no more events 4688 in eventlog anymore

Rob Mulder 231 Reputation points
2022-10-13T13:42:23.567+00:00

4688 is normally logged in event Viewer when a new process is created. This is the number one event to be monitored on all systems in the domain.
It is enabled by setting the Audit: Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit Process Creation.

It looks like the Events 4688 stopped after installing Windows 11 build 22H2, not sure yet.

Anyone else experienced this?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,782 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,993 questions
{count} vote

Accepted answer
  1. Ramesh Srinivasan 176 Reputation points
    2022-12-04T06:25:28.137+00:00

    KB5020044 Fixes Process Creation Audit Logging (Event ID 4688/1108 Issue

    The 1108 events should stop after updating to 22621.900. The 4688 (Process creation event) entries appear correctly now.

    From November 29, 2022—KB5020044 (OS Build 22621.900) Preview:

    Improvements

    "It addresses an issue that affects process creation. It fails to create security audits for it and other related audit events."

    2 people found this answer helpful.
    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Rob Mulder 231 Reputation points
    2022-10-21T11:46:02.103+00:00

    Uninstalled update 22H2 and event 4688 was logged again. So, definitely due to the update!

    2 people found this answer helpful.
    0 comments No comments

  2. ErrorRaffyline0 6 Reputation points
    2022-10-23T10:50:04.317+00:00

    I can back this up. Some other sources if devs want to check it out:

    https://github.com/MicrosoftDocs/windows-itpro-docs/issues/10954
    Several feedback hub reports found with keyword "4688"

    1 person found this answer helpful.
    0 comments No comments

  3. Rob Mulder 231 Reputation points
    2022-11-08T07:26:56.523+00:00
    1 person found this answer helpful.
    0 comments No comments

  4. Rob Mulder 231 Reputation points
    2022-11-08T07:26:20.993+00:00

    With Feedback Hub App the problem reported to Microsoft....

    0 comments No comments