no more events 4688 in eventlog anymore

Rob Mulder 231 Reputation points
2022-10-13T13:42:23.567+00:00

4688 is normally logged in event Viewer when a new process is created. This is the number one event to be monitored on all systems in the domain.
It is enabled by setting the Audit: Windows Settings > Security Settings > Advanced Audit Policy Configuration > Audit Policies > Detailed Tracking > Audit Process Creation.

It looks like the Events 4688 stopped after installing Windows 11 build 22H2, not sure yet.

Anyone else experienced this?

Windows Server Security
Windows Server Security
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
1,834 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
9,606 questions
{count} vote

Accepted answer
  1. Ramesh Srinivasan 176 Reputation points
    2022-12-04T06:25:28.137+00:00

    KB5020044 Fixes Process Creation Audit Logging (Event ID 4688/1108 Issue

    The 1108 events should stop after updating to 22621.900. The 4688 (Process creation event) entries appear correctly now.

    From November 29, 2022—KB5020044 (OS Build 22621.900) Preview:

    Improvements

    "It addresses an issue that affects process creation. It fails to create security audits for it and other related audit events."

    2 people found this answer helpful.
    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Rob Mulder 231 Reputation points
    2022-12-02T13:34:49.753+00:00

    releasing-windows-11-build-22621-898-to-the-release-preview-channel

    quote: We fixed an issue that affected process creation. It failed to create security audits for it and other related audit events.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.