https://learn.microsoft.com/en-us/answers/questions/653193/disable-logging-of-certain-events.html
윈도우키 + R
perfmon
성능에서 레벨 찾아 보라고 하는대 그런 옵션은 없는 것 같다.
(성능)->데이터 수집기 세트->이벤트 추적 세션에서 EventLog-Application을 선택하고 [ENTER]를 누릅니다.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger
여기서 자신의 이벤트가 되는 키를 검색 하면 된다.
Enabled
이것을 1로 하면 사용
Enabled
0으로 하면 중지다.
https://learn.microsoft.com/ko-kr/windows-server/administration/windows-commands/auditpol-list
https://superuser.com/questions/1516725/how-to-disable-windows-10-system-log
검색 하는 방법
auditpol /list /subcategory:*
auditpol /list /subcategory:*test*
응용 한다면
auditpol /list /subcategory:* > d:\test.txt
auditpol /set /subcategory:"시스템 무결성" /success:disable /failure:disable
한글로 작성 해야 한다.
auditpol /set /subcategory:"시스템 무결성" /success:disable /failure:enable
실패만 기록 하기
gpupdate /force
rem https://docs.microsoft.com/en-us/windows/win32/fwp/auditing-and-logging
rem https://social.technet.microsoft.com/Forums/en-US/ec2b033f-3e9b-4727-88d2-e6e358393734/how-to-disable-stop-windows-filtering-platform-filtering-platform-packet-drop
rem ALL
Auditpol /set /category:* /Success:disable /failure:disable
rem FIREWALL
Auditpol /set /subcategory:"Filtering Platform Policy Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Filtering Platform Packet Drop" /success:disable /failure:disable
Auditpol /set /subcategory:"Filtering Platform Connection" /success:disable /failure:disable
Auditpol /set /subcategory:"Other Object Access Events" /success:disable /failure:disable
Auditpol /set /subcategory:"IPsec Main Mode" /success:disable /failure:disable
Auditpol /set /subcategory:"IPsec Quick Mode" /success:disable /failure:disable
Auditpol /set /subcategory:"IPsec Extended Mode" /success:disable /failure:disable
Auditpol /set /subcategory:"IPsec Driver" /success:disable /failure:disable
rem https://thesystemengineers.wordpress.com/2014/05/08/the-best-advanced-audit-script-and-advanced-audit-policy-i-use/
rem http://www.ultimatewindowssecurity.com/wiki/WindowsSecuritySettings/Recommended-Baseline-Audit-Policy-for-Windows-Server-2008
Auditpol /set /subcategory:"DPAPI Activity" /success:disable /failure:disable
Auditpol /set /subcategory:"Detailed Directory Service Replication" /success:disable /failure:disable
Auditpol /set /subcategory:"Directory Service Replication" /success:disable /failure:disable
Auditpol /set /subcategory:"Handle Manipulation" /success:disable /failure:disable
Auditpol /set /subcategory:"MPSSVC Rule-Level Policy Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Non Sensitive Privilege Use" /success:disable /failure:disable
Auditpol /set /subcategory:"Other Policy Change Events" /success:disable /failure:enable
Auditpol /set /subcategory:"Other Privilege Use Events" /success:disable /failure:disable
Auditpol /set /subcategory:"SAM" /success:disable /failure:disable
Auditpol /set /subcategory:"Sensitive Privilege Use" /success:disable /failure:disable
rem may be enabled on failure
Auditpol /set /subcategory:"Other System Events" /success:disable /failure:disable
rem Usually all enabled
Auditpol /set /subcategory:"Account Lockout" /success:disable /failure:disable
Auditpol /set /subcategory:"Application Generated" /success:disable /failure:disable
Auditpol /set /subcategory:"Application Group Management" /success:disable /failure:disable
Auditpol /set /subcategory:"Audit Policy Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Authentication Policy Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Authorization Policy Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Certification Services" /success:disable /failure:disable
Auditpol /set /subcategory:"Computer Account Management" /success:disable /failure:disable
Auditpol /set /subcategory:"Credential Validation" /success:disable /failure:disable
Auditpol /set /subcategory:"Directory Service Access" /success:disable /failure:disable
Auditpol /set /subcategory:"Directory Service Changes" /success:disable /failure:disable
Auditpol /set /subcategory:"Distribution Group Management" /success:disable /failure:disable
Auditpol /set /subcategory:"File Share" /success:disable /failure:disable
Auditpol /set /subcategory:"File System" /success:disable /failure:disable
Auditpol /set /subcategory:"Kerberos Authentication Service" /success:disable /failure:disable
Auditpol /set /subcategory:"Kerberos Service Ticket Operations" /success:disable /failure:disable
Auditpol /set /subcategory:"Kernel Object" /success:disable /failure:disable
Auditpol /set /subcategory:"Logoff" /success:disable /failure:disable
Auditpol /set /subcategory:"Logon" /success:disable /failure:disable
Auditpol /set /subcategory:"Network Policy Server" /success:disable /failure:disable
Auditpol /set /subcategory:"Other Account Logon Events" /success:disable /failure:disable
Auditpol /set /subcategory:"Other Account Management Events" /success:disable /failure:disable
Auditpol /set /subcategory:"Other Logon/Logoff Events" /success:disable /failure:disable
Auditpol /set /subcategory:"Process Creation" /success:disable /failure:disable
Auditpol /set /subcategory:"Process Termination" /success:disable /failure:disable
Auditpol /set /subcategory:"RPC Events" /success:disable /failure:disable
Auditpol /set /subcategory:"Registry" /success:disable /failure:disable
Auditpol /set /subcategory:"Security Group Management" /success:disable /failure:disable
Auditpol /set /subcategory:"Security State Change" /success:disable /failure:disable
Auditpol /set /subcategory:"Security System Extension" /success:disable /failure:disable
Auditpol /set /subcategory:"Special Logon" /success:disable /failure:disable
Auditpol /set /subcategory:"System Integrity" /success:disable /failure:disable
Auditpol /set /subcategory:"User Account Management" /success:disable /failure:disable
rem Apply immediatly
gpupdate /force
앞서 말한것 같이 모두 한글로 해야 한다.