Skip to main content
Skip table of contents

V 2.0 : Group Management Events

Vendor Documentation

Classification

Rule NameRule TypeCommon EventClassification
V 2.0 : Group Management EventsBase RuleGroup InformationInformation
V 2.0 : EVID 4727 : Sec-Enable Global Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4728 : Member Add to Sec-Enable GlobalSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4729 : Member Remove from Sec-EnabledSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4730 : Sec-Enable Global Group DeleteSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4731 : Sec-Enabled Local Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4732 : Member Add to Sec-Enable LocalSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4733 : Member Remove from Sec-EnabledSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4734 : Sec-Enable Local Group DeleteSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4735 : Sec-Enable Local Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4737 : Sec-Enable Global Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4744 : Sec-Disable Local Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4745 : Sec-Disable Local Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4746 : Member Add to Sec-Disable LocalSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4747 : Member Remove from Sec-DisableSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4748 : Sec-Disable Local Group DeleteSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4749 : Sec-Disable Global Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4750 : Sec-Disable Global Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4751 : Member Add to Sec-Disable GlobalSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4752 : Member Remove from Sec-DisabledSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4753 : Sec-Disable Global Group DeletedSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4754 : Sec-Enabled Univ Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4755 : Sec-Enable Univ Group ModifiedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4756 : Member Add to Sec-Enable UnivSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4757 : Member Remove from Sec-EnabledSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4758 : Sec-Enable Global Univ DeleteSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4759 : Sec-Disable Univ Group CreateSub RuleGroup CreatedAccount Created
V 2.0 : EVID 4760 : Sec-Disable Univ Group ModifiSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4761 : Member Add to Sec-Disable UnivSub RuleAccount Added to GroupAccess Granted
V 2.0 : EVID 4762 : Member Remove from Sec-DisableSub RuleAccount Removed from GroupAccess Revoked
V 2.0 : EVID 4763 : Sec-Disable Global Univ DeleteSub RuleGroup DeletedAccount Deleted
V 2.0 : EVID 4764 : Group Type ChangedSub RuleGroup Attribute ModifiedAccount Modified
V 2.0 : EVID 4799 : Sec-Enable Local Group MembersSub RuleObject ReadAccess Success

Mapping with LogRhythm Schema  

Device Key in Log MessageLogRhythm SchemaSchema Description
ProviderN/AIdentifies the provider that logged the event. The Name and GUID attributes are included if the provider used an instrumentation manifest to define its events. The EventSourceName attribute is included if a legacy event provider (using the Event Logging API) logged the event.
EventID<vmid>The identifier that the provider used to identify the event.
VersionN/A The version number of the event's definition.
Level<severity>The severity level defined in the event.
Task<vendorinfo>The task defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
OpcodeN/A The opcode defined in the event. Task and Opcode are typically used to identify the location in the application from where the event was logged.
Keywords<result>A bitmask of the keywords defined in the event. Keywords are used to classify types of events (for example, events associated with reading data).
TimeCreatedN/A The time stamp that identifies when the event was logged. The time stamp will include either the SystemTime attribute or the RawTime attribute.
EventRecordIDN/A The record number assigned to the event when it was logged.
CorrelationN/A The activity identifiers that consumers can use to group related events together.
ExecutionN/A Contains information about the process and thread that logged the event.
ChannelN/A The channel to which the event was logged.
Computer<dname>The name of the computer on which the event occurred.
MemberName<account>The distinguished name of account that was added to the group. For example: CN=Auditor,CN=Users,DC=contoso,DC=local. For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is “-”.
MemberSid

<domainimpacted>

<account>

The SID of account that was added to the group.
TargetUserName<group>The name of the group to which new member was added.
TargetDomainName<domainimpacted>The domain name of the group to which new member was added. Formats vary, and include the following:
  • Domain NETBIOS name example: CONTOSO
  • Lowercase full domain name: contoso.local
  • Uppercase full domain name: CONTOSO.LOCAL
  • Built-in groups: Builtin
TargetSidN/A The SID of the group to which new member was added.
SubjectUserSid

<domainorigin>

<login>

The SID of account that requested the add member to the group operation.
SubjectUserName<login>The name of the account that requested the add member to the group operation.
SubjectDomainName<domainorigin>The subject’s domain name. Formats vary, and include the following:
  • Domain NETBIOS name example: CONTOSO
  • Lowercase full domain name: contoso.local
  • Uppercase full domain name: CONTOSO.LOCAL
  • For some well-known security principals, such as LOCAL SERVICE or ANONYMOUS LOGON, the value of this field is NT AUTHORITY.
SubjectLogonId<session>A hexadecimal value that can help you correlate this event with recent events that might contain the same Logon ID.
PrivilegeListN/A The list of user privileges which were used during the operation, for example, SeBackupPrivilege. This parameter might not be captured in the event, and in that case appears as “-”.
CallerProcessId<processid>Hexadecimal Process ID of the process that enumerated the members of the group. Process ID (PID) is a number used by the operating system to uniquely identify an active process.
CallerProcessName<process>Full path and the name of the executable for the process.
GroupTypeChange<action>N/A
JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.