Event Details
User Activity->Policy Changes->Windows 2008->EventID 4719 - System audit policy was changed.
EventID 4719 - System audit policy was changed.
 Sample:
Log Name:      Security
Source:        Microsoft-Windows-Security-Auditing
Date:          10/27/2009 9:52:10 PM
Event ID:      4719
Task Category: Audit Policy Change
Level:         Information
Keywords:      Audit Success
User:          N/A
Computer:      dcc1.Logistics.corp
Description:   
System audit policy was changed.
Subject:
	Security ID:		S-1-5-21-1135140816-2109348461-2107143693-500
	Account Name:		Administrator
	Account Domain:		LOGISTICS
	Logon ID:		0x1806d9
Audit Policy Change:
	Category:		System
	Subcategory:		Security State Change
	Subcategory GUID:	{0CCE9210-69AE-11D9-BED3-505054503030}
	Changes:		Success Added, Failure added
===========================
Description template stored in adtschema.dll:
===========================
System audit policy was changed.

Subject:
	Security ID:		%1
	Account Name:		%2
	Account Domain:		%3
	Logon ID:		%4

Audit Policy Change:
	Category:		%5
	Subcategory:		%6
	Subcategory GUID:	%7
	Changes:		%8
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Policy Change
Source Microsoft-Windows-Security-Auditing
TaskCategory Audit Policy Change
EventId 4719
Field Matching
FieldDescriptionStored inSample Value
When At what date and time a user activity originated in the system. DateTime 10.10.2000 19:00:00
Who Account or user name under which the activity occured. Subject: Account Name Administrator
What The type of activity occurred (e.g. Logon, Password Changed, etc.) "Policy Change" Policy Change
Where The name of the workstation/server where the activity was logged. Computer DC1
Where From The name of the workstation/server where the activity was initiated from. - 10.10.10.10
Severity Specify the seriousness of the event. "High" High
WhoDomain Subject: Account Domain LOGISTICS
WhereDomain -
Policy Name The name of the affected policy. "Audit Policy" Audit Policy
Comments
You must be logged in to comment