Active Directory: NetLogon
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 1 | NetLogon Server Authentication | ETW Trace | N | N |
| 2 | NetLogon Server Authentication | ETW Trace | N | N |
Event ID 1: NetLogon Server Authentication
#Fields #
| Name | Description |
|---|---|
Client mof:String | |
Account mof:String | |
ChannelType mof:UInt32 | |
NegotiatedFlags mof:UInt32 |
Event ID 2: NetLogon Server Authentication
#Fields #
| Name | Description |
|---|---|
Client mof:String | |
Account mof:String | |
ChannelType mof:UInt32 | |
NegotiatedFlags mof:UInt32 | |
Status mof:UInt32 | NTSTATUS reference |
Provenance
ETW provider GUID {F33959B4-DBEC-11D2-895B-00C04F79AB69}
- WS2025-26100.0, schema read from the WMI MOF class, captured 2026-02-26
Taken from Windows installation media (build 26100.1), not a patched system, so the exact update level is unknown.
- WS2022-20348.4893, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSNetLogonTrace
- Win11-26200.6584, schema read from the WMI MOF class, captured 2026-06-02
MOF class: MSNetLogonTrace