Microsoft-Windows-Eventlog

40 events across 4 channels

Event IDTitleChannel
20The event logging service encountered an error %1 while obtaining or processing …System
21The event logging service encountered a configuration-related error (res=%1) for …System
22The event logging service encountered an error while initializing publishing …System
23The event logging service encountered an error (res=%1) while initializing …System
25The event logging service encountered a corrupt log file for channel %1.System
26The event logging service encountered a log file for channel %1 which is an …System
27The event logging service encountered an error (res=%1) while opening log file …System
28The event logging service encountered an error (res=%1) while parsing filter for …System
29The event logging service encountered a fatal error (res=%1) when applying …System
30The event logging service encountered an error (%1) while enabling publisher %3 …System
31The event logging service encountered an error (res=%1) while opening …System
40The event logging service encountered an error when attempting to apply one or …System
100The event logging service encountered an error while processing an incoming …Analytic
102The event logging service encountered an error while processing an incoming …Analytic
103Events have been dropped by the transport.Analytic
104The System log file was cleared.System
105Event log automatic backup Log: %1 File: %2.System
106Corruption was detected in the log for the %1 channel and some data was erased.System
107The event logging service encountered an error %1 while going through publisher …Analytic
108The previous system shutdown was unexpected.System
109The event logging service encountered an error while processing an incoming …Analytic
110Loading metadata for publisher %2 (%1) and trying to process the metadata for …Debug
111Finished loading metadata for publisher %2 (%1), with %3 event metadatas …Debug
112Failed to load metadata for publisher %2 (%1).Debug
200Channel %1 (%2) was enabled (%3) programmatically.Analytic
201A push subscription was created for %1.Analytic
202A pull subscription was created for %1.Analytic
203OpenEventLog legacy API was used to open %2.Analytic
204RegisterEventSource legacy API was used to register %2.Analytic
205ReportEvent legacy API was used to write an event to %2.Analytic
1100The event logging service has shut down.Security
1101Audit events have been dropped by the transport.Security
1102The audit log was cleared.Security
1103The security log is now %1 percent full.Security
1104The security log is now full.Security
1105Event log automatic backup Log: %1 File: %2.Security
1106Events have been dropped by the event logging service.Security
1107The event logging service encountered an error while processing an incoming …Security
1108The event logging service encountered an error while processing an incoming …Security
6000The %1 log file is full.System

Event ID 20 — The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.

Fields

NameDescription
ErrorCode
Path

Event ID 21 — The event logging service encountered a configuration-related error (res=%1) for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered a configuration-related error (res=%1) for channel %2. The error was encountered while processing the %3 configuration property.

Fields

NameDescription
ErrorCode
ChannelPath
ConfigProperty

Event ID 22 — The event logging service encountered an error while initializing publishing resources for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error while initializing publishing resources for channel %2. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Fields

NameDescription
ErrorCode
Path

Event ID 23 — The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.

Fields

NameDescription
ErrorCode
Path

Event ID 25 — The event logging service encountered a corrupt log file for channel %1.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered a corrupt log file for channel %1. The log was renamed with a .corrupt extension.

Fields

NameDescription
ChannelPath

Event ID 26 — The event logging service encountered a log file for channel %1 which is an unsupported version.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered a log file for channel %1 which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Fields

NameDescription
ChannelPath

Event ID 27 — The event logging service encountered an error (res=%1) while opening log file for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error (res=%1) while opening log file for channel %2. Trying again using default log file path %3.

Fields

NameDescription
ErrorCode
ChannelPath
FailedLogFilePath
NewLogFilePath

Event ID 28 — The event logging service encountered an error (res=%1) while parsing filter for channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error (res=%1) while parsing filter for channel %2. Will continue without filter.

Fields

NameDescription
ErrorCode
ChannelPath

Event ID 29 — The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel. The service is shutting down since this channel is vital to its operation.

Fields

NameDescription
ErrorCode
ChannelPath

Event ID 30 — The event logging service encountered an error (%1) while enabling publisher %3 to channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error (%1) while enabling publisher %3 to channel %2. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Fields

NameDescription
ErrorCode
ChannelPath
PublisherGuid

Event ID 31 — The event logging service encountered an error (res=%1) while opening configuration for primary channel %2.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error (res=%1) while opening configuration for primary channel %2. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Fields

NameDescription
ErrorCode
ChannelPath

Event ID 40 — The event logging service encountered an error when attempting to apply one or more policy settings.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The event logging service encountered an error when attempting to apply one or more policy settings.

Fields

NameDescription
ErrorCode
ChannelPath

Event ID 100 — The event logging service encountered an error while processing an incoming event published from %3.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

The event logging service encountered an error while processing an incoming event published from %3.

Fields

NameDescription
ErrorCode
EventID
PubID

Event ID 102 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields

NameDescription
ErrorCode
EventID
PublisherName
PublisherGuid
ProcessID

Event ID 103 — Events have been dropped by the transport.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

Events have been dropped by the transport.  The session name is %2 and the reason code is %1.

Fields

NameDescription
Reason
SessionName

Event ID 104 — The System log file was cleared.

Provider
Microsoft-Windows-Eventlog
Channel
System
Level
4
Samples
1

Message

The %3 log file was cleared.

Fields

NameDescription
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.Channel
LogFileCleared.BackupPath
LogFileCleared.ClientProcessId
LogFileCleared.ClientProcessStartKey

Example Event

system:
  provider: Microsoft-Windows-Eventlog
  guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
  event_source_name: ''
  event_id: 104
  version: 1
  level: 4
  task: 104
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2023-10-25T22:53:10.300656+00:00'
  event_record_id: 1453
  correlation: {}
  execution:
    process_id: 1796
    thread_id: 2028
  channel: System
  computer: WinDevEval
  security:
    user_id: S-1-5-21-2533829718-189860685-2477588761-500
user_data:
  LogFileCleared:
    SubjectUserName: Administrator
    SubjectDomainName: WINDEVEVAL
    Channel: Application
    BackupPath: null
    ClientProcessId: 4544
    ClientProcessStartKey: 2533274790396090
message: ''

Community Notes

This will show System, Application, and other non-Security logs being cleared. Review the event to identify which one.

Sigma Rules

References

Event ID 105 — Event log automatic backup Log: %1 File: %2.

Provider
Microsoft-Windows-Eventlog
Channel
System
Level
4
Samples
1

Message

Event log automatic backup
	Log:	%1
	File:	%2

Fields

NameDescription
Log
File

Example Event

system:
  provider: Microsoft-Windows-Eventlog
  guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
  event_source_name: ''
  event_id: 105
  version: 0
  level: 4
  task: 105
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2012-03-26T05:50:08.470644Z'
  event_record_id: 13049
  correlation: {}
  execution:
    process_id: 772
    thread_id: 4256
  channel: System
  computer: WKS-WIN764BITB.shieldbase.local
  security:
    user_id: ''
user_data:
  AutoBackup:
    xmlns:auto-ns3: http://schemas.microsoft.com/win/2004/08/events
    Channel: Application
    BackupPath: C:\Windows\System32\Winevt\Logs\Archive-Application-2012-03-26-05-50-01-755.evtx

Event ID 106 — Corruption was detected in the log for the %1 channel and some data was erased.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

Corruption was detected in the log for the %1 channel and some data was erased.

Fields

NameDescription
Channel

Event ID 107 — The event logging service encountered an error %1 while going through publisher configuration.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

The event logging service encountered an error %1 while going through publisher configuration. The publisher %2 is already installed with GUID %3.

Fields

NameDescription
ErrorCode
ProviderName
PublisherGuid

Event ID 108 — The previous system shutdown was unexpected.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The previous system shutdown was unexpected.

Fields

NameDescription
ShutdownTime
ActualMaxInterval
DiskPmDisabledMaxInterval
DiskPmEnabledFlag
DiskPmEnabledMaxInterval
TimestampForced
DiskPmPolicy
BiasValid
StartBias

Event ID 109 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields

NameDescription
ErrorCode
EventID
PublisherName
PublisherGuid
ProcessID
EventName

Event ID 110 — Loading metadata for publisher %2 (%1) and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Debug

Message

Loading metadata for publisher %2 (%1) and trying to process the metadata for it.

Fields

NameDescription
PublisherGuid
PublisherName

Event ID 111 — Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.

Provider
Microsoft-Windows-Eventlog
Channel
Debug

Message

Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.

Fields

NameDescription
PublisherGuid
PublisherName
EventMetaDataCount

Event ID 112 — Failed to load metadata for publisher %2 (%1).

Provider
Microsoft-Windows-Eventlog
Channel
Debug

Message

Failed to load metadata for publisher %2 (%1). The reason code is %3.

Fields

NameDescription
PublisherGuid
PublisherName
ErrorCode

Event ID 200 — Channel %1 (%2) was enabled (%3) programmatically.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

Channel %1 (%2) was enabled (%3) programmatically.

Fields

NameDescription
ChannelName
ChannelType
Enabled

Event ID 201 — A push subscription was created for %1.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

A push subscription was created for %1.

Fields

NameDescription
ChannelName
Query

Event ID 202 — A pull subscription was created for %1.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

A pull subscription was created for %1.

Fields

NameDescription
ChannelName
Query

Event ID 203 — OpenEventLog legacy API was used to open %2.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

OpenEventLog legacy API was used to open %2.

Fields

NameDescription
ModuleNameLen
ModuleName

Event ID 204 — RegisterEventSource legacy API was used to register %2.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

RegisterEventSource legacy API was used to register %2.

Fields

NameDescription
ModuleNameLen
ModuleName

Event ID 205 — ReportEvent legacy API was used to write an event to %2.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Message

ReportEvent legacy API was used to write an event to %2.

Fields

NameDescription
ModuleNameLen
ModuleName

Event ID 1100 — The event logging service has shut down.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
4
Samples
1

Message

The event logging service has shut down.

Fields

NameDescription
ServiceShutdown

Example Event

system:
  provider: Microsoft-Windows-Eventlog
  guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
  event_source_name: ''
  event_id: 1100
  version: 0
  level: 4
  task: 103
  opcode: 0
  keywords: 4620693217682128896
  time_created: '2023-11-05T22:31:36.994928+00:00'
  event_record_id: 3371
  correlation: {}
  execution:
    process_id: 1816
    thread_id: 1352
  channel: Security
  computer: WinDev2310Eval
  security:
    user_id: ''
user_data:
  ServiceShutdown: {}
message: ''

References

Event ID 1101 — Audit events have been dropped by the transport.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

Audit events have been dropped by the transport.  %1

Fields

NameDescription
Reason

References

Event ID 1102 — The audit log was cleared.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
4
Samples
1

Message

The audit log was cleared.
Subject:
	Security ID:	%1
	Account Name:	%2
	Domain Name:	%3
	Logon ID:	%4

Fields

NameDescription
LogFileCleared.SubjectUserSid[Subject] Security ID.
LogFileCleared.SubjectUserName[Subject] Account Name.
LogFileCleared.SubjectDomainName[Subject] Domain Name.
LogFileCleared.SubjectLogonId[Subject] Logon ID.
LogFileCleared.ClientProcessId
LogFileCleared.ClientProcessStartKey

Example Event

system:
  provider: Microsoft-Windows-Eventlog
  guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
  event_source_name: ''
  event_id: 1102
  version: 1
  level: 4
  task: 104
  opcode: 0
  keywords: 4620693217682128896
  time_created: '2023-10-25T22:53:10.300656+00:00'
  event_record_id: 2625
  correlation: {}
  execution:
    process_id: 1796
    thread_id: 2028
  channel: Security
  computer: WinDevEval
  security:
    user_id: ''
user_data:
  LogFileCleared:
    SubjectUserSid: S-1-5-21-2533829718-189860685-2477588761-500
    SubjectUserName: Administrator
    SubjectDomainName: WINDEVEVAL
    SubjectLogonId: '0x42eea'
    ClientProcessId: 4544
    ClientProcessStartKey: 2533274790396090
message: ''

References

Event ID 1103 — The security log is now %1 percent full.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

The security log is now %1 percent full.

Fields

NameDescription
PercentFull

Event ID 1104 — The security log is now full.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

The security log is now full.

References

Event ID 1105 — Event log automatic backup Log: %1 File: %2.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

Event log automatic backup
	Log:	%1
	File:	%2

Fields

NameDescription
Log
File
Channel
BackupPath

References

Event ID 1106 — Events have been dropped by the event logging service.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

Events have been dropped by the event logging service. The reason code is %1.

Fields

NameDescription
Reason

Event ID 1107 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
2
Samples
1

Message

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields

NameDescription
ErrorCode
EventID
PublisherName
PublisherGuid
ProcessID

Example Event

system:
  provider: Microsoft-Windows-Eventlog
  guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
  event_source_name: ''
  event_id: 1107
  version: 0
  level: 2
  task: 101
  opcode: 0
  keywords: 4620693217682128896
  time_created: '2016-08-18T16:53:04.313375Z'
  event_record_id: 5538
  correlation: {}
  execution:
    process_id: 716
    thread_id: 1128
  channel: Security
  computer: IE10Win7
  security:
    user_id: ''
user_data:
  EventPublisherMetaDataFailure:
    '#attributes':
      xmlns:auto-ns3: http://schemas.microsoft.com/win/2004/08/events
      xmlns: http://manifests.microsoft.com/win/2004/08/windows/eventlog
    Error:
      '#attributes':
        Code: 15002
    EventID: 0
    PublisherName: null
    PublisherGuid: 54849625-5478-4994-A5BA-3E3B0328C30D
    ProcessID: 0

References

Event ID 1108 — The event logging service encountered an error while processing an incoming event published from %3.

Provider
Microsoft-Windows-Eventlog
Channel
Security

Message

The event logging service encountered an error while processing an incoming event published from %3.

Fields

NameDescription
ErrorCode
EventID
PubID

References

Event ID 6000 — The %1 log file is full.

Provider
Microsoft-Windows-Eventlog
Channel
System

Message

The %1 log file is full.

Fields

NameDescription
Channel