$ 0 0 I just tested this, and it showed up in my LEM Internal Events filter. In nDepth, you could search for Event Name = Internal Commands, InferenceRule = Kill Proc Name and ExtraneousInfo = [machine, user account, or process] The event looks like this: