You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please use the following bug reporting template to help produce actionable and reproducible issues. Please try to ensure that the reproduction is minimal so that the team can go through more bugs!
A brief description
Creating a new process within the Linux subsystem causes an incomplete Process Creation event (ID 4688) to be added the Security event log. The New Process Name and Process Command Line fields are blank.
Expected results
Creating a new process within the Linux subsystem should log the same quality of information as normal Windows process creation. New Process Name should be the full pathname to the process, and Process Command Line should be the command line.
Actual results (with terminal output if applicable)
Here is an excerpt from the XML view of a Linux subsystem Process Creation event:
Steps / All commands required to reproduce the error from a brand new installation
Using the Local Group Policy Editor, under Computer Configuration -> Windows Settings -> Security Settings -> Local Policy -> Audit Policy, enable Audit Process Tracking.
Run any Windows program, e.g. notepad.exe.
In the Event Viewer, check the Security log for a Process Creation event (filter by ID 4688) corresponding to that program.
Open a Linux subsystem bash prompt, and run any command that will create a new process, e.g. vim.
In the Event Viewer, check the Security log for a corresponding Process Creation event. This can be identified where the Creator Process Name is bash. In this event, both the New Process Name and Process Command Line will be blank.
Strace of the failing command
Running the command using strace -e execve confirms that the system call is being made to execute a program.
Required packages and commands to install
Nothing other than the Linux subsystem itself.
Please use the following bug reporting template to help produce actionable and reproducible issues. Please try to ensure that the reproduction is minimal so that the team can go through more bugs!
A brief description
Creating a new process within the Linux subsystem causes an incomplete Process Creation event (ID 4688) to be added the Security event log. The New Process Name and Process Command Line fields are blank.
Expected results
Creating a new process within the Linux subsystem should log the same quality of information as normal Windows process creation. New Process Name should be the full pathname to the process, and Process Command Line should be the command line.
Actual results (with terminal output if applicable)
Here is an excerpt from the XML view of a Linux subsystem Process Creation event:
Your Windows build number
14393.693
Steps / All commands required to reproduce the error from a brand new installation
notepad.exe
.vim
.bash
. In this event, both the New Process Name and Process Command Line will be blank.Strace of the failing command
Running the command using
strace -e execve
confirms that the system call is being made to execute a program.Required packages and commands to install
Nothing other than the Linux subsystem itself.
See our contributing instructions for assistance.
The text was updated successfully, but these errors were encountered: