Windows Server services auditing

Copper Contributor

Hi,

I was wondering if it's possible to audit domain joined hosts for changes in services status, like when a service has stopped or if startup type has changed.

 

Thanks,

 

 

3 Replies

@Dave Patrick Hi maybe I wasn't specific, what I meant was that we want to audit the service state using windows event log.

For an example if host A had his service state changed from running to stopped then it will generate an event id 7035/7036 on the windows event log on the Windows Server.

 


@itai248 wrote:

 we want to audit the service state using windows event log.


You can follow along here to build a custom event log filter.

https://techcommunity.microsoft.com/t5/Ask-the-Directory-Services-Team/Advanced-XML-filtering-in-the...