# Windows General Log Recommendations

<table data-header-hidden><thead><tr><th></th><th width="269">Category </th><th>Name </th><th>ID </th><th>Level </th><th>Event Log </th><th>Event Source </th></tr></thead><tbody><tr><td>1 </td><td>Boot Events </td><td>Shutdown Initiate Failed </td><td>1074 </td><td>Warning </td><td>User32 </td><td>User32 </td></tr><tr><td>2 </td><td>Application Crashes </td><td>BSOD </td><td>1001 </td><td>Error </td><td>System </td><td>Microsoft-Windows-WER-SystemErrorReporting </td></tr><tr><td>3 </td><td>Boot Events </td><td>Windows Shutdown </td><td>13 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>4 </td><td>Boot Events </td><td>Windows Startup </td><td>12 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>5 </td><td>Clearing Event Logs </td><td>Event Log was Cleared </td><td>104 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Eventlog </td></tr><tr><td>6 </td><td>Group Policy Errors </td><td>Generic Internal Error </td><td>1126 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>7 </td><td>Group Policy Errors </td><td>Group Policy Application Failed due to Connectivity </td><td>1129 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>8 </td><td>Group Policy Errors </td><td>Internal Error </td><td>1125 </td><td>Error </td><td>System </td><td>Microsoft-Windows-GroupPolicy </td></tr><tr><td>9 </td><td>Kernel Driver Signing </td><td>Failed Kernel Driver Loading </td><td>219 </td><td>Warning </td><td>System </td><td>Microsoft-Windows-Kernel-PnP </td></tr><tr><td>10 </td><td>Software and Service Installation </td><td>New Kernel Filter Driver </td><td>6 </td><td>Information </td><td>System </td><td>Microsoft-Windows-FilterManager </td></tr><tr><td>11 </td><td>Software and Service Installation </td><td>New Windows Service </td><td>7045 </td><td>Information </td><td>System </td><td>Microsoft-Windows-FilterManager </td></tr><tr><td>12 </td><td>Software and Service Installation </td><td>Service Start Failure </td><td>7000 </td><td>Error </td><td>System </td><td>Service Control Manager </td></tr><tr><td>13 </td><td>Software and Service Installation </td><td>Windows Update Installed </td><td>19 </td><td>Information </td><td>System </td><td>Microsoft-Windows-WindowsUpdateClient </td></tr><tr><td>14 </td><td>System Integrity </td><td>System Time Changed </td><td>1 </td><td>Information </td><td>System </td><td>Microsoft-Windows-Kernel-General </td></tr><tr><td>15 </td><td>System or Service Failures </td><td>Windows Service Fails or Crashes </td><td>7022, 7023, 7024, 7026, 7031, 7032, 7034 </td><td>Error </td><td>System </td><td>Service Control Manager </td></tr><tr><td>16 </td><td>Software and Service Installation </td><td>Update Packages Installed </td><td>2 </td><td>Information </td><td>Setup </td><td>Microsoft-Windows-Servicing </td></tr><tr><td>17 </td><td>Windows Update Errors </td><td>Hotpatching Failed </td><td>1009 </td><td>Information </td><td>Setup </td><td>Microsoft-Windows-Servicing </td></tr><tr><td>18 </td><td>Account Usage </td><td>Account Lockouts </td><td>4740 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>19 </td><td>Account Usage </td><td>Account Login with Explicit Credentials </td><td>4648 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>20 </td><td>Account Usage </td><td>Account Name Changed </td><td>4781 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>21 </td><td>Account Usage </td><td>Account removed from Local Sec. Grp. </td><td>4733 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>22 </td><td>Account Usage </td><td>Credential Authentication </td><td>4776 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>23 </td><td>Account Usage </td><td>Credentials backed up </td><td>5376 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>24 </td><td>Account Usage </td><td>Credentials restored </td><td>5377 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>25 </td><td>Account Usage </td><td>Failed User Account Login </td><td>4625 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>26 </td><td>Account Usage </td><td>Logoff Event </td><td>4634 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>27 </td><td>Account Usage </td><td>Logon with Special Privs </td><td>4672 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>28 </td><td>Account Usage </td><td>New User Account Created </td><td>4720 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>29 </td><td>Account Usage </td><td>New User Account Enabled </td><td>4722 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>30 </td><td>Account Usage </td><td>Password Hash Accessed </td><td>4782 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>31 </td><td>Account Usage </td><td>Password Policy Checking API called </td><td>4793 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>32 </td><td>Account Usage </td><td>Security-enabled Group Created </td><td>4731 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>33 </td><td>Account Usage </td><td>Security-Enabled group Modification </td><td>4735 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>34 </td><td>Account Usage </td><td>SID History add attempted on Account </td><td>4766 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>35 </td><td>Account Usage </td><td>SID History added to Account </td><td>4765 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>36 </td><td>Account Usage </td><td>Successful User Account Login </td><td>4624 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>37 </td><td>Account Usage </td><td>User Account Deleted </td><td>4726 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>38 </td><td>Account Usage </td><td>User Account Disabled </td><td>4725 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>39 </td><td>Account Usage </td><td>User Account Unlocked </td><td>4767 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>40 </td><td>Account Usage </td><td>User Added to Privileged Group </td><td>4728, 4732, 4756 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>41 </td><td>Account Usage </td><td>User Right Assigned </td><td>4704 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>42 </td><td>Application Whitelisting </td><td>Process Created </td><td>4688 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>43 </td><td>Application Whitelisting </td><td>Process Terminated </td><td>4689 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>44 </td><td>Certificate Services </td><td>CA Services Request </td><td>4886 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>45 </td><td>Certificate Services </td><td>Certificate Manager Settings Changed </td><td>4890 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>46 </td><td>Certificate Services </td><td>Certificate Request Attributes Changed </td><td>4874 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>47 </td><td>Certificate Services </td><td>Certificate Request Extension Changed </td><td>4873 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>48 </td><td>Certificate Services </td><td>Certificate Revoked </td><td>4870 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>49 </td><td>Certificate Services </td><td>Certificate Services approved request </td><td>4887 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>50 </td><td>Certificate Services </td><td>Certificate Services Audit Filter Changed </td><td>4885 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>51 </td><td>Certificate Services </td><td>Certificate Services Configuration Changed </td><td>4891 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>52 </td><td>Certificate Services </td><td>Certificate Services denied request </td><td>4888 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>53 </td><td>Certificate Services </td><td>Certificate Services Loaded Template </td><td>4898 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>54 </td><td>Certificate Services </td><td>Certificate Services Permissions Changed </td><td>4882 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>55 </td><td>Certificate Services </td><td>Certificate Services Property Changed </td><td>4892 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>56 </td><td>Certificate Services </td><td>Certificate Services Started </td><td>4880 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>57 </td><td>Certificate Services </td><td>Certificate Services Stopped </td><td>4881 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>58 </td><td>Certificate Services </td><td>Certificate Services Template Security Updated </td><td>4900 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>59 </td><td>Certificate Services </td><td>Certificate Services Template Updated </td><td>4899 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>60 </td><td>Certificate Services </td><td>Entries Removed from Certificate Database </td><td>4896 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>61 </td><td>Clearing Event Logs </td><td>Event Log Service Shutdown </td><td>1100 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-EventLog </td></tr><tr><td>62 </td><td>Clearing Event Logs </td><td>Event Log was Cleared </td><td>1102 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Eventlog </td></tr><tr><td>63 </td><td>DNS/Directory Services </td><td>Directory service created </td><td>5137 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>64 </td><td>DNS/Directory Services </td><td>Directory service deleted </td><td>5141 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>65 </td><td>DNS/Directory Services </td><td>Directory service modified </td><td>5136 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>66 </td><td>DNS/Directory Services </td><td>Directory service moved </td><td>5139 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>67 </td><td>DNS/Directory Services </td><td>Directory service recovered </td><td>5138 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>68 </td><td>Kernel Driver Signing </td><td>Detected an invalid image hash of a file </td><td>5038 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>69 </td><td>Kernel Driver Signing </td><td>Detected an invalid page hash of an image file </td><td>6281 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>70 </td><td>Network Policy </td><td>Encrypted Data Recovery Policy Changed </td><td>4714 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>71 </td><td>Network Policy </td><td>Kerberos Policy Changed </td><td>4713 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>72 </td><td>Network Policy </td><td>Kerberos Service Ticket Req. Failed </td><td>4769 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>73 </td><td>Network Policy </td><td>Network Policy Server Denied Access </td><td>6273 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>74 </td><td>Network Policy </td><td>Network Policy Server Discarded Accounting Request </td><td>6275 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>75 </td><td>Network Policy </td><td>Network Policy Server Discarded Request </td><td>6274 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>76 </td><td>Network Policy </td><td>Network Policy Server Granted Access </td><td>6272 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>77 </td><td>Network Policy </td><td>Network Policy Server Granted Full Access </td><td>6278 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>78 </td><td>Network Policy </td><td>Network Policy Server Granted Probationary Access </td><td>6277 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>79 </td><td>Network Policy </td><td>Network Policy Server Locked Account </td><td>6279 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>80 </td><td>Network Policy </td><td>Network Policy Server Quarantined User </td><td>6276 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>81 </td><td>Network Policy </td><td>Network Policy Server Unlocked Account </td><td>6280 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>82 </td><td>Network Policy </td><td>Network share accessed </td><td>5140 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>83 </td><td>Network Policy </td><td>Network Share Checked </td><td>5145 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>84 </td><td>Network Policy </td><td>Network Share Created </td><td>5142 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>85 </td><td>Network Policy </td><td>Network Share Deleted </td><td>5144 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>86 </td><td>Network Policy </td><td>New Trust for Domain </td><td>4706 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>87 </td><td>Network Policy </td><td>Role Separation Enabled </td><td>4897 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>88 </td><td>Network Policy </td><td>System Audit Policy Changed </td><td>4719 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>89 </td><td>Network Policy </td><td>Trusted Domain Information Modified </td><td>4716 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>90 </td><td>Network Policy </td><td>TS Session Disconnect </td><td>4779 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>91 </td><td>Network Policy </td><td>TS Session Reconnect </td><td>4778 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>92 </td><td>Network Policy </td><td>Wireless 802.1X Auth </td><td>5632 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>93 </td><td>System Integrity </td><td>Registry Modification </td><td>4657 </td><td>Information </td><td>Security </td><td>Microsoft-Windows-Security-Auditing </td></tr><tr><td>94 </td><td>Network Policy </td><td>RADIUS User assigned IP </td><td>20250 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>95 </td><td>Network Policy </td><td>RADIUS User Authenticated </td><td>20274 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>96 </td><td>Network Policy </td><td>RADIUS User Disconnected </td><td>20275 </td><td>Success </td><td>RemoteAccess </td><td>Microsoft-Windows-MPRMSG </td></tr><tr><td>97 </td><td>PowerShell Activities </td><td>Get-MessageTrackingLog cmdlet </td><td>800 </td><td>Information </td><td>Powershell </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>98 </td><td>PowerShell Activities </td><td>Remote Connection </td><td>169 </td><td>Information </td><td>Powershell </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>99 </td><td>Mobile Device Activities </td><td>Disconnect from Wireless connection </td><td>8003 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>100 </td><td>Mobile Device Activities </td><td>Starting a Wireless connection </td><td>8000, 8011 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>101 </td><td>Mobile Device Activities </td><td>Successfully connected to a Wireless connection </td><td>8001 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>102 </td><td>Mobile Device Activities </td><td>Wireless Association Status </td><td>11000, 11001 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>103 </td><td>Mobile Device Activities </td><td>Wireless Association Status </td><td>11002 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>104 </td><td>Mobile Device Activities </td><td>Wireless Authentication Started and Failed </td><td>12011, 12012 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>105 </td><td>Mobile Device Activities </td><td>Wireless Authentication Started and Failed </td><td>12013 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>106 </td><td>Mobile Device Activities </td><td>Wireless Connection Failed </td><td>8002 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>107 </td><td>Mobile Device Activities </td><td>Wireless Security Started, Stopped, Successful, or Failed </td><td>11004, 11005 </td><td>Information </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>108 </td><td>Mobile Device Activities </td><td>Wireless Security Started, Stopped, Successful, or Failed </td><td>11010, 11006 </td><td>Error </td><td>Microsoft-Windows-WLAN-AutoConfig/Operational </td><td>Microsoft-Windows-WLAN-AutoConfig </td></tr><tr><td>109 </td><td>Windows Update Errors </td><td>Windows Update Failed </td><td>20, 24, 25, 31, 34, 35 </td><td>Error </td><td>Microsoft-Windows-WindowsUpdateClient/Operational </td><td>Microsoft-Windows-WindowsUpdateClient </td></tr><tr><td>110 </td><td>Windows Firewall </td><td>Firewall Failed to load Group Policy </td><td>2009 </td><td>Error </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>111 </td><td>Windows Firewall </td><td>Firewall Rule Add </td><td>2004 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>112 </td><td>Windows Firewall </td><td>Firewall Rule Change </td><td>2005 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>113 </td><td>Windows Firewall </td><td>Firewall Rules Deleted </td><td>2006, 2033 </td><td>Information </td><td>Microsoft-Windows-Windows Firewall With Advanced Security/Firewall </td><td>Microsoft-Windows-Windows Firewall With Advanced Security </td></tr><tr><td>114 </td><td>Windows Defender Activities </td><td>Action on Malware Failed </td><td>1008 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>115 </td><td>Windows Defender Activities </td><td>Detected Malware </td><td>1006, 1116 </td><td>Warning </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>116 </td><td>Windows Defender Activities </td><td>Failed to remove item from quarantine </td><td>1010 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>117 </td><td>Windows Defender Activities </td><td>Failed to update engine </td><td>2003 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>118 </td><td>Windows Defender Activities </td><td>Failed to update signatures </td><td>2001 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>119 </td><td>Windows Defender Activities </td><td>File Restored from Quarantine </td><td>1009 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>120 </td><td>Windows Defender Activities </td><td>Malware Removal Error </td><td>1118 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>121 </td><td>Windows Defender Activities </td><td>Malware Removal Fatal Error </td><td>1119 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>122 </td><td>Windows Defender Activities </td><td>Malware Removed </td><td>1007, 1117 </td><td>Information </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>123 </td><td>Windows Defender Activities </td><td>Real-Time Protection failed </td><td>3002 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>124 </td><td>Windows Defender Activities </td><td>Reverting to last known good set of signatures </td><td>2004 </td><td>Warning </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>125 </td><td>Windows Defender Activities </td><td>Scan Failed </td><td>1005 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>126 </td><td>Windows Defender Activities </td><td>Unexpected Error </td><td>5008 </td><td>Error </td><td>Microsoft-Windows-Windows Defender/Operational </td><td>Microsoft-Windows-Windows Defender </td></tr><tr><td>127 </td><td>External Media Detection </td><td>New Device Information </td><td>43 </td><td>Information </td><td>Microsoft-Windows-USB-USBHUB3-Analytic </td><td>Microsoft-Windows-USB-USBHUB3 </td></tr><tr><td>128 </td><td>Network Policy </td><td>Outbound TS Connect Attempt </td><td>1024 </td><td>Information </td><td>Microsoft-Windows-TerminalServices-RDPClient/Operational </td><td>Microsoft-Windows-TerminalServices-ClientActiveXCore </td></tr><tr><td>129 </td><td>Task Scheduler Activities </td><td>New Task Registered </td><td>106 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>130 </td><td>Task Scheduler Activities </td><td>Task Deleted </td><td>141 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>131 </td><td>Task Scheduler Activities </td><td>Task Disabled </td><td>142 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>132 </td><td>Task Scheduler Activities </td><td>Task Launched </td><td>200 </td><td>Information </td><td>Microsoft-Windows-TaskScheduler/Operational </td><td>Microsoft-Windows-TaskScheduler </td></tr><tr><td>133 </td><td>Printing Services </td><td>Printing Document </td><td>307 </td><td>Information </td><td>Microsoft-Windows-PrintService/Operational </td><td>Microsoft-Windows-PrintService </td></tr><tr><td>134 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4103 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>135 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4104 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>136 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4105 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>137 </td><td>PowerShell Activities </td><td>Exception Raised </td><td>4106 </td><td>Information </td><td>Microsoft-Windows-Powershell/Operational </td><td>Microsoft-Windows-Powershell </td></tr><tr><td>138 </td><td>Mobile Device Activities </td><td>Network Connection and Disconnection Status (Wired and Wireless) </td><td>10000, 10001 </td><td>Information </td><td>Microsoft-Windows-NetworkProfile/Operational </td><td>Microsoft-Windows-NetworkProfile </td></tr><tr><td>139 </td><td>Account Usage </td><td>Group Assigned to new Session </td><td>300 </td><td>Information </td><td>Microsoft-Windows-LSA/Operational </td><td>LsaSrv </td></tr><tr><td>140 </td><td>External Media Detection </td><td>New Mass Storage Installation </td><td>400, 410 </td><td>Information </td><td>Microsoft-Windows-Kernel-PnP/Device Configuration </td><td>Microsoft-Windows-Kernel-PnP </td></tr><tr><td>141 </td><td>DNS/Directory Services </td><td>DNS Request/Response </td><td>256, 257 </td><td>Information </td><td>Microsoft-Windows-DNSServer/Analytical </td><td>Microsoft-Windows-DNSServer </td></tr><tr><td>142 </td><td>DNS/Directory Services </td><td>DNS Query Complete </td><td>3008 </td><td>Information </td><td>Microsoft-Windows-DNS-Client/Operational </td><td>Microsoft-Windows-DNS-Client </td></tr><tr><td>143 </td><td>DNS/Directory Services </td><td>DNS Response Complete </td><td>3020 </td><td>Information </td><td>Microsoft-Windows-DNS-Client/Operational </td><td>Microsoft-Windows-DNS-Client </td></tr><tr><td>144 </td><td>Kernel Driver Signing </td><td>Code Integrity Check </td><td>3001, 3002, 3003, 3004, 3010, 3023 </td><td>Warning, Error </td><td>Microsoft-Windows-CodeIntegrity/Operational </td><td>Microsoft-Windows-CodeIntegrity </td></tr><tr><td>145 </td><td>Certificate Services </td><td>CA Permissions Corrupted or Missing </td><td>90 </td><td>Information </td><td>Microsoft-Windows-CertificationAuthority </td><td>Microsoft-Windows-CertificationAuthority </td></tr><tr><td>146 </td><td>Microsoft Cryptography API </td><td>Cert Trust Chain Build Failed </td><td>11 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>147 </td><td>Microsoft Cryptography API </td><td>Private Key Accessed </td><td>70 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>148 </td><td>Microsoft Cryptography API </td><td>X.509 Object </td><td>90 </td><td>Information </td><td>Microsoft-Windows-CAPI2/Operational </td><td>Microsoft-Windows-CAPI2 </td></tr><tr><td>149 </td><td>Application Whitelisting </td><td>Application Ran </td><td>8020 </td><td>Information </td><td>Microsoft-Windows-AppLocker/Packaged app-Execution </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>150 </td><td>Application Whitelisting </td><td>Application Installed </td><td>8023 </td><td>Information </td><td>Microsoft-Windows-AppLocker/Packaged app-Deployment </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>151 </td><td>Application Whitelisting </td><td>AppLocker Warning </td><td>8006 </td><td>Error </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>152 </td><td>Application Whitelisting </td><td>AppLocker Warning </td><td>8007 </td><td>Warning </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>153 </td><td>Application Whitelisting </td><td>Script or Installer ran </td><td>8005 </td><td>Information </td><td>Microsoft-Windows-AppLocker/MSI and Script </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>154 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8002 </td><td>Information </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>155 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8003 </td><td>Error </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>156 </td><td>Application Whitelisting </td><td>AppLocker Block </td><td>8004 </td><td>Warning </td><td>Microsoft-Windows-AppLocker/EXE and DLL </td><td>Microsoft-Windows-AppLocker </td></tr><tr><td>157 </td><td>Software and Service Installation </td><td>New Application Installation </td><td>903, 904 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>158 </td><td>Software and Service Installation </td><td>Removed Application </td><td>907, 908 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>159 </td><td>Software and Service Installation </td><td>Summary of Software Activities </td><td>800 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>160 </td><td>Software and Service Installation </td><td>Updated Application </td><td>905, 906 </td><td>Information </td><td>Microsoft-Windows-Application-Experience/Program-Inventory </td><td>Microsoft-Windows-Application-Experience </td></tr><tr><td>161 </td><td>Account Usage </td><td>Create Profile failed </td><td>1518 </td><td>Error </td><td>Application </td><td>Microsoft-Windows-User Profiles Service </td></tr><tr><td>162 </td><td>Account Usage </td><td>Temp Profile Logon </td><td>1511 </td><td>Error </td><td>Application </td><td>Microsoft-Windows-User Profiles Service </td></tr><tr><td>163 </td><td>Application Crashes </td><td>App Crash </td><td>1000 </td><td>Error </td><td>Application </td><td>Application Error </td></tr><tr><td>164 </td><td>Application Crashes </td><td>App Error </td><td>1000 </td><td>Error </td><td>Application </td><td>Application Error </td></tr><tr><td>165 </td><td>Application Crashes </td><td>App Hang </td><td>1002 </td><td>Error </td><td>Application </td><td>Application Hang </td></tr><tr><td>166 </td><td>Application Crashes </td><td>WER </td><td>1001 </td><td>Information </td><td>Application </td><td>Windows Error Reporting </td></tr><tr><td>167 </td><td>Application Whitelisting </td><td>SRP Block </td><td>865, 866, 867, 868, 882 </td><td>Warning </td><td>Application </td><td>Microsoft-Windows-SoftwareRestrictionPolicies </td></tr><tr><td>168 </td><td>Software and Service Installation </td><td>New MSI File Installed </td><td>1022, 1033 </td><td>Information </td><td>Application </td><td>MsiInstaller </td></tr></tbody></table>

## What log events should I collect/send to my SIEM?

### Account Management

&#x20;           4740: Account Lockouts

&#x20;           4627: Group Membership Information

&#x20;           4703: A user right was adjusted.

&#x20;           4704: A user right (privilege) was assigned.

&#x20;           4704: A user right (privilege) was removed.

&#x20;           4720: A user account was created.

&#x20;           4722: A user account was enabled.

&#x20;           4723: Attempt was made to change account's password.

&#x20;           4724: An attempt was made to reset an account's password.

&#x20;           4725: A user account was disabled.

&#x20;           4726: A user account was deleted.

&#x20;           4727: A security-enabled global group was created.

&#x20;           4728: A member was added to a security-enabled global group.

&#x20;           4729: A member was removed to a security-enabled global group.

&#x20;           4730: A security-enabled global group was deleted.

&#x20;           4731: A security-enabled local group was created.

&#x20;           4732: A member was added to a security-enabled local group.

&#x20;           4733: A member was removed from a security-enabled local group.

&#x20;           4734: A security-enabled local group was deleted.

&#x20;           4735: Modification of Security-enabled groups

&#x20;           4737: A security-enabled global group was changed.

&#x20;           4738: A user account was changed.

&#x20;           4739: Domain Policy was changed.

&#x20;           4741: A computer account was created.

&#x20;           4742: A computer account was changed.

&#x20;           4743: A computer account was deleted.

&#x20;           4744: A security-disabled local group was created.

&#x20;           4745: A security-disabled local group was changed.

&#x20;           4746: A member was added to a security-disabled local group.

&#x20;           4747: A member was removed from a security-disabled local group.

&#x20;           4748: A security-disabled local group was deleted.

&#x20;           4749: A security-disabled global group was created.

&#x20;           4750: A security-disabled global group was changed.

&#x20;           4751: A member was added to a security-disabled global group.

&#x20;           4752: A member was removed from a security-disabled global group.

&#x20;           4753: A security-disabled global group was deleted.

&#x20;           4754: A security-enabled universal group was created.

&#x20;           4755: A security-enabled universal group was changed.

&#x20;           4756: A security-enabled universal group was changed.

&#x20;           4757: A security-enabled universal group was changed.

&#x20;           4758: A security-enabled universal group was created.

&#x20;           4759: A security-disabled universal group was created.

&#x20;           4760: A security-disabled universal group was changed.

&#x20;           4761: A member was added to a security-disabled universal group.

&#x20;           4762: A member was removed from a security-disabled universal group.

&#x20;           4763: A security-disabled universal group was deleted.

&#x20;           4764: A group's type was changed.

&#x20;           4765: SID History was added to an account.

&#x20;           4766: An attempt to add SID History to an account failed.

&#x20;           4767: A user account was unlocked.

&#x20;           4780: The ACL was set on accounts which are members of administrators group.

&#x20;           4781: The name of an account was changed.

&#x20;           4782: The password hash an account was accessed.

&#x20;           4793: The Password Policy Checking API was called.

&#x20;           4794: An attempt was made to set the Directory Services Restore Mode administrator password.

&#x20;           4798: A user's local group membership was enumerated.

&#x20;           4799: A security-enabled local group membership was enumerated.

&#x20;           5376: Credential Manager credentials were backed up.

&#x20;           5377: Credential Manager credentials were restored from a backup.

### Active Directory

&#x20;           4662: Directory Service Access Operation Performed On An Object

&#x20;           5136: A directory service object was modified.

&#x20;           5137: A directory service object was created.

&#x20;           5138: A directory service object was undeleted.

&#x20;           5139: A directory service object was moved.

&#x20;           5141: A directory service object was deleted.

&#x20;           4713: Kerberos Policy was changed.

&#x20;           4706: A new trust was created to a domain.

&#x20;           4707: A trust to a domain was removed.

&#x20;           4716: Trusted domain information was modified.

&#x20;           4717: System security access was granted to an account.

&#x20;           4718: System security access was removed from an account.

&#x20;           4739: Domain Policy was changed.

&#x20;           4864: A namespace collision was detected.

&#x20;           4865: A trusted forest information entry was added.

&#x20;           4866: A trusted forest information entry was removed.

&#x20;           4867: A trusted forest information entry was modified.

### Application Error and Hang

&#x20;           EventID=1000

&#x20;           EventID=1002

&#x20;           WER Application Crashes Reports

&#x20;           EventID=1001

### Applocker

&#x20;           Microsoft-Windows-AppLocker/EXE and DLL

&#x20;           Rules that look for Applocker EXE or Script events

&#x20;           Applocker Packaged app execution

&#x20;           Applocker Packaged app installation

### Authentication Events

&#x20; 4624: An account was successfully logged on.

&#x20; 4625: An account failed to log on.

&#x20; 4626: User/Device claims information.

&#x20; 4634: An account was successfully logged off.

&#x20; 4647: User initiated logoff.

&#x20; 4649: A replay attack was detected.

&#x20; 4672: Special privileges assigned to a new logon, administrative logins -sa, -ada, etc.

&#x20; 4675: SIDs were filtered.

&#x20; 4774: An account was mapped for logon.

&#x20; 4775: An account could not be mapped for logon.

&#x20; 4776: The computer attempted to validate the credentials for an account.

&#x20; 4777: The domain controller failed to validate the credentials for an account.

&#x20; 4778: A session was reconnected to a Window Station.

&#x20; 4779: A session was disconnected from a Window Station.

&#x20; 4800 The workstation was locked.

&#x20; 4801 The workstation was unlocked.

&#x20; 4802 The screen saver was invoked.

&#x20; 4803 The screen saver was dismissed.

&#x20; 4964: Special groups have been assigned a new logon.

&#x20; 5378 The requested credentials delegation was disallowed by policy.

&#x20; \*\*\*\* Suppress \[EventData\[Data\[1]="S-1-5-18"]] to avoid SECURITY\_LOCAL\_SYSTEM\_RID\*\*\*\*\*\*\*

### BITS

&#x20; Microsoft-Windows-Bits-Client/Operational

### Certificate Authority

&#x20;           Security

&#x20;           4886: Certificate Services received certificate request

&#x20;           4887: Approved and Certificate issued

&#x20;           4888: Denied request

### Code Integrity

&#x20; Windows Code Integrity Checks (Kernel-mode Driver and User-mode Protected Media Validation)

&#x20; Level = 2 or 3

&#x20; and Event ID is

&#x20; EventID=3001 or

&#x20; EventID=3002 or

&#x20; EventID=3003 or

&#x20; EventID=3004 or

&#x20; EventID=3010 or

&#x20; EventID=3023)

&#x20; Windows Code Integrity Checks (Invalid hashes)

&#x20; Level=0 or Level=4 and

&#x20; EventID=5038 or

&#x20; EventID=6281 or

&#x20; EventID=6410

### DNS Logs

&#x20; 3008: DNS Client events Query Completed

&#x20; Suppress EventData\[Data\[@Name="QueryOptions"]="140737488355328"

&#x20; Suppress EventData\[Data\[@Name="QueryResults"]=""

&#x20; 150: DNS Server could not load or initialize the plug-in DLL

&#x20; 770: DNS Server plugin DLL has been loaded

&#x20; 541: The setting serverlevelplugindll on scope . has been set to $dll\_path

### Drivers Logs

&#x20; Microsoft-Windows-Kernel-PnP

&#x20; Level=3 and EventID=219

&#x20; Microsoft-Windows-DriverFrameworks-UserMode/Operational

&#x20; Detect User-Mode drivers loaded - for potential BadUSB detection.

&#x20; EventID=2004

### EventLog Diagnostics

&#x20; 1100: The event logging service has shut down.

&#x20; 1104: The security log is now full.

&#x20; 1105: Event log automatic backup.

&#x20; 1108: The event logging service encountered an error while processing an incoming event published from %1

### Explicit Login Credentials

&#x20; Microsoft-Windows-Security-Auditing

&#x20; Level=4 or Level=0 and EventID=4648 and ProcessName != 'C:\Windows\System32\taskhost.exe'

### Firewall Events

### &#x20;

&#x20; Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

&#x20; 4944: The following policy was active when the Windows Firewall started.

&#x20; 4945: A rule was listed when the Windows Firewall started.

&#x20; 4946: A change has been made to Windows Firewall exception list. A rule was added.

&#x20; 4947: A change has been made to Windows Firewall exception list. A rule was modified.

&#x20; 4948: A change has been made to Windows Firewall exception list. A rule was deleted.

&#x20; 4949: Windows Firewall settings were restored to the default values.

&#x20; 4950: A Windows Firewall setting has changed.

&#x20; 4951: A rule has been ignored because its major version number was not recognized by Windows Firewall.

&#x20; 4952: Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.

&#x20; 4953: A rule has been ignored by Windows Firewall because it could not parse the rule.

&#x20; 4954: Windows Firewall Group Policy settings have changed. The new settings have been applied.

&#x20; 4956: Windows Firewall has changed the active profile.

&#x20; 4957: Windows Firewall did not apply the following rule

&#x20; 4958: Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer

&#x20; Security Log

&#x20; 5024: The Windows Firewall Service has started successfully.

&#x20; 5025:  The Windows Firewall Service has been stopped.

&#x20; 5027:  The Windows Firewall Service was unable to retrieve the security policy from local storage. The service will continue enforcing the current policy.

&#x20; 5028:  The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.

&#x20; 5029:  The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.

&#x20; 5030:  The Windows Firewall Service failed to start.

&#x20; 5032:  Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

&#x20; 5033:  The Windows Firewall Driver has started successfully.

&#x20; 5034:  The Windows Firewall Driver was stopped.

&#x20; 5035:  The Windows Firewall Driver failed to start.

&#x20; 5037:  The Windows Firewall Driver detected critical runtime error. Terminating.

### External Devices Log

&#x20; Security

&#x20; 6416: A new external device was recognized by the System.

&#x20; 6419: A request was made to disable a device.

&#x20; 6420: A device was disabled.

&#x20; 6421: A request was made to enable a device.

&#x20; 6422: A device was enabled..

&#x20; 6423: The installation of this device is forbidden by system policy.

&#x20; 6424: The installation of this device was allowed after having previously been forbidden by policy.

&#x20; Microsoft-Windows-USB-USBHUB3-Analytic

&#x20; Level=4 and EventID=43

&#x20; EventData\[Data\[@Name='fid\_DeviceDescription']="USB Mass Storage Device

&#x20; Microsoft-Windows-Kernel-PnP/Configuration

&#x20; 400, 410: New Mass Storage Device Installation

&#x20; Level=4 and

&#x20; EventID=400 or EventID=410

&#x20; and EventData\[Data\[@Name='DriverName']=usbstor.inf

### GPO logs

&#x20; Microsoft-Windows-GroupPolicy

&#x20; Level 2 and

&#x20; 1085: Application of Group Policy failures

&#x20; 1125: Group Policy Service

&#x20; 1127: Group Policy Service

&#x20; 1129: Group Policy Preprocessing Networking

&#x20; Security

&#x20; 6144: Security policy in the group policy objects has been applied successfully.

&#x20; 6145: One or more errors occurred while processing security policy in the group policy object.

### Kerberos

&#x20; Security

&#x20; 4768 - A Kerberos authentication ticket (TGT) was requested

&#x20; 4769 - A Kerberos service ticket was requested

&#x20; 4770 - A Kerberos service ticket was renewed

&#x20; 4771 - A Kerberos pre-authentication failed.

&#x20; 4772 - A Kerberos authentication ticket request failed.

&#x20; 4773 - A Kerberos service ticket request failed.

### LOG Deletion

&#x20; Security

&#x20; 1102: Security Log File Cleared

&#x20; System

&#x20; 104: Log File Cleared

### Object Manipulation

&#x20; Security

&#x20; 4715: The audit policy (SACL) on an object was changed.

&#x20; 4817: Auditing settings on object were changed.

&#x20; 4656: A handle to an object was requested.

&#x20; 4658: The handle to an object was closed.

&#x20; 4660: An object was deleted.

&#x20; 4663: An attempt was made to access an object.

&#x20; 4670: Permissions on an object were changed.

### Operating System

&#x20; System

&#x20; 41: The system has rebooted without cleanly shutting down first

&#x20; 1001: Application crashes, hangs, and generic reports

&#x20; 4621: Administrator recovered system from CrashOnAuditFail.

&#x20; 6008: The previous system shutdown was unexpected.

&#x20; 1074: Shutdown initiate requests, with user, process and reason (if supplied)

&#x20; 12: System startup (12 - includes OS/SP/Version) and shutdown

&#x20; 16962: A remote call to the SAM database has been denied

&#x20; 16965: Remote calls to the SAM database have been denied in the past 900 seconds throttling window

&#x20; 16968: The following client would have been normally been denied access to the SAM database

&#x20; 16969: Remote calls to the SAM database are being restricted using the default security descriptor

&#x20; 16965: is enabled via a registry key

### &#x20; Security

&#x20; 4719: System audit policy was changed.

&#x20; 4817: A trusted logon process has been registered with the Local Security Authority.

&#x20; 4902: The Per-user audit policy table was created.

&#x20; 4906: The CrashOnAuditFail value has changed.

&#x20; 4908: Special Groups Logon table modified.

&#x20; 4912: Per User Audit Policy was changed.

&#x20; 4904: An attempt was made to register a security event source..

&#x20; 4905: An attempt was made to unregister a security event source.

&#x20; 4610: An authentication package has been loaded by the Local Security Authority.

&#x20; 4611: A trusted logon process has been registered with the Local Security Authority.

&#x20; 4614: A notification package has been loaded by the Security Account Manager.

&#x20; 4622: A security package has been loaded by the Local Security Authority.

&#x20; 4697: A service was installed in the system.

&#x20; 4817: Auditing settings on object were changed.

&#x20; 4826 Boot Configuration Data loaded.

&#x20; 4608: Windows is starting up

&#x20; Microsoft-Windows-SMBServer/Audit

&#x20; 3000: Client attempted to use SMBv1

### Privilege Use

&#x20; Security

&#x20; 4673: A privileged service was called..

&#x20; 4674: An operation was attempted on a privileged object..

&#x20; 4985: The state of a transaction has changed.

### Process execution

&#x20; Security

&#x20; 4688: Process Created

&#x20; 4699: Process Terminated

### Registry

&#x20; Security

&#x20; 4657: Registry modified events for Operations

&#x20; and EventData\[Data\[@Name=OperationType]] =

&#x20; 1904: New Registry Value created OR

&#x20; 1905: Existing Registry Value modified OR

&#x20; 1906: Registry Value Deleted

### Services

&#x20; System

&#x20; Level 0 OR 1 OR 2 OR 3 OR 4

&#x20; 7022: The service hung on starting

&#x20; 7023: The service terminated with the following error

&#x20; 7023: The service terminated with the following error

&#x20; 7024: The service terminated with service-specific error

&#x20; 7026: The following boot-start or system-start driver(s) failed to load

&#x20; 7031: The service terminated unexpectedly. It has done this x time(s).

&#x20; 7040: Service Start Type Changed

&#x20; 7045: Service Installed

### Network Shares

&#x20; Security

&#x20; 5140: Network share object access

&#x20; 5142: Network Share create

&#x20; 5144: Network Share Delete

&#x20; 5145: A network share object was checked to see whether client can be granted desired access

&#x20; 5168: SPN check for SMB/SMB2 failed.

&#x20; Microsoft-Windows-SMBClient/Operational

&#x20; Event ID: 30622 OR

&#x20; Event ID: 30624

&#x20; Microsoft-Windows-SMBClient/Security

&#x20; Microsoft-Windows-SMBServer/Security

### System Time Modification

&#x20; Security

&#x20; 4616: System Time Changed

### Task Scheduler

&#x20; Microsoft-Windows-TaskScheduler/Operational

&#x20; EventID=106 or

&#x20; EventID=129 or

&#x20; EventID=141 or

&#x20; EventID=142 or

&#x20; EventID=200 or

&#x20; EventID=201

&#x20; Security

&#x20; 4698: A scheduled task was created

&#x20; 4699: A scheduled task was deleted

&#x20; 4700: A scheduled task was enabled

&#x20; 4701: A scheduled task was disabled

&#x20; 4702: A scheduled task was updated

### PowerShell

&#x20; Microsoft-Windows-PowerShell/Operational

&#x20; Microsoft-Windows-PowerShell-DesiredStateConfiguration-FileDownloadManager/Operational

&#x20; Windows PowerShell

### Print Jobs

&#x20; Microsoft-Windows-PrintService/Operational

&#x20; Level=4 and EventID=307

### Terminal Services

&#x20; All TSG Admin Events

&#x20; Microsoft-Windows-TerminalServices-Gateway/Admin

&#x20; Microsoft-Windows-TerminalServices-Gateway/Operational

&#x20; All TSG Client USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ClientUSBDevices/Admin

&#x20; All TSG Client USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ClientUSBDevices/Operational

&#x20; All TSG Client USB PNP Events

&#x20; Microsoft-Windows-TerminalServices-PnPDevices/Admin

&#x20; All TSG Client USB PNP Events

&#x20; Microsoft-Windows-TerminalServices-PnPDevices/Operational

&#x20; All TSG Printer Events

&#x20; Microsoft-Windows-TerminalServices-Printers/Admin

&#x20; All TSG Printer Events

&#x20; Microsoft-Windows-TerminalServices-Printers/Operational

&#x20; All TSG Server USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin

&#x20; All TSG Server USB Device Events

&#x20; Microsoft-Windows-TerminalServices-ServerUSBDevices/Operational

### WMI

&#x20; Microsoft-Windows-WMI-Activity/Operational

&#x20; Microsoft-Windows-TPM-WMI

&#x20; 513: TPM Owner Authorization information was backed up successfully to Active Directory Domain Services.

&#x20; 514: Failed to backup TPM Owner Authorization information to Active Directory Domain Services.

### Windows Defender

&#x20; Microsoft-Windows-Windows Defender/Operational

&#x20; Event ID: 1006 OR 1007 OR 1008 OR 1009

&#x20; Event ID: 1116 OR 1117 OR 1118 OR 1119

### Wireless

&#x20; Security

&#x20; 5632: Request made to authenticate to Wireless network.

&#x20; 5633: A request was made to authenticate to a wired network.


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.blusapphire.io/16_best-practices/windows-logging-recommendations/windows-general-log-recommendations.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
