Microsoft-Windows-Security-Audit-Configuration-Client
32 events across 2 channels
Event ID 100 — Group policy processing for audit settings initiated.
Message
Event ID 101 — Group policy processing for audit settings could not be started.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 102 — List of applicable GPOs.
Message
Fields
| Name | Description |
|---|---|
GPOList | List of applicable GPOs |
Example Event
system:
provider: Microsoft-Windows-Security-Audit-Configuration-Client
guid: 08466062-AED4-4834-8B04-CDDB414504E5
event_source_name: ''
event_id: 102
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T23:49:58.045589+00:00'
event_record_id: 40
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-Security-Audit-Configuration-Client/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
GPOList: 'Local Group Policy
'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 103 — Group policy processing for audit settings started.
Message
Event ID 104 — Failed to create local directory for downloading audit settings.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 105 — Processing audit settings from the following GPO.
Message
Fields
| Name | Description |
|---|---|
Display_Name | — |
GPO_ID | — |
SYSVOL_Path | — |
GPOName | — |
GPOID | — |
SysvolPath | — |
Event ID 106 — Successfully downloaded the audit settings file as follows.
Message
Fields
| Name | Description |
|---|---|
Remote_File | — |
Local_File | — |
GPO_Name | — |
RemoteFile | — |
LocalFile | — |
GPOName | — |
Event ID 107 — Failed to downloaded the audit settings file as follows.
Message
Fields
| Name | Description |
|---|---|
Remote_File | — |
Local_File | — |
GPO_Name | — |
Error | — |
RemoteFile | — |
LocalFile | — |
GPOName | — |
ErrorCode | — |
Event ID 108 — Successfully configured the audit settings on the system.
Message
Event ID 109 — Failed to configure the audit settings on the system.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorCode | — |
Event ID 110 — Successfully generated RSoP data in WMI.
Message
Event ID 111 — Failed to generate RSoP data in WMI.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 112 — Group policy processing for audit settings finished successfully.
Message
Event ID 113 — Group policy processing for audit settings finished with error.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 114 — Successfully communicated the results of the operation to group policy engine.
Message
Event ID 115 — Failed to communicate the results of the operation to group policy engine.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 200 — Group policy processing for central access policy settings initiated.
Message
Event ID 201 — Group policy processing for central access policy settings could not be started.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 202 — List of applicable GPOs.
Message
Fields
| Name | Description |
|---|---|
GPOList | — |
Event ID 203 — Group policy processing for central access policy settings started.
Message
Event ID 204 — Failed to create local directory for downloading central access policy settings.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 205 — Processing central access policy settings from the following GPO.
Message
Fields
| Name | Description |
|---|---|
Display_Name | — |
GPO_ID | — |
SYSVOL_Path | — |
GPOName | — |
GPOID | — |
SysvolPath | — |
Event ID 206 — Successfully downloaded the central access policy settings file as follows.
Message
Fields
| Name | Description |
|---|---|
Remote_File | — |
Local_File | — |
GPO_Name | — |
RemoteFile | — |
LocalFile | — |
GPOName | — |
Event ID 207 — Failed to downloaded the central access policy settings file as follows.
Message
Fields
| Name | Description |
|---|---|
Remote_File | — |
Local_File | — |
GPO_Name | — |
Error | — |
RemoteFile | — |
LocalFile | — |
GPOName | — |
ErrorCode | — |
Event ID 208 — Successfully configured the central access policy settings on the system.
Message
Event ID 209 — Failed to configure the central access policy settings on the system.
Message
Fields
| Name | Description |
|---|---|
Error | — |
ErrorCode | — |
Event ID 210 — Successfully generated RSoP data in WMI.
Message
Event ID 211 — Failed to generate RSoP data in WMI.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 212 — Group policy processing for central access policy settings finished successfully.
Message
Event ID 213 — Group policy processing for central access policy settings finished with error.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 214 — Successfully communicated the results of the operation to group policy engine.
Message
Event ID 215 — Failed to communicate the results of the operation to group policy engine.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |