M Active Directory Audit Events

Topics

About Active Directory Audit Events

This appendix maps audit event names and event ID used in the Active Directory to their equivalent values in the command_class and target_type fields in the Oracle AVDF audit record. You can use the audit events mapped here to create custom audit reports using other Oracle Database reporting products or third-party tools. See also "Oracle Audit Vault and Database Firewall Database Schemas" for Oracle AVDF data warehouse details that may be useful in designing your own reports.

Directory Service Audit Trail Events

Table M-1 lists the Directory Service audit trail events and their command_class and target_type mappings in the Oracle AVDF audit record.

Table M-1 Directory Service Audit Trail Events

Event ID Source Event command_class target_type

1000

START_ACTIVE_DIRECTORY_DOMAIN_SERVICES_COMPLETED

STARTUP

DIRECTORY SERVICE

1001

START_ACTIVE_DIRECTORY_DOMAIN_SERVICES_FAILED

STARTUP

DIRECTORY SERVICE

1003

DIRLOG_DBINIT_FAILED

INITIALIZE

DATABASE

1004

SHUTDOWN_ACTIVE_DIRECTORY_DOMAIN_SERVICES_SUCCEEDED

SHUTDOWN

DIRECTORY SERVICE

1007

DIRLOG_CHK_INIT_SUCCESS

INITIALIZE

CHECKER

1008

DIRLOG_CHK_INIT_FAILURE

INITIALIZE

CHECKER

1010

DIRLOG_NO_MEMORY_FOR_LOG_OVERRIDES

INHERIT

LOG

1016

DIRLOG_SCHEMA_NOT_LOADED

LOAD

SCHEMA

1024

DIRLOG_CHK_STOP_FAILURE

STOP

CHECKER

1054

DIRLOG_SECURITY_CHECKING_ERROR

VALIDATE

ACCESS RIGHT

1062

DOMAIN_NO_LONGER_INSTANTIATED

CREATE

DOMAIN

1066

DIRLOG_DRA_REPLICAADD_ENTRY

UPDATE

REPLICA

1067

DIRLOG_DRA_REPLICADEL_ENTRY

DELETE

REPLICA

1068

DIRLOG_DRA_UPDATEREFS_ENTRY

UPDATE

PARTITION

1070

DIRLOG_DRA_REPLICASYNC_ENTRY

SYNCHRONIZE

REPLICA

1072

DIRLOG_DRA_GETNCCH_ENTRY

SYNCHRONIZE

REPLICA

1080

NOTIFY_DS_ABOUT_CHANGES_FAILED

NOTIFY

SERVICE

1081

SEND_DP_CHANGES_FAILED

SEND

CHANGES

1082

SEND_DP_MESSAGE_WITH_CHANGES_FAILED

SEND

CHANGES

1085

SYNCHRONIZE_DIRECTORY_PARTITION_FAILED

SYNCHRONIZE

PARTITION

1089

INITIALIZE_DSP_LAYER_FAILED

INITIALIZE

PRINCIPAL

1090

DIRECTORY_PARTITION_REPLICATION_FAILED

COPY

PARTITION

1094

DISABLED_DISK_DRIVE_WRITE_CACHE

DISABLE

DRIVE

1097

REPLICATE_INVALID_DIRECTORY_PARTITION

COPY

PARTITION

1098

DIRLOG_DRA_MAIL_UPDREP_BADNC

UPDATE

REPLICA

1100

DIRLOG_DRA_RECORD_TOO_BIG_SUCCESS

UPDATE

REPLICA

1102

DIRLOG_DRA_MAIL_REQ_UPD_SENT

REQUEST

REPLICA CHANGES

1103

DIRLOG_DRA_MAIL_UPD_REP_SENT

UPDATE

REPLICA CHANGES

1104

DIRLOG_CHK_REPSTO_DEL_SUCCESS

DELETE

TOPOLOGY

1109

DIRLOG_DRA_INVOCATION_ID_CHANGED

UPDATE

INVOCATION IDENTIFIER

1111

DIRLOG_DRA_UPDATENC_PROGRESS

SYNCHRONIZE

REPLICA

1113

DIRLOG_DRA_DISABLED_INBOUND_REPL

DISABLE

REPLICATION

1114

DIRLOG_DRA_REENABLED_INBOUND_REPL

ENABLE

REPLICATION

1115

DIRLOG_DRA_DISABLED_OUTBOUND_REPL

DISABLE

REPLICATION

1116

DIRLOG_DRA_REENABLED_OUTBOUND_REPL

ENABLE

REPLICATION

1117

DIRLOG_CHK_ALL_CONNECTIONS_FOR_NC_DISABLED

DISABLE

CONNECTION

1124

DIRLOG_DRA_GET_RPC_HANDLE_FAILURE

RECEIVE

HANDLE

1125

DIRLOG_RPC_CONNECTION_FAILED

CONNECT

CALL

1138

DIRLOG_API_TRACE

EXECUTE

FUNCTION

1139

DIRLOG_API_TRACE_COMPLETE

EXECUTE

FUNCTION

1171

DIRLOG_EXIT_WITH_ACTIVE_THREADS

SHUTDOWN

DIRECTORY SERVICE

1172

DIRLOG_RPC_CONNECTION

CONNECT

SERVER

1174

DIRLOG_PRIVILEGED_OPERATION_PERFORMED

EXECUTE

OBJECT

1175

DIRLOG_PRIVILEGED_OPERATION_FAILED

EXECUTE

OBJECT

1176

DIRLOG_UNAUTHENTICATED_LOGON

LOGIN

SERVER

1177

DIRLOG_SECURITY_ATTS_MODIFIED

UPDATE

OBJECT

1194

DIRLOG_DRA_ADUPD_NC_SYNCED

SYNCHRONIZE

PARTITION

1195

DIRLOG_DRA_ADUPD_ALL_SYNCED

SYNCHRONIZE

PARTITION

1196

DIRLOG_CANT_APPLY_SERVER_SECURITY

GRANT

OBJECT

1198

DIRLOG_RECOVER_RESTORED_FAILED

RECOVER

DATABASE

1205

DIRLOG_SDPROP_OBJ_CLASS_PROBLEM

INVALIDATE

OBJECT CLASS

1209

DIRLOG_AUDIT_PRIVILEGE_FAILED

SET

AUDIT PRIVILEGE

1210

DIRLOG_ATQ_MAX_CONNECTIONS_EXCEEDED

EXCEED

CONNECTION

1211

DIRLOG_ATQ_CLOSE_SOCKET_SHUTDOWN

CLOSE

SOCKET

1213

DIRLOG_ATQ_CLOSE_SOCKET_CONTACT_LOST

CLOSE

SOCKET

1214

DIRLOG_SDPROP_NO_SD

SEARCH

SECURITY DESCRIPTOR

1215

DIRLOG_ATQ_CLOSE_SOCKET_OK

CLOSE

SOCKET

1216

DIRLOG_ATQ_CLOSE_SOCKET_ERROR

CLOSE

SOCKET

1217

DIRLOG_LDAP_NTLM_WARNING

INITIALIZE

AUTHENTICATION

1218

DIRLOG_LDAP_NEGOTIATE_WARNING

INITIALIZE

AUTHENTICATION

1219

DIRLOG_LDAP_SIMPLE_WARNING

INITIALIZE

AUTHENTICATION

1220

DIRLOG_LDAP_SSL_NO_CERT

VALIDATE

CERTIFICATE

1221

DIRLOG_LDAP_SSL_GOT_CERT

VALIDATE

CERTIFICATE

1222

DIRLOG_DRA_CERT_ACCESS_DENIED_WINERR

DENY

ACCESS

1223

DIRLOG_DRA_CERT_ACCESS_DENIED_TRUSTERR

DENY

ACCESS

1234

DIRLOG_FAILED_LOOKUP_ACCOUNT_SID

LOGIN

SERVER

1236

DIRLOG_WRONG_SERVER_NAME

VALIDATE

SERVER

1237

DIRLOG_SAM_LOOPBACK_ERROR

SEND

OPERATION

1238

DIRLOG_LDAP_SSP_ERROR

INITIALIZE

CONNECTION

1247

TRANSFER_SECURITY_PRINCIPAL_FAILED

MOVE

PRINCIPAL

1257

DIRLOG_SDPROP_DOING_PROPAGATION

EXECUTE

PROPAGATION

1258

DIRLOG_SDPROP_REPORT_ON_PROPAGATION

FINISH

PROPAGATION

1259

DIRLOG_SDPROP_STARTING

START

PROPAGATION

1260

DIRLOG_SDPROP_SLEEP

WAIT

PROPAGATION

1261

DIRLOG_SDPROP_AWAKE

NOTIFY

PROPAGATION

1262

DIRLOG_SDPROP_END_ABNORMAL

ABORT

PROPAGATION

1263

DIRLOG_SDPROP_END_NORMAL

FINISH

PROPAGATION

1264

DIRLOG_CHK_LINK_ADD_SUCCESS

UPDATE

LINK

1265

DIRLOG_CHK_LINK_ADD_FAILURE

UPDATE

LINK

1268

DIRLOG_CHK_LINK_DEL_NOTGC_SUCCESS

COPY

PARTITION

1269

DIRLOG_CHK_LINK_DEL_NOTGC_FAILURE

COPY

PARTITION

1270

DIRLOG_CHK_LINK_DEL_DOMDEL_SUCCESS

COPY

PARTITION

1271

DIRLOG_CHK_LINK_DEL_DOMDEL_FAILURE

STOP

REPLICATION

1272

DIRLOG_CHK_LINK_DEL_NOCONN_SUCCESS

COPY

PARTITION

1273

DIRLOG_CHK_LINK_DEL_NOCONN_FAILURE

STOP

REPLICATION

1274

REPLICATE_DIRECTORY_PARTITION_FAILED

COPY

PARTITION

1275

CREATE_DIRECTORY_PARTITION_FAILED

CREATE

PARTITION

1277

DIRMSG_INSTALL_FAILED_TO_CREATE_NTDSA_OBJECT

CREATE

OBJECT

1278

DIRMSG_INSTALL_FAILED_TO_CREATE_DOMAIN_OBJECT

CREATE

OBJECT

1279

DIRMSG_INSTALL_FAILED_TO_INIT_JET

INITIALIZE

DATABASE

1280

DIRMSG_INSTALL_FAILED_GENERAL

INSTALL

SERVER

1281

DIRMSG_INSTALL_FAILED_LDAP_CONNECT

CONNECT

CONTROLLER

1282

DIRMSG_INSTALL_FAILED_BIND

BIND

CONTROLLER

1283

DIRMSG_INSTALL_FAILED_SITE

INSTALL

SERVER

1284

DIRMSG_INSTALL_FAILED_SITE_EXIST

SEARCH

SITE

1285

DIRLOG_INSTALL_SERVER_EXISTS

VALIDATE

SERVER

1286

DIRLOG_INSTALL_FAILED_TO_DELETE_SERVER

DELETE

SERVER

1287

DIRLOG_INSTALL_DOMAIN_EXISTS

VALIDATE

DOMAIN

1288

DIRLOG_INSTALL_FAILED_TO_DELETE_DOMAIN

DELETE

PARTITION

1290

WIZARD_ACCESS_REGISTRY_FAILED

ACCESS

REGISTRY

1292

LOAD_SAM_DB_FAILED

LOAD

DATABASE

1293

CREATE_ACCOUNT_FAILED

CREATE

ACCOUNT

1294

AUTO_ENROLL_CERTIFICATE_FAILED

REGISTER

CERTIFICATE

1295

ADD_DIRECTORY_SERVICES_RESTORE_MODE_FAILED

UPDATE

RESTORE MODE

1297

ERROR_INSTALL_DOMAIN_SERVICES

INSTALL

DOMAIN SERVICE

1298

WIZARD_READ_ATTRIBUTES_FROM_DC_FAILED

READ

ATTRIBUTE

1299

SCHEMA_VALIDATION_CHECK_FAILED

VALIDATE

SCHEMA

1301

ADD_SECURITY_PRINCIPALS_TO_DS_DB_FAILED

UPDATE

PRINCIPAL

1305

SHUTDOWN_DOMAIN_SERVICES_FOR_REMOVAL_FAILED

SHUTDOWN

DIRECTORY SERVICE

1309

DIRLOG_WINSOCK_INIT_FAILED

INITIALIZE

SERVER

1317

DIRLOG_LDAP_CONNECTION_TIMEOUT

DISCONNECT

SERVICE

1318

PREPARE_SAM_DS_DEMOTION

DEMOTE

SECURITY ACCOUNT MANAGER

1319

VALIDATE_REMOVE_DOMAIN_CONTROLLER

VALIDATE

CONTROLLER

1320

AUTHENTICATE_CREDENTIAL

AUTHENTICATE

CREDENTIAL

1321

CREATE_LOCAL_ACCOUNT

CREATE

ACCOUNT

1322

CREATE_LOCAL_SAM_DATABASE

CREATE

DATABASE

1323

SET_NEW_LOCAL_SECURITY_AUTHORITY_ACCOUNT

SET

ACCOUNT

1325

REMOVE_ALL_OPERATIONS_MASTER_ROLES

DROP

ROLE

1326

REMOVE_LDAP_RPC_ACCESS

DROP

ACCESS

1327

REMOVE_COMPLETE_DS_SAM_LSA

DROP

SERVER

1328

START_INSTALL_AD_DS

INSTALL

SERVER

1329

VALIDATE_USER_SUPPLIED_OPTIONS

VALIDATE

OPTION

1330

FIND_SITE_TO_INSTALL

SEARCH

SITE

1331

EXAMINE_EXISTING_FOREST

VALIDATE

FOREST

1335

CONFIG_LOCAL_COMP_TO_HOST_DS

CONFIGURE

COMPUTER

1337

CREATE_SECURITY_ID_FOR_NEW_DOMAIN

CREATE

SECURITY IDENTIFIER

1338

REPLICATE_SCHEMA_DIRECTORY_PARTITION

COPY

PARTITION

1339

CREATE_DIRECTORY_PARTITION

CREATE

PARTITION

1340

REPLICATE_CONFIG_DIRECTORY_PARTITION

COPY

PARTITION

1342

REPLICATE_CRITICAL_DOMAIN_INFO

COPY

INFORMATION

1346

CREATE_NEW_DOMAIN_USERS_GROUPS_COMPUTER_OBJECTS

CREATE

OBJECT

1347

COMPLETE_INSTALL_AD_DS

INSTALL

SERVER

1348

DIRLOG_BEGIN_DIR_SEARCH

SEARCH

OBJECT

1349

DIRLOG_END_DIR_SEARCH

SEARCH

OBJECT

1350

DIRLOG_BEGIN_DIR_ADDENTRY

CREATE

OBJECT

1351

DIRLOG_END_DIR_ADDENTRY

CREATE

OBJECT

1352

DIRLOG_BEGIN_DIR_REMOVE

DELETE

OBJECT

1353

DIRLOG_END_DIR_REMOVE

DELETE

OBJECT

1354

DIRLOG_BEGIN_DIR_MODIFY

UPDATE

OBJECT

1355

DIRLOG_END_DIR_MODIFY

UPDATE

OBJECT

1356

DIRLOG_BEGIN_DIR_MODIFYDN

UPDATE

OBJECT

1357

DIRLOG_END_DIR_MODIFYDN

UPDATE

OBJECT

1358

DIRLOG_BEGIN_DIR_COMPARE

COMPARE

ATTRIBUTE

1359

DIRLOG_END_DIR_COMPARE

COMPARE

ATTRIBUTE

1360

DIRLOG_DRA_REPLICASYNC_EXIT

FINISH

SYNCHRONIZATION

1362

REPLICATE_DIRECTORY_PARTITION

COPY

PARTITION

1377

INITIALIZE_TRANSPORT_FAILED

INITIALIZE

TRANSPORT

1383

DIRLOG_DRA_NO_CERTIFICATE

VALIDATE

CERTIFICATE

1384

DIRLOG_DRA_CERTIFICATE_ACQUIRED

ACQUIRE

CERTIFICATE

1390

SET_SID_FAILED_IN_SAM_DB

SET

SECURITY IDENTIFIER

1391

CONFIG_ACCOUNT_FAILED_ON_REMOTE_DC

CONFIGURE

ACCOUNT

1392

REMOVE_ACTIVE_DIRECTORY_DC_FAILED

DROP

SERVER

1411

DIRLOG_BUILD_SPN_FAILURE

CREATE

PRINCIPAL

1423

RESTORE_AD_DC_FROM_IMPROPER_BACKUP

RESTORE

CONTROLLER

1424

START_REPLICATION_CYCLE

START

CYCLE

1425

INSTALL_REPLICA

INSTALL

REPLICA

1434

DIRLOG_DB_REG_PATH_CHANGED

UPDATE

REGISTRY

1437

MISSING_CRITICAL_INFO

VALIDATE

INFORMATION

1440

CREATE_NTDS_SETTINGS_OBJECT_FAILED_ON_REMOTE_DC

CREATE

OBJECT

1441

CREATE_NTDS_SETTINGS_OBJECT_ON_REMOTE_DC

CREATE

OBJECT

1442

DIRLOG_FAILED_TO_REMOVE_NTDSA

DROP

OBJECT

1446

DIRLOG_FAILED_TO_CREATE_RESTORE_MARKER_FILE

RESTORE

FILE

1447

DIRLOG_FAILED_TO_DELETE_RESTORE_MARKER_FILE

RESTORE

FILE

1450

DIRLOG_SDPROP_MERGE_SD_FAIL

CALCULATE

SECURITY DESCRIPTOR

1452

DIRLOG_SDPROP_ADD_SD_PROBLEM

UPDATE

SECURITY DESCRIPTOR

1458

DIRLOG_FSMO_XFER

MOVE

ROLE

1459

DIRLOG_BEGIN_DIR_FIND

SEARCH

ATTRIBUTE

1460

DIRLOG_END_DIR_FIND

SEARCH

ATTRIBUTE

1461

DIRLOG_BEGIN_LDAP_BIND

BIND

LDAP

1462

DIRLOG_END_LDAP_BIND

BIND

LDAP

1487

DIRLOG_IDL_DRS_REPLICA_SYNC_ENTRY

START

REPLICATION

1488

DIRLOG_IDL_DRS_REPLICA_SYNC_EXIT

FINISH

REPLICATION

1489

DIRLOG_IDL_DRS_GETCHG_ENTRY

START

REPLICATION

1490

DIRLOG_IDL_DRS_GETCHG_EXIT

FINISH

REPLICATION

1523

DIRLOG_SCHEMA_SD_CONVERSION_FAILED

CONVERT

SECURITY DESCRIPTOR

1524

DIRLOG_BEGIN_LDAP_REQUEST

START

OPERATION

1525

DIRLOG_END_LDAP_REQUEST

FINISH

OPERATION

1526

DIRLOG_CHK_UPDATED_SCHEDULE

UPDATE

SCHEDULE

1538

RESTORE_AD_DS_FROM_BACKUP_FAILED

RESTORE

DOMAIN SERVICE

1540

ADD_SID_TO_OBJECT_FAILED

UPDATE

SECURITY IDENTIFIER

1541

ADD_SID_TO_OBJECT_SUCCEEDED

UPDATE

SECURITY IDENTIFIER

1548

REPLICATE_DIRECTORY_PARTITION_FAILED

COPY

PARTITION

1551

SYNCHRONIZE_DIRECTORY_PARTITION

SYNCHRONIZE

PARTITION

1552

DIRLOG_DSA_NOT_ADVERTISE_DC

PUBLISH

CONTROLLER

1553

DIRLOG_ADUPD_SYNC_PROGRESS

SYNCHRONIZE

DIRECTORY PARTITION

1554

DIRLOG_ADUPD_SYNC_NO_PROGRESS

SYNCHRONIZE

DIRECTORY PARTITION

1555

DIRLOG_ADUPD_INIT_SYNC_ONGOING

RESUME

SYNCHRONIZATION

1556

DIRLOG_ADUPD_NC_GAVE_UP

STOP

SYNCHRONIZATION

1557

DIRLOG_ADUPD_NC_NEVER_SYNCED_WRITE

WRITE

PARTITION

1558

DIRLOG_ADUPD_NC_NEVER_SYNCED_READ

READ

PARTITION

1560

DIRLOG_DRA_NEW_REPLICA_FULL_SYNC

UPDATE

REPLICA

1561

DIRLOG_DRA_USER_REQ_FULL_SYNC

SYNCHRONIZE

PARTITION

1562

DIRLOG_DRA_FULL_SYNC_CONTINUED

SYNCHRONIZE

PARTITION

1564

DIRLOG_DRA_INIT_SYNCS_DISABLED

DISABLE

SYNCHRONIZATION

1569

CANCELLED_AD_DS_INSTALLATION

CANCEL

INSTALLATION

1576

DIRLOG_INHERIT_SECURITY_IDENTITY_FAILURE

INHERIT

SECURITY IDENTIFIER

1577

DIRLOG_INHERIT_SECURITY_IDENTITY_SUCCEEDED

INHERIT

SECURITY IDENTIFIER

1580

DIRLOG_DRA_REPLICATION_FINISHED

FINISH

REPLICATION

1622

DIRLOG_NSPI_BEGIN_BIND

BIND

DIRECTORY

1623

DIRLOG_NSPI_END_BIND

BIND

DIRECTORY

1642

DIRLOG_DRA_CERT_ACCESS_DENIED_NOT_DC

ACCESS

CERTIFICATE

1643

DIRLOG_SEARCH_OPERATIONS

SEARCH

DATABASE

1644

DIRLOG_SEARCH_FILTER_LOGGING

SEARCH

DATABASE

1645

DIRLOG_DRA_SPN_WRONG_TARGET_NAME

REGISTER

PRINCIPAL

1646

DIRLOG_DB_FREE_SPACE

VALIDATE

SPACE

1659

RESUMED_DIRECTORY_PARTITION_REMOVAL

REMOVE

PARTITION

1660

COMPLETED_DIRECTORY_PARTITION_REMOVAL

DROP

PARTITION

1661

REMOVE_DIRECTORY_PARTITION_OBJECTS_FAILED

DROP

OBJECT

1695

ENABLE_LINKED_VALUED_REPLICATION

ENABLE

REPLICATION

1700

PROCESS_REPLICATION_FAILED

EXECUTE

REPLICATION

1702

SYNCHRONIZE_DIRECTORY_PARTITION

SYNCHRONIZE

PARTITION

1703

SYNCHRONIZE_DIRECTORY_PARTITION

SYNCHRONIZE

PARTITION

1704

SYNCHRONIZE_DIRECTORY_PARTITION

SYNCHRONIZE

PARTITION

1710

REPLICATE_DIRECTORY_PARTITION_FAILED

COPY

PARTITION

1717

FUNCTIONAL_LEVEL_INCOMPATIBLE_WITH_OS

VALIDATE

LEVEL

1718

FUNCTIONAL_LEVEL_INCOMPATIBLE_WITH_LOCAL_DC

VALIDATE

LEVEL

1719

READ_NTDS_SETTINGS_OBJECT_FAILED

READ

OBJECT

1720

FUNCTIONAL_LEVEL_INCOMPATIBLE_WITH_OS

VALIDATE

LEVEL

1721

UPDATE_OBJECT_FUNCTIONAL_LEVEL_FAILED

UPDATE

LEVEL

1722

RAISE_OBJECT_FUNCTIONAL_LEVEL

RAISE

LEVEL

1723

RAISE_FUNCTIONAL_LEVEL_FAILED

RAISE

LEVEL

1724

UPDATE_DOMAIN_FUNCTIONAL_LEVEL_FAILED

UPDATE

LEVEL

1725

ADD_NTDS_SETTINGS_OBJECT_DENIED

UPDATE

OBJECT

1726

UPDATE_FUNCTIONAL_LEVEL_TO_INCOMPATIBLE_VALUE

UPDATE

LEVEL

1727

RESTORE_AD_DS_FAILED_TOO_OLD_COPY

RESTORE

DOMAIN SERVICE

1728

RESTORE_AD_DS_FILES_FOR_INSTALL_FAILED

RESTORE

FILE

1746

REMOVED_DOMAIN_FROM_FOREST

DROP

DOMAIN

1750

DELETED_APPLICATION_DIRECTORY_PARTITION

DELETE

PARTITION

1752

REPLICATE_APPLICATION_DIRECTORY_PARTITION_FAILED

COPY

PARTITION

1753

STOP_APPLICATION_DIRECTORY_PARTITION_REPLICATION_FAILED

STOP

PARTITION

1755

STOP_DIRECTORY_PARTITION_REPLICATION_FAILED

STOP

PARTITION

1758

TRANSFER_OPERATIONS_MASTER_ROLES

MOVE

ROLE

1767

PROMOTE_DOMAIN_CONTROLLER_FAILED

PROMOTE

CONTROLLER

1769

CHECK_SECURITY_DESCRIPTOR

VALIDATE

SECURITY DESCRIPTOR

1773

INSTALL_ACTIVE_DIRECTORY_DOMAIN_SERVICES_FAILED_FROM_RESTORED_FILES

INSTALL

DOMAIN SERVICE

1775

INITIALIZE_LDAP_MD5_AUTHENTICATION_FAILED

INITIALIZE

AUTHENTICATION

1791

REPLICATE_DIRECTORY_PARTITION_ABORTED

COPY

PARTITION

1812

INTERSITE_MESSAGING_SERVICE_INITIALIZATION_FAILED

INITIALIZE

MESSAGING SERVICE

1838

REPLICATION_OPERATION_TAKE_LONGER_THAN_EXPECTED

COPY

PARTITION

1861

FAILED_TO_START_RPC_SERVER

START

SERVER

1874

INSTALL_ACTIVE_DIRECTORY_DOMAIN_SERVICES_FAILED_FROM_RESTORED_FILES

INSTALL

DOMAIN SERVICE

1877

RENAME_DOMAIN_FAILED_USER_NOT_HAVE_RIGHTS

RENAME

DOMAIN

1881

FAILED_TO_ASSIGN_NEW_DOMAIN_NAME

ASSIGN

DOMAIN

1882

AD_DS_SHUTDOWN_TO_COMPLETE_DOMAIN_RENAME_OPERATION

SHUTDOWN

DIRECTORY SERVICE

1883

FAILED_TO_SHUTDOWN_AD_DS

SHUTDOWN

DIRECTORY SERVICE

1893

FAILED_TO_RETRIEVE_REPLICATION_EPOCH

RETRIEVE

EPOCH

1894

INSTALL_AD_DS_FAILED_FROM_RESTORED_DB_FILES

INSTALL

DOMAIN SERVICE

1901

DELETE_AUTO_ENROLLMENT_ENTRY_FOR_CERT_SERVICES_FAILED

DELETE

ENTRY

1912

INITIALIZE_SHADOW_COPY_SERVICE_FAILED

INITIALIZE

SERVICE

1913

BACKUP_RESTORE_AD_DS_FAILED

BACKUP

DOMAIN SERVICE

1914

CANT_USE_SHADOW_COPY_SERVICE_TO_BACKUP_AD_DS

BACKUP

SERVICE

1915

CANT_USE_SHADOW_COPY_SERVICE_TO_RESTORE_AD_DS

RESTORE

SERVICE

1916

SHADOW_COPY_BACKUP_AD_DS_FAILED

BACKUP

DOMAIN SERVICE

1917

SHADOW_COPY_BACKUP_AD_DS_SUCCEEDED

BACKUP

DOMAIN SERVICE

1918

CANT_RESTORE_AD_DS_AS_SHADOW_COPY_TOO_OLD

RESTORE

DOMAIN SERVICE

1919

SHADOW_COPY_RESTORE_AD_DS_FAILED

RESTORE

DOMAIN SERVICE

1920

SHADOW_COPY_RESTORE_AD_DS_SUCCEEDED

RESTORE

DOMAIN SERVICE

1921

BACKUP_RESTORE_FAILED_WHILE_AD_DS_READ_OPERATION

BACKUP

DOMAIN SERVICE

1931

AD_DS_RESTORE_FAILED_BY_SHADOW_COPY_SERVICE

RESTORE

DOMAIN SERVICE

1953

STARTED_FULL_PROPAGATION_PASS

START

PROPAGATION

1954

COMPLETED_FULL_PROPAGATION_PASS

FINISH

PROPAGATION

1956

DELETED_DIRECTORY_PARTITION

DELETE

PARTITION

1964

DIRLOG_DRA_UNAUTHORIZED_NC

DENY

REPLICATION

1965

INITIALIZE_RESTORED_DB_FILES

INITIALIZE

FILE

1966

COMPLETED_FULL_PROPAGATION_PASS

FINISH

PROPAGATION

1967

FAILED_TO_CACHE_GROUP_MEMBERSHIP

CACHE

MEMBERSHIP

1968

RAISED_DOMAIN_FUNC_LEVEL_TO_BE_COMPATIBLE_WITH_FOREST_FUNC_LEVEL

RAISE

LEVEL

1977

DIRLOG_DRA_REPLICATION_ALL_ACCESS_DENIED_DC

DENY

REPLICATION

1979

DIRLOG_SCHEMA_CLASS_DEFAULT_MOD_FAILED

CREATE

SECURITY DESCRIPTOR

1980

DIRLOG_SCHEMA_CLASS_DEFAULT_SD_MISSING

DROP

ACCESS CONTROL LIST

1981

DIRLOG_SCHEMA_CLASS_EDC_SID_FAILURE

ACCESS

SECURITY IDENTIFIER

1982

DIRLOG_SCHEMA_CLASS_DDC_REMOVE_FAILURE

DELETE

ACCESS CONTROL ENTRY

1983

DIRLOG_SCHEMA_CLASS_EDC_ACE_CREATE_FAILURE

CREATE

ACCESS CONTROL ENTRY

1987

FAILED_TO_REMOVE_LAST_DOMAIN_CONTROLLER

DROP

CONTROLLER

1989

REMOVE_APPLICATION_DIRECTORY_PARTITION_FAILED

DROP

PARTITION

1990

NOTIFY_DIRECTORY_SERVICE_FAILED_FOR_LONG_PERIOD

NOTIFY

SERVICE

1994

REFRESH_KERBEROS_SECURITY_TICKETS_FAILED

REFRESH

SECURITY TICKET

1996

AD_DS_INSTALL_REQUIRES_DOMAIN_CONFIG_CHANGES

INSTALL

DOMAIN SERVICE

1997

NOT_REPLICATED_CONFIG_CHANGES_TO_INSTALL_AD_DS

COPY

CONFIG CHANGES

1998

AD_DS_INSTALLATION_QUIT

STOP

DOMAIN SERVICE

2000

APPLIED_NTFS_SECURITY_SETTINGS

APPLY

SETTING

2001

APPLY_NTFS_SECURITY_SETTINGS_FAILED

APPLY

SETTING

2012

CANT_INSTALL_AD_DS_AS_FOREST_IS_NOT_PREPARED

INSTALL

DOMAIN SERVICE

2022

TRANSFER_OPERATIONS_MASTER_ROLES_FAILED_TO_REMOTE_DS

MOVE

ROLE

2023

REPLICATE_DIRECTORY_PARTITION_FAILED

COPY

PARTITION

2025

UNABLE_TO_GET_USER_CREDENTIAL_FOR_REQUESTED_OPERATION

GET

CREDENTIAL

2027

CREATE_APPLICATION_DIRECTORY_PARTITION_FAILED_INSUFFICIENT_PERMISSION

CREATE

PARTITION

2029

CERTIFICATE_AUTHENTICATION_FAILED

AUTHENTICATE

CERTIFICATE

2032

AD_DS_BACKUP_PREPARATION_FAILED

INITIALIZE

BACKUP

2039

RAISED_DOMAIN_FUNCTIONAL_LEVEL

RAISE

LEVEL

2040

RAISED_FOREST_FUNCTIONAL_LEVEL

RAISE

LEVEL

2043

INVALIDATED_SCRIPT_SIGNATURE

INVALIDATE

SIGNATURE

2046

CLOSED_CONNECTIONS_AS_LDAP_SEND_QUEUES_FULL

CLOSE

CONNECTION

2047

CANT_REPLICATE_CONFIG_SCHEMA_INFO

COPY

INFORMATION

2049

NO_OF_CONNECTIONS_REQUESTED_EXCEEDED_ADMIN_LIMIT

EXCEED

CONNECTION

2050

RESTORE_AD_DS_BACKUP_FILES_FAILED

RESTORE

FILE

2055

DATABASE_RESTORE_FAILED

RESTORE

DATABASE

2060

AD_DS_DB_BACKUP_PREPARATION_FAILED

BACKUP

DATABASE

2062

AD_DS_COULD_NOT_BOOT_NORMALLY

START

DOMAIN SERVICE

2085

LDAP_SSL_CONNECTION_CANT_ESTABLISH

CREATE

CONNECTION

2097

FAILED_TO_DISABLE_OR_ENABLE_REPLICATION

CONFIGURE

REPLICATION

2101

PAUSED_NET_LOGON_SERVICE

PAUSE

SERVICE

2112

NSPI_BIND_OPERATION_COMPLETED

FINISH

BIND

2116

CANT_START_RODC_INSTALL_FROM_MEDIA_PROMOTION

START

PROMOTION

2117

CANT_START_DC_INSTALL_FROM_MEDIA_PROMOTION

START

PROMOTION

2118

INSTALL_AD_DS_FAILED

INSTALL

DOMAIN SERVICE

2500

SHUTDOWN_AD_DS_AS_EXPIRATION_DATE_NOT_FOUND

SHUTDOWN

DIRECTORY SERVICE

2501

SHUTDOWN_AD_DS_AS_TRIAL_PERIOD_EXPIRED

SHUTDOWN

DIRECTORY SERVICE

2502

STARTED_AD_DS_TRIAL_VERSION

STARTUP

DIRECTORY SERVICE

2504

CREATED_VSS_ACCESS_CONTROL_KEY

CONFIGURE

KEY

2505

CREATE_VSS_ACCESS_CONTROL_VALUE_FAILED

CONFIGURE

VALUE

2506

ADDED_VSS_ACCESS_CONTROL_REGISTRY_KEY

UPDATE

REGISTRY

2507

INITIALIZE_SHADOW_COPY_SERVICE_FAILED

INITIALIZE

SERVICE

2508

INITIALIZE_SHADOW_COPY_SERVICE_FAILED

INITIALIZE

SERVICE

2509

OPEN_TCP_PORT_FAILED

OPEN

PORT

2510

ADD_APPLICATION_DIRECTORY_PARTITION_REPLICA_FAILED

UPDATE

REPLICA

2511

CREATED_SERVICE_PRINCIPAL_NAME

CREATE

PRINCIPAL

2512

CANT_ESTABLISH_MUTUALLY_AUTHENTICATED_CONNECTION

CREATE

CONNECTION

2513

SET_CONNECTION_AUTHENTICATION_PROTOCOL_FAILED

SET

PROTOCOL

2514

UNABLE_TO_BIND_DOMAIN

BIND

DOMAIN

2515

UNABLE_TO_CRACK_ACCOUNT

SEARCH

ACCOUNT

2516

UNABLE_TO_UPDATE_SERVICE_PRINCIPAL_NAME

UPDATE

PRINCIPAL

2517

WROTE_SERVICE_PRINCIPAL_NAME

WRITE

PRINCIPAL

2521

DIRLOG_ADAM_NO_AUDITING

INITIALIZE

SYSTEM

2524

DIR_SERVICE_DETECT_DATABASE_REPLACE

UPDATE

DATABASE

2538

DIRLOG_ADAM_SERVICE_ACCOUNT_CHANGED

UPDATE

ACCOUNT

2542

DIR_SERVICE_DETECT_DATABASE_REPLACE

UPDATE

DATABASE

2550

CANNOT_INSTALL_REPLICA_IN_FOREST_USING_LOCAL_ACCOUNT

INSTALL

REPLICA

2551

ACCOUNT_CANNOT_AUTHENTICATE_WITH_REPLICA_SOURCE_USING_KERBEROS_MUTUAL_AUTHENTICATION

AUTHENTICATE

ACCOUNT

2553

CANNOT_INSTALL_REPLICA_IN_FOREST_USING_BUILTIN_OR_DOMAIN ACCOUNT

INSTALL

REPLICA

2554

ACCOUNT_NAME_DOESNOT_MATCH_SOURCE_SERVER_ACCOUNT_NAME

COMPARE

ACCOUNT

2555

ACCOUNT_CANNOT_AUTHENTICATE_WITH_REPLICA_SOURCE_USING_NTLM_AUTHENTICATION

AUTHENTICATE

ACCOUNT

2557

UNINSTALLING_DOMAIN_SERVICES

UNINSTALL

SERVICE

2560

RECEIVED_REQUEST_TO_BEGIN_INBOUND_REPLICATION

REQUEST

SERVICE

2561

COMPLETED_REQUEST_TO_REMOVE_LOCAL_REPLICA_OF_DIRECTORY_PARTITION

DROP

REPLICA

2564

RECEIVED_REQUEST_TO_BEGIN_INBOUND_REPLICATION

REQUEST

SERVICE

2567

COMPLETED_REQUEST_TO_UNINSTALL_INSTANCE

UNINSTALL

INSTANCE

2574

DS_BEGUN_UNINSTALL

UNINSTALL

SERVICE

2575

DS_COMMITTED_UNINSTALL_DATABASE

UNINSTALL

DATABASE

2579

UNINSTALL_CANT_CONNECT_ACTIVE_DIRECTORY_DOMAIN_SERVICES

CONNECT

DOMAIN SERVICE

2580

PREPARE_DOMAIN_CONTROLLER_FOR_UNINSTALL

UNINSTALL

CONTROLLER

2581

UNINSTALL_CONNECT_NAMING_MASTER_FAILED

CONNECT

MASTER

2587

CRITICAL_FAILURE_TO_GET_USER_INPUT

GET

INPUT

2590

CONNECT_TO_SERVER_AS_DOMAIN_USER

CONNECT

SERVER

2591

CONNECT_TO_SERVER_AS_LOGGED_ON_USER

CONNECT

SERVER

2595

COMMIT_UNINSTALL_DATABASE_SUCCESSFUL

UNINSTALL

DATABASE

2603

FIND_DELETE_SERVICE_CONNECTION_POINTS_UNDER_SERVICE_ACCOUNT_OBJECT

DELETE

POINT

2612

COMPLETE_REMOVAL_OF_ACTIVE_DIRECTORY_DOMAIN_SERVICES

DROP

DOMAIN SERVICE

2800

DENIED_REPLICATION_CACHE_REQUEST_FOR_SECURITY_PRINCIPAL

DENY

REQUEST

2812

FAILED_TO_GENERATE_WRITE_REFERRAL_TO_WRITABLE_DC

CREATE

REFERRAL

2813

GENERATED_WRITE_REFERRAL_TO_WRITABLE_DC

CREATE

REFERRAL

2817

OPENED_UDP_ENDPOINT

OPEN

POINT

2818

OPEN_UDP_PORT_FAILED_FOR_EXCLUSIVE_USE

OPEN

PORT

2819

VALIDATE_NSPI_MAX_CONNECTION_LIMIT_FAILED

VALIDATE

LIMIT

2820

NSPI_MAX_CONNECTION_LIMIT_REACHED

EXCEED

CONNECTION

2828

NOT_AN_ACTIVE_DIRECTORY_DOMAIN_CONTROLLER_ACCOUNT

VALIDATE

ACCOUNT

2834

ADD_WRITABLE_REPLICA_DIRECTORY_PARTITION_FAILED

UPDATE

REPLICA

2840

REQUIRE_STARTUP_COM_PLUS_EVENT_SYSTEM_SERVICE

START

SERVICE

2841

BACKUP_ACTIVE_DIRECTORY_DOMAIN_SERVICES_FAILED

BACKUP

DOMAIN SERVICE

2842

REMOTE_PROCEDURE_CALL_TOOK_TOO_LONG_TO_COMPLETE

FINISH

CALL

2866

ABORT_OBJECT_OPERATION_AS_LOGGING_MAX_LIMIT_REACHED

ABORT

OPERATION

2869

CANT_START_INSTALL_FROM_MEDIA_PROMOTION_OF_DOMAIN CONTROLLER

START

PROMOTION

2872

REPLICATE_NAMING_CONTEXT_NOT_ALLOWED_TO_PROCEED

COPY

CONTEXT

2873

CANT_INITIALIZE_AD_DS_AS_UPDATE_DEFAULT_SECURITY_ON_OBJECT_FAILED

UPDATE

DEFAULT SECURITY

2881

PAUSED_NET_LOGON_SERVICE

PAUSE

SERVICE

2883

DIRLOG_DRA_REPLICATION_GET_FILTERED_SET_ACCESS_DENIED_DC

DENY

ACCESS

2884

IDENTIFIED_UNTRUSTED_CLIENT_DURING_REPLICATION

NOTIFY

CLIENT

2885

IDENTIFIED_UNTRUSTED_CLIENT_DURING_REPLICATION

NOTIFY

CLIENT

2887

DIRLOG_WOULD_REJECT_UNSIGNED_CLIENTS

BIND

SERVER

2888

DIRLOG_HAVE_REJECTED_UNSIGNED_CLIENTS

BIND

SERVER

2889

DIRLOG_UNSIGNED_CLIENT_DETAILS

BIND

SERVER

2890

UNABLE_TO_GAIN_AUTHORIZATION

ACQUIRE

AUTHORIZATION

2891

UPDATE_SERVICE_PRINCIPAL_NAME

UPDATE

PRINCIPAL

2892

UPDATE_SERVICE_PRINCIPAL_NAME_FAILED

UPDATE

PRINCIPAL

2893

REPLICATE_SERVICE_PRINCIPAL_NAME_FAILED

COPY

PRINCIPAL

2895

SYNCHRONIZE_ATTRIBUTES_IN_FILTERED_SET_FAILED

SYNCHRONIZE

ATTRIBUTE

2896

DENIED_ACCESS_FOR_DIRECTORY_PARTITION_SYNCHRONIZATION

DENY

ACCESS

104

DATABSE_STOPPED_WITH_ERROR

STOP

INSTANCE

203

STOPPED_DATABASE_BACKUP_WITH_ERROR

BACKUP

DATABASE

214

DATABASE_BACKUP_STOPPED_WITH_ERROR

BACKUP

DATABASE

217

ERROR_DURING_DATABASE_FILE_BACKUP

BACKUP

FILE

455

ERROR_IN_OPENING_LOG_FILE

OPEN

LOGFILE

471

UNABLE_TO_ROLLBACK_OPERATION_ON_DATABASE

ROLLBACK

OPERATION

481

READ_FROM_DATABASE_FILE_FAILED

READ

FILE

490

OPEN_DATABASE_FILE_FAILED_FOR_READ_WRITE_ACCESS

OPEN

FILE

494

DATABSE_RECOVERY_FAILED

RECOVER

DATABASE

705

ONLINE_DEFRAGMENTATION_OF_DATABASE_TERMINATED_PREMATURELY

ABORT

DEFRAGMENTATION


Security Audit Trail Events

Table M-2 lists the Security audit trail events and their command_class and target_type mappings in the Oracle AVDF audit record.

Table M-2 Security Audit Trail Events

Event ID Source Event command_class target_type

4662

OPERATE_OBJECT

EXECUTE

OBJECT

4928

ESTABLISH_SOURCE_NAMING_CONTEXT

CREATE

CONTEXT

4929

REMOVE_SOURCE_NAMING_CONTEXT

DROP

CONTEXT

4930

MODIFY_SOURCE_NAMING_CONTEXT

UPDATE

CONTEXT

4931

REMOVE_DESTINATION_NAMING_CONTEXT

UPDATE

CONTEXT

4932

BEGIN_SYNCRONIZE_NAMING_CONTEXT

SYNCRONIZE

CONTEXT

4933

END_SYNCRONIZE_NAMING_CONTEXT

SYNCRONIZE

CONTEXT

4934

REPLICATE_OBJECT_ATTRIBUTES

COPY

ATTRIBUTE

4935

BEGIN_FAILURE_REPLICATION

FAIL

REPLICATE

4936

END_FAILURE_REPLICATION

FAIL

REPLICATE

4937

REMOVE_LINGERING_OBJECT_FROM_REPLICA

DROP

OBJECT

5136

MODIFY_OBJECT

UPDATE

OBJECT

5137

CREATE_OBJECT

CREATE

OBJECT

5138

RESTORE_OBJECT

RESTORE

OBJECT

5139

MOVE_OBJECT

MOVE

OBJECT

5141

DELETE_OBJECT

DELETE

OBJECT