|Alert Message||Windows audit event|
This event indicates that the Software Protection service has scheduled an event (typically a restart) successfully.
 What you should do
In some virtual machine environments, this can be causing systems to be restarted in an unplanned fashion. It would manifest in a "random restart" pattern, and you can use this rule ID to identify the hosts where this is affecting Availability.
 False Positives
There are no false positives with this rule.
 Tuning Guidance
There is no guidance for tuning this rule, this is a generic Windows event and the rule should not be disabled.
 Additional Information
If you are unsure about how to respond to this alert, please contact Atomicorp support. We're here to help you!
 Similar Rules
 Knowledge Base Articles
 Outside References