITID_USER_RIGHT_ASSIGNED
  1993. ;//
  1994. ;// Category: SE_CATEGID_POLICY_CHANGE
  1995. ;//
  1996. ;// Parameter Strings -
  1997. ;//
  1998. ;// 1 - User right name
  1999. ;//
  2000. ;// 2 - SID string of account assigned the user right
  2001. ;//
  2002. ;// 3 - User name of subject assigning the right
  2003. ;//
  2004. ;// 4 - Domain name of subject assigning the right
  2005. ;//
  2006. ;// 5 - Logon ID string of subject assigning the right
  2007. ;//
  2008. ;//
  2009. ;//
  2010. MessageId=0x0260
  2011. SymbolicName=SE_AUDITID_USER_RIGHT_ASSIGNED
  2012. Language=English
  2013. User Right Assigned:%n
  2014. %tUser Right:%t%1%n
  2015. %tAssigned To:%t%2%n
  2016. %tAssigned By:%n
  2017. %t User Name:%t%3%n
  2018. %t Domain:%t%t%4%n
  2019. %t Logon ID:%t%5%n
  2020. .
  2021. ;//
  2022. ;//
  2023. ;// SE_AUDITID_USER_RIGHT_REMOVED
  2024. ;//
  2025. ;// Category: SE_CATEGID_POLICY_CHANGE
  2026. ;//
  2027. ;// Parameter Strings -
  2028. ;//
  2029. ;// 1 - User right name
  2030. ;//
  2031. ;// 2 - SID string of account from which the user
  2032. ;// right was removed
  2033. ;//
  2034. ;// 3 - User name of subject removing the right
  2035. ;//
  2036. ;// 4 - Domain name of subject removing the right
  2037. ;//
  2038. ;// 5 - Logon ID string of subject removing the right
  2039. ;//
  2040. ;//
  2041. MessageId=0x0261
  2042. SymbolicName=SE_AUDITID_USER_RIGHT_REMOVED
  2043. Language=English
  2044. User Right Removed:%n
  2045. %tUser Right:%t%1%n
  2046. %tRemoved From:%t%2%n
  2047. %tRemoved By:%n
  2048. %t User Name:%t%3%n
  2049. %t Domain:%t%t%4%n
  2050. %t Logon ID:%t%5%n
  2051. .
  2052. ;//
  2053. ;//
  2054. ;// SE_AUDITID_TRUSTED_DOMAIN_ADD
  2055. ;//
  2056. ;// Category: SE_CATEGID_POLICY_CHANGE
  2057. ;//
  2058. ;// Event type: success/failure
  2059. ;//
  2060. ;// Description:
  2061. ;// This event is generated when somebody creates a trust relationship
  2062. ;// with another domain.
  2063. ;//
  2064. ;// Note:
  2065. ;// It is recorded on the domain controller on which
  2066. ;// the trusted domain object (TDO) is created and not on any other
  2067. ;// domain controller to which the TDO creation replicates.
  2068. ;//
  2069. MessageId=0x0262
  2070. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_ADD
  2071. Language=English
  2072. New Trusted Domain:%n
  2073. %tDomain Name:%t%1%n
  2074. %tDomain ID:%t%2%n
  2075. %tEstablished By:%n
  2076. %t User Name:%t%3%n
  2077. %t Domain:%t%t%4%n
  2078. %t Logon ID:%t%5%n
  2079. %tTrust Type:%t%6%n
  2080. %tTrust Direction:%t%7%n
  2081. %tTrust Attributes:%t%8%n
  2082. .
  2083. ;//
  2084. ;//
  2085. ;// SE_AUDITID_TRUSTED_DOMAIN_REM
  2086. ;//
  2087. ;// Category: SE_CATEGID_POLICY_CHANGE
  2088. ;//
  2089. ;// Event type: success/failure
  2090. ;//
  2091. ;// Description:
  2092. ;// This event is generated when somebody removes a trust relationship
  2093. ;// with another domain.
  2094. ;//
  2095. ;// Note:
  2096. ;// It is recorded on the domain controller on which
  2097. ;// the trusted domain object (TDO) is deleted and not on any other
  2098. ;// domain controller to which the TDO deletion replicates.
  2099. ;//
  2100. MessageId=0x0263
  2101. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_REM
  2102. Language=English
  2103. Trusted Domain Removed:%n
  2104. %tDomain Name:%t%1%n
  2105. %tDomain ID:%t%2%n
  2106. %tRemoved By:%n
  2107. %t User Name:%t%3%n
  2108. %t Domain:%t%t%4%n
  2109. %t Logon ID:%t%5%n
  2110. .
  2111. ;//
  2112. ;//
  2113. ;// SE_AUDITID_POLICY_CHANGE
  2114. ;//
  2115. ;// Category: SE_CATEGID_POLICY_CHANGE
  2116. ;//
  2117. ;// Parameter Strings -
  2118. ;//
  2119. ;// 1 - System success audit status ("+" or "-")
  2120. ;// 2 - System failure audit status ("+" or "-")
  2121. ;//
  2122. ;// 3 - Logon/Logoff success audit status ("+" or "-")
  2123. ;// 4 - Logon/Logoff failure audit status ("+" or "-")
  2124. ;//
  2125. ;// 5 - Object Access success audit status ("+" or "-")
  2126. ;// 6 - Object Access failure audit status ("+" or "-")
  2127. ;//
  2128. ;// 7 - Detailed Tracking success audit status ("+" or "-")
  2129. ;// 8 - Detailed Tracking failure audit status ("+" or "-")
  2130. ;//
  2131. ;// 9 - Privilege Use success audit status ("+" or "-")
  2132. ;// 10 - Privilege Use failure audit status ("+" or "-")
  2133. ;//
  2134. ;// 11 - Policy Change success audit status ("+" or "-")
  2135. ;// 12 - Policy Change failure audit status ("+" or "-")
  2136. ;//
  2137. ;// 13 - Account Management success audit status ("+" or "-")
  2138. ;// 14 - Account Management failure audit status ("+" or "-")
  2139. ;//
  2140. ;// 15 - Directory Service access success audit status ("+" or "-")
  2141. ;// 16 - Directory Service access failure audit status ("+" or "-")
  2142. ;//
  2143. ;// 17 - Account Logon success audit status ("+" or "-")
  2144. ;// 18 - Account Logon failure audit status ("+" or "-")
  2145. ;//
  2146. ;// 19 - Account Name of user that changed the policy
  2147. ;//
  2148. ;// 20 - Domain of user that changed the policy
  2149. ;//
  2150. ;// 21 - Logon ID of user that changed the policy
  2151. ;//
  2152. ;//
  2153. MessageId=0x0264
  2154. SymbolicName=SE_AUDITID_POLICY_CHANGE
  2155. Language=English
  2156. Audit Policy Change:%n
  2157. New Policy:%n
  2158. %tSuccess%tFailure%n
  2159. %t %3%t %4%tLogon/Logoff%n
  2160. %t %5%t %6%tObject Access%n
  2161. %t %7%t %8%tPrivilege Use%n
  2162. %t %13%t %14%tAccount Management%n
  2163. %t %11%t %12%tPolicy Change%n
  2164. %t %1%t %2%tSystem%n
  2165. %t %9%t %10%tDetailed Tracking%n
  2166. %t %15%t %16%tDirectory Service Access%n
  2167. %t %17%t %18%tAccount Logon%n%n
  2168. Changed By:%n
  2169. %t User Name:%t%19%n
  2170. %t Domain Name:%t%20%n
  2171. %t Logon ID:%t%21
  2172. .
  2173. ;//
  2174. ;//
  2175. ;// SE_AUDITID_IPSEC_POLICY_START
  2176. ;//
  2177. ;// Category: SE_CATEGID_POLICY_CHANGE
  2178. ;//
  2179. ;// Parameter Strings -
  2180. ;//
  2181. ;// 1 - Ipsec Policy Agent
  2182. ;//
  2183. ;// 2 - Policy Source
  2184. ;//
  2185. ;// 3 - Event Data
  2186. ;//
  2187. ;//
  2188. MessageId=0x0265
  2189. SymbolicName=SE_AUDITID_IPSEC_POLICY_START
  2190. Language=English
  2191. IPSec Services started: %t%1%n
  2192. Policy Source: %t%2%n
  2193. %3%n
  2194. .
  2195. ;//
  2196. ;//
  2197. ;// SE_AUDITID_IPSEC_POLICY_DISABLED
  2198. ;//
  2199. ;// Category: SE_CATEGID_POLICY_CHANGE
  2200. ;//
  2201. ;// Parameter Strings -
  2202. ;//
  2203. ;// 1 - Ipsec Policy Agent
  2204. ;//
  2205. ;// 2 - Event Data
  2206. ;//
  2207. ;//
  2208. MessageId=0x0266
  2209. SymbolicName=SE_AUDITID_IPSEC_POLICY_DISABLED
  2210. Language=English
  2211. IPSec Services disabled: %t%1%n
  2212. %2%n
  2213. .
  2214. ;//
  2215. ;//
  2216. ;// SE_AUDITID_IPSEC_POLICY_CHANGED
  2217. ;//
  2218. ;// Category: SE_CATEGID_POLICY_CHANGE
  2219. ;//
  2220. ;// Parameter Strings -
  2221. ;//
  2222. ;// 1 - Event Data
  2223. ;//
  2224. ;//
  2225. MessageId=0x0267
  2226. SymbolicName=SE_AUDITID_IPSEC_POLICY_CHANGED
  2227. Language=English
  2228. IPSec Services: %t%1%n
  2229. .
  2230. ;//
  2231. ;//
  2232. ;// SE_AUDITID_IPSEC_POLICY_FAILURE
  2233. ;//
  2234. ;// Category: SE_CATEGID_POLICY_CHANGE
  2235. ;//
  2236. ;// Parameter Strings -
  2237. ;//
  2238. ;// 1 - Event Data
  2239. ;//
  2240. ;//
  2241. MessageId=0x0268
  2242. SymbolicName=SE_AUDITID_IPSEC_POLICY_FAILURE
  2243. Language=English
  2244. IPSec Services encountered a potentially serious failure.%n
  2245. %1%n
  2246. .
  2247. ;//
  2248. ;//
  2249. ;// SE_AUDITID_KERBEROS_POLICY_CHANGE
  2250. ;//
  2251. ;// Category: SE_CATEGID_POLICY_CHANGE
  2252. ;//
  2253. ;// Parameter Strings -
  2254. ;//
  2255. ;// 1 - user account name
  2256. ;//
  2257. ;// 2 - domain name of user
  2258. ;//
  2259. ;// 3 - logon ID of user
  2260. ;//
  2261. ;// 4 - description of the change made
  2262. ;//
  2263. ;//
  2264. MessageId=0x0269
  2265. SymbolicName=SE_AUDITID_KERBEROS_POLICY_CHANGE
  2266. Language=English
  2267. Kerberos Policy Changed:%n
  2268. Changed By:%n
  2269. %t User Name:%t%1%n
  2270. %t Domain Name:%t%2%n
  2271. %t Logon ID:%t%3%n
  2272. Changes made:%n
  2273. ('--' means no changes, otherwise each change is shown as:%n
  2274. <ParameterName>: <new value> (<old value>))%n
  2275. %4%n
  2276. .
  2277. ;//
  2278. ;//
  2279. ;// SE_AUDITID_EFS_POLICY_CHANGE
  2280. ;//
  2281. ;// Category: SE_CATEGID_POLICY_CHANGE
  2282. ;//
  2283. ;// Parameter Strings -
  2284. ;//
  2285. ;// 1 - user account name
  2286. ;//
  2287. ;// 2 - domain name of user
  2288. ;//
  2289. ;// 3 - logon ID of user
  2290. ;//
  2291. ;// 4 - description of the change made
  2292. ;//
  2293. ;//
  2294. MessageId=0x026a
  2295. SymbolicName=SE_AUDITID_EFS_POLICY_CHANGE
  2296. Language=English
  2297. Encrypted Data Recovery Policy Changed:%n
  2298. Changed By:%n
  2299. %t User Name:%t%1%n
  2300. %t Domain Name:%t%2%n
  2301. %t Logon ID:%t%3%n
  2302. Changes made:%n
  2303. ('--' means no changes, otherwise each change is shown as:%n
  2304. <ParameterName>: <new value> (<old value>))%n
  2305. %4%n
  2306. .
  2307. ;//
  2308. ;//
  2309. ;// SE_AUDITID_TRUSTED_DOMAIN_MOD
  2310. ;//
  2311. ;// Category: SE_CATEGID_POLICY_CHANGE
  2312. ;//
  2313. ;// Event type: success/failure
  2314. ;//
  2315. ;// Description:
  2316. ;// This event is generated when somebody modifies a trust relationship
  2317. ;// with another domain.
  2318. ;//
  2319. ;// Note:
  2320. ;// It is recorded on the domain controller on which
  2321. ;// the trusted domain object (TDO) is modified and not on any other
  2322. ;// domain controller to which the TDO modification replicates.
  2323. ;//
  2324. MessageId=0x026C
  2325. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_MOD
  2326. Language=English
  2327. Trusted Domain Information Modified:%n
  2328. %tDomain Name:%t%1%n
  2329. %tDomain ID:%t%2%n
  2330. %tModified By:%n
  2331. %t User Name:%t%3%n
  2332. %t Domain:%t%t%4%n
  2333. %t Logon ID:%t%5%n
  2334. %tTrust Type:%t%6%n
  2335. %tTrust Direction:%t%7%n
  2336. %tTrust Attributes:%t%8%n
  2337. .
  2338. ;//
  2339. ;//
  2340. ;// SE_AUDITID_SYSTEM_ACCESS_GRANTED
  2341. ;//
  2342. ;// Category: SE_CATEGID_POLICY_CHANGE
  2343. ;//
  2344. ;// Parameter Strings -
  2345. ;//
  2346. ;// 1 - User right name
  2347. ;//
  2348. ;// 2 - SID string of account for which the user
  2349. ;// right was affected
  2350. ;//
  2351. ;// 3 - User name of subject changing the right
  2352. ;//
  2353. ;// 4 - Domain name of subject changing the right
  2354. ;//
  2355. ;// 5 - Logon ID string of subject changing the right
  2356. ;//
  2357. ;//
  2358. MessageId=0x026d
  2359. SymbolicName=SE_AUDITID_SYSTEM_ACCESS_GRANTED
  2360. Language=English
  2361. System Security Access Granted:%n
  2362. %tAccess Granted:%t%4%n
  2363. %tAccount Modified:%t%5%n
  2364. %tAssigned By:%n
  2365. %t User Name:%t%1%n
  2366. %t Domain:%t%t%2%n
  2367. %t Logon ID:%t%3%n
  2368. .
  2369. ;//
  2370. ;//
  2371. ;// SE_AUDITID_SYSTEM_ACCESS_REMOVED
  2372. ;//
  2373. ;// Category: SE_CATEGID_POLICY_CHANGE
  2374. ;//
  2375. ;// Parameter Strings -
  2376. ;//
  2377. ;// 1 - User right name
  2378. ;//
  2379. ;// 2 - SID string of account for which the user
  2380. ;// right was affected
  2381. ;//
  2382. ;// 3 - User name of subject changing the right
  2383. ;//
  2384. ;// 4 - Domain name of subject changing the right
  2385. ;//
  2386. ;// 5 - Logon ID string of subject changing the right
  2387. ;//
  2388. ;//
  2389. MessageId=0x026e
  2390. SymbolicName=SE_AUDITID_SYSTEM_ACCESS_REMOVED
  2391. Language=English
  2392. System Security Access Removed:%n
  2393. %tAccess Removed:%t%4%n
  2394. %tAccount Modified:%t%5%n
  2395. %tRemoved By:%n
  2396. %t User Name:%t%1%n
  2397. %t Domain:%t%t%2%n
  2398. %t Logon ID:%t%3%n
  2399. .
  2400. ;//
  2401. ;//
  2402. ;// SE_AUDITID_NAMESPACE_COLLISION
  2403. ;//
  2404. ;// Category: SE_CATEGID_POLICY_CHANGE
  2405. ;//
  2406. ;// Event type: success
  2407. ;//
  2408. ;// Description:
  2409. ;// When a namespace element in one forest overlaps a namespace element in
  2410. ;// some other forest, it can lead to ambiguity in resolving a name
  2411. ;// belonging to one of the namespace elements. This overlap is also called
  2412. ;// a collision.This event is generated when such a collision is detected.
  2413. ;//
  2414. ;// Note:
  2415. ;// Not all fields are valid for each entry type.
  2416. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2417. ;// for an entry of type 'TopLevelName'.
  2418. ;//
  2419. MessageId=0x0300
  2420. SymbolicName=SE_AUDITID_NAMESPACE_COLLISION
  2421. Language=English
  2422. Namespace collision detected:%n
  2423. %tTarget type:%t%1%n
  2424. %tTarget name:%t%2%n
  2425. %tForest Root:%t%3%n
  2426. %tTop Level Name:%t%4%n
  2427. %tDNS Name:%t%5%n
  2428. %tNetBIOS Name:%t%6%n
  2429. %tSID:%t%t%7%n
  2430. %tNew Flags:%t%8%n
  2431. .
  2432. ;//
  2433. ;//
  2434. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD
  2435. ;//
  2436. ;// Category: SE_CATEGID_POLICY_CHANGE
  2437. ;//
  2438. ;// Event type: success
  2439. ;//
  2440. ;// Description:
  2441. ;// This event is generated when the forest trust information is updated and
  2442. ;// one or more entries get added. One such audit event is generated
  2443. ;// per added entry. If multiple entries get added, deleted or modified
  2444. ;// in a single update of the forest trust information, all the generated
  2445. ;// audit events will have a single unique identifier called OperationID.
  2446. ;// This allows one to determine that the multiple generated audits are
  2447. ;// the result of a single operation.
  2448. ;//
  2449. ;// Note:
  2450. ;// Not all fields are valid for each entry type.
  2451. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2452. ;// for an entry of type 'TopLevelName'.
  2453. ;//
  2454. MessageId=0x0301
  2455. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD
  2456. Language=English
  2457. Trusted Forest Information Entry Added:%n
  2458. %tForest Root:%t%1%n
  2459. %tForest Root SID:%t%2%n
  2460. %tOperation ID:%t{%3,%4}%n
  2461. %tEntry Type:%t%5%n
  2462. %tFlags:%t%t%6%n
  2463. %tTop Level Name:%t%7%n
  2464. %tDNS Name:%t%8%n
  2465. %tNetBIOS Name:%t%9%n
  2466. %tDomain SID:%t%10%n
  2467. %tAdded by%t:%n
  2468. %tClient User Name:%t%11%n
  2469. %tClient Domain:%t%12%n
  2470. %tClient Logon ID:%t%13%n
  2471. .
  2472. ;//
  2473. ;//
  2474. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM
  2475. ;//
  2476. ;// Category: SE_CATEGID_POLICY_CHANGE
  2477. ;//
  2478. ;// Event type: success
  2479. ;//
  2480. ;// Description:
  2481. ;// This event is generated when the forest trust information is updated and
  2482. ;// one or more entries get deleted. One such audit event is generated
  2483. ;// per deleted entry. If multiple entries get added, deleted or modified
  2484. ;// in a single update of the forest trust information, all the generated
  2485. ;// audit events will have a single unique identifier called OperationID.
  2486. ;// This allows one to determine that the multiple generated audits are
  2487. ;// the result of a single operation.
  2488. ;//
  2489. ;// Note:
  2490. ;// Not all fields are valid for each entry type.
  2491. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2492. ;// for an entry of type 'TopLevelName'.
  2493. ;//
  2494. MessageId=0x0302
  2495. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM
  2496. Language=English
  2497. Trusted Forest Information Entry Removed:%n
  2498. %tForest Root:%t%1%n
  2499. %tForest Root SID:%t%2%n
  2500. %tOperation ID:%t{%3,%4}%n
  2501. %tEntry Type:%t%5%n
  2502. %tFlags:%t%t%6%n
  2503. %tTop Level Name:%t%7%n
  2504. %tDNS Name:%t%8%n
  2505. %tNetBIOS Name:%t%9%n
  2506. %tDomain SID:%t%10%n
  2507. %tRemoved by%t:%n
  2508. %tClient User Name:%t%11%n
  2509. %tClient Domain:%t%12%n
  2510. %tClient Logon ID:%t%13%n
  2511. .
  2512. ;//
  2513. ;//
  2514. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD
  2515. ;//
  2516. ;// Category: SE_CATEGID_POLICY_CHANGE
  2517. ;//
  2518. ;// Event type: success
  2519. ;//
  2520. ;// Description:
  2521. ;// This event is generated when the forest trust information is updated and
  2522. ;// one or more entries get modified. One such audit event is generated
  2523. ;// per modified entry. If multiple entries get added, deleted or modified
  2524. ;// in a single update of the forest trust information, all the generated
  2525. ;// audit events will have a single unique identifier called OperationID.
  2526. ;// This allows one to determine that the multiple generated audits are
  2527. ;// the result of a single operation.
  2528. ;//
  2529. ;// Note:
  2530. ;// Not all fields are valid for each entry type.
  2531. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2532. ;// for an entry of type 'TopLevelName'.
  2533. ;//
  2534. MessageId=0x0303
  2535. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD
  2536. Language=English
  2537. Trusted Forest Information Entry Modified:%n
  2538. %tForest Root:%t%1%n
  2539. %tForest Root SID:%t%2%n
  2540. %tOperation ID:%t{%3,%4}%n
  2541. %tEntry Type:%t%5%n
  2542. %tFlags:%t%t%6%n
  2543. %tTop Level Name:%t%7%n
  2544. %tDNS Name:%t%8%n
  2545. %tNetBIOS Name:%t%9%n
  2546. %tDomain SID:%t%10%n
  2547. %tModified by%t:%n
  2548. %tClient User Name:%t%11%n
  2549. %tClient Domain:%t%12%n
  2550. %tClient Logon ID:%t%13%n
  2551. .
  2552. ;
  2553. ;/////////////////////////////////////////////////////////////////////////////
  2554. ;// //
  2555. ;// //
  2556. ;// Messages for Category: SE_CATEGID_ACCOUNT_MANAGEMENT //
  2557. ;// //
  2558. ;// Event IDs: //
  2559. ;// SE_AUDITID_USER_CREATED //
  2560. ;// SE_AUDITID_USER_CHANGE //
  2561. ;// SE_AUDITID_ACCOUNT_TYPE_CHANGE //
  2562. ;// SE_AUDITID_USER_ENABLED //
  2563. ;// SE_AUDITID_USER_PWD_CHANGED //
  2564. ;// SE_AUDITID_USER_PWD_SET //
  2565. ;// SE_AUDITID_USER_DISABLED //
  2566. ;// SE_AUDITID_USER_DELETED //
  2567. ;// //
  2568. ;// SE_AUDITID_COMPUTER_CREATED //
  2569. ;// SE_AUDITID_COMPUTER_CHANGE //
  2570. ;// SE_AUDITID_COMPUTER_DELETED //
  2571. ;// //
  2572. ;// SE_AUDITID_GLOBAL_GROUP_CREATED //
  2573. ;// SE_AUDITID_GLOBAL_GROUP_ADD //
  2574. ;// SE_AUDITID_GLOBAL_GROUP_REM //
  2575. ;// SE_AUDITID_GLOBAL_GROUP_DELETED //
  2576. ;// SE_AUDITID_LOCAL_GROUP_CREATED //
  2577. ;// SE_AUDITID_LOCAL_GROUP_ADD //
  2578. ;// SE_AUDITID_LOCAL_GROUP_REM //
  2579. ;// SE_AUDITID_LOCAL_GROUP_DELETED //
  2580. ;// //
  2581. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED //
  2582. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE //
  2583. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD //
  2584. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM //
  2585. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED //
  2586. ;// //
  2587. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED //
  2588. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE //
  2589. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD //
  2590. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM //
  2591. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED //
  2592. ;// //
  2593. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED //
  2594. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE //
  2595. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD //
  2596. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM //
  2597. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED //
  2598. ;// //
  2599. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED //
  2600. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE //
  2601. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD //
  2602. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM //
  2603. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED //
  2604. ;// //
  2605. ;// SE_AUDITID_GROUP_TYPE_CHANGE //
  2606. ;// //
  2607. ;// SE_AUDITID_ADD_SID_HISTORY //
  2608. ;// //
  2609. ;// SE_AUDITID_OTHER_ACCT_CHANGE //
  2610. ;// SE_AUDITID_DOMAIN_POLICY_CHANGE //
  2611. ;// SE_AUDITID_ACCOUNT_AUTO_LOCKED //
  2612. ;// SE_AUDITID_ACCOUNT_UNLOCKED //
  2613. ;// SE_AUDITID_SECURE_ADMIN_GROUP //
  2614. ;// //
  2615. ;// //
  2616. ;/////////////////////////////////////////////////////////////////////////////
  2617. ;//
  2618. ;//
  2619. ;// SE_AUDITID_USER_CREATED
  2620. ;//
  2621. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2622. ;//
  2623. ;// Parameter Strings -
  2624. ;//
  2625. ;// 1 - name of new user account
  2626. ;//
  2627. ;// 2 - domain of new user account
  2628. ;//
  2629. ;// 3 - SID string of new user account
  2630. ;//
  2631. ;// 4 - User name of subject creating the user account
  2632. ;//
  2633. ;// 5 - Domain name of subject creating the user account
  2634. ;//
  2635. ;// 6 - Logon ID string of subject creating the user account
  2636. ;//
  2637. ;// 7 - Privileges used to create the user account
  2638. ;//
  2639. ;//
  2640. MessageId=0x0270
  2641. SymbolicName=SE_AUDITID_USER_CREATED
  2642. Language=English
  2643. User Account Created:%n
  2644. %tNew Account Name:%t%1%n
  2645. %tNew Domain:%t%2%n
  2646. %tNew Account ID:%t%3%n
  2647. %tCaller User Name:%t%4%n
  2648. %tCaller Domain:%t%5%n
  2649. %tCaller Logon ID:%t%6%n
  2650. %tPrivileges%t%t%7%n
  2651. .
  2652. ;//
  2653. ;//
  2654. ;// SE_AUDITID_ACCOUNT_TYPE_CHANGE
  2655. ;//
  2656. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2657. ;//
  2658. ;// MessageId 0x271 unused
  2659. ;//
  2660. ;//
  2661. ;//
  2662. ;// SE_AUDITID_USER_ENABLED
  2663. ;//
  2664. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2665. ;//
  2666. ;// Parameter Strings -
  2667. ;//
  2668. ;// 1 - name of target user account
  2669. ;//
  2670. ;// 2 - domain of target user account
  2671. ;//
  2672. ;// 3 - SID string of target user account
  2673. ;//
  2674. ;// 4 - User name of subject changing the user account
  2675. ;//
  2676. ;// 5 - Domain name of subject changing the user account
  2677. ;//
  2678. ;// 6 - Logon ID string of subject changing the user account
  2679. ;//
  2680. ;//
  2681. MessageId=0x0272
  2682. SymbolicName=SE_AUDITID_USER_ENABLED
  2683. Language=English
  2684. User Account Enabled:%n
  2685. %tTarget Account Name:%t%1%n
  2686. %tTarget Domain:%t%2%n
  2687. %tTarget Account ID:%t%3%n
  2688. %tCaller User Name:%t%4%n
  2689. %tCaller Domain:%t%5%n
  2690. %tCaller Logon ID:%t%6%n
  2691. .
  2692. ;//
  2693. ;//
  2694. ;// SE_AUDITID_USER_PWD_CHANGED
  2695. ;//
  2696. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2697. ;//
  2698. ;// Parameter Strings -
  2699. ;//
  2700. ;// 1 - name of target user account
  2701. ;//
  2702. ;// 2 - domain of target user account
  2703. ;//
  2704. ;// 3 - SID string of target user account
  2705. ;//
  2706. ;// 4 - User name of subject changing the user account
  2707. ;//
  2708. ;// 5 - Domain name of subject changing the user account
  2709. ;//
  2710. ;// 6 - Logon ID string of subject changing the user account
  2711. ;//
  2712. ;//
  2713. MessageId=0x0273
  2714. SymbolicName=SE_AUDITID_USER_PWD_CHANGED
  2715. Language=English
  2716. Change Password Attempt:%n
  2717. %tTarget Account Name:%t%1%n
  2718. %tTarget Domain:%t%2%n
  2719. %tTarget Account ID:%t%3%n
  2720. %tCaller User Name:%t%4%n
  2721. %tCaller Domain:%t%5%n
  2722. %tCaller Logon ID:%t%6%n
  2723. %tPrivileges:%t%7%n
  2724. .
  2725. ;//
  2726. ;//
  2727. ;// SE_AUDITID_USER_PWD_SET
  2728. ;//
  2729. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2730. ;//
  2731. ;// Parameter Strings -
  2732. ;//
  2733. ;// 1 - name of target user account
  2734. ;//
  2735. ;// 2 - domain of target user account
  2736. ;//
  2737. ;// 3 - SID string of target user account
  2738. ;//
  2739. ;// 4 - User name of subject changing the user account
  2740. ;//
  2741. ;// 5 - Domain name of subject changing the user account
  2742. ;//
  2743. ;// 6 - Logon ID string of subject changing the user account
  2744. ;//
  2745. ;//
  2746. MessageId=0x0274
  2747. SymbolicName=SE_AUDITID_USER_PWD_SET
  2748. Language=English
  2749. User Account password set:%n
  2750. %tTarget Account Name:%t%1%n
  2751. %tTarget Domain:%t%2%n
  2752. %tTarget Account ID:%t%3%n
  2753. %tCaller User Name:%t%4%n
  2754. %tCaller Domain:%t%5%n
  2755. %tCaller Logon ID:%t%6%n
  2756. .
  2757. ;//
  2758. ;//
  2759. ;// SE_AUDITID_USER_DISABLED
  2760. ;//
  2761. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2762. ;//
  2763. ;// Parameter Strings -
  2764. ;//
  2765. ;// 1 - name of target user account
  2766. ;//
  2767. ;// 2 - domain of target user account
  2768. ;//
  2769. ;// 3 - SID string of target user account
  2770. ;//
  2771. ;// 4 - User name of subject changing the user account
  2772. ;//
  2773. ;// 5 - Domain name of subject changing the user account
  2774. ;//
  2775. ;// 6 - Logon ID string of subject changing the user account
  2776. ;//
  2777. ;//
  2778. MessageId=0x0275
  2779. SymbolicName=SE_AUDITID_USER_DISABLED
  2780. Language=English
  2781. User Account Disabled:%n
  2782. %tTarget Account Name:%t%1%n
  2783. %tTarget Domain:%t%2%n
  2784. %tTarget Account ID:%t%3%n
  2785. %tCaller User Name:%t%4%n
  2786. %tCaller Domain:%t%5%n
  2787. %tCaller Logon ID:%t%6%n
  2788. .
  2789. ;//
  2790. ;//
  2791. ;// SE_AUDITID_USER_DELETED
  2792. ;//
  2793. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2794. ;//
  2795. ;// Parameter Strings -
  2796. ;//
  2797. ;// 1 - name of target account
  2798. ;//
  2799. ;// 2 - domain of target account
  2800. ;//
  2801. ;// 3 - SID string of target account
  2802. ;//
  2803. ;// 4 - User name of subject changing the account
  2804. ;//
  2805. ;// 5 - Domain name of subject changing the account
  2806. ;//
  2807. ;// 6 - Logon ID string of subject changing the account
  2808. ;//
  2809. ;//
  2810. MessageId=0x0276
  2811. SymbolicName=SE_AUDITID_USER_DELETED
  2812. Language=English
  2813. User Account Deleted:%n
  2814. %tTarget Account Name:%t%1%n
  2815. %tTarget Domain:%t%2%n
  2816. %tTarget Account ID:%t%3%n
  2817. %tCaller User Name:%t%4%n
  2818. %tCaller Domain:%t%5%n
  2819. %tCaller Logon ID:%t%6%n
  2820. %tPrivileges:%t%7%n
  2821. .
  2822. ;//
  2823. ;//
  2824. ;// SE_AUDITID_GLOBAL_GROUP_CREATED
  2825. ;//
  2826. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2827. ;//
  2828. ;// Parameter Strings -
  2829. ;//
  2830. ;// 1 - name of new group account
  2831. ;//
  2832. ;// 2 - domain of new group account
  2833. ;//
  2834. ;// 3 - SID string of new group account
  2835. ;//
  2836. ;// 4 - User name of subject creating the account
  2837. ;//
  2838. ;// 5 - Domain name of subject creating the account
  2839. ;//
  2840. ;// 6 - Logon ID string of subject creating the account
  2841. ;//
  2842. ;//
  2843. MessageId=0x0277
  2844. SymbolicName=SE_AUDITID_GLOBAL_GROUP_CREATED
  2845. Language=English
  2846. Security Enabled Global Group Created:%n
  2847. %tNew Account Name:%t%1%n
  2848. %tNew Domain:%t%2%n
  2849. %tNew Account ID:%t%3%n
  2850. %tCaller User Name:%t%4%n
  2851. %tCaller Domain:%t%5%n
  2852. %tCaller Logon ID:%t%6%n
  2853. %tPrivileges:%t%7%n
  2854. .
  2855. ;//
  2856. ;//
  2857. ;// SE_AUDITID_GLOBAL_GROUP_ADD
  2858. ;//
  2859. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2860. ;//
  2861. ;// Parameter Strings -
  2862. ;//
  2863. ;// 1 - SID string of member being added
  2864. ;//
  2865. ;// 2 - name of target account
  2866. ;//
  2867. ;// 3 - domain of target account
  2868. ;//
  2869. ;// 4 - SID string of target account
  2870. ;//
  2871. ;// 5 - User name of subject changing the account
  2872. ;//
  2873. ;// 6 - Domain name of subject changing the account
  2874. ;//
  2875. ;// 7 - Logon ID string of subject changing the account
  2876. ;//
  2877. ;//
  2878. MessageId=0x0278
  2879. SymbolicName=SE_AUDITID_GLOBAL_GROUP_ADD
  2880. Language=English
  2881. Security Enabled Global Group Member Added:%n
  2882. %tMember Name:%t%1%n
  2883. %tMember ID:%t%2%n
  2884. %tTarget Account Name:%t%3%n
  2885. %tTarget Domain:%t%4%n
  2886. %tTarget Account ID:%t%5%n
  2887. %tCaller User Name:%t%6%n
  2888. %tCaller Domain:%t%7%n
  2889. %tCaller Logon ID:%t%8%n
  2890. %tPrivileges:%t%9%n
  2891. .
  2892. ;//
  2893. ;//
  2894. ;// SE_AUDITID_GLOBAL_GROUP_REM
  2895. ;//
  2896. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2897. ;//
  2898. ;// Parameter Strings -
  2899. ;//
  2900. ;// 1 - SID string of member being removed
  2901. ;//
  2902. ;// 2 - name of target account
  2903. ;//
  2904. ;// 3 - domain of target account
  2905. ;//
  2906. ;// 4 - SID string of target account
  2907. ;//
  2908. ;// 5 - User name of subject changing the account
  2909. ;//
  2910. ;// 6 - Domain name of subject changing the account
  2911. ;//
  2912. ;// 7 - Logon ID string of subject changing the account
  2913. ;//
  2914. ;//
  2915. MessageId=0x0279
  2916. SymbolicName=SE_AUDITID_GLOBAL_GROUP_REM
  2917. Language=English
  2918. Security Enabled Global Group Member Removed:%n
  2919. %tMember Name:%t%1%n
  2920. %tMember ID:%t%2%n
  2921. %tTarget Account Name:%t%3%n
  2922. %tTarget Domain:%t%4%n
  2923. %tTarget Account ID:%t%5%n
  2924. %tCaller User Name:%t%6%n
  2925. %tCaller Domain:%t%7%n
  2926. %tCaller Logon ID:%t%8%n
  2927. %tPrivileges:%t%9%n
  2928. .
  2929. ;//
  2930. ;//
  2931. ;// SE_AUDITID_GLOBAL_GROUP_DELETED
  2932. ;//
  2933. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2934. ;//
  2935. ;// Parameter Strings -
  2936. ;//
  2937. ;// 1 - name of target account
  2938. ;//
  2939. ;// 2 - domain of target account
  2940. ;//
  2941. ;// 3 - SID string of target account
  2942. ;//
  2943. ;// 4 - User name of subject changing the account
  2944. ;//
  2945. ;// 5 - Domain name of subject changing the account
  2946. ;//
  2947. ;// 6 - Logon ID string of subject changing the account
  2948. ;//
  2949. ;//
  2950. MessageId=0x027A
  2951. SymbolicName=SE_AUDITID_GLOBAL_GROUP_DELETED
  2952. Language=English
  2953. Security Enabled Global Group Deleted:%n
  2954. %tTarget Account Name:%t%1%n
  2955. %tTarget Domain:%t%2%n
  2956. %tTarget Account ID:%t%3%n
  2957. %tCaller User Name:%t%4%n
  2958. %tCaller Domain:%t%5%n
  2959. %tCaller Logon ID:%t%6%n
  2960. %tPrivileges:%t%7%n
  2961. .
  2962. ;//
  2963. ;//
  2964. ;// SE_AUDITID_LOCAL_GROUP_CREATED
  2965. ;//
  2966. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2967. ;//
  2968. ;// Parameter Strings -
  2969. ;//
  2970. ;// 1 - name of new group account
  2971. ;//
  2972. ;// 2 - domain of new group account
  2973. ;//
  2974. ;// 3 - SID string of new group account
  2975. ;//
  2976. ;// 4 - User name of subject creating the account
  2977. ;//
  2978. ;// 5 - Domain name of subject creating the account
  2979. ;//
  2980. ;// 6 - Logon ID string of subject creating the account
  2981. ;//
  2982. ;//
  2983. MessageId=0x027B
  2984. SymbolicName=SE_AUDITID_LOCAL_GROUP_CREATED
  2985. Language=English
  2986. Security Enabled Local Group Created:%n
  2987. %tNew Account Name:%t%1%n
  2988. %tNew Domain:%t%2%n
  2989. %tNew Account ID:%t%3%n
  2990. %tCaller User Name:%t%4%n
  2991. %tCaller Domain:%t%5%n
  2992. %tCaller Logon ID:%t%6%n
  2993. %tPrivileges:%t%7%n
  2994. .
  2995. ;//
  2996. ;//
  2997. ;// SE_AUDITID_LOCAL_GROUP_ADD
  2998. ;//
  2999. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3000. ;//
  3001. ;// Parameter Strings -
  3002. ;//
  3003. ;// 1 - SID string of member being added
  3004. ;//
  3005. ;// 2 - name of target account
  3006. ;//
  3007. ;// 3 - domain of target account
  3008. ;//
  3009. ;// 4 - SID string of target account
  3010. ;//
  3011. ;// 5 - User name of subject changing the account
  3012. ;//
  3013. ;// 6 - Domain name of subject changing the account
  3014. ;//
  3015. ;// 7 - Logon ID string of subject changing the account
  3016. ;//
  3017. ;//
  3018. MessageId=0x027C
  3019. SymbolicName=SE_AUDITID_LOCAL_GROUP_ADD
  3020. Language=English
  3021. Security Enabled Local Group Member Added:%n
  3022. %tMember Name:%t%1%n
  3023. %tMember ID:%t%2%n
  3024. %tTarget Account Name:%t%3%n
  3025. %tTarget Domain:%t%4%n
  3026. %tTarget Account ID:%t%5%n
  3027. %tCaller User Name:%t%6%n
  3028. %tCaller Domain:%t%7%n
  3029. %tCaller Logon ID:%t%8%n
  3030. %tPrivileges:%t%9%n
  3031. .
  3032. ;//
  3033. ;//
  3034. ;// SE_AUDITID_LOCAL_GROUP_REM
  3035. ;//
  3036. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3037. ;//
  3038. ;// Parameter Strings -
  3039. ;//
  3040. ;// 1 - SID string of member being removed
  3041. ;//
  3042. ;// 2 - name of target account
  3043. ;//
  3044. ;// 3 - domain of target account
  3045. ;//
  3046. ;// 4 - SID string of target account
  3047. ;//
  3048. ;// 5 - User name of subject changing the account
  3049. ;//
  3050. ;// 6 - Domain name of subject changing the account
  3051. ;//
  3052. ;// 7 - Logon ID string of subject changing the account
  3053. ;//
  3054. ;//
  3055. MessageId=0x027D
  3056. SymbolicName=SE_AUDITID_LOCAL_GROUP_REM
  3057. Language=English
  3058. Security Enabled Local Group Member Removed:%n
  3059. %tMember Name:%t%1%n
  3060. %tMember ID:%t%2%n
  3061. %tTarget Account Name:%t%3%n
  3062. %tTarget Domain:%t%4%n
  3063. %tTarget Account ID:%t%5%n
  3064. %tCaller User Name:%t%6%n
  3065. %tCaller Domain:%t%7%n
  3066. %tCaller Logon ID:%t%8%n
  3067. %tPrivileges:%t%9%n
  3068. .
  3069. ;//
  3070. ;//
  3071. ;// SE_AUDITID_LOCAL_GROUP_DELETED
  3072. ;//
  3073. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3074. ;//
  3075. ;// Parameter Strings -
  3076. ;//
  3077. ;// 1 - name of target account
  3078. ;//
  3079. ;// 2 - domain of target account
  3080. ;//
  3081. ;// 3 - SID string of target account
  3082. ;//
  3083. ;// 4 - User name of subject changing the account
  3084. ;//
  3085. ;// 5 - Domain name of subject changing the account
  3086. ;//
  3087. ;// 6 - Logon ID string of subject changing the account
  3088. ;//
  3089. ;//
  3090. MessageId=0x027E
  3091. SymbolicName=SE_AUDITID_LOCAL_GROUP_DELETED
  3092. Language=English
  3093. Security Enabled Local Group Deleted:%n
  3094. %tTarget Account Name:%t%1%n
  3095. %tTarget Domain:%t%2%n
  3096. %tTarget Account ID:%t%3%n
  3097. %tCaller User Name:%t%4%n
  3098. %tCaller Domain:%t%5%n
  3099. %tCaller Logon ID:%t%6%n
  3100. %tPrivileges:%t%7%n
  3101. .
  3102. ;//
  3103. ;//
  3104. ;// SE_AUDITID_LOCAL_GROUP_CHANGE
  3105. ;//
  3106. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3107. ;//
  3108. ;// Parameter Strings -
  3109. ;//
  3110. ;// 1 - name of target account
  3111. ;//
  3112. ;// 2 - domain of target account
  3113. ;//
  3114. ;// 3 - SID string of target account
  3115. ;//
  3116. ;// 4 - User name of subject changing the account
  3117. ;//
  3118. ;// 5 - Domain name of subject changing the account
  3119. ;//
  3120. ;// 6 - Logon ID string of subject changing the account
  3121. ;//
  3122. ;//
  3123. MessageId=0x027F
  3124. SymbolicName=SE_AUDITID_LOCAL_GROUP_CHANGE
  3125. Language=English
  3126. Security Enabled Local Group Changed:%n
  3127. %tTarget Account Name:%t%1%n
  3128. %tTarget Domain:%t%2%n
  3129. %tTarget Account ID:%t%3%n
  3130. %tCaller User Name:%t%4%n
  3131. %tCaller Domain:%t%5%n
  3132. %tCaller Logon ID:%t%6%n
  3133. %tPrivileges:%t%7%n
  3134. .
  3135. ;//
  3136. ;//
  3137. ;// SE_AUDITID_OTHER_ACCOUNT_CHANGE
  3138. ;//
  3139. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3140. ;//
  3141. ;// Parameter Strings -
  3142. ;//
  3143. ;// 1 - Type of change (sigh, this isn't localizable)
  3144. ;//
  3145. ;// 2 - Type of changed object
  3146. ;//
  3147. ;// 3 - SID string (of changed object)
  3148. ;//
  3149. ;// 4 - User name of subject changing the account
  3150. ;//
  3151. ;// 5 - Domain name of subject changing the account
  3152. ;//
  3153. ;// 6 - Logon ID string of subject changing the account
  3154. ;//
  3155. ;//
  3156. MessageId=0x0280
  3157. SymbolicName=SE_AUDITID_OTHER_ACCOUNT_CHANGE
  3158. Language=English
  3159. General Account Database Change:%n
  3160. %tType of change:%t%1%n
  3161. %tObject Type:%t%2%n
  3162. %tObject Name:%t%3%n
  3163. %tObject ID:%t%4%n
  3164. %tCaller User Name:%t%5%n
  3165. %tCaller Domain:%t%6%n
  3166. %tCaller Logon ID:%t%7%n
  3167. .
  3168. ;//
  3169. ;//
  3170. ;// SE_AUDITID_GLOBAL_GROUP_CHANGE
  3171. ;//
  3172. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3173. ;//
  3174. ;// Parameter Strings -
  3175. ;//
  3176. ;// 1 - name of target account
  3177. ;//
  3178. ;// 2 - domain of target account
  3179. ;//
  3180. ;// 3 - SID string of target account
  3181. ;//
  3182. ;// 4 - User name of subject changing the account
  3183. ;//
  3184. ;// 5 - Domain name of subject changing the account
  3185. ;//
  3186. ;// 6 - Logon ID string of subject changing the account
  3187. ;//
  3188. ;//
  3189. MessageId=0x0281
  3190. SymbolicName=SE_AUDITID_GLOBAL_GROUP_CHANGE
  3191. Language=English
  3192. Security Enabled Global Group Changed:%n
  3193. %tTarget Account Name:%t%1%n
  3194. %tTarget Domain:%t%2%n
  3195. %tTarget Account ID:%t%3%n
  3196. %tCaller User Name:%t%4%n
  3197. %tCaller Domain:%t%5%n
  3198. %tCaller Logon ID:%t%6%n
  3199. %tPrivileges:%t%7%n
  3200. .
  3201. ;//
  3202. ;//
  3203. ;// SE_AUDITID_USER_CHANGE
  3204. ;//
  3205. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3206. ;//
  3207. ;// Parameter Strings -
  3208. ;//
  3209. ;// 1 - name of target user account
  3210. ;//
  3211. ;// 2 - domain of target user account
  3212. ;//
  3213. ;// 3 - SID string of target user account
  3214. ;//
  3215. ;// 4 - User name of subject changing the user account
  3216. ;//
  3217. ;// 5 - Domain name of subject changing the user account
  3218. ;//
  3219. ;// 6 - Logon ID string of subject changing the user account
  3220. ;//
  3221. ;//
  3222. MessageId=0x0282
  3223. SymbolicName=SE_AUDITID_USER_CHANGE
  3224. Language=English
  3225. User Account Changed:%n
  3226. %t%1%n
  3227. %tTarget Account Name:%t%2%n
  3228. %tTarget Domain:%t%3%n
  3229. %tTarget Account ID:%t%4%n
  3230. %tCaller User Name:%t%5%n
  3231. %tCaller Domain:%t%6%n
  3232. %tCaller Logon ID:%t%7%n
  3233. %tPrivileges:%t%8%n
  3234. .
  3235. ;//
  3236. ;//
  3237. ;// SE_AUDITID_DOMAIN_POLICY_CHANGE
  3238. ;//
  3239. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3240. ;//
  3241. ;// Parameter Strings -
  3242. ;//
  3243. ;// 1 - (unused)
  3244. ;//
  3245. ;// 2 - domain of target user account
  3246. ;//
  3247. ;// 3 - SID string of target user account
  3248. ;//
  3249. ;// 4 - User name of subject changing the user account
  3250. ;//
  3251. ;// 5 - Domain name of subject changing the user account
  3252. ;//
  3253. ;// 6 - Logon ID string of subject changing the user account
  3254. ;//
  3255. ;//
  3256. MessageId=0x0283
  3257. SymbolicName=SE_AUDITID_DOMAIN_POLICY_CHANGE
  3258. Language=English
  3259. Domain Policy Changed: %1 modified%n
  3260. %tDomain Name:%t%t%2%n
  3261. %tDomain ID:%t%3%n
  3262. %tCaller User Name:%t%4%n
  3263. %tCaller Domain:%t%5%n
  3264. %tCaller Logon ID:%t%6%n
  3265. %tPrivileges:%t%7%n
  3266. .
  3267. ;//
  3268. ;//
  3269. ;// SE_AUDITID_ACCOUNT_AUTO_LOCKED
  3270. ;//
  3271. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3272. ;//
  3273. ;// Type: success / failure
  3274. ;//
  3275. ;// Description: This event is generated when an account is auto locked. This happens
  3276. ;// when a user attempts to log in unsuccessfully multiple times. The exact
  3277. ;// number of times is specified by the administrator.
  3278. ;//
  3279. ;// Parameter Strings -
  3280. ;//
  3281. ;// 1 - name of target user account
  3282. ;//
  3283. ;// 2 - domain of target user account
  3284. ;//
  3285. ;// 3 - SID string of target user account
  3286. ;//
  3287. ;// 4 - User name of subject changing the user account
  3288. ;//
  3289. ;// 5 - Domain name of subject changing the user account
  3290. ;//
  3291. ;// 6 - Logon ID string of subject changing the user account
  3292. ;//
  3293. ;//
  3294. MessageId=0x0284
  3295. SymbolicName=SE_AUDITID_ACCOUNT_AUTO_LOCKED
  3296. Language=English
  3297. User Account Locked Out:%n
  3298. %tTarget Account Name:%t%1%n
  3299. %tTarget Account ID:%t%3%n
  3300. %tCaller Machine Name:%t%2%n
  3301. %tCaller User Name:%t%4%n
  3302. %tCaller Domain:%t%5%n
  3303. %tCaller Logon ID:%t%6%n
  3304. .
  3305. ;//
  3306. ;//
  3307. ;// SE_AUDITID_COMPUTER_CREATED
  3308. ;//
  3309. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3310. ;//
  3311. ;// Parameter Strings -
  3312. ;//
  3313. ;// 1 - name of new computer account
  3314. ;//
  3315. ;// 2 - domain of new computer account
  3316. ;//
  3317. ;// 3 - SID string of new computer account
  3318. ;//
  3319. ;// 4 - User name of subject creating the computer account
  3320. ;//
  3321. ;// 5 - Domain name of subject creating the computer account
  3322. ;//
  3323. ;// 6 - Logon ID string of subject creating the computer account
  3324. ;//
  3325. ;// 7 - Privileges used to create the computer account
  3326. ;//
  3327. ;//
  3328. MessageId=0x0285
  3329. SymbolicName=SE_AUDITID_COMPUTER_CREATED
  3330. Language=English
  3331. Computer Account Created:%n
  3332. %tNew Account Name:%t%1%n
  3333. %tNew Domain:%t%2%n
  3334. %tNew Account ID:%t%3%n
  3335. %tCaller User Name:%t%4%n
  3336. %tCaller Domain:%t%5%n
  3337. %tCaller Logon ID:%t%6%n
  3338. %tPrivileges%t%t%7%n
  3339. .
  3340. ;//
  3341. ;//
  3342. ;// SE_AUDITID_COMPUTER_CHANGE
  3343. ;//
  3344. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3345. ;//
  3346. ;// Parameter Strings -
  3347. ;//
  3348. ;// 1 - name of target computer account
  3349. ;//
  3350. ;// 2 - domain of target computer account
  3351. ;//
  3352. ;// 3 - SID string of target computer account
  3353. ;//
  3354. ;// 4 - User name of subject changing the computer account
  3355. ;//
  3356. ;// 5 - Domain name of subject changing the computer account
  3357. ;//
  3358. ;// 6 - Logon ID string of subject changing the computer account
  3359. ;//
  3360. ;//
  3361. MessageId=0x0286
  3362. SymbolicName=SE_AUDITID_COMPUTER_CHANGE
  3363. Language=English
  3364. Computer Account Changed:%n
  3365. %t%1%n
  3366. %tTarget Account Name:%t%2%n
  3367. %tTarget Domain:%t%3%n
  3368. %tTarget Account ID:%t%4%n
  3369. %tCaller User Name:%t%5%n
  3370. %tCaller Domain:%t%6%n
  3371. %tCaller Logon ID:%t%7%n
  3372. %tPrivileges:%t%8%n
  3373. .
  3374. ;//
  3375. ;//
  3376. ;// SE_AUDITID_COMPUTER_DELETED
  3377. ;//
  3378. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3379. ;//
  3380. ;// Parameter Strings -
  3381. ;//
  3382. ;// 1 - name of target account
  3383. ;//
  3384. ;// 2 - domain of target account
  3385. ;//
  3386. ;// 3 - SID string of target account
  3387. ;//
  3388. ;// 4 - User name of subject changing the account
  3389. ;//
  3390. ;// 5 - Domain name of subject changing the account
  3391. ;//
  3392. ;// 6 - Logon ID string of subject changing the account
  3393. ;//
  3394. ;//
  3395. MessageId=0x0287
  3396. SymbolicName=SE_AUDITID_COMPUTER_DELETED
  3397. Language=English
  3398. Computer Account Deleted:%n
  3399. %tTarget Account Name:%t%1%n
  3400. %tTarget Domain:%t%2%n
  3401. %tTarget Account ID:%t%3%n
  3402. %tCaller User Name:%t%4%n
  3403. %tCaller Domain:%t%5%n
  3404. %tCaller Logon ID:%t%6%n
  3405. %tPrivileges:%t%7%n
  3406. .
  3407. ;//
  3408. ;//
  3409. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED
  3410. ;//
  3411. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3412. ;//
  3413. ;// Parameter Strings -
  3414. ;//
  3415. ;// 1 - name of target account
  3416. ;//
  3417. ;// 2 - domain of target account
  3418. ;//
  3419. ;// 3 - SID string of target account
  3420. ;//
  3421. ;// 4 - User name of subject changing the account
  3422. ;//
  3423. ;// 5 - Domain name of subject changing the account
  3424. ;//
  3425. ;// 6 - Logon ID string of subject changing the account
  3426. ;//
  3427. ;//
  3428. MessageId=0x0288
  3429. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED
  3430. Language=English
  3431. Security Disabled Local Group Created:%n
  3432. %tTarget Account Name:%t%1%n
  3433. %tTarget Domain:%t%2%n
  3434. %tTarget Account ID:%t%3%n
  3435. %tCaller User Name:%t%4%n
  3436. %tCaller Domain:%t%5%n
  3437. %tCaller Logon ID:%t%6%n
  3438. %tPrivileges:%t%7%n
  3439. .
  3440. ;//
  3441. ;//
  3442. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE
  3443. ;//
  3444. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3445. ;//
  3446. ;// Parameter Strings -
  3447. ;//
  3448. ;// 1 - name of target account
  3449. ;//
  3450. ;// 2 - domain of target account
  3451. ;//
  3452. ;// 3 - SID string of target account
  3453. ;//
  3454. ;// 4 - User name of subject changing the account
  3455. ;//
  3456. ;// 5 - Domain name of subject changing the account
  3457. ;//
  3458. ;// 6 - Logon ID string of subject changing the account
  3459. ;//
  3460. ;//
  3461. MessageId=0x0289
  3462. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE
  3463. Language=English
  3464. Security Disabled Local Group Changed:%n
  3465. %tTarget Account Name:%t%1%n
  3466. %tTarget Domain:%t%2%n
  3467. %tTarget Account ID:%t%3%n
  3468. %tCaller User Name:%t%4%n
  3469. %tCaller Domain:%t%5%n
  3470. %tCaller Logon ID:%t%6%n
  3471. %tPrivileges:%t%7%n
  3472. .
  3473. ;//
  3474. ;//
  3475. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD
  3476. ;//
  3477. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3478. ;//
  3479. ;// Parameter Strings -
  3480. ;//
  3481. ;// 1 - SID string of member being added
  3482. ;//
  3483. ;// 2 - name of target account
  3484. ;//
  3485. ;// 3 - domain of target account
  3486. ;//
  3487. ;// 4 - SID string of target account
  3488. ;//
  3489. ;// 5 - User name of subject changing the account
  3490. ;//
  3491. ;// 6 - Domain name of subject changing the account
  3492. ;//
  3493. ;// 7 - Logon ID string of subject changing the account
  3494. ;//
  3495. ;//
  3496. MessageId=0x028A
  3497. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD
  3498. Language=English
  3499. Security Disabled Local Group Member Added:%n
  3500. %tMember Name:%t%1%n
  3501. %tMember ID:%t%2%n
  3502. %tTarget Account Name:%t%3%n
  3503. %tTarget Domain:%t%4%n
  3504. %tTarget Account ID:%t%5%n
  3505. %tCaller User Name:%t%6%n
  3506. %tCaller Domain:%t%7%n
  3507. %tCaller Logon ID:%t%8%n
  3508. %tPrivileges:%t%9%n
  3509. .
  3510. ;//
  3511. ;//
  3512. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM
  3513. ;//
  3514. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3515. ;//
  3516. ;// Parameter Strings -
  3517. ;//
  3518. ;// 1 - SID string of member being removed
  3519. ;//
  3520. ;// 2 - name of target account
  3521. ;//
  3522. ;// 3 - domain of target account
  3523. ;//
  3524. ;// 4 - SID string of target account
  3525. ;//
  3526. ;// 5 - User name of subject changing the account
  3527. ;//
  3528. ;// 6 - Domain name of subject changing the account
  3529. ;//
  3530. ;// 7 - Logon ID string of subject changing the account
  3531. ;//
  3532. ;//
  3533. MessageId=0x028B
  3534. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM
  3535. Language=English
  3536. Security Disabled Local Group Member Removed:%n
  3537. %tMember Name:%t%1%n
  3538. %tMember ID:%t%2%n
  3539. %tTarget Account Name:%t%3%n
  3540. %tTarget Domain:%t%4%n
  3541. %tTarget Account ID:%t%5%n
  3542. %tCaller User Name:%t%6%n
  3543. %tCaller Domain:%t%7%n
  3544. %tCaller Logon ID:%t%8%n
  3545. %tPrivileges:%t%9%n
  3546. .
  3547. ;//
  3548. ;//
  3549. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED
  3550. ;//
  3551. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3552. ;//
  3553. ;// Parameter Strings -
  3554. ;//
  3555. ;// 1 - name of target account
  3556. ;//
  3557. ;// 2 - domain of target account
  3558. ;//
  3559. ;// 3 - SID string of target account
  3560. ;//
  3561. ;// 4 - User name of subject changing the account
  3562. ;//
  3563. ;// 5 - Domain name of subject changing the account
  3564. ;//
  3565. ;// 6 - Logon ID string of subject changing the account
  3566. ;//
  3567. ;//
  3568. MessageId=0x028C
  3569. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED
  3570. Language=English
  3571. Security Disabled Local Group Deleted:%n
  3572. %tTarget Account Name:%t%1%n
  3573. %tTarget Domain:%t%2%n
  3574. %tTarget Account ID:%t%3%n
  3575. %tCaller User Name:%t%4%n
  3576. %tCaller Domain:%t%5%n
  3577. %tCaller Logon ID:%t%6%n
  3578. %tPrivileges:%t%7%n
  3579. .
  3580. ;//
  3581. ;//
  3582. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED
  3583. ;//
  3584. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3585. ;//
  3586. ;// Parameter Strings -
  3587. ;//
  3588. ;// 1 - name of new group account
  3589. ;//
  3590. ;// 2 - domain of new group account
  3591. ;//
  3592. ;// 3 - SID string of new group account
  3593. ;//
  3594. ;// 4 - User name of subject creating the account
  3595. ;//
  3596. ;// 5 - Domain name of subject creating the account
  3597. ;//
  3598. ;// 6 - Logon ID string of subject creating the account
  3599. ;//
  3600. ;//
  3601. MessageId=0x028D
  3602. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED
  3603. Language=English
  3604. Security Disabled Global Group Created:%n
  3605. %tNew Account Name:%t%1%n
  3606. %tNew Domain:%t%2%n
  3607. %tNew Account ID:%t%3%n
  3608. %tCaller User Name:%t%4%n
  3609. %tCaller Domain:%t%5%n
  3610. %tCaller Logon ID:%t%6%n
  3611. %tPrivileges:%t%7%n
  3612. .
  3613. ;//
  3614. ;//
  3615. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE
  3616. ;//
  3617. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3618. ;//
  3619. ;// Parameter Strings -
  3620. ;//
  3621. ;// 1 - name of target account
  3622. ;//
  3623. ;// 2 - domain of target account
  3624. ;//
  3625. ;// 3 - SID string of target account
  3626. ;//
  3627. ;// 4 - User name of subject changing the account
  3628. ;//
  3629. ;// 5 - Domain name of subject changing the account
  3630. ;//
  3631. ;// 6 - Logon ID string of subject changing the account
  3632. ;//
  3633. ;//
  3634. MessageId=0x028E
  3635. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE
  3636. Language=English
  3637. Security Disabled Global Group Changed:%n
  3638. %tTarget Account Name:%t%1%n
  3639. %tTarget Domain:%t%2%n
  3640. %tTarget Account ID:%t%3%n
  3641. %tCaller User Name:%t%4%n
  3642. %tCaller Domain:%t%5%n
  3643. %tCaller Logon ID:%t%6%n
  3644. %tPrivileges:%t%7%n
  3645. .
  3646. ;//
  3647. ;//
  3648. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD
  3649. ;//
  3650. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3651. ;//
  3652. ;// Parameter Strings -
  3653. ;//
  3654. ;// 1 - SID string of member being added
  3655. ;//
  3656. ;// 2 - name of target account
  3657. ;//
  3658. ;// 3 - domain of target account
  3659. ;//
  3660. ;// 4 - SID string of target account
  3661. ;//
  3662. ;// 5 - User name of subject changing the account
  3663. ;//
  3664. ;// 6 - Domain name of subject changing the account
  3665. ;//
  3666. ;// 7 - Logon ID string of subject changing the account
  3667. ;//
  3668. ;//
  3669. MessageId=0x028F
  3670. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD
  3671. Language=English
  3672. Security Disabled Global Group Member Added:%n
  3673. %tMember Name:%t%1%n
  3674. %tMember ID:%t%2%n
  3675. %tTarget Account Name:%t%3%n
  3676. %tTarget Domain:%t%4%n
  3677. %tTarget Account ID:%t%5%n
  3678. %tCaller User Name:%t%6%n
  3679. %tCaller Domain:%t%7%n
  3680. %tCaller Logon ID:%t%8%n
  3681. %tPrivileges:%t%9%n
  3682. .
  3683. ;//
  3684. ;//
  3685. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM
  3686. ;//
  3687. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3688. ;//
  3689. ;// Parameter Strings -
  3690. ;//
  3691. ;// 1 - SID string of member being removed
  3692. ;//
  3693. ;// 2 - name of target account
  3694. ;//
  3695. ;// 3 - domain of target account
  3696. ;//
  3697. ;// 4 - SID string of target account
  3698. ;//
  3699. ;// 5 - User name of subject changing the account
  3700. ;//
  3701. ;// 6 - Domain name of subject changing the account
  3702. ;//
  3703. ;// 7 - Logon ID string of subject changing the account
  3704. ;//
  3705. ;//
  3706. MessageId=0x0290
  3707. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM
  3708. Language=English
  3709. Security Disabled Global Group Member Removed:%n
  3710. %tMember Name:%t%1%n
  3711. %tMember ID:%t%2%n
  3712. %tTarget Account Name:%t%3%n
  3713. %tTarget Domain:%t%4%n
  3714. %tTarget Account ID:%t%5%n
  3715. %tCaller User Name:%t%6%n
  3716. %tCaller Domain:%t%7%n
  3717. %tCaller Logon ID:%t%8%n
  3718. %tPrivileges:%t%9%n
  3719. .
  3720. ;//
  3721. ;//
  3722. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED
  3723. ;//
  3724. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3725. ;//
  3726. ;// Parameter Strings -
  3727. ;//
  3728. ;// 1 - name of target account
  3729. ;//
  3730. ;// 2 - domain of target account
  3731. ;//
  3732. ;// 3 - SID string of target account
  3733. ;//
  3734. ;// 4 - User name of subject changing the account
  3735. ;//
  3736. ;// 5 - Domain name of subject changing the account
  3737. ;//
  3738. ;// 6 - Logon ID string of subject changing the account
  3739. ;//
  3740. ;//
  3741. MessageId=0x0291
  3742. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED
  3743. Language=English
  3744. Security Disabled Global Group Deleted:%n
  3745. %tTarget Account Name:%t%1%n
  3746. %tTarget Domain:%t%2%n
  3747. %tTarget Account ID:%t%3%n
  3748. %tCaller User Name:%t%4%n
  3749. %tCaller Domain:%t%5%n
  3750. %tCaller Logon ID:%t%6%n
  3751. %tPrivileges:%t%7%n
  3752. .
  3753. ;//
  3754. ;//
  3755. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED
  3756. ;//
  3757. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3758. ;//
  3759. ;// Parameter Strings -
  3760. ;//
  3761. ;// 1 - name of new group account
  3762. ;//
  3763. ;// 2 - domain of new group account
  3764. ;//
  3765. ;// 3 - SID string of new group account
  3766. ;//
  3767. ;// 4 - User name of subject creating the account
  3768. ;//
  3769. ;// 5 - Domain name of subject creating the account
  3770. ;//
  3771. ;// 6 - Logon ID string of subject creating the account
  3772. ;//
  3773. ;//
  3774. MessageId=0x0292
  3775. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED
  3776. Language=English
  3777. Security Enabled Universal Group Created:%n
  3778. %tNew Account Name:%t%1%n
  3779. %tNew Domain:%t%2%n
  3780. %tNew Account ID:%t%3%n
  3781. %tCaller User Name:%t%4%n
  3782. %tCaller Domain:%t%5%n
  3783. %tCaller Logon ID:%t%6%n
  3784. %tPrivileges:%t%7%n
  3785. .
  3786. ;//
  3787. ;//
  3788. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE
  3789. ;//
  3790. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3791. ;//
  3792. ;// Parameter Strings -
  3793. ;//
  3794. ;// 1 - name of target account
  3795. ;//
  3796. ;// 2 - domain of target account
  3797. ;//
  3798. ;// 3 - SID string of target account
  3799. ;//
  3800. ;// 4 - User name of subject changing the account
  3801. ;//
  3802. ;// 5 - Domain name of subject changing the account
  3803. ;//
  3804. ;// 6 - Logon ID string of subject changing the account
  3805. ;//
  3806. ;//
  3807. MessageId=0x0293
  3808. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE
  3809. Language=English
  3810. Security Enabled Universal Group Changed:%n
  3811. %tTarget Account Name:%t%1%n
  3812. %tTarget Domain:%t%2%n
  3813. %tTarget Account ID:%t%3%n
  3814. %tCaller User Name:%t%4%n
  3815. %tCaller Domain:%t%5%n
  3816. %tCaller Logon ID:%t%6%n
  3817. %tPrivileges:%t%7%n
  3818. .
  3819. ;//
  3820. ;//
  3821. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD
  3822. ;//
  3823. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3824. ;//
  3825. ;// Parameter Strings -
  3826. ;//
  3827. ;// 1 - SID string of member being added
  3828. ;//
  3829. ;// 2 - name of target account
  3830. ;//
  3831. ;// 3 - domain of target account
  3832. ;//
  3833. ;// 4 - SID string of target account
  3834. ;//
  3835. ;// 5 - User name of subject changing the account
  3836. ;//
  3837. ;// 6 - Domain name of subject changing the account
  3838. ;//
  3839. ;// 7 - Logon ID string of subject changing the account
  3840. ;//
  3841. ;//
  3842. MessageId=0x0294
  3843. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD
  3844. Language=English
  3845. Security Enabled Universal Group Member Added:%n
  3846. %tMember Name:%t%1%n
  3847. %tMember ID:%t%2%n
  3848. %tTarget Account Name:%t%3%n
  3849. %tTarget Domain:%t%4%n
  3850. %tTarget Account ID:%t%5%n
  3851. %tCaller User Name:%t%6%n
  3852. %tCaller Domain:%t%7%n
  3853. %tCaller Logon ID:%t%8%n
  3854. %tPrivileges:%t%9%n
  3855. .
  3856. ;//
  3857. ;//
  3858. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM
  3859. ;//
  3860. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3861. ;//
  3862. ;// Parameter Strings -
  3863. ;//
  3864. ;// 1 - SID string of member being removed
  3865. ;//
  3866. ;// 2 - name of target account
  3867. ;//
  3868. ;// 3 - domain of target account
  3869. ;//
  3870. ;// 4 - SID string of target account
  3871. ;//
  3872. ;// 5 - User name of subject changing the account
  3873. ;//
  3874. ;// 6 - Domain name of subject changing the account
  3875. ;//
  3876. ;// 7 - Logon ID string of subject changing the account
  3877. ;//
  3878. ;//
  3879. MessageId=0x0295
  3880. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM
  3881. Language=English
  3882. Security Enabled Universal Group Member Removed:%n
  3883. %tMember Name:%t%1%n
  3884. %tMember ID:%t%2%n
  3885. %tTarget Account Name:%t%3%n
  3886. %tTarget Domain:%t%4%n
  3887. %tTarget Account ID:%t%5%n
  3888. %tCaller User Name:%t%6%n
  3889. %tCaller Domain:%t%7%n
  3890. %tCaller Logon ID:%t%8%n
  3891. %tPrivileges:%t%9%n
  3892. .
  3893. ;//
  3894. ;//
  3895. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED
  3896. ;//
  3897. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3898. ;//
  3899. ;// Parameter Strings -
  3900. ;//
  3901. ;// 1 - name of target account
  3902. ;//
  3903. ;// 2 - domain of target account
  3904. ;//
  3905. ;// 3 - SID string of target account
  3906. ;//
  3907. ;// 4 - User name of subject changing the account
  3908. ;//
  3909. ;// 5 - Domain name of subject changing the account
  3910. ;//
  3911. ;// 6 - Logon ID string of subject changing the account
  3912. ;//
  3913. ;//
  3914. MessageId=0x0296
  3915. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED
  3916. Language=English
  3917. Security Enabled Universal Group Deleted:%n
  3918. %tTarget Account Name:%t%1%n
  3919. %tTarget Domain:%t%2%n
  3920. %tTarget Account ID:%t%3%n
  3921. %tCaller User Name:%t%4%n
  3922. %tCaller Domain:%t%5%n
  3923. %tCaller Logon ID:%t%6%n
  3924. %tPrivileges:%t%7%n
  3925. .
  3926. ;//
  3927. ;//
  3928. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED
  3929. ;//
  3930. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3931. ;//
  3932. ;// Parameter Strings -
  3933. ;//
  3934. ;// 1 - name of new group account
  3935. ;//
  3936. ;// 2 - domain of new group account
  3937. ;//
  3938. ;// 3 - SID string of new group account
  3939. ;//
  3940. ;// 4 - User name of subject creating the account
  3941. ;//
  3942. ;// 5 - Domain name of subject creating the account
  3943. ;//
  3944. ;// 6 - Logon ID string of subject creating the account
  3945. ;//
  3946. ;//
  3947. MessageId=0x0297
  3948. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED
  3949. Language=English
  3950. Security Disabled Universal Group Created:%n
  3951. %tNew Account Name:%t%1%n
  3952. %tNew Domain:%t%2%n
  3953. %tNew Account ID:%t%3%n
  3954. %tCaller User Name:%t%4%n
  3955. %tCaller Domain:%t%5%n
  3956. %tCaller Logon ID:%t%6%n
  3957. %tPrivileges:%t%7%n
  3958. .
  3959. ;//
  3960. ;//
  3961. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE
  3962. ;//
  3963. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3964. ;//
  3965. ;// Parameter Strings -
  3966. ;//
  3967. ;// 1 - name of target account
  3968. ;//
  3969. ;// 2 - domain of target account
  3970. ;//
  3971. ;// 3 - SID string of target account
  3972. ;//
  3973. ;// 4 - User name of subject changing the account
  3974. ;//
  3975. ;// 5 - Domain name of subject changing the account
  3976. ;//
  3977. ;// 6 - Logon ID string of subject changing the account
  3978. ;//
  3979. ;//
  3980. MessageId=0x0298
  3981. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE
  3982. Language=English
  3983. Security Disabled Universal Group Changed:%n
  3984. %tTarget Account Name:%t%1%n
  3985. %tTarget Domain:%t%2%n
  3986. %tTarget Account ID:%t%3%n
  3987. %tCaller User Name:%t%4%n
  3988. %tCaller Domain:%t%5%n
  3989. %tCaller Logon ID:%t%6%n
  3990. %tPrivileges:%t%7%n
  3991. .
  3992. ;//
  3993. ;//
  3994. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD
  3995. ;//
  3996. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3997. ;//
  3998. ;// Parameter Strings -
  3999. ;//
  4000. ;// 1 - SID string of member being added
  4001. ;//
  4002. ;// 2 - name of target account
  4003. ;//
  4004. ;// 3 - domain of target account
  4005. ;//
  4006. ;// 4 - SID string of target account
  4007. ;//
  4008. ;// 5 - User name of subject changing the account
  4009. ;//
  4010. ;// 6 - Domain name of subject changing the account
  4011. ;//
  4012. ;// 7 - Logon ID string of subject changing the account
  4013. ;//
  4014. ;//
  4015. MessageId=0x0299
  4016. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD
  4017. Language=English
  4018. Security Disabled Universal Group Member Added:%n
  4019. %tMember Name:%t%1%n
  4020. %tMember ID:%t%2%n
  4021. %tTarget Account Name:%t%3%n
  4022. %tTarget Domain:%t%4%n
  4023. %tTarget Account ID:%t%5%n
  4024. %tCaller User Name:%t%6%n
  4025. %tCaller Domain:%t%7%n
  4026. %tCaller Logon ID:%t%8%n
  4027. %tPrivileges:%t%9%n
  4028. .
  4029. ;//
  4030. ;//
  4031. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM
  4032. ;//
  4033. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4034. ;//
  4035. ;// Parameter Strings -
  4036. ;//
  4037. ;// 1 - SID string of member being removed
  4038. ;//
  4039. ;// 2 - name of target account
  4040. ;//
  4041. ;// 3 - domain of target account
  4042. ;//
  4043. ;// 4 - SID string of target account
  4044. ;//
  4045. ;// 5 - User name of subject changing the account
  4046. ;//
  4047. ;// 6 - Domain name of subject changing the account
  4048. ;//
  4049. ;// 7 - Logon ID string of subject changing the account
  4050. ;//
  4051. ;//
  4052. MessageId=0x029A
  4053. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM
  4054. Language=English
  4055. Security Disabled Universal Group Member Removed:%n
  4056. %tMember Name:%t%1%n
  4057. %tMember ID:%t%2%n
  4058. %tTarget Account Name:%t%3%n
  4059. %tTarget Domain:%t%4%n
  4060. %tTarget Account ID:%t%5%n
  4061. %tCaller User Name:%t%6%n
  4062. %tCaller Domain:%t%7%n
  4063. %tCaller Logon ID:%t%8%n
  4064. %tPrivileges:%t%9%n
  4065. .
  4066. ;//
  4067. ;//
  4068. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED
  4069. ;//
  4070. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4071. ;//
  4072. ;// Parameter Strings -
  4073. ;//
  4074. ;// 1 - name of target account
  4075. ;//
  4076. ;// 2 - domain of target account
  4077. ;//
  4078. ;// 3 - SID string of target account
  4079. ;//
  4080. ;// 4 - User name of subject changing the account
  4081. ;//
  4082. ;// 5 - Domain name of subject changing the account
  4083. ;//
  4084. ;// 6 - Logon ID string of subject changing the account
  4085. ;//
  4086. ;//
  4087. MessageId=0x029B
  4088. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED
  4089. Language=English
  4090. Security Disabled Universal Group Deleted:%n
  4091. %tTarget Account Name:%t%1%n
  4092. %tTarget Domain:%t%2%n
  4093. %tTarget Account ID:%t%3%n
  4094. %tCaller User Name:%t%4%n
  4095. %tCaller Domain:%t%5%n
  4096. %tCaller Logon ID:%t%6%n
  4097. %tPrivileges:%t%7%n
  4098. .
  4099. ;//
  4100. ;//
  4101. ;// SE_AUDITID_GROUP_TYPE_CHANGE
  4102. ;//
  4103. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4104. ;//
  4105. ;// Parameter Strings -
  4106. ;//
  4107. ;// 1 - nature of group type change
  4108. ;//
  4109. ;// 2 - name of target account
  4110. ;//
  4111. ;// 3 - domain of target account
  4112. ;//
  4113. ;// 4 - SID string of target account
  4114. ;//
  4115. ;// 5 - User name of subject changing the account
  4116. ;//
  4117. ;// 6 - Domain name of subject changing the account
  4118. ;//
  4119. ;// 7 - Logon ID string of subject changing the account
  4120. ;//
  4121. ;//
  4122. MessageId=0x029C
  4123. SymbolicName=SE_AUDITID_GROUP_TYPE_CHANGE
  4124. Language=English
  4125. Group Type Changed:%n
  4126. %t%1%n
  4127. %tTarget Account Name:%t%2%n
  4128. %tTarget Domain:%t%3%n
  4129. %tTarget Account ID:%t%4%n
  4130. %tCaller User Name:%t%5%n
  4131. %tCaller Domain:%t%6%n
  4132. %tCaller Logon ID:%t%7%n
  4133. %tPrivileges:%t%8%n
  4134. .
  4135. ;//
  4136. ;//
  4137. ;// SE_AUDITID_ADD_SID_HISTORY
  4138. ;//
  4139. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4140. ;//
  4141. ;// Parameter Strings -
  4142. ;//
  4143. ;// 1 - SID string of the source account
  4144. ;//
  4145. ;// 2 - Name of the source account (including domain name)
  4146. ;//
  4147. ;// 3 - Name of the target account
  4148. ;//
  4149. ;// 4 - Domain name of subject changing the SID history
  4150. ;//
  4151. ;// 5 - SID String of the target account
  4152. ;//
  4153. ;// 6 - Logon ID string of subject changing the user account
  4154. ;//
  4155. ;//
  4156. MessageId=0x029D
  4157. SymbolicName=SE_AUDITID_ADD_SID_HISTORY
  4158. Language=English
  4159. Add SID History:%n
  4160. %tSource Account Name:%t%1%n
  4161. %tSource Account ID:%t%2%n
  4162. %tTarget Account Name:%t%3%n
  4163. %tTarget Domain:%t%4%n
  4164. %tTarget Account ID:%t%5%n
  4165. %tCaller User Name:%t%6%n
  4166. %tCaller Domain:%t%7%n
  4167. %tCaller Logon ID:%t%8%n
  4168. %tPrivileges:%t%9%n
  4169. .
  4170. ;//
  4171. ;//
  4172. ;// SE_AUDITID_ADD_SID_HISTORY_FAILURE
  4173. ;//
  4174. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4175. ;//
  4176. ;// Note:
  4177. ;// This event is obsolete. It is not generated by Whistler.
  4178. ;// It is retained in this file so that anybody viewing w2k events
  4179. ;// from a whistler machine can view them correctly.
  4180. ;//
  4181. ;//
  4182. ;//
  4183. MessageId=0x029E
  4184. SymbolicName=SE_AUDITID_ADD_SID_HISTORY_FAILURE
  4185. Language=English
  4186. Add SID History:%n
  4187. %tSource Account Name:%t%1%n
  4188. %tTarget Account Name:%t%2%n
  4189. %tTarget Domain:%t%3%n
  4190. %tTarget Account ID:%t%4%n
  4191. %tCaller User Name:%t%5%n
  4192. %tCaller Domain:%t%6%n
  4193. %tCaller Logon ID:%t%7%n
  4194. %tPrivileges:%t%8%n
  4195. .
  4196. ;//
  4197. ;//
  4198. ;// SE_AUDITID_ACCOUNT_UNLOCKED
  4199. ;//
  4200. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4201. ;//
  4202. ;// Parameter Strings -
  4203. ;//
  4204. ;// 1 - name of target user account
  4205. ;//
  4206. ;// 2 - domain of target user account
  4207. ;//
  4208. ;// 3 - SID string of target user account
  4209. ;//
  4210. ;// 4 - User name of subject changing the user account
  4211. ;//
  4212. ;// 5 - Domain name of subject changing the user account
  4213. ;//
  4214. ;// 6 - Logon ID string of subject changing the user account
  4215. ;//
  4216. ;//
  4217. MessageId=0x029F
  4218. SymbolicName=SE_AUDITID_ACCOUNT_UNLOCKED
  4219. Language=English
  4220. User Account Unlocked:%n
  4221. %tTarget Account Name:%t%1%n
  4222. %tTarget Domain:%t%t%2%n
  4223. %tTarget Account ID:%t%3%n
  4224. %tCaller User Name:%t%4%n
  4225. %tCaller Domain:%t%5%n
  4226. %tCaller Logon ID:%t%6%n
  4227. .
  4228. ;//
  4229. ;//
  4230. ;// SE_AUDITID_SECURE_ADMIN_GROUP
  4231. ;//
  4232. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4233. ;//
  4234. ;// Parameter Strings -
  4235. ;//
  4236. ;// 1 - (unused)
  4237. ;//
  4238. ;// 2 - domain of target user account
  4239. ;//
  4240. ;// 3 - SID string of target user account
  4241. ;//
  4242. ;// 4 - User name of subject changing the user account
  4243. ;//
  4244. ;// 5 - Domain name of subject changing the user account
  4245. ;//
  4246. ;// 6 - Logon ID string of subject changing the user account
  4247. ;//
  4248. ;//
  4249. ;//
  4250. MessageId=0x02AC
  4251. SymbolicName=SE_AUDITID_SECURE_ADMIN_GROUP
  4252. Language=English
  4253. Set ACLs of members in administrators groups:%n
  4254. %tTarget Account Name:%t%1%n
  4255. %tTarget Domain:%t%t%2%n
  4256. %tTarget Account ID:%t%3%n
  4257. %tCaller User Name:%t%4%n
  4258. %tCaller Domain:%t%5%n
  4259. %tCaller Logon ID:%t%6%n
  4260. %tPrivileges:%t%7%n
  4261. .
  4262. ;//
  4263. ;//
  4264. ;// SE_AUDITID_ACCOUNT_NAME_CHANGE
  4265. ;//
  4266. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4267. ;//
  4268. ;// Parameter Strings -
  4269. ;//
  4270. ;// 1 - name of target account
  4271. ;//
  4272. ;// 2 - domain of target account
  4273. ;//
  4274. ;// 3 - SID string of target account
  4275. ;//
  4276. ;// 4 - Account name of subject changing the account
  4277. ;//
  4278. ;// 5 - Domain name of subject changing the account
  4279. ;//
  4280. ;// 6 - Logon ID string of subject changing the account
  4281. ;//
  4282. ;//
  4283. ;//
  4284. MessageId=0x02AD
  4285. SymbolicName=SE_AUDITID_ACCOUNT_NAME_CHANGE
  4286. Language=English
  4287. Account Name Changed:%n
  4288. %tOld Account Name:%t%1%n
  4289. %tNew Account Name:%t%2%n
  4290. %tTarget Domain:%t%t%3%n
  4291. %tTarget Account ID:%t%4%n
  4292. %tCaller User Name:%t%5%n
  4293. %tCaller Domain:%t%6%n
  4294. %tCaller Logon ID:%t%7%n
  4295. %tPrivileges:%t%8%n
  4296. .
  4297. ;//
  4298. ;//
  4299. ;// SE_AUDITID_PASSWORD_HASH_ACCESS
  4300. ;//
  4301. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4302. ;//
  4303. ;// Event Type : success/failure
  4304. ;//
  4305. ;// Description:
  4306. ;// This event is generated when user password hashes are retrieved
  4307. ;// by the ADMT password filter DLL. This typically happens during
  4308. ;// ADMT password migration.
  4309. ;//
  4310. ;// Notes:
  4311. ;// To migrate passwords, a DLL (name?) gets loaded in lsass.exe as
  4312. ;// a password filter. This filter registers an RPC interface used by ADMT
  4313. ;// to request password migration. One SE_AUDITID_PASSWORD_HASH_ACCESS event
  4314. ;// is generated per password fetched.
  4315. ;//
  4316. ;//
  4317. MessageId=0x02AE
  4318. SymbolicName=SE_AUDITID_PASSWORD_HASH_ACCESS
  4319. Language=English
  4320. Password of the following user accessed:%n
  4321. %tTarget User Name:%t%1%n
  4322. %tTarget User Domain:%t%t%2%n
  4323. By user:%n
  4324. %tCaller User Name:%t%3%n
  4325. %tCaller Domain:%t%t%4%n
  4326. %tCaller Logon ID:%t%t%5%n
  4327. .
  4328. ;
  4329. ;/////////////////////////////////////////////////////////////////////////////
  4330. ;// //
  4331. ;// //
  4332. ;// Messages for Category: SE_CATEGID_ACCOUNT_LOGON //
  4333. ;// //
  4334. ;// Event IDs: //
  4335. ;// SE_AUDITID_AS_TICKET //
  4336. ;// SE_AUDITID_TGS_TICKET_REQUEST //
  4337. ;// SE_AUDITID_TICKET_RENEW_SUCCESS //
  4338. ;// SE_AUDITID_PREAUTH_FAILURE //
  4339. ;// SE_AUDITID_TGS_TICKET_FAILURE //
  4340. ;// SE_AUDITID_ACCOUNT_MAPPED //
  4341. ;// SE_AUDITID_ACCOUNT_LOGON //
  4342. ;// //
  4343. ;/////////////////////////////////////////////////////////////////////////////
  4344. ;//
  4345. ;//
  4346. ;// SE_AUDITID_AS_TICKET
  4347. ;//
  4348. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4349. ;//
  4350. ;// Parameter Strings -
  4351. ;//
  4352. ;// 1 - User name of client
  4353. ;//
  4354. ;// 2 - Supplied realm name
  4355. ;//
  4356. ;// 3 - SID of client user
  4357. ;//
  4358. ;// 4 - User name of service
  4359. ;//
  4360. ;// 5 - SID of service
  4361. ;//
  4362. ;// 6 - Ticket Options
  4363. ;//
  4364. ;// 7 - Failure code
  4365. ;//
  4366. ;// 8 - Ticket Encryption Type
  4367. ;//
  4368. ;// 9 - Preauthentication type (i.e. PK_INIT)
  4369. ;//
  4370. ;// 10 - Client IP address
  4371. ;//
  4372. MessageId=0x02a0
  4373. SymbolicName=SE_AUDITID_AS_TICKET
  4374. Language=English
  4375. Authentication Ticket Request:%n
  4376. %tUser Name:%t%t%1%n
  4377. %tSupplied Realm Name:%t%2%n
  4378. %tUser ID:%t%3%n
  4379. %tService Name:%t%t%4%n
  4380. %tService ID:%t%t%5%n
  4381. %tTicket Options:%t%t%6%n
  4382. %tResult Code:%t%t%7%n
  4383. %tTicket Encryption Type:%t%8%n
  4384. %tPre-Authentication Type:%t%9%n
  4385. %tClient Address:%t%t%10%n
  4386. .
  4387. ;//
  4388. ;//
  4389. ;// SE_AUDITID_AS_TICKET_FAILURE
  4390. ;//
  4391. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4392. ;//
  4393. ;// Note:
  4394. ;// This event is obsolete. It is not generated by Whistler.
  4395. ;// It is retained in this file so that anybody viewing w2k events
  4396. ;// from a whistler machine can view them correctly.
  4397. ;//
  4398. ;//
  4399. MessageId=0x02a4
  4400. SymbolicName=SE_AUDITID_AS_TICKET_FAILURE
  4401. Language=English
  4402. Authentication Ticket Request Failed:%n
  4403. %tUser Name:%t%1%n
  4404. %tSupplied Realm Name:%t%2%n
  4405. %tService Name:%t%3%n
  4406. %tTicket Options:%t%4%n
  4407. %tFailure Code:%t%5%n
  4408. %tClient Address:%t%6%n
  4409. .
  4410. ;//
  4411. ;//
  4412. ;// SE_AUDITID_TGS_TICKET_REQUEST
  4413. ;//
  4414. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4415. ;//
  4416. ;// Parameter Strings -
  4417. ;//
  4418. ;// 1 - User name of client
  4419. ;//
  4420. ;// 2 - Domain name of client
  4421. ;//
  4422. ;// 3 - User name of service
  4423. ;//
  4424. ;// 4 - SID of service
  4425. ;//
  4426. ;// 5 - Ticket Options
  4427. ;//
  4428. ;// 6 - Ticket Encryption Type
  4429. ;//
  4430. ;// 7 - Client IP address
  4431. ;//
  4432. ;// 8 - Failure code (0 for success)
  4433. ;//
  4434. ;// 9 - logon GUID
  4435. ;//
  4436. MessageId=0x02a1
  4437. SymbolicName=SE_AUDITID_TGS_TICKET_REQUEST
  4438. Language=English
  4439. Service Ticket Request:%n
  4440. %tUser Name:%t%t%1%n
  4441. %tUser Domain:%t%t%2%n
  4442. %tService Name:%t%t%3%n
  4443. %tService ID:%t%t%4%n
  4444. %tTicket Options:%t%t%5%n
  4445. %tTicket Encryption Type:%t%6%n
  4446. %tClient Address:%t%t%7%n
  4447. %tFailure Code:%t%t%8%n
  4448. %tLogon GUID:%t%9
  4449. .
  4450. ;//
  4451. ;//
  4452. ;// SE_AUDITID_TICKET_RENEW_SUCCESS
  4453. ;//
  4454. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4455. ;//
  4456. ;// Parameter Strings -
  4457. ;//
  4458. ;// 1 - User name of client
  4459. ;//
  4460. ;// 2 - Domain name of client
  4461. ;//
  4462. ;// 3 - User name of service
  4463. ;//
  4464. ;// 4 - SID of service
  4465. ;//
  4466. ;// 5 - Ticket Options
  4467. ;//
  4468. ;// 6 - Ticket Encryption Type
  4469. ;//
  4470. ;// 7 - Client IP address
  4471. ;//
  4472. MessageId=0x02a2
  4473. SymbolicName=SE_AUDITID_TICKET_RENEW_SUCCESS
  4474. Language=English
  4475. Ticket Granted Renewed:%n
  4476. %tUser Name:%t%1%n
  4477. %tUser Domain:%t%2%n
  4478. %tService Name:%t%3%n
  4479. %tService ID:%t%4%n
  4480. %tTicket Options:%t%5%n
  4481. %tTicket Encryption Type:%t%6%n
  4482. %tClient Address:%t%7%n
  4483. .
  4484. ;//
  4485. ;//
  4486. ;// SE_AUDITID_PREAUTH_FAILURE
  4487. ;//
  4488. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4489. ;//
  4490. ;// Parameter Strings -
  4491. ;//
  4492. ;// 1 - User name of client
  4493. ;//
  4494. ;// 2 - SID of client user
  4495. ;//
  4496. ;// 3 - User name of service
  4497. ;//
  4498. ;// 4 - Preauth Type
  4499. ;//
  4500. ;// 5 - Failure code
  4501. ;//
  4502. ;// 6 - Client IP address
  4503. ;//
  4504. ;// Event type: failure
  4505. ;// Description: This event is generated on a KDC when
  4506. ;// preauthentication fails (user types in wrong password).
  4507. ;//
  4508. MessageId=0x02a3
  4509. SymbolicName=SE_AUDITID_PREAUTH_FAILURE
  4510. Language=English
  4511. Pre-authentication failed:%n
  4512. %tUser Name:%t%t%1%n
  4513. %tUser ID:%t%t%2%n
  4514. %tService Name:%t%t%3%n
  4515. %tPre-Authentication Type:%t%4%n
  4516. %tFailure Code:%t%t%5%n
  4517. %tClient Address:%t%t%6%n
  4518. .
  4519. ;//
  4520. ;//
  4521. ;// SE_AUDITID_TGS_TICKET_FAILURE
  4522. ;//
  4523. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4524. ;//
  4525. ;// Note:
  4526. ;// This event is obsolete. It is not generated by Whistler.
  4527. ;// It is retained in this file so that anybody viewing w2k events
  4528. ;// from a whistler machine can view them correctly.
  4529. ;//
  4530. MessageId=0x02a5
  4531. SymbolicName=SE_AUDITID_TGS_TICKET_FAILURE
  4532. Language=English
  4533. Service Ticket Request Failed:%n
  4534. %tUser Name:%t%1%n
  4535. %tUser Domain:%t%2%n
  4536. %tService Name:%t%3%n
  4537. %tTicket Options:%t%4%n
  4538. %tFailure Code:%t%5%n
  4539. %tClient Address:%t%6%n
  4540. .
  4541. ;//
  4542. ;//
  4543. ;// SE_AUDITID_ACCOUNT_MAPPED
  4544. ;//
  4545. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4546. ;//
  4547. ;// Type: success / failure
  4548. ;//
  4549. ;// Description: An account mapping is a map of a user authenticated in an MIT realm to a
  4550. ;// domain account. A mapping acts much like a logon. Hence, it is important to audit this.
  4551. ;//
  4552. ;// Parameter Strings -
  4553. ;//
  4554. ;// 1 - Source
  4555. ;//
  4556. ;// 2 - Client Name
  4557. ;//
  4558. ;// 3 - Mapped Name
  4559. ;//
  4560. ;//
  4561. ;//
  4562. MessageId=0x02a6
  4563. SymbolicName=SE_AUDITID_ACCOUNT_MAPPED
  4564. Language=English
  4565. Account Mapped for Logon.%n
  4566. Mapping Attempted By:%n
  4567. %t%1%n
  4568. Client Name:%n
  4569. %t%2%n
  4570. %tMapped Name:%n
  4571. %t%3%n
  4572. .
  4573. ;//
  4574. ;//
  4575. ;// SE_AUDITID_ACCOUNT_NOT_MAPPED
  4576. ;//
  4577. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4578. ;//
  4579. ;// Note:
  4580. ;// This event is obsolete. It is not generated by Whistler.
  4581. ;// It is retained in this file so that anybody viewing w2k events
  4582. ;// from a whistler machine can view them correctly.
  4583. ;// Parameter Strings -
  4584. ;//
  4585. MessageId=0x02a7
  4586. SymbolicName=SE_AUDITID_ACCOUNT_NOT_MAPPED
  4587. Language=English
  4588. The name:%n
  4589. %t%2%n
  4590. could not be mapped for logon by:
  4591. %t%1%n
  4592. .
  4593. ;//
  4594. ;//
  4595. ;// SE_AUDITID_ACCOUNT_LOGON
  4596. ;//
  4597. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4598. ;//
  4599. ;// Type: Success / Failure
  4600. ;//
  4601. ;// Description: This audits a logon attempt. The audit appears on the DC.
  4602. ;// This is generated by calling LogonUser.
  4603. ;//
  4604. ;//
  4605. MessageId=0x02a8
  4606. SymbolicName=SE_AUDITID_ACCOUNT_LOGON
  4607. Language=English
  4608. Logon attempt by: %1%n
  4609. Logon account: %2%n
  4610. Source Workstation: %3%n
  4611. Error Code: %4%n
  4612. .
  4613. ;//
  4614. ;//
  4615. ;// SE_AUDITID_ACCOUNT_LOGON_FAILURE
  4616. ;//
  4617. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4618. ;//
  4619. ;// Note:
  4620. ;// This event is obsolete. It is not generated by Whistler.
  4621. ;// It is retained in this file so that anybody viewing w2k events
  4622. ;// from a whistler machine can view them correctly.
  4623. ;//
  4624. ;//
  4625. MessageId=0x02a9
  4626. SymbolicName=SE_AUDITID_ACCOUNT_LOGON_FAILURE
  4627. Language=English
  4628. The logon to account: %2%n
  4629. by: %1%n
  4630. from workstation: %3%n
  4631. failed. The error code was: %4%n
  4632. .
  4633. ;//
  4634. ;//
  4635. ;// SE_AUDITID_SESSION_RECONNECTED
  4636. ;//
  4637. ;// Category: SE_CATEGID_LOGON
  4638. ;//
  4639. ;// Parameter Strings -
  4640. ;//
  4641. ;// 1 - User account name
  4642. ;//
  4643. ;// 2 - Authenticating domain name
  4644. ;//
  4645. ;// 3 - Logon ID string
  4646. ;//
  4647. ;// 4 - Session Name
  4648. ;//
  4649. ;// 5 - Client Name
  4650. ;//
  4651. ;// 6 - Client Address
  4652. ;//
  4653. ;//
  4654. MessageId=0x02aa
  4655. SymbolicName=SE_AUDITID_SESSION_RECONNECTED
  4656. Language=English
  4657. Session reconnected to winstation:%n
  4658. %tUser Name:%t%1%n
  4659. %tDomain:%t%t%2%n
  4660. %tLogon ID:%t%t%3%n
  4661. %tSession Name:%t%4%n
  4662. %tClient Name:%t%5%n
  4663. %tClient Address:%t%6
  4664. .
  4665. ;//
  4666. ;//
  4667. ;// SE_AUDITID_SESSION_DISCONNECTED
  4668. ;//
  4669. ;// Category: SE_CATEGID_LOGON
  4670. ;//
  4671. ;// Parameter Strings -
  4672. ;//
  4673. ;// 1 - User account name
  4674. ;//
  4675. ;// 2 - Authenticating domain name
  4676. ;//
  4677. ;// 3 - Logon ID string
  4678. ;//
  4679. ;// 4 - Session Name
  4680. ;//
  4681. ;// 5 - Client Name
  4682. ;//
  4683. ;// 6 - Client Address
  4684. ;//
  4685. ;//
  4686. MessageId=0x02ab
  4687. SymbolicName=SE_AUDITID_SESSION_DISCONNECTED
  4688. Language=English
  4689. Session disconnected from winstation:%n
  4690. %tUser Name:%t%1%n
  4691. %tDomain:%t%t%2%n
  4692. %tLogon ID:%t%t%3%n
  4693. %tSession Name:%t%4%n
  4694. %tClient Name:%t%5%n
  4695. %tClient Address:%t%6
  4696. .
  4697. ;/////////////////////////////////////////////////////////////////////////////
  4698. ;// //
  4699. ;// //
  4700. ;// Messages for Category: SE_CATEGID_OBJECT_ACCESS - CertSrv //
  4701. ;// //
  4702. ;// Event IDs: //
  4703. ;// SE_AUDITID_CERTSRV_DENYREQUEST //
  4704. ;// SE_AUDITID_CERTSRV_RESUBMITREQUEST //
  4705. ;// SE_AUDITID_CERTSRV_REVOKECERT //
  4706. ;// SE_AUDITID_CERTSRV_PUBLISHCRL //
  4707. ;// SE_AUDITID_CERTSRV_AUTOPUBLISHCRL //
  4708. ;// SE_AUDITID_CERTSRV_SETEXTENSION //
  4709. ;// SE_AUDITID_CERTSRV_SETATTRIBUTES //
  4710. ;// SE_AUDITID_CERTSRV_SHUTDOWN //
  4711. ;// SE_AUDITID_CERTSRV_BACKUPSTART //
  4712. ;// SE_AUDITID_CERTSRV_BACKUPEND //
  4713. ;// SE_AUDITID_CERTSRV_RESTORESTART //
  4714. ;// SE_AUDITID_CERTSRV_RESTOREEND //
  4715. ;// SE_AUDITID_CERTSRV_SERVICESTART //
  4716. ;// SE_AUDITID_CERTSRV_SERVICESTOP //
  4717. ;// SE_AUDITID_CERTSRV_SETSECURITY //
  4718. ;// SE_AUDITID_CERTSRV_GETARCHIVEDKEY //
  4719. ;// SE_AUDITID_CERTSRV_IMPORTCERT //
  4720. ;// SE_AUDITID_CERTSRV_SETAUDITFILTER //
  4721. ;// SE_AUDITID_CERTSRV_NEWREQUEST //
  4722. ;// SE_AUDITID_CERTSRV_REQUESTAPPROVED //
  4723. ;// SE_AUDITID_CERTSRV_REQUESTDENIED //
  4724. ;// SE_AUDITID_CERTSRV_REQUESTPENDING //
  4725. ;// SE_AUDITID_CERTSRV_SETOFFICERRIGHTS //
  4726. ;// SE_AUDITID_CERTSRV_SETCONFIGENTRY //
  4727. ;// SE_AUDITID_CERTSRV_SETCAPROPERTY //
  4728. ;// SE_AUDITID_CERTSRV_KEYARCHIVED //
  4729. ;// SE_AUDITID_CERTSRV_IMPORTKEY //
  4730. ;// SE_AUDITID_CERTSRV_PUBLISHCERT //
  4731. ;// //
  4732. ;// //
  4733. ;/////////////////////////////////////////////////////////////////////////////
  4734. ;//
  4735. ;//
  4736. ;// SE_AUDITID_CERTSRV_DENYREQUEST
  4737. ;//
  4738. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4739. ;//
  4740. ;// Parameter Strings -
  4741. ;//
  4742. ;// 1 - Request ID
  4743. ;//
  4744. ;//
  4745. MessageId=0x0304
  4746. SymbolicName=SE_AUDITID_CERTSRV_DENYREQUEST
  4747. Language=English
  4748. The certificate manager denied a pending certificate request.%n
  4749. %n
  4750. Request ID:%t%1
  4751. .
  4752. ;//
  4753. ;//
  4754. ;// SE_AUDITID_CERTSRV_RESUBMITREQUEST
  4755. ;//
  4756. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4757. ;//
  4758. ;// Parameter Strings -
  4759. ;//
  4760. ;// 1 - Request ID
  4761. ;//
  4762. ;//
  4763. MessageId=0x0305
  4764. SymbolicName=SE_AUDITID_CERTSRV_RESUBMITREQUEST
  4765. Language=English
  4766. Certificate Services received a resubmitted certificate request.%n
  4767. %n
  4768. Request ID:%t%1
  4769. .
  4770. ;//
  4771. ;//
  4772. ;// SE_AUDITID_CERTSRV_REVOKECERT
  4773. ;//
  4774. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4775. ;//
  4776. ;// Parameter Strings -
  4777. ;//
  4778. ;// 1 - Serial No.
  4779. ;//
  4780. ;// 2 - Reason
  4781. ;//
  4782. ;//
  4783. MessageId=0x0306
  4784. SymbolicName=SE_AUDITID_CERTSRV_REVOKECERT
  4785. Language=English
  4786. Certificate Services revoked a certificate.%n
  4787. %n
  4788. Serial No:%t%1%n
  4789. Reason:%t%2
  4790. .
  4791. ;//
  4792. ;//
  4793. ;// SE_AUDITID_CERTSRV_PUBLISHCRL
  4794. ;//
  4795. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4796. ;//
  4797. ;// Parameter Strings -
  4798. ;//
  4799. ;// 1 - Next Update
  4800. ;//
  4801. ;// 2 - Publish Base
  4802. ;//
  4803. ;// 3 - Publish Delta
  4804. ;//
  4805. ;//
  4806. MessageId=0x0307
  4807. SymbolicName=SE_AUDITID_CERTSRV_PUBLISHCRL
  4808. Language=English
  4809. Certificate Services received a request to publish the certificate revocation list (CRL).%n
  4810. %n
  4811. Next Update:%t%1%n
  4812. Publish Base:%t%2%n
  4813. Publish Delta:%t%3
  4814. .
  4815. ;//
  4816. ;//
  4817. ;// SE_AUDITID_CERTSRV_AUTOPUBLISHCRL
  4818. ;//
  4819. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4820. ;//
  4821. ;// Parameter Strings -
  4822. ;//
  4823. ;// 1 - Base CRL
  4824. ;//
  4825. ;// 2 - CRL No.
  4826. ;//
  4827. ;// 3 - Key Container
  4828. ;//
  4829. ;// 4 - Next Publish
  4830. ;//
  4831. ;// 5 - Publish URLs
  4832. ;//
  4833. ;//
  4834. MessageId=0x0308
  4835. SymbolicName=SE_AUDITID_CERTSRV_AUTOPUBLISHCRL
  4836. Language=English
  4837. Certificate Services published the certificate revocation list (CRL).%n
  4838. %n
  4839. Base CRL:%t%1%n
  4840. CRL No:%t%t%2%n
  4841. Key Container%t%3%n
  4842. Next Publish%t%4%n
  4843. Publish URLs:%t%5
  4844. .
  4845. ;//
  4846. ;//
  4847. ;// SE_AUDITID_CERTSRV_SETEXTENSION
  4848. ;//
  4849. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4850. ;//
  4851. ;// Parameter Strings -
  4852. ;//
  4853. ;// 1 - Request ID
  4854. ;//
  4855. ;// 2 - Extension Name
  4856. ;//
  4857. ;// 3 - Extension Type
  4858. ;//
  4859. ;// 4 - Flags
  4860. ;//
  4861. ;// 5 - Extension Data
  4862. ;//
  4863. ;//
  4864. MessageId=0x0309
  4865. SymbolicName=SE_AUDITID_CERTSRV_SETEXTENSION
  4866. Language=English
  4867. A certificate request extension changed.%n
  4868. %n
  4869. Request ID:%t%1%n
  4870. Name:%t%2%n
  4871. Type:%t%3%n
  4872. Flags:%t%4%n
  4873. Data:%t%5
  4874. .
  4875. ;//
  4876. ;//
  4877. ;// SE_AUDITID_CERTSRV_SETATTRIBUTES
  4878. ;//
  4879. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4880. ;//
  4881. ;// Parameter Strings -
  4882. ;//
  4883. ;// 1 - Request ID
  4884. ;//
  4885. ;// 2 - Attributes
  4886. ;//
  4887. ;//
  4888. MessageId=0x030a
  4889. SymbolicName=SE_AUDITID_CERTSRV_SETATTRIBUTES
  4890. Language=English
  4891. One or more certificate request attributes changed.%n
  4892. %n
  4893. Request ID:%t%1%n
  4894. Attributes:%t%2
  4895. .
  4896. ;//
  4897. ;//
  4898. ;// SE_AUDITID_CERTSRV_SHUTDOWN
  4899. ;//
  4900. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4901. ;//
  4902. ;// Parameter Strings -
  4903. ;//
  4904. ;//
  4905. MessageId=0x030b
  4906. SymbolicName=SE_AUDITID_CERTSRV_SHUTDOWN
  4907. Language=English
  4908. Certificate Services received a request to shut down.
  4909. .
  4910. ;//
  4911. ;//
  4912. ;// SE_AUDITID_CERTSRV_BACKUPSTART
  4913. ;//
  4914. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4915. ;//
  4916. ;// Parameter Strings -
  4917. ;//
  4918. ;// 1 - Backup Type
  4919. ;//
  4920. ;//
  4921. MessageId=0x030c
  4922. SymbolicName=SE_AUDITID_CERTSRV_BACKUPSTART
  4923. Language=English
  4924. Certificate Services backup started.%n
  4925. Backup Type:%t%1
  4926. .
  4927. ;//
  4928. ;//
  4929. ;// SE_AUDITID_CERTSRV_BACKUPEND
  4930. ;//
  4931. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4932. ;//
  4933. ;// Parameter Strings -
  4934. ;//
  4935. ;//
  4936. MessageId=0x030d
  4937. SymbolicName=SE_AUDITID_CERTSRV_BACKUPEND
  4938. Language=English
  4939. Certificate Services backup completed.
  4940. .
  4941. ;//
  4942. ;//
  4943. ;// SE_AUDITID_CERTSRV_RESTORESTART
  4944. ;//
  4945. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4946. ;//
  4947. ;// Parameter Strings -
  4948. ;//
  4949. ;//
  4950. MessageId=0x030e
  4951. SymbolicName=SE_AUDITID_CERTSRV_RESTORESTART
  4952. Language=English
  4953. Certificate Services restore started.
  4954. .
  4955. ;//
  4956. ;//
  4957. ;// SE_AUDITID_CERTSRV_RESTOREEND
  4958. ;//
  4959. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4960. ;//
  4961. ;// Parameter Strings -
  4962. ;//
  4963. ;//
  4964. MessageId=0x030f
  4965. SymbolicName=SE_AUDITID_CERTSRV_RESTOREEND
  4966. Language=English
  4967. Certificate Services restore completed.
  4968. .
  4969. ;//
  4970. ;//
  4971. ;// SE_AUDITID_CERTSRV_SERVICESTART
  4972. ;//
  4973. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4974. ;//
  4975. ;// Parameter Strings -
  4976. ;//
  4977. ;// 1 - Database Hash
  4978. ;//
  4979. ;// 2 - Key Usage Count
  4980. ;//
  4981. ;//
  4982. MessageId=0x0310
  4983. SymbolicName=SE_AUDITID_CERTSRV_SERVICESTART
  4984. Language=English
  4985. Certificate Services started.%n
  4986. %n
  4987. Database Hash:%t%1%n
  4988. Key Usage Count:%t%2
  4989. .
  4990. ;//
  4991. ;//
  4992. ;// SE_AUDITID_CERTSRV_SERVICESTOP
  4993. ;//
  4994. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4995. ;//
  4996. ;// Parameter Strings -
  4997. ;//
  4998. ;// 1 - Database Hash
  4999. ;//
  5000. ;// 2 - Key Usage Count
  5001. ;//
  5002. ;//
  5003. MessageId=0x0311
  5004. SymbolicName=SE_AUDITID_CERTSRV_SERVICESTOP
  5005. Language=English
  5006. Certificate Services stopped.%n
  5007. %n
  5008. Database Hash:%t%1%n
  5009. Key Usage Count:%t%2
  5010. .
  5011. ;//
  5012. ;//
  5013. ;// SE_AUDITID_CERTSRV_SETSECURITY
  5014. ;//
  5015. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5016. ;//
  5017. ;// Parameter Strings -
  5018. ;//
  5019. ;// 1 - New permissions
  5020. ;//
  5021. ;//
  5022. MessageId=0x0312
  5023. SymbolicName=SE_AUDITID_CERTSRV_SETSECURITY
  5024. Language=English
  5025. The security permissions for Certificate Services changed.%n
  5026. %n
  5027. %1
  5028. .
  5029. ;//
  5030. ;//
  5031. ;// SE_AUDITID_CERTSRV_GETARCHIVEDKEY
  5032. ;//
  5033. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5034. ;//
  5035. ;// Parameter Strings -
  5036. ;//
  5037. ;// 1 - Request ID
  5038. ;//
  5039. ;//
  5040. MessageId=0x0313
  5041. SymbolicName=SE_AUDITID_CERTSRV_GETARCHIVEDKEY
  5042. Language=English
  5043. Certificate Services retrieved an archived key.%n
  5044. %n
  5045. Request ID:%t%1
  5046. .
  5047. ;//
  5048. ;//
  5049. ;// SE_AUDITID_CERTSRV_IMPORTCERT
  5050. ;//
  5051. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5052. ;//
  5053. ;// Parameter Strings -
  5054. ;//
  5055. ;// 1 - Certificate
  5056. ;//
  5057. ;// 2 - Request ID
  5058. ;//
  5059. ;//
  5060. MessageId=0x0314
  5061. SymbolicName=SE_AUDITID_CERTSRV_IMPORTCERT
  5062. Language=English
  5063. Certificate Services imported a certificate into its database.%n
  5064. %n
  5065. Certificate:%t%1%n
  5066. Request ID:%t%2
  5067. .
  5068. ;//
  5069. ;//
  5070. ;// SE_AUDITID_CERTSRV_SETAUDITFILTER
  5071. ;//
  5072. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5073. ;//
  5074. ;// Parameter Strings -
  5075. ;//
  5076. ;// 1 - Filter
  5077. ;//
  5078. ;//
  5079. MessageId=0x0315
  5080. SymbolicName=SE_AUDITID_CERTSRV_SETAUDITFILTER
  5081. Language=English
  5082. The audit filter for Certificate Services changed.%n
  5083. %n
  5084. Filter:%t%1
  5085. .
  5086. ;//
  5087. ;//
  5088. ;// SE_AUDITID_CERTSRV_NEWREQUEST
  5089. ;//
  5090. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5091. ;//
  5092. ;// Parameter Strings -
  5093. ;//
  5094. ;// 1 - Request ID
  5095. ;//
  5096. ;// 2 - Requester
  5097. ;//
  5098. ;// 3 - Attributes
  5099. ;//
  5100. ;//
  5101. MessageId=0x0316
  5102. SymbolicName=SE_AUDITID_CERTSRV_NEWREQUEST
  5103. Language=English
  5104. Certificate Services received a certificate request.%n
  5105. %n
  5106. Request ID:%t%1%n
  5107. Requester:%t%2%n
  5108. Attributes:%t%3
  5109. .
  5110. ;//
  5111. ;//
  5112. ;// SE_AUDITID_CERTSRV_REQUESTAPPROVED
  5113. ;//
  5114. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5115. ;//
  5116. ;// Parameter Strings -
  5117. ;//
  5118. ;// 1 - Request ID
  5119. ;//
  5120. ;// 2 - Requester
  5121. ;//
  5122. ;// 3 - Attributes
  5123. ;//
  5124. ;// 4 - Disposition
  5125. ;//
  5126. ;// 5 - SKI
  5127. ;//
  5128. ;// 6 - Subject
  5129. ;//
  5130. ;//
  5131. MessageId=0x0317
  5132. SymbolicName=SE_AUDITID_CERTSRV_REQUESTAPPROVED
  5133. Language=English
  5134. Certificate Services approved a certificate request and issued a certificate.%n
  5135. %n
  5136. Request ID:%t%1%n
  5137. Requester:%t%2%n
  5138. Attributes:%t%3%n
  5139. Disposition:%t%4%n
  5140. SKI:%t%t%5%n
  5141. Subject:%t%6
  5142. .
  5143. ;//
  5144. ;//
  5145. ;// SE_AUDITID_CERTSRV_REQUESTDENIED
  5146. ;//
  5147. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5148. ;//
  5149. ;// Parameter Strings -
  5150. ;//
  5151. ;// 1 - Request ID
  5152. ;//
  5153. ;// 2 - Requester
  5154. ;//
  5155. ;// 3 - Attributes
  5156. ;//
  5157. ;// 4 - Disposition
  5158. ;//
  5159. ;// 5 - SKI
  5160. ;//
  5161. ;// 6 - Subject
  5162. ;//
  5163. ;//
  5164. MessageId=0x0318
  5165. SymbolicName=SE_AUDITID_CERTSRV_REQUESTDENIED
  5166. Language=English
  5167. Certificate Services denied a certificate request.%n
  5168. %n
  5169. Request ID:%t%1%n
  5170. Requester:%t%2%n
  5171. Attributes:%t%3%n
  5172. Disposition:%t%4%n
  5173. SKI:%t%t%5%n
  5174. Subject:%t%6
  5175. .
  5176. ;//
  5177. ;//
  5178. ;// SE_AUDITID_CERTSRV_REQUESTPENDING
  5179. ;//
  5180. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5181. ;//
  5182. ;// Parameter Strings -
  5183. ;//
  5184. ;// 1 - Request ID
  5185. ;//
  5186. ;// 2 - Requester
  5187. ;//
  5188. ;// 3 - Attributes
  5189. ;//
  5190. ;// 4 - Disposition
  5191. ;//
  5192. ;// 5 - SKI
  5193. ;//
  5194. ;// 6 - Subject
  5195. ;//
  5196. ;//
  5197. MessageId=0x0319
  5198. SymbolicName=SE_AUDITID_CERTSRV_REQUESTPENDING
  5199. Language=English
  5200. Certificate Services set the status of a certificate request to pending.%n
  5201. %n
  5202. Request ID:%t%1%n
  5203. Requester:%t%2%n
  5204. Attributes:%t%3%n
  5205. Disposition:%t%4%n
  5206. SKI:%t%t%5%n
  5207. Subject:%t%6
  5208. .
  5209. ;//
  5210. ;//
  5211. ;// SE_AUDITID_CERTSRV_SETOFFICERRIGHTS
  5212. ;//
  5213. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5214. ;//
  5215. ;// Parameter Strings -
  5216. ;//
  5217. ;// 1 - Enable restrictions
  5218. ;//
  5219. ;// 2 - Restrictions
  5220. ;//
  5221. ;//
  5222. MessageId=0x031a
  5223. SymbolicName=SE_AUDITID_CERTSRV_SETOFFICERRIGHTS
  5224. Language=English
  5225. The certificate manager settings for Certificate Services changed.%n
  5226. %n
  5227. Enable:%t%1%n
  5228. %n
  5229. %2
  5230. .
  5231. ;//
  5232. ;//
  5233. ;// SE_AUDITID_CERTSRV_SETCONFIGENTRY
  5234. ;//
  5235. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5236. ;//
  5237. ;// Parameter Strings -
  5238. ;//
  5239. ;// 1 - Node
  5240. ;//
  5241. ;// 2 - Entry
  5242. ;//
  5243. ;// 3 - Value
  5244. ;//
  5245. ;//
  5246. MessageId=0x031b
  5247. SymbolicName=SE_AUDITID_CERTSRV_SETCONFIGENTRY
  5248. Language=English
  5249. A configuration entry changed in Certificate Services.%n
  5250. %n
  5251. Node:%t%1%n
  5252. Entry:%t%2%n
  5253. Value:%t%3
  5254. .
  5255. ;//
  5256. ;//
  5257. ;// SE_AUDITID_CERTSRV_SETCAPROPERTY
  5258. ;//
  5259. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5260. ;//
  5261. ;// Parameter Strings -
  5262. ;//
  5263. ;// 1 - Property
  5264. ;//
  5265. ;// 2 - Index
  5266. ;//
  5267. ;// 3 - Type
  5268. ;//
  5269. ;// 4 - Value
  5270. ;//
  5271. ;//
  5272. MessageId=0x031c
  5273. SymbolicName=SE_AUDITID_CERTSRV_SETCAPROPERTY
  5274. Language=English
  5275. A property of Certificate Services changed.%n
  5276. %n
  5277. Property:%t%1%n
  5278. Index:%t%2%n
  5279. Type:%t%3%n
  5280. Value:%t%4
  5281. .
  5282. ;//
  5283. ;//
  5284. ;// SE_AUDITID_CERTSRV_KEYARCHIVED
  5285. ;//
  5286. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5287. ;//
  5288. ;// Parameter Strings -
  5289. ;//
  5290. ;// 1 - Request ID
  5291. ;//
  5292. ;// 2 - Requester
  5293. ;//
  5294. ;// 3 - KRA Hashes
  5295. ;//
  5296. ;//
  5297. MessageId=0x031d
  5298. SymbolicName=SE_AUDITID_CERTSRV_KEYARCHIVED
  5299. Language=English
  5300. Certificate Services archived a key.%n
  5301. %n
  5302. Request ID:%t%1%n
  5303. Requester:%t%2%n
  5304. KRA Hashes:%t%3
  5305. .
  5306. ;//
  5307. ;//
  5308. ;// SE_AUDITID_CERTSRV_IMPORTKEY
  5309. ;//
  5310. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5311. ;//
  5312. ;// Parameter Strings -
  5313. ;//
  5314. ;// 1 - Request ID
  5315. ;//
  5316. ;//
  5317. MessageId=0x031e
  5318. SymbolicName=SE_AUDITID_CERTSRV_IMPORTKEY
  5319. Language=English
  5320. Certificate Services imported and archived a key.%n
  5321. %n
  5322. Request ID:%t%1
  5323. .
  5324. ;//
  5325. ;//
  5326. ;// SE_AUDITID_CERTSRV_PUBLISHCACERT
  5327. ;//
  5328. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5329. ;//
  5330. ;// Parameter Strings -
  5331. ;//
  5332. ;// 1 - Certificate Hash
  5333. ;//
  5334. ;// 2 - Valid From
  5335. ;//
  5336. ;// 3 - Valid To
  5337. ;//
  5338. ;//
  5339. MessageId=0x031f
  5340. SymbolicName=SE_AUDITID_CERTSRV_PUBLISHCACERT
  5341. Language=English
  5342. Certificate Services published the CA certificate to Active Directory.%n
  5343. %n
  5344. Certificate Hash:%t%1%n
  5345. Valid From:%t%2%n
  5346. Valid To:%t%3
  5347. .
  5348. ;//
  5349. ;//
  5350. ;// SE_AUDITID_CERTSRV_DELETEROW
  5351. ;//
  5352. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5353. ;//
  5354. ;// Parameter Strings -
  5355. ;//
  5356. ;// 1 - Table ID
  5357. ;//
  5358. ;// 2 - Filter
  5359. ;//
  5360. ;// 3 - Rows Deleted
  5361. ;//
  5362. ;//
  5363. MessageId=0x0320
  5364. SymbolicName=SE_AUDITID_CERTSRV_DELETEROW
  5365. Language=English
  5366. One or more rows have been deleted from the certificate database.%n
  5367. %n
  5368. Table ID:%t%1%n
  5369. Filter:%t%2%n
  5370. Rows Deleted:%t%3
  5371. .
  5372. ;//
  5373. ;//
  5374. ;// SE_AUDITID_CERTSRV_ROLESEPARATIONSTATE
  5375. ;//
  5376. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5377. ;//
  5378. ;// Parameter Strings -
  5379. ;//
  5380. ;// 1 - Role separation state
  5381. ;//
  5382. ;//
  5383. MessageId=0x0321
  5384. SymbolicName=SE_AUDITID_CERTSRV_ROLESEPARATIONSTATE
  5385. Language=English
  5386. Role separation enabled:%t%1
  5387. .
  5388. ;/*lint +e767 */ // Resume checking for different macro definitions // winnt
  5389. ;
  5390. ;
  5391. ;#endif // _MSAUDITE_