ChangeAuditor for AD (InTrust for AD) log rules expect the 'distinguishedName' attribute value for the object name.
For Example:
CN=User1,CN=Users,DC=domain,DC=com
One method to retrieve this value is via Active Directory Users and Computers (ADUC).
1. Ensure 'Advanced Features' is enabled.
2. Right-click and select 'Properties' on the object in question.
3. Select the 'Attribute Editor' tab.
4. Locate the 'distinguishedName' attribute and click 'View'.
5. Copy the value for use in the real-time rule 'Object' parameter.