Audit policy subcategory
1actions
1reasons
1sources
Livestatus
One subcategory of the Windows audit policy, which decides what the Security log records.
Identified by: sparklogs.config_change.target, which carries a GUID.
| Action | Reported by | What that reason says |
|---|---|---|
updated | audit_policy_changed on Windows Security event log | Local audit policy changed (system, object security descriptor, or per-user). These events are dependable even when other audit subcategories are off. |