Enable “audit process tracking” using batch file





.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty{ height:90px;width:728px;box-sizing:border-box;
}







0















I'm following this post and trying to enable Audit process tracking.




Local Security Policy > Local Policies > Audit Policy > Double Click Audit process tracking and enable.




I'm hoping for a quicker way to do it (preferably a batch file).



I took a look at ntrights but can't seem to figure out how to enable it .





I just need the batch file to enable "Success" audits.










share|improve this question























  • This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

    – Doug Deden
    Feb 6 at 21:45











  • @DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

    – WELZ
    Feb 6 at 21:46






  • 1





    It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

    – Doug Deden
    Feb 6 at 22:04


















0















I'm following this post and trying to enable Audit process tracking.




Local Security Policy > Local Policies > Audit Policy > Double Click Audit process tracking and enable.




I'm hoping for a quicker way to do it (preferably a batch file).



I took a look at ntrights but can't seem to figure out how to enable it .





I just need the batch file to enable "Success" audits.










share|improve this question























  • This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

    – Doug Deden
    Feb 6 at 21:45











  • @DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

    – WELZ
    Feb 6 at 21:46






  • 1





    It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

    – Doug Deden
    Feb 6 at 22:04














0












0








0








I'm following this post and trying to enable Audit process tracking.




Local Security Policy > Local Policies > Audit Policy > Double Click Audit process tracking and enable.




I'm hoping for a quicker way to do it (preferably a batch file).



I took a look at ntrights but can't seem to figure out how to enable it .





I just need the batch file to enable "Success" audits.










share|improve this question














I'm following this post and trying to enable Audit process tracking.




Local Security Policy > Local Policies > Audit Policy > Double Click Audit process tracking and enable.




I'm hoping for a quicker way to do it (preferably a batch file).



I took a look at ntrights but can't seem to figure out how to enable it .





I just need the batch file to enable "Success" audits.







windows batch automation security-policy






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Feb 6 at 21:37









WELZWELZ

1501314




1501314













  • This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

    – Doug Deden
    Feb 6 at 21:45











  • @DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

    – WELZ
    Feb 6 at 21:46






  • 1





    It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

    – Doug Deden
    Feb 6 at 22:04



















  • This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

    – Doug Deden
    Feb 6 at 21:45











  • @DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

    – WELZ
    Feb 6 at 21:46






  • 1





    It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

    – Doug Deden
    Feb 6 at 22:04

















This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

– Doug Deden
Feb 6 at 21:45





This might help: serverfault.com/questions/133104/… Or this: blogs.technet.microsoft.com/secguide/2016/01/21/…

– Doug Deden
Feb 6 at 21:45













@DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

– WELZ
Feb 6 at 21:46





@DougDeden I saw the SF post, that's how I found out about ntrights, still confused though. I will check out the other page you linked, thanks.

– WELZ
Feb 6 at 21:46




1




1





It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

– Doug Deden
Feb 6 at 22:04





It seems like this should do it: auditpol /set /subcategory:"Process Creation" /success:enable. But I don't see that doing that correlates with the desired line in Local Security Policy, at least I my testing. Maybe it will spur someone else to contribute.

– Doug Deden
Feb 6 at 22:04










0






active

oldest

votes












Your Answer








StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "3"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1402875%2fenable-audit-process-tracking-using-batch-file%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown

























0






active

oldest

votes








0






active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Super User!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f1402875%2fenable-audit-process-tracking-using-batch-file%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

Plaza Victoria

Puebla de Zaragoza

Musa