Windows does not include some advanced features in the default settings. You will need to enable advanced security checking to capture the details. The advantage of using Windows Service Auditor is that you can activate it immediately.
Click the Application menu and then select Enable Local Audit Policy . This option is automatically enabled by default, but if you want to turn it off, this is the menu you need to access.
The final step is to select a service, then click the eye icon on the top menu to start tracking. Once enabled, notice the eye icon next to the service being monitored.
Select it and you will have details in the Events section . It will include all changes made by a program or user along with the timestamp. There is no way to enable this feature for many services and it will not work for all services, but only for those that are not under the control of the system.
You can also enable auditing for any service using the menu option available in the Service.
You can also enable auditing for any service using the menu option available in the Service