WinSecWiki > Security Settings > Advanced Audit Policies > Policy Change > Other Policy Change Events

Audit Other Policy Change Events

So far I've only found one event in this category and it should clearly be in the Filtering Platform Policy Change subcategory instead. As with all subcategories you must use auditpol to enable to disable these events.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
5447 A Windows Filtering Platform filter has been changed.

Back to top

 

Additional Resources