Windows Security Log Event ID 4621
Operating Systems |
Windows 2008 R2 and 7
Windows 2012 R2 and 8.1
Windows 2016 and 10
Windows Server 2019 and 2022
|
Category • Subcategory | System • Security State Change |
Type
|
Success
|
Corresponding events
in Windows
2003 and before |
|
4621: Administrator recovered system from CrashOnAuditFail
On this page
In testing I configured the log to crash on audit failure and then filled up the security log which indeed brought the system down. I rebooted, reset the CrashOnAuditFail registry setting, cleared the log and restarted. The event was never logged. I haven't been able to produce this event. Have you? If so, please start a discussion (see above) and post a sample along with any comments you may have! Don't forget to sanitize any private information.
Free Security Log Resources by Randy
Supercharger Free Edition
Your entire Windows Event Collection environment on a single pane of glass.
Free.