auditpol
CautionAudit policy
auditpol /get /category:*
Shows/sets what gets audited — when failed logons never appear in the log, enable them here.
Examples
auditpol /set /subcategory:"Logon" /failure:enableAudit failed logons
Syntax
auditpol /get|/set /category:... [/success:enable]
Before you run it
Over-auditing floods the logs.
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store