no more events 4688 in eventlog anymore

Rob Mulder 231 Reputation points
2022-10-13T13:42:23.567+00:00

4688 is normally logged in event Viewer when a new process is created. This is the number one event to be monitored on all systems in the domain.
It is enabled by setting the Audit: Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit Process Creation.

It looks like the Events 4688 stopped after installing Windows 11 build 22H2, not sure yet.

Anyone else experienced this?

Windows for business | Windows Server | Devices and deployment | Configure application groups
Windows for business | Windows Client for IT Pros | User experience | Other
{count} vote

Accepted answer
  1. Ramesh Srinivasan 176 Reputation points Volunteer Moderator
    2022-12-04T06:25:28.137+00:00

    KB5020044 Fixes Process Creation Audit Logging (Event ID 4688/1108 Issue

    The 1108 events should stop after updating to 22621.900. The 4688 (Process creation event) entries appear correctly now.

    From November 29, 2022—KB5020044 (OS Build 22621.900) Preview:

    Improvements

    "It addresses an issue that affects process creation. It fails to create security audits for it and other related audit events."

    2 people found this answer helpful.
    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Rob Mulder 231 Reputation points
    2022-10-21T11:46:02.103+00:00

    Uninstalled update 22H2 and event 4688 was logged again. So, definitely due to the update!

    2 people found this answer helpful.
    0 comments No comments

  2. ErrorRaffyline0 6 Reputation points
    2022-10-23T10:50:04.317+00:00

    I can back this up. Some other sources if devs want to check it out:

    https://github.com/MicrosoftDocs/windows-itpro-docs/issues/10954
    Several feedback hub reports found with keyword "4688"

    1 person found this answer helpful.
    0 comments No comments

  3. Rob Mulder 231 Reputation points
    2022-11-08T07:26:56.523+00:00
    1 person found this answer helpful.
    0 comments No comments

  4. Rob Mulder 231 Reputation points
    2022-11-08T07:26:20.993+00:00

    With Feedback Hub App the problem reported to Microsoft....

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.