Windows Security Log Event ID 645
Operating Systems |
Windows Server 2000
Windows 2003 and XP
|
Category | Account Management |
Type
|
Success
|
Corresponding events
in Windows
2008 and Vista |
4741
|
645: Computer Account Created
On this page
"Caller" user created a new computer account. Note that internally Windows appends a $ to all computer account names and this is reflected in other events where computer account names are listed.
Free Security Log Resources by Randy
- New Account Name: %1
- New Domain: %2
- New Account ID: %3
- Caller User Name: %4
- Caller Domain: %5
- Caller Logon ID: %6
- Privileges %7
- Attributes:
- Sam Account Name: %8
- Display Name: %9
- User Principal Name: %10
- Home Directory: %11
- Home Drive: %12
- Script Path: %13
- Profile Path: %14
- User Workstations: %15
- Password Last Set: %16
- Account Expires: %17
- Primary Group ID: %18
- AllowedToDelegateTo: %19
- Old UAC Value: %20
- New UAC Value: %21
- User Account Control: %22
- User Parameters: %23
- Sid History: %24
- Logon Hours: %25
- DNS Host Name: %26
- Service Principal Names: %27
Supercharger Free Edition
Your entire Windows Event Collection environment on a single pane of glass.
Free.
Computer Account Created:
New Account Name:COMP1$
New Domain:ELMW2
New Account ID:comp1
DEL:30f31309-cd32-4171-aad9-be7ddbfd04fe
Caller User Name:Administrator
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x12D622)
Privileges-
Windows Server 2003 adds these fields
Attributes:
Sam Account Name:FILESERVER12$
Display Name:-
User Principal Name:-
Home Directory:-
Home Drive:-
Script Path:-
Profile Path:-
User Workstations:-
Password Last Set:
Account Expires:
Primary Group ID:515
AllowedToDelegateTo:-
Old UAC Value:0x0
New UAC Value:0x85
User Account Control:
Account Disabled
'Password Not Required' - Enabled
'Workstation Trust Account' - Enabled
User Parameters:-
Sid History:-
Logon Hours:
DNS Host Name:-
Service Principal Names:-
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection