Event ID 4618: A monitored security event pattern has occurred.
Description | The event is generated when Windows is configured to generate alerts in accordance with the Common Criteria Security Audit Analysis requirements (FAU_SAA) and an auditable event pattern occurs. |
Category | System |
Subcategory | System integrity |
This event logs the following information:
Subject |
|
Alert information |
|
Failure Information |
|
Reasons to monitor this event:
This event can only be generated manually/externally using the following command.
%windir%\system32\rundll32
%windir%\system32\authz.dll,AuthziGenerateAdminAlertAudit
OrgEventId ComputerName UserSid UserName UserDomain
UserLogonId EventCount Duration
Pro tips:
- ADAudit Plus can generate reports and alerts when a monitored security event pattern has occurred.
- These reports consolidate all the information required about the monitored security event, such as time of occurrence, and the domain controller on which it occurs.
Event 4618 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools