Object Access Event: 5889

Active Directory Auditing Tool

The Who, Where and When information is very important for an administrator to have complete knowledge of all activities that occur on their Active Directory. This helps them identify any desired / undesired activity happening. ADAudit Plus assists an administrator with this information in the form of reports. In real-time, ensure critical resources in the network like the Domain Controllers are audited, monitored and reported with the entire information on AD objects - Users, Groups, GPO, Computer, OU, DNS, AD Schema and Configuration changes with 200+ detailed event specific GUI reports and email alerts.

Object Access » Object Access Event: 5889

Event ID 5889 – An object was deleted from the COM+ Catalog.

Event ID 5889
Category Object Access: Other Object Access Events
Type Success Audit

When an object in the COM+ Catalog is deleted, event ID 5889 is logged. This event, though categorized as "Other Object Access Events", would be better suited for the System Integrity sub-category.

This event log contains the following information:

  • Security ID
  • Account Name
  • Account Domain
  • Logon ID
  • COM+ Catalog Collection
  • Object Name
  • Object Details

Why does event ID 5889 need to be monitored?

Monitoring event 5888 helps track all the interactions that a particular COM+ object has. Each COM+ object is uniquely identifiable by its "Object Name".

Pro Tip:

ADAudit Plus provides real-time pre-configured reports and auditing of the changes along with alerts within a Domain & OU. The advanced Group Policy settings real-time audit reports provide detailed information about object related events.

Event 5889 applies to the following operating systems:

  • Windows 2008 R2 and 7
  • Windows 2012 R2 and 8.1
  • Windows 2016 and 10