mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-28 21:27:23 +00:00
Merge branch 'wdav-wdeg-rs4-new-events' into anbic-rs4
This commit is contained in:
commit
d8864e4efa
@ -9,9 +9,9 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.localizationpriority: medium
|
||||
author: iaanw
|
||||
ms.author: iawilt
|
||||
ms.date: 11/20/2017
|
||||
author: andreabichsel
|
||||
ms.author: v-anbic
|
||||
ms.date: 04/16/2018
|
||||
---
|
||||
|
||||
# Review event logs and error codes to troubleshoot issues with Windows Defender AV
|
||||
@ -1377,6 +1377,60 @@ User action:
|
||||
No action is necessary. The Windows Defender Antivirus client is in a healthy state. This event is reported on an hourly basis.
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<th colspan="2">Event ID: 1151</th>
|
||||
</tr>
|
||||
<tr><td>
|
||||
Symbolic name:
|
||||
</td>
|
||||
<td >
|
||||
<b>MALWAREPROTECTION_SERVICE_HEALTH_REPORT</b>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
Message:
|
||||
</td>
|
||||
<td >
|
||||
<b>Endpoint Protection client health report (time in UTC)
|
||||
</b>
|
||||
</td>
|
||||
</tr>
|
||||
<tr>
|
||||
<td>
|
||||
Description:
|
||||
</td>
|
||||
<td >
|
||||
Windows Defender client health report.
|
||||
<dl>
|
||||
<dt>Platform Version: <Current platform version></dt>
|
||||
<dt>Engine Version: <Antimalware Engine version></dt>
|
||||
<dt>Network Realtime Inspection engine version: <Network Realtime Inspection engine version></dt>
|
||||
<dt>Antivirus signature version: <Antivirus signature version></dt>
|
||||
<dt>Antispyware signature version: <Antispyware signature version></dt>
|
||||
<dt>Network Realtime Inspection signature version: <Network Realtime Inspection signature version></dt>
|
||||
<dt>RTP state: <Realtime protection state> (Enabled or Disabled)</dt>
|
||||
<dt>OA state: <On Access state> (Enabled or Disabled)</dt>
|
||||
<dt>IOAV state: <IE Downloads and Outlook Express Attachments state> (Enabled or Disabled)</dt>
|
||||
<dt>BM state: <Behavior Monitoring state> (Enabled or Disabled)</dt>
|
||||
<dt>Antivirus signature age: <Antivirus signature age> (in days)</dt>
|
||||
<dt>Antispyware signature age: <Antispyware signature age> (in days)</dt>
|
||||
<dt>Last quick scan age: <Last quick scan age> (in days)</dt>
|
||||
<dt>Last full scan age: <Last full scan age> (in days)</dt>
|
||||
<dt>Antivirus signature creation time: ?<Antivirus signature creation time></dt>
|
||||
<dt>Antispyware signature creation time: ?<Antispyware signature creation time></dt>
|
||||
<dt>Last quick scan start time: ?<Last quick scan start time></dt>
|
||||
<dt>Last quick scan end time: ?<Last quick scan end time></dt>
|
||||
<dt>Last quick scan source: <Last quick scan source> (1 = scheduled, 2 = on demand)</dt>
|
||||
<dt>Last full scan start time: ?<Last full scan start time></dt>
|
||||
<dt>Last full scan end time: ?<Last full scan end time></dt>
|
||||
<dt>Last full scan source: <Last full scan source> (1 = scheduled, 2 = on demand)</dt>
|
||||
<dt>Product status: For internal troubleshooting
|
||||
</dl>
|
||||
</td>
|
||||
</tr>
|
||||
|
||||
<tr>
|
||||
<th colspan="2">Event ID: 2000</th>
|
||||
</tr>
|
||||
|
@ -9,9 +9,9 @@ ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
localizationpriority: medium
|
||||
author: iaanw
|
||||
ms.author: iawilt
|
||||
ms.date: 11/20/2017
|
||||
author: andreabichsel
|
||||
ms.author: v-anbic
|
||||
ms.date: 04/16/2018
|
||||
---
|
||||
|
||||
|
||||
@ -100,6 +100,8 @@ Event ID | Description
|
||||
5007 | Event when settings are changed
|
||||
1124 | Audited Controlled folder access event
|
||||
1123 | Blocked Controlled folder access event
|
||||
1127 | Blocked Controlled folder access sector write block event
|
||||
1128 | Audited Controlled folder access sector write block event
|
||||
|
||||
|
||||
## Use audit mode to measure impact
|
||||
|
@ -8,10 +8,10 @@ ms.prod: w10
|
||||
ms.mktglfcycl: manage
|
||||
ms.sitesec: library
|
||||
ms.pagetype: security
|
||||
ms.date: 12/12/2017
|
||||
ms.date: 04/16/2018
|
||||
localizationpriority: medium
|
||||
author: iaanw
|
||||
ms.author: iawilt
|
||||
author: andreabichsel
|
||||
ms.author: v-anbic
|
||||
|
||||
---
|
||||
|
||||
@ -190,6 +190,8 @@ Network protection | Windows Defender (Operational) | 1126 | Event when Network
|
||||
Controlled folder access | Windows Defender (Operational) | 5007 | Event when settings are changed
|
||||
Controlled folder access | Windows Defender (Operational) | 1124 | Audited Controlled folder access event
|
||||
Controlled folder access | Windows Defender (Operational) | 1123 | Blocked Controlled folder access event
|
||||
Controlled folder access | Windows Defender (Operational) | 1127 | Blocked Controlled folder access sector write block event
|
||||
Controlled folder access | Windows Defender (Operational) | 1128 | Audited Controlled folder access sector write block event
|
||||
Attack surface reduction | Windows Defender (Operational) | 5007 | Event when settings are changed
|
||||
Attack surface reduction | Windows Defender (Operational) | 1122 | Event when rule fires in Audit-mode
|
||||
Attack surface reduction | Windows Defender (Operational) | 1121 | Event when rule fires in Block-mode
|
Loading…
x
Reference in New Issue
Block a user