Microsoft-Windows-Configuration-Change-Monitor

1 events across 1 channel

EventTitleChannelSample
1Event ID 1SystemY

Event ID 1

#
Provider
Microsoft-Windows-Configuration-Change-Monitor
Channel
System
Level
4

Fields #

NameDescription
Sid
Command line
Parent Process 1
Parent Process 2
Parent Process 3
Parent Process 4
Parent Process 5
Parent Process 6
Parent Process 7
Parent Process 8
Parent Process 9
Parent Process 10

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Configuration-Change-Monitor",
    "guid": "{a148cf02-be6d-5f08-94e3-b68de60d8422}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-04-18 00:31:16.840525+00:00",
    "event_record_id": 443,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 7928,
      "thread_id": 8048
    },
    "channel": "System",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": "S-1-5-21-3798294047-1846905762-1150995898-1000"
    }
  },
  "event_data": {
    "Sid": "S-1-5-21-3798294047-1846905762-1150995898-1000",
    "Command line": "\"C:\\WINDOWS\\system32\\netsh.exe\" advfirewall firewall show rule \"name=Allow WinRM HTTPS\"",
    "Parent Process 1": "C:\\Windows\\System32\\netsh.exe",
    "Parent Process 2": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "Parent Process 3": "C:\\Windows\\System32\\runonce.exe",
    "Parent Process 4": "C:\\Windows\\explorer.exe",
    "Parent Process 5": "",
    "Parent Process 6": "",
    "Parent Process 7": "",
    "Parent Process 8": "",
    "Parent Process 9": "",
    "Parent Process 10": ""
  },
  "message": ""
}