Audit who restart services

MMASLOUH 61 Reputation points
2021-03-04T21:06:52.917+00:00

Hello,

i have a problem with tracking users who start/stop services on my Servers (Win Srv 2012 / Win Srv 2016).

the event 7036 doesn't show me the user id.

74492-eventlog.png

Windows Server 2016
Windows Server 2016
A Microsoft server operating system that supports enterprise-level management updated to data storage.
2,594 questions
Windows Server 2012
Windows Server 2012
A Microsoft server operating system that supports enterprise-level management, data storage, applications, and communications.
1,629 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Anonymous
    2021-03-04T22:03:12.907+00:00

    You can follow along here to setup some auditing.
    https://www.itprotoday.com/windows-78/access-denied-auditing-users-who-might-be-starting-and-stopping-services

    --please don't forget to Accept as answer if the reply is helpful--

    0 comments No comments

  2. Daisy Zhou 30,891 Reputation points Microsoft External Staff
    2021-03-05T01:42:35.243+00:00

    Hello @MMASLOUH ,

    Thank you for posting here.

    Please set the audit policy based on the following similar case with marked answer.

    There are detailed steps that I posted in the case last year.

    Service audit log
    https://social.technet.microsoft.com/Forums/en-US/aeeecc07-368f-4f68-b773-6af70eec2995/service-audit-log?forum=winserversecurity

    Hope the information above is helpful.

    Should you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.