2 IDL constants for windows event codes.
6 pointer_default(unique)
8 interface windows_events
11 typedef [v1_enum,public] enum {
13 EVT_ID_SUCCESSFUL_LOGON
= 4624,
14 EVT_ID_UNSUCCESSFUL_LOGON
= 4625,
15 EVT_ID_PASSWORD_CHANGE
= 4723,
16 EVT_ID_PASSWORD_RESET
= 4724,
17 EVT_ID_USER_ADDED_TO_GLOBAL_SEC_GROUP
= 4728,
18 EVT_ID_USER_REMOVED_FROM_GLOBAL_SEC_GROUP
= 4729,
19 EVT_ID_USER_ADDED_TO_LOCAL_SEC_GROUP
= 4732,
20 EVT_ID_USER_REMOVED_FROM_LOCAL_SEC_GROUP
= 4733,
21 EVT_ID_USER_ADDED_TO_LOCAL_GROUP
= 4746,
22 EVT_ID_USER_REMOVED_FROM_LOCAL_GROUP
= 4747,
23 EVT_ID_USER_ADDED_TO_GLOBAL_GROUP
= 4751,
24 EVT_ID_USER_REMOVED_FROM_GLOBAL_GROUP
= 4752,
25 EVT_ID_USER_ADDED_TO_UNIVERSAL_SEC_GROUP
= 4756,
26 EVT_ID_USER_REMOVED_FROM_UNIVERSAL_SEC_GROUP
= 4757,
27 EVT_ID_USER_ADDED_TO_UNIVERSAL_GROUP
= 4761,
28 EVT_ID_USER_REMOVED_FROM_UNIVERSAL_GROUP
= 4762
31 /* See https://learn.microsoft.com/en-us/windows-server/security/credentials-protection-and-management/authentication-policies-and-authentication-policy-silos#BKMK_ErrorandEvents */
32 typedef [v1_enum,public] enum {
34 AUTH_EVT_ID_NTLM_DEVICE_RESTRICTION
= 101,
35 AUTH_EVT_ID_KERBEROS_DEVICE_RESTRICTION
= 105,
36 AUTH_EVT_ID_KERBEROS_DEVICE_RESTRICTION_AUDIT
= 305,
37 AUTH_EVT_ID_KERBEROS_SERVER_RESTRICTION
= 106,
38 AUTH_EVT_ID_KERBEROS_SERVER_RESTRICTION_AUDIT
= 306
41 typedef [v1_enum,public] enum {
42 EVT_LOGON_INTERACTIVE
= 2,
43 EVT_LOGON_NETWORK
= 3,
45 EVT_LOGON_SERVICE
= 5,
47 EVT_LOGON_NETWORK_CLEAR_TEXT
= 8,
48 EVT_LOGON_NEW_CREDENTIALS
= 9,
49 EVT_LOGON_REMOTE_INTERACTIVE
= 10,
50 EVT_LOGON_CACHED_INTERACTIVE
= 11