Microsoft-Windows-Eventlog
40 events across 4 channels
Event ID 20 — The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Path | — |
Event ID 21 — The event logging service encountered a configuration-related error (res=%1) for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
ConfigProperty | — |
Event ID 22 — The event logging service encountered an error while initializing publishing resources for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Path | — |
Event ID 23 — The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Path | — |
Event ID 25 — The event logging service encountered a corrupt log file for channel %1.
Message
Fields
| Name | Description |
|---|---|
ChannelPath | — |
Event ID 26 — The event logging service encountered a log file for channel %1 which is an unsupported version.
Message
Fields
| Name | Description |
|---|---|
ChannelPath | — |
Event ID 27 — The event logging service encountered an error (res=%1) while opening log file for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
FailedLogFilePath | — |
NewLogFilePath | — |
Event ID 28 — The event logging service encountered an error (res=%1) while parsing filter for channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
Event ID 29 — The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
Event ID 30 — The event logging service encountered an error (%1) while enabling publisher %3 to channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
PublisherGuid | — |
Event ID 31 — The event logging service encountered an error (res=%1) while opening configuration for primary channel %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
Event ID 40 — The event logging service encountered an error when attempting to apply one or more policy settings.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ChannelPath | — |
Event ID 100 — The event logging service encountered an error while processing an incoming event published from %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
EventID | — |
PubID | — |
Event ID 102 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
EventID | — |
PublisherName | — |
PublisherGuid | — |
ProcessID | — |
Event ID 103 — Events have been dropped by the transport.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
SessionName | — |
Event ID 104 — The System log file was cleared.
Message
Fields
| Name | Description |
|---|---|
LogFileCleared.SubjectUserName | — |
LogFileCleared.SubjectDomainName | — |
LogFileCleared.Channel | — |
LogFileCleared.BackupPath | — |
LogFileCleared.ClientProcessId | — |
LogFileCleared.ClientProcessStartKey | — |
Example Event
system:
provider: Microsoft-Windows-Eventlog
guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
event_source_name: ''
event_id: 104
version: 1
level: 4
task: 104
opcode: 0
keywords: 9223372036854775808
time_created: '2023-10-25T22:53:10.300656+00:00'
event_record_id: 1453
correlation: {}
execution:
process_id: 1796
thread_id: 2028
channel: System
computer: WinDevEval
security:
user_id: S-1-5-21-2533829718-189860685-2477588761-500
user_data:
LogFileCleared:
SubjectUserName: Administrator
SubjectDomainName: WINDEVEVAL
Channel: Application
BackupPath: null
ClientProcessId: 4544
ClientProcessStartKey: 2533274790396090
message: ''
Community Notes
This will show System, Application, and other non-Security logs being cleared. Review the event to identify which one.Sigma Rules
- Eventlog Cleared
One of the Windows Eventlogs has been cleared. e.g. caused by "wevtutil cl" command execution - Important Windows Eventlog Cleared
Detects the clearing of one of the Windows Core Eventlogs. e.g. caused by "wevtutil cl" command execution
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 105 — Event log automatic backup Log: %1 File: %2.
Message
Fields
| Name | Description |
|---|---|
Log | — |
File | — |
Example Event
system:
provider: Microsoft-Windows-Eventlog
guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
event_source_name: ''
event_id: 105
version: 0
level: 4
task: 105
opcode: 0
keywords: 9223372036854775808
time_created: '2012-03-26T05:50:08.470644Z'
event_record_id: 13049
correlation: {}
execution:
process_id: 772
thread_id: 4256
channel: System
computer: WKS-WIN764BITB.shieldbase.local
security:
user_id: ''
user_data:
AutoBackup:
xmlns:auto-ns3: http://schemas.microsoft.com/win/2004/08/events
Channel: Application
BackupPath: C:\Windows\System32\Winevt\Logs\Archive-Application-2012-03-26-05-50-01-755.evtx
Event ID 106 — Corruption was detected in the log for the %1 channel and some data was erased.
Message
Fields
| Name | Description |
|---|---|
Channel | — |
Event ID 107 — The event logging service encountered an error %1 while going through publisher configuration.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ProviderName | — |
PublisherGuid | — |
Event ID 108 — The previous system shutdown was unexpected.
Message
Fields
| Name | Description |
|---|---|
ShutdownTime | — |
ActualMaxInterval | — |
DiskPmDisabledMaxInterval | — |
DiskPmEnabledFlag | — |
DiskPmEnabledMaxInterval | — |
TimestampForced | — |
DiskPmPolicy | — |
BiasValid | — |
StartBias | — |
Event ID 109 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
EventID | — |
PublisherName | — |
PublisherGuid | — |
ProcessID | — |
EventName | — |
Event ID 110 — Loading metadata for publisher %2 (%1) and trying to process the metadata for it.
Message
Fields
| Name | Description |
|---|---|
PublisherGuid | — |
PublisherName | — |
Event ID 111 — Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.
Message
Fields
| Name | Description |
|---|---|
PublisherGuid | — |
PublisherName | — |
EventMetaDataCount | — |
Event ID 112 — Failed to load metadata for publisher %2 (%1).
Message
Fields
| Name | Description |
|---|---|
PublisherGuid | — |
PublisherName | — |
ErrorCode | — |
Event ID 200 — Channel %1 (%2) was enabled (%3) programmatically.
Message
Fields
| Name | Description |
|---|---|
ChannelName | — |
ChannelType | — |
Enabled | — |
Event ID 201 — A push subscription was created for %1.
Message
Fields
| Name | Description |
|---|---|
ChannelName | — |
Query | — |
Event ID 202 — A pull subscription was created for %1.
Message
Fields
| Name | Description |
|---|---|
ChannelName | — |
Query | — |
Event ID 203 — OpenEventLog legacy API was used to open %2.
Message
Fields
| Name | Description |
|---|---|
ModuleNameLen | — |
ModuleName | — |
Event ID 204 — RegisterEventSource legacy API was used to register %2.
Message
Fields
| Name | Description |
|---|---|
ModuleNameLen | — |
ModuleName | — |
Event ID 205 — ReportEvent legacy API was used to write an event to %2.
Message
Fields
| Name | Description |
|---|---|
ModuleNameLen | — |
ModuleName | — |
Event ID 1100 — The event logging service has shut down.
Message
Fields
| Name | Description |
|---|---|
ServiceShutdown | — |
Example Event
system:
provider: Microsoft-Windows-Eventlog
guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
event_source_name: ''
event_id: 1100
version: 0
level: 4
task: 103
opcode: 0
keywords: 4620693217682128896
time_created: '2023-11-05T22:31:36.994928+00:00'
event_record_id: 3371
correlation: {}
execution:
process_id: 1816
thread_id: 1352
channel: Security
computer: WinDev2310Eval
security:
user_id: ''
user_data:
ServiceShutdown: {}
message: ''
References
- Microsoft Learn https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1100
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1100
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1101 — Audit events have been dropped by the transport.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
References
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1101
Event ID 1102 — The audit log was cleared.
Message
Fields
| Name | Description |
|---|---|
LogFileCleared.SubjectUserSid | [Subject] Security ID. |
LogFileCleared.SubjectUserName | [Subject] Account Name. |
LogFileCleared.SubjectDomainName | [Subject] Domain Name. |
LogFileCleared.SubjectLogonId | [Subject] Logon ID. |
LogFileCleared.ClientProcessId | — |
LogFileCleared.ClientProcessStartKey | — |
Example Event
system:
provider: Microsoft-Windows-Eventlog
guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
event_source_name: ''
event_id: 1102
version: 1
level: 4
task: 104
opcode: 0
keywords: 4620693217682128896
time_created: '2023-10-25T22:53:10.300656+00:00'
event_record_id: 2625
correlation: {}
execution:
process_id: 1796
thread_id: 2028
channel: Security
computer: WinDevEval
security:
user_id: ''
user_data:
LogFileCleared:
SubjectUserSid: S-1-5-21-2533829718-189860685-2477588761-500
SubjectUserName: Administrator
SubjectDomainName: WINDEVEVAL
SubjectLogonId: '0x42eea'
ClientProcessId: 4544
ClientProcessStartKey: 2533274790396090
message: ''
References
- Microsoft Learn https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-1102
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=1102
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1103 — The security log is now %1 percent full.
Message
Fields
| Name | Description |
|---|---|
PercentFull | — |
Event ID 1104 — The security log is now full.
Message
References
Event ID 1105 — Event log automatic backup Log: %1 File: %2.
Message
Fields
| Name | Description |
|---|---|
Log | — |
File | — |
Channel | — |
BackupPath | — |
References
Event ID 1106 — Events have been dropped by the event logging service.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 1107 — The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
EventID | — |
PublisherName | — |
PublisherGuid | — |
ProcessID | — |
Example Event
system:
provider: Microsoft-Windows-Eventlog
guid: '{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}'
event_source_name: ''
event_id: 1107
version: 0
level: 2
task: 101
opcode: 0
keywords: 4620693217682128896
time_created: '2016-08-18T16:53:04.313375Z'
event_record_id: 5538
correlation: {}
execution:
process_id: 716
thread_id: 1128
channel: Security
computer: IE10Win7
security:
user_id: ''
user_data:
EventPublisherMetaDataFailure:
'#attributes':
xmlns:auto-ns3: http://schemas.microsoft.com/win/2004/08/events
xmlns: http://manifests.microsoft.com/win/2004/08/windows/eventlog
Error:
'#attributes':
Code: 15002
EventID: 0
PublisherName: null
PublisherGuid: 54849625-5478-4994-A5BA-3E3B0328C30D
ProcessID: 0
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1108 — The event logging service encountered an error while processing an incoming event published from %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
EventID | — |
PubID | — |
References
Event ID 6000 — The %1 log file is full.
Message
Fields
| Name | Description |
|---|---|
Channel | — |