SQL Server Audit Action Group: SERVER_STATE_CHANGE_GROUP

Available in New to:
Database
Audit
Specification
Server
Audit
Specification
2012 2016
  •  

This group tracks state changes (start, pause, stop, resume) on the SQL Server service in Windows.

LOGbinder for SQL Server events generated under this Audit Action Group:

Event ID Description
24054 Started SQL server
24055 Paused SQL server
24056 Resumed SQL server
24057 Stopped SQL server

 

Upcoming Webinars
  • Patch Faster, Break Less: A Practical Guide to Windows 11 OS and 3rd Party Application Updates
  • AI Security Hands-On: Understanding and Red Teaming the LLM as a Black Box
  • Inside Entra ID Authentication: How Tokens, MFA, and Conditional Access Work and Where Attackers Break the Chain
Additional Resources
    Audit Policy
    •Server Audit Specification
    •Database Audit Specification
    •Audit Action Groups
    •Audit Actions
    •Audit Policy Wizard
     
     
    User name:
    Password:
      / Forgot?
      Register
    August 2026
    Patch Tuesday
    "Patch Tuesday - Three Zero Days this Month " - sponsored by Supercharger
    .
    Tweet
    Follow @randyfsmith
    About | Newsletter | Contact Ultimate IT Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, Inc. All rights reserved.
    Disclaimer: We do our best to provide quality information and expert commentary but use all information at your own risk. For complaints, please contact abuse@ultimatewindowssecurity.com.
    Terms of Use | Privacy |
    Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.