Someone here could help me.
I want to manager security log in a windows 2008 R2 SP1.
I observe That in Local Security Policy-Audit Policy the policy are not enabled.
When I saw the security log I observe that there is a lot of events:
Source - Microsft Windows security auditing
Event ID -5156 Task Category - Filtering Plataform Connection
Event ID - 5145 - Task Category - Detailed File Share
Event ID -4634 - Task Category - Logoff
etc...........
What event ID in security log are enabled by default ?
Lyra