Reporting of 651 Events
Even if 651 events are configured to be reported, they do not show up in the Windows Event Log or the central DES-Log. These events only show up in logs once an ABC-Rule rule is created that:
- Monitors the relevant Skript Executions
- Is configured to generate events when DriveLock approves the Skript executions
This behavior of DriveLock is not documented anywhere.
All other events that I have come across don't work this way and get reported if they are appropriately configured in the "Events & Alerts" section of the policy. The additional ABC-Rule seems to be only necessary for 651 events
We would appreciate one or both of the following changes:
- Just configuring the Event 651 under "Alerts &Event" causes this Event to be logged to the configured Targets.
- This behavior is explained in the Configuration Tab of the 651 Event and on this webpage: https://drivelock.help/versions/2026_1/web/de/events/content/concepts/con_events26-1.htm
Thank you for your feedback.
The current behavior is intentional: Events & Alerts defines how an event is handled once it has been generated. For allowed Application Control access, event generation must be explicitly enabled via an ABC rule.
We agree that this behavior is not sufficiently clear in the documentation. Our documentation team will update the relevant documentation accordingly.
We will therefore close this idea.