EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Logon/Logoff (5)
Operating Systems
  • Windows 10 (5)
  • Windows 2016 (5)
  • Windows 2019 (5)
  • Windows 2022 (5)
  • Windows 2012 (4)
  • Windows 2012 R2 (4)
  • Windows 8 (4)
  • Windows 8.1 (4)
  • Windows 2008 (3)
  • Windows 2008 R2 (3)
  • Windows 7 (3)
  • Windows Vista (3)
Tags
  • Audit Success (4)
  • CJIS (2)
  • CMMC L1 (2)
  • HIPAA (2)
  • ISO 27001:2013 (2)
  • NIST 800-171 (2)
  • NIST SP 800-53 (2)
  • Audit Failure (1)
  • PCI-DSS (1)
Auditing
  • Always (3)
  • Conditional (2)
Volume
  • Low (5)
  • Medium (5)
  • High (3)
  • Very high (1)
Audit Subcategory
  • Logon (2)
  • Account Lockout (1)
  • Group Membership (1)
  • Logoff (1)
  • User / Device Claims (1)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
4624 An account was successfully logged on
CJIS, Audit Success, ISO 27001:2013, HIPAA, NIST SP 800-53, CMMC L1, NIST 800-171
4625 An account failed to log on
Audit Failure, CJIS, ISO 27001:2013, PCI-DSS, HIPAA, NIST SP 800-53, NIST 800-171, CMMC L1
4626 User / Device claims information
Audit Success
4627 Group membership information
Audit Success
4634 An account was logged off
Audit Success



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy