windows 2008 event id database

when you do not know an event id but have an understanding of what you want to look for, is there a database where you can search by keyword - for example "remove user from group"- find it from the list, get the event id and then look in event viewer for that event id?

Who is Participating?
AmitConnect With a Mentor IT ArchitectCommented:
In order to trace that, first you need to enable the Auditing settings. Goto>Default Domain Controller policy and see what is enabled. Attaching screenshot.

Then goto to security logs and trace for event id

609 -  User Right Removed  

Here is the site which you are searching

I hope you have all your answer now
AmitIT ArchitectCommented:
Best site is

Try this way while searching in google, this way you can drill down into the site

sites: put your description
sites: exchange
anushahannaAuthor Commented: to search by description is asking for membership.

sites: remove user from group
did not bring anything quickly or easily.

any other options?
Making Bulk Changes to Active Directory

Watch this video to see how easy it is to make mass changes to Active Directory from an external text file without using complicated scripts.

AmitIT ArchitectCommented:
Search on google.
anushahannaAuthor Commented:
I am trying..

compared to "remove user from group"
what are other appropriate words to search by?
AmitIT ArchitectCommented:
Try like

how to remove user from group active directory

what are you really trying to find. I can help you fast
anushahannaAuthor Commented:
thanks Amit-

someone removed domain users from Admin group- just need to check the audit on that- when it was done.
anushahannaAuthor Commented:
very very good - thanks.
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.