SQL Server Audit Log Event ID 24048
24048: Issued a create database audit specification command (action_id CR class_type DA)
This is an event from
SQL Server
audit event from
LOGbinder SQL
generated by
.
On this page
A create database audit specification command was issued
Free Security Log Resources by Randy
Field |
Description |
Occurred |
When event was reported by SQL Server |
Authorization result |
If the command passed authorization checks |
Session ID |
ID of the session on which the event occurred |
User |
|
Server |
|
Database |
Database affected by the event |
Audit Specification Name |
Defines which Audit Action Groups will be audited for the entire server (Server Audit Specification) or database (Database Audit Specification). See SQL Server Audit Policy . |
Statement |
Transact-SQL statement |
Supercharger Free Edition
This Event Is Produced By
Which Integrates with Your SIEM
Issued a created database audit specification command
A create database audit specification command was issued
Action Group: AUDIT_CHANGE_GROUP
Occurred: 9/16/2013 1:26:41.0000000 AM
Authorization result: Access allowed
Session ID: 60
User: LB\Administrator
Server: DEV2
Database: master
Audit Specification Name: TestDBAuditSpec
Statement: CREATE DATABASE AUDIT SPECIFICATION TestDBAuditSpec ; FOR SERVER AUDIT TestServerAudit ; -- ADD (APPLICATION_ROLE_CHANGE_PASSWORD_GROUP),; -- ADD (AUDIT_CHANGE_GROUP),; -- ADD (BACKUP_RESTORE_GROUP),; -- ADD (DATABASE_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_ACCESS_GROUP),; -- ADD (DATABASE_OBJECT_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_OWNERSHIP_CHANGE_GROUP),; -- ADD (DATABASE_OBJECT_PERMISSION_CHANGE_GROUP),; -- ADD (DATABASE_OPERATION_GROUP),; -- ADD (DATABASE_OWNERSHIP_CHANGE_GROUP),; -- ADD (DATABASE_PERMISSION_CHANGE_GROUP),; -- ADD (DATABASE_PRINCIPAL_CHANGE_GROUP),; -- ADD (DATABASE_PRINCIPAL_IMPERSONATION_GROUP),; -- ADD (DATABASE_ROLE_MEMBER_CHANGE_GROUP),; -- ADD (DBCC_GROUP),; -- ADD (SCHEMA_OBJECT_ACCESS_GROUP),; -- ADD (SCHEMA_OBJECT_CHANGE_GROUP),; -- ADD (SCHEMA_OBJECT_OWNERSHIP_CHANGE_GROUP),; -- ADD (SCHEMA_OBJECT_PERMISSION_CHANGE_GROUP); ADD ( SELECT, UPDATE, INSERT, DELETE, EXECUTE, RECEIVE, REFERENCES; ON TestDatabase BY dbo ); WITH (STATE=ON)
For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=24048
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection