Microsoft-Windows-Eventlog

41 events across 4 channels

Event IDTitleChannel
20The event logging service encountered an error ErrorCode while obtaining or …System
21The event logging service encountered a configuration-related error …System
22The event logging service encountered an error while initializing publishing …System
23The event logging service encountered an error (res=ErrorCode) while …System
25The event logging service encountered a corrupt log file for channel …System
26The event logging service encountered a log file for channel ChannelPath which …System
27The event logging service encountered an error (res=ErrorCode) while opening log …System
28The event logging service encountered an error (res=ErrorCode) while parsing …System
29The event logging service encountered a fatal error (res=ErrorCode) when …System
30The event logging service encountered an error …System
31The event logging service encountered an error (res=ErrorCode) while opening …System
40The event logging service encountered an error when attempting to apply one or …System
100The event logging service encountered an error while processing an incoming …Analytic
102The event logging service encountered an error while processing an incoming …Analytic
103Events have been dropped by the transport.Analytic
104The LogFileCleared.Channel log file was cleared.System
105Event log automatic backup.System
106Corruption was detected in the log for the Channel channel and some data was …System
107The event logging service encountered an error ErrorCode while going through …Analytic
108The previous system shutdown was unexpected.System
109The event logging service encountered an error while processing an incoming …Analytic
110Loading metadata for publisher PublisherName (PublisherGuid) and trying to …Debug
111Finished loading metadata for publisher PublisherName (PublisherGuid), with …Debug
112Failed to load metadata for publisher PublisherName (PublisherGuid).Debug
200Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.Analytic
201A push subscription was created for ChannelName.Analytic
202A pull subscription was created for ChannelName.Analytic
203OpenEventLog legacy API was used to open ModuleName.Analytic
204RegisterEventSource legacy API was used to register ModuleName.Analytic
205ReportEvent legacy API was used to write an event to ModuleName.Analytic
517The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by …Security
1100The event logging service has shut down.Security
1101Audit events have been dropped by the transport.Security
1102The audit log was cleared.Security
1103The security log is now PercentFull percent full.Security
1104The security log is now full.Security
1105Event log automatic backup.Security
1106Events have been dropped by the event logging service.Security
1107The event logging service encountered an error while processing an incoming …Security
1108The event logging service encountered an error while processing an incoming …Security
6000The Channel log file is full.System

Event ID 20 — The event logging service encountered an error ErrorCode while obtaining or processing configuration for channel Path.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error ErrorCode while obtaining or processing configuration for channel Path.

Message #

The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 21 — The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath. The error was encountered while processing the ConfigProperty configuration property.

Message #

The event logging service encountered a configuration-related error (res=%1) for channel %2. The error was encountered while processing the %3 configuration property.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
ConfigProperty UnicodeString

Event ID 22 — The event logging service encountered an error while initializing publishing resources for channel Path.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Message #

The event logging service encountered an error while initializing publishing resources for channel %2. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 23 — The event logging service encountered an error (res=ErrorCode) while initializing logging resources for channel Path.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while initializing logging resources for channel Path.

Message #

The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 25 — The event logging service encountered a corrupt log file for channel ChannelPath.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a corrupt log file for channel ChannelPath. The log was renamed with a .corrupt extension.

Message #

The event logging service encountered a corrupt log file for channel %1. The log was renamed with a .corrupt extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 26 — The event logging service encountered a log file for channel ChannelPath which is an unsupported version.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a log file for channel ChannelPath which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Message #

The event logging service encountered a log file for channel %1 which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 27 — The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath. Trying again using default log file path FailedLogFilePath.

Message #

The event logging service encountered an error (res=%1) while opening log file for channel %2. Trying again using default log file path %3.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
FailedLogFilePath UnicodeString
NewLogFilePath UnicodeString

Event ID 28 — The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath. Will continue without filter.

Message #

The event logging service encountered an error (res=%1) while parsing filter for channel %2. Will continue without filter.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 29 — The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel.

Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel. The service is shutting down since this channel is vital to its operation.

Message #

The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel. The service is shutting down since this channel is vital to its operation.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 30 — The event logging service encountered an error (InitChannelPublisherEnableFailure.ErrorCode) while enabling publisher InitChannelPublisherEnableFailure.PublisherGuid to channel InitChannelPublisher...

Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Error
Task
Servicestartup

Message #

The event logging service encountered an error (%1) while enabling publisher %3 to channel %2. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Fields #

NameDescription
InitChannelPublisherEnableFailure.ErrorCode UInt32
InitChannelPublisherEnableFailure.ChannelPath UnicodeString
InitChannelPublisherEnableFailure.PublisherGuid GUID
ErrorCode UInt32
ChannelPath UnicodeString
PublisherGuid GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148",
    "event_source_name": "",
    "event_id": 30,
    "version": 0,
    "level": 2,
    "task": 100,
    "opcode": 0,
    "keywords": 9223372036854906880,
    "time_created": "2026-03-13T19:59:15.259008+00:00",
    "event_record_id": 11634,
    "correlation": {},
    "execution": {
      "process_id": 1844,
      "thread_id": 8176
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "user_data": {
    "InitChannelPublisherEnableFailure": {
      "ErrorCode": 5,
      "ChannelPath": "Microsoft-Windows-WinINet-Capture/Analytic",
      "PublisherGuid": "A70FF94F-570B-4979-BA5C-E59C9FEAB61B"
    }
  },
  "message": ""
}

Event ID 31 — The event logging service encountered an error (res=ErrorCode) while opening configuration for primary channel ChannelPath.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Message #

The event logging service encountered an error (res=%1) while opening configuration for primary channel %2. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 40 — The event logging service encountered an error when attempting to apply one or more policy settings.

Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The event logging service encountered an error when attempting to apply one or more policy settings.

Message #

The event logging service encountered an error when attempting to apply one or more policy settings.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 100 — The event logging service encountered an error while processing an incoming event published from PubID.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event published from PubID.

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Event ID 102 — The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Event ID 103 — Events have been dropped by the transport.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

Events have been dropped by the transport. The session name is SessionName and the reason code is Reason.

Message #

Events have been dropped by the transport.  The session name is %2 and the reason code is %1.

Fields #

NameDescription
Reason UInt8
SessionName UnicodeString

Event ID 104 — The LogFileCleared.Channel log file was cleared.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Logclear

Description

The LogFileCleared.Channel log file was cleared.

Message #

The %3 log file was cleared.

Fields #

NameDescription
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.Channel
LogFileCleared.BackupPath
LogFileCleared.ClientProcessId
LogFileCleared.ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 104,
    "version": 1,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-10-25T22:53:10.300656+00:00",
    "event_record_id": 1453,
    "correlation": {},
    "execution": {
      "process_id": 1796,
      "thread_id": 2028
    },
    "channel": "System",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-21-2533829718-189860685-2477588761-500"
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserName": "Administrator",
      "SubjectDomainName": "WINDEVEVAL",
      "Channel": "Application",
      "BackupPath": null,
      "ClientProcessId": 4544,
      "ClientProcessStartKey": 2533274790396090
    }
  },
  "message": ""
}

Detection Patterns #

Defense Evasion: Clear Windows Event Logs

2 rules

Elastic

Elastic, Anabella Cristaldi

Splunk

Rico Valdez, Michael Haag, Splunk

Defense Evasion: Clear Windows Event Logs

2 rules

Elastic

Elastic, Anabella Cristaldi

Splunk

Rico Valdez, Michael Haag, Splunk

Community Notes #

This will show System, Application, and other non-Security logs being cleared. Review the event to identify which one.

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

References #

Event ID 105 — Event log automatic backup.

Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Informational
Task
Logautomaticbackup

Description

Event log automatic backup.

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Log UnicodeString
File UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 105,
    "version": 0,
    "level": 4,
    "task": 105,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2012-03-26T05:50:08.470644Z",
    "event_record_id": 13049,
    "correlation": {},
    "execution": {
      "process_id": 772,
      "thread_id": 4256
    },
    "channel": "System",
    "computer": "WKS-WIN764BITB.shieldbase.local",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AutoBackup": {
      "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
      "Channel": "Application",
      "BackupPath": "C:\\Windows\\System32\\Winevt\\Logs\\Archive-Application-2012-03-26-05-50-01-755.evtx"
    }
  }
}

Event ID 106 — Corruption was detected in the log for the Channel channel and some data was erased.

Provider
Microsoft-Windows-Eventlog
Channel
System

Description

Corruption was detected in the log for the Channel channel and some data was erased.

Message #

Corruption was detected in the log for the %1 channel and some data was erased.

Fields #

NameDescription
Channel UnicodeString

Event ID 107 — The event logging service encountered an error ErrorCode while going through publisher configuration.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Description

The event logging service encountered an error ErrorCode while going through publisher configuration. The publisher ProviderName is already installed with GUID PublisherGuid.

Message #

The event logging service encountered an error %1 while going through publisher configuration. The publisher %2 is already installed with GUID %3.

Fields #

NameDescription
ErrorCode UInt32
ProviderName UnicodeString
PublisherGuid GUID

Event ID 108 — The previous system shutdown was unexpected.

Provider
Microsoft-Windows-Eventlog
Channel
System
Task
SystemAbnormalShutdown

Description

The previous system shutdown was unexpected.

Message #

The previous system shutdown was unexpected.

Fields #

NameDescription
ShutdownTime SYSTEMTIME
ActualMaxInterval UInt32
DiskPmDisabledMaxInterval UInt32
DiskPmEnabledFlag UInt32
DiskPmEnabledMaxInterval UInt32
TimestampForced UInt32
DiskPmPolicy UInt32
BiasValid UInt32
StartBias UInt32

Event ID 109 — The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32
EventName UnicodeString

Event ID 110 — Loading metadata for publisher PublisherName (PublisherGuid) and trying to process the metadata for it.

Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Start

Description

Loading metadata for publisher PublisherName (PublisherGuid) and trying to process the metadata for it.

Message #

Loading metadata for publisher %2 (%1) and trying to process the metadata for it.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString

Event ID 111 — Finished loading metadata for publisher PublisherName (PublisherGuid), with EventMetaDataCount event metadatas processed.

Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Description

Finished loading metadata for publisher PublisherName (PublisherGuid), with EventMetaDataCount event metadatas processed.

Message #

Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
EventMetaDataCount UInt32

Event ID 112 — Failed to load metadata for publisher PublisherName (PublisherGuid).

Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Description

Failed to load metadata for publisher PublisherName (PublisherGuid). The reason code is ErrorCode.

Message #

Failed to load metadata for publisher %2 (%1). The reason code is %3.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
ErrorCode UInt32

Event ID 200 — Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.

Message #

Channel %1 (%2) was enabled (%3) programmatically.

Fields #

NameDescription
ChannelName UnicodeString
ChannelType UInt8
Enabled Boolean

Event ID 201 — A push subscription was created for ChannelName.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

A push subscription was created for ChannelName.

Message #

A push subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 202 — A pull subscription was created for ChannelName.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

A pull subscription was created for ChannelName.

Message #

A pull subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 203 — OpenEventLog legacy API was used to open ModuleName.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

OpenEventLog legacy API was used to open ModuleName.

Message #

OpenEventLog legacy API was used to open %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Event ID 204 — RegisterEventSource legacy API was used to register ModuleName.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Level
Verbose
Task
ServiceUsageAudit

Description

RegisterEventSource legacy API was used to register ModuleName.

Message #

RegisterEventSource legacy API was used to register %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "204",
    "version": "0",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.389555800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 205 — ReportEvent legacy API was used to write an event to ModuleName.

Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Level
Verbose
Task
ServiceUsageAudit

Description

ReportEvent legacy API was used to write an event to ModuleName.

Message #

ReportEvent legacy API was used to write an event to %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "205",
    "version": "1",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.390335800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 517 — The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102).

Provider
Microsoft-Windows-Eventlog
Channel
Security

Description

Legacy security-log clear event from Windows 2000/XP/2003. Superseded by EventID 1102 in Vista+.

Detection Patterns #

Event ID 1100 — The event logging service has shut down.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Informational
Collection Priority
Recommended (JSCU-NL)
Task
Serviceshutdown

Description

The event logging service has shut down.

Message #

The event logging service has shut down.

Fields #

NameDescription
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1100,
    "version": 0,
    "level": 4,
    "task": 103,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2023-11-05T22:31:36.994928+00:00",
    "event_record_id": 3371,
    "correlation": {},
    "execution": {
      "process_id": 1816,
      "thread_id": 1352
    },
    "channel": "Security",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "ServiceShutdown": {}
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Splunk # view in reference

  • Windows Event Logging Service Has Shutdown source: The following analytic detects the shutdown of the Windows Event Log service by leveraging Windows Event ID 1100. This event is logged every time the service stops, including during normal system shutdowns. Monitoring this activity is crucial as it can indicate attempts to cover tracks or disable logging. If confirmed malicious, an attacker could hide their activities, making it difficult to trace their actions and investigate further incidents. Analysts should verify if the shutdown was planned and review other alerts and data sources for additional suspicious behavior.

References #

Event ID 1101 — Audit events have been dropped by the transport.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

Audit events have been dropped by the transport. AuditEventsDropped.Reason.

Message #

Audit events have been dropped by the transport.  %1

Fields #

NameDescription
AuditEventsDropped.Reason UInt8
Reason UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1101,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-06T19:18:41.161306+00:00",
    "event_record_id": 13453892,
    "correlation": {},
    "execution": {
      "process_id": 1788,
      "thread_id": 2828
    },
    "channel": "Security",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AuditEventsDropped": {
      "Reason": 0
    }
  },
  "message": ""
}

References #

Event ID 1102 — The audit log was cleared.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Informational
Collection Priority
Recommended (ASD, others)
Task
Logclear

Description

The audit log was cleared.

Message #

The audit log was cleared.
Subject:
	Security ID: %1
	Account Name: %2
	Domain Name: %3
	Logon ID: %4

Fields #

NameDescription
LogFileCleared.SubjectUserSid[Subject] Security ID.
LogFileCleared.SubjectUserName[Subject] Account Name.
LogFileCleared.SubjectDomainName[Subject] Domain Name.
LogFileCleared.SubjectLogonId[Subject] Logon ID.
LogFileCleared.ClientProcessId
LogFileCleared.ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1102,
    "version": 1,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2023-10-25T22:53:10.300656+00:00",
    "event_record_id": 2625,
    "correlation": {},
    "execution": {
      "process_id": 1796,
      "thread_id": 2028
    },
    "channel": "Security",
    "computer": "WinDevEval",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserSid": "S-1-5-21-2533829718-189860685-2477588761-500",
      "SubjectUserName": "Administrator",
      "SubjectDomainName": "WINDEVEVAL",
      "SubjectLogonId": "0x42eea",
      "ClientProcessId": 4544,
      "ClientProcessStartKey": 2533274790396090
    }
  },
  "message": ""
}

Detection Patterns #

Defense Evasion: Clear Windows Event Logs

2 rules

Elastic

Elastic, Anabella Cristaldi

Splunk

Rico Valdez, Michael Haag, Splunk

Defense Evasion: Clear Windows Event Logs

2 rules

Elastic

Elastic, Anabella Cristaldi

Splunk

Rico Valdez, Michael Haag, Splunk

Detection Rules #

View all rules referencing this event →

Kusto Query Language # view in reference

  • Security Event log cleared source medium: 'Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.'
  • NRT Security Event log cleared source medium: 'Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.'

References #

Event ID 1103 — The security log is now PercentFull percent full.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Eventprocessing

Description

The security log is now PercentFull percent full.

Message #

The security log is now %1 percent full.

Fields #

NameDescription
PercentFull UInt32

Event ID 1104 — The security log is now full.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Collection Priority
Recommended (Palantir)
Task
Eventprocessing

Description

The security log is now full.

Message #

The security log is now full.

References #

Event ID 1105 — Event log automatic backup.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Logautomaticbackup

Description

Event log automatic backup.

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Log UnicodeString
File UnicodeString
Channel UnicodeString
BackupPath UnicodeString

References #

Event ID 1106 — Events have been dropped by the event logging service.

Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Eventprocessing

Description

Events have been dropped by the event logging service. The reason code is Reason.

Message #

Events have been dropped by the event logging service. The reason code is %1.

Fields #

NameDescription
Reason HexInt32

Event ID 1107 — The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1107,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2016-08-18T16:53:04.313375Z",
    "event_record_id": 5538,
    "correlation": {},
    "execution": {
      "process_id": 716,
      "thread_id": 1128
    },
    "channel": "Security",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventPublisherMetaDataFailure": {
      "#attributes": {
        "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
        "xmlns": "http://manifests.microsoft.com/win/2004/08/windows/eventlog"
      },
      "Error": {
        "#attributes": {
          "Code": 15002
        }
      },
      "EventID": 0,
      "PublisherName": null,
      "PublisherGuid": "54849625-5478-4994-A5BA-3E3B0328C30D",
      "ProcessID": 0
    }
  }
}

References #

Event ID 1108 — The event logging service encountered an error while processing an incoming event published from EventProcessingFailure.PublisherID.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event published from EventProcessingFailure.PublisherID.

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
EventProcessingFailure.ErrorCode UInt32
EventProcessingFailure.EventID UInt16
EventProcessingFailure.PublisherID
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1108,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-12T03:08:47.632904+00:00",
    "event_record_id": 2761579,
    "correlation": {},
    "execution": {
      "process_id": 1916,
      "thread_id": 2348
    },
    "channel": "Security",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventProcessingFailure": {
      "ErrorCode": 15003,
      "EventID": 4688,
      "PublisherID": "Microsoft-Windows-Security-Auditing"
    }
  },
  "message": ""
}

References #

Event ID 6000 — The Channel log file is full.

Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The Channel log file is full.

Message #

The %1 log file is full.

Fields #

NameDescription
Channel UnicodeString