This is a static archive of our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Nº windows event

0

¿what is the windows event when run wireshark?

asked 05 Jun '14, 02:22

agonsed's gravatar image

agonsed
11112
accept rate: 0%

Your question doesn't make much sense to me, can you try to describe your issue another way?

(05 Jun '14, 02:36) grahamb ♦

I guess he wants to know what event ID shows up in the windows event log when Wireshark is run. Probably to be able to detect if anyone is using Wireshark unauthorized.

(05 Jun '14, 02:38) Jasper ♦♦

One Answer:

0

There is no special windows event for Wireshark, but if you enable Security Audit Logging on Windows, it will log every process start with the event ID 4688. The log entry contains the process name, user, etc.

http://technet.microsoft.com/en-us/library/dd941613%28v=ws.10%29.aspx

Regards
Kurt

answered 05 Jun '14, 13:41

Kurt%20Knochner's gravatar image

Kurt Knochner ♦
24.8k1039237
accept rate: 15%