Event ID:
4907
Category:
Policy Change
Subcategory:
Audit Policy Change
Supported on:
Windows Vista, Windows Server 2008
Auditing settings on object were changed.
Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Object:
Object Server: %5
Object Type: %6
Object Name: %7
Handle ID: %8
Process Information:
Process ID: %11
Process Name: %12
Auditing Settings:
Original Security Descriptor: %9
New Security Descriptor: %10