Event IDs
This is not a comprehensive list of event IDs. The full list will be available at a later date.
LSASS events
Event name | Event ID | Description |
---|---|---|
LSASSSERVICESTARTED | 1000 | The authentication service was started. |
LSASSSERVICECONFIGURATIONCHANGED | 1004 | AD Bridge authentication service provider configuration settings have been reloaded. |
SUCCESSFULLOGONCREATESESSION | 1201 | Successful logon: Authentication provider lsa-local-provider Successful logon: Authentication provider lsa-activedirectory-provider |
SUCCESSFULLOGONCHECKUSER | 1203 | Successful logon: Authentication provider lsa-local-provider Successful logon: Authentication provider lsa-activedirectory-provider |
FAILEDLOGONACCOUNTDISABLED | 1207 | Logon Failure: Authentication provider: lsa-activedirectory-provider |
FAILEDLOGONPASSWORDEXPIRED | 1211 | Logon Failure: Authentication provider: lsa-activedirectory-provider |
SUCCESSFULLOGOFF | 1220 | User Logoff: Authentication provider lsa-local-provider User Logoff: Authentication provider lsa-activedirectory-provider |
SUCCESSFULINITIATIONOFADSESSION | 1224 | An Active Directory user account has initiated an active session |
SUCCESSFULTERMINATIONOFADSESSION | 1225 | An Active Directory user account has terminated their active session. |
SUCCESSFULAUTHENTICATIONSSH | 1230 | Successful Logon: Authentication provider: lsa-local-provider Successful Logon: Authentication provider: lsa-activedirectory-provider |
SUCCESSFULAUTHENTICATIONOTHER | 1249 | Successful Logon: Authentication provider: lsa-activedirectory-provider |
FAILEDAUTHENTICATIONSSH | 1250 | Logon Failure: Authentication provider: lsa-activedirectory-provider Logon Failure: Authentication provider: lsa-local-provider …. |
FAILEDAUTHENTICATIONOTHER | 1269 | Logon Failure: Authentication provider: lsa-activedirectory-provider |
SUCCESSFULUSERACCOUNTPASSWORDCHANGE | 1300 | Change Password Attempt: Authentication provider: lsa-activedirectory-provider |
FAILEDUSERACCOUNTPASSWORDCHANGE | 1301 | Change Password Attempt: Authentication provider: lsa-activedirectory-provider |
SUCCESSFULUSERACCOUNTKERBREFRESH | 1302 | Refreshed Active Directory user account Kerberos credentials. Authentication provider: lsa-activedirectory-provider |
SUCCESSFULMACHINEACCOUNTPASSWORDUPDATE | 1320 | Updated Active Directory machine password. Authentication provider: lsa-activedirectory-provider |
SUCCESSFULMACHINEACCOUNTTGTREFRESH | 1322 | Refreshed Active Directory machine account TGT (Ticket Granting Ticket). Authentication provider: lsa-activedirectory-provider |
ADDUSERACCOUNT | 1400 | User account created. Authentication provider: lsa-local-provider |
SUCCESSFULPROVIDERINITIALIZATION | 1500 | AD Bridge authentication service provider initialization succeeded. Authentication provider: lsa-activedirectory-provider AD Bridge authentication service provider initialization succeeded. Authentication provider: lsa-local-provider |
FAILEDPROVIDERINITIALIZATION | 1501 | AD Bridge authentication service provider initialization failed. Authentication provider: lsa-activedirectory-provider |
REQUIREMEMBERSHIPOFUPDATED | 1502 | AD Bridge authentication service provider login restriction settings have been reloaded. Authentication provider: lsa-activedirectory-provider |
AUDITINGCONFIGURATIONENABLED | 1503 | AD Bridge authentication service provider auditing settings have been updated. Authentication provider: lsa-activedirectory-provider |
NETWORKDOMAINONLINE | 1700 | Detected domain controller for Active Directory domain. Switching to online mode: Authentication provider: lsa-activedirectory-provider |
NETWORKDOMAINOFFLINE | 1701 | Detected unreachable global catalog server for Active Directory forest. Switching to offline mode: Authentication provider: lsa-activedirectory-provider Detected unreachable domain controller for Active Directory domain. Switching to offline mode: Authentication provider: lsa-activedirectory-provider |
Domain join events
Event name | Event ID | Description |
---|---|---|
SUCCESSFULDOMAINJOIN | 1000 | Domain join successful. Domain name Domain name (short) |
FAILEDDOMAINJOIN | 1001 | Domain leave failed. Reason message: |
SUCCESSFULDOMAINLEAVE | 1002 | Domain leave successful. Domain name Domain name (short) |
FAILEDDOMAINLEAVE | 1003 | Domain leave failed. Reason message: |
GPAgent events
Event name | Event ID | Description |
---|---|---|
GPAGENTSERVICESTARTED | 1000 | The AD Bridge group policy service was started. |
GPAGENTSERVICECONFIGURATIONCHANGED | 1004 | AD Bridge group policy service provider configuration settings have been reloaded. |
SUCCESSFULPOLICYUPDATE | 1100 | Group Policy update succeeded. Client-Side Extension: AD Bridge - GP Extension CSE library name : |
User monitor events
Event name | Event ID | Description |
---|---|---|
USERMONITORLOCALUSERGROUPADDED | 1000 | Between unknown and , user was added. |
USERMONITORADUSERGROUPADDED | 1002, 1003, 1004 | Between unknown and , user/group <user/group> was added. |
Netlogon events
Event name | Event ID | Description |
---|---|---|
NETLOGONSERVICESTARTED | 1000 | The Likewise site manager service was started. |
NETLOGONSERVICESTOPPED | 1002 | The Likewise site manager service was stopped. |
Updated 12 days ago