Event Name,?????? Type,???? Event ID,??? Version,??? Channel,????? Level,???? Opcode,?????? Task,??????????? Keyword,??????? PID,??????? TID,???? Processor Number,? Instance ID,?? Parent Instance ID,????????????????????????????? Activity ID,????????????????????? Related Activity ID,?????????? Clock-Time, Kernel(ms),?? User(ms), User Data
DsDirSearch,????? Start,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 1,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577092364013,??????? 105,??????? 210, "DS", 4, 6, 1141178432,??????? 0, "LSA", "deep", "DC=exchange,DC=local", " (sAMAccountName=EXCHANGE-XP-02$) ", "[types_only]", "SDflags:0x0;",? 0x5404000000000B0000000000 DsDirSearch,??????? End,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 2,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577092366011,??????? 105,??????? 210, "DS", 4, 6, 1157955648,??????? 0, "0", " (sAMAccountName=EXCHANGE-XP-02$) ", "idx_sAMAccountName:1:N;", "1", "1", "NTDS", "",? 0x54040000000050145404
DsDirSearch,????? Start,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 1,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577093494882,??????? 105,??????? 210, "DS", 4, 6, 1141178432,??????? 0, "NTDSAPI", "deep", "DC=exchange,DC=local", " (sAMAccountName=EXCHANGE-XP-02$) ", "distinguishedName", "", "", "",? 0x0000540400000000 DsDirSearch,??????? End,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 2,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577093497496,??????? 105,??????? 210, "DS", 4, 6, 1157955648,??????? 0, "0", " (sAMAccountName=EXCHANGE-XP-02$) ", "idx_sAMAccountName:1:N;", "1", "1", "NTDS",? 0x00314EFCFE070000E0060901
DsDirSearch,????? Start,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 1,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577093738939,??????? 105,??????? 225, "DS", 4, 6, 1141178432,??????? 0, "NTDSAPI", "deep", "DC=exchange,DC=local", " (sAMAccountName=EXCHANGE-XP-02$) ", "distinguishedName", "", "", "",? 0x0000540400000000 DsDirSearch,??????? End,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 2,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000984,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577093741473,??????? 105,??????? 225, "DS", 4, 6, 1157955648,??????? 0, "0", " (sAMAccountName=EXCHANGE-XP-02$) ", "idx_sAMAccountName:1:N;", "1", "1", "NTDS",? 0x00314EFCFE070000E0060901
DsDirSearch,????? Start,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 1,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000530,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577094493737,??????? 165,??????? 825, "DS", 4, 6, 1141178432,? 4194304, "10.2.0.2:1052", "base", "CN=EXCHANGE-XP-02,CN=Computers,DC=exchange,DC=local", " (objectClass=*) ", "objectClass", "",? 0xAC2981770000000000005404 DsDirSearch,??????? End,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 2,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000530,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577094494885,??????? 165,??????? 825, "DS", 4, 6, 1157955648,? 4194304, "0", "[]", "[]", "1", "1", "NTDS", "",? 0x0F000000000000000000
DsDirSearch,????? Start,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 1,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000530,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577094915903,??????? 165,??????? 825, "DS", 4, 6, 1141178432,? 4194304, "10.2.0.2:1052", "base", "CN=Windows Virtual Machine,CN=EXCHANGE-XP-02,CN=Computers,DC=exchange,DC=local", " (objectClass=*) ", "objectClass", "", "", "",? 0x5404000000000B00 DsDirSearch,??????? End,??????????? 0,????????? 4,????????? 0,????????? 0,????????? 2,????????? 0, 0x0000000000000000, 0x000001FC, 0x00000530,??????????????????? 0,???????????? ,???????????????????? ,?? {00000000-0000-0000-0000-000000000000},???????????????????????????????????????? ,?? 129104577095060716,??????? 165,??????? 825, "DS", 4, 6, 1157955648,? 4194304, "0", "[]", "[]", "1", "1", "NTDS", "",? 0x0F000000000000000000
|