Windows Event Catalog

106396 events across 1740 providers, 8393 with sample data85530 with field definitions571 trace events4694 with reference links

More
ProviderEventsSamples
Microsoft-Windows-Security-Auditing426207
Microsoft-Windows-Sysmon3030
Microsoft-Windows-PowerShell18941
Microsoft-Windows-Windows Defender9426
Microsoft-Windows-TaskScheduler14838
Microsoft-Windows-WMI-Activity2515
Microsoft-Windows-TerminalServices-LocalSessionManager4716
Microsoft-Windows-DNS-Server-Service49735
Microsoft-Windows-ActiveDirectory_DomainService4141
Microsoft-Windows-Kernel-Process2713
Service Control Manager9136
Microsoft-Windows-Bits-Client11428
Microsoft-Windows-Windows Firewall With Advanced Security17151
Microsoft-Windows-AppLocker4916
Microsoft-Windows-NTLM215
Microsoft-Windows-Security-Kerberos9014
Microsoft-Windows-CertificationAuthority35535
Microsoft-Office-Word2976955
Microsoft-Office-Word886886
OfficeAirSpace470470
Microsoft-Office-Word3450417
Microsoft-Windows-Shell-Core2380217
Linux Auditd205164
Microsoft-Windows-TCPIP624140
Microsoft-Windows-AppXDeployment-Server2020125
Microsoft-Windows-Security-SPP326117
Microsoft-Windows-Hyper-V-VMMS7057109
Microsoft-Windows-Dwm-Core334107
Microsoft-Office-Events9191
AD FS56278
Microsoft-Windows-Application Server-Applications48178
Microsoft-Windows-DxgKrnl70775
Microsoft-Windows-ServerManager-MultiMachine33365
Microsoft-Windows-GroupPolicy17764
MSSQL$SQLEXPRESS6363
Microsoft-Windows-PushNotifications-Platform41262
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider99659
ESF14857
Microsoft-Windows-WinRM32757
MSSQL$MICROSOFT##WID5050
Microsoft-Windows-Win32k35849
Microsoft-Windows-Dhcp-Client16448
Microsoft-Windows-DeviceManagement-Pushrouter10746
Microsoft-Windows-ESE14046
Microsoft-Windows-Hyper-V-VmSwitch52945
Microsoft-Windows-Time-Service17843
Microsoft-Windows-SENSE21441
Microsoft-Windows-DHCP-Server56538
ESENT3636
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS8934
Microsoft-Windows-SMBClient18134
Microsoft-Antimalware-Engine11032
Microsoft-Windows-FailoverClustering76232
Microsoft-Windows-AppReadiness17431
Microsoft-Windows-Ntfs7231
Microsoft-Windows-DotNETRuntime14530
Microsoft-Windows-SMBServer20729
Microsoft-Windows-CAPI27428
Microsoft-Windows-PrintService21928
Microsoft-Windows-ShellCommon-StartLayoutPopulation12628
Microsoft-Windows-Threat-Intelligence3428
Microsoft-Windows-DHCPv6-Client12727
Microsoft-Windows-VHDMP8427
Microsoft-Windows-Winlogon15127
Microsoft-Windows-Winsock-AFD9627
Microsoft-Windows-DNS-Client10726
Microsoft-Windows-DNSServer16726
Microsoft-Windows-Search25826
AD FS Auditing2525
Microsoft-Windows-COM-Perf5525
Microsoft-Windows-DeviceSetupManager10225
Microsoft-Windows-DriverFrameworks-UserMode7725
OfficeLoggingLiblet2525
Microsoft-Windows-Kernel-Registry4523
Microsoft-Windows-User Device Registration22023
Microsoft-Windows-Hyper-V-Worker166922
Microsoft-Windows-Kernel-File2522
Microsoft-Windows-Kernel-PnP19622
Microsoft-Windows-StorPort36222
Microsoft-Windows-CodeIntegrity11121
Microsoft-Windows-DSC25521
Microsoft-Windows-Kernel-Boot26121
Microsoft-Windows-UxTheme3321
Microsoft-Windows-DotNETRuntimeRundown2320
Microsoft-Windows-HttpService13220
Microsoft-Windows-ModernDeployment-Diagnostics-Provider23920
MsiInstaller4620
DFSR1919
Windows Server Update Services1919
Microsoft-Windows-Diagnosis-PLA4818
Microsoft-Windows-MSDTC72318
Microsoft-Windows-ServerManager-ManagementProvider7018
Microsoft-Windows-TSF-msctf9518
NTDS ISAM1818
Microsoft-Windows-CloudStore6017
Microsoft-Windows-StateRepository9517
MSSQLSERVER2217
Microsoft-Windows-Dwm-Compositor3616
Microsoft-Windows-Kernel-Network2216
Microsoft-Windows-WAS43016

View all 1740 providers (showing the top 100 by sample data)