{"id":363,"date":"2014-03-26T07:40:27","date_gmt":"2014-03-25T21:40:27","guid":{"rendered":"https:\/\/girl-germs.com\/?p=363"},"modified":"2015-09-27T15:09:53","modified_gmt":"2015-09-27T05:09:53","slug":"advanced-audit-policy-which-gpo-corresponds-with-which-event-id","status":"publish","type":"post","link":"https:\/\/girl-germs.com\/?p=363","title":{"rendered":"Advanced Audit Policy &#8211; which GPO corresponds with which Event ID"},"content":{"rendered":"<p>I spent a good part of a day a few weeks ago searching around looking for a simple spreadsheet or table that lists the Advanced Audit GPO&#8217;s and what Event ID&#8217;s they correspond to. I couldn&#8217;t find one. Went through 4 pages of Google results, went through multiple TechNet articles. Could not find something that simply stated &#8220;These event ID&#8217;s are covered by this GPO&#8221;. The closest I could find was this link &#8211; <a href=\"http:\/\/www.windowsecurity.com\/articles-tutorials\/authentication_and_encryption\/Event-IDs-Windows-Server-2008-Vista-Revealed.html\">Event IDs for Windows Server 2008 and Vista Revealed!<\/a> &#8211; but it didn&#8217;t list them in the way I wanted, nor did it include everything that I could see listed in my GPO&#8217;s.<\/p>\n<p>This is important information to me &#8211; I&#8217;m currently trying to tweak our security settings so that what we&#8217;re logging is *actually* useful rather than thousands upon thousands of lines with logons and logoffs. A list like this would allow me to filter our event logs, to then be able to see which GPO&#8217;s I could easily turn on or off in order to get the filtered results I&#8217;m looking for &#8211; and prevent my event logs from filling up with useless crap!<\/p>\n<p>So, because I couldn&#8217;t find it, I decided to make it myself&#8230;and because I figured I wouldn&#8217;t be the only one looking for it, I thought I might share it with the world!<\/p>\n<style type=\"text\/css\">\n\ttable.tableizer-table {\n\tborder: 1px solid #CCC; font-family: Tahoma, Geneva, sans-serif\n\tfont-size: 10px;\n} \n.tableizer-table td {\n\tpadding: 4px;\n\tmargin: 3px;\n\tborder: 1px solid #ccc;\n}\n.tableizer-table th {\n\tbackground-color: #77108C; \n\tcolor: #FFF;\n\tfont-weight: bold;\n}\n<\/style>\n<table class=\"tableizer-table\">\n<tr class=\"tableizer-firstrow\">\n<th>Group Policy Group<\/th>\n<th>Group Policy Option<\/th>\n<th>Event IDs<\/th>\n<\/tr>\n<tr>\n<td>Account Logon<\/td>\n<td>Audit Credential Validation<\/td>\n<td>4774, 4775, 4776, 4777<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Kerberos Authentication Service<\/td>\n<td>4768, 4771, 4772<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Kerberos Service Ticket Operations<\/td>\n<td>4769, 4770<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Account Logon Events<\/td>\n<td>4649, 4778, 4779, 4800, 4801, 4802, 4803, 5378, 5632, 5633<\/td>\n<\/tr>\n<tr>\n<td>Account Management<\/td>\n<td>Audit Application Group Management<\/td>\n<td>4783, 4784, 4785, 4786, 4787, 4788, 4789, 4790<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Computer Account Management<\/td>\n<td>4741, 4742, 4743<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Distribution Group Management<\/td>\n<td>4744, 4745, 4746, 4747, 4748, 4749, 4750, 4751, 4752, 4753, 4759, 4760, 4761, 4762<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Account Management Events<\/td>\n<td>4782, 4793<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Security Group Management<\/td>\n<td>4727, 4728, 4729, 4730, 4731, 4732, 4733, 4734, 4735, 4737, 4754, 4755, 4756, 4757, 4758, 4764<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit User Account Management<\/td>\n<td>4720, 4722, 4723, 4724, 4725, 4726, 4738, 4740, 4765, 4766, 4767, 4780, 4781, 4794, 5376, 5377<\/td>\n<\/tr>\n<tr>\n<td>Detailed Tracking<\/td>\n<td>Audit DPAPI Activity<\/td>\n<td>4692, 4693, 4694, 4695<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Process Creation<\/td>\n<td>4688, 4696<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Process Termination<\/td>\n<td>4689<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit RPC Events<\/td>\n<td>5712<\/td>\n<\/tr>\n<tr>\n<td>DS Access<\/td>\n<td>Audit Detailed Directory Service Replication<\/td>\n<td>4928, 4929, 4930, 4931, 4934, 4935, 4936, 4937<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Directory Service Access<\/td>\n<td>4662<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Directory Service Changes<\/td>\n<td>5136, 5137, 5138, 5139, 5141<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Directory Service Replication<\/td>\n<td>4932, 4933<\/td>\n<\/tr>\n<tr>\n<td>Logon\/Logoff<\/td>\n<td>Audit Account Lockout<\/td>\n<td>4625<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit IPsec Extended Mode<\/td>\n<td>4978, 4979, 4980, 4981, 4982, 4983, 4984<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit IPsec Main Mode<\/td>\n<td>4646, 4650, 4651, 4652, 4653, 4655, 4976, 5049, 5453<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit IPsec Quick Mode<\/td>\n<td>4977, 5451, 5452<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Logoff<\/td>\n<td>4634, 4647<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Logon<\/td>\n<td>4624, 4625, 4648, 4675<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Network Policy Server<\/td>\n<td>6272, 6273, 6274, 6275, 6276, 6277, 6278, 6279, 6280<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Logon\/Logoff Events<\/td>\n<td>4649, 4778, 4779, 4800, 4801, 4802, 4803, 5378, 5632, 5633<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Special Logon<\/td>\n<td>4964<\/td>\n<\/tr>\n<tr>\n<td>Object Access<\/td>\n<td>Audit Application Generated<\/td>\n<td>4665, 4666 ,4667, 4668<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Certification Services<\/td>\n<td>4868, 4869, 4870, 4871, 4872, 4873, 4874, 4875, 4876, 4877, 4878, 4879, 4880, 4881, 4882, 4883, 4884, 4885, 4886 ,4887, 4888, 4889, 4890, 4891, 4892, 4893, 4894, 4895, 4896, 4897, 4898<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Detailed File Share<\/td>\n<td>5145<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit File Share<\/td>\n<td>5140, 5142, 5143, 5144, 5168<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit File System<\/td>\n<td>4664, 4985, 5051<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Filtering Platform Connection<\/td>\n<td>5031, 5140, 5150, 5151, 5154, 5155, 5156, 5157, 5158, 5159<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Filtering Platform Packet Drop<\/td>\n<td>5152, 5153<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Handle Manipulation<\/td>\n<td>4656, 4658, 4690 <\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Kernel Object<\/td>\n<td>4659, 4660, 4661, 4663<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Object Access Events<\/td>\n<td>4671, 4691, 4698, 4699, 4700, 4701, 4702 ,5148, 5149, 5888, 5889, 5890<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Registry<\/td>\n<td>4657, 5039<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit SAM<\/td>\n<td>4659, 4660, 4661, 4663<\/td>\n<\/tr>\n<tr>\n<td>Policy Change<\/td>\n<td>Audit Audit Policy Change<\/td>\n<td>4715, 4719, 4817, 4902, 4904, 4905, 4906, 4907, 4908, 4912<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Authentication Policy Change<\/td>\n<td>4713, 4716, 4717, 4718, 4739, 4864, 4865, 4866, 4867<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Authorization Policy Change<\/td>\n<td>4704, 4705, 4706, 4707, 4714<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Filtering Platform Policy Change<\/td>\n<td>4709, 4710, 4711, 4712, 5040, 5041, 5042, 5043, 5044, 5045, 5046, 5047, 5048, 5440, 5441, 5442, 5443, 5444, 5446, 5448, 5449, 5450, 5456, 5457, 5458, 5459, 5460, 5461, 5462, 5463, 5464, 5465, 5466, 5467, 5468, 5471, 5472, 5473, 5474, 5477<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit MPSSVC Rule-Level Policy Change<\/td>\n<td>4944, 4945, 4946, 4947, 4948, 4949, 4950, 4951, 4952, 4953, 4954, 4956, 4957, 4958<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Policy Change Events<\/td>\n<td>4670, 4909, 4910, 5063, 5064, 5065, 5066, 5067, 5068, 5069, 5070, 5447, 6144, 6145<\/td>\n<\/tr>\n<tr>\n<td>Privilege Use<\/td>\n<td>Audit Non-Sensitive Privilege Use<\/td>\n<td>4672, 4673, 4674<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Sensitive Privilege Use<\/td>\n<td>4672, 4673, 4674<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other Privilege Use Events<\/td>\n<td>N\/A<\/td>\n<\/tr>\n<tr>\n<td>System<\/td>\n<td>Audit IPsec Driver<\/td>\n<td>4960, 4961, 4962, 4963, 4965, 5478, 5479, 5480, 5483, 5484, 5485<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Other System Events<\/td>\n<td>5024, 5025, 5027, 5028, 5029, 5030, 5032, 5033, 5034, 5035, 5037, 5058, 5059, 6400, 6401, 6402, 6403 ,6404, 6405, 6406, 6407, 6408<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Security State Change<\/td>\n<td>4608, 4609 ,4616, 4621<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit Security System Extension<\/td>\n<td>4610, 4611, 4614, 4622, 4697<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>Audit System Integrity<\/td>\n<td>4612, 4615, 4618, 4816, 5038, 5056, 5057, 5060, 5061, 5062, 6281<\/td>\n<\/tr>\n<tr>\n<td>Glbal Object Access Auditing<\/td>\n<td>Registry (GOAA)<\/td>\n<td>N\/A<\/td>\n<\/tr>\n<tr>\n<td>&nbsp;<\/td>\n<td>File System (GOAA)<\/td>\n<td>N\/A<\/td>\n<\/tr>\n<\/table>\n<p>I figure if only one person finds it useful, then the 2 or so hours I spent doing this and double-checking it against the GPO&#8217;s are well worth it!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I spent a good part of a day a few weeks ago searching around looking for a simple spreadsheet or table that lists the Advanced Audit GPO&#8217;s and what Event ID&#8217;s they correspond to. I couldn&#8217;t find one. Went through 4 pages of Google results, went through multiple TechNet articles. Could not find something that simply stated &#8220;These event ID&#8217;s&#8230; <a href=\"https:\/\/girl-germs.com\/?p=363\">Read more &raquo;<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[5,328,2,7],"tags":[191,193,192,189,190],"class_list":["post-363","post","type-post","status-publish","format-standard","hentry","category-sys-admin","category-techstuff","category-technology","category-work","tag-audit","tag-event-id","tag-event-log","tag-gpo","tag-group-policy"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/p2Tmk1-5R","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/posts\/363","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/girl-germs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=363"}],"version-history":[{"count":6,"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/posts\/363\/revisions"}],"predecessor-version":[{"id":394,"href":"https:\/\/girl-germs.com\/index.php?rest_route=\/wp\/v2\/posts\/363\/revisions\/394"}],"wp:attachment":[{"href":"https:\/\/girl-germs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=363"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/girl-germs.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=363"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/girl-germs.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=363"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}