Welcome Serena Central users! CLICK HERE
The migration of the Serena Central community is currently underway. Be sure to read THIS MESSAGE to get your new login set up to access your account.
Highlighted
keo.fua@amd.com Absent Member.
Absent Member.
1245 views

Status or Sub-status code for Windows Event ID 4625

Jump to solution

Hi everyone,

I have an existing rules for Windows Servers 2008 that filter up event ID 4625, is it possible to filter down to the status or substatus code number?

For example, the status code below:-

0xc000015bThe user has not been granted the requested logon type (aka logon right) at this machine

Is it possible to filter Event ID 4625 AND Status Code 0xc000015b? If yes, what fields should i put for the filter?

I looked at the MicrosoftWindows2008EventLogMappingsConfig.pdf and MicrosoftWindows2008EventLogMappingsNativeConfig.pdf but found nothing related to Status Code.

Thanks,

Keo

Labels (2)
0 Likes
1 Solution

Accepted Solutions
rkent1 Acclaimed Contributor.
Acclaimed Contributor.

Re: Status or Sub-status code for Windows Event ID 4625

Jump to solution

You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

P724_Win4625_Status_code.png

0 Likes
2 Replies
rkent1 Acclaimed Contributor.
Acclaimed Contributor.

Re: Status or Sub-status code for Windows Event ID 4625

Jump to solution

You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

P724_Win4625_Status_code.png

0 Likes
alomotan Absent Member.
Absent Member.

Re: Status or Sub-status code for Windows Event ID 4625

Jump to solution

Hi Keo,

If the reply provided was sufficient in solving your query, please mark the question as answered.

Thanks!

Alexandra

0 Likes
The opinions expressed above are the personal opinions of the authors, not of Micro Focus. By using this site, you accept the Terms of Use and Rules of Participation. Certain versions of content ("Material") accessible here may contain branding from Hewlett-Packard Company (now HP Inc.) and Hewlett Packard Enterprise Company. As of September 1, 2017, the Material is now offered by Micro Focus, a separately owned and operated company. Any reference to the HP and Hewlett Packard Enterprise/HPE marks is historical in nature, and the HP and Hewlett Packard Enterprise/HPE marks are the property of their respective owners.