Detection rules › By eventMicrosoft-Windows-Security-Auditing event 47195 detection rules reference this event. View event page.Sigma (2)Important Windows Event Auditing Disabled severity high T1562.002 Windows Event Auditing Disabled severity low T1562.002 Elastic (1)Sensitive Audit Policy Sub-Category Disabled T1070, T1070.001, T1562, T1562.002, T1562.006 Splunk (2)Windows AD Domain Controller Audit Policy Disabled T1562.001 Windows Important Audit Policy Disabled T1562.001