Event ID 1101 – Audit Events Have Been Dropped By The Transport
Event ID | 1101 |
Category | Non Audit (Event Log) |
Sub-category | Other Events (Service Shutdown) |
Type | Success Audit |
Description | Audit events have been dropped by the transport |
Whenever Windows is logged onto during a restart, caused by a dirty shutdown, event ID 1101 is logged.
Why does event ID 1101 need to be monitored?
- To track dirty system shutdowns and restarts
- To monitor possible malicious activity
Pro Tip:
With in-depth reports, real-time alerts, and options for actions like automatic archiving, ADAudit Plus handles all log related non-audit events, helping you meet your security, operational, and compliance needs with absolute ease.
Event 1101 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools