Microsoft-Windows-Winlogon

150 events across 4 channels

Event IDTitleChannel
1Authentication started.Operational
2Authentication stopped.Operational
3Diagnostic
4Diagnostic
5Diagnostic
6Diagnostic
7Diagnostic
8Diagnostic
9Diagnostic
10Diagnostic
11Diagnostic
12Diagnostic
13Diagnostic
14Diagnostic
51Diagnostic
52Diagnostic
61Diagnostic
62Diagnostic
64Diagnostic
65Diagnostic
67Diagnostic
68Diagnostic
70Diagnostic
71Diagnostic
72Diagnostic
73Diagnostic
101Diagnostic
102Diagnostic
103Diagnostic
104Diagnostic
105Diagnostic
106Diagnostic
107Diagnostic
108Diagnostic
201Diagnostic
202Diagnostic
203Diagnostic
204Diagnostic
205Diagnostic
206Diagnostic
207Diagnostic
208Diagnostic
301Diagnostic
401Diagnostic
402Diagnostic
403Diagnostic
404Diagnostic
501Diagnostic
502Diagnostic
503Diagnostic
504Diagnostic
505Operational
801Diagnostic
802Diagnostic
803Diagnostic
804Diagnostic
805Diagnostic
806Diagnostic
807Diagnostic
808Diagnostic
809Diagnostic
810Diagnostic
811The winlogon notification subscriber <SubscriberName> began handling the …Operational
812The winlogon notification subscriber <SubscriberName> finished handling the …Operational
1001Logon hours expiration warning.Operational
1002Application
1002Operational
1101The computer will be locked because the user has exceeded the maximum number of …Operational
1102The computer will be rebooted because the user has exceeded the maximum number …Operational
1103The user is approaching the threshold for maximum number of failed logon …Operational
1104Encryption Provider initialization failed.Operational
4002Operational
4003Operational
4004Application
4004Operational
4005Operational
4006Operational
4007Operational
4008Operational
4101Windows license validated.Application
4101Operational
4102Operational
4103Operational
4104Application
4104Operational
4105Application
4105Operational
5001Diagnostic
5002Diagnostic
5003Diagnostic
5005Diagnostic
5007Diagnostic
6000The winlogon notification subscriber <SessionEnv> was unavailable to handle a …Application
6000Operational
6001Diagnostic
6002Operational
6003The winlogon notification subscriber <SessionEnv> was unavailable to handle a …Application
6003Operational
6004The winlogon notification subscriber <TrustedInstaller> failed a critical …Application
6004Operational
6005The winlogon notification subscriber <GPClient> is taking long time to handle …Application
6005Operational
6006The winlogon notification subscriber <GPClient> took 119 second(s) to handle the …Application
6006Operational
6101Diagnostic
6102Diagnostic
6103Diagnostic
6104Diagnostic
6105Diagnostic
6106Diagnostic
6107Diagnostic
6108Diagnostic
6109Diagnostic
6110Diagnostic
6111Diagnostic
6112Diagnostic
6113Diagnostic
6114Diagnostic
6115Diagnostic
6116Diagnostic
6117Diagnostic
6118Diagnostic
6119Diagnostic
6120Diagnostic
6121Diagnostic
6122Diagnostic
6123Diagnostic
6124Diagnostic
7001User Logon Notification for Customer Experience Improvement ProgramSystem
7002User Logoff Notification for Customer Experience Improvement ProgramSystem
1073742826The shell stopped unexpectedly and %1 was restarted.Operational
1073745826The logon hours restriction policy is applied to the logged on user.Operational
1073745925Windows license validated.Operational
1073745928Accessing Windows in Notification period.Operational
2147487654The Windows logon process has failed to spawn a user application.Operational
2147487655The Windows logon process has failed to disconnect the user session.Operational
2147487656The Windows logon process has failed to connect the user session.Operational
2147487753Windows is in Notification period.Operational
2147489648The winlogon notification subscriber <.Operational
2147489649The winlogon notification subscriber <.Operational
2147489650The winlogon notification subscriber registration database cannot be loaded.Operational
2147489651The winlogon notification subscriber <.Operational
2147489652The winlogon notification subscriber <.Operational
2147489653The winlogon notification subscriber <.Operational
2147489654The winlogon notification subscriber <.Operational
3221229475The Windows logon process has failed to switch the desktop.Operational
3221229476The Windows logon process has failed to terminate the currently logged on user's …Operational
3221229477The Windows logon process has unexpectedly terminated.Operational
3221229574Windows license is invalid.Operational
3221229575Windows license activation failed.Operational

Event ID 1 — Authentication started.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
AuthenticateUser
Opcode
Start

Description

Authentication started.

Message #

Authentication started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": 4611721202799542272,
    "time_created": "2023-11-05T22:32:19.983931+00:00",
    "event_record_id": 353,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1032
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 2 — Authentication stopped.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
AuthenticateUser
Opcode
Stop

Description

Authentication stopped. Result Win32Status.

Message #

Authentication stopped. Result %1

Fields #

NameDescription
Win32Status UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": 4611721202799542272,
    "time_created": "2023-11-05T22:32:20.244576+00:00",
    "event_record_id": 354,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1032
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Win32Status": 0
  },
  "message": ""
}

References #

Event ID 3 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UpdatePerUserSystemParameters
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 4 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UpdatePerUserSystemParameters
Opcode
Stop

Fields #

NameDescription
Flags UInt32

Event ID 5 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CheckWindowsLicenseStatus
Opcode
Start

Event ID 6 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CheckWindowsLicenseStatus
Opcode
Stop

Event ID 7 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RestoringNetConnections
Opcode
Start

Event ID 8 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RestoringNetConnections
Opcode
Stop

Event ID 9 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ExecuteShellCommandList
Opcode
Start

Fields #

NameDescription
CommandList UnicodeString

Event ID 10 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ExecuteShellCommandList
Opcode
Stop

Event ID 11 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPre
Opcode
Start

Event ID 12 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPre
Opcode
Stop

Event ID 13 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPost
Opcode
Start

Event ID 14 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPost
Opcode
Stop

Event ID 51 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogoff
Opcode
Start

Event ID 52 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogoff
Opcode
Stop

Event ID 61 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpCreateSessionProcess
Opcode
Start

Event ID 62 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpCreateSessionProcess
Opcode
Stop

Event ID 64 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpTerminateSessionProcess
Opcode
Start

Event ID 65 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpTerminateSessionProcess
Opcode
Stop

Event ID 67 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogon
Opcode
Start

Event ID 68 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogon
Opcode
Stop

Event ID 70 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnEarlyCreateSession
Opcode
Start

Event ID 71 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnEarlyCreateSession
Opcode
Stop

Event ID 72 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogoff
Opcode
Start

Event ID 73 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogoff
Opcode
Stop

Event ID 101 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CreatePrimaryTerminal
Opcode
Start

Event ID 102 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CreatePrimaryTerminal
Opcode
Stop

Event ID 103 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
StartLogonUI
Opcode
Start

Event ID 104 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
StartLogonUI
Opcode
Stop

Event ID 105 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RunStateMachine
Opcode
Start

Event ID 106 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RunStateMachine
Opcode
Stop

Event ID 107 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WaitForLSM
Opcode
Start

Event ID 108 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WaitForLSM
Opcode
Stop

Event ID 201 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DisplayWelcomeScreen
Opcode
Start

Event ID 202 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DisplayWelcomeScreen
Opcode
Stop

Event ID 203 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RequestCredentials
Opcode
Start

Event ID 204 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RequestCredentials
Opcode
Stop

Event ID 205 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnCreateSession
Opcode
Start

Event ID 206 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnCreateSession
Opcode
Stop

Event ID 207 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnTerminateSession
Opcode
Start

Event ID 208 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnTerminateSession
Opcode
Stop

Event ID 301 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ReceivedLogoffRequest

Fields #

NameDescription
Flags UInt32

Event ID 401 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 402 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 403 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
InitiateShutdown
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 404 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
InitiateShutdown
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 501 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerStartup
Opcode
Start

Event ID 502 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerStartup
Opcode
Stop

Event ID 503 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerShutdown
Opcode
Start

Event ID 504 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerShutdown
Opcode
Stop

Event ID 505 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
WluiServerStartup

Event ID 801 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyExecute
Opcode
Start

Fields #

NameDescription
Event UInt32

Event ID 802 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyExecute
Opcode
Stop

Fields #

NameDescription
Event UInt32

Event ID 803 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyServices
Opcode
Start

Fields #

NameDescription
EventCode UInt32
SessionId UInt32

Event ID 804 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyServices
Opcode
Stop

Fields #

NameDescription
EventCode UInt32
SessionId UInt32

Event ID 805 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
Start

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Event ID 806 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
Stop

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Event ID 807 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
NotificationPended

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString
Message UnicodeString

Event ID 808 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
NotificationFailed

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString
Message UnicodeString

Event ID 809 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ConnectToSubscriber
Opcode
Start

Fields #

NameDescription
SubscriberName UnicodeString

Event ID 810 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ConnectToSubscriber
Opcode
Stop

Fields #

NameDescription
SubscriberName UnicodeString

Event ID 811 — The winlogon notification subscriber <SubscriberName> began handling the notification event (Event).

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
CallSubscriber
Opcode
Start

Description

The winlogon notification subscriber <SubscriberName> began handling the notification event (Event).

Message #

The winlogon notification subscriber <%2> began handling the notification event (%1).

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 811,
    "version": 0,
    "level": 4,
    "task": 811,
    "opcode": 1,
    "keywords": 4611686018427453440,
    "time_created": "2023-11-05T22:32:22.759378+00:00",
    "event_record_id": 367,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1032
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Event": 12,
    "SubscriberName": "TermSrv"
  },
  "message": ""
}

References #

Event ID 812 — The winlogon notification subscriber <SubscriberName> finished handling the notification event (Event).

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
CallSubscriber
Opcode
Stop

Description

The winlogon notification subscriber <SubscriberName> finished handling the notification event (Event).

Message #

The winlogon notification subscriber <%2> finished handling the notification event (%1).

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 812,
    "version": 0,
    "level": 4,
    "task": 811,
    "opcode": 2,
    "keywords": 4611686018427453440,
    "time_created": "2023-11-05T22:32:22.759585+00:00",
    "event_record_id": 368,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1032
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "Event": 12,
    "SubscriberName": "TermSrv"
  },
  "message": ""
}

References #

Event ID 1001 — Logon hours expiration warning.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
LogonHours

Description

Logon hours expiration warning.

Message #

Logon hours expiration warning.

Fields #

NameDescription
ActionId UInt32
TimeLeft UInt32

Event ID 1002 —

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T23:53:34.619082+00:00",
    "event_record_id": 1811,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "explorer.exe",
    "Binary": ""
  },
  "message": ""
}

References #

Event ID 1002 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 1101 — The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer. A recovery key is required to unlock the device.

Message #

The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer. A recovery key is required to unlock the device.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1102 — The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

Message #

The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1103 — The user is approaching the threshold for maximum number of failed logon attempts.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The user is approaching the threshold for maximum number of failed logon attempts. Once the maximum limit is reached the computer will be locked or rebooted.

Message #

The user is approaching the threshold for maximum number of failed logon attempts. Once the maximum limit is reached the computer will be locked or rebooted.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1104 — Encryption Provider initialization failed.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

Encryption Provider initialization failed. Error Win32Status.

Message #

Encryption Provider initialization failed. Error %1

Fields #

NameDescription
Win32Status UInt32

Event ID 4002 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4003 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4004 —

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-21T21:00:34.000000Z",
    "event_record_id": 1596,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4004 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4005 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4006 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4007 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4008 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4101 — Windows license validated.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4101,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T17:51:18+00:00",
    "event_record_id": 232,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "0x00000000",
      "0x00000001"
    ]
  },
  "message": "Windows license validated."
}

References #

Event ID 4101 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4102 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4103 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4104 —

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4104,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2014-11-21T23:44:00.000000Z",
    "event_record_id": 812,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4104 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4105 —

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4105,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2014-11-21T23:43:09.000000Z",
    "event_record_id": 811,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4105 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 5001 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot
Opcode
Start

Fields #

NameDescription
SessionId UInt32

Event ID 5002 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot
Opcode
Stop

Event ID 5003 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot

Fields #

NameDescription
SessionId UInt32

Event ID 5005 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserShellLaunch

Event ID 5007 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
SystemBoot
Opcode
Stop

Fields #

NameDescription
SessionId UInt32
ReadyBootTrainingCountSinceLastServicing UInt32
SyncPrefetchErrorCode UInt32
SyncPrefetchDurationMs UInt32

Event ID 6000 — The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:22.560419+00:00",
    "event_record_id": 1545,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "SessionEnv"
    ],
    "Binary": "2QYAAA=="
  },
  "message": "The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event."
}

References #

Event ID 6000 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6001 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownDiagnostics
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 6002 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6003 — The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:20.495672+00:00",
    "event_record_id": 1542,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "SessionEnv"
    ],
    "Binary": "2QYAAA=="
  },
  "message": "The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event."
}

References #

Event ID 6003 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6004 — The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6004,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T17:32:12+00:00",
    "event_record_id": 181,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "TrustedInstaller"
    ],
    "Binary": "aQYAAA=="
  },
  "message": "The winlogon notification subscriber <TrustedInstaller> failed a critical notification event."
}

References #

Event ID 6004 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6005 — The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession).

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6005,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:16:03.529427+00:00",
    "event_record_id": 116,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "GPClient",
      "CreateSession"
    ],
    "Binary": "SNCCJg=="
  },
  "message": "The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession)."
}

References #

Event ID 6005 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6006 — The winlogon notification subscriber <GPClient> took 119 second(s) to handle the notification event (CreateSession).

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6006,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:17:03.466560+00:00",
    "event_record_id": 120,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "GPClient",
      "119",
      "CreateSession"
    ],
    "Binary": "AAAAAA=="
  },
  "message": "The winlogon notification subscriber <GPClient> took 119 second(s) to handle the notification event (CreateSession)."
}

References #

Event ID 6006 —

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6101 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffRequestToUserFeedback
Opcode
Start

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6102 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffRequestToUserFeedback
Opcode
Stop

Fields #

NameDescription
Flags UInt32

Event ID 6103 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffAppsTerminationToSessionEnd
Opcode
Start

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6104 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffAppsTerminationToSessionEnd
Opcode
Stop

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6105 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Start

Event ID 6106 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Stop

Event ID 6107 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6108 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Start

Event ID 6109 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6110 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6111 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6112 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6113 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Start

Event ID 6114 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Stop

Event ID 6115 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Stop

Event ID 6116 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logoff

Fields #

NameDescription
Duration UInt32
ResolverData UInt32

Event ID 6117 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DelayLockDisplayLockScreen

Event ID 6118 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
KillingScreenSaverToLockWorkStation

Event ID 6119 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AutomaticRestartSignOn

Event ID 6120 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
HotKeyLockDesktopInvoked

Event ID 6121 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
PINResetLogon

Event ID 6122 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
PINResetUnlock

Event ID 6123 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AssignedAccessLogon

Event ID 6124 —

Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AssignedAccessUnlock

Event ID 7001 — User Logon Notification for Customer Experience Improvement Program

#
Provider
Microsoft-Windows-Winlogon
Channel
System
Level
Informational
Task
WinSqmUserLogin

Description

User Logon Notification for Customer Experience Improvement Program.

Message #

User Logon Notification for Customer Experience Improvement Program

Fields #

NameDescription
TSId UInt32
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 7001,
    "version": 0,
    "level": 4,
    "task": 1101,
    "opcode": 0,
    "keywords": 2305878193585782784,
    "time_created": "2023-11-05T22:32:20.322384+00:00",
    "event_record_id": 1941,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1032
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TSId": 1,
    "UserSid": "S-1-5-21-1992711665-1655669231-58201500-1000"
  },
  "message": ""
}

References #

Event ID 7002 — User Logoff Notification for Customer Experience Improvement Program

#
Provider
Microsoft-Windows-Winlogon
Channel
System
Level
Informational
Task
WinSqmUserLogoff

Description

User Logoff Notification for Customer Experience Improvement Program.

Message #

User Logoff Notification for Customer Experience Improvement Program

Fields #

NameDescription
TSId UInt32
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "DBE9B383-7CF3-4331-91CC-A3CB16A3B538",
    "event_source_name": "",
    "event_id": 7002,
    "version": 0,
    "level": 4,
    "task": 1102,
    "opcode": 0,
    "keywords": 2305878193585782784,
    "time_created": "2023-11-05T22:31:34.253350+00:00",
    "event_record_id": 1850,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 1328
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TSId": 1,
    "UserSid": "S-1-5-21-1992711665-1655669231-58201500-1000"
  },
  "message": ""
}

References #

Event ID 1073742826 — The shell stopped unexpectedly and %1 was restarted.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Opcode
Info

Description

The shell stopped unexpectedly and was restarted.

Message #

The shell stopped unexpectedly and %1 was restarted.

Event ID 1073745826 — The logon hours restriction policy is applied to the logged on user.

Provider
Microsoft-Windows-Winlogon
Channel
Operational
Opcode
Info

Description

The logon hours restriction policy is applied to the logged on user. The user's session has been locked, disconnected or logged off depending on the policy setting. User Name: Domain Name.

Message #

The logon hours restriction policy is applied to the logged on user. The user's session has been locked, disconnected or logged off depending on the policy setting. User Name: %1 Domain Name: %2

Event ID 1073745925 — Windows license validated.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license validated.

Message #

Windows license validated.

Event ID 1073745928 — Accessing Windows in Notification period.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Accessing Windows in Notification period.

Message #

Accessing Windows in Notification period.

Event ID 2147487654 — The Windows logon process has failed to spawn a user application.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to spawn a user application. Application name: . Command line parameters: .

Message #

The Windows logon process has failed to spawn a user application. Application name: %1. Command line parameters: %2.

Event ID 2147487655 — The Windows logon process has failed to disconnect the user session.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to disconnect the user session.

Message #

The Windows logon process has failed to disconnect the user session.

Event ID 2147487656 — The Windows logon process has failed to connect the user session.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to connect the user session.

Message #

The Windows logon process has failed to connect the user session.

Event ID 2147487753 — Windows is in Notification period.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows is in Notification period.

Message #

Windows is in Notification period.

Event ID 2147489648 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> was unavailable to handle a notification event.

Message #

The winlogon notification subscriber <%1> was unavailable to handle a notification event.

Event ID 2147489649 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> failed a notification event.

Message #

The winlogon notification subscriber <%1> failed a notification event.

Event ID 2147489650 — The winlogon notification subscriber registration database cannot be loaded.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber registration database cannot be loaded. Reason: <>.

Message #

The winlogon notification subscriber registration database cannot be loaded. Reason: <%1>.

Event ID 2147489651 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> was unavailable to handle a critical notification event.

Message #

The winlogon notification subscriber <%1> was unavailable to handle a critical notification event.

Event ID 2147489652 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> failed a critical notification event.

Message #

The winlogon notification subscriber <%1> failed a critical notification event.

Event ID 2147489653 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> is taking long time to handle the notification event ().

Message #

The winlogon notification subscriber <%1> is taking long time to handle the notification event (%2).

Event ID 2147489654 — The winlogon notification subscriber <.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> took second(s) to handle the notification event ().

Message #

The winlogon notification subscriber <%1> took %2 second(s) to handle the notification event (%3).

Event ID 3221229475 — The Windows logon process has failed to switch the desktop.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to switch the desktop.

Message #

The Windows logon process has failed to switch the desktop.

Event ID 3221229476 — The Windows logon process has failed to terminate the currently logged on user's processes.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to terminate the currently logged on user's processes.

Message #

The Windows logon process has failed to terminate the currently logged on user's processes.

Event ID 3221229477 — The Windows logon process has unexpectedly terminated.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has unexpectedly terminated.

Message #

The Windows logon process has unexpectedly terminated.

Event ID 3221229574 — Windows license is invalid.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license is invalid. Error . Policy Value .

Message #

Windows license is invalid. Error %1. Policy Value %2.

Event ID 3221229575 — Windows license activation failed.

Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license activation failed. Error .

Message #

Windows license activation failed. Error %1.