Enable full "Event Audit Logs" by default in AD Enterprise

Created by: Brendan Bone
Created date:
Last Updated date:


How can I enable full "Event Audit Logs" by default for all new cases in AD Enterprise instead of having to enable them for each case individually?



  1. Ensure AD Enterprise is closed
  2. Open regedit.exe (as Administrator)
  3. Navigate to the key "HKEY_LOCAL_MACHINE\SOFTWARE\AccessData\Products\Forensic Toolkit\<version>"
  4. Create a new DWORD value named "enable_audit_logging_ui" with the decimal value 11



This works for AD Enterprise 5.3 and newer.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Submit a request


Powered by Zendesk