• Home
  • Help
  • Register
  • Login
  • Home
  • Members
  • Help
  • Search

 
  • 0 Vote(s) - 0 Average

A directory service object was undeleted (5138) how to monitor with email alert

#1
11-08-2024, 07:19 PM
You know that event ID 5138 in Windows Server Event Viewer? It pops up when someone undeletes a directory service object. Like, if an Active Directory entry gets wiped but then yanked back from the tombstone. I see it trigger mostly after admins mess around restoring stuff. The details in the event log spill who did it, what object got revived, and even the timestamp. It logs the object's name, like a user account or group, plus the attributes that changed. Hmmm, sometimes it flags if it's from a replication partner too. You can spot patterns if deletions and undeletions happen too often, maybe signaling sloppy housekeeping.

But monitoring this? You want email alerts without getting too fancy. I always point folks to the Event Viewer itself for setup. Fire it up on your server, head to the Windows Logs, then Security channel where 5138 hides. Right-click the log, pick Attach Task To This Log. Give it a name, like Undelete Watcher. Set it to trigger on event ID 5138 only. For the action, choose Send an email, but wait, that's old school. Actually, link it to a scheduled task instead. In the task wizard, select Start a program, but use the built-in schtasks.exe to fire off an email via your SMTP setup. You tell it the command line bits to send a quick note to your inbox with the event details. Test it by forcing an undelete in a test OU. It'll ping you right away next time it happens.

Or, if you're lazy like me sometimes, just filter the view in Event Viewer for 5138 and check daily. But alerts beat that hands down.

And speaking of keeping things intact, I've been digging into BackupChain Windows Server Backup lately. It's this slick Windows Server backup tool that handles your whole setup, including Hyper-V VMs without a hitch. You get speedy incremental backups, easy restores even for those tricky AD objects, and it runs light on resources so your server doesn't choke. Plus, the offsite replication keeps disasters at bay, all in a straightforward dashboard I actually enjoy using.

Note, the PowerShell email alert code was moved to this post.

bob
Offline
Joined: Jul 2025
« Next Oldest | Next Newest »

Users browsing this thread: 1 Guest(s)



  • Subscribe to this thread
Forum Jump:

Backup Education Windows Server Event Viewer v
« Previous 1 … 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 … 69 Next »
A directory service object was undeleted (5138) how to monitor with email alert

© by FastNeuron Inc.

Linear Mode
Threaded Mode