For example, which Event "Source" or log should we expect to find these audited entries in.
⚠Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.
@officedocsbot assign @e0i
@itguysocal Thank you for reaching out. You can find this in the Windows Event Log. "While the features will not block or prevent apps, scripts, or files from being modified, the Windows Event Log will record events as if the features were fully enabled. This means you can enable audit mode and then review the event log to see what impact the feature would have had were it enabled."
Right, but my question is "which" Windows Event Log? System? Security? Application? I couldn't find it. So if the documentation can please be updated to list which event log "source" (that's a type of event log)
@andreabichsel
As requested by the issue author, Lindsay needs more information regarding different types of Windows Event Log for her editing.
Could you kindly point us to a right direction?
Thanks.
I believe Applications and Services > Microsoft > Windows > Windows Defender > Operational.
@justinha Can you confirm with the product team?
@e0i I'm in another group now, and Justin's the right contact for these topics now. Thanks! :)
Andrea's right. For more info, see https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-exploit-guard/event-views-exploit-guard
@itguysocal
With the help of your feedback, the issue has been reviewed and an update to the documentation has been published.
Thank you for your feedback.
@officedocsbot close
Most helpful comment
I believe Applications and Services > Microsoft > Windows > Windows Defender > Operational.
@justinha Can you confirm with the product team?
@e0i I'm in another group now, and Justin's the right contact for these topics now. Thanks! :)