Tema: auditpol
-
Windows audit policy with auditpol: reading subcategories, enforcing them, and sizing the security log
auditpol /get /category:* lists the advanced audit policy actually in effect on Windows Server; subcategory settings win over the basic, category-level policy only while the 'force subcategory settings' option (SCENoApplyLegacyAuditPolicy) is enabled, which is the effective default, and an undersized Security log overwrites or discards audited events.
Legible por máquina: JSON