Skip to main content
Skip table of contents

EVID 4673, 4674 : Privileged Object Access (Part 2) (Security)

Event Details

Event TypeAudit Sensitive Privilege Use
Event Description
  • 4673(S, F) : A privileged service was called.
  • 4674(S, F) : An operation was attempted on a privileged object.
Event IDs4673, 4674


This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there is no value parsed for a specified log field.

Log FieldLogRhythm DefaultLogRhythm Default v2.0
ProviderN/AN/A
EventID<vmid><vmid>
VersionN/AN/A
Level<severity><severity>
Task<tag1><vendorinfo>
OpcodeN/AN/A
KeywordsN/A<result>, <tag1>
TimeCreatedN/AN/A
EventRecordIDN/AN/A
CorrelationN/AN/A
ExecutionN/AN/A
ChannelN/AN/A
Computer<dname><dname>
EventData<vendorinfo>, <tag4>N/A
SubjectUserSidN/AN/A
SubjectUserNameN/A<login>
SubjectDomainNameN/A<domainorigin>
SubjectLogonIdN/A<session>
ObjectServerN/AN/A
Account Name<login>, <tag2>N/A
Account Domain<domain>N/A
LogonID<session>N/A
ServiceN/A<objectname>
ObjectType<tag3><objecttype> 
ObjectName<object> <objectname>
HandleIdN/AN/A
AccessMaskN/AN/A
PrivilegeListN/A<subject>
ProcessId<processid><processid>
ProcessName<process><process>
HandleIdN/A<object>

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

Regex IDRule NameRule TypeCommon EventClassification
1000622EVID 1102, 4673, 4674 : Privileged Object AccessBase RuleObject AccessedAccess Success
EVID 4673 : Fail Priv Svc CallSub RuleAccess Object FailureAccess Failure
EVID 1102 : Audit Log ClearedSub RuleLog ClearedAccess Success
EVID 4673 : Priv Svc CallSub RuleObject AccessedAccess Success
EVID 4674 : Fail Priv Object OperationSub RuleAccess Object FailureAccess Failure
EVID 4674 : Privileged Object OperationSub RuleObject AccessedAccess Success

LogRhythm Default v2.0


Regex IDRule NameRule TypeCommon EventClassification
1011151V 2.0 : Privilege Use EventsBase RuleObject Access AttemptOther Audit
V 2.0 : EVID 4673 : Privilege Service Call SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4673 :  Privilege Service Call FailedSub RuleAccess Object FailureAccess Failure
V 2.0 : EVID 4674 : Oper On Privileged Obj SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4674 : Oper On Privileged Obj FailedSub RuleAccess Object FailureAccess Failure
V 2.0 : EVID 4673 : Privilege Service Call SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4673 : Privilege Service Call SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4673 :  Privilege Service Call FailedSub RuleAccess Object FailureAccess Failure
V 2.0 : EVID 4673 :  Privilege Service Call FailedSub RuleAccess Object FailureAccess Failure
V 2.0 : EVID 4674 : Oper On Privileged Obj SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4674 : Oper On Privileged Obj SucceedSub RuleObject AccessedAccess Success
V 2.0 : EVID 4674 : Oper On Privileged Obj FailedSub RuleAccess Object FailureAccess Failure
V 2.0 : EVID 4674 : Oper On Privileged Obj SucceedSub RuleObject AccessedAccess Success
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.