Chat now with support
Chat with Support

Change Auditor 7.5 - Event Reference Guide

Change Auditor Service event log

The Change Auditor Service event log contains the following types of events depending on the event logging enabled in Change Auditor:

Registry events

The following table lists the events that will be recorded to the Change Auditor Service event log when Registry event logging is enabled in Change Auditor.

101

Binary registry value added

102

Binary registry value changed

103

Binary registry value deleted

104

Numeric registry value added

105

Numeric registry value changed

106

Numeric registry value deleted

107

String registry value added

108

String registry value changed

109

String registry value deleted

110

Registry key added

111

Registry key deleted

Local Groups events

The following table lists the events that will be recorded to the Change Auditor Service event log when Local Account event logging is enabled in Change Auditor.

201

Local group added

202

Local group removed

203

Local group renamed

204

Member added to local group

205

Member removed from local group

301

Account disabled for local user

302

Account enabled for local user

303

Account expiration change for local user

304

Active session limit changed for local user

305

Allow reconnection option changed for local user

306

Can’t change password option changed for local user

307

Connect client drives at logon option changed for local user

308

Connect client printers at logon option changed for local user

309

Default to main client printer option changed for local user

310

Deny this user terminal services permission changed for local user

311

Dial-in callback number changed for local user

312

Dial-in callback options changed for local user

313

Dial-in static IP address changed for local user

314

Dial-in static routes changed for local user

315

Dial-in verify caller-ID changed for local user

316

Disconnected session timeout changed for local user

317

Enable remote control changed for local user

318

Home folder mapped drive changed for local user

319

Home folder path changed for local user

320

Idle session limit changed for local users

321

Local user account locked

322

Local user account unlocked

323

Local user added

324

Local user badPwdCount changed

325

Local user logged on

326

Local user removed

327

Local user renamed

328

Logon program filename changed for local user

329

Logon program folder changed for local user

330

Logon script changed for local user

331

Must change password at next logon option changed for local user

332

Password changed for local user

333

Password never expires option changed for local user

334

Password required option changed for local user

335

Profile path changed for local user

336

Remote access permission changed for local user

337

Remote control level of control option changed for local user

338

Remote control require user’s permission option changed for local user

339

Session limit action changed for user

340

Start the following program at logon option changed for local user

341

Terminal services home folder mapped drive change for local user

342

Terminal services home folder path changed for local user

343

Terminal services profile path changed for local user

Service events

The following table lists the events the will be recorded to the Change Auditor Service event log when Service event logging is enabled in Change Auditor.

401

Service account changed

402

Service dependencies changed

403

Service paused

404

Service recovery actions changed

405

Service resumed

406

Service start type changed

407

Service started

408

Service stopped

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating