Skip to content

Activity Auditing

Enabling Auditing for WEF Operations

To audit WEF operations, configure Windows Audit Policies to track events related to event log management and forwarding. These policies are managed via Group Policy or Local Security Policy:

  1. Audit Event Log Management
    Enable auditing for events related to event log creation, deletion, and modification. This captures actions like configuring event subscriptions or modifying the Event Log service.
    Command to enable via PowerShell:

    auditpol /set /subcategory:"Event Log Management" /success:enable /failure:enable
    

  2. Audit Event Creation and Deletion
    Track when events are added to or removed from the event log. This helps detect unauthorized modifications to event data.
    Group Policy Location:
    Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Audit Event Creation and Deletion

  3. Audit Event Forwarding
    While Windows does not provide a direct policy for WEF-specific auditing, the Security log on the collector server can be configured to capture events related to event forwarding (e.g., successful or failed event ingestion). Note that WEF operations are indirectly monitored via Security log events, which may include standard event IDs like 4663 or 4656.


The collector server must log events that indicate successful or failed event forwarding operations. Use the Security log to monitor these activities:

  1. Event IDs to Monitor
  2. Event ID 4663: A user attempted to access an event log. This may indicate unauthorized access to event data.
  3. Event ID 4656: A user was logged on to the system, which may correlate with event forwarding activity.
    Note: Event ID 10000000000 is not a standard Windows event ID. Use verified IDs like 4663 or 4656 for monitoring, or define custom event IDs as needed.

  4. Configuring the Security Log
    Ensure the Security log is enabled and configured to retain sufficient historical data. Adjust log size and retention via:

  5. Event Viewer > Windows Logs > Security > Properties > Retention Settings

  6. Using PowerShell to Query Logs
    Filter the Security log for WEF-related events using Get-WinEvent:

    Get-WinEvent -LogName Security | Where-Object { $_.Id -in 4663, 4656 }
    


Real-Time Monitoring and Alerts

Set up real-time monitoring for critical events using Event Subscriptions or SIEM integration:

  1. Event Subscriptions
    Create a subscription in Event Viewer to forward specific events to a centralized log server or monitoring tool.
    Steps:
  2. Open Event Viewer > Action > Event Subscriptions.
  3. Configure a subscription to filter events (e.g., Event ID 4663) and forward them to a remote server.

  4. SIEM Integration
    Forward Security log events to a Security Information and Event Management (SIEM) system (e.g., Microsoft Sentinel, Splunk) for centralized analysis and alerting.


Key takeaways

  • Enable audit policies for Event Log Management and Event Creation/Deletion to track WEF-related activities.
  • Monitor the Security log on the collector server for events like 4663 and 4656 to detect unauthorized access or failures.
  • Use PowerShell to query and filter event logs for targeted analysis.
  • Integrate with SIEM tools for real-time monitoring and alerting on suspicious event forwarding behavior.