Microsoft-Windows-IIS-W3SVC
284 events across 1 channel
Event ID 1001 —
Event ID 1002 —
Event ID 1003 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1004 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1005 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1006 —
Event ID 1007 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-IIS-W3SVC
guid: '{05448E22-93DE-4A7A-BBA5-92E27486A8BE}'
event_source_name: W3SVC
event_id: 1007
version: 0
level: 2
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-04T14:08:17.969392+00:00'
event_record_id: 1849
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: System
computer: WIN-TKC15D7KHUR
security:
user_id: ''
event_data:
UrlPrefix: http://*:80/
SiteID: '2'
Binary: B7000780
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1008 —
Event ID 1009 —
Event ID 1010 —
Event ID 1011 —
Event ID 1012 —
Event ID 1013 —
Event ID 1014 —
Event ID 1015 —
Event ID 1016 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1017 —
Event ID 1018 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1019 —
Event ID 1020 —
Fields
| Name | Description |
|---|---|
HttpSysControlChannelProperty | — |
__binLength | — |
binary | — |
Event ID 1021 —
Event ID 1022 —
Event ID 1023 —
Event ID 1024 —
Event ID 1025 —
Event ID 1026 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1027 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1028 —
Event ID 1029 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1030 —
Event ID 1031 —
Event ID 1032 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1033 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1034 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1035 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1036 —
Event ID 1037 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1038 —
Event ID 1039 —
Event ID 1040 —
Event ID 1041 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Property | — |
Value | — |
RangeLow | — |
RangeHigh | — |
DefaultValue | — |
Event ID 1042 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
CmdValue | — |
Event ID 1043 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1044 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1045 —
Event ID 1046 —
Event ID 1047 —
Event ID 1048 —
Event ID 1049 —
Event ID 1050 —
Event ID 1051 —
Event ID 1052 —
Event ID 1053 —
Event ID 1054 —
Event ID 1055 —
Event ID 1056 —
Event ID 1057 —
Event ID 1058 —
Event ID 1059 —
Event ID 1060 —
Event ID 1061 —
Event ID 1062 —
Fields
| Name | Description |
|---|---|
LogEnabled | — |
LogFileDirectory | — |
LogPeriod | — |
LogTruncateSize | — |
__binLength | — |
binary | — |
Event ID 1063 —
Event ID 1064 —
Event ID 1065 —
Event ID 1066 —
Event ID 1067 —
Event ID 1068 —
Event ID 1069 —
Event ID 1070 —
Event ID 1071 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1072 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1073 —
Event ID 1074 —
Event ID 1075 —
Event ID 1076 —
Event ID 1077 —
Event ID 1078 —
Event ID 1079 —
Event ID 1080 —
Event ID 1081 —
Event ID 1082 —
Event ID 1083 —
Event ID 1084 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1085 —
Event ID 1086 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1087 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1088 —
Event ID 1089 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 1090 —
Event ID 1091 —
Event ID 1092 —
Event ID 1093 —
Event ID 1094 —
Event ID 1095 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1096 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1097 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1098 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1099 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1100 —
Event ID 1101 —
Event ID 1102 —
Event ID 1103 —
Event ID 1104 —
Event ID 1105 —
Event ID 1106 —
Event ID 1107 —
Event ID 1108 —
Event ID 1109 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1110 —
Event ID 1111 —
Event ID 1112 —
Event ID 1113 —
Event ID 1114 —
Event ID 1115 —
Event ID 1116 —
Event ID 1117 —
Event ID 1118 —
Event ID 1119 —
Event ID 1120 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1121 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1122 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1123 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1124 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1125 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1126 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1127 —
Event ID 1128 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1129 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1130 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1131 —
Fields
| Name | Description |
|---|---|
UrlPrefix | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1132 —
Event ID 1133 —
Event ID 1134 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1135 —
Fields
| Name | Description |
|---|---|
LogEnabled | — |
LogFileDirectory | — |
LogPeriod | — |
LogTruncateSize | — |
LogExtFileFlags | — |
LocalTimeRollover | — |
__binLength | — |
binary | — |
Event ID 1168 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 1172 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 1173 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1174 —
Fields
| Name | Description |
|---|---|
SiteID | — |
BindingString | — |
__binLength | — |
binary | — |
Event ID 1175 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1176 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 1177 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |