Forum Discussion
ⓛ ⓤⓝ W
Dec 15, 2017Copper Contributor
Window server 2012 R2 audit SAM log issue
Hi all,
I have a question about the audit log 4661.
I am using advanced audit logging. Enabled audit SAM and audit kernel object which generate event id 4661.
Now I have 2 2012 R2 DC, one is setup without any window update. Another one installed all recommend and important update.
The situation is, when a domain user logged off.
DC without update can generate event id 4661.
DC with updates will not generate event id 4661 but event 4768,4769.
What can I do to make the DC with updates generate 4661 when a user is logged off?
No RepliesBe the first to reply