Windows

Record which programs start and stop

What it does

If the software is ever closed unexpectedly, this is what tells us what closed it. Windows notes each program that starts in its Security log (event 4688), and "Download Logs" includes the relevant entries from the last three days.

In the app: Notes what starts and stops programs

The quickest way

In ANPR Edge, go to Support, press "How this computer is set up" and tick this row.

Change it by hand

  1. 1Right-click Start and choose "Terminal (Admin)" or "Windows PowerShell (Admin)".
  2. 2Type: auditpol /set /subcategory:"Process Creation" /success:enable and press Enter.
  3. 3It should answer "The command was successfully executed."

On computers managed by an IT department, audit settings may be controlled centrally and reset. If the row keeps going back to Off, ask your IT team to allow "Audit Process Creation".

What it records — and what it does not

It records the name of each program as it starts, and which account started it. It does not record anything you type, any files or any pictures. It only sees programs started after it was switched on.

Check it worked

  • In the same window, type auditpol /get /subcategory:"Process Creation". It should show "Success".

Turning it off

Untick the row in the app, or run auditpol /set /subcategory:"Process Creation" /success:disable.

Still need help?

In ANPR Edge, open Support and choose Chat with support, or email [email protected]. Attach the file from Activity & logs › Download Logs — it includes these settings and the Windows records we need.

Contact us

Other setup guides