Enable additional event logs using Event Viewer

For the following event IDs, the auditing setup is configured using the **Windows Event Viewer**. Access the **Event Viewer** through the search box in the **Start** menu.

![image34.png](/docs/images/564d416fbbd6aad6.png)

### Event IDs 1511, 1518

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **User Profile Service**, right click **Operational** and select **Enable Log**.

![image22.png](/docs/images/77d101b635aa03c5.png)

### Event IDs 11, 70, 90

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **CAPI2**, right click **Operational** and select **Enable Log**.

![image36.png](/docs/images/e45c7ce306132088.png)

### Event ID 3008

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **DNS Client Events**, right click **Operational** and select **Enable Log**.

![image33.png](/docs/images/73631e508a5ce35d.png)

### Event ID 2004

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **DriverFrameworks-UserMode**, right click **Operational** and select **Enable Log**.

![image28.png](/docs/images/1f2ed64c4d78c7b3.png)

### Event IDs 4103, 4104, 4105, 4106

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **PowerShell**, right click **Operational** and select **Enable Log**.

![image31.png](/docs/images/564d416fbbd6aad6.png)

### Event IDs 1006, 1009, 1116-1119

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **Windows Defender**, right click **Operational** and select **Enable Log**.

![image35.png](/docs/images/212f929eba7bb2d4.png)

### Event ID 1024

In **Event viewer** → **Application and Services Logs** → **Microsoft** → **Windows** → **TerminalServices-ClientActiveXCore** → **Microsoft-Windows-TerminalServices-RDPClient**, right click **Operational** and select **Enable Log**.

![image30.png](/docs/images/90b338266dfbe939.png)

### Event IDs 2005, 2006, 2009, 2033

In **Event Viewer** → **Expand Applications and Services Logs** → **Microsoft** → **Windows** → **Windows Firewall With Advanced Security** → **Firewall**, right click **Operational** and select **Enable Log**.

![image17.png](/docs/images/c34ee4ac789da08b.png)