Microsoft-Windows-Security-Netlogon
31 events across 2 channels
Event ID 4004 — Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Description
Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 4005 — Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Description
Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 4006 — Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Description
Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 4030 — The DC DCName processed a network NTLM authentication involving an account from this domain.
Description
The DC DCName processed a network NTLM authentication involving an account from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ForwarderType UnicodeString | — |
ForwarderName UnicodeString | — |
ForwarderDomain UnicodeString | — |
ForwarderIP UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4030 —
Description
The DC processed a network NTLM authentication involving an account from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ForwarderType UnicodeString | — |
ForwarderName UnicodeString | — |
ForwarderDomain UnicodeString | — |
ForwarderIP UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4031 — The DC DCName processed a network NTLM authentication involving an account from this domain.
Description
The DC DCName processed a network NTLM authentication involving an account from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ForwarderType UnicodeString | — |
ForwarderName UnicodeString | — |
ForwarderDomain UnicodeString | — |
ForwarderIP UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4031 —
Description
The DC processed a network NTLM authentication involving an account from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ForwarderType UnicodeString | — |
ForwarderName UnicodeString | — |
ForwarderDomain UnicodeString | — |
ForwarderIP UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4032 — The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Description
The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ServerIP UnicodeString | — |
ServerOS UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4032 —
Description
The DC processed a forwarded NTLM authentication request originating from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ServerIP UnicodeString | — |
ServerOS UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4033 — The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Description
The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ServerIP UnicodeString | — |
ServerOS UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 4033 —
Description
The DC processed a forwarded NTLM authentication request originating from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | — |
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
AccountMachine UnicodeString | — |
ServerName UnicodeString | — |
ServerDomain UnicodeString | — |
ServerIP UnicodeString | — |
ServerOS UnicodeString | — |
NtlmVersion UnicodeString | — |
ServiceBinding UnicodeString | — |
TargetMachine UnicodeString | — |
TargetDomain UnicodeString | — |
MicStatus UnicodeString | — |
AvFlags HexInt32 | — |
AvFlagsStr UnicodeString | — |
Status HexInt32 | — NTSTATUS reference |
StatusMsg UInt32 | — |
Event ID 8004 — Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Description
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 8005 — Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Description
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 8006 — Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Description
Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
Message #
Fields #
| Name | Description |
|---|---|
Secure_Channel_name UnicodeString | — |
User_name UnicodeString | — |
Domain_name UnicodeString | — |
Workstation_name UnicodeString | — |
Secure_Channel_type UInt32 | — |
SChannelName UnicodeString | — |
UserName UnicodeString | — |
DomainName UnicodeString | — |
WorkstationName UnicodeString | — |
SChannelType UInt32 | — |
Event ID 9000 — Netlogon failed to retrieve the password for account AccountName in domain AccountDomain.
Description
Netlogon failed to retrieve the password for account AccountName in domain AccountDomain. Status.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | — |
AccountDomain UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"guid": "E5BA83F6-07D0-46B1-8BC7-7E669A1D31DC",
"event_source_name": "",
"event_id": 9000,
"version": 0,
"level": 2,
"task": 3,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:17:37.552321+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 7024
},
"channel": "Microsoft-Windows-Security-Netlogon/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"AccountName": ".\\domainadmin",
"AccountDomain": "NULL",
"Status": 3221225524
},
"message": ""
}
Event ID 9001 — The account Account cannot be used as managed service account on the local machine because not all the supported encryption types of the account are sup...
Event ID 9002 — Netlogon failed to add Account as a managed service account to this local machine.
Description
Netlogon failed to add Account as a managed service account to this local machine. Status.
Message #
Fields #
| Name | Description |
|---|---|
Account UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 9003 — Netlogon failed to remove the managed service account Account from this local machine.
Description
Netlogon failed to remove the managed service account Account from this local machine. Status.
Message #
Fields #
| Name | Description |
|---|---|
Account UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 9004 — A total of RequestsRejected DC locator queries were rejected since the last reported event because they would have exceeded the configured maximum on concurrent ...
Event ID 9005 — Secure channel setup has failed with Kerberos: Status.
Description
Secure channel setup has failed with Kerberos: Status. Falling back to Netlogon.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 9006 — Secure channel setup has failed : Status.
Description
Secure channel setup has failed : Status. Protocol used: Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Protocol UnicodeString | — Known values
|
Event ID 9007 — Netlogon is currently configured to allow mailslot messages to be used when locating domain controllers.
Description
Netlogon is currently configured to allow mailslot messages to be used when locating domain controllers. This mode is unsecure and will be deprecated and removed in a future release.
Message #
Event ID 9008 — Netlogon is currently configured to listen for mailslot messages sent by clients during a domain controller location operation.
Message #
Event ID 9009 — Netlogon was unable to find the domain name 'DomainName' using any of the known domain name mapping sources.
Event ID 9010 — Netlogon discovered a DC using the Netbios protocol.
Event ID 9011 — Netlogon successfully downloaded the latest administrator-configured domain name mappings.
Description
Netlogon successfully downloaded the latest administrator-configured domain name mappings. Run 'nltest.exe /list_dclocmappings' to view the data.
Message #
Event ID 9012 — Netlogon failed to download the latest administrator-configured domain name mappings.
Description
Netlogon failed to download the latest administrator-configured domain name mappings.
Message #
Event ID 9013 — Netlogon successfully downloaded the latest trusted-domain-based domain name mappings.
Description
Netlogon successfully downloaded the latest trusted-domain-based domain name mappings. Run 'nltest.exe /list_dclocmappings' to view the data.
Message #
Event ID 9014 — Netlogon failed to download the latest trusted-domain-based domain name mappings.
Description
Netlogon failed to download the latest trusted-domain-based domain name mappings.
Message #
Event ID 9015 — Netlogon denied an RPC call.
Description
Netlogon denied an RPC call. The policy is in enforce mode.
Message #
Fields #
| Name | Description |
|---|---|
Method_name | [Client Information] Method name. |
Method_opnum | [Client Information] Method opnum. |
Client_address | [Client Information] Client address. |
Client_identity | [Client Information] Client identity. |
MethodName AnsiString | — |
MethodOpnum UInt32 | — |
ClientAddress UnicodeString | — |
ClientSid SID | — |
Event ID 9016 — Netlogon allowed an RPC call that normally would have been denied.
Description
Netlogon allowed an RPC call that normally would have been denied. The policy is in audit mode.
Message #
Fields #
| Name | Description |
|---|---|
Method_name | [Client Information] Method name. |
Method_opnum | [Client Information] Method opnum. |
Client_address | [Client Information] Client address. |
Client_identity | [Client Information] Client identity. |
MethodName AnsiString | — |
MethodOpnum UInt32 | — |
ClientAddress UnicodeString | — |
ClientSid SID | — |