Enable security log events

Before you can use Sigma rules related to security log events, you will need to enable them.

  1. Open the Windows Start menu and search for the Local Security Policy application. Launch the application.

  2. Select Security Settings > System Audit Policies - Local Group.

  3. Select Object Access > Audit Other Object Access Events.

  4. In the Policy tab, select these checkboxes:
    • Configure the following audit events
    • Success
    • Failure


Security log events are now enabled in Windows.