﻿<?xml version='1.0' encoding='UTF-8'?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/"><channel><title>UltimateWindowsSecurity.com Forum / Ultimate Windows Security Forum / Security Log / 624 - User Account Created </title><generator>InstantForum.NET v4.1.4</generator><description>UltimateWindowsSecurity.com Forum</description><link>http://forum.ultimatewindowssecurity.com/</link><webMaster>noreply@ultimatewindowssecurity.com</webMaster><lastBuildDate>Thu, 17 May 2012 09:01:02 GMT</lastBuildDate><ttl>20</ttl><item><title>New Users - No 624 event generated</title><link>http://forum.ultimatewindowssecurity.com/Topic800-70-1.aspx</link><description>I am attempting to create a report in our new SIEM that will run each week and display all new users accounts created in that week.  I built a custom query to look for 624 events.  I sat down with one of our account provisoners to verify my query results against the actual accounts they created. I am only catching half of the accounts.  I took the list of names of users my report missed and built a quick query looking for all relevant events. All came back with 642s and and 628s, which I know are often generated by a 624 event.  Any idea why there are no 624s? I am just querying our DC's which all have the same level of logging. I also ruled out 2008 machines (4072 events I believe). Any thoughts?</description><pubDate>Wed, 14 Sep 2011 11:12:49 GMT</pubDate><dc:creator>bladerunner</dc:creator></item><item><title>Privileges field in Account Management events</title><link>http://forum.ultimatewindowssecurity.com/Topic268-70-1.aspx</link><description>The field "Privileges" in most of the Account Management events is most of the time empty. Does anyboe have any idea of whose privileges this is supposed to display? &lt;/P&gt;&lt;P&gt;E.g. 624 - User Account Created. Does it show the privileges granted to the created user at the moment of account creation or on the other hand the privileges of the account initiating this action?&lt;/P&gt;&lt;P&gt;I googled the entire internet and MSDN but failed to find anything on this topic.&lt;/P&gt;&lt;P&gt;Would be grateful if someone could shed some light on this.&lt;/P&gt;&lt;P&gt;Thanks in advance.</description><pubDate>Tue, 17 Nov 2009 04:30:27 GMT</pubDate><dc:creator>jsilver</dc:creator></item><item><title>administrator privilege</title><link>http://forum.ultimatewindowssecurity.com/Topic426-70-1.aspx</link><description>Hello,&lt;/P&gt;&lt;P&gt;i'm french and my english is not perfect. I work on a RSA Envision plateform and I want to make a report with event viewer log with the create user and also the administror privilege.&lt;/P&gt;&lt;P&gt;I use the eventid 624, but i dont know where I can see if this user is administrator. In witch Eventid can I have find this reference.&lt;/P&gt;&lt;P&gt;I use also eventid 684 but i haven't also the administrator users.&lt;/P&gt;&lt;P&gt;thank you</description><pubDate>Wed, 11 Aug 2010 10:01:02 GMT</pubDate><dc:creator>Gcetech</dc:creator></item></channel></rss>
