Event ID 4618
A monitored security event pattern has occurred.A monitored security event pattern has occurred.
Subject:
Security ID: %3
Account Name: %4
Account Domain: %5
Logon ID: %6
Alert Information:
Computer: %2
Event ID: %1
Number of Events: %7
Duration: %8
This event is generated when Windows is configured to generate alerts in accordance with the Common Criteria Security Audit Analysis requirements (FAU_SAA) and an auditable event pattern occurs.
Auditing:
Conditional
Volume:
Low
This event is not generated by Windows, it is generated with the "%windir%\system32\rundll32 %windir%\system32\authz.dll, AuthziGenerateAdminAlertAudit" command. As such, the volume depends on the caller.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"System Integrity"
LEFT/RIGHT arrow keys for navigation
Back to List