Windows Event Id 4904
Event 4660 S: An object was deleted. Event 6408: Registered product %1 failed and Windows Firewall is now controlling the filtering for %2. Event 5027 F: The Windows Firewall Service was unable to retrieve the security policy from the local storage. Sample: Log Name: Security Source: Microsoft-Windows-Security-Auditing Date: 10/27/2009 9:53:35 PM Event ID: 4902 Task Category: Audit Policy Change Level: Information Keywords: Audit Success User: N/A Computer: dcc1.Logistics.corp Description: The Per-user audit http://0pacity.com/event-id/event-id-4904.html
Event 5028 F: The Windows Firewall Service was unable to parse the new security policy. Event 5447 S: A Windows Filtering Platform filter has been changed. Event 4764 S: A group’s type was changed. We recommend upgrading to the latest Safari, Google Chrome, or Firefox.
Windows Event Id 4904
Audit File Share Event 5140 S, F: A network share object was accessed. The content you requested has been removed. Event 5137 S: A directory service object was created.
Event 6402: BranchCache: The message to the hosted cache offering it data is incorrectly formatted. Event 6405: BranchCache: %2 instances of event id %1 occurred. Event 4660 S: An object was deleted. Audit Sensitive Privilege Use Event 4673 S, F: A privileged service was called.
Terms Privacy Security Status Help You can't perform that action at this time. Auditing Settings On Object Were Changed. Event 4909: The local policy settings for the TBS were changed. Computer Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10 Severity Specify the seriousness of the event. "High" High WhoDomain - WhereDomain - Policy Name Audit Kerberos Service Ticket Operations Event 4769 S, F: A Kerberos service ticket was requested.
Microsoft Customer Support Microsoft Community Forums United States (English) Sign in Home Windows Server 2012 R2 Windows Server 2008 R2 Library Forums We’re sorry. Event 5039: A registry key was virtualized. Audit DPAPI Activity Event 4692 S, F: Backup of data protection master key was attempted. Audit Process Creation Event 4688 S: A new process has been created.
Auditing Settings On Object Were Changed.
Audit Audit Policy Change Updated: June 15, 2009Applies To: Windows 7, Windows Server 2008 R2 This security policy setting determines whether the operating system generates audit events when changes are made Event 4793 S: The Password Policy Checking API was called. Windows Event Id 4904 but no where it mentions how this particular event id - 4902 can be triggered. Event 5377 S: Credential Manager credentials were restored from a backup.
Event 5029 F: The Windows Firewall Service failed to initialize the driver. EventID 4707 - A trust to a domain was removed. Event 4775 F: An account could not be mapped for logon. Check This Out Event 4864 S: A namespace collision was detected.
Event 4722 S: A user account was enabled. Changing the system audit policy. knowledgebase Forum Bot Posts: 170Joined: Wed May 28, 2008 10:09 am Post a reply About the KnowledgeBase Event Repository This is a repository of known Windows Events, hopefully together with
Event 4725 S: A user account was disabled.
Event 6419 S: A request was made to disable a device. Jump to Line Go Contact GitHub API Training Shop Blog About © 2016 GitHub, Inc. Audit Handle Manipulation Event 4690 S: An attempt was made to duplicate a handle to an object. Event 4954 S: Windows Firewall Group Policy settings have changed.
Other Events Event 1100 S: The event logging service has shut down. can someone tell me what operation should i perform that this event id is logged? 4902- the Per-User audit policy table was created. Event 6144 S: Security policy in the group policy objects has been applied successfully. Yes No Additional feedback? 1500 characters remaining Submit Skip this Thank you!
Typically this is an informational event and has little to no security relevance. Event 4947 S: A change has been made to Windows Firewall exception list. Event XML: -
Event 4772 F: A Kerberos authentication ticket request failed. Event 4906 S: The CrashOnAuditFail value has changed. Event 5068 S, F: A cryptographic function provider operation was attempted. Event 5070 S, F: A cryptographic function property modification was attempted.
Not a member? Event 4724 S, F: An attempt was made to reset an account's password.