Skip to main content

AU-3 Content of Audit Records

Android

iOS

Linux

macOS

Windows

This is set by Group Policy which is maintained as part of the AUTH service, the GPO is called Security Controls - Forest Baseline and the Event Log and Advanced Audit Configuration sections contain the policies that tell which events are logged. The default windows event viewer contains all the required content.
Windows Log Capacity