New Ranks & Badges For The Community!
Notice something different? The ranks and associated badges have gone "Star Fleet". See what they all mean HERE
Highlighted
Absent Member.
Absent Member.
1467 views

Status or Sub-status code for Windows Event ID 4625

Jump to solution

Hi everyone,

I have an existing rules for Windows Servers 2008 that filter up event ID 4625, is it possible to filter down to the status or substatus code number?

For example, the status code below:-

0xc000015bThe user has not been granted the requested logon type (aka logon right) at this machine

Is it possible to filter Event ID 4625 AND Status Code 0xc000015b? If yes, what fields should i put for the filter?

I looked at the MicrosoftWindows2008EventLogMappingsConfig.pdf and MicrosoftWindows2008EventLogMappingsNativeConfig.pdf but found nothing related to Status Code.

Thanks,

Keo

Labels (2)
0 Likes
1 Solution

Accepted Solutions
Highlighted
Fleet Admiral
Fleet Admiral

You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

P724_Win4625_Status_code.png

View solution in original post

0 Likes
2 Replies
Highlighted
Fleet Admiral
Fleet Admiral

You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

P724_Win4625_Status_code.png

View solution in original post

0 Likes
Highlighted
Absent Member.
Absent Member.

Hi Keo,

If the reply provided was sufficient in solving your query, please mark the question as answered.

Thanks!

Alexandra

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.