How to Track Software Installation and Removal Using Event IDs 11707, 11724, and 592

There some requirements, you may need to trace software installations and removals along with the user account details.

Under the events you can look for in both the Application Event Log and Security Event Log that will help you do this.

In the Application log, setup packages that use the Windows Installer to install themselves will create numerous events, all with an event source of MsiInstaller.

Event ID 11707 tells you when a install completes successfully, and also the user who executed the install package.

Event ID 11724 tells you when a software package is removed successfully, again logging the user behind the operation.

Event ID 592 in the Security log tells you the exact user account, which was used during the installation / removal process.

Please follow and like us:

Author: Chathura Ariyadasa

♚Father ♚Innovative Technical Architect ♚ Cyber Security Strategist ♞ vCISO | vCIO ♞ Blogger & an Adrenaline junkie...