System32
Sysmon
Events
Compliance
Validator
TLS/SSL
GeoIP
Tools
Windows Security Events
Audit Category
Policy Change
(3)
Logon/Logoff
(1)
Object Access
(1)
Operating Systems
Windows 10
(5)
Windows 11
(5)
Windows 2008 R2
(5)
Windows 2012
(5)
Windows 2012 R2
(5)
Windows 2016
(5)
Windows 2019
(5)
Windows 2022
(5)
Windows 2025
(5)
Windows 7
(5)
Windows 8
(5)
Windows 8.1
(5)
Windows Vista
(5)
Windows 2008
(4)
Tags
Audit Failure
(2)
Audit Success
(1)
Auditing
Conditional
(5)
Volume
Low
(4)
High
(1)
Medium
(1)
Very high
(1)
Audit Subcategory
Filtering Platform Policy Change
(3)
File Share
(1)
Other Logon/Logoff Events
(1)
AppLocker
All AppLocker events
EventSentry
All EventSentry events
Security
All Windows Security events
Sysmon
All Sysmon events
ID
Event Description
5168
Spn check for SMB/SMB2 fails.
Audit Failure
5457
IPsec Policy Agent failed to apply Active Directory storage IPsec policy on the computer.
5459
IPsec Policy Agent failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.
5461
PAStore Engine failed to apply local registry storage IPsec policy on the computer
5632
A request was made to authenticate to a wireless network.
Audit Success, Audit Failure