Defender-DeviceLogonEvents

4 events across 4 channels

Event IDTitleChannel
9003000Logon activity (any)DeviceLogonEvents
9003001Logon succeededLogonSuccess
9003002Logon failedLogonFailed
9003003Logon attempted (no result yet)LogonAttempted

Event ID 9003000 — Logon activity (any)

Provider
Defender-DeviceLogonEvents
Channel
DeviceLogonEvents

Description

Logon activity (any)

Fields #

NameDescription
DeviceId
Timestamp
ActionType
LogonType
AccountName
AccountDomain
AccountSid
RemoteIP
RemotePort
IsLocalAdmin
InitiatingProcessFileName
FailureReason

References #

Event ID 9003001 — Logon succeeded

#

Event ID 9003002 — Logon failed

#

Event ID 9003003 — Logon attempted (no result yet)

Provider
Defender-DeviceLogonEvents
Channel
LogonAttempted

Description

Logon attempted (no result yet)

Fields #

NameDescription
DeviceId
Timestamp
LogonType
AccountName
RemoteIP

References #