Introducing ADAudit Plus' Attack Surface Analyzer—Detect 25+ AD attacks and identify risky Azure configurations. Learn more×
 
Support
 
Phone Get Quote
 
Support
 
US: +1 888 720 9500
US: +1 888 791 1189
Intl: +1 925 924 9500
Aus: +1 800 631 268
UK: 0800 028 6590
CN: +86 400 660 8680

Direct Inward Dialing: +1 408 916 9892

Windows security event log library

Gain quick insights into all the Windows security log events audited and analyzed by ADAudit Plus.

EVENT ID

Audit Categories:

S.No Event ID Description
  4608 Windows is starting up.
This event is generated when a Windows machine is started. It is logged on domain controllers and member computers.  
  4609 Windows is shutting down.
This event is generated when a Windows machine is shutting down. It is logged on domain controllers and member computers.   
  1102 The audit log was cleared.
This event is generated whenever the security log is cleared. It is logged on domain controllers and member computers.   
  4614 A notification package has been loaded by the Security Account Manager.
This event is generated when a user attempts to change their password. It is logged on domain controllers and member computers.  
  4616 The system time was changed.
This event is generated when the system time is changed. It is logged on domain controllers and member computers.   
  521 Unable to log events in the security log.
This event is generated when Windows is unable to write events to the security event log. It is logged on domain controllers and member computers.   
  4697 A service was installed in the system.
This event is generated when a new service is installed on a system. It is logged on domain controllers and member computers.   
  1100 The event logging service has shut down.
This event is generated during a normal system shutdown, and when the Windows Event Log service shuts down. It is logged on domain controllers and member computers.   
  4618 A monitored security event pattern has occurred.
This event is generated when Windows is configured to generate alerts per the Common Criteria security audit analysis requirements and an auditable event pattern occurs. It is logged on domain controllers and member computers.  
  4610 An authentication package has been loaded by the Local Security Authority.
This event is generated at startup for each authentication package on the system. It is logged on domain controllers and member computers.   
  4611 A trusted logon process has been registered with the Local Security Authority.
This event is generated when a logon process is registered with the Local Security Authority to submit trusted logon requests. It is logged on domain controllers and member computers.   
  4622 A security package has been loaded by the Local Security Authority.
This event is generated when a security package is loaded by the Local Security Authority. It is logged on domain controllers and member computers.   
  7045 A new service was installed in the system.
A new service was installed in the system.  
  1101 Audit events have been dropped by the transport.
This event is generated when restarting Windows after a dirty shutdown. It is logged on domain controllers, member servers, and workstations  
  1104 The security log is now full. 
This event is generated when the Windows security log becomes full. It is logged on domain controllers, member servers, and workstations.   
  1105 Event log automatic backup.
This event is generated when the Windows security log becomes full and a new event log file is created (for example, when the maximum size of Security Event Log file is reached and event log retention method has been set to “Archive the log when full, do not overwrite events”). It is logged on domain controllers, member servers, and workstations.   
  1108 The event logging service encountered an error.
This event is generated when the event logging service encounters an error while processing an incoming event. It is logged on domain controllers, member servers, and workstations.   

ADAudit Plus Trusted By

Back to Top