Record which programs start and stop
What it does
If the software is ever closed unexpectedly, this is what tells us what closed it. Windows notes each program that starts in its Security log (event 4688), and "Download Logs" includes the relevant entries from the last three days.
In the app: Notes what starts and stops programs
The quickest way
In ANPR Edge, go to Support, press "How this computer is set up" and tick this row.
Change it by hand
- 1Right-click Start and choose "Terminal (Admin)" or "Windows PowerShell (Admin)".
- 2Type: auditpol /set /subcategory:"Process Creation" /success:enable and press Enter.
- 3It should answer "The command was successfully executed."
On computers managed by an IT department, audit settings may be controlled centrally and reset. If the row keeps going back to Off, ask your IT team to allow "Audit Process Creation".
What it records — and what it does not
It records the name of each program as it starts, and which account started it. It does not record anything you type, any files or any pictures. It only sees programs started after it was switched on.
Check it worked
- In the same window, type auditpol /get /subcategory:"Process Creation". It should show "Success".
Turning it off
Untick the row in the app, or run auditpol /set /subcategory:"Process Creation" /success:disable.
Still need help?
In ANPR Edge, open Support and choose Chat with support, or email [email protected]. Attach the file from Activity & logs › Download Logs — it includes these settings and the Windows records we need.
Contact us