Source code of Windows XP (NT5)
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

6030 lines
132 KiB

  1. ;/*++ BUILD Version: 0001 // Increment this if a change has global effects
  2. ;
  3. ;Copyright (c) 1991 Microsoft Corporation
  4. ;
  5. ;Module Name:
  6. ;
  7. ; msaudite.mc
  8. ;
  9. ;Abstract:
  10. ;
  11. ; Constant definitions for the NT Audit Event Messages.
  12. ;
  13. ;Author:
  14. ;
  15. ; Jim Kelly (JimK) 30-Mar-1992
  16. ;
  17. ;Revision History:
  18. ;
  19. ;Notes:
  20. ;
  21. ; The .h and .res forms of this file are generated from the .mc
  22. ; form of the file (base\seaudit\msaudite\msaudite.mc).
  23. ; Please make all changes to the .mc form of the file.
  24. ;
  25. ; If you add a new audit category or make any change to the
  26. ; audit event id valid limits (0x200 ~ 0x5ff), please make a
  27. ; corresponding change to ntlsa.h
  28. ;
  29. ;--*/
  30. ;
  31. ;#ifndef _MSAUDITE_
  32. ;#define _MSAUDITE_
  33. ;
  34. ;/*lint -e767 */ // Don't complain about different definitions // winnt
  35. MessageIdTypedef=ULONG
  36. SeverityNames=(None=0x0)
  37. FacilityNames=(None=0x0)
  38. MessageId=0x0000
  39. Language=English
  40. Unused message ID
  41. .
  42. ;// Message ID 0 is unused - just used to flush out the diagram
  43. ;//
  44. ;// min/max limits on audit category-id and event-id of audit events
  45. ;//
  46. ;
  47. ;#define SE_ADT_MIN_CATEGORY_ID 1 // SE_CATEGID_SYSTEM
  48. ;#define SE_ADT_MAX_CATEGORY_ID 9 // SE_CATEGID_ACCOUNT_LOGON
  49. ;
  50. ;
  51. ;#define SE_ADT_MIN_AUDIT_ID 0x200 // see msaudite.h
  52. ;#define SE_ADT_MAX_AUDIT_ID 0x5ff // see msaudite.h
  53. ;///////////////////////////////////////////////////////////////////////////
  54. ;///////////////////////////////////////////////////////////////////////////
  55. ;// //
  56. ;// //
  57. ;// Audit Message ID Space: //
  58. ;// //
  59. ;// 0x0000 - 0x00FF : Reserved for future use. //
  60. ;// //
  61. ;// 0x0100 - 0x01FF : Categories //
  62. ;// //
  63. ;// 0x0200 - 0x05FF : Events //
  64. ;// //
  65. ;// 0x0600 - 0x063F : Standard access types and names for //
  66. ;// specific accesses when no specific names //
  67. ;// can be found. //
  68. ;// //
  69. ;// 0x0640 - 0x06FF : Well known privilege names (as we would //
  70. ;// like them displayed in the event viewer). //
  71. ;// //
  72. ;// 0x0700 - 0x0FFE : Reserved for future use. //
  73. ;// //
  74. ;// 0X0FFF : SE_ADT_LAST_SYSTEM_MESSAGE (the highest //
  75. ;// value audit message used by the system) //
  76. ;// //
  77. ;// //
  78. ;// 0x1000 and above: For use by Parameter Message Files //
  79. ;// //
  80. ;///////////////////////////////////////////////////////////////////////////
  81. ;///////////////////////////////////////////////////////////////////////////
  82. MessageId=0x0FFF
  83. SymbolicName=SE_ADT_LAST_SYSTEM_MESSAGE
  84. Language=English
  85. Highest System-Defined Audit Message Value.
  86. .
  87. ;
  88. ;/////////////////////////////////////////////////////////////////////////////
  89. ;// //
  90. ;// //
  91. ;// CATEGORIES //
  92. ;// //
  93. ;// Categories take up the range 0x1 - 0x400 //
  94. ;// //
  95. ;// Category IDs: //
  96. ;// //
  97. ;// SE_CATEGID_SYSTEM //
  98. ;// SE_CATEGID_LOGON //
  99. ;// SE_CATEGID_OBJECT_ACCESS //
  100. ;// SE_CATEGID_PRIVILEGE_USE //
  101. ;// SE_CATEGID_DETAILED_TRACKING //
  102. ;// SE_CATEGID_POLICY_CHANGE //
  103. ;// SE_CATEGID_ACCOUNT_MANAGEMENT //
  104. ;// SE_CATEGID_DS_ACCESS //
  105. ;// SE_CATEGID_ACCOUNT_LOGON //
  106. ;// //
  107. ;// //
  108. ;/////////////////////////////////////////////////////////////////////////////
  109. MessageId=0x0001
  110. SymbolicName=SE_CATEGID_SYSTEM
  111. Language=English
  112. System Event
  113. .
  114. MessageId=0x0002
  115. SymbolicName=SE_CATEGID_LOGON
  116. Language=English
  117. Logon/Logoff
  118. .
  119. MessageId=0x0003
  120. SymbolicName=SE_CATEGID_OBJECT_ACCESS
  121. Language=English
  122. Object Access
  123. .
  124. MessageId=0x0004
  125. SymbolicName=SE_CATEGID_PRIVILEGE_USE
  126. Language=English
  127. Privilege Use
  128. .
  129. MessageId=0x0005
  130. SymbolicName=SE_CATEGID_DETAILED_TRACKING
  131. Language=English
  132. Detailed Tracking
  133. .
  134. MessageId=0x0006
  135. SymbolicName=SE_CATEGID_POLICY_CHANGE
  136. Language=English
  137. Policy Change
  138. .
  139. MessageId=0x0007
  140. SymbolicName=SE_CATEGID_ACCOUNT_MANAGEMENT
  141. Language=English
  142. Account Management
  143. .
  144. MessageId=0x0008
  145. SymbolicName=SE_CATEGID_DS_ACCESS
  146. Language=English
  147. Directory Service Access
  148. .
  149. MessageId=0x0009
  150. SymbolicName=SE_CATEGID_ACCOUNT_LOGON
  151. Language=English
  152. Account Logon
  153. .
  154. ;
  155. ;/////////////////////////////////////////////////////////////////////////////
  156. ;// //
  157. ;// //
  158. ;// Messages for Category: SE_CATEGID_SYSTEM //
  159. ;// //
  160. ;// Event IDs: //
  161. ;// SE_AUDITID_SYSTEM_RESTART //
  162. ;// SE_AUDITID_SYSTEM_SHUTDOWN //
  163. ;// SE_AUDITID_AUTH_PACKAGE_LOAD //
  164. ;// SE_AUDITID_LOGON_PROC_REGISTER //
  165. ;// SE_AUDITID_AUDITS_DISCARDED //
  166. ;// SE_AUDITID_NOTIFY_PACKAGE_LOAD //
  167. ;// SE_AUDITID_SYSTEM_TIME_CHANGE //
  168. ;// SE_AUDITID_LPC_INVALID_USE //
  169. ;// //
  170. ;/////////////////////////////////////////////////////////////////////////////
  171. ;//
  172. ;//
  173. ;// SE_AUDITID_SYSTEM_RESTART
  174. ;//
  175. ;// Category: SE_CATEGID_SYSTEM
  176. ;//
  177. ;// Parameter Strings - None
  178. ;//
  179. ;//
  180. ;//
  181. MessageId=0x0200
  182. SymbolicName=SE_AUDITID_SYSTEM_RESTART
  183. Language=English
  184. Windows is starting up.
  185. .
  186. ;//
  187. ;//
  188. ;// SE_AUDITID_SYSTEM_SHUTDOWN
  189. ;//
  190. ;// Category: SE_CATEGID_SYSTEM
  191. ;//
  192. ;// Parameter Strings - None
  193. ;//
  194. ;//
  195. ;//
  196. MessageId=0x0201
  197. SymbolicName=SE_AUDITID_SYSTEM_SHUTDOWN
  198. Language=English
  199. Windows is shutting down.
  200. All logon sessions will be terminated by this shutdown.
  201. .
  202. ;//
  203. ;//
  204. ;// SE_AUDITID_SYSTEM_AUTH_PACKAGE_LOAD
  205. ;//
  206. ;// Category: SE_CATEGID_SYSTEM
  207. ;//
  208. ;// Parameter Strings -
  209. ;//
  210. ;// 1 - Authentication Package Name
  211. ;//
  212. ;//
  213. ;//
  214. MessageId=0x0202
  215. SymbolicName=SE_AUDITID_AUTH_PACKAGE_LOAD
  216. Language=English
  217. An authentication package has been loaded by the Local Security Authority.
  218. This authentication package will be used to authenticate logon attempts.
  219. %n
  220. Authentication Package Name:%t%1
  221. .
  222. ;//
  223. ;//
  224. ;// SE_AUDITID_SYSTEM_LOGON_PROC_REGISTER
  225. ;//
  226. ;// Category: SE_CATEGID_SYSTEM
  227. ;//
  228. ;// Parameter Strings -
  229. ;//
  230. ;// 1 - Logon Process Name
  231. ;//
  232. ;//
  233. ;//
  234. MessageId=0x0203
  235. SymbolicName=SE_AUDITID_SYSTEM_LOGON_PROC_REGISTER
  236. Language=English
  237. A trusted logon process has registered with the Local Security Authority.
  238. This logon process will be trusted to submit logon requests.
  239. %n
  240. %n
  241. Logon Process Name:%t%1
  242. .
  243. ;//
  244. ;//
  245. ;// SE_AUDITID_AUDITS_DISCARDED
  246. ;//
  247. ;// Category: SE_CATEGID_SYSTEM
  248. ;//
  249. ;// Parameter Strings -
  250. ;//
  251. ;// 1 - Number of audits discarded
  252. ;//
  253. ;//
  254. ;//
  255. MessageId=0x0204
  256. SymbolicName=SE_AUDITID_AUDITS_DISCARDED
  257. Language=English
  258. Internal resources allocated for the queuing of audit messages have been exhausted,
  259. leading to the loss of some audits.
  260. %n
  261. %tNumber of audit messages discarded:%t%1
  262. .
  263. ;//
  264. ;//
  265. ;// SE_AUDITID_AUDIT_LOG_CLEARED
  266. ;//
  267. ;// Category: SE_CATEGID_SYSTEM
  268. ;//
  269. ;// Parameter Strings -
  270. ;//
  271. ;// 1 - Primary user account name
  272. ;//
  273. ;// 2 - Primary authenticating domain name
  274. ;//
  275. ;// 3 - Primary logon ID string
  276. ;//
  277. ;// 4 - Client user account name ("-" if no client)
  278. ;//
  279. ;// 5 - Client authenticating domain name ("-" if no client)
  280. ;//
  281. ;// 6 - Client logon ID string ("-" if no client)
  282. ;//
  283. ;//
  284. ;//
  285. MessageId=0x0205
  286. SymbolicName=SE_AUDITID_AUDIT_LOG_CLEARED
  287. Language=English
  288. The audit log was cleared
  289. %n
  290. %tPrimary User Name:%t%1%n
  291. %tPrimary Domain:%t%2%n
  292. %tPrimary Logon ID:%t%3%n
  293. %tClient User Name:%t%4%n
  294. %tClient Domain:%t%5%n
  295. %tClient Logon ID:%t%6%n
  296. .
  297. ;//
  298. ;//
  299. ;// SE_AUDITID_SYSTEM_NOTIFY_PACKAGE_LOAD
  300. ;//
  301. ;// Category: SE_CATEGID_SYSTEM
  302. ;//
  303. ;// Parameter Strings -
  304. ;//
  305. ;// 1 - Notification Package Name
  306. ;//
  307. ;//
  308. ;//
  309. MessageId=0x0206
  310. SymbolicName=SE_AUDITID_NOTIFY_PACKAGE_LOAD
  311. Language=English
  312. An notification package has been loaded by the Security Account Manager.
  313. This package will be notified of any account or password changes.
  314. %n
  315. Notification Package Name:%t%1
  316. .
  317. ;//
  318. ;//
  319. ;// SE_AUDITID_LPC_INVALID_USE
  320. ;//
  321. ;// Category: SE_CATEGID_SYSTEM
  322. ;//
  323. ;// Parameter Strings -
  324. ;//
  325. ;// 1 - LPC call (e.g. "impersonation" | "reply")
  326. ;//
  327. ;// 2 - Server Port name
  328. ;//
  329. ;// 3 - Faulting process
  330. ;//
  331. ;// Event type: success
  332. ;//
  333. ;// Description:
  334. ;// SE_AUDIT_LPC_INVALID_USE is generated when a process uses an invalid LPC
  335. ;// port in an attempt to impersonate a client, reply or read/write from/to a client address space.
  336. ;//
  337. MessageId=0x0207
  338. SymbolicName=SE_AUDITID_LPC_INVALID_USE
  339. Language=English
  340. Invalid use of LPC port.%n
  341. %tProcess ID: %1%n
  342. %tImage File Name: %2%n
  343. %tPrimary User Name:%t%3%n
  344. %tPrimary Domain:%t%4%n
  345. %tPrimary Logon ID:%t%5%n
  346. %tClient User Name:%t%6%n
  347. %tClient Domain:%t%7%n
  348. %tClient Logon ID:%t%8%n
  349. %tInvalid use: %9%n
  350. %tServer Port Name:%t%10%n
  351. .
  352. ;//
  353. ;//
  354. ;// SE_AUDITID_SYSTEM_TIME_CHANGE
  355. ;//
  356. ;// Category: SE_CATEGID_SYSTEM
  357. ;//
  358. ;// Parameter Strings -
  359. ;//
  360. ;// Type: success
  361. ;//
  362. ;// Description: This event is generated when the system time is changed.
  363. ;//
  364. ;// Note: This will often appear twice in the audit log; this is an implementation
  365. ;// detail wherein changing the system time results in two calls to NtSetSystemTime.
  366. ;// This is necessary to deal with time zone changes.
  367. ;//
  368. ;//
  369. MessageId=0x0208
  370. SymbolicName=SE_AUDITID_SYSTEM_TIME_CHANGE
  371. Language=English
  372. The system time was changed.%n
  373. Process ID:%t%1%n
  374. Process Name:%t%2%n
  375. Primary User Name:%t%3%n
  376. Primary Domain:%t%4%n
  377. Primary Logon ID:%t%5%n
  378. Client User Name:%t%6%n
  379. Client Domain:%t%7%n
  380. Client Logon ID:%t%8%n
  381. Previous Time:%t%10 %9%n
  382. New Time:%t%12 %11%n
  383. .
  384. ;
  385. ;/////////////////////////////////////////////////////////////////////////////
  386. ;// //
  387. ;// //
  388. ;// Messages for Category: SE_CATEGID_LOGON //
  389. ;// //
  390. ;// Event IDs: //
  391. ;// SE_AUDITID_SUCCESSFUL_LOGON //
  392. ;// SE_AUDITID_UNKNOWN_USER_OR_PWD //
  393. ;// SE_AUDITID_ACCOUNT_TIME_RESTR //
  394. ;// SE_AUDITID_ACCOUNT_DISABLED //
  395. ;// SE_AUDITID_ACCOUNT_EXPIRED //
  396. ;// SE_AUDITID_WORKSTATION_RESTR //
  397. ;// SE_AUDITID_LOGON_TYPE_RESTR //
  398. ;// SE_AUDITID_PASSWORD_EXPIRED //
  399. ;// SE_AUDITID_NETLOGON_NOT_STARTED //
  400. ;// SE_AUDITID_UNSUCCESSFUL_LOGON //
  401. ;// SE_AUDITID_LOGOFF //
  402. ;// SE_AUDITID_ACCOUNT_LOCKED //
  403. ;// SE_AUDITID_NETWORK_LOGON //
  404. ;// SE_AUDITID_IPSEC_LOGON_SUCCESS //
  405. ;// SE_AUDITID_IPSEC_LOGOFF_MM //
  406. ;// SE_AUDITID_IPSEC_LOGOFF_QM //
  407. ;// SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST //
  408. ;// SE_AUDITID_IPSEC_AUTH //
  409. ;// SE_AUDITID_IPSEC_ATTRIB_FAIL //
  410. ;// SE_AUDITID_IPSEC_NEGOTIATION_FAIL //
  411. ;// SE_AUDITID_IPSEC_IKE_NOTIFICATION //
  412. ;// SE_AUDITID_DOMAIN_TRUST_INCONSISTENT //
  413. ;// //
  414. ;/////////////////////////////////////////////////////////////////////////////
  415. ;//
  416. ;//
  417. ;// SE_AUDITID_SUCCESSFUL_LOGON
  418. ;//
  419. ;// Category: SE_CATEGID_LOGON
  420. ;//
  421. ;// Parameter Strings -
  422. ;//
  423. ;// 1 - User account name
  424. ;//
  425. ;// 2 - Authenticating domain name
  426. ;//
  427. ;// 3 - Logon ID string
  428. ;//
  429. ;// 4 - Logon Type string
  430. ;//
  431. ;// 5 - Logon process name
  432. ;//
  433. ;// 6 - Authentication package name
  434. ;//
  435. ;//
  436. ;//
  437. MessageId=0x0210
  438. SymbolicName=SE_AUDITID_SUCCESSFUL_LOGON
  439. Language=English
  440. Successful Logon:%n
  441. %tUser Name:%t%1%n
  442. %tDomain:%t%t%2%n
  443. %tLogon ID:%t%t%3%n
  444. %tLogon Type:%t%4%n
  445. %tLogon Process:%t%5%n
  446. %tAuthentication Package:%t%6%n
  447. %tWorkstation Name:%t%7
  448. .
  449. ;//
  450. ;//
  451. ;// SE_AUDITID_UNKNOWN_USER_OR_PWD
  452. ;//
  453. ;// Category: SE_CATEGID_LOGON
  454. ;//
  455. ;// Parameter Strings -
  456. ;//
  457. ;// 1 - User account name
  458. ;//
  459. ;// 2 - Authenticating domain name
  460. ;//
  461. ;// 3 - Logon Type string
  462. ;//
  463. ;// 4 - Logon process name
  464. ;//
  465. ;// 5 - Authentication package name
  466. ;//
  467. ;//
  468. MessageId=0x0211
  469. SymbolicName=SE_AUDITID_UNKNOWN_USER_OR_PWD
  470. Language=English
  471. Logon Failure:%n
  472. %tReason:%t%tUnknown user name or bad password%n
  473. %tUser Name:%t%1%n
  474. %tDomain:%t%t%2%n
  475. %tLogon Type:%t%3%n
  476. %tLogon Process:%t%4%n
  477. %tAuthentication Package:%t%5%n
  478. %tWorkstation Name:%t%6
  479. .
  480. ;//
  481. ;//
  482. ;// SE_AUDITID_ACCOUNT_TIME_RESTR
  483. ;//
  484. ;// Category: SE_CATEGID_LOGON
  485. ;//
  486. ;// Parameter Strings -
  487. ;//
  488. ;// 1 - User account name
  489. ;//
  490. ;// 2 - Authenticating domain name
  491. ;//
  492. ;// 3 - Logon Type string
  493. ;//
  494. ;// 4 - Logon process name
  495. ;//
  496. ;// 5 - Authentication package name
  497. ;//
  498. ;//
  499. MessageId=0x0212
  500. SymbolicName=SE_AUDITID_ACCOUNT_TIME_RESTR
  501. Language=English
  502. Logon Failure:%n
  503. %tReason:%t%tAccount logon time restriction violation%n
  504. %tUser Name:%t%1%n
  505. %tDomain:%t%2%n
  506. %tLogon Type:%t%3%n
  507. %tLogon Process:%t%4%n
  508. %tAuthentication Package:%t%5%n
  509. %tWorkstation Name:%t%6
  510. .
  511. ;//
  512. ;//
  513. ;// SE_AUDITID_ACCOUNT_DISABLED
  514. ;//
  515. ;// Category: SE_CATEGID_LOGON
  516. ;//
  517. ;// Parameter Strings -
  518. ;//
  519. ;// 1 - User account name
  520. ;//
  521. ;// 2 - Authenticating domain name
  522. ;//
  523. ;// 3 - Logon Type string
  524. ;//
  525. ;// 4 - Logon process name
  526. ;//
  527. ;// 5 - Authentication package name
  528. ;//
  529. ;//
  530. MessageId=0x0213
  531. SymbolicName=SE_AUDITID_ACCOUNT_DISABLED
  532. Language=English
  533. Logon Failure:%n
  534. %tReason:%t%tAccount currently disabled%n
  535. %tUser Name:%t%1%n
  536. %tDomain:%t%t%2%n
  537. %tLogon Type:%t%3%n
  538. %tLogon Process:%t%4%n
  539. %tAuthentication Package:%t%5%n
  540. %tWorkstation Name:%t%6
  541. .
  542. ;//
  543. ;//
  544. ;// SE_AUDITID_ACCOUNT_EXPIRED
  545. ;//
  546. ;// Category: SE_CATEGID_LOGON
  547. ;//
  548. ;// Parameter Strings -
  549. ;//
  550. ;// 1 - User account name
  551. ;//
  552. ;// 2 - Authenticating domain name
  553. ;//
  554. ;// 3 - Logon Type string
  555. ;//
  556. ;// 4 - Logon process name
  557. ;//
  558. ;// 5 - Authentication package name
  559. ;//
  560. ;//
  561. MessageId=0x0214
  562. SymbolicName=SE_AUDITID_ACCOUNT_EXPIRED
  563. Language=English
  564. Logon Failure:%n
  565. %tReason:%t%tThe specified user account has expired%n
  566. %tUser Name:%t%1%n
  567. %tDomain:%t%t%2%n
  568. %tLogon Type:%t%3%n
  569. %tLogon Process:%t%4%n
  570. %tAuthentication Package:%t%5%n
  571. %tWorkstation Name:%t%6
  572. .
  573. ;//
  574. ;//
  575. ;// SE_AUDITID_WORKSTATION_RESTR
  576. ;//
  577. ;// Category: SE_CATEGID_LOGON
  578. ;//
  579. ;// Parameter Strings -
  580. ;//
  581. ;// 1 - User account name
  582. ;//
  583. ;// 2 - Authenticating domain name
  584. ;//
  585. ;// 3 - Logon Type string
  586. ;//
  587. ;// 4 - Logon process name
  588. ;//
  589. ;// 5 - Authentication package name
  590. ;//
  591. ;//
  592. MessageId=0x0215
  593. SymbolicName=SE_AUDITID_WORKSTATION_RESTR
  594. Language=English
  595. Logon Failure:%n
  596. %tReason:%t%tUser not allowed to logon at this computer%n
  597. %tUser Name:%t%1%n
  598. %tDomain:%t%2%n
  599. %tLogon Type:%t%3%n
  600. %tLogon Process:%t%4%n
  601. %tAuthentication Package:%t%5%n
  602. %tWorkstation Name:%t%6
  603. .
  604. ;//
  605. ;//
  606. ;// SE_AUDITID_LOGON_TYPE_RESTR
  607. ;//
  608. ;// Category: SE_CATEGID_LOGON
  609. ;//
  610. ;// Parameter Strings -
  611. ;//
  612. ;// 1 - User account name
  613. ;//
  614. ;// 2 - Authenticating domain name
  615. ;//
  616. ;// 3 - Logon Type string
  617. ;//
  618. ;// 4 - Logon process name
  619. ;//
  620. ;// 5 - Authentication package name
  621. ;//
  622. ;//
  623. MessageId=0x0216
  624. SymbolicName=SE_AUDITID_LOGON_TYPE_RESTR
  625. Language=English
  626. Logon Failure:%n
  627. %tReason:%tThe user has not been granted the requested%n
  628. %t%tlogon type at this machine%n
  629. %tUser Name:%t%1%n
  630. %tDomain:%t%t%2%n
  631. %tLogon Type:%t%3%n
  632. %tLogon Process:%t%4%n
  633. %tAuthentication Package:%t%5%n
  634. %tWorkstation Name:%t%6
  635. .
  636. ;//
  637. ;//
  638. ;// SE_AUDITID_PASSWORD_EXPIRED
  639. ;//
  640. ;// Category: SE_CATEGID_LOGON
  641. ;//
  642. ;// Parameter Strings -
  643. ;//
  644. ;// 1 - User account name
  645. ;//
  646. ;// 2 - Authenticating domain name
  647. ;//
  648. ;// 3 - Logon Type string
  649. ;//
  650. ;// 4 - Logon process name
  651. ;//
  652. ;// 5 - Authentication package name
  653. ;//
  654. ;//
  655. MessageId=0x0217
  656. SymbolicName=SE_AUDITID_PASSWORD_EXPIRED
  657. Language=English
  658. Logon Failure:%n
  659. %tReason:%t%tThe specified account's password has expired%n
  660. %tUser Name:%t%1%n
  661. %tDomain:%t%t%2%n
  662. %tLogon Type:%t%3%n
  663. %tLogon Process:%t%4%n
  664. %tAuthentication Package:%t%5%n
  665. %tWorkstation Name:%t%6
  666. .
  667. ;//
  668. ;//
  669. ;// SE_AUDITID_NETLOGON_NOT_STARTED
  670. ;//
  671. ;// Category: SE_CATEGID_LOGON
  672. ;//
  673. ;// Parameter Strings -
  674. ;//
  675. ;// 1 - User account name
  676. ;//
  677. ;// 2 - Authenticating domain name
  678. ;//
  679. ;// 3 - Logon Type string
  680. ;//
  681. ;// 4 - Logon process name
  682. ;//
  683. ;// 5 - Authentication package name
  684. ;//
  685. ;//
  686. MessageId=0x0218
  687. SymbolicName=SE_AUDITID_NETLOGON_NOT_STARTED
  688. Language=English
  689. Logon Failure:%n
  690. %tReason:%t%tThe NetLogon component is not active%n
  691. %tUser Name:%t%1%n
  692. %tDomain:%t%t%2%n
  693. %tLogon Type:%t%3%n
  694. %tLogon Process:%t%4%n
  695. %tAuthentication Package:%t%5%n
  696. %tWorkstation Name:%t%6
  697. .
  698. ;//
  699. ;//
  700. ;// SE_AUDITID_UNSUCCESSFUL_LOGON
  701. ;//
  702. ;// Category: SE_CATEGID_LOGON
  703. ;//
  704. ;// Parameter Strings -
  705. ;//
  706. ;// 1 - User account name
  707. ;//
  708. ;// 2 - Authenticating domain name
  709. ;//
  710. ;// 3 - Logon Type string
  711. ;//
  712. ;// 4 - Logon process name
  713. ;//
  714. ;// 5 - Authentication package name
  715. ;//
  716. ;//
  717. MessageId=0x0219
  718. SymbolicName=SE_AUDITID_UNSUCCESSFUL_LOGON
  719. Language=English
  720. Logon Failure:%n
  721. %tReason:%t%tAn error occurred during logon%n
  722. %tUser Name:%t%1%n
  723. %tDomain:%t%t%2%n
  724. %tLogon Type:%t%3%n
  725. %tLogon Process:%t%4%n
  726. %tAuthentication Package:%t%5%n
  727. %tWorkstation Name:%t%6%n
  728. %tStatus code:%t%7%n
  729. %tSubstatus code:%t%8
  730. .
  731. ;//
  732. ;//
  733. ;// SE_AUDITID_LOGOFF
  734. ;//
  735. ;// Category: SE_CATEGID_LOGON
  736. ;//
  737. ;// Parameter Strings -
  738. ;//
  739. ;// 1 - User account name
  740. ;//
  741. ;// 2 - Authenticating domain name
  742. ;//
  743. ;// 3 - Logon ID string
  744. ;//
  745. ;// 3 - Logon Type string
  746. ;//
  747. ;//
  748. ;//
  749. MessageId=0x021A
  750. SymbolicName=SE_AUDITID_LOGOFF
  751. Language=English
  752. User Logoff:%n
  753. %tUser Name:%t%1%n
  754. %tDomain:%t%t%2%n
  755. %tLogon ID:%t%t%3%n
  756. %tLogon Type:%t%4%n
  757. .
  758. ;//
  759. ;//
  760. ;// SE_AUDITID_ACCOUNT_LOCKED
  761. ;//
  762. ;// Category: SE_CATEGID_LOGON
  763. ;//
  764. ;// Parameter Strings -
  765. ;//
  766. ;// 1 - User account name
  767. ;//
  768. ;// 2 - Authenticating domain name
  769. ;//
  770. ;// 3 - Logon Type string
  771. ;//
  772. ;// 4 - Logon process name
  773. ;//
  774. ;// 5 - Authentication package name
  775. ;//
  776. ;//
  777. MessageId=0x021B
  778. SymbolicName=SE_AUDITID_ACCOUNT_LOCKED
  779. Language=English
  780. Logon Failure:%n
  781. %tReason:%t%tAccount locked out%n
  782. %tUser Name:%t%1%n
  783. %tDomain:%t%2%n
  784. %tLogon Type:%t%3%n
  785. %tLogon Process:%t%4%n
  786. %tAuthentication Package:%t%5%n
  787. %tWorkstation Name:%t%6
  788. .
  789. ;//
  790. ;//
  791. ;// SE_AUDITID_SUCCESSFUL_LOGON
  792. ;//
  793. ;// Category: SE_CATEGID_LOGON
  794. ;//
  795. ;// Description:
  796. ;// This event represents a successful logon of type Network(2) or
  797. ;// NetworkCleartext(8).
  798. ;//
  799. ;// [kumarp] I do not know why this event was created separately because
  800. ;// this was already covered by SE_AUDITID_SUCCESSFUL_LOGON with
  801. ;// the right logon types.
  802. ;//
  803. ;// Parameter Strings -
  804. ;//
  805. ;// 1 - User account name
  806. ;//
  807. ;// 2 - Authenticating domain name
  808. ;//
  809. ;// 3 - Logon ID string
  810. ;//
  811. ;// 4 - Logon Type string
  812. ;//
  813. ;// 5 - Logon process name
  814. ;//
  815. ;// 6 - Authentication package name
  816. ;//
  817. ;//
  818. ;//
  819. MessageId=0x021c
  820. SymbolicName=SE_AUDITID_NETWORK_LOGON
  821. Language=English
  822. Successful Network Logon:%n
  823. %tUser Name:%t%1%n
  824. %tDomain:%t%t%2%n
  825. %tLogon ID:%t%t%3%n
  826. %tLogon Type:%t%4%n
  827. %tLogon Process:%t%5%n
  828. %tAuthentication Package:%t%6%n
  829. %tWorkstation Name:%t%7
  830. .
  831. ;//
  832. ;//
  833. ;// SE_AUDITID_IPSEC_LOGON_SUCCESS
  834. ;//
  835. ;// Category: SE_CATEGID_LOGON
  836. ;//
  837. ;// Parameter Strings -
  838. ;//
  839. ;// 1 - Mode
  840. ;//
  841. ;// 2 - Peer Identity
  842. ;//
  843. ;// 3 - Filter
  844. ;//
  845. ;// 4 - Parameters
  846. ;//
  847. ;//
  848. MessageId=0x021d
  849. SymbolicName=SE_AUDITID_IPSEC_LOGON_SUCCESS
  850. Language=English
  851. IKE security association established.%n
  852. Mode: %n%1%n
  853. Peer Identity: %n%2%n
  854. Filter: %n%3%n
  855. Parameters: %n%4%n
  856. .
  857. ;//
  858. ;//
  859. ;// SE_AUDITID_IPSEC_LOGOFF_QM
  860. ;//
  861. ;// Category: SE_CATEGID_LOGON
  862. ;//
  863. ;// Parameter Strings -
  864. ;//
  865. ;// 1 - Filter
  866. ;//
  867. ;// 2 - Inbound SPI
  868. ;//
  869. ;// 3 - Outbound SPI
  870. ;//
  871. ;//
  872. MessageId=0x021e
  873. SymbolicName=SE_AUDITID_IPSEC_LOGOFF_QM
  874. Language=English
  875. IKE security association ended.%n
  876. Mode: Data Protection (Quick mode)
  877. Filter: %n%1%n
  878. Inbound SPI: %n%2%n
  879. Outbound SPI: %n%3%n
  880. .
  881. ;//
  882. ;//
  883. ;// SE_AUDITID_IPSEC_LOGOFF_MM
  884. ;//
  885. ;// Category: SE_CATEGID_LOGON
  886. ;//
  887. ;// Parameter Strings -
  888. ;//
  889. ;// 1 - Filter
  890. ;//
  891. MessageId=0x021f
  892. SymbolicName=SE_AUDITID_IPSEC_LOGOFF_MM
  893. Language=English
  894. IKE security association ended.%n
  895. Mode: Key Exchange (Main mode)%n
  896. Filter: %n%1%n
  897. .
  898. ;//
  899. ;//
  900. ;// SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST
  901. ;//
  902. ;// Category: SE_CATEGID_LOGON
  903. ;//
  904. ;// Parameter Strings -
  905. ;//
  906. ;// 1 - Peer Identity
  907. ;//
  908. ;// 2 - Filter
  909. ;//
  910. ;//
  911. MessageId=0x0220
  912. SymbolicName=SE_AUDITID_IPSEC_AUTH_FAIL_CERT_TRUST
  913. Language=English
  914. IKE security association establishment failed because peer could not authenticate.
  915. The certificate trust could not be established.%n
  916. Peer Identity: %n%1%n
  917. Filter: %n%2%n
  918. .
  919. ;//
  920. ;//
  921. ;// SE_AUDITID_IPSEC_AUTH_FAIL
  922. ;//
  923. ;// Category: SE_CATEGID_LOGON
  924. ;//
  925. ;// Parameter Strings -
  926. ;//
  927. ;// 1 - Peer Identity
  928. ;//
  929. ;// 2 - Filter
  930. ;//
  931. ;//
  932. MessageId=0x0221
  933. SymbolicName=SE_AUDITID_IPSEC_AUTH_FAIL
  934. Language=English
  935. IKE peer authentication failed.%n
  936. Peer Identity: %n%1%n
  937. Filter: %n%2%n
  938. .
  939. ;//
  940. ;//
  941. ;// SE_AUDITID_IPSEC_ATTRIB_FAIL
  942. ;//
  943. ;// Category: SE_CATEGID_LOGON
  944. ;//
  945. ;// Parameter Strings -
  946. ;//
  947. ;// 1 - Mode
  948. ;//
  949. ;// 2 - Filter
  950. ;//
  951. ;// 3 - Attribute Name
  952. ;//
  953. ;// 4 - Expected Value
  954. ;//
  955. ;// 5 - Received Value
  956. ;//
  957. ;//
  958. MessageId=0x0222
  959. SymbolicName=SE_AUDITID_IPSEC_ATTRIB_FAIL
  960. Language=English
  961. IKE security association establishment failed because peer
  962. sent invalid proposal.%n
  963. Mode: %n%1%n
  964. Filter: %n%2%n
  965. Attribute: %n%3%n
  966. Expected value: %n%4%n
  967. Received value: %n%5%n
  968. .
  969. ;//
  970. ;//
  971. ;// SE_AUDITID_IPSEC_NEGOTIATION_FAIL
  972. ;//
  973. ;// Category: SE_CATEGID_LOGON
  974. ;//
  975. ;// Parameter Strings -
  976. ;//
  977. ;// 1 - Mode
  978. ;//
  979. ;// 2 - Filter
  980. ;//
  981. ;// 3 - Failure Point
  982. ;//
  983. ;// 4 - Failure Reason
  984. ;//
  985. ;//
  986. MessageId=0x0223
  987. SymbolicName=SE_AUDITID_IPSEC_NEGOTIATION_FAIL
  988. Language=English
  989. IKE security association negotiation failed.%n
  990. Mode: %n%1%n
  991. Filter: %n%2%n
  992. Failure Point: %n%3%n
  993. Failure Reason: %n%4%n
  994. .
  995. ;//
  996. ;//
  997. ;// SE_AUDITID_DOMAIN_TRUST_INCONSISTENT
  998. ;//
  999. ;// Category: SE_CATEGID_LOGON
  1000. ;//
  1001. ;// Event Type : failure
  1002. ;//
  1003. ;// Description:
  1004. ;// This event is generated by an authentication package when the
  1005. ;// quarantined domain SID filtering function in LSA returns
  1006. ;// STATUS_DOMAIN_TRUST_INCONSISTENT error code.
  1007. ;//
  1008. ;// In case of kerberos:
  1009. ;// If the server ticket info has a TDOSid then KdcCheckPacForSidFiltering
  1010. ;// function makes a check to make sure the SID from the TDO matches
  1011. ;// the client's home domain SID. A call to LsaIFilterSids
  1012. ;// is made to do the check. If this function fails with
  1013. ;// STATUS_DOMAIN_TRUST_INCONSISTENT then this event is generated.
  1014. ;//
  1015. ;// In case of netlogon:
  1016. ;// NlpUserValidateHigher function does a similar check by
  1017. ;// calling LsaIFilterSids.
  1018. ;//
  1019. ;// Notes:
  1020. ;//
  1021. MessageId=0x0224
  1022. SymbolicName=SE_AUDITID_DOMAIN_TRUST_INCONSISTENT
  1023. Language=English
  1024. Logon Failure:%n
  1025. %tReason:%t%tDomain sid inconsistent%n
  1026. %tUser Name:%t%1%n
  1027. %tDomain:%t%t%2%n
  1028. %tLogon Type:%t%3%n
  1029. %tLogon Process:%t%4%n
  1030. %tAuthentication Package:%t%5%n
  1031. %tWorkstation Name:%t%6
  1032. .
  1033. ;//
  1034. ;//
  1035. ;// SE_AUDITID_ALL_SIDS_FILTERED
  1036. ;//
  1037. ;// Category: SE_CATEGID_LOGON
  1038. ;//
  1039. ;// Event Type : failure
  1040. ;//
  1041. ;// Description:
  1042. ;// During a cross forest authentication, SIDS corresponding to untrusted
  1043. ;// namespaces are filtered out. If this filtering action results into
  1044. ;// removal of all sids then this event is generated.
  1045. ;//
  1046. ;// Notes:
  1047. ;// This is generated on the computer running kdc
  1048. ;//
  1049. MessageId=0x0225
  1050. SymbolicName=SE_AUDITID_ALL_SIDS_FILTERED
  1051. Language=English
  1052. Logon Failure:%n
  1053. %tReason: %tAll sids were filtered out%n
  1054. %tUser Name:%t%1%n
  1055. %tDomain:%t%2%n
  1056. %tLogon Type:%t%3%n
  1057. %tLogon Process:%t%4%n
  1058. %tAuthentication Package%t: %5%n
  1059. %tWorkstation Name:%t%6
  1060. .
  1061. ;//
  1062. ;//
  1063. ;// SE_AUDITID_IPSEC_IKE_NOTIFICATION
  1064. ;//
  1065. ;// Category: SE_CATEGID_LOGON
  1066. ;//
  1067. ;// Parameter Strings -
  1068. ;//
  1069. ;// 1 - Notification Message
  1070. ;//
  1071. MessageId=0x0226
  1072. SymbolicName=SE_AUDITID_IPSEC_IKE_NOTIFICATION
  1073. Language=English
  1074. %1%n
  1075. .
  1076. ;
  1077. ;/////////////////////////////////////////////////////////////////////////////
  1078. ;// //
  1079. ;// //
  1080. ;// Messages for Category: SE_CATEGID_OBJECT_ACCESS //
  1081. ;// //
  1082. ;// Event IDs: //
  1083. ;// SE_AUDITID_OPEN_HANDLE //
  1084. ;// SE_AUDITID_CLOSE_HANDLE //
  1085. ;// SE_AUDITID_OPEN_OBJECT_FOR_DELETE //
  1086. ;// SE_AUDITID_DELETE_OBJECT //
  1087. ;// SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE //
  1088. ;// SE_AUDITID_OBJECT_OPERATION //
  1089. ;// //
  1090. ;// //
  1091. ;/////////////////////////////////////////////////////////////////////////////
  1092. ;//
  1093. ;//
  1094. ;// SE_AUDITID_OPEN_HANDLE
  1095. ;//
  1096. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1097. ;//
  1098. ;// Parameter Strings -
  1099. ;//
  1100. ;// 1 - Object Type string
  1101. ;//
  1102. ;// 2 - Object name
  1103. ;//
  1104. ;// 3 - New handle ID string
  1105. ;//
  1106. ;// 4 - Object server name
  1107. ;//
  1108. ;// 5 - Process ID string
  1109. ;//
  1110. ;// 6 - Primary user account name
  1111. ;//
  1112. ;// 7 - Primary authenticating domain name
  1113. ;//
  1114. ;// 8 - Primary logon ID string
  1115. ;//
  1116. ;// 9 - Client user account name ("-" if no client)
  1117. ;//
  1118. ;// 10 - Client authenticating domain name ("-" if no client)
  1119. ;//
  1120. ;// 11 - Client logon ID string ("-" if no client)
  1121. ;//
  1122. ;// 12 - Access names
  1123. ;//
  1124. ;//
  1125. ;//
  1126. ;//
  1127. MessageId=0x0230
  1128. SymbolicName=SE_AUDITID_OPEN_HANDLE
  1129. Language=English
  1130. Object Open:%n
  1131. %tObject Server:%t%1%n
  1132. %tObject Type:%t%2%n
  1133. %tObject Name:%t%3%n
  1134. %tHandle ID:%t%4%n
  1135. %tOperation ID:%t{%5,%6}%n
  1136. %tProcess ID:%t%7%n
  1137. %tImage File Name:%t%8%n
  1138. %tPrimary User Name:%t%9%n
  1139. %tPrimary Domain:%t%10%n
  1140. %tPrimary Logon ID:%t%11%n
  1141. %tClient User Name:%t%12%n
  1142. %tClient Domain:%t%13%n
  1143. %tClient Logon ID:%t%14%n
  1144. %tAccesses:%t%t%15%n
  1145. %tPrivileges:%t%t%16%n
  1146. %tRestricted Sid Count: %17%n
  1147. .
  1148. ;//
  1149. ;//
  1150. ;// SE_AUDITID_CLOSE_HANDLE
  1151. ;//
  1152. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1153. ;//
  1154. ;// Parameter Strings -
  1155. ;//
  1156. ;// 1 - Object server name
  1157. ;//
  1158. ;// 2 - Handle ID string
  1159. ;//
  1160. ;// 3 - Process ID string
  1161. ;//
  1162. ;//
  1163. ;//
  1164. ;//
  1165. MessageId=0x0232
  1166. SymbolicName=SE_AUDITID_CLOSE_HANDLE
  1167. Language=English
  1168. Handle Closed:%n
  1169. %tObject Server:%t%1%n
  1170. %tHandle ID:%t%2%n
  1171. %tProcess ID:%t%3%n
  1172. %tImage File Name:%t%4%n
  1173. .
  1174. ;//
  1175. ;//
  1176. ;// SE_AUDITID_OPEN_OBJECT_FOR_DELETE
  1177. ;//
  1178. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1179. ;//
  1180. ;// Parameter Strings -
  1181. ;//
  1182. ;// 1 - Object Type string
  1183. ;//
  1184. ;// 2 - Object name
  1185. ;//
  1186. ;// 3 - New handle ID string
  1187. ;//
  1188. ;// 4 - Object server name
  1189. ;//
  1190. ;// 5 - Process ID string
  1191. ;//
  1192. ;// 6 - Primary user account name
  1193. ;//
  1194. ;// 7 - Primary authenticating domain name
  1195. ;//
  1196. ;// 8 - Primary logon ID string
  1197. ;//
  1198. ;// 9 - Client user account name ("-" if no client)
  1199. ;//
  1200. ;// 10 - Client authenticating domain name ("-" if no client)
  1201. ;//
  1202. ;// 11 - Client logon ID string ("-" if no client)
  1203. ;//
  1204. ;// 12 - Access names
  1205. ;//
  1206. ;//
  1207. ;//
  1208. ;//
  1209. MessageId=0x0233
  1210. SymbolicName=SE_AUDITID_OPEN_OBJECT_FOR_DELETE
  1211. Language=English
  1212. Object Open for Delete:%n
  1213. %tObject Server:%t%1%n
  1214. %tObject Type:%t%2%n
  1215. %tObject Name:%t%3%n
  1216. %tHandle ID:%t%4%n
  1217. %tOperation ID:%t{%5,%6}%n
  1218. %tProcess ID:%t%7%n
  1219. %tPrimary User Name:%t%8%n
  1220. %tPrimary Domain:%t%9%n
  1221. %tPrimary Logon ID:%t%10%n
  1222. %tClient User Name:%t%11%n
  1223. %tClient Domain:%t%12%n
  1224. %tClient Logon ID:%t%13%n
  1225. %tAccesses%t%t%14%n
  1226. %tPrivileges%t%t%15%n
  1227. .
  1228. ;//
  1229. ;//
  1230. ;// SE_AUDITID_DELETE_OBJECT
  1231. ;//
  1232. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1233. ;//
  1234. ;// Parameter Strings -
  1235. ;//
  1236. ;// 1 - Object server name
  1237. ;//
  1238. ;// 2 - Handle ID string
  1239. ;//
  1240. ;// 3 - Process ID string
  1241. ;//
  1242. ;//
  1243. ;//
  1244. ;//
  1245. MessageId=0x0234
  1246. SymbolicName=SE_AUDITID_DELETE_OBJECT
  1247. Language=English
  1248. Object Deleted:%n
  1249. %tObject Server:%t%1%n
  1250. %tHandle ID:%t%2%n
  1251. %tProcess ID:%t%3%n
  1252. .
  1253. ;//
  1254. ;//
  1255. ;// SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE
  1256. ;//
  1257. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1258. ;//
  1259. ;// Parameter Strings -
  1260. ;//
  1261. ;// 1 - Object Type string
  1262. ;//
  1263. ;// 2 - Object name
  1264. ;//
  1265. ;// 3 - New handle ID string
  1266. ;//
  1267. ;// 4 - Object server name
  1268. ;//
  1269. ;// 5 - Process ID string
  1270. ;//
  1271. ;// 6 - Primary user account name
  1272. ;//
  1273. ;// 7 - Primary authenticating domain name
  1274. ;//
  1275. ;// 8 - Primary logon ID string
  1276. ;//
  1277. ;// 9 - Client user account name ("-" if no client)
  1278. ;//
  1279. ;// 10 - Client authenticating domain name ("-" if no client)
  1280. ;//
  1281. ;// 11 - Client logon ID string ("-" if no client)
  1282. ;//
  1283. ;// 12 - Access names
  1284. ;//
  1285. ;// 13 - Object Type parameters
  1286. ;//
  1287. ;//
  1288. ;//
  1289. ;//
  1290. MessageId=0x0235
  1291. SymbolicName=SE_AUDITID_OPEN_HANDLE_OBJECT_TYPE
  1292. Language=English
  1293. Object Open:%n
  1294. %tObject Server:%t%1%n
  1295. %tObject Type:%t%2%n
  1296. %tObject Name:%t%3%n
  1297. %tHandle ID:%t%4%n
  1298. %tOperation ID:%t{%5,%6}%n
  1299. %tProcess ID:%t%7%n
  1300. %tProcess Name:%t%8%n
  1301. %tPrimary User Name:%t%9%n
  1302. %tPrimary Domain:%t%10%n
  1303. %tPrimary Logon ID:%t%11%n
  1304. %tClient User Name:%t%12%n
  1305. %tClient Domain:%t%13%n
  1306. %tClient Logon ID:%t%14%n
  1307. %tAccesses%t%t%15%n
  1308. %tPrivileges%t%t%16%n%n
  1309. Properties:%n%17%18%19%20%21%22%23%24%25%26%n
  1310. .
  1311. ;
  1312. ;// SE_AUDITID_OBJECT_OPERATION
  1313. ;//
  1314. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1315. ;//
  1316. ;// Parameter Strings -
  1317. ;//
  1318. ;// 1 - Operation Name
  1319. ;//
  1320. ;// 2 - Object Type
  1321. ;//
  1322. ;// 3 - Object name
  1323. ;//
  1324. ;// 4 - Handle ID
  1325. ;//
  1326. ;// 5 - Primary user account name
  1327. ;//
  1328. ;// 6 - Primary authenticating domain name
  1329. ;//
  1330. ;// 7 - Primary logon ID string
  1331. ;//
  1332. ;// 8 - Client user account name ("-" if no client)
  1333. ;//
  1334. ;// 9 - Client authenticating domain name ("-" if no client)
  1335. ;//
  1336. ;// 10 - Client logon ID string ("-" if no client)
  1337. ;//
  1338. ;// 11 - Requested accesses to the object
  1339. ;//
  1340. ;// 12 - Object properties ("-" if none)
  1341. ;//
  1342. ;// 13 - additional information ("-" if none)
  1343. ;//
  1344. MessageId=0x0236
  1345. SymbolicName=SE_AUDITID_OBJECT_OPERATION
  1346. Language=English
  1347. Object Operation:%n
  1348. %tOperation Type%t%1%n
  1349. %tObject Type:%t%2%n
  1350. %tObject Name:%t%3%n
  1351. %tHandle ID:%t%4%n
  1352. %tPrimary User Name:%t%5%n
  1353. %tPrimary Domain:%t%6%n
  1354. %tPrimary Logon ID:%t%7%n
  1355. %tClient User Name:%t%8%n
  1356. %tClient Domain:%t%9%n
  1357. %tClient Logon ID:%t%10%n
  1358. %tAccesses%t%t%11%n
  1359. %tProperties:%n%12%n
  1360. %tAdditional Info:%t%13%n
  1361. .
  1362. ;//
  1363. ;//
  1364. ;// SE_AUDITID_OBJECT_ACCESS
  1365. ;//
  1366. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1367. ;//
  1368. ;// Parameter Strings -
  1369. ;//
  1370. ;// 1 - Object server name
  1371. ;//
  1372. ;// 2 - Handle ID string
  1373. ;//
  1374. ;// 3 - Process ID string
  1375. ;//
  1376. ;// 4 - List of Accesses
  1377. ;//
  1378. ;//
  1379. MessageId=0x0237
  1380. SymbolicName=SE_AUDITID_OBJECT_ACCESS
  1381. Language=English
  1382. Object Accessed:%n
  1383. %tObject Server:%t%1%n
  1384. %tHandle ID:%t%2%n
  1385. %tObject Type:%t%3%n
  1386. %tProcess ID:%t%4%n
  1387. %tAccess Mask:%t%5%n
  1388. .
  1389. ;//
  1390. ;//
  1391. ;// SE_AUDITID_HARDLINK_CREATION
  1392. ;//
  1393. ;// Category: SE_CATEGID_OBJECT_ACCESS
  1394. ;//
  1395. ;// Parameter Strings -
  1396. ;//
  1397. ;// 1 - Object server name
  1398. ;//
  1399. ;// 2 - Handle ID string
  1400. ;//
  1401. ;// 3 - Process ID string
  1402. ;//
  1403. ;//
  1404. ;//
  1405. ;//
  1406. MessageId=0x0238
  1407. SymbolicName=SE_AUDITID_HARDLINK_CREATION
  1408. Language=English
  1409. Hard link creation attempt:%n
  1410. %tPrimary User Name:%t%1%n
  1411. %tPrimary Domain:%t%2%n
  1412. %tPrimary Logon ID:%t%3%n
  1413. %tFile Name:%t%4%n
  1414. %tLink Name:%t%5%n
  1415. .
  1416. ;
  1417. ;/////////////////////////////////////////////////////////////////////////////
  1418. ;// //
  1419. ;// //
  1420. ;// Messages for Category: SE_CATEGID_PRIVILEGE_USE //
  1421. ;// //
  1422. ;// Event IDs: //
  1423. ;// SE_AUDITID_ASSIGN_SPECIAL_PRIV //
  1424. ;// SE_AUDITID_PRIVILEGED_SERVICE //
  1425. ;// SE_AUDITID_PRIVILEGED_OBJECT //
  1426. ;// //
  1427. ;// //
  1428. ;// //
  1429. ;/////////////////////////////////////////////////////////////////////////////
  1430. ;//
  1431. ;//
  1432. ;// SE_AUDITID_ASSIGN_SPECIAL_PRIV
  1433. ;//
  1434. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1435. ;//
  1436. ;// Description:
  1437. ;// When a user logs on, if any one of the following privileges is added
  1438. ;// to his/her token, this event is generated.
  1439. ;//
  1440. ;// - SeChangeNotifyPrivilege
  1441. ;// - SeAuditPrivilege
  1442. ;// - SeCreateTokenPrivilege
  1443. ;// - SeAssignPrimaryTokenPrivilege
  1444. ;// - SeBackupPrivilege
  1445. ;// - SeRestorePrivilege
  1446. ;// - SeDebugPrivilege
  1447. ;//
  1448. ;//
  1449. ;// Parameter Strings -
  1450. ;//
  1451. ;// 1 - User name
  1452. ;//
  1453. ;// 2 - domain name
  1454. ;//
  1455. ;// 3 - Logon ID string
  1456. ;//
  1457. ;// 4 - Privilege names (as 1 string, with formatting)
  1458. ;//
  1459. ;//
  1460. ;//
  1461. ;//
  1462. MessageId=0x0240
  1463. SymbolicName=SE_AUDITID_ASSIGN_SPECIAL_PRIV
  1464. Language=English
  1465. Special privileges assigned to new logon:%n
  1466. %tUser Name:%t%1%n
  1467. %tDomain:%t%t%2%n
  1468. %tLogon ID:%t%t%3%n
  1469. %tPrivileges:%t%t%4
  1470. .
  1471. ;//
  1472. ;//
  1473. ;// SE_AUDITID_PRIVILEGED_SERVICE
  1474. ;//
  1475. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1476. ;//
  1477. ;// Description:
  1478. ;// This event is generated when a user makes an attempt to perform
  1479. ;// a privileged system service operation.
  1480. ;//
  1481. ;// Parameter Strings -
  1482. ;//
  1483. ;// 1 - server name
  1484. ;//
  1485. ;// 2 - service name
  1486. ;//
  1487. ;// 3 - Primary User name
  1488. ;//
  1489. ;// 4 - Primary domain name
  1490. ;//
  1491. ;// 5 - Primary Logon ID string
  1492. ;//
  1493. ;// 6 - Client User name (or "-" if not impersonating)
  1494. ;//
  1495. ;// 7 - Client domain name (or "-" if not impersonating)
  1496. ;//
  1497. ;// 8 - Client Logon ID string (or "-" if not impersonating)
  1498. ;//
  1499. ;// 9 - Privilege names (as 1 string, with formatting)
  1500. ;//
  1501. ;//
  1502. ;//
  1503. ;//
  1504. MessageId=0x0241
  1505. SymbolicName=SE_AUDITID_PRIVILEGED_SERVICE
  1506. Language=English
  1507. Privileged Service Called:%n
  1508. %tServer:%t%t%1%n
  1509. %tService:%t%t%2%n
  1510. %tPrimary User Name:%t%3%n
  1511. %tPrimary Domain:%t%4%n
  1512. %tPrimary Logon ID:%t%5%n
  1513. %tClient User Name:%t%6%n
  1514. %tClient Domain:%t%7%n
  1515. %tClient Logon ID:%t%8%n
  1516. %tPrivileges:%t%9
  1517. .
  1518. ;//
  1519. ;//
  1520. ;// SE_AUDITID_PRIVILEGED_OBJECT
  1521. ;//
  1522. ;// Category: SE_CATEGID_PRIVILEGE_USE
  1523. ;//
  1524. ;// Parameter Strings -
  1525. ;//
  1526. ;// 1 - object server
  1527. ;//
  1528. ;// 2 - object handle (if available)
  1529. ;//
  1530. ;// 3 - process ID string
  1531. ;//
  1532. ;// 4 - Primary User name
  1533. ;//
  1534. ;// 5 - Primary domain name
  1535. ;//
  1536. ;// 6 - Primary Logon ID string
  1537. ;//
  1538. ;// 7 - Client User name (or "-" if not impersonating)
  1539. ;//
  1540. ;// 8 - Client domain name (or "-" if not impersonating)
  1541. ;//
  1542. ;// 9 - Client Logon ID string (or "-" if not impersonating)
  1543. ;//
  1544. ;// 10 - Privilege names (as 1 string, with formatting)
  1545. ;//
  1546. ;//
  1547. MessageId=0x0242
  1548. SymbolicName=SE_AUDITID_PRIVILEGED_OBJECT
  1549. Language=English
  1550. Privileged object operation:%n
  1551. %tObject Server:%t%1%n
  1552. %tObject Handle:%t%2%n
  1553. %tProcess ID:%t%3%n
  1554. %tPrimary User Name:%t%4%n
  1555. %tPrimary Domain:%t%5%n
  1556. %tPrimary Logon ID:%t%6%n
  1557. %tClient User Name:%t%7%n
  1558. %tClient Domain:%t%8%n
  1559. %tClient Logon ID:%t%9%n
  1560. %tPrivileges:%t%10
  1561. .
  1562. ;
  1563. ;/////////////////////////////////////////////////////////////////////////////
  1564. ;// //
  1565. ;// //
  1566. ;// Messages for Category: SE_CATEGID_DETAILED_TRACKING //
  1567. ;// //
  1568. ;// Event IDs: //
  1569. ;// SE_AUDITID_PROCESS_CREATED //
  1570. ;// SE_AUDITID_PROCESS_EXIT //
  1571. ;// SE_AUDITID_DUPLICATE_HANDLE //
  1572. ;// SE_AUDITID_INDIRECT_REFERENCE //
  1573. ;// SE_AUDITID_DPAPI_BACKUP //
  1574. ;// SE_AUDITID_DPAPI_BACKUP_FAILURE //
  1575. ;// SE_AUDITID_DPAPI_RECOVERY //
  1576. ;// SE_AUDITID_DPAPI_RECOVERY_FAILURE //
  1577. ;// SE_AUDITID_DPAPI_PROTECT //
  1578. ;// SE_AUDITID_DPAPI_PROTECT_FAILURE //
  1579. ;// SE_AUDITID_DPAPI_UNPROTECT //
  1580. ;// SE_AUDITID_DPAPI_UNPROTECT_FAILURE //
  1581. ;// SE_AUDITID_ASSIGN_TOKEN //
  1582. ;// //
  1583. ;// //
  1584. ;// //
  1585. ;/////////////////////////////////////////////////////////////////////////////
  1586. ;//
  1587. ;//
  1588. ;// SE_AUDITID_PROCESS_CREATED
  1589. ;//
  1590. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1591. ;//
  1592. ;// Parameter Strings -
  1593. ;//
  1594. ;// 1 - process ID string
  1595. ;//
  1596. ;// 2 - Image file name (if available - otherwise "-")
  1597. ;//
  1598. ;// 3 - Creating process's ID
  1599. ;//
  1600. ;// 4 - User name (of new process)
  1601. ;//
  1602. ;// 5 - domain name (of new process)
  1603. ;//
  1604. ;// 6 - Logon ID string (of new process)
  1605. ;//
  1606. MessageId=0x0250
  1607. SymbolicName=SE_AUDITID_PROCESS_CREATED
  1608. Language=English
  1609. A new process has been created:%n
  1610. %tNew Process ID:%t%1%n
  1611. %tImage File Name:%t%2%n
  1612. %tCreator Process ID:%t%3%n
  1613. %tUser Name:%t%4%n
  1614. %tDomain:%t%t%5%n
  1615. %tLogon ID:%t%t%6%n
  1616. .
  1617. ;//
  1618. ;//
  1619. ;// SE_AUDITID_PROCESS_EXIT
  1620. ;//
  1621. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1622. ;//
  1623. ;// Parameter Strings -
  1624. ;//
  1625. ;// 1 - process ID string
  1626. ;//
  1627. ;// 2 - image name
  1628. ;//
  1629. ;// 3 - User name
  1630. ;//
  1631. ;// 4 - domain name
  1632. ;//
  1633. ;// 5 - Logon ID string
  1634. ;//
  1635. ;//
  1636. ;//
  1637. ;//
  1638. MessageId=0x0251
  1639. SymbolicName=SE_AUDITID_PROCESS_EXIT
  1640. Language=English
  1641. A process has exited:%n
  1642. %tProcess ID:%t%1%n
  1643. %tImage File Name:%t%2%n
  1644. %tUser Name:%t%3%n
  1645. %tDomain:%t%t%4%n
  1646. %tLogon ID:%t%t%5%n
  1647. .
  1648. ;//
  1649. ;//
  1650. ;// SE_AUDITID_DUPLICATE_HANDLE
  1651. ;//
  1652. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1653. ;//
  1654. ;// Parameter Strings -
  1655. ;//
  1656. ;// 1 - Origin (source) handle ID string
  1657. ;//
  1658. ;// 2 - Origin (source) process ID string
  1659. ;//
  1660. ;// 3 - New (Target) handle ID string
  1661. ;//
  1662. ;// 4 - Target process ID string
  1663. ;//
  1664. ;//
  1665. ;//
  1666. MessageId=0x0252
  1667. SymbolicName=SE_AUDITID_DUPLICATE_HANDLE
  1668. Language=English
  1669. A handle to an object has been duplicated:%n
  1670. %tSource Handle ID:%t%1%n
  1671. %tSource Process ID:%t%2%n
  1672. %tTarget Handle ID:%t%3%n
  1673. %tTarget Process ID:%t%4%n
  1674. .
  1675. ;//
  1676. ;//
  1677. ;// SE_AUDITID_INDIRECT_REFERENCE
  1678. ;//
  1679. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1680. ;//
  1681. ;// Parameter Strings -
  1682. ;//
  1683. ;// 1 - Object type
  1684. ;//
  1685. ;// 2 - object name (if available - otherwise "-")
  1686. ;//
  1687. ;// 3 - ID string of handle used to gain access
  1688. ;//
  1689. ;// 3 - server name
  1690. ;//
  1691. ;// 4 - process ID string
  1692. ;//
  1693. ;// 5 - primary User name
  1694. ;//
  1695. ;// 6 - primary domain name
  1696. ;//
  1697. ;// 7 - primary logon ID
  1698. ;//
  1699. ;// 8 - client User name
  1700. ;//
  1701. ;// 9 - client domain name
  1702. ;//
  1703. ;// 10 - client logon ID
  1704. ;//
  1705. ;// 11 - granted access names (with formatting)
  1706. ;//
  1707. ;//
  1708. MessageId=0x0253
  1709. SymbolicName=SE_AUDITID_INDIRECT_REFERENCE
  1710. Language=English
  1711. Indirect access to an object has been obtained:%n
  1712. %tObject Type:%t%1%n
  1713. %tObject Name:%t%2%n
  1714. %tProcess ID:%t%3%n
  1715. %tPrimary User Name:%t%4%n
  1716. %tPrimary Domain:%t%5%n
  1717. %tPrimary Logon ID:%t%6%n
  1718. %tClient User Name:%t%7%n
  1719. %tClient Domain:%t%8%n
  1720. %tClient Logon ID:%t%9%n
  1721. %tAccesses:%t%10%n
  1722. .
  1723. ;//
  1724. ;//
  1725. ;// SE_AUDITID_DPAPI_BACKUP
  1726. ;//
  1727. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1728. ;//
  1729. ;// Parameter Strings -
  1730. ;//
  1731. ;// 1 - Master key GUID
  1732. ;//
  1733. ;// 2 - Recovery Server
  1734. ;//
  1735. ;// 3 - GUID identifier of the recovery key
  1736. ;//
  1737. ;// 4 - Failure reason
  1738. ;//
  1739. MessageId=0x0254
  1740. SymbolicName=SE_AUDITID_DPAPI_BACKUP
  1741. Language=English
  1742. Backup of data protection master key.
  1743. %n
  1744. %tKey Identifier:%t%t%1%n
  1745. %tRecovery Server:%t%t%2%n
  1746. %tRecovery Key ID:%t%t%3%n
  1747. %tFailure Reason:%t%t%4%n
  1748. .
  1749. ;//
  1750. ;//
  1751. ;// SE_AUDITID_DPAPI_RECOVERY
  1752. ;//
  1753. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1754. ;//
  1755. ;// Parameter Strings -
  1756. ;//
  1757. ;// 1 - Master key GUID
  1758. ;//
  1759. ;// 2 - Recovery Server
  1760. ;//
  1761. ;// 3 - Reason for the backup
  1762. ;//
  1763. ;// 4 - GUID identifier of the recovery key
  1764. ;//
  1765. ;// 5 - Failure reason
  1766. ;//
  1767. MessageId=0x0255
  1768. SymbolicName=SE_AUDITID_DPAPI_RECOVERY
  1769. Language=English
  1770. Recovery of data protection master key.
  1771. %n
  1772. %tKey Identifier:%t%t%1%n
  1773. %tRecovery Reason:%t%t%3%n
  1774. %tRecovery Server:%t%t%2%n
  1775. %tRecovery Key ID:%t%t%4%n
  1776. %tFailure Reason:%t%t%5%n
  1777. .
  1778. ;//
  1779. ;//
  1780. ;// SE_AUDITID_DPAPI_PROTECT
  1781. ;//
  1782. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1783. ;//
  1784. ;// Parameter Strings -
  1785. ;//
  1786. ;//
  1787. ;// 1 - Master key GUID
  1788. ;//
  1789. ;// 2 - Data Description
  1790. ;//
  1791. ;// 3 - Protected data flags
  1792. ;//
  1793. ;// 4 - Algorithms
  1794. ;//
  1795. ;// 5 - failure reason
  1796. ;//
  1797. MessageId=0x0256
  1798. SymbolicName=SE_AUDITID_DPAPI_PROTECT
  1799. Language=English
  1800. Protection of auditable protected data.
  1801. %n
  1802. %tData Description:%t%t%2%n
  1803. %tKey Identifier:%t%t%1%n
  1804. %tProtected Data Flags:%t%3%n
  1805. %tProtection Algorithms:%t%4%n
  1806. %tFailure Reason:%t%t%5%n
  1807. .
  1808. ;//
  1809. ;//
  1810. ;// SE_AUDITID_DPAPI_UNPROTECT
  1811. ;//
  1812. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1813. ;//
  1814. ;// Parameter Strings -
  1815. ;//
  1816. ;//
  1817. ;// 1 - Master key GUID
  1818. ;//
  1819. ;// 2 - Data Description
  1820. ;//
  1821. ;// 3 - Protected data flags
  1822. ;//
  1823. ;// 4 - Algorithms
  1824. ;//
  1825. ;// 5 - failure reason
  1826. ;//
  1827. MessageId=0x0257
  1828. SymbolicName=SE_AUDITID_DPAPI_UNPROTECT
  1829. Language=English
  1830. Unprotection of auditable protected data.
  1831. %n
  1832. %tData Description:%t%t%2%n
  1833. %tKey Identifier:%t%t%1%n
  1834. %tProtected Data Flags:%t%3%n
  1835. %tProtection Algorithms:%t%4%n
  1836. %tFailure Reason:%t%t%5%n
  1837. .
  1838. ;//
  1839. ;//
  1840. ;// SE_AUDITID_ASSIGN_TOKEN
  1841. ;//
  1842. ;// Category: SE_CATEGID_DETAILED_TRACKING
  1843. ;//
  1844. ;// Parameter Strings -
  1845. ;//
  1846. ;// 1. Current Process ID (the process doing the assignment
  1847. ;// 2. Current Image File Name
  1848. ;// 3. Current User Name
  1849. ;// 4. Current Domain
  1850. ;// 5. Current Logon ID
  1851. ;//
  1852. ;// 6. Process ID (of new process)
  1853. ;// 7. Image Name (of new process)
  1854. ;// 8. User name (of new process)
  1855. ;// 9. domain name (of new process)
  1856. ;// 10. Logon ID string (of new process)
  1857. ;//
  1858. MessageId=0x0258
  1859. SymbolicName=SE_AUDITID_ASSIGN_TOKEN
  1860. Language=English
  1861. A process was assigned a primary token.
  1862. %n
  1863. Assigning Process Information:%n
  1864. %tProcess ID:%t%1%n
  1865. %tImage File Name:%t%2%n
  1866. %tUser Name:%t%3%n
  1867. %tDomain:%t%t%4%n
  1868. %tLogon ID:%t%t%5%n
  1869. New Process Information:%n
  1870. %tProcess ID:%t%6%n
  1871. %tImage File Name:%t%7%n
  1872. %tUser Name:%t%8%n
  1873. %tDomain:%t%t%9%n
  1874. %tLogon ID:%t%t%10%n
  1875. .
  1876. ;
  1877. ;/////////////////////////////////////////////////////////////////////////////
  1878. ;// //
  1879. ;// //
  1880. ;// Messages for Category: SE_CATEGID_POLICY_CHANGE //
  1881. ;// //
  1882. ;// Event IDs: //
  1883. ;// SE_AUDITID_USER_RIGHT_ASSIGNED //
  1884. ;// SE_AUDITID_USER_RIGHT_REMOVED //
  1885. ;// SE_AUDITID_TRUSTED_DOMAIN_ADD //
  1886. ;// SE_AUDITID_TRUSTED_DOMAIN_REM //
  1887. ;// SE_AUDITID_TRUSTED_DOMAIN_MOD //
  1888. ;// SE_AUDITID_POLICY_CHANGE //
  1889. ;// SE_AUDITID_IPSEC_POLICY_START //
  1890. ;// SE_AUDITID_IPSEC_POLICY_DISABLED //
  1891. ;// SE_AUDITID_IPSEC_POLICY_CHANGED //
  1892. ;// SE_AUDITID_IPSEC_POLICY_FAILURE //
  1893. ;// SE_AUDITID_SYSTEM_ACCESS_CHANGE //
  1894. ;// SE_AUDITID_NAMESPACE_COLLISION //
  1895. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD //
  1896. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM //
  1897. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD //
  1898. ;// //
  1899. ;// //
  1900. ;/////////////////////////////////////////////////////////////////////////////
  1901. ;//
  1902. ;//
  1903. ;// SE_AUDITID_USER_RIGHT_ASSIGNED
  1904. ;//
  1905. ;// Category: SE_CATEGID_POLICY_CHANGE
  1906. ;//
  1907. ;// Parameter Strings -
  1908. ;//
  1909. ;// 1 - User right name
  1910. ;//
  1911. ;// 2 - SID string of account assigned the user right
  1912. ;//
  1913. ;// 3 - User name of subject assigning the right
  1914. ;//
  1915. ;// 4 - Domain name of subject assigning the right
  1916. ;//
  1917. ;// 5 - Logon ID string of subject assigning the right
  1918. ;//
  1919. ;//
  1920. ;//
  1921. MessageId=0x0260
  1922. SymbolicName=SE_AUDITID_USER_RIGHT_ASSIGNED
  1923. Language=English
  1924. User Right Assigned:%n
  1925. %tUser Right:%t%1%n
  1926. %tAssigned To:%t%2%n
  1927. %tAssigned By:%n
  1928. %t User Name:%t%3%n
  1929. %t Domain:%t%t%4%n
  1930. %t Logon ID:%t%5%n
  1931. .
  1932. ;//
  1933. ;//
  1934. ;// SE_AUDITID_USER_RIGHT_REMOVED
  1935. ;//
  1936. ;// Category: SE_CATEGID_POLICY_CHANGE
  1937. ;//
  1938. ;// Parameter Strings -
  1939. ;//
  1940. ;// 1 - User right name
  1941. ;//
  1942. ;// 2 - SID string of account from which the user
  1943. ;// right was removed
  1944. ;//
  1945. ;// 3 - User name of subject removing the right
  1946. ;//
  1947. ;// 4 - Domain name of subject removing the right
  1948. ;//
  1949. ;// 5 - Logon ID string of subject removing the right
  1950. ;//
  1951. ;//
  1952. MessageId=0x0261
  1953. SymbolicName=SE_AUDITID_USER_RIGHT_REMOVED
  1954. Language=English
  1955. User Right Removed:%n
  1956. %tUser Right:%t%1%n
  1957. %tRemoved From:%t%2%n
  1958. %tRemoved By:%n
  1959. %t User Name:%t%3%n
  1960. %t Domain:%t%t%4%n
  1961. %t Logon ID:%t%5%n
  1962. .
  1963. ;//
  1964. ;//
  1965. ;// SE_AUDITID_TRUSTED_DOMAIN_ADD
  1966. ;//
  1967. ;// Category: SE_CATEGID_POLICY_CHANGE
  1968. ;//
  1969. ;// Event type: success/failure
  1970. ;//
  1971. ;// Description:
  1972. ;// This event is generated when somebody creates a trust relationship
  1973. ;// with another domain.
  1974. ;//
  1975. ;// Note:
  1976. ;// It is recorded on the domain controller on which
  1977. ;// the trusted domain object (TDO) is created and not on any other
  1978. ;// domain controller to which the TDO creation replicates.
  1979. ;//
  1980. MessageId=0x0262
  1981. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_ADD
  1982. Language=English
  1983. New Trusted Domain:%n
  1984. %tDomain Name:%t%1%n
  1985. %tDomain ID:%t%2%n
  1986. %tEstablished By:%n
  1987. %t User Name:%t%3%n
  1988. %t Domain:%t%t%4%n
  1989. %t Logon ID:%t%5%n
  1990. %tTrust Type:%t%6%n
  1991. %tTrust Direction:%t%7%n
  1992. %tTrust Attributes:%t%8%n
  1993. .
  1994. ;//
  1995. ;//
  1996. ;// SE_AUDITID_TRUSTED_DOMAIN_REM
  1997. ;//
  1998. ;// Category: SE_CATEGID_POLICY_CHANGE
  1999. ;//
  2000. ;// Event type: success/failure
  2001. ;//
  2002. ;// Description:
  2003. ;// This event is generated when somebody removes a trust relationship
  2004. ;// with another domain.
  2005. ;//
  2006. ;// Note:
  2007. ;// It is recorded on the domain controller on which
  2008. ;// the trusted domain object (TDO) is deleted and not on any other
  2009. ;// domain controller to which the TDO deletion replicates.
  2010. ;//
  2011. MessageId=0x0263
  2012. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_REM
  2013. Language=English
  2014. Trusted Domain Removed:%n
  2015. %tDomain Name:%t%1%n
  2016. %tDomain ID:%t%2%n
  2017. %tRemoved By:%n
  2018. %t User Name:%t%3%n
  2019. %t Domain:%t%t%4%n
  2020. %t Logon ID:%t%5%n
  2021. .
  2022. ;//
  2023. ;//
  2024. ;// SE_AUDITID_POLICY_CHANGE
  2025. ;//
  2026. ;// Category: SE_CATEGID_POLICY_CHANGE
  2027. ;//
  2028. ;// Parameter Strings -
  2029. ;//
  2030. ;// 1 - System success audit status ("+" or "-")
  2031. ;// 2 - System failure audit status ("+" or "-")
  2032. ;//
  2033. ;// 3 - Logon/Logoff success audit status ("+" or "-")
  2034. ;// 4 - Logon/Logoff failure audit status ("+" or "-")
  2035. ;//
  2036. ;// 5 - Object Access success audit status ("+" or "-")
  2037. ;// 6 - Object Access failure audit status ("+" or "-")
  2038. ;//
  2039. ;// 7 - Detailed Tracking success audit status ("+" or "-")
  2040. ;// 8 - Detailed Tracking failure audit status ("+" or "-")
  2041. ;//
  2042. ;// 9 - Privilege Use success audit status ("+" or "-")
  2043. ;// 10 - Privilege Use failure audit status ("+" or "-")
  2044. ;//
  2045. ;// 11 - Policy Change success audit status ("+" or "-")
  2046. ;// 12 - Policy Change failure audit status ("+" or "-")
  2047. ;//
  2048. ;// 13 - Account Management success audit status ("+" or "-")
  2049. ;// 14 - Account Management failure audit status ("+" or "-")
  2050. ;//
  2051. ;// 15 - Directory Service access success audit status ("+" or "-")
  2052. ;// 16 - Directory Service access failure audit status ("+" or "-")
  2053. ;//
  2054. ;// 17 - Account Logon success audit status ("+" or "-")
  2055. ;// 18 - Account Logon failure audit status ("+" or "-")
  2056. ;//
  2057. ;// 19 - Account Name of user that changed the policy
  2058. ;//
  2059. ;// 20 - Domain of user that changed the policy
  2060. ;//
  2061. ;// 21 - Logon ID of user that changed the policy
  2062. ;//
  2063. ;//
  2064. MessageId=0x0264
  2065. SymbolicName=SE_AUDITID_POLICY_CHANGE
  2066. Language=English
  2067. Audit Policy Change:%n
  2068. New Policy:%n
  2069. %tSuccess%tFailure%n
  2070. %t %3%t %4%tLogon/Logoff%n
  2071. %t %5%t %6%tObject Access%n
  2072. %t %7%t %8%tPrivilege Use%n
  2073. %t %13%t %14%tAccount Management%n
  2074. %t %11%t %12%tPolicy Change%n
  2075. %t %1%t %2%tSystem%n
  2076. %t %9%t %10%tDetailed Tracking%n
  2077. %t %15%t %16%tDirectory Service Access%n
  2078. %t %17%t %18%tAccount Logon%n%n
  2079. Changed By:%n
  2080. %t User Name:%t%19%n
  2081. %t Domain Name:%t%20%n
  2082. %t Logon ID:%t%21
  2083. .
  2084. ;//
  2085. ;//
  2086. ;// SE_AUDITID_IPSEC_POLICY_START
  2087. ;//
  2088. ;// Category: SE_CATEGID_POLICY_CHANGE
  2089. ;//
  2090. ;// Parameter Strings -
  2091. ;//
  2092. ;// 1 - Ipsec Policy Agent
  2093. ;//
  2094. ;// 2 - Policy Source
  2095. ;//
  2096. ;// 3 - Event Data
  2097. ;//
  2098. ;//
  2099. MessageId=0x0265
  2100. SymbolicName=SE_AUDITID_IPSEC_POLICY_START
  2101. Language=English
  2102. IPSec policy agent started: %t%1%n
  2103. Policy Source: %t%2%n
  2104. %3%n
  2105. .
  2106. ;//
  2107. ;//
  2108. ;// SE_AUDITID_IPSEC_POLICY_DISABLED
  2109. ;//
  2110. ;// Category: SE_CATEGID_POLICY_CHANGE
  2111. ;//
  2112. ;// Parameter Strings -
  2113. ;//
  2114. ;// 1 - Ipsec Policy Agent
  2115. ;//
  2116. ;// 2 - Event Data
  2117. ;//
  2118. ;//
  2119. MessageId=0x0266
  2120. SymbolicName=SE_AUDITID_IPSEC_POLICY_DISABLED
  2121. Language=English
  2122. IPSec policy agent disabled: %t%1%n
  2123. %2%n
  2124. .
  2125. ;//
  2126. ;//
  2127. ;// SE_AUDITID_IPSEC_POLICY_CHANGED
  2128. ;//
  2129. ;// Category: SE_CATEGID_POLICY_CHANGE
  2130. ;//
  2131. ;// Parameter Strings -
  2132. ;//
  2133. ;// 1 - Event Data
  2134. ;//
  2135. ;//
  2136. MessageId=0x0267
  2137. SymbolicName=SE_AUDITID_IPSEC_POLICY_CHANGED
  2138. Language=English
  2139. IPSEC PolicyAgent Service: %t%1%n
  2140. .
  2141. ;//
  2142. ;//
  2143. ;// SE_AUDITID_IPSEC_POLICY_FAILURE
  2144. ;//
  2145. ;// Category: SE_CATEGID_POLICY_CHANGE
  2146. ;//
  2147. ;// Parameter Strings -
  2148. ;//
  2149. ;// 1 - Event Data
  2150. ;//
  2151. ;//
  2152. MessageId=0x0268
  2153. SymbolicName=SE_AUDITID_IPSEC_POLICY_FAILURE
  2154. Language=English
  2155. IPSec policy agent encountered a potentially serious failure.%n
  2156. %1%n
  2157. .
  2158. ;//
  2159. ;//
  2160. ;// SE_AUDITID_KERBEROS_POLICY_CHANGE
  2161. ;//
  2162. ;// Category: SE_CATEGID_POLICY_CHANGE
  2163. ;//
  2164. ;// Parameter Strings -
  2165. ;//
  2166. ;// 1 - user account name
  2167. ;//
  2168. ;// 2 - domain name of user
  2169. ;//
  2170. ;// 3 - logon ID of user
  2171. ;//
  2172. ;// 4 - description of the change made
  2173. ;//
  2174. ;//
  2175. MessageId=0x0269
  2176. SymbolicName=SE_AUDITID_KERBEROS_POLICY_CHANGE
  2177. Language=English
  2178. Kerberos Policy Changed:%n
  2179. Changed By:%n
  2180. %t User Name:%t%1%n
  2181. %t Domain Name:%t%2%n
  2182. %t Logon ID:%t%3%n
  2183. Changes made:%n
  2184. ('--' means no changes, otherwise each change is shown as:%n
  2185. <ParameterName>: <new value> (<old value>))%n
  2186. %4%n
  2187. .
  2188. ;//
  2189. ;//
  2190. ;// SE_AUDITID_EFS_POLICY_CHANGE
  2191. ;//
  2192. ;// Category: SE_CATEGID_POLICY_CHANGE
  2193. ;//
  2194. ;// Parameter Strings -
  2195. ;//
  2196. ;// 1 - user account name
  2197. ;//
  2198. ;// 2 - domain name of user
  2199. ;//
  2200. ;// 3 - logon ID of user
  2201. ;//
  2202. ;// 4 - description of the change made
  2203. ;//
  2204. ;//
  2205. MessageId=0x026a
  2206. SymbolicName=SE_AUDITID_EFS_POLICY_CHANGE
  2207. Language=English
  2208. Encrypted Data Recovery Policy Changed:%n
  2209. Changed By:%n
  2210. %t User Name:%t%1%n
  2211. %t Domain Name:%t%2%n
  2212. %t Logon ID:%t%3%n
  2213. Changes made:%n
  2214. ('--' means no changes, otherwise each change is shown as:%n
  2215. <ParameterName>: <new value> (<old value>))%n
  2216. %4%n
  2217. .
  2218. ;//
  2219. ;//
  2220. ;// SE_AUDITID_TRUSTED_DOMAIN_MOD
  2221. ;//
  2222. ;// Category: SE_CATEGID_POLICY_CHANGE
  2223. ;//
  2224. ;// Event type: success/failure
  2225. ;//
  2226. ;// Description:
  2227. ;// This event is generated when somebody modifies a trust relationship
  2228. ;// with another domain.
  2229. ;//
  2230. ;// Note:
  2231. ;// It is recorded on the domain controller on which
  2232. ;// the trusted domain object (TDO) is modified and not on any other
  2233. ;// domain controller to which the TDO modification replicates.
  2234. ;//
  2235. MessageId=0x026C
  2236. SymbolicName=SE_AUDITID_TRUSTED_DOMAIN_MOD
  2237. Language=English
  2238. Trusted Domain Information Modified:%n
  2239. %tDomain Name:%t%1%n
  2240. %tDomain ID:%t%2%n
  2241. %tModified By:%n
  2242. %t User Name:%t%3%n
  2243. %t Domain:%t%t%4%n
  2244. %t Logon ID:%t%5%n
  2245. %tTrust Type:%t%6%n
  2246. %tTrust Direction:%t%7%n
  2247. %tTrust Attributes:%t%8%n
  2248. .
  2249. ;//
  2250. ;//
  2251. ;// SE_AUDITID_SYSTEM_ACCESS_GRANTED
  2252. ;//
  2253. ;// Category: SE_CATEGID_POLICY_CHANGE
  2254. ;//
  2255. ;// Parameter Strings -
  2256. ;//
  2257. ;// 1 - User right name
  2258. ;//
  2259. ;// 2 - SID string of account for which the user
  2260. ;// right was affected
  2261. ;//
  2262. ;// 3 - User name of subject changing the right
  2263. ;//
  2264. ;// 4 - Domain name of subject changing the right
  2265. ;//
  2266. ;// 5 - Logon ID string of subject changing the right
  2267. ;//
  2268. ;//
  2269. MessageId=0x026d
  2270. SymbolicName=SE_AUDITID_SYSTEM_ACCESS_GRANTED
  2271. Language=English
  2272. System Security Access Granted:%n
  2273. %tAccess Granted:%t%4%n
  2274. %tAccount Modified:%t%5%n
  2275. %tAssigned By:%n
  2276. %t User Name:%t%1%n
  2277. %t Domain:%t%t%2%n
  2278. %t Logon ID:%t%3%n
  2279. .
  2280. ;//
  2281. ;//
  2282. ;// SE_AUDITID_SYSTEM_ACCESS_REMOVED
  2283. ;//
  2284. ;// Category: SE_CATEGID_POLICY_CHANGE
  2285. ;//
  2286. ;// Parameter Strings -
  2287. ;//
  2288. ;// 1 - User right name
  2289. ;//
  2290. ;// 2 - SID string of account for which the user
  2291. ;// right was affected
  2292. ;//
  2293. ;// 3 - User name of subject changing the right
  2294. ;//
  2295. ;// 4 - Domain name of subject changing the right
  2296. ;//
  2297. ;// 5 - Logon ID string of subject changing the right
  2298. ;//
  2299. ;//
  2300. MessageId=0x026e
  2301. SymbolicName=SE_AUDITID_SYSTEM_ACCESS_REMOVED
  2302. Language=English
  2303. System Security Access Removed:%n
  2304. %tAccess Removed:%t%4%n
  2305. %tAccount Modified:%t%5%n
  2306. %tRemoved By:%n
  2307. %t User Name:%t%1%n
  2308. %t Domain:%t%t%2%n
  2309. %t Logon ID:%t%3%n
  2310. .
  2311. ;//
  2312. ;//
  2313. ;// SE_AUDITID_NAMESPACE_COLLISION
  2314. ;//
  2315. ;// Category: SE_CATEGID_POLICY_CHANGE
  2316. ;//
  2317. ;// Event type: success
  2318. ;//
  2319. ;// Description:
  2320. ;// When a namespace element in one forest overlaps a namespace element in
  2321. ;// some other forest, it can lead to ambiguity in resolving a name
  2322. ;// belonging to one of the namespace elements. This overlap is also called
  2323. ;// a collision.This event is generated when such a collision is detected.
  2324. ;//
  2325. ;// Note:
  2326. ;// Not all fields are valid for each entry type.
  2327. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2328. ;// for an entry of type 'TopLevelName'.
  2329. ;//
  2330. MessageId=0x0300
  2331. SymbolicName=SE_AUDITID_NAMESPACE_COLLISION
  2332. Language=English
  2333. Namespace collision detected:%n
  2334. %tTarget type:%t%1%n
  2335. %tTarget name:%t%2%n
  2336. %tForest Root:%t%3%n
  2337. %tTop Level Name:%t%4%n
  2338. %tDNS Name:%t%5%n
  2339. %tNetBIOS Name:%t%6%n
  2340. %tSID:%t%t%7%n
  2341. %tNew Flags:%t%8%n
  2342. .
  2343. ;//
  2344. ;//
  2345. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD
  2346. ;//
  2347. ;// Category: SE_CATEGID_POLICY_CHANGE
  2348. ;//
  2349. ;// Event type: success
  2350. ;//
  2351. ;// Description:
  2352. ;// This event is generated when the forest trust information is updated and
  2353. ;// one or more entries get added. One such audit event is generated
  2354. ;// per added entry. If multiple entries get added, deleted or modified
  2355. ;// in a single update of the forest trust information, all the generated
  2356. ;// audit events will have a single unique identifier called OperationID.
  2357. ;// This allows one to determine that the multiple generated audits are
  2358. ;// the result of a single operation.
  2359. ;//
  2360. ;// Note:
  2361. ;// Not all fields are valid for each entry type.
  2362. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2363. ;// for an entry of type 'TopLevelName'.
  2364. ;//
  2365. MessageId=0x0301
  2366. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_ADD
  2367. Language=English
  2368. Trusted Forest Information Entry Added:%n
  2369. %tForest Root:%t%1%n
  2370. %tForest Root SID:%t%2%n
  2371. %tOperation ID:%t{%3,%4}%n
  2372. %tEntry Type:%t%5%n
  2373. %tFlags:%t%t%6%n
  2374. %tTop Level Name:%t%7%n
  2375. %tDNS Name:%t%8%n
  2376. %tNetBIOS Name:%t%9%n
  2377. %tDomain SID:%t%10%n
  2378. %tAdded by%t:%n
  2379. %tClient User Name:%t%11%n
  2380. %tClient Domain:%t%12%n
  2381. %tClient Logon ID:%t%13%n
  2382. .
  2383. ;//
  2384. ;//
  2385. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM
  2386. ;//
  2387. ;// Category: SE_CATEGID_POLICY_CHANGE
  2388. ;//
  2389. ;// Event type: success
  2390. ;//
  2391. ;// Description:
  2392. ;// This event is generated when the forest trust information is updated and
  2393. ;// one or more entries get deleted. One such audit event is generated
  2394. ;// per deleted entry. If multiple entries get added, deleted or modified
  2395. ;// in a single update of the forest trust information, all the generated
  2396. ;// audit events will have a single unique identifier called OperationID.
  2397. ;// This allows one to determine that the multiple generated audits are
  2398. ;// the result of a single operation.
  2399. ;//
  2400. ;// Note:
  2401. ;// Not all fields are valid for each entry type.
  2402. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2403. ;// for an entry of type 'TopLevelName'.
  2404. ;//
  2405. MessageId=0x0302
  2406. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_REM
  2407. Language=English
  2408. Trusted Forest Information Entry Removed:%n
  2409. %tForest Root:%t%1%n
  2410. %tForest Root SID:%t%2%n
  2411. %tOperation ID:%t{%3,%4}%n
  2412. %tEntry Type:%t%5%n
  2413. %tFlags:%t%t%6%n
  2414. %tTop Level Name:%t%7%n
  2415. %tDNS Name:%t%8%n
  2416. %tNetBIOS Name:%t%9%n
  2417. %tDomain SID:%t%10%n
  2418. %tRemoved by%t:%n
  2419. %tClient User Name:%t%11%n
  2420. %tClient Domain:%t%12%n
  2421. %tClient Logon ID:%t%13%n
  2422. .
  2423. ;//
  2424. ;//
  2425. ;// SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD
  2426. ;//
  2427. ;// Category: SE_CATEGID_POLICY_CHANGE
  2428. ;//
  2429. ;// Event type: success
  2430. ;//
  2431. ;// Description:
  2432. ;// This event is generated when the forest trust information is updated and
  2433. ;// one or more entries get modified. One such audit event is generated
  2434. ;// per modified entry. If multiple entries get added, deleted or modified
  2435. ;// in a single update of the forest trust information, all the generated
  2436. ;// audit events will have a single unique identifier called OperationID.
  2437. ;// This allows one to determine that the multiple generated audits are
  2438. ;// the result of a single operation.
  2439. ;//
  2440. ;// Note:
  2441. ;// Not all fields are valid for each entry type.
  2442. ;// For example, fields like DNS name, NetBIOS name and SID are not valid
  2443. ;// for an entry of type 'TopLevelName'.
  2444. ;//
  2445. MessageId=0x0303
  2446. SymbolicName=SE_AUDITID_TRUSTED_FOREST_INFO_ENTRY_MOD
  2447. Language=English
  2448. Trusted Forest Information Entry Modified:%n
  2449. %tForest Root:%t%1%n
  2450. %tForest Root SID:%t%2%n
  2451. %tOperation ID:%t{%3,%4}%n
  2452. %tEntry Type:%t%5%n
  2453. %tFlags:%t%t%6%n
  2454. %tTop Level Name:%t%7%n
  2455. %tDNS Name:%t%8%n
  2456. %tNetBIOS Name:%t%9%n
  2457. %tDomain SID:%t%10%n
  2458. %tModified by%t:%n
  2459. %tClient User Name:%t%11%n
  2460. %tClient Domain:%t%12%n
  2461. %tClient Logon ID:%t%13%n
  2462. .
  2463. ;
  2464. ;/////////////////////////////////////////////////////////////////////////////
  2465. ;// //
  2466. ;// //
  2467. ;// Messages for Category: SE_CATEGID_ACCOUNT_MANAGEMENT //
  2468. ;// //
  2469. ;// Event IDs: //
  2470. ;// SE_AUDITID_USER_CREATED //
  2471. ;// SE_AUDITID_USER_CHANGE //
  2472. ;// SE_AUDITID_ACCOUNT_TYPE_CHANGE //
  2473. ;// SE_AUDITID_USER_ENABLED //
  2474. ;// SE_AUDITID_USER_PWD_CHANGED //
  2475. ;// SE_AUDITID_USER_PWD_SET //
  2476. ;// SE_AUDITID_USER_DISABLED //
  2477. ;// SE_AUDITID_USER_DELETED //
  2478. ;// //
  2479. ;// SE_AUDITID_COMPUTER_CREATED //
  2480. ;// SE_AUDITID_COMPUTER_CHANGE //
  2481. ;// SE_AUDITID_COMPUTER_DELETED //
  2482. ;// //
  2483. ;// SE_AUDITID_GLOBAL_GROUP_CREATED //
  2484. ;// SE_AUDITID_GLOBAL_GROUP_ADD //
  2485. ;// SE_AUDITID_GLOBAL_GROUP_REM //
  2486. ;// SE_AUDITID_GLOBAL_GROUP_DELETED //
  2487. ;// SE_AUDITID_LOCAL_GROUP_CREATED //
  2488. ;// SE_AUDITID_LOCAL_GROUP_ADD //
  2489. ;// SE_AUDITID_LOCAL_GROUP_REM //
  2490. ;// SE_AUDITID_LOCAL_GROUP_DELETED //
  2491. ;// //
  2492. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED //
  2493. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE //
  2494. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD //
  2495. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM //
  2496. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED //
  2497. ;// //
  2498. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED //
  2499. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE //
  2500. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD //
  2501. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM //
  2502. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED //
  2503. ;// //
  2504. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED //
  2505. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE //
  2506. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD //
  2507. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM //
  2508. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED //
  2509. ;// //
  2510. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED //
  2511. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE //
  2512. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD //
  2513. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM //
  2514. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED //
  2515. ;// //
  2516. ;// SE_AUDITID_GROUP_TYPE_CHANGE //
  2517. ;// //
  2518. ;// SE_AUDITID_ADD_SID_HISTORY //
  2519. ;// //
  2520. ;// SE_AUDITID_OTHER_ACCT_CHANGE //
  2521. ;// SE_AUDITID_DOMAIN_POLICY_CHANGE //
  2522. ;// SE_AUDITID_ACCOUNT_AUTO_LOCKED //
  2523. ;// SE_AUDITID_ACCOUNT_UNLOCKED //
  2524. ;// SE_AUDITID_SECURE_ADMIN_GROUP //
  2525. ;// //
  2526. ;// //
  2527. ;/////////////////////////////////////////////////////////////////////////////
  2528. ;//
  2529. ;//
  2530. ;// SE_AUDITID_USER_CREATED
  2531. ;//
  2532. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2533. ;//
  2534. ;// Parameter Strings -
  2535. ;//
  2536. ;// 1 - name of new user account
  2537. ;//
  2538. ;// 2 - domain of new user account
  2539. ;//
  2540. ;// 3 - SID string of new user account
  2541. ;//
  2542. ;// 4 - User name of subject creating the user account
  2543. ;//
  2544. ;// 5 - Domain name of subject creating the user account
  2545. ;//
  2546. ;// 6 - Logon ID string of subject creating the user account
  2547. ;//
  2548. ;// 7 - Privileges used to create the user account
  2549. ;//
  2550. ;//
  2551. MessageId=0x0270
  2552. SymbolicName=SE_AUDITID_USER_CREATED
  2553. Language=English
  2554. User Account Created:%n
  2555. %tNew Account Name:%t%1%n
  2556. %tNew Domain:%t%2%n
  2557. %tNew Account ID:%t%3%n
  2558. %tCaller User Name:%t%4%n
  2559. %tCaller Domain:%t%5%n
  2560. %tCaller Logon ID:%t%6%n
  2561. %tPrivileges%t%t%7%n
  2562. .
  2563. ;//
  2564. ;//
  2565. ;// SE_AUDITID_ACCOUNT_TYPE_CHANGE
  2566. ;//
  2567. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2568. ;//
  2569. ;// MessageId 0x271 unused
  2570. ;//
  2571. ;//
  2572. ;//
  2573. ;// SE_AUDITID_USER_ENABLED
  2574. ;//
  2575. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2576. ;//
  2577. ;// Parameter Strings -
  2578. ;//
  2579. ;// 1 - name of target user account
  2580. ;//
  2581. ;// 2 - domain of target user account
  2582. ;//
  2583. ;// 3 - SID string of target user account
  2584. ;//
  2585. ;// 4 - User name of subject changing the user account
  2586. ;//
  2587. ;// 5 - Domain name of subject changing the user account
  2588. ;//
  2589. ;// 6 - Logon ID string of subject changing the user account
  2590. ;//
  2591. ;//
  2592. MessageId=0x0272
  2593. SymbolicName=SE_AUDITID_USER_ENABLED
  2594. Language=English
  2595. User Account Enabled:%n
  2596. %tTarget Account Name:%t%1%n
  2597. %tTarget Domain:%t%2%n
  2598. %tTarget Account ID:%t%3%n
  2599. %tCaller User Name:%t%4%n
  2600. %tCaller Domain:%t%5%n
  2601. %tCaller Logon ID:%t%6%n
  2602. .
  2603. ;//
  2604. ;//
  2605. ;// SE_AUDITID_USER_PWD_CHANGED
  2606. ;//
  2607. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2608. ;//
  2609. ;// Parameter Strings -
  2610. ;//
  2611. ;// 1 - name of target user account
  2612. ;//
  2613. ;// 2 - domain of target user account
  2614. ;//
  2615. ;// 3 - SID string of target user account
  2616. ;//
  2617. ;// 4 - User name of subject changing the user account
  2618. ;//
  2619. ;// 5 - Domain name of subject changing the user account
  2620. ;//
  2621. ;// 6 - Logon ID string of subject changing the user account
  2622. ;//
  2623. ;//
  2624. MessageId=0x0273
  2625. SymbolicName=SE_AUDITID_USER_PWD_CHANGED
  2626. Language=English
  2627. Change Password Attempt:%n
  2628. %tTarget Account Name:%t%1%n
  2629. %tTarget Domain:%t%2%n
  2630. %tTarget Account ID:%t%3%n
  2631. %tCaller User Name:%t%4%n
  2632. %tCaller Domain:%t%5%n
  2633. %tCaller Logon ID:%t%6%n
  2634. %tPrivileges:%t%7%n
  2635. .
  2636. ;//
  2637. ;//
  2638. ;// SE_AUDITID_USER_PWD_SET
  2639. ;//
  2640. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2641. ;//
  2642. ;// Parameter Strings -
  2643. ;//
  2644. ;// 1 - name of target user account
  2645. ;//
  2646. ;// 2 - domain of target user account
  2647. ;//
  2648. ;// 3 - SID string of target user account
  2649. ;//
  2650. ;// 4 - User name of subject changing the user account
  2651. ;//
  2652. ;// 5 - Domain name of subject changing the user account
  2653. ;//
  2654. ;// 6 - Logon ID string of subject changing the user account
  2655. ;//
  2656. ;//
  2657. MessageId=0x0274
  2658. SymbolicName=SE_AUDITID_USER_PWD_SET
  2659. Language=English
  2660. User Account password set:%n
  2661. %tTarget Account Name:%t%1%n
  2662. %tTarget Domain:%t%2%n
  2663. %tTarget Account ID:%t%3%n
  2664. %tCaller User Name:%t%4%n
  2665. %tCaller Domain:%t%5%n
  2666. %tCaller Logon ID:%t%6%n
  2667. .
  2668. ;//
  2669. ;//
  2670. ;// SE_AUDITID_USER_DISABLED
  2671. ;//
  2672. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2673. ;//
  2674. ;// Parameter Strings -
  2675. ;//
  2676. ;// 1 - name of target user account
  2677. ;//
  2678. ;// 2 - domain of target user account
  2679. ;//
  2680. ;// 3 - SID string of target user account
  2681. ;//
  2682. ;// 4 - User name of subject changing the user account
  2683. ;//
  2684. ;// 5 - Domain name of subject changing the user account
  2685. ;//
  2686. ;// 6 - Logon ID string of subject changing the user account
  2687. ;//
  2688. ;//
  2689. MessageId=0x0275
  2690. SymbolicName=SE_AUDITID_USER_DISABLED
  2691. Language=English
  2692. User Account Disabled:%n
  2693. %tTarget Account Name:%t%1%n
  2694. %tTarget Domain:%t%2%n
  2695. %tTarget Account ID:%t%3%n
  2696. %tCaller User Name:%t%4%n
  2697. %tCaller Domain:%t%5%n
  2698. %tCaller Logon ID:%t%6%n
  2699. .
  2700. ;//
  2701. ;//
  2702. ;// SE_AUDITID_USER_DELETED
  2703. ;//
  2704. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2705. ;//
  2706. ;// Parameter Strings -
  2707. ;//
  2708. ;// 1 - name of target account
  2709. ;//
  2710. ;// 2 - domain of target account
  2711. ;//
  2712. ;// 3 - SID string of target account
  2713. ;//
  2714. ;// 4 - User name of subject changing the account
  2715. ;//
  2716. ;// 5 - Domain name of subject changing the account
  2717. ;//
  2718. ;// 6 - Logon ID string of subject changing the account
  2719. ;//
  2720. ;//
  2721. MessageId=0x0276
  2722. SymbolicName=SE_AUDITID_USER_DELETED
  2723. Language=English
  2724. User Account Deleted:%n
  2725. %tTarget Account Name:%t%1%n
  2726. %tTarget Domain:%t%2%n
  2727. %tTarget Account ID:%t%3%n
  2728. %tCaller User Name:%t%4%n
  2729. %tCaller Domain:%t%5%n
  2730. %tCaller Logon ID:%t%6%n
  2731. %tPrivileges:%t%7%n
  2732. .
  2733. ;//
  2734. ;//
  2735. ;// SE_AUDITID_GLOBAL_GROUP_CREATED
  2736. ;//
  2737. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2738. ;//
  2739. ;// Parameter Strings -
  2740. ;//
  2741. ;// 1 - name of new group account
  2742. ;//
  2743. ;// 2 - domain of new group account
  2744. ;//
  2745. ;// 3 - SID string of new group account
  2746. ;//
  2747. ;// 4 - User name of subject creating the account
  2748. ;//
  2749. ;// 5 - Domain name of subject creating the account
  2750. ;//
  2751. ;// 6 - Logon ID string of subject creating the account
  2752. ;//
  2753. ;//
  2754. MessageId=0x0277
  2755. SymbolicName=SE_AUDITID_GLOBAL_GROUP_CREATED
  2756. Language=English
  2757. Security Enabled Global Group Created:%n
  2758. %tNew Account Name:%t%1%n
  2759. %tNew Domain:%t%2%n
  2760. %tNew Account ID:%t%3%n
  2761. %tCaller User Name:%t%4%n
  2762. %tCaller Domain:%t%5%n
  2763. %tCaller Logon ID:%t%6%n
  2764. %tPrivileges:%t%7%n
  2765. .
  2766. ;//
  2767. ;//
  2768. ;// SE_AUDITID_GLOBAL_GROUP_ADD
  2769. ;//
  2770. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2771. ;//
  2772. ;// Parameter Strings -
  2773. ;//
  2774. ;// 1 - SID string of member being added
  2775. ;//
  2776. ;// 2 - name of target account
  2777. ;//
  2778. ;// 3 - domain of target account
  2779. ;//
  2780. ;// 4 - SID string of target account
  2781. ;//
  2782. ;// 5 - User name of subject changing the account
  2783. ;//
  2784. ;// 6 - Domain name of subject changing the account
  2785. ;//
  2786. ;// 7 - Logon ID string of subject changing the account
  2787. ;//
  2788. ;//
  2789. MessageId=0x0278
  2790. SymbolicName=SE_AUDITID_GLOBAL_GROUP_ADD
  2791. Language=English
  2792. Security Enabled Global Group Member Added:%n
  2793. %tMember Name:%t%1%n
  2794. %tMember ID:%t%2%n
  2795. %tTarget Account Name:%t%3%n
  2796. %tTarget Domain:%t%4%n
  2797. %tTarget Account ID:%t%5%n
  2798. %tCaller User Name:%t%6%n
  2799. %tCaller Domain:%t%7%n
  2800. %tCaller Logon ID:%t%8%n
  2801. %tPrivileges:%t%9%n
  2802. .
  2803. ;//
  2804. ;//
  2805. ;// SE_AUDITID_GLOBAL_GROUP_REM
  2806. ;//
  2807. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2808. ;//
  2809. ;// Parameter Strings -
  2810. ;//
  2811. ;// 1 - SID string of member being removed
  2812. ;//
  2813. ;// 2 - name of target account
  2814. ;//
  2815. ;// 3 - domain of target account
  2816. ;//
  2817. ;// 4 - SID string of target account
  2818. ;//
  2819. ;// 5 - User name of subject changing the account
  2820. ;//
  2821. ;// 6 - Domain name of subject changing the account
  2822. ;//
  2823. ;// 7 - Logon ID string of subject changing the account
  2824. ;//
  2825. ;//
  2826. MessageId=0x0279
  2827. SymbolicName=SE_AUDITID_GLOBAL_GROUP_REM
  2828. Language=English
  2829. Security Enabled Global Group Member Removed:%n
  2830. %tMember Name:%t%1%n
  2831. %tMember ID:%t%2%n
  2832. %tTarget Account Name:%t%3%n
  2833. %tTarget Domain:%t%4%n
  2834. %tTarget Account ID:%t%5%n
  2835. %tCaller User Name:%t%6%n
  2836. %tCaller Domain:%t%7%n
  2837. %tCaller Logon ID:%t%8%n
  2838. %tPrivileges:%t%9%n
  2839. .
  2840. ;//
  2841. ;//
  2842. ;// SE_AUDITID_GLOBAL_GROUP_DELETED
  2843. ;//
  2844. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2845. ;//
  2846. ;// Parameter Strings -
  2847. ;//
  2848. ;// 1 - name of target account
  2849. ;//
  2850. ;// 2 - domain of target account
  2851. ;//
  2852. ;// 3 - SID string of target account
  2853. ;//
  2854. ;// 4 - User name of subject changing the account
  2855. ;//
  2856. ;// 5 - Domain name of subject changing the account
  2857. ;//
  2858. ;// 6 - Logon ID string of subject changing the account
  2859. ;//
  2860. ;//
  2861. MessageId=0x027A
  2862. SymbolicName=SE_AUDITID_GLOBAL_GROUP_DELETED
  2863. Language=English
  2864. Security Enabled Global Group Deleted:%n
  2865. %tTarget Account Name:%t%1%n
  2866. %tTarget Domain:%t%2%n
  2867. %tTarget Account ID:%t%3%n
  2868. %tCaller User Name:%t%4%n
  2869. %tCaller Domain:%t%5%n
  2870. %tCaller Logon ID:%t%6%n
  2871. %tPrivileges:%t%7%n
  2872. .
  2873. ;//
  2874. ;//
  2875. ;// SE_AUDITID_LOCAL_GROUP_CREATED
  2876. ;//
  2877. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2878. ;//
  2879. ;// Parameter Strings -
  2880. ;//
  2881. ;// 1 - name of new group account
  2882. ;//
  2883. ;// 2 - domain of new group account
  2884. ;//
  2885. ;// 3 - SID string of new group account
  2886. ;//
  2887. ;// 4 - User name of subject creating the account
  2888. ;//
  2889. ;// 5 - Domain name of subject creating the account
  2890. ;//
  2891. ;// 6 - Logon ID string of subject creating the account
  2892. ;//
  2893. ;//
  2894. MessageId=0x027B
  2895. SymbolicName=SE_AUDITID_LOCAL_GROUP_CREATED
  2896. Language=English
  2897. Security Enabled Local Group Created:%n
  2898. %tNew Account Name:%t%1%n
  2899. %tNew Domain:%t%2%n
  2900. %tNew Account ID:%t%3%n
  2901. %tCaller User Name:%t%4%n
  2902. %tCaller Domain:%t%5%n
  2903. %tCaller Logon ID:%t%6%n
  2904. %tPrivileges:%t%7%n
  2905. .
  2906. ;//
  2907. ;//
  2908. ;// SE_AUDITID_LOCAL_GROUP_ADD
  2909. ;//
  2910. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2911. ;//
  2912. ;// Parameter Strings -
  2913. ;//
  2914. ;// 1 - SID string of member being added
  2915. ;//
  2916. ;// 2 - name of target account
  2917. ;//
  2918. ;// 3 - domain of target account
  2919. ;//
  2920. ;// 4 - SID string of target account
  2921. ;//
  2922. ;// 5 - User name of subject changing the account
  2923. ;//
  2924. ;// 6 - Domain name of subject changing the account
  2925. ;//
  2926. ;// 7 - Logon ID string of subject changing the account
  2927. ;//
  2928. ;//
  2929. MessageId=0x027C
  2930. SymbolicName=SE_AUDITID_LOCAL_GROUP_ADD
  2931. Language=English
  2932. Security Enabled Local Group Member Added:%n
  2933. %tMember Name:%t%1%n
  2934. %tMember ID:%t%2%n
  2935. %tTarget Account Name:%t%3%n
  2936. %tTarget Domain:%t%4%n
  2937. %tTarget Account ID:%t%5%n
  2938. %tCaller User Name:%t%6%n
  2939. %tCaller Domain:%t%7%n
  2940. %tCaller Logon ID:%t%8%n
  2941. %tPrivileges:%t%9%n
  2942. .
  2943. ;//
  2944. ;//
  2945. ;// SE_AUDITID_LOCAL_GROUP_REM
  2946. ;//
  2947. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2948. ;//
  2949. ;// Parameter Strings -
  2950. ;//
  2951. ;// 1 - SID string of member being removed
  2952. ;//
  2953. ;// 2 - name of target account
  2954. ;//
  2955. ;// 3 - domain of target account
  2956. ;//
  2957. ;// 4 - SID string of target account
  2958. ;//
  2959. ;// 5 - User name of subject changing the account
  2960. ;//
  2961. ;// 6 - Domain name of subject changing the account
  2962. ;//
  2963. ;// 7 - Logon ID string of subject changing the account
  2964. ;//
  2965. ;//
  2966. MessageId=0x027D
  2967. SymbolicName=SE_AUDITID_LOCAL_GROUP_REM
  2968. Language=English
  2969. Security Enabled Local Group Member Removed:%n
  2970. %tMember Name:%t%1%n
  2971. %tMember ID:%t%2%n
  2972. %tTarget Account Name:%t%3%n
  2973. %tTarget Domain:%t%4%n
  2974. %tTarget Account ID:%t%5%n
  2975. %tCaller User Name:%t%6%n
  2976. %tCaller Domain:%t%7%n
  2977. %tCaller Logon ID:%t%8%n
  2978. %tPrivileges:%t%9%n
  2979. .
  2980. ;//
  2981. ;//
  2982. ;// SE_AUDITID_LOCAL_GROUP_DELETED
  2983. ;//
  2984. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  2985. ;//
  2986. ;// Parameter Strings -
  2987. ;//
  2988. ;// 1 - name of target account
  2989. ;//
  2990. ;// 2 - domain of target account
  2991. ;//
  2992. ;// 3 - SID string of target account
  2993. ;//
  2994. ;// 4 - User name of subject changing the account
  2995. ;//
  2996. ;// 5 - Domain name of subject changing the account
  2997. ;//
  2998. ;// 6 - Logon ID string of subject changing the account
  2999. ;//
  3000. ;//
  3001. MessageId=0x027E
  3002. SymbolicName=SE_AUDITID_LOCAL_GROUP_DELETED
  3003. Language=English
  3004. Security Enabled Local Group Deleted:%n
  3005. %tTarget Account Name:%t%1%n
  3006. %tTarget Domain:%t%2%n
  3007. %tTarget Account ID:%t%3%n
  3008. %tCaller User Name:%t%4%n
  3009. %tCaller Domain:%t%5%n
  3010. %tCaller Logon ID:%t%6%n
  3011. %tPrivileges:%t%7%n
  3012. .
  3013. ;//
  3014. ;//
  3015. ;// SE_AUDITID_LOCAL_GROUP_CHANGE
  3016. ;//
  3017. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3018. ;//
  3019. ;// Parameter Strings -
  3020. ;//
  3021. ;// 1 - name of target account
  3022. ;//
  3023. ;// 2 - domain of target account
  3024. ;//
  3025. ;// 3 - SID string of target account
  3026. ;//
  3027. ;// 4 - User name of subject changing the account
  3028. ;//
  3029. ;// 5 - Domain name of subject changing the account
  3030. ;//
  3031. ;// 6 - Logon ID string of subject changing the account
  3032. ;//
  3033. ;//
  3034. MessageId=0x027F
  3035. SymbolicName=SE_AUDITID_LOCAL_GROUP_CHANGE
  3036. Language=English
  3037. Security Enabled Local Group Changed:%n
  3038. %tTarget Account Name:%t%1%n
  3039. %tTarget Domain:%t%2%n
  3040. %tTarget Account ID:%t%3%n
  3041. %tCaller User Name:%t%4%n
  3042. %tCaller Domain:%t%5%n
  3043. %tCaller Logon ID:%t%6%n
  3044. %tPrivileges:%t%7%n
  3045. .
  3046. ;//
  3047. ;//
  3048. ;// SE_AUDITID_OTHER_ACCOUNT_CHANGE
  3049. ;//
  3050. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3051. ;//
  3052. ;// Parameter Strings -
  3053. ;//
  3054. ;// 1 - Type of change (sigh, this isn't localizable)
  3055. ;//
  3056. ;// 2 - Type of changed object
  3057. ;//
  3058. ;// 3 - SID string (of changed object)
  3059. ;//
  3060. ;// 4 - User name of subject changing the account
  3061. ;//
  3062. ;// 5 - Domain name of subject changing the account
  3063. ;//
  3064. ;// 6 - Logon ID string of subject changing the account
  3065. ;//
  3066. ;//
  3067. MessageId=0x0280
  3068. SymbolicName=SE_AUDITID_OTHER_ACCOUNT_CHANGE
  3069. Language=English
  3070. General Account Database Change:%n
  3071. %tType of change:%t%1%n
  3072. %tObject Type:%t%2%n
  3073. %tObject Name:%t%3%n
  3074. %tObject ID:%t%4%n
  3075. %tCaller User Name:%t%5%n
  3076. %tCaller Domain:%t%6%n
  3077. %tCaller Logon ID:%t%7%n
  3078. .
  3079. ;//
  3080. ;//
  3081. ;// SE_AUDITID_GLOBAL_GROUP_CHANGE
  3082. ;//
  3083. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3084. ;//
  3085. ;// Parameter Strings -
  3086. ;//
  3087. ;// 1 - name of target account
  3088. ;//
  3089. ;// 2 - domain of target account
  3090. ;//
  3091. ;// 3 - SID string of target account
  3092. ;//
  3093. ;// 4 - User name of subject changing the account
  3094. ;//
  3095. ;// 5 - Domain name of subject changing the account
  3096. ;//
  3097. ;// 6 - Logon ID string of subject changing the account
  3098. ;//
  3099. ;//
  3100. MessageId=0x0281
  3101. SymbolicName=SE_AUDITID_GLOBAL_GROUP_CHANGE
  3102. Language=English
  3103. Security Enabled Global Group Changed:%n
  3104. %tTarget Account Name:%t%1%n
  3105. %tTarget Domain:%t%2%n
  3106. %tTarget Account ID:%t%3%n
  3107. %tCaller User Name:%t%4%n
  3108. %tCaller Domain:%t%5%n
  3109. %tCaller Logon ID:%t%6%n
  3110. %tPrivileges:%t%7%n
  3111. .
  3112. ;//
  3113. ;//
  3114. ;// SE_AUDITID_USER_CHANGE
  3115. ;//
  3116. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3117. ;//
  3118. ;// Parameter Strings -
  3119. ;//
  3120. ;// 1 - name of target user account
  3121. ;//
  3122. ;// 2 - domain of target user account
  3123. ;//
  3124. ;// 3 - SID string of target user account
  3125. ;//
  3126. ;// 4 - User name of subject changing the user account
  3127. ;//
  3128. ;// 5 - Domain name of subject changing the user account
  3129. ;//
  3130. ;// 6 - Logon ID string of subject changing the user account
  3131. ;//
  3132. ;//
  3133. MessageId=0x0282
  3134. SymbolicName=SE_AUDITID_USER_CHANGE
  3135. Language=English
  3136. User Account Changed:%n
  3137. %t%1%n
  3138. %tTarget Account Name:%t%2%n
  3139. %tTarget Domain:%t%3%n
  3140. %tTarget Account ID:%t%4%n
  3141. %tCaller User Name:%t%5%n
  3142. %tCaller Domain:%t%6%n
  3143. %tCaller Logon ID:%t%7%n
  3144. %tPrivileges:%t%8%n
  3145. .
  3146. ;//
  3147. ;//
  3148. ;// SE_AUDITID_DOMAIN_POLICY_CHANGE
  3149. ;//
  3150. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3151. ;//
  3152. ;// Parameter Strings -
  3153. ;//
  3154. ;// 1 - (unused)
  3155. ;//
  3156. ;// 2 - domain of target user account
  3157. ;//
  3158. ;// 3 - SID string of target user account
  3159. ;//
  3160. ;// 4 - User name of subject changing the user account
  3161. ;//
  3162. ;// 5 - Domain name of subject changing the user account
  3163. ;//
  3164. ;// 6 - Logon ID string of subject changing the user account
  3165. ;//
  3166. ;//
  3167. MessageId=0x0283
  3168. SymbolicName=SE_AUDITID_DOMAIN_POLICY_CHANGE
  3169. Language=English
  3170. Domain Policy Changed: %1 modified%n
  3171. %tDomain Name:%t%t%2%n
  3172. %tDomain ID:%t%3%n
  3173. %tCaller User Name:%t%4%n
  3174. %tCaller Domain:%t%5%n
  3175. %tCaller Logon ID:%t%6%n
  3176. %tPrivileges:%t%7%n
  3177. .
  3178. ;//
  3179. ;//
  3180. ;// SE_AUDITID_ACCOUNT_AUTO_LOCKED
  3181. ;//
  3182. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3183. ;//
  3184. ;// Type: success / failure
  3185. ;//
  3186. ;// Description: This event is generated when an account is auto locked. This happens
  3187. ;// when a user attempts to log in unsuccessfully multiple times. The exact
  3188. ;// number of times is specified by the administrator.
  3189. ;//
  3190. ;// Parameter Strings -
  3191. ;//
  3192. ;// 1 - name of target user account
  3193. ;//
  3194. ;// 2 - domain of target user account
  3195. ;//
  3196. ;// 3 - SID string of target user account
  3197. ;//
  3198. ;// 4 - User name of subject changing the user account
  3199. ;//
  3200. ;// 5 - Domain name of subject changing the user account
  3201. ;//
  3202. ;// 6 - Logon ID string of subject changing the user account
  3203. ;//
  3204. ;//
  3205. MessageId=0x0284
  3206. SymbolicName=SE_AUDITID_ACCOUNT_AUTO_LOCKED
  3207. Language=English
  3208. User Account Locked Out:%n
  3209. %tTarget Account Name:%t%1%n
  3210. %tTarget Account ID:%t%3%n
  3211. %tCaller Machine Name:%t%2%n
  3212. %tCaller User Name:%t%4%n
  3213. %tCaller Domain:%t%5%n
  3214. %tCaller Logon ID:%t%6%n
  3215. .
  3216. ;//
  3217. ;//
  3218. ;// SE_AUDITID_COMPUTER_CREATED
  3219. ;//
  3220. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3221. ;//
  3222. ;// Parameter Strings -
  3223. ;//
  3224. ;// 1 - name of new computer account
  3225. ;//
  3226. ;// 2 - domain of new computer account
  3227. ;//
  3228. ;// 3 - SID string of new computer account
  3229. ;//
  3230. ;// 4 - User name of subject creating the computer account
  3231. ;//
  3232. ;// 5 - Domain name of subject creating the computer account
  3233. ;//
  3234. ;// 6 - Logon ID string of subject creating the computer account
  3235. ;//
  3236. ;// 7 - Privileges used to create the computer account
  3237. ;//
  3238. ;//
  3239. MessageId=0x0285
  3240. SymbolicName=SE_AUDITID_COMPUTER_CREATED
  3241. Language=English
  3242. Computer Account Created:%n
  3243. %tNew Account Name:%t%1%n
  3244. %tNew Domain:%t%2%n
  3245. %tNew Account ID:%t%3%n
  3246. %tCaller User Name:%t%4%n
  3247. %tCaller Domain:%t%5%n
  3248. %tCaller Logon ID:%t%6%n
  3249. %tPrivileges%t%t%7%n
  3250. .
  3251. ;//
  3252. ;//
  3253. ;// SE_AUDITID_COMPUTER_CHANGE
  3254. ;//
  3255. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3256. ;//
  3257. ;// Parameter Strings -
  3258. ;//
  3259. ;// 1 - name of target computer account
  3260. ;//
  3261. ;// 2 - domain of target computer account
  3262. ;//
  3263. ;// 3 - SID string of target computer account
  3264. ;//
  3265. ;// 4 - User name of subject changing the computer account
  3266. ;//
  3267. ;// 5 - Domain name of subject changing the computer account
  3268. ;//
  3269. ;// 6 - Logon ID string of subject changing the computer account
  3270. ;//
  3271. ;//
  3272. MessageId=0x0286
  3273. SymbolicName=SE_AUDITID_COMPUTER_CHANGE
  3274. Language=English
  3275. Computer Account Changed:%n
  3276. %t%1%n
  3277. %tTarget Account Name:%t%2%n
  3278. %tTarget Domain:%t%3%n
  3279. %tTarget Account ID:%t%4%n
  3280. %tCaller User Name:%t%5%n
  3281. %tCaller Domain:%t%6%n
  3282. %tCaller Logon ID:%t%7%n
  3283. %tPrivileges:%t%8%n
  3284. .
  3285. ;//
  3286. ;//
  3287. ;// SE_AUDITID_COMPUTER_DELETED
  3288. ;//
  3289. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3290. ;//
  3291. ;// Parameter Strings -
  3292. ;//
  3293. ;// 1 - name of target account
  3294. ;//
  3295. ;// 2 - domain of target account
  3296. ;//
  3297. ;// 3 - SID string of target account
  3298. ;//
  3299. ;// 4 - User name of subject changing the account
  3300. ;//
  3301. ;// 5 - Domain name of subject changing the account
  3302. ;//
  3303. ;// 6 - Logon ID string of subject changing the account
  3304. ;//
  3305. ;//
  3306. MessageId=0x0287
  3307. SymbolicName=SE_AUDITID_COMPUTER_DELETED
  3308. Language=English
  3309. Computer Account Deleted:%n
  3310. %tTarget Account Name:%t%1%n
  3311. %tTarget Domain:%t%2%n
  3312. %tTarget Account ID:%t%3%n
  3313. %tCaller User Name:%t%4%n
  3314. %tCaller Domain:%t%5%n
  3315. %tCaller Logon ID:%t%6%n
  3316. %tPrivileges:%t%7%n
  3317. .
  3318. ;//
  3319. ;//
  3320. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED
  3321. ;//
  3322. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3323. ;//
  3324. ;// Parameter Strings -
  3325. ;//
  3326. ;// 1 - name of target account
  3327. ;//
  3328. ;// 2 - domain of target account
  3329. ;//
  3330. ;// 3 - SID string of target account
  3331. ;//
  3332. ;// 4 - User name of subject changing the account
  3333. ;//
  3334. ;// 5 - Domain name of subject changing the account
  3335. ;//
  3336. ;// 6 - Logon ID string of subject changing the account
  3337. ;//
  3338. ;//
  3339. MessageId=0x0288
  3340. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CREATED
  3341. Language=English
  3342. Security Disabled Local Group Created:%n
  3343. %tTarget Account Name:%t%1%n
  3344. %tTarget Domain:%t%2%n
  3345. %tTarget Account ID:%t%3%n
  3346. %tCaller User Name:%t%4%n
  3347. %tCaller Domain:%t%5%n
  3348. %tCaller Logon ID:%t%6%n
  3349. %tPrivileges:%t%7%n
  3350. .
  3351. ;//
  3352. ;//
  3353. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE
  3354. ;//
  3355. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3356. ;//
  3357. ;// Parameter Strings -
  3358. ;//
  3359. ;// 1 - name of target account
  3360. ;//
  3361. ;// 2 - domain of target account
  3362. ;//
  3363. ;// 3 - SID string of target account
  3364. ;//
  3365. ;// 4 - User name of subject changing the account
  3366. ;//
  3367. ;// 5 - Domain name of subject changing the account
  3368. ;//
  3369. ;// 6 - Logon ID string of subject changing the account
  3370. ;//
  3371. ;//
  3372. MessageId=0x0289
  3373. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_CHANGE
  3374. Language=English
  3375. Security Disabled Local Group Changed:%n
  3376. %tTarget Account Name:%t%1%n
  3377. %tTarget Domain:%t%2%n
  3378. %tTarget Account ID:%t%3%n
  3379. %tCaller User Name:%t%4%n
  3380. %tCaller Domain:%t%5%n
  3381. %tCaller Logon ID:%t%6%n
  3382. %tPrivileges:%t%7%n
  3383. .
  3384. ;//
  3385. ;//
  3386. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD
  3387. ;//
  3388. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3389. ;//
  3390. ;// Parameter Strings -
  3391. ;//
  3392. ;// 1 - SID string of member being added
  3393. ;//
  3394. ;// 2 - name of target account
  3395. ;//
  3396. ;// 3 - domain of target account
  3397. ;//
  3398. ;// 4 - SID string of target account
  3399. ;//
  3400. ;// 5 - User name of subject changing the account
  3401. ;//
  3402. ;// 6 - Domain name of subject changing the account
  3403. ;//
  3404. ;// 7 - Logon ID string of subject changing the account
  3405. ;//
  3406. ;//
  3407. MessageId=0x028A
  3408. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_ADD
  3409. Language=English
  3410. Security Disabled Local Group Member Added:%n
  3411. %tMember Name:%t%1%n
  3412. %tMember ID:%t%2%n
  3413. %tTarget Account Name:%t%3%n
  3414. %tTarget Domain:%t%4%n
  3415. %tTarget Account ID:%t%5%n
  3416. %tCaller User Name:%t%6%n
  3417. %tCaller Domain:%t%7%n
  3418. %tCaller Logon ID:%t%8%n
  3419. %tPrivileges:%t%9%n
  3420. .
  3421. ;//
  3422. ;//
  3423. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM
  3424. ;//
  3425. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3426. ;//
  3427. ;// Parameter Strings -
  3428. ;//
  3429. ;// 1 - SID string of member being removed
  3430. ;//
  3431. ;// 2 - name of target account
  3432. ;//
  3433. ;// 3 - domain of target account
  3434. ;//
  3435. ;// 4 - SID string of target account
  3436. ;//
  3437. ;// 5 - User name of subject changing the account
  3438. ;//
  3439. ;// 6 - Domain name of subject changing the account
  3440. ;//
  3441. ;// 7 - Logon ID string of subject changing the account
  3442. ;//
  3443. ;//
  3444. MessageId=0x028B
  3445. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_REM
  3446. Language=English
  3447. Security Disabled Local Group Member Removed:%n
  3448. %tMember Name:%t%1%n
  3449. %tMember ID:%t%2%n
  3450. %tTarget Account Name:%t%3%n
  3451. %tTarget Domain:%t%4%n
  3452. %tTarget Account ID:%t%5%n
  3453. %tCaller User Name:%t%6%n
  3454. %tCaller Domain:%t%7%n
  3455. %tCaller Logon ID:%t%8%n
  3456. %tPrivileges:%t%9%n
  3457. .
  3458. ;//
  3459. ;//
  3460. ;// SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED
  3461. ;//
  3462. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3463. ;//
  3464. ;// Parameter Strings -
  3465. ;//
  3466. ;// 1 - name of target account
  3467. ;//
  3468. ;// 2 - domain of target account
  3469. ;//
  3470. ;// 3 - SID string of target account
  3471. ;//
  3472. ;// 4 - User name of subject changing the account
  3473. ;//
  3474. ;// 5 - Domain name of subject changing the account
  3475. ;//
  3476. ;// 6 - Logon ID string of subject changing the account
  3477. ;//
  3478. ;//
  3479. MessageId=0x028C
  3480. SymbolicName=SE_AUDITID_SECURITY_DISABLED_LOCAL_GROUP_DELETED
  3481. Language=English
  3482. Security Disabled Local Group Deleted:%n
  3483. %tTarget Account Name:%t%1%n
  3484. %tTarget Domain:%t%2%n
  3485. %tTarget Account ID:%t%3%n
  3486. %tCaller User Name:%t%4%n
  3487. %tCaller Domain:%t%5%n
  3488. %tCaller Logon ID:%t%6%n
  3489. %tPrivileges:%t%7%n
  3490. .
  3491. ;//
  3492. ;//
  3493. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED
  3494. ;//
  3495. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3496. ;//
  3497. ;// Parameter Strings -
  3498. ;//
  3499. ;// 1 - name of new group account
  3500. ;//
  3501. ;// 2 - domain of new group account
  3502. ;//
  3503. ;// 3 - SID string of new group account
  3504. ;//
  3505. ;// 4 - User name of subject creating the account
  3506. ;//
  3507. ;// 5 - Domain name of subject creating the account
  3508. ;//
  3509. ;// 6 - Logon ID string of subject creating the account
  3510. ;//
  3511. ;//
  3512. MessageId=0x028D
  3513. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CREATED
  3514. Language=English
  3515. Security Disabled Global Group Created:%n
  3516. %tNew Account Name:%t%1%n
  3517. %tNew Domain:%t%2%n
  3518. %tNew Account ID:%t%3%n
  3519. %tCaller User Name:%t%4%n
  3520. %tCaller Domain:%t%5%n
  3521. %tCaller Logon ID:%t%6%n
  3522. %tPrivileges:%t%7%n
  3523. .
  3524. ;//
  3525. ;//
  3526. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE
  3527. ;//
  3528. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3529. ;//
  3530. ;// Parameter Strings -
  3531. ;//
  3532. ;// 1 - name of target account
  3533. ;//
  3534. ;// 2 - domain of target account
  3535. ;//
  3536. ;// 3 - SID string of target account
  3537. ;//
  3538. ;// 4 - User name of subject changing the account
  3539. ;//
  3540. ;// 5 - Domain name of subject changing the account
  3541. ;//
  3542. ;// 6 - Logon ID string of subject changing the account
  3543. ;//
  3544. ;//
  3545. MessageId=0x028E
  3546. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_CHANGE
  3547. Language=English
  3548. Security Disabled Global Group Changed:%n
  3549. %tTarget Account Name:%t%1%n
  3550. %tTarget Domain:%t%2%n
  3551. %tTarget Account ID:%t%3%n
  3552. %tCaller User Name:%t%4%n
  3553. %tCaller Domain:%t%5%n
  3554. %tCaller Logon ID:%t%6%n
  3555. %tPrivileges:%t%7%n
  3556. .
  3557. ;//
  3558. ;//
  3559. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD
  3560. ;//
  3561. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3562. ;//
  3563. ;// Parameter Strings -
  3564. ;//
  3565. ;// 1 - SID string of member being added
  3566. ;//
  3567. ;// 2 - name of target account
  3568. ;//
  3569. ;// 3 - domain of target account
  3570. ;//
  3571. ;// 4 - SID string of target account
  3572. ;//
  3573. ;// 5 - User name of subject changing the account
  3574. ;//
  3575. ;// 6 - Domain name of subject changing the account
  3576. ;//
  3577. ;// 7 - Logon ID string of subject changing the account
  3578. ;//
  3579. ;//
  3580. MessageId=0x028F
  3581. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_ADD
  3582. Language=English
  3583. Security Disabled Global Group Member Added:%n
  3584. %tMember Name:%t%1%n
  3585. %tMember ID:%t%2%n
  3586. %tTarget Account Name:%t%3%n
  3587. %tTarget Domain:%t%4%n
  3588. %tTarget Account ID:%t%5%n
  3589. %tCaller User Name:%t%6%n
  3590. %tCaller Domain:%t%7%n
  3591. %tCaller Logon ID:%t%8%n
  3592. %tPrivileges:%t%9%n
  3593. .
  3594. ;//
  3595. ;//
  3596. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM
  3597. ;//
  3598. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3599. ;//
  3600. ;// Parameter Strings -
  3601. ;//
  3602. ;// 1 - SID string of member being removed
  3603. ;//
  3604. ;// 2 - name of target account
  3605. ;//
  3606. ;// 3 - domain of target account
  3607. ;//
  3608. ;// 4 - SID string of target account
  3609. ;//
  3610. ;// 5 - User name of subject changing the account
  3611. ;//
  3612. ;// 6 - Domain name of subject changing the account
  3613. ;//
  3614. ;// 7 - Logon ID string of subject changing the account
  3615. ;//
  3616. ;//
  3617. MessageId=0x0290
  3618. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_REM
  3619. Language=English
  3620. Security Disabled Global Group Member Removed:%n
  3621. %tMember Name:%t%1%n
  3622. %tMember ID:%t%2%n
  3623. %tTarget Account Name:%t%3%n
  3624. %tTarget Domain:%t%4%n
  3625. %tTarget Account ID:%t%5%n
  3626. %tCaller User Name:%t%6%n
  3627. %tCaller Domain:%t%7%n
  3628. %tCaller Logon ID:%t%8%n
  3629. %tPrivileges:%t%9%n
  3630. .
  3631. ;//
  3632. ;//
  3633. ;// SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED
  3634. ;//
  3635. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3636. ;//
  3637. ;// Parameter Strings -
  3638. ;//
  3639. ;// 1 - name of target account
  3640. ;//
  3641. ;// 2 - domain of target account
  3642. ;//
  3643. ;// 3 - SID string of target account
  3644. ;//
  3645. ;// 4 - User name of subject changing the account
  3646. ;//
  3647. ;// 5 - Domain name of subject changing the account
  3648. ;//
  3649. ;// 6 - Logon ID string of subject changing the account
  3650. ;//
  3651. ;//
  3652. MessageId=0x0291
  3653. SymbolicName=SE_AUDITID_SECURITY_DISABLED_GLOBAL_GROUP_DELETED
  3654. Language=English
  3655. Security Disabled Global Group Deleted:%n
  3656. %tTarget Account Name:%t%1%n
  3657. %tTarget Domain:%t%2%n
  3658. %tTarget Account ID:%t%3%n
  3659. %tCaller User Name:%t%4%n
  3660. %tCaller Domain:%t%5%n
  3661. %tCaller Logon ID:%t%6%n
  3662. %tPrivileges:%t%7%n
  3663. .
  3664. ;//
  3665. ;//
  3666. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED
  3667. ;//
  3668. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3669. ;//
  3670. ;// Parameter Strings -
  3671. ;//
  3672. ;// 1 - name of new group account
  3673. ;//
  3674. ;// 2 - domain of new group account
  3675. ;//
  3676. ;// 3 - SID string of new group account
  3677. ;//
  3678. ;// 4 - User name of subject creating the account
  3679. ;//
  3680. ;// 5 - Domain name of subject creating the account
  3681. ;//
  3682. ;// 6 - Logon ID string of subject creating the account
  3683. ;//
  3684. ;//
  3685. MessageId=0x0292
  3686. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CREATED
  3687. Language=English
  3688. Security Enabled Universal Group Created:%n
  3689. %tNew Account Name:%t%1%n
  3690. %tNew Domain:%t%2%n
  3691. %tNew Account ID:%t%3%n
  3692. %tCaller User Name:%t%4%n
  3693. %tCaller Domain:%t%5%n
  3694. %tCaller Logon ID:%t%6%n
  3695. %tPrivileges:%t%7%n
  3696. .
  3697. ;//
  3698. ;//
  3699. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE
  3700. ;//
  3701. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3702. ;//
  3703. ;// Parameter Strings -
  3704. ;//
  3705. ;// 1 - name of target account
  3706. ;//
  3707. ;// 2 - domain of target account
  3708. ;//
  3709. ;// 3 - SID string of target account
  3710. ;//
  3711. ;// 4 - User name of subject changing the account
  3712. ;//
  3713. ;// 5 - Domain name of subject changing the account
  3714. ;//
  3715. ;// 6 - Logon ID string of subject changing the account
  3716. ;//
  3717. ;//
  3718. MessageId=0x0293
  3719. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_CHANGE
  3720. Language=English
  3721. Security Enabled Universal Group Changed:%n
  3722. %tTarget Account Name:%t%1%n
  3723. %tTarget Domain:%t%2%n
  3724. %tTarget Account ID:%t%3%n
  3725. %tCaller User Name:%t%4%n
  3726. %tCaller Domain:%t%5%n
  3727. %tCaller Logon ID:%t%6%n
  3728. %tPrivileges:%t%7%n
  3729. .
  3730. ;//
  3731. ;//
  3732. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD
  3733. ;//
  3734. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3735. ;//
  3736. ;// Parameter Strings -
  3737. ;//
  3738. ;// 1 - SID string of member being added
  3739. ;//
  3740. ;// 2 - name of target account
  3741. ;//
  3742. ;// 3 - domain of target account
  3743. ;//
  3744. ;// 4 - SID string of target account
  3745. ;//
  3746. ;// 5 - User name of subject changing the account
  3747. ;//
  3748. ;// 6 - Domain name of subject changing the account
  3749. ;//
  3750. ;// 7 - Logon ID string of subject changing the account
  3751. ;//
  3752. ;//
  3753. MessageId=0x0294
  3754. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_ADD
  3755. Language=English
  3756. Security Enabled Universal Group Member Added:%n
  3757. %tMember Name:%t%1%n
  3758. %tMember ID:%t%2%n
  3759. %tTarget Account Name:%t%3%n
  3760. %tTarget Domain:%t%4%n
  3761. %tTarget Account ID:%t%5%n
  3762. %tCaller User Name:%t%6%n
  3763. %tCaller Domain:%t%7%n
  3764. %tCaller Logon ID:%t%8%n
  3765. %tPrivileges:%t%9%n
  3766. .
  3767. ;//
  3768. ;//
  3769. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM
  3770. ;//
  3771. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3772. ;//
  3773. ;// Parameter Strings -
  3774. ;//
  3775. ;// 1 - SID string of member being removed
  3776. ;//
  3777. ;// 2 - name of target account
  3778. ;//
  3779. ;// 3 - domain of target account
  3780. ;//
  3781. ;// 4 - SID string of target account
  3782. ;//
  3783. ;// 5 - User name of subject changing the account
  3784. ;//
  3785. ;// 6 - Domain name of subject changing the account
  3786. ;//
  3787. ;// 7 - Logon ID string of subject changing the account
  3788. ;//
  3789. ;//
  3790. MessageId=0x0295
  3791. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_REM
  3792. Language=English
  3793. Security Enabled Universal Group Member Removed:%n
  3794. %tMember Name:%t%1%n
  3795. %tMember ID:%t%2%n
  3796. %tTarget Account Name:%t%3%n
  3797. %tTarget Domain:%t%4%n
  3798. %tTarget Account ID:%t%5%n
  3799. %tCaller User Name:%t%6%n
  3800. %tCaller Domain:%t%7%n
  3801. %tCaller Logon ID:%t%8%n
  3802. %tPrivileges:%t%9%n
  3803. .
  3804. ;//
  3805. ;//
  3806. ;// SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED
  3807. ;//
  3808. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3809. ;//
  3810. ;// Parameter Strings -
  3811. ;//
  3812. ;// 1 - name of target account
  3813. ;//
  3814. ;// 2 - domain of target account
  3815. ;//
  3816. ;// 3 - SID string of target account
  3817. ;//
  3818. ;// 4 - User name of subject changing the account
  3819. ;//
  3820. ;// 5 - Domain name of subject changing the account
  3821. ;//
  3822. ;// 6 - Logon ID string of subject changing the account
  3823. ;//
  3824. ;//
  3825. MessageId=0x0296
  3826. SymbolicName=SE_AUDITID_SECURITY_ENABLED_UNIVERSAL_GROUP_DELETED
  3827. Language=English
  3828. Security Enabled Universal Group Deleted:%n
  3829. %tTarget Account Name:%t%1%n
  3830. %tTarget Domain:%t%2%n
  3831. %tTarget Account ID:%t%3%n
  3832. %tCaller User Name:%t%4%n
  3833. %tCaller Domain:%t%5%n
  3834. %tCaller Logon ID:%t%6%n
  3835. %tPrivileges:%t%7%n
  3836. .
  3837. ;//
  3838. ;//
  3839. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED
  3840. ;//
  3841. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3842. ;//
  3843. ;// Parameter Strings -
  3844. ;//
  3845. ;// 1 - name of new group account
  3846. ;//
  3847. ;// 2 - domain of new group account
  3848. ;//
  3849. ;// 3 - SID string of new group account
  3850. ;//
  3851. ;// 4 - User name of subject creating the account
  3852. ;//
  3853. ;// 5 - Domain name of subject creating the account
  3854. ;//
  3855. ;// 6 - Logon ID string of subject creating the account
  3856. ;//
  3857. ;//
  3858. MessageId=0x0297
  3859. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CREATED
  3860. Language=English
  3861. Security Disabled Universal Group Created:%n
  3862. %tNew Account Name:%t%1%n
  3863. %tNew Domain:%t%2%n
  3864. %tNew Account ID:%t%3%n
  3865. %tCaller User Name:%t%4%n
  3866. %tCaller Domain:%t%5%n
  3867. %tCaller Logon ID:%t%6%n
  3868. %tPrivileges:%t%7%n
  3869. .
  3870. ;//
  3871. ;//
  3872. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE
  3873. ;//
  3874. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3875. ;//
  3876. ;// Parameter Strings -
  3877. ;//
  3878. ;// 1 - name of target account
  3879. ;//
  3880. ;// 2 - domain of target account
  3881. ;//
  3882. ;// 3 - SID string of target account
  3883. ;//
  3884. ;// 4 - User name of subject changing the account
  3885. ;//
  3886. ;// 5 - Domain name of subject changing the account
  3887. ;//
  3888. ;// 6 - Logon ID string of subject changing the account
  3889. ;//
  3890. ;//
  3891. MessageId=0x0298
  3892. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_CHANGE
  3893. Language=English
  3894. Security Disabled Universal Group Changed:%n
  3895. %tTarget Account Name:%t%1%n
  3896. %tTarget Domain:%t%2%n
  3897. %tTarget Account ID:%t%3%n
  3898. %tCaller User Name:%t%4%n
  3899. %tCaller Domain:%t%5%n
  3900. %tCaller Logon ID:%t%6%n
  3901. %tPrivileges:%t%7%n
  3902. .
  3903. ;//
  3904. ;//
  3905. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD
  3906. ;//
  3907. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3908. ;//
  3909. ;// Parameter Strings -
  3910. ;//
  3911. ;// 1 - SID string of member being added
  3912. ;//
  3913. ;// 2 - name of target account
  3914. ;//
  3915. ;// 3 - domain of target account
  3916. ;//
  3917. ;// 4 - SID string of target account
  3918. ;//
  3919. ;// 5 - User name of subject changing the account
  3920. ;//
  3921. ;// 6 - Domain name of subject changing the account
  3922. ;//
  3923. ;// 7 - Logon ID string of subject changing the account
  3924. ;//
  3925. ;//
  3926. MessageId=0x0299
  3927. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_ADD
  3928. Language=English
  3929. Security Disabled Universal Group Member Added:%n
  3930. %tMember Name:%t%1%n
  3931. %tMember ID:%t%2%n
  3932. %tTarget Account Name:%t%3%n
  3933. %tTarget Domain:%t%4%n
  3934. %tTarget Account ID:%t%5%n
  3935. %tCaller User Name:%t%6%n
  3936. %tCaller Domain:%t%7%n
  3937. %tCaller Logon ID:%t%8%n
  3938. %tPrivileges:%t%9%n
  3939. .
  3940. ;//
  3941. ;//
  3942. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM
  3943. ;//
  3944. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3945. ;//
  3946. ;// Parameter Strings -
  3947. ;//
  3948. ;// 1 - SID string of member being removed
  3949. ;//
  3950. ;// 2 - name of target account
  3951. ;//
  3952. ;// 3 - domain of target account
  3953. ;//
  3954. ;// 4 - SID string of target account
  3955. ;//
  3956. ;// 5 - User name of subject changing the account
  3957. ;//
  3958. ;// 6 - Domain name of subject changing the account
  3959. ;//
  3960. ;// 7 - Logon ID string of subject changing the account
  3961. ;//
  3962. ;//
  3963. MessageId=0x029A
  3964. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_REM
  3965. Language=English
  3966. Security Disabled Universal Group Member Removed:%n
  3967. %tMember Name:%t%1%n
  3968. %tMember ID:%t%2%n
  3969. %tTarget Account Name:%t%3%n
  3970. %tTarget Domain:%t%4%n
  3971. %tTarget Account ID:%t%5%n
  3972. %tCaller User Name:%t%6%n
  3973. %tCaller Domain:%t%7%n
  3974. %tCaller Logon ID:%t%8%n
  3975. %tPrivileges:%t%9%n
  3976. .
  3977. ;//
  3978. ;//
  3979. ;// SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED
  3980. ;//
  3981. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  3982. ;//
  3983. ;// Parameter Strings -
  3984. ;//
  3985. ;// 1 - name of target account
  3986. ;//
  3987. ;// 2 - domain of target account
  3988. ;//
  3989. ;// 3 - SID string of target account
  3990. ;//
  3991. ;// 4 - User name of subject changing the account
  3992. ;//
  3993. ;// 5 - Domain name of subject changing the account
  3994. ;//
  3995. ;// 6 - Logon ID string of subject changing the account
  3996. ;//
  3997. ;//
  3998. MessageId=0x029B
  3999. SymbolicName=SE_AUDITID_SECURITY_DISABLED_UNIVERSAL_GROUP_DELETED
  4000. Language=English
  4001. Security Disabled Universal Group Deleted:%n
  4002. %tTarget Account Name:%t%1%n
  4003. %tTarget Domain:%t%2%n
  4004. %tTarget Account ID:%t%3%n
  4005. %tCaller User Name:%t%4%n
  4006. %tCaller Domain:%t%5%n
  4007. %tCaller Logon ID:%t%6%n
  4008. %tPrivileges:%t%7%n
  4009. .
  4010. ;//
  4011. ;//
  4012. ;// SE_AUDITID_GROUP_TYPE_CHANGE
  4013. ;//
  4014. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4015. ;//
  4016. ;// Parameter Strings -
  4017. ;//
  4018. ;// 1 - nature of group type change
  4019. ;//
  4020. ;// 2 - name of target account
  4021. ;//
  4022. ;// 3 - domain of target account
  4023. ;//
  4024. ;// 4 - SID string of target account
  4025. ;//
  4026. ;// 5 - User name of subject changing the account
  4027. ;//
  4028. ;// 6 - Domain name of subject changing the account
  4029. ;//
  4030. ;// 7 - Logon ID string of subject changing the account
  4031. ;//
  4032. ;//
  4033. MessageId=0x029C
  4034. SymbolicName=SE_AUDITID_GROUP_TYPE_CHANGE
  4035. Language=English
  4036. Group Type Changed:%n
  4037. %t%1%n
  4038. %tTarget Account Name:%t%2%n
  4039. %tTarget Domain:%t%3%n
  4040. %tTarget Account ID:%t%4%n
  4041. %tCaller User Name:%t%5%n
  4042. %tCaller Domain:%t%6%n
  4043. %tCaller Logon ID:%t%7%n
  4044. %tPrivileges:%t%8%n
  4045. .
  4046. ;//
  4047. ;//
  4048. ;// SE_AUDITID_ADD_SID_HISTORY
  4049. ;//
  4050. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4051. ;//
  4052. ;// Parameter Strings -
  4053. ;//
  4054. ;// 1 - SID string of the source account
  4055. ;//
  4056. ;// 2 - Name of the source account (including domain name)
  4057. ;//
  4058. ;// 3 - Name of the target account
  4059. ;//
  4060. ;// 4 - Domain name of subject changing the SID history
  4061. ;//
  4062. ;// 5 - SID String of the target account
  4063. ;//
  4064. ;// 6 - Logon ID string of subject changing the user account
  4065. ;//
  4066. ;//
  4067. MessageId=0x029D
  4068. SymbolicName=SE_AUDITID_ADD_SID_HISTORY
  4069. Language=English
  4070. Add SID History:%n
  4071. %tSource Account Name:%t%1%n
  4072. %tSource Account ID:%t%2%n
  4073. %tTarget Account Name:%t%3%n
  4074. %tTarget Domain:%t%4%n
  4075. %tTarget Account ID:%t%5%n
  4076. %tCaller User Name:%t%6%n
  4077. %tCaller Domain:%t%7%n
  4078. %tCaller Logon ID:%t%8%n
  4079. %tPrivileges:%t%9%n
  4080. .
  4081. ;//
  4082. ;//
  4083. ;// SE_AUDITID_ACCOUNT_UNLOCKED
  4084. ;//
  4085. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4086. ;//
  4087. ;// Parameter Strings -
  4088. ;//
  4089. ;// 1 - name of target user account
  4090. ;//
  4091. ;// 2 - domain of target user account
  4092. ;//
  4093. ;// 3 - SID string of target user account
  4094. ;//
  4095. ;// 4 - User name of subject changing the user account
  4096. ;//
  4097. ;// 5 - Domain name of subject changing the user account
  4098. ;//
  4099. ;// 6 - Logon ID string of subject changing the user account
  4100. ;//
  4101. ;//
  4102. MessageId=0x029F
  4103. SymbolicName=SE_AUDITID_ACCOUNT_UNLOCKED
  4104. Language=English
  4105. User Account Unlocked:%n
  4106. %tTarget Account Name:%t%1%n
  4107. %tTarget Domain:%t%t%2%n
  4108. %tTarget Account ID:%t%3%n
  4109. %tCaller User Name:%t%4%n
  4110. %tCaller Domain:%t%5%n
  4111. %tCaller Logon ID:%t%6%n
  4112. .
  4113. ;//
  4114. ;//
  4115. ;// SE_AUDITID_SECURE_ADMIN_GROUP
  4116. ;//
  4117. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4118. ;//
  4119. ;// Parameter Strings -
  4120. ;//
  4121. ;// 1 - (unused)
  4122. ;//
  4123. ;// 2 - domain of target user account
  4124. ;//
  4125. ;// 3 - SID string of target user account
  4126. ;//
  4127. ;// 4 - User name of subject changing the user account
  4128. ;//
  4129. ;// 5 - Domain name of subject changing the user account
  4130. ;//
  4131. ;// 6 - Logon ID string of subject changing the user account
  4132. ;//
  4133. ;//
  4134. ;//
  4135. MessageId=0x02AC
  4136. SymbolicName=SE_AUDITID_SECURE_ADMIN_GROUP
  4137. Language=English
  4138. Set ACLs of members in administrators groups:%n
  4139. %tTarget Account Name:%t%1%n
  4140. %tTarget Domain:%t%t%2%n
  4141. %tTarget Account ID:%t%3%n
  4142. %tCaller User Name:%t%4%n
  4143. %tCaller Domain:%t%5%n
  4144. %tCaller Logon ID:%t%6%n
  4145. %tPrivileges:%t%7%n
  4146. .
  4147. ;//
  4148. ;//
  4149. ;// SE_AUDITID_ACCOUNT_NAME_CHANGE
  4150. ;//
  4151. ;// Category: SE_CATEGID_ACCOUNT_MANAGEMENT
  4152. ;//
  4153. ;// Parameter Strings -
  4154. ;//
  4155. ;// 1 - name of target account
  4156. ;//
  4157. ;// 2 - domain of target account
  4158. ;//
  4159. ;// 3 - SID string of target account
  4160. ;//
  4161. ;// 4 - Account name of subject changing the account
  4162. ;//
  4163. ;// 5 - Domain name of subject changing the account
  4164. ;//
  4165. ;// 6 - Logon ID string of subject changing the account
  4166. ;//
  4167. ;//
  4168. ;//
  4169. MessageId=0x02AD
  4170. SymbolicName=SE_AUDITID_ACCOUNT_NAME_CHANGE
  4171. Language=English
  4172. Account Name Changed:%n
  4173. %tOld Account Name:%t%1%n
  4174. %tNew Account Name:%t%2%n
  4175. %tTarget Domain:%t%t%3%n
  4176. %tTarget Account ID:%t%4%n
  4177. %tCaller User Name:%t%5%n
  4178. %tCaller Domain:%t%6%n
  4179. %tCaller Logon ID:%t%7%n
  4180. %tPrivileges:%t%8%n
  4181. .
  4182. ;
  4183. ;/////////////////////////////////////////////////////////////////////////////
  4184. ;// //
  4185. ;// //
  4186. ;// Messages for Category: SE_CATEGID_ACCOUNT_LOGON //
  4187. ;// //
  4188. ;// Event IDs: //
  4189. ;// SE_AUDITID_AS_TICKET //
  4190. ;// SE_AUDITID_TGS_TICKET_SUCCESS //
  4191. ;// SE_AUDITID_TICKET_RENEW_SUCCESS //
  4192. ;// SE_AUDITID_PREAUTH_FAILURE //
  4193. ;// SE_AUDITID_TGS_TICKET_FAILURE //
  4194. ;// SE_AUDITID_ACCOUNT_MAPPED //
  4195. ;// SE_AUDITID_ACCOUNT_LOGON //
  4196. ;// //
  4197. ;/////////////////////////////////////////////////////////////////////////////
  4198. ;//
  4199. ;//
  4200. ;// SE_AUDITID_AS_TICKET
  4201. ;//
  4202. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4203. ;//
  4204. ;// Parameter Strings -
  4205. ;//
  4206. ;// 1 - User name of client
  4207. ;//
  4208. ;// 2 - Supplied realm name
  4209. ;//
  4210. ;// 3 - SID of client user
  4211. ;//
  4212. ;// 4 - User name of service
  4213. ;//
  4214. ;// 5 - SID of service
  4215. ;//
  4216. ;// 6 - Ticket Options
  4217. ;//
  4218. ;// 7 - Failure code
  4219. ;//
  4220. ;// 8 - Ticket Encryption Type
  4221. ;//
  4222. ;// 9 - Preauthentication type (i.e. PK_INIT)
  4223. ;//
  4224. ;// 10 - Client IP address
  4225. ;//
  4226. MessageId=0x02a0
  4227. SymbolicName=SE_AUDITID_AS_TICKET
  4228. Language=English
  4229. Authentication Ticket Request:%n
  4230. %tUser Name:%t%t%1%n
  4231. %tSupplied Realm Name:%t%2%n
  4232. %tUser ID:%t%3%n
  4233. %tService Name:%t%t%4%n
  4234. %tService ID:%t%t%5%n
  4235. %tTicket Options:%t%t%6%n
  4236. %tResult Code:%t%t%7%n
  4237. %tTicket Encryption Type:%t%8%n
  4238. %tPre-Authentication Type:%t%9%n
  4239. %tClient Address:%t%t%10%n
  4240. .
  4241. ;//
  4242. ;//
  4243. ;// SE_AUDITID_TGS_TICKET_SUCCESS
  4244. ;//
  4245. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4246. ;//
  4247. ;// Parameter Strings -
  4248. ;//
  4249. ;// 1 - User name of client
  4250. ;//
  4251. ;// 2 - Domain name of client
  4252. ;//
  4253. ;// 3 - User name of service
  4254. ;//
  4255. ;// 4 - SID of service
  4256. ;//
  4257. ;// 5 - Ticket Options
  4258. ;//
  4259. ;// 6 - Ticket Encryption Type
  4260. ;//
  4261. ;// 7 - Client IP address
  4262. ;//
  4263. MessageId=0x02a1
  4264. SymbolicName=SE_AUDITID_TGS_TICKET_REQUEST
  4265. Language=English
  4266. Service Ticket Request:%n
  4267. %tUser Name:%t%t%1%n
  4268. %tUser Domain:%t%t%2%n
  4269. %tService Name:%t%t%3%n
  4270. %tService ID:%t%t%4%n
  4271. %tTicket Options:%t%t%5%n
  4272. %tTicket Encryption Type:%t%6%n
  4273. %tClient Address:%t%t%7%n
  4274. %tFailure Code:%t%t%8%n
  4275. .
  4276. ;//
  4277. ;//
  4278. ;// SE_AUDITID_TICKET_RENEW_SUCCESS
  4279. ;//
  4280. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4281. ;//
  4282. ;// Parameter Strings -
  4283. ;//
  4284. ;// 1 - User name of client
  4285. ;//
  4286. ;// 2 - Domain name of client
  4287. ;//
  4288. ;// 3 - User name of service
  4289. ;//
  4290. ;// 4 - SID of service
  4291. ;//
  4292. ;// 5 - Ticket Options
  4293. ;//
  4294. ;// 6 - Ticket Encryption Type
  4295. ;//
  4296. ;// 7 - Client IP address
  4297. ;//
  4298. MessageId=0x02a2
  4299. SymbolicName=SE_AUDITID_TICKET_RENEW_SUCCESS
  4300. Language=English
  4301. Ticket Granted Renewed:%n
  4302. %tUser Name:%t%1%n
  4303. %tUser Domain:%t%2%n
  4304. %tService Name:%t%3%n
  4305. %tService ID:%t%4%n
  4306. %tTicket Options:%t%5%n
  4307. %tTicket Encryption Type:%t%6%n
  4308. %tClient Address:%t%7%n
  4309. .
  4310. ;//
  4311. ;//
  4312. ;// SE_AUDITID_PREAUTH_FAILURE
  4313. ;//
  4314. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4315. ;//
  4316. ;// Parameter Strings -
  4317. ;//
  4318. ;// 1 - User name of client
  4319. ;//
  4320. ;// 2 - SID of client user
  4321. ;//
  4322. ;// 3 - User name of service
  4323. ;//
  4324. ;// 4 - Preauth Type
  4325. ;//
  4326. ;// 5 - Failure code
  4327. ;//
  4328. ;// 6 - Client IP address
  4329. ;//
  4330. ;// Event type: failure
  4331. ;// Description: This event is generated on a KDC when
  4332. ;// preauthentication fails (user types in wrong password).
  4333. ;//
  4334. MessageId=0x02a3
  4335. SymbolicName=SE_AUDITID_PREAUTH_FAILURE
  4336. Language=English
  4337. Pre-authentication failed:%n
  4338. %tUser Name:%t%t%1%n
  4339. %tUser ID:%t%t%2%n
  4340. %tService Name:%t%t%3%n
  4341. %tPre-Authentication Type:%t%4%n
  4342. %tFailure Code:%t%t%5%n
  4343. %tClient Address:%t%t%6%n
  4344. .
  4345. ;//
  4346. ;//
  4347. ;// SE_AUDITID_TGS_TICKET_FAILURE
  4348. ;//
  4349. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4350. ;//
  4351. ;// Parameter Strings -
  4352. ;//
  4353. ;// 1 - User name of client
  4354. ;//
  4355. ;// 2 - Domain name of client
  4356. ;//
  4357. ;// 3 - User name of service
  4358. ;//
  4359. ;// 4 - Ticket Options
  4360. ;//
  4361. ;// 5 - Failure code
  4362. ;//
  4363. ;// 6 - Client IP address
  4364. ;//
  4365. MessageId=0x02a5
  4366. SymbolicName=SE_AUDITID_TGS_TICKET_FAILURE
  4367. Language=English
  4368. Service Ticket Request Failed:%n
  4369. %tUser Name:%t%1%n
  4370. %tUser Domain:%t%2%n
  4371. %tService Name:%t%3%n
  4372. %tTicket Options:%t%4%n
  4373. %tFailure Code:%t%5%n
  4374. %tClient Address:%t%6%n
  4375. .
  4376. ;//
  4377. ;//
  4378. ;// SE_AUDITID_ACCOUNT_MAPPED
  4379. ;//
  4380. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4381. ;//
  4382. ;// Type: success / failure
  4383. ;//
  4384. ;// Description: An account mapping is a map of a user authenticated in an MIT realm to a
  4385. ;// domain account. A mapping acts much like a logon. Hence, it is important to audit this.
  4386. ;//
  4387. ;// Parameter Strings -
  4388. ;//
  4389. ;// 1 - Source
  4390. ;//
  4391. ;// 2 - Client Name
  4392. ;//
  4393. ;// 3 - Mapped Name
  4394. ;//
  4395. ;//
  4396. ;//
  4397. MessageId=0x02a6
  4398. SymbolicName=SE_AUDITID_ACCOUNT_MAPPED
  4399. Language=English
  4400. Account Mapped for Logon.%n
  4401. Mapping Attempted By:%n
  4402. %t%1%n
  4403. Client Name:%n
  4404. %t%2%n
  4405. %tMapped Name:%n
  4406. %t%3%n
  4407. .
  4408. ;//
  4409. ;//
  4410. ;// SE_AUDITID_ACCOUNT_LOGON
  4411. ;//
  4412. ;// Category: SE_CATEGID_ACCOUNT_LOGON
  4413. ;//
  4414. ;// Type: Success / Failure
  4415. ;//
  4416. ;// Description: This audits a logon attempt. The audit appears on the DC.
  4417. ;// This is generated by calling LogonUser.
  4418. ;//
  4419. ;//
  4420. MessageId=0x02a9
  4421. SymbolicName=SE_AUDITID_ACCOUNT_LOGON
  4422. Language=English
  4423. Logon attempt by: %1%n
  4424. Logon account: %2%n
  4425. Source Workstation: %3%n
  4426. Error Code: %4%n
  4427. .
  4428. ;//
  4429. ;//
  4430. ;// SE_AUDITID_SESSION_RECONNECTED
  4431. ;//
  4432. ;// Category: SE_CATEGID_LOGON
  4433. ;//
  4434. ;// Parameter Strings -
  4435. ;//
  4436. ;// 1 - User account name
  4437. ;//
  4438. ;// 2 - Authenticating domain name
  4439. ;//
  4440. ;// 3 - Logon ID string
  4441. ;//
  4442. ;// 4 - Session Name
  4443. ;//
  4444. ;// 5 - Client Name
  4445. ;//
  4446. ;// 6 - Client Address
  4447. ;//
  4448. ;//
  4449. MessageId=0x02aa
  4450. SymbolicName=SE_AUDITID_SESSION_RECONNECTED
  4451. Language=English
  4452. Session reconnected to winstation:%n
  4453. %tUser Name:%t%1%n
  4454. %tDomain:%t%t%2%n
  4455. %tLogon ID:%t%t%3%n
  4456. %tSession Name:%t%4%n
  4457. %tClient Name:%t%5%n
  4458. %tClient Address:%t%6
  4459. .
  4460. ;//
  4461. ;//
  4462. ;// SE_AUDITID_SESSION_DISCONNECTED
  4463. ;//
  4464. ;// Category: SE_CATEGID_LOGON
  4465. ;//
  4466. ;// Parameter Strings -
  4467. ;//
  4468. ;// 1 - User account name
  4469. ;//
  4470. ;// 2 - Authenticating domain name
  4471. ;//
  4472. ;// 3 - Logon ID string
  4473. ;//
  4474. ;// 4 - Session Name
  4475. ;//
  4476. ;// 5 - Client Name
  4477. ;//
  4478. ;// 6 - Client Address
  4479. ;//
  4480. ;//
  4481. MessageId=0x02ab
  4482. SymbolicName=SE_AUDITID_SESSION_DISCONNECTED
  4483. Language=English
  4484. Session disconnected from winstation:%n
  4485. %tUser Name:%t%1%n
  4486. %tDomain:%t%t%2%n
  4487. %tLogon ID:%t%t%3%n
  4488. %tSession Name:%t%4%n
  4489. %tClient Name:%t%5%n
  4490. %tClient Address:%t%6
  4491. .
  4492. ;/////////////////////////////////////////////////////////////////////////////
  4493. ;// //
  4494. ;// //
  4495. ;// Messages for Category: SE_CATEGID_OBJECT_ACCESS - CertSrv //
  4496. ;// //
  4497. ;// Event IDs: //
  4498. ;// SE_AUDITID_CERTSRV_DENYREQUEST //
  4499. ;// SE_AUDITID_CERTSRV_RESUBMITREQUEST //
  4500. ;// SE_AUDITID_CERTSRV_REVOKECERT //
  4501. ;// SE_AUDITID_CERTSRV_PUBLISHCRL //
  4502. ;// SE_AUDITID_CERTSRV_AUTOPUBLISHCRL //
  4503. ;// SE_AUDITID_CERTSRV_SETEXTENSION //
  4504. ;// SE_AUDITID_CERTSRV_SETATTRIBUTES //
  4505. ;// SE_AUDITID_CERTSRV_SHUTDOWN //
  4506. ;// SE_AUDITID_CERTSRV_BACKUPSTART //
  4507. ;// SE_AUDITID_CERTSRV_BACKUPEND //
  4508. ;// SE_AUDITID_CERTSRV_RESTORESTART //
  4509. ;// SE_AUDITID_CERTSRV_RESTOREEND //
  4510. ;// SE_AUDITID_CERTSRV_SERVICESTART //
  4511. ;// SE_AUDITID_CERTSRV_SERVICESTOP //
  4512. ;// SE_AUDITID_CERTSRV_SETSECURITY //
  4513. ;// SE_AUDITID_CERTSRV_GETARCHIVEDKEY //
  4514. ;// SE_AUDITID_CERTSRV_IMPORTCERT //
  4515. ;// SE_AUDITID_CERTSRV_SETAUDITFILTER //
  4516. ;// SE_AUDITID_CERTSRV_NEWREQUEST //
  4517. ;// SE_AUDITID_CERTSRV_REQUESTAPPROVED //
  4518. ;// SE_AUDITID_CERTSRV_REQUESTDENIED //
  4519. ;// SE_AUDITID_CERTSRV_REQUESTPENDING //
  4520. ;// SE_AUDITID_CERTSRV_SETOFFICERRIGHTS //
  4521. ;// SE_AUDITID_CERTSRV_SETCONFIGENTRY //
  4522. ;// SE_AUDITID_CERTSRV_SETCAPROPERTY //
  4523. ;// SE_AUDITID_CERTSRV_KEYARCHIVED //
  4524. ;// SE_AUDITID_CERTSRV_IMPORTKEY //
  4525. ;// SE_AUDITID_CERTSRV_PUBLISHCERT //
  4526. ;// //
  4527. ;// //
  4528. ;/////////////////////////////////////////////////////////////////////////////
  4529. ;//
  4530. ;//
  4531. ;// SE_AUDITID_CERTSRV_DENYREQUEST
  4532. ;//
  4533. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4534. ;//
  4535. ;// Parameter Strings -
  4536. ;//
  4537. ;// 1 - Request ID
  4538. ;//
  4539. ;//
  4540. MessageId=0x0304
  4541. SymbolicName=SE_AUDITID_CERTSRV_DENYREQUEST
  4542. Language=English
  4543. The certificate manager denied a pending certificate request.%n
  4544. %n
  4545. Request ID:%t%1
  4546. .
  4547. ;//
  4548. ;//
  4549. ;// SE_AUDITID_CERTSRV_RESUBMITREQUEST
  4550. ;//
  4551. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4552. ;//
  4553. ;// Parameter Strings -
  4554. ;//
  4555. ;// 1 - Request ID
  4556. ;//
  4557. ;//
  4558. MessageId=0x0305
  4559. SymbolicName=SE_AUDITID_CERTSRV_RESUBMITREQUEST
  4560. Language=English
  4561. Certificate Services received a resubmitted certificate request.%n
  4562. %n
  4563. Request ID:%t%1
  4564. .
  4565. ;//
  4566. ;//
  4567. ;// SE_AUDITID_CERTSRV_REVOKECERT
  4568. ;//
  4569. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4570. ;//
  4571. ;// Parameter Strings -
  4572. ;//
  4573. ;// 1 - Serial No.
  4574. ;//
  4575. ;// 2 - Reason
  4576. ;//
  4577. ;//
  4578. MessageId=0x0306
  4579. SymbolicName=SE_AUDITID_CERTSRV_REVOKECERT
  4580. Language=English
  4581. Certificate Services revoked a certificate.%n
  4582. %n
  4583. Serial No:%t%1%n
  4584. Reason:%t%2
  4585. .
  4586. ;//
  4587. ;//
  4588. ;// SE_AUDITID_CERTSRV_PUBLISHCRL
  4589. ;//
  4590. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4591. ;//
  4592. ;// Parameter Strings -
  4593. ;//
  4594. ;// 1 - Next Update
  4595. ;//
  4596. ;// 2 - Publish Base
  4597. ;//
  4598. ;// 3 - Publish Delta
  4599. ;//
  4600. ;//
  4601. MessageId=0x0307
  4602. SymbolicName=SE_AUDITID_CERTSRV_PUBLISHCRL
  4603. Language=English
  4604. Certificate Services received a request to publish the certificate revocation list (CRL).%n
  4605. %n
  4606. Next Update:%t%1%n
  4607. Publish Base:%t%2%n
  4608. Publish Delta:%t%3
  4609. .
  4610. ;//
  4611. ;//
  4612. ;// SE_AUDITID_CERTSRV_AUTOPUBLISHCRL
  4613. ;//
  4614. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4615. ;//
  4616. ;// Parameter Strings -
  4617. ;//
  4618. ;// 1 - Base CRL
  4619. ;//
  4620. ;// 2 - CRL No.
  4621. ;//
  4622. ;// 3 - Key Container
  4623. ;//
  4624. ;// 4 - Next Publish
  4625. ;//
  4626. ;// 5 - Publish URLs
  4627. ;//
  4628. ;//
  4629. MessageId=0x0308
  4630. SymbolicName=SE_AUDITID_CERTSRV_AUTOPUBLISHCRL
  4631. Language=English
  4632. Certificate Services published the certificate revocation list (CRL).%n
  4633. %n
  4634. Base CRL:%t%1%n
  4635. CRL No:%t%t%2%n
  4636. Key Container%t%3%n
  4637. Next Publish%t%4%n
  4638. Publish URLs:%t%5
  4639. .
  4640. ;//
  4641. ;//
  4642. ;// SE_AUDITID_CERTSRV_SETEXTENSION
  4643. ;//
  4644. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4645. ;//
  4646. ;// Parameter Strings -
  4647. ;//
  4648. ;// 1 - Request ID
  4649. ;//
  4650. ;// 2 - Extension Name
  4651. ;//
  4652. ;// 3 - Extension Type
  4653. ;//
  4654. ;// 4 - Flags
  4655. ;//
  4656. ;// 5 - Extension Data
  4657. ;//
  4658. ;//
  4659. MessageId=0x0309
  4660. SymbolicName=SE_AUDITID_CERTSRV_SETEXTENSION
  4661. Language=English
  4662. A certificate request extension changed.%n
  4663. %n
  4664. Request ID:%t%1%n
  4665. Name:%t%2%n
  4666. Type:%t%3%n
  4667. Flags:%t%4%n
  4668. Data:%t%5
  4669. .
  4670. ;//
  4671. ;//
  4672. ;// SE_AUDITID_CERTSRV_SETATTRIBUTES
  4673. ;//
  4674. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4675. ;//
  4676. ;// Parameter Strings -
  4677. ;//
  4678. ;// 1 - Request ID
  4679. ;//
  4680. ;// 2 - Attributes
  4681. ;//
  4682. ;//
  4683. MessageId=0x030a
  4684. SymbolicName=SE_AUDITID_CERTSRV_SETATTRIBUTES
  4685. Language=English
  4686. One or more certificate request attributes changed.%n
  4687. %n
  4688. Request ID:%t%1%n
  4689. Attributes:%t%2
  4690. .
  4691. ;//
  4692. ;//
  4693. ;// SE_AUDITID_CERTSRV_SHUTDOWN
  4694. ;//
  4695. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4696. ;//
  4697. ;// Parameter Strings -
  4698. ;//
  4699. ;//
  4700. MessageId=0x030b
  4701. SymbolicName=SE_AUDITID_CERTSRV_SHUTDOWN
  4702. Language=English
  4703. Certificate Services received a request to shut down.
  4704. .
  4705. ;//
  4706. ;//
  4707. ;// SE_AUDITID_CERTSRV_BACKUPSTART
  4708. ;//
  4709. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4710. ;//
  4711. ;// Parameter Strings -
  4712. ;//
  4713. ;// 1 - Backup Type
  4714. ;//
  4715. ;//
  4716. MessageId=0x030c
  4717. SymbolicName=SE_AUDITID_CERTSRV_BACKUPSTART
  4718. Language=English
  4719. Certificate Services backup started.%n
  4720. Backup Type:%t%1
  4721. .
  4722. ;//
  4723. ;//
  4724. ;// SE_AUDITID_CERTSRV_BACKUPEND
  4725. ;//
  4726. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4727. ;//
  4728. ;// Parameter Strings -
  4729. ;//
  4730. ;//
  4731. MessageId=0x030d
  4732. SymbolicName=SE_AUDITID_CERTSRV_BACKUPEND
  4733. Language=English
  4734. Certificate Services backup completed.
  4735. .
  4736. ;//
  4737. ;//
  4738. ;// SE_AUDITID_CERTSRV_RESTORESTART
  4739. ;//
  4740. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4741. ;//
  4742. ;// Parameter Strings -
  4743. ;//
  4744. ;//
  4745. MessageId=0x030e
  4746. SymbolicName=SE_AUDITID_CERTSRV_RESTORESTART
  4747. Language=English
  4748. Certificate Services restore started.
  4749. .
  4750. ;//
  4751. ;//
  4752. ;// SE_AUDITID_CERTSRV_RESTOREEND
  4753. ;//
  4754. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4755. ;//
  4756. ;// Parameter Strings -
  4757. ;//
  4758. ;//
  4759. MessageId=0x030f
  4760. SymbolicName=SE_AUDITID_CERTSRV_RESTOREEND
  4761. Language=English
  4762. Certificate Services restore completed.
  4763. .
  4764. ;//
  4765. ;//
  4766. ;// SE_AUDITID_CERTSRV_SERVICESTART
  4767. ;//
  4768. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4769. ;//
  4770. ;// Parameter Strings -
  4771. ;//
  4772. ;// 1 - Database Hash
  4773. ;//
  4774. ;// 2 - Key Usage Count
  4775. ;//
  4776. ;//
  4777. MessageId=0x0310
  4778. SymbolicName=SE_AUDITID_CERTSRV_SERVICESTART
  4779. Language=English
  4780. Certificate Services started.%n
  4781. %n
  4782. Database Hash:%t%1%n
  4783. Key Usage Count:%t%2
  4784. .
  4785. ;//
  4786. ;//
  4787. ;// SE_AUDITID_CERTSRV_SERVICESTOP
  4788. ;//
  4789. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4790. ;//
  4791. ;// Parameter Strings -
  4792. ;//
  4793. ;// 1 - Database Hash
  4794. ;//
  4795. ;// 2 - Key Usage Count
  4796. ;//
  4797. ;//
  4798. MessageId=0x0311
  4799. SymbolicName=SE_AUDITID_CERTSRV_SERVICESTOP
  4800. Language=English
  4801. Certificate Services stopped.%n
  4802. %n
  4803. Database Hash:%t%1%n
  4804. Key Usage Count:%t%2
  4805. .
  4806. ;//
  4807. ;//
  4808. ;// SE_AUDITID_CERTSRV_SETSECURITY
  4809. ;//
  4810. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4811. ;//
  4812. ;// Parameter Strings -
  4813. ;//
  4814. ;// 1 - New permissions
  4815. ;//
  4816. ;//
  4817. MessageId=0x0312
  4818. SymbolicName=SE_AUDITID_CERTSRV_SETSECURITY
  4819. Language=English
  4820. The security permissions for Certificate Services changed.%n
  4821. %n
  4822. %1
  4823. .
  4824. ;//
  4825. ;//
  4826. ;// SE_AUDITID_CERTSRV_GETARCHIVEDKEY
  4827. ;//
  4828. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4829. ;//
  4830. ;// Parameter Strings -
  4831. ;//
  4832. ;// 1 - Request ID
  4833. ;//
  4834. ;//
  4835. MessageId=0x0313
  4836. SymbolicName=SE_AUDITID_CERTSRV_GETARCHIVEDKEY
  4837. Language=English
  4838. Certificate Services retrieved an archived key.%n
  4839. %n
  4840. Request ID:%t%1
  4841. .
  4842. ;//
  4843. ;//
  4844. ;// SE_AUDITID_CERTSRV_IMPORTCERT
  4845. ;//
  4846. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4847. ;//
  4848. ;// Parameter Strings -
  4849. ;//
  4850. ;// 1 - Certificate
  4851. ;//
  4852. ;// 2 - Request ID
  4853. ;//
  4854. ;//
  4855. MessageId=0x0314
  4856. SymbolicName=SE_AUDITID_CERTSRV_IMPORTCERT
  4857. Language=English
  4858. Certificate Services imported a certificate into its database.%n
  4859. %n
  4860. Certificate:%t%1%n
  4861. Request ID:%t%2
  4862. .
  4863. ;//
  4864. ;//
  4865. ;// SE_AUDITID_CERTSRV_SETAUDITFILTER
  4866. ;//
  4867. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4868. ;//
  4869. ;// Parameter Strings -
  4870. ;//
  4871. ;// 1 - Filter
  4872. ;//
  4873. ;//
  4874. MessageId=0x0315
  4875. SymbolicName=SE_AUDITID_CERTSRV_SETAUDITFILTER
  4876. Language=English
  4877. The audit filter for Certificate Services changed.%n
  4878. %n
  4879. Filter:%t%1
  4880. .
  4881. ;//
  4882. ;//
  4883. ;// SE_AUDITID_CERTSRV_NEWREQUEST
  4884. ;//
  4885. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4886. ;//
  4887. ;// Parameter Strings -
  4888. ;//
  4889. ;// 1 - Request ID
  4890. ;//
  4891. ;// 2 - Requester
  4892. ;//
  4893. ;// 3 - Attributes
  4894. ;//
  4895. ;//
  4896. MessageId=0x0316
  4897. SymbolicName=SE_AUDITID_CERTSRV_NEWREQUEST
  4898. Language=English
  4899. Certificate Services received a certificate request.%n
  4900. %n
  4901. Request ID:%t%1%n
  4902. Requester:%t%2%n
  4903. Attributes:%t%3
  4904. .
  4905. ;//
  4906. ;//
  4907. ;// SE_AUDITID_CERTSRV_REQUESTAPPROVED
  4908. ;//
  4909. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4910. ;//
  4911. ;// Parameter Strings -
  4912. ;//
  4913. ;// 1 - Request ID
  4914. ;//
  4915. ;// 2 - Requester
  4916. ;//
  4917. ;// 3 - Attributes
  4918. ;//
  4919. ;// 4 - Disposition
  4920. ;//
  4921. ;// 5 - SKI
  4922. ;//
  4923. ;// 6 - Subject
  4924. ;//
  4925. ;//
  4926. MessageId=0x0317
  4927. SymbolicName=SE_AUDITID_CERTSRV_REQUESTAPPROVED
  4928. Language=English
  4929. Certificate Services approved a certificate request and issued a certificate.%n
  4930. %n
  4931. Request ID:%t%1%n
  4932. Requester:%t%2%n
  4933. Attributes:%t%3%n
  4934. Disposition:%t%4%n
  4935. SKI:%t%t%5%n
  4936. Subject:%t%6
  4937. .
  4938. ;//
  4939. ;//
  4940. ;// SE_AUDITID_CERTSRV_REQUESTDENIED
  4941. ;//
  4942. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4943. ;//
  4944. ;// Parameter Strings -
  4945. ;//
  4946. ;// 1 - Request ID
  4947. ;//
  4948. ;// 2 - Requester
  4949. ;//
  4950. ;// 3 - Attributes
  4951. ;//
  4952. ;// 4 - Disposition
  4953. ;//
  4954. ;// 5 - SKI
  4955. ;//
  4956. ;// 6 - Subject
  4957. ;//
  4958. ;//
  4959. MessageId=0x0318
  4960. SymbolicName=SE_AUDITID_CERTSRV_REQUESTDENIED
  4961. Language=English
  4962. Certificate Services denied a certificate request.%n
  4963. %n
  4964. Request ID:%t%1%n
  4965. Requester:%t%2%n
  4966. Attributes:%t%3%n
  4967. Disposition:%t%4%n
  4968. SKI:%t%t%5%n
  4969. Subject:%t%6
  4970. .
  4971. ;//
  4972. ;//
  4973. ;// SE_AUDITID_CERTSRV_REQUESTPENDING
  4974. ;//
  4975. ;// Category: SE_CATEGID_OBJECT_ACCESS
  4976. ;//
  4977. ;// Parameter Strings -
  4978. ;//
  4979. ;// 1 - Request ID
  4980. ;//
  4981. ;// 2 - Requester
  4982. ;//
  4983. ;// 3 - Attributes
  4984. ;//
  4985. ;// 4 - Disposition
  4986. ;//
  4987. ;// 5 - SKI
  4988. ;//
  4989. ;// 6 - Subject
  4990. ;//
  4991. ;//
  4992. MessageId=0x0319
  4993. SymbolicName=SE_AUDITID_CERTSRV_REQUESTPENDING
  4994. Language=English
  4995. Certificate Services set the status of a certificate request to pending.%n
  4996. %n
  4997. Request ID:%t%1%n
  4998. Requester:%t%2%n
  4999. Attributes:%t%3%n
  5000. Disposition:%t%4%n
  5001. SKI:%t%t%5%n
  5002. Subject:%t%6
  5003. .
  5004. ;//
  5005. ;//
  5006. ;// SE_AUDITID_CERTSRV_SETOFFICERRIGHTS
  5007. ;//
  5008. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5009. ;//
  5010. ;// Parameter Strings -
  5011. ;//
  5012. ;// 1 - Enable restrictions
  5013. ;//
  5014. ;// 2 - Restrictions
  5015. ;//
  5016. ;//
  5017. MessageId=0x031a
  5018. SymbolicName=SE_AUDITID_CERTSRV_SETOFFICERRIGHTS
  5019. Language=English
  5020. The certificate manager settings for Certificate Services changed.%n
  5021. %n
  5022. Enable:%t%1%n
  5023. %n
  5024. %2
  5025. .
  5026. ;//
  5027. ;//
  5028. ;// SE_AUDITID_CERTSRV_SETCONFIGENTRY
  5029. ;//
  5030. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5031. ;//
  5032. ;// Parameter Strings -
  5033. ;//
  5034. ;// 1 - Node
  5035. ;//
  5036. ;// 2 - Entry
  5037. ;//
  5038. ;// 3 - Value
  5039. ;//
  5040. ;//
  5041. MessageId=0x031b
  5042. SymbolicName=SE_AUDITID_CERTSRV_SETCONFIGENTRY
  5043. Language=English
  5044. A configuration entry changed in Certificate Services.%n
  5045. %n
  5046. Node:%t%1%n
  5047. Entry:%t%2%n
  5048. Value:%t%3
  5049. .
  5050. ;//
  5051. ;//
  5052. ;// SE_AUDITID_CERTSRV_SETCAPROPERTY
  5053. ;//
  5054. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5055. ;//
  5056. ;// Parameter Strings -
  5057. ;//
  5058. ;// 1 - Property
  5059. ;//
  5060. ;// 2 - Index
  5061. ;//
  5062. ;// 3 - Type
  5063. ;//
  5064. ;// 4 - Value
  5065. ;//
  5066. ;//
  5067. MessageId=0x031c
  5068. SymbolicName=SE_AUDITID_CERTSRV_SETCAPROPERTY
  5069. Language=English
  5070. A property of Certificate Services changed.%n
  5071. %n
  5072. Property:%t%1%n
  5073. Index:%t%2%n
  5074. Type:%t%3%n
  5075. Value:%t%4
  5076. .
  5077. ;//
  5078. ;//
  5079. ;// SE_AUDITID_CERTSRV_KEYARCHIVED
  5080. ;//
  5081. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5082. ;//
  5083. ;// Parameter Strings -
  5084. ;//
  5085. ;// 1 - Request ID
  5086. ;//
  5087. ;// 2 - Requester
  5088. ;//
  5089. ;// 3 - KRA Hashes
  5090. ;//
  5091. ;//
  5092. MessageId=0x031d
  5093. SymbolicName=SE_AUDITID_CERTSRV_KEYARCHIVED
  5094. Language=English
  5095. Certificate Services archived a key.%n
  5096. %n
  5097. Request ID:%t%1%n
  5098. Requester:%t%2%n
  5099. KRA Hashes:%t%3
  5100. .
  5101. ;//
  5102. ;//
  5103. ;// SE_AUDITID_CERTSRV_IMPORTKEY
  5104. ;//
  5105. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5106. ;//
  5107. ;// Parameter Strings -
  5108. ;//
  5109. ;// 1 - Request ID
  5110. ;//
  5111. ;//
  5112. MessageId=0x031e
  5113. SymbolicName=SE_AUDITID_CERTSRV_IMPORTKEY
  5114. Language=English
  5115. Certificate Services imported and archived a key.%n
  5116. %n
  5117. Request ID:%t%1
  5118. .
  5119. ;//
  5120. ;//
  5121. ;// SE_AUDITID_CERTSRV_PUBLISHCACERT
  5122. ;//
  5123. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5124. ;//
  5125. ;// Parameter Strings -
  5126. ;//
  5127. ;// 1 - Certificate Hash
  5128. ;//
  5129. ;// 2 - Valid From
  5130. ;//
  5131. ;// 3 - Valid To
  5132. ;//
  5133. ;//
  5134. MessageId=0x031f
  5135. SymbolicName=SE_AUDITID_CERTSRV_PUBLISHCACERT
  5136. Language=English
  5137. Certificate Services published the CA certificate to Active Directory.%n
  5138. %n
  5139. Certificate Hash:%t%1%n
  5140. Valid From:%t%2%n
  5141. Valid To:%t%3
  5142. .
  5143. ;//
  5144. ;//
  5145. ;// SE_AUDITID_CERTSRV_DELETEROW
  5146. ;//
  5147. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5148. ;//
  5149. ;// Parameter Strings -
  5150. ;//
  5151. ;// 1 - Table ID
  5152. ;//
  5153. ;// 2 - Filter
  5154. ;//
  5155. ;// 3 - Rows Deleted
  5156. ;//
  5157. ;//
  5158. MessageId=0x0320
  5159. SymbolicName=SE_AUDITID_CERTSRV_DELETEROW
  5160. Language=English
  5161. One or more rows have been deleted from the certificate database.%n
  5162. %n
  5163. Table ID:%t%1%n
  5164. Filter:%t%2%n
  5165. Rows Deleted:%t%3
  5166. .
  5167. ;//
  5168. ;//
  5169. ;// SE_AUDITID_CERTSRV_ROLESEPARATIONSTATE
  5170. ;//
  5171. ;// Category: SE_CATEGID_OBJECT_ACCESS
  5172. ;//
  5173. ;// Parameter Strings -
  5174. ;//
  5175. ;// 1 - Role separation state
  5176. ;//
  5177. ;//
  5178. MessageId=0x0321
  5179. SymbolicName=SE_AUDITID_CERTSRV_ROLESEPARATIONSTATE
  5180. Language=English
  5181. Role separation enabled:%t%1
  5182. .
  5183. ;/*lint +e767 */ // Resume checking for different macro definitions // winnt
  5184. ;
  5185. ;
  5186. ;#endif // _MSAUDITE_