Windows Security Log Event ID 647

Operating Systems Windows Server 2000
Windows 2003 and XP
CategoryAccount Management
Type Success
Corresponding events
in Windows 2008
and Vista
4743  

647: Computer Account Deleted

On this page

"Caller" user deleted "target" computer account.

Note, this event also gets logged when a trust relationship is deleted. "Target" account name will correspond to the trusted/ing domain appended with a $.

Free Security Log Resources by Randy

Description Fields in 647

  • Target Account Name: %1
  • Target Domain: %2
  • Target Account ID: %3
  • Caller User Name: %4
  • Caller Domain: %5
  • Caller Logon ID: %6
  • Privileges: %7

Setup PowerShell Audit Log Forwarding in 4 Minutes

 

Examples of 647

Computer Account Deleted:
Target Account Name:COMP1$
Target Domain:ELMW2
Target Account ID:comp1
Caller User Name:Administrator
Caller Domain:ELMW2
Caller Logon ID:(0x0,0x12D622)
Privileges:-

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection



 

Upcoming Webinars
    Additional Resources

      Go To Event ID:

      Security Log
      Quick Reference
      Chart
      Download now!