Windows - Enable Audit Logging

Oscar Romero
Oscar Romero Registered Users, Member, Kaseya Certified, Kaseyan

KASEYAN

edited January 2022 in Solutions

Product Name: Windows - Enable Audit Logging

Version: 1.0

Description : Security is a critical aspect of monitoring and management. Although you may not have a domain based environment for your endpoints, you can still enable domain settings through VSA scripting. This specific script enables logon events on endpoints. You can read about logon events below:
https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/basic-audit-logon-events

Once enabled - we can alert, monitor, and automate these type of security alerts. We can even build security based policies to automate and manage even further.

I wrote a brief article on endpoint standardization.

Happy Automating!
- Oscar Romero
Kaseya Technical Success

Instructions :

Unzip > Import XML through Agent Procedures Module > Automate!


Comments

  • McQ
    McQ Member
    edited September 2019

    How can I update this procedure to disable what has been pushed?  This has begun bottlenecking the SQL host and we need to get it stopped

  • Norberto
    Norberto Member CHOCOLATE MILK
    edited December 2019

    Can this be used on normal window 10 machines? To log failed login to the machine?

  • Brian Davis
    Brian Davis Member CHOCOLATE MILK

    Can this be updated to the new XML format?