Windows 10: Is there a way to log process creation and termination events only for a specific program?

Discus and support Is there a way to log process creation and termination events only for a specific program? in Windows 10 Customization to solve the problem; Is there a way to log process creation and process termination events only for a specific program? I know how to set Detailed Tracking under Audit... Discussion in 'Windows 10 Customization' started by ItzTheRav, Aug 20, 2020.

  1. ItzTheRav Win User

    Is there a way to log process creation and termination events only for a specific program?


    Is there a way to log process creation and process termination events only for a specific program? I know how to set Detailed Tracking under Audit Policy Configuration in the Group Policy Editor, and there I have selected to audit only process creation 4688 and termination 4689 events. I also know how to filter the events that are already in the Security event log to only show me events for a specific program. But is there a way to only log events for that specific program in the first place, and not log events for any other programs? As it is now, I get tons of events for other programs being logged and I'm not interested in them, and they're taking a lot of space and making debugging more onerous. Thanks.

    :)
     
    ItzTheRav, Aug 20, 2020
    #1
  2. MEH
    meh Win User

    Processes with elevation terminated randomly?


    Lately, I've been experiencing a weird and new problem: Programs I run with elevation (i.e. as Administrator) have been randomly terminated. I'm not sure why this is happening. Is this a new Windows 10 security feature?

    Examples: I run Process Hacker with elevation to access all its features and allow for services to be stopped, processes to be killed, etc. But Process Hacker is one of the applications that is itself being terminated soow at seemingly random intervals. It will be running, tray icons and all, then suddenly be terminated. I won't know it has been killed until I move the mouse cursor over its tray icons, which disappear as soon as I do.

    There are several other examples of programs I always run with elevation. They are all being terminated at the same time, but I'm not doing it. It's pissing me off.

    Nothing jumps out at me in the event logs.

    Any ideas?
     
  3. Walale12 Win User
    Some programs won't start, but processes run in the background and can't be terminated.

    I'm having trouble launching some programs (at the moment, they are Grand Theft Auto V, Payday 2, Skyrim, and Google Chrome). When I launch these programs, in some cases, they come with a launcher, which works (This is the case for Grand Theft Auto and
    Skyrim), but then when the programs themselves try to launch, Windows pops up the standard "Program has stopped working" box, with the option to terminate or debug with Visual Studio. However, the process associated with the program is still running, according
    to task manager, and, when I attempt to terminate the process, it says "Access is denied", and the only way to terminate the processes is to reboot. I can post system specs upon request.
     
    Walale12, Aug 20, 2020
    #3
  4. Is there a way to log process creation and termination events only for a specific program?

    Event ID 7036 not showing in Windows Event Log on Win10

    It looks like 7036 event is missing from Windows desktop OS (starting from 8).
    However you can monitor process termination:

    1. Enable Audit Policy to audit process tracking:

    1. Check for event 4689 in Security Event Log

    Alternatively you may try this solution.

    But in this case, you will get event 4546 not only when the service starts or stops, but whenever something is trying to access it (e.g. when Services applet is open).
     
    Michael Karsyan, Aug 20, 2020
    #4
Thema:

Is there a way to log process creation and termination events only for a specific program?

Loading...
  1. Is there a way to log process creation and termination events only for a specific program? - Similar Threads - log process creation

  2. How to fix this? The terminal process "C:\Program Files\PowerShell\7\pwsh.exe" terminated...

    in Windows 10 Gaming
    How to fix this? The terminal process "C:\Program Files\PowerShell\7\pwsh.exe" terminated...: I got this problem just after opening vs code.Maybe that may be come when i updated my vs code via popup message https://answers.microsoft.com/en-us/windows/forum/all/how-to-fix-this-the-terminal-process-cprogram/e8f7c9aa-57bd-42b3-a106-9d1949355ea1
  3. is there a way to block a specific program from accessing a specific website?

    in Windows 10 Gaming
    is there a way to block a specific program from accessing a specific website?: i know i can edit the hosts file but the hosts file blocks all apps. is there a way to only block 1 app from accessing a website? google wasn't any help.edit: the app should still be able to use the internet, just not access a few websites....
  4. is there a way to block a specific program from accessing a specific website?

    in Windows 10 Software and Apps
    is there a way to block a specific program from accessing a specific website?: i know i can edit the hosts file but the hosts file blocks all apps. is there a way to only block 1 app from accessing a website? google wasn't any help.edit: the app should still be able to use the internet, just not access a few websites....
  5. is there a way to block a specific program from accessing a specific website?

    in Windows 10 Customization
    is there a way to block a specific program from accessing a specific website?: i know i can edit the hosts file but the hosts file blocks all apps. is there a way to only block 1 app from accessing a website? google wasn't any help.edit: the app should still be able to use the internet, just not access a few websites....
  6. Is there a way for antimalware services to ignore specific programs

    in Windows 10 BSOD Crashes and Debugging
    Is there a way for antimalware services to ignore specific programs: Hi!I have been trying to learn some programming c++ and as practice I wrote some code but everytime i run my .exe file Those that run for a few minutes behind the scenes Anti-malware service executable starts using high cpu ~78%-90% as reported by task manager and if I...
  7. Windows scaling only for a specific program?

    in Windows 10 Ask Insider
    Windows scaling only for a specific program?: Don't know where to ask this, I tried searching but did not get anything useful. I'm wondering if there is a Program or a command line that makes certain application run at a different scaling than that of default. ex.: Game I play has text and UI based on windows scaling...
  8. Is there a way to disable UAC for a specific program?

    in Windows 10 Ask Insider
    Is there a way to disable UAC for a specific program?: So I have programs that I use often, but they trigger UAC notifications. Without disabling UAC entirely, is there a way to not have the UAC notification pop up for that program? submitted by /u/Goodperson5656 [link] [comments]...
  9. Is there a way to only associate specific files with a certain program without making all...

    in Windows 10 Ask Insider
    Is there a way to only associate specific files with a certain program without making all...: I want to make it so that only some ISOs open with Dolphin so I can launch them through steam, but it makes so that EVERY ISO is opened through Dolphin submitted by /u/YourVeryOwnCat [link] [comments]...
  10. Stop Logging a Specific Event Error - 7031

    in Windows 10 Support
    Stop Logging a Specific Event Error - 7031: I want to stop error code 7031 from showing up in the event viewer log in win 10 (since its a redundant code that means nothing anyway), so does anyone know the steps (and explain in layman terms) to prevent it from posting. I do not mean just filtering it unless that is all...