4937 Security log · DS Access info severity low volume

Windows Event ID 4937 — A lingering object was removed from the replica

An AD object that lingered past its tombstone lifetime was removed.

Why event 4937 matters

Lingering objects are a sign of long-term replication failure. In some attacks, lingering objects are used to maintain access across DC restoration.

How to detect it

Alert: large numbers of lingering objects removed (may indicate USN rollback attack or prolonged replication failure).

Log source
Security
Advanced Audit Policy — enable the 'DS Access' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4937   // A lingering object was removed from the replica
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4937
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# A lingering object was removed from the replica — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4937 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related DS Access events

4662 An operation was performed on an object 4928 An Active Directory replica source naming context was established 4929 An Active Directory replica source naming context was removed 4930 An Active Directory replica source naming context was modified 4932 Synchronization of a replica of an Active Directory naming context has begun 4933 Synchronization of a replica of an Active Directory naming context has ended 4934 Attributes of an Active Directory object were replicated 4935 Replication failure begins 4936 Replication failure ends 5136 A directory service object was modified 5137 A directory service object was created 5138 A directory service object was undeleted

Frequently asked questions

What is Windows Event ID 4937?

A lingering object was removed from the replica. An AD object that lingered past its tombstone lifetime was removed.

Which log records event 4937?

Event 4937 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'DS Access' subcategory (Success and/or Failure).

How do you detect activity around event 4937?

Alert: large numbers of lingering objects removed (may indicate USN rollback attack or prolonged replication failure).