Skip to main content

Audit policy subcategory

1actions
1reasons
1sources
Livestatus

One subcategory of the Windows audit policy, which decides what the Security log records.

Identified by: sparklogs.config_change.target, which carries a GUID.

ActionReported byWhat that reason says
updatedaudit_policy_changed on Windows Security event logLocal audit policy changed (system, object security descriptor, or per-user). These events are dependable even when other audit subcategories are off.