Event ID: 578

Privileged object operation

Privileged object operation:
    Object Server:     %1
    Object Handle:     %2
    Process ID:        %3
    Primary User Name: %4
    Primary Domain:    %5
    Primary Logon ID:  %6
    Client User Name:  %7
    Client Domain:     %8
    Client Logon ID:   %9
    Privileges:        %10
    Object Type:       %11
    Object Name:       %12
    Desired Access:    %13

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /category:"Privilege Use"
How to enable Windows Auditing

Audit Category:
Privilege Use
Corresponding Events:

LEFT/RIGHT arrow keys for navigation

Back to List