I will like to be able to produce a report of machines with audit settings using the invoke block to execute the auditpool.exe command and generate a report of settings not enable from a machine.
I could probably use gpresult from GPO but I will like to fllter by settings not enabled.
invoke-Scriptblock -computername machinexxxx
-command {auditpol.exe /get /category:* > c:\windows\text.txt | -pattern "No Auditing" | select-object | line}
michael john ocasio