
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi everyone,
I have an existing rules for Windows Servers 2008 that filter up event ID 4625, is it possible to filter down to the status or substatus code number?
For example, the status code below:-
0xc000015b | The user has not been granted the requested logon type (aka logon right) at this machine |
Is it possible to filter Event ID 4625 AND Status Code 0xc000015b? If yes, what fields should i put for the filter?
I looked at the MicrosoftWindows2008EventLogMappingsConfig.pdf and MicrosoftWindows2008EventLogMappingsNativeConfig.pdf but found nothing related to Status Code.
Thanks,
Keo
Accepted Solutions

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
You're right, I don't see it in the mapping documentation, but I checked events from a 2008 R2 system and I *DO* see the value you are looking for stored in FlexString1:

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi Keo,
If the reply provided was sufficient in solving your query, please mark the question as answered.
Thanks!
Alexandra