Hello,
The following audit generate duplicate event on Windows application log, why ?
CREATE SERVER AUDIT [ApplicationLog_Logon]
TO APPLICATION_LOG
WITH
( QUEUE_DELAY = 1000
,ON_FAILURE = CONTINUE
,AUDIT_GUID = 'ed3842b-ea77-4547-a77f-c8874785874''
)
WHERE (NOT [server_principal_name] like 'NT SERVICE\SQLAgent$%')
ALTER SERVER AUDIT [ApplicationLog_Logon] WITH (STATE = ON)
GO
Thanks
regards