WinSecWiki
Windows Security Settings
Articles
WinSecWiki
»
Windows Security Settings
»
Local Policies
»
Audit Policy
»
Audit policy change
»
Audit Policy Change
Audit Policy Change
Audit Policy Change
This category tracks any policy changes that would affect what gets reported to the security log. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy
.
Coverage on events generated by this category are currently in the
Security Log Encyclopedia
:
Event ID
Title
4715
The audit policy (SACL) on an object was changed.
4719
System audit policy was changed.
4902
The Per-user audit policy table was created.
4904
An attempt was made to register a security event source.
4905
An attempt was made to unregister a security event source.
4906
The CrashOnAuditFail value has changed.
4907
Auditing settings on object were changed.
4912
Per User Audit Policy was changed.
Add Your Comments
Name:
*
Email Address:
Web Address:
Verification Code:
*
Details
Applies To:
Vista, Windows Server 2008, Windows Server 2008 R2, Windows 8, Windows Server 2012
Rated 5 stars based on 1 vote.
Article has been viewed 4,318 times.
Options
Bookmark Article
Social Bookmarks
Comments RSS
Upcoming Webinars
Cutting through the Hype: What is Big Data Security Analytics?
3 Ways Two-Factor Authentication Can Stop APTs from Spreading
Understanding the Security Boundaries and Risks of Multiple Domains, Forests and Trust Relationships
6 Steps to Classifying Your Data
Top 6 Security Events to Monitor in SQL Server
Top 10 Security Events to Monitor in SharePoint
Additional Resources
Security Log Quick Reference Chart
Learn about the SharePoint Audit Log
Patch Tuesday Analysis
User name:
Password:
/
Forgot?
Register
Home