Microsoft-Windows-Eventlog

EventTitleChannelSampleRule
20The event logging service encountered an error ErrorCode while obtaining or …SystemNN
21The event logging service encountered a configuration-related error …SystemNN
22The event logging service encountered an error while initializing publishing …SystemNN
23The event logging service encountered an error (res=ErrorCode) while …SystemNN
25The event logging service encountered a corrupt log file for channel …SystemNN
26The event logging service encountered a log file for channel ChannelPath which …SystemNN
27The event logging service encountered an error (res=ErrorCode) while opening log …SystemNN
28The event logging service encountered an error (res=ErrorCode) while parsing …SystemNN
29The event logging service encountered a fatal error (res=ErrorCode) when …SystemNN
30The event logging service encountered an error …SystemYN
31The event logging service encountered an error (res=ErrorCode) while opening …SystemNN
40The event logging service encountered an error when attempting to apply one or …SystemNN
100The event logging service encountered an error while processing an incoming …AnalyticNN
102The event logging service encountered an error while processing an incoming …AnalyticNN
103Events have been dropped by the transport.AnalyticNN
104The LogFileCleared.Channel log file was cleared.SystemYY
105Event log automatic backup.SystemYN
106Corruption was detected in the log for the Channel channel and some data was …SystemNN
107The event logging service encountered an error ErrorCode while going through …AnalyticNN
108The previous system shutdown was unexpected.SystemNN
109The event logging service encountered an error while processing an incoming …AnalyticNN
110Loading metadata for publisher PublisherName (PublisherGuid) and trying to …DebugNN
111Finished loading metadata for publisher PublisherName (PublisherGuid), with …DebugNN
112Failed to load metadata for publisher PublisherName (PublisherGuid).DebugNN
200Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.AnalyticNN
201A push subscription was created for ChannelName.AnalyticNN
202A pull subscription was created for ChannelName.AnalyticNN
203OpenEventLog legacy API was used to open ModuleName.AnalyticYN
204RegisterEventSource legacy API was used to register ModuleName.AnalyticYN
205ReportEvent legacy API was used to write an event to ModuleName.AnalyticYN
517The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by …SecurityNY
1100The event logging service has shut down.SecurityYY
1101Audit events have been dropped by the transport.SecurityYN
1102The audit log was cleared.SecurityYY
1103The security log is now PercentFull percent full.SecurityNN
1104The security log is now full.SecurityNN
1105Event log automatic backup.SecurityNN
1106Events have been dropped by the event logging service.SecurityNN
1107The event logging service encountered an error while processing an incoming …SecurityYN
1108The event logging service encountered an error while processing an incoming …SecurityYN
6000The Channel log file is full.SystemNN

Event ID 20: The event logging service encountered an error ErrorCode while obtaining or processing configuration for channel Path.

#
Channel
System
Task
Servicestartup

Message #

The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 21: The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath. The error was encountered while processing the ConfigProperty configuration property.

Message #

The event logging service encountered a configuration-related error (res=%1) for channel %2. The error was encountered while processing the %3 configuration property.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
ConfigProperty UnicodeString

Event ID 22: The event logging service encountered an error while initializing publishing resources for channel Path.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error while initializing publishing resources for channel Path. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Message #

The event logging service encountered an error while initializing publishing resources for channel %2. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 23: The event logging service encountered an error (res=ErrorCode) while initializing logging resources for channel Path.

#
Channel
System
Task
Servicestartup

Message #

The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 25: The event logging service encountered a corrupt log file for channel ChannelPath.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered a corrupt log file for channel ChannelPath. The log was renamed with a .corrupt extension.

Message #

The event logging service encountered a corrupt log file for channel %1. The log was renamed with a .corrupt extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 26: The event logging service encountered a log file for channel ChannelPath which is an unsupported version.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered a log file for channel ChannelPath which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Message #

The event logging service encountered a log file for channel %1 which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 27: The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath. Trying again using default log file path FailedLogFilePath.

Message #

The event logging service encountered an error (res=%1) while opening log file for channel %2. Trying again using default log file path %3.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
FailedLogFilePath UnicodeString
NewLogFilePath UnicodeString

Event ID 28: The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath. Will continue without filter.

Message #

The event logging service encountered an error (res=%1) while parsing filter for channel %2. Will continue without filter.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 29: The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel.

#
Channel
System

Description

The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel. The service is shutting down since this channel is vital to its operation.

Message #

The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel. The service is shutting down since this channel is vital to its operation.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 30: The event logging service encountered an error (InitChannelPublisherEnableFailure.ErrorCode) while enabling publisher InitChannelPublisherEnableFailure.PublisherGuid to channel InitChannelPublisher...

#
Channel
System
Level
Error
Task
Servicestartup

Description

The event logging service encountered an error (ErrorCode) while enabling publisher PublisherGuid to channel ChannelPath. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Message #

The event logging service encountered an error (%1) while enabling publisher %3 to channel %2. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
PublisherGuid GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148",
    "event_source_name": "",
    "event_id": 30,
    "version": 0,
    "level": 2,
    "task": 100,
    "opcode": 0,
    "keywords": 9223372036854906880,
    "time_created": "2026-03-13T19:59:15.259008+00:00",
    "event_record_id": 11634,
    "correlation": {},
    "execution": {
      "process_id": 1844,
      "thread_id": 8176
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "user_data": {
    "InitChannelPublisherEnableFailure": {
      "ErrorCode": 5,
      "ChannelPath": "Microsoft-Windows-WinINet-Capture/Analytic",
      "PublisherGuid": "A70FF94F-570B-4979-BA5C-E59C9FEAB61B"
    }
  },
  "message": ""
}

Event ID 31: The event logging service encountered an error (res=ErrorCode) while opening configuration for primary channel ChannelPath.

#
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while opening configuration for primary channel ChannelPath. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Message #

The event logging service encountered an error (res=%1) while opening configuration for primary channel %2. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 40: The event logging service encountered an error when attempting to apply one or more policy settings.

#
Channel
System

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 100: The event logging service encountered an error while processing an incoming event published from PubID.

#
Channel
Analytic
Task
Eventprocessing

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Event ID 102: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Channel
Analytic
Task
Eventprocessing

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Event ID 103: Events have been dropped by the transport.

#
Channel
Analytic
Task
Eventprocessing

Description

Events have been dropped by the transport. The session name is SessionName and the reason code is Reason.

Message #

Events have been dropped by the transport.  The session name is %2 and the reason code is %1.

Fields #

NameDescription
Reason UInt8
SessionName UnicodeString

Event ID 104: The LogFileCleared.Channel log file was cleared.

#
Channel
System
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Logclear

Message #

The %3 log file was cleared.

Fields #

NameDescriptionRules
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.Channel
LogFileCleared.BackupPath
SubjectUserName
SubjectDomainName
Channel12 detection rules
BackupPath
ClientProcessId
ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-28T00:50:57.4445174+00:00",
    "event_record_id": 6146,
    "correlation": {},
    "execution": {
      "process_id": 1616,
      "thread_id": 3308
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserName": "localuser",
      "SubjectDomainName": "cell-a",
      "Channel": "Windows PowerShell",
      "BackupPath": ""
    }
  },
  "message": "The Windows PowerShell log file was cleared."
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqmicrosoft-windows-eventlog2 rulessigma

Community Notes #

This will show System, Application, and other non-Security logs being cleared. Review the event to identify which one.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 105: Event log automatic backup.

#
Channel
System
Level
Informational
Task
Logautomaticbackup

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Channel
BackupPath

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 105,
    "version": 0,
    "level": 4,
    "task": 105,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2012-03-26T05:50:08.470644Z",
    "event_record_id": 13049,
    "correlation": {},
    "execution": {
      "process_id": 772,
      "thread_id": 4256
    },
    "channel": "System",
    "computer": "WKS-WIN764BITB.shieldbase.local",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AutoBackup": {
      "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
      "Channel": "Application",
      "BackupPath": "C:\\Windows\\System32\\Winevt\\Logs\\Archive-Application-2012-03-26-05-50-01-755.evtx"
    }
  }
}

Event ID 106: Corruption was detected in the log for the Channel channel and some data was erased.

#
Channel
System

Message #

Corruption was detected in the log for the %1 channel and some data was erased.

Fields #

NameDescription
Channel UnicodeString

Event ID 107: The event logging service encountered an error ErrorCode while going through publisher configuration.

#
Channel
Analytic

Description

The event logging service encountered an error ErrorCode while going through publisher configuration. The publisher ProviderName is already installed with GUID PublisherGuid.

Message #

The event logging service encountered an error %1 while going through publisher configuration. The publisher %2 is already installed with GUID %3.

Fields #

NameDescription
ErrorCode UInt32
ProviderName UnicodeString
PublisherGuid GUID

Event ID 108: The previous system shutdown was unexpected.

#
Channel
System
Task
SystemAbnormalShutdown

Fields #

NameDescription
ShutdownTime SYSTEMTIME
ActualMaxInterval UInt32
DiskPmDisabledMaxInterval UInt32
DiskPmEnabledFlag UInt32
DiskPmEnabledMaxInterval UInt32
TimestampForced UInt32
DiskPmPolicy UInt32
BiasValid UInt32
StartBias UInt32

Event ID 109: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Channel
Analytic
Task
Eventprocessing

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32
EventName UnicodeString

Event ID 110: Loading metadata for publisher PublisherName (PublisherGuid) and trying to process the metadata for it.

#
Channel
Debug
Task
Eventprocessing
Opcode
Start

Message #

Loading metadata for publisher %2 (%1) and trying to process the metadata for it.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString

Event ID 111: Finished loading metadata for publisher PublisherName (PublisherGuid), with EventMetaDataCount event metadatas processed.

#
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Message #

Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
EventMetaDataCount UInt32

Event ID 112: Failed to load metadata for publisher PublisherName (PublisherGuid).

#
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Description

Failed to load metadata for publisher PublisherName (PublisherGuid). The reason code is ErrorCode.

Message #

Failed to load metadata for publisher %2 (%1). The reason code is %3.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
ErrorCode UInt32

Event ID 200: Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.

#
Channel
Analytic
Task
ServiceUsageAudit

Message #

Channel %1 (%2) was enabled (%3) programmatically.

Fields #

NameDescription
ChannelName UnicodeString
ChannelType UInt8
Enabled Boolean

Event ID 201: A push subscription was created for ChannelName.

#
Channel
Analytic
Task
ServiceUsageAudit

Message #

A push subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 202: A pull subscription was created for ChannelName.

#
Channel
Analytic
Task
ServiceUsageAudit

Message #

A pull subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 203: OpenEventLog legacy API was used to open ModuleName.

#
Channel
Analytic
Level
Verbose
Task
ServiceUsageAudit

Message #

OpenEventLog legacy API was used to open %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 203,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 8580,
      "thread_id": 11800
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-Eventlog",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 00:04:15.990Z",
    "version": 0
  },
  "event_data": {
    "ModuleName": "System",
    "ModuleNameLen": 6
  },
  "message": ""
}

Event ID 204: RegisterEventSource legacy API was used to register ModuleName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
ServiceUsageAudit

Message #

RegisterEventSource legacy API was used to register %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "204",
    "version": "0",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.389555800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 205: ReportEvent legacy API was used to write an event to ModuleName.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
ServiceUsageAudit

Message #

ReportEvent legacy API was used to write an event to %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "205",
    "version": "1",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.390335800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 517: The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102).

#
Channel
Security

Description

Legacy security-log clear event from Windows 2000/XP/2003. Superseded by EventID 1102 in Vista+.

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqmicrosoft-windows-eventlog1 rulesigma

Event ID 1100: The event logging service has shut down.

#
Channel
Security
Level
Informational
Collection Priority
Recommended (JSCU-NL)
Task
Serviceshutdown

Fields #

NameDescription
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 1100,
    "version": 0,
    "level": 4,
    "task": 103,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-06-13T05:22:34.5804660+00:00",
    "event_record_id": 2929211,
    "correlation": {},
    "execution": {
      "process_id": 1468,
      "thread_id": 7088
    },
    "channel": "Security",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "ServiceShutdown": {}
  },
  "message": "The event logging service has shut down."
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk # view in coverage

References #

Event ID 1101: Audit events have been dropped by the transport.

#
Channel
Security
Level
Error
Task
Eventprocessing

Description

Audit events have been dropped by the transport. AuditEventsDropped.Reason.

Message #

Audit events have been dropped by the transport.  %1

Fields #

NameDescription
Reason UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1101,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-06T19:18:41.161306+00:00",
    "event_record_id": 13453892,
    "correlation": {},
    "execution": {
      "process_id": 1788,
      "thread_id": 2828
    },
    "channel": "Security",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AuditEventsDropped": {
      "Reason": 0
    }
  },
  "message": ""
}

References #

Event ID 1102: The audit log was cleared.

#
Channel
Security
Level
Informational
Collection Priority
Recommended (ASD, others)
Task
Logclear

Message #

The audit log was cleared.
Subject:
	Security ID: %1
	Account Name: %2
	Domain Name: %3
	Logon ID: %4

Fields #

NameDescription
LogFileCleared.SubjectUserSid
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.SubjectLogonId
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
ClientProcessId
ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 1102,
    "version": 0,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-05-28T00:50:56.9132673+00:00",
    "event_record_id": 1401962,
    "correlation": {},
    "execution": {
      "process_id": 1616,
      "thread_id": 3308
    },
    "channel": "Security",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1000",
      "SubjectUserName": "localuser",
      "SubjectDomainName": "cell-a",
      "SubjectLogonId": "0x196099a"
    }
  },
  "message": "The audit log was cleared.\r\nSubject:\r\n\tSecurity ID:\tS-1-5-21-1006758700-2167138679-1475694448-1000\r\n\tAccount Name:\tlocaluser\r\n\tDomain Name:\tcell-a\r\n\tLogon ID:\t0x196099A"
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_Nameeqmicrosoft-windows-eventlog1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto # view in coverage

  • Security Event log cleared source medium: Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.T1070
  • NRT Security Event log cleared source medium: Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.T1070

YARA-L # view in coverage

References #

Event ID 1103: The security log is now PercentFull percent full.

#
Channel
Security
Task
Eventprocessing

Message #

The security log is now %1 percent full.

Fields #

NameDescription
PercentFull UInt32

Event ID 1104: The security log is now full.

#
Channel
Security
Collection Priority
Recommended (Palantir)
Task
Eventprocessing

References #

Event ID 1105: Event log automatic backup.

#
Channel
Security
Task
Logautomaticbackup

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Channel UnicodeString
BackupPath UnicodeString

References #

Event ID 1106: Events have been dropped by the event logging service.

#
Channel
Security
Task
Eventprocessing

Description

Events have been dropped by the event logging service. The reason code is Reason.

Message #

Events have been dropped by the event logging service. The reason code is %1.

Fields #

NameDescription
Reason HexInt32

Event ID 1107: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Channel
Security
Level
Error
Task
Eventprocessing

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1107,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2016-08-18T16:53:04.313375Z",
    "event_record_id": 5538,
    "correlation": {},
    "execution": {
      "process_id": 716,
      "thread_id": 1128
    },
    "channel": "Security",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventPublisherMetaDataFailure": {
      "#attributes": {
        "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
        "xmlns": "http://manifests.microsoft.com/win/2004/08/windows/eventlog"
      },
      "Error": {
        "#attributes": {
          "Code": 15002
        }
      },
      "EventID": 0,
      "PublisherName": null,
      "PublisherGuid": "54849625-5478-4994-A5BA-3E3B0328C30D",
      "ProcessID": 0
    }
  }
}

References #

Event ID 1108: The event logging service encountered an error while processing an incoming event published from EventProcessingFailure.PublisherID.

#
Channel
Security
Level
Error
Task
Eventprocessing

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1108,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-12T03:08:47.632904+00:00",
    "event_record_id": 2761579,
    "correlation": {},
    "execution": {
      "process_id": 1916,
      "thread_id": 2348
    },
    "channel": "Security",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventProcessingFailure": {
      "ErrorCode": 15003,
      "EventID": 4688,
      "PublisherID": "Microsoft-Windows-Security-Auditing"
    }
  },
  "message": ""
}

References #

Event ID 6000: The Channel log file is full.

#
Channel
System

Message #

The %1 log file is full.

Fields #

NameDescription
Channel UnicodeString

Provenance

ETW provider GUID {FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}

Defined in wevtsvc.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4946, captured 2026-06-02 — Manifest XML pack, 2.0 MB