To work around this behavior, configure an audit policy to audit successful system events. To do this, follow these steps on the local computer.
Note Because there are several versions of Microsoft Windows, the following steps may be different on your computer. If they are, see your product documentation to complete these steps.
- Click Start, and then click Control Panel.
- Double-click Administrative Tools, and then double-click Local Security Settings.
- Expand Local Policies, and then expand Audit Policy.
- In the right pane, double-click Audit system events.
- Click to select the Success check box, and then click OK.
- Restart the computer.
The following event ID is logged to the security event log:
Type: Success Audit
Source: Security
Category: System
Event ID: 512
Description:
Windows is starting up.
Also, if you are running Windows Server 2003 or Windows XP, the following event is logged to the security event log:
Type: Success Audit
Source: Security
Category: Logon/Logoff
Event ID: 551
Description:
User initiated logoff:
User Name: UserName
Domain: Domain
Logon ID: LogonID