Controls which outcomes of a Windows audit subcategory are recorded in the Security event log.
Values
| Enum Value | Description |
|---|---|
|
|
Record only events that completed successfully. |
|
|
Record only events that failed. |
|
|
Do not record events for this subcategory. |
|
|
Record both successful and failed events. |
Used by
AuditAccountLogontype: Account Logon audit subcategories for credential validation events.AuditAccountManagementtype: Account Management audit subcategories for user and group account operations.AuditDetailedTrackingtype: Detailed Tracking audit subcategories for process and application monitoring.AuditDSAccesstype: Directory Service Access audit subcategories for Active Directory operations.AuditLogonLogofftype: Logon/Logoff audit subcategories for authentication and session events.AuditObjectAccesstype: Object Access audit subcategories for file, registry, and resource access.AuditPolicyChangetype: Policy Change audit subcategories for monitoring security policy modifications.AuditPrivilegeUsetype: Privilege Use audit subcategories for monitoring use of user rights.AuditSystemtype: System audit subcategories for system-level security events.
Example
Example
"SUCCESS"