Event ID: 4905
An attempt was made to unregister a security event sourceAn attempt was made to unregister a security event source. Subject Security ID: %1 Account Name: %2 Account Domain: %3 Logon ID: %4 Process: Process ID: %7 Process Name: %8 Event Source: Source Name: %5 Event Source ID: %6
This event generates every time a security event source is unregistered.
You typically see this event if specific roles were removed, for example, Internet Information Services.
Microsoft Documentation
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Audit Policy Change"
Operating Systems:
Windows Vista Windows 2008 Windows 7 Windows 2008 R2 Windows 8 Windows 2012 Windows 8.1 Windows 2012 R2 Windows 10 Windows 2016 Windows 2019Tags:
Audit SuccessLEFT/RIGHT arrow keys for navigation
Back to List