mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-28 21:27:23 +00:00
Merge branch 'wdav-wdeg-rs4-new-events' into anbic-rs4
This commit is contained in:
commit
d8864e4efa
@ -9,9 +9,9 @@ ms.mktglfcycl: manage
|
|||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.localizationpriority: medium
|
ms.localizationpriority: medium
|
||||||
author: iaanw
|
author: andreabichsel
|
||||||
ms.author: iawilt
|
ms.author: v-anbic
|
||||||
ms.date: 11/20/2017
|
ms.date: 04/16/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
# Review event logs and error codes to troubleshoot issues with Windows Defender AV
|
# Review event logs and error codes to troubleshoot issues with Windows Defender AV
|
||||||
@ -1377,6 +1377,60 @@ User action:
|
|||||||
No action is necessary. The Windows Defender Antivirus client is in a healthy state. This event is reported on an hourly basis.
|
No action is necessary. The Windows Defender Antivirus client is in a healthy state. This event is reported on an hourly basis.
|
||||||
</td>
|
</td>
|
||||||
</tr>
|
</tr>
|
||||||
|
|
||||||
|
<tr>
|
||||||
|
<th colspan="2">Event ID: 1151</th>
|
||||||
|
</tr>
|
||||||
|
<tr><td>
|
||||||
|
Symbolic name:
|
||||||
|
</td>
|
||||||
|
<td >
|
||||||
|
<b>MALWAREPROTECTION_SERVICE_HEALTH_REPORT</b>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
<tr>
|
||||||
|
<td>
|
||||||
|
Message:
|
||||||
|
</td>
|
||||||
|
<td >
|
||||||
|
<b>Endpoint Protection client health report (time in UTC)
|
||||||
|
</b>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
<tr>
|
||||||
|
<td>
|
||||||
|
Description:
|
||||||
|
</td>
|
||||||
|
<td >
|
||||||
|
Windows Defender client health report.
|
||||||
|
<dl>
|
||||||
|
<dt>Platform Version: <Current platform version></dt>
|
||||||
|
<dt>Engine Version: <Antimalware Engine version></dt>
|
||||||
|
<dt>Network Realtime Inspection engine version: <Network Realtime Inspection engine version></dt>
|
||||||
|
<dt>Antivirus signature version: <Antivirus signature version></dt>
|
||||||
|
<dt>Antispyware signature version: <Antispyware signature version></dt>
|
||||||
|
<dt>Network Realtime Inspection signature version: <Network Realtime Inspection signature version></dt>
|
||||||
|
<dt>RTP state: <Realtime protection state> (Enabled or Disabled)</dt>
|
||||||
|
<dt>OA state: <On Access state> (Enabled or Disabled)</dt>
|
||||||
|
<dt>IOAV state: <IE Downloads and Outlook Express Attachments state> (Enabled or Disabled)</dt>
|
||||||
|
<dt>BM state: <Behavior Monitoring state> (Enabled or Disabled)</dt>
|
||||||
|
<dt>Antivirus signature age: <Antivirus signature age> (in days)</dt>
|
||||||
|
<dt>Antispyware signature age: <Antispyware signature age> (in days)</dt>
|
||||||
|
<dt>Last quick scan age: <Last quick scan age> (in days)</dt>
|
||||||
|
<dt>Last full scan age: <Last full scan age> (in days)</dt>
|
||||||
|
<dt>Antivirus signature creation time: ?<Antivirus signature creation time></dt>
|
||||||
|
<dt>Antispyware signature creation time: ?<Antispyware signature creation time></dt>
|
||||||
|
<dt>Last quick scan start time: ?<Last quick scan start time></dt>
|
||||||
|
<dt>Last quick scan end time: ?<Last quick scan end time></dt>
|
||||||
|
<dt>Last quick scan source: <Last quick scan source> (1 = scheduled, 2 = on demand)</dt>
|
||||||
|
<dt>Last full scan start time: ?<Last full scan start time></dt>
|
||||||
|
<dt>Last full scan end time: ?<Last full scan end time></dt>
|
||||||
|
<dt>Last full scan source: <Last full scan source> (1 = scheduled, 2 = on demand)</dt>
|
||||||
|
<dt>Product status: For internal troubleshooting
|
||||||
|
</dl>
|
||||||
|
</td>
|
||||||
|
</tr>
|
||||||
|
|
||||||
<tr>
|
<tr>
|
||||||
<th colspan="2">Event ID: 2000</th>
|
<th colspan="2">Event ID: 2000</th>
|
||||||
</tr>
|
</tr>
|
||||||
|
@ -9,9 +9,9 @@ ms.mktglfcycl: manage
|
|||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
localizationpriority: medium
|
localizationpriority: medium
|
||||||
author: iaanw
|
author: andreabichsel
|
||||||
ms.author: iawilt
|
ms.author: v-anbic
|
||||||
ms.date: 11/20/2017
|
ms.date: 04/16/2018
|
||||||
---
|
---
|
||||||
|
|
||||||
|
|
||||||
@ -100,6 +100,8 @@ Event ID | Description
|
|||||||
5007 | Event when settings are changed
|
5007 | Event when settings are changed
|
||||||
1124 | Audited Controlled folder access event
|
1124 | Audited Controlled folder access event
|
||||||
1123 | Blocked Controlled folder access event
|
1123 | Blocked Controlled folder access event
|
||||||
|
1127 | Blocked Controlled folder access sector write block event
|
||||||
|
1128 | Audited Controlled folder access sector write block event
|
||||||
|
|
||||||
|
|
||||||
## Use audit mode to measure impact
|
## Use audit mode to measure impact
|
||||||
|
@ -8,10 +8,10 @@ ms.prod: w10
|
|||||||
ms.mktglfcycl: manage
|
ms.mktglfcycl: manage
|
||||||
ms.sitesec: library
|
ms.sitesec: library
|
||||||
ms.pagetype: security
|
ms.pagetype: security
|
||||||
ms.date: 12/12/2017
|
ms.date: 04/16/2018
|
||||||
localizationpriority: medium
|
localizationpriority: medium
|
||||||
author: iaanw
|
author: andreabichsel
|
||||||
ms.author: iawilt
|
ms.author: v-anbic
|
||||||
|
|
||||||
---
|
---
|
||||||
|
|
||||||
@ -190,6 +190,8 @@ Network protection | Windows Defender (Operational) | 1126 | Event when Network
|
|||||||
Controlled folder access | Windows Defender (Operational) | 5007 | Event when settings are changed
|
Controlled folder access | Windows Defender (Operational) | 5007 | Event when settings are changed
|
||||||
Controlled folder access | Windows Defender (Operational) | 1124 | Audited Controlled folder access event
|
Controlled folder access | Windows Defender (Operational) | 1124 | Audited Controlled folder access event
|
||||||
Controlled folder access | Windows Defender (Operational) | 1123 | Blocked Controlled folder access event
|
Controlled folder access | Windows Defender (Operational) | 1123 | Blocked Controlled folder access event
|
||||||
|
Controlled folder access | Windows Defender (Operational) | 1127 | Blocked Controlled folder access sector write block event
|
||||||
|
Controlled folder access | Windows Defender (Operational) | 1128 | Audited Controlled folder access sector write block event
|
||||||
Attack surface reduction | Windows Defender (Operational) | 5007 | Event when settings are changed
|
Attack surface reduction | Windows Defender (Operational) | 5007 | Event when settings are changed
|
||||||
Attack surface reduction | Windows Defender (Operational) | 1122 | Event when rule fires in Audit-mode
|
Attack surface reduction | Windows Defender (Operational) | 1122 | Event when rule fires in Audit-mode
|
||||||
Attack surface reduction | Windows Defender (Operational) | 1121 | Event when rule fires in Block-mode
|
Attack surface reduction | Windows Defender (Operational) | 1121 | Event when rule fires in Block-mode
|
Loading…
x
Reference in New Issue
Block a user