I'm aware of what a transaction is in terms of databases and other similar types of events (bank transactions, credits, debits, etc) but in terms of this event, we're just not

Event ID 4985 - The state of a transaction has cha...

DateTime 10.10.2000 19:00:00 Source Name of an Application or System Service originating the event.

  Subject: Security ID: Account Name: Account Domain: Logon ID: Transaction Information: RM Transaction ID: New State: Resource Manager:
This field can help you correlate this event with other events that might contain the same Transaction ID, such as "4656(S, F): A handle to an object was requested."Note  GUID is an

What triggers this event?

Event Id4985SourceMicrosoft-Windows-Security-AuditingDescriptionThe state of a transaction has changed.

The system uses the SID in the access token to identify the user in all subsequent interactions with Windows security.

It's a part of the Transaction Manager for the filesystem, which you can take a peek at here.

Event 4985 S: The state of a transaction has changed.

Audit Logon Event 4624 S: An account was successfully logged on.

Each time a user logs on, the system retrieves the SID for that user from the database and places it in the access token for that user.

Subject: Security ID: SYSTEM Account Name: WIN-R9H529RIO4Y$ Account Domain: WORKGROUP Logon ID: 0x3e7 Transaction Information: RM Transaction ID: {7a1beac9-ab0f-11dc-a998-000c29fee385} New State: 48 Resource Manager: Go to the node Audit Policy (Security Settings->Local Policy->Audit Policy). 3.

Audit Filtering Platform Packet Drop Event 5152 F: The Windows Filtering Platform blocked a packet. Event 5038 F: Code integrity determined that the image hash of a file is not valid. Event 6409: BranchCache: A service connection point object could not be parsed. http://supportcanonprinter.com/event-id/error-7886-severity-20-state-2.html Event 4715 S: The audit policy, SACL, on an object was changed.

Event 4906 S: The CrashOnAuditFail value has changed. Audit Network Policy Server Audit Other Logon/Logoff Events Event 4649 S: A replay attack was detected. Audit Distribution Group Management Event 4749 S: A security-disabled global group was created. Event 4946 S: A change has been made to Windows Firewall exception list.

Doesn't imply success or failure ;) permalinkembedsavegive gold[–]workedupsosexual[S] 1 point2 points3 points 3 years ago(1 child) It's to do with filesystem journaling Already this is better information than I was able to obtain

Each account has a unique SID that is issued by an authority, such as an Active Directory domain controller, and stored in a security database.

Event 4663 S: An attempt was made to access an object. Event 4794 S, F: An attempt was made to set the Directory Services Restore Mode administrator password. Open the Local Security Policy by running the command secpol.msc. 2. Event 5060 F: Verification operation failed.

Event 4904 S: An attempt was made to register a security event source. Event 4696 S: A primary token was assigned to process. Audit User/Device Claims Event 4626 S: User/Device claims information. Event 4614 S: A notification package has been loaded by the Security Account Manager.

By using Auditpol, we can get/set Audit Security settings per user level and computer level.