Windows

auditpol

CautionAudit policy

auditpol /get /category:*

Shows/sets what gets audited — when failed logons never appear in the log, enable them here.

Examples

  • auditpol /set /subcategory:"Logon" /failure:enableAudit failed logons

Syntax

auditpol /get|/set /category:... [/success:enable]

Before you run it

Over-auditing floods the logs.

Related commands

The same reference, with no signal at all

Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.

Get it free on the App Store