audit policy change

About this tag
The audit policy change tag on WindowsForum.com covers discussions about Windows Event Log auditing events related to policy changes. Users seek help identifying the root cause of recurring audit events, such as those triggered by security software like SentinelOne on Windows Server 2019. Topics include interpreting event log details, debugging frequent audit policy change alerts, and understanding the interaction between third-party security tools and Windows auditing. The tag is relevant for IT professionals managing SIEM systems and Windows security event monitoring.
  1. T

    I need some assistance finding out what is causing this Event Log Auditing event

    I am using Alienvault to log our SIEM Events from our Windows 2019 servers, and I am trying to find out how to debug what is causing this recurring Auditing Event in our Windows Event Logs. I have found out that SentinelOne is scanning this file at the time, but is there a way to see what...
Back
Top