EventSentry
  • System32
  • Sysmon
  • Events
  • Compliance
  • Validator
  • TLS/SSL
  • GeoIP
  • Tools


Windows Security Events



Audit Category
  • Logon/Logoff (9)
Operating Systems
  • Windows 10 (9)
  • Windows 11 (9)
  • Windows 2008 (9)
  • Windows 2008 R2 (9)
  • Windows 2012 (9)
  • Windows 2012 R2 (9)
  • Windows 2016 (9)
  • Windows 2019 (9)
  • Windows 2022 (9)
  • Windows 7 (9)
  • Windows 8 (9)
  • Windows 8.1 (9)
  • Windows Vista (9)
Tags
  • Audit Failure (9)
  • Audit Success (9)
Auditing
  • Conditional (9)
Volume
Audit Subcategory
  • Network Policy Server (9)

AppLocker
  • All AppLocker events
EventSentry
  • All EventSentry events
Security
  • All Windows Security events
Sysmon
  • All Sysmon events
ID Event Description
6272 Network Policy Server granted access to a user.
Audit Success, Audit Failure
6273 Network Policy Server denied access to a user.
Audit Success, Audit Failure
6274 Network Policy Server discarded the request for a user.
Audit Success, Audit Failure
6275 Network Policy Server discarded the accounting request for a user.
Audit Success, Audit Failure
6276 Network Policy Server quarantined a user.
Audit Success, Audit Failure
6277 Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.
Audit Success, Audit Failure
6278 Network Policy Server granted full access to a user because the host met the defined health policy.
Audit Success, Audit Failure
6279 Network Policy Server locked the user account due to repeated failed authentication attempts.
Audit Success, Audit Failure
6280 Network Policy Server unlocked the user account.
Audit Success, Audit Failure



© netikus.net ltd 2002-2025 | EventSentry | Event Log Messages | Codes | Sysmon | STIG | AppLocker | Privacy Policy