Microsoft-Windows-Eventlog

41 events across 4 channels

EventTitleChannelSample
20The event logging service encountered an error ErrorCode while obtaining or …SystemN
21The event logging service encountered a configuration-related error …SystemN
22The event logging service encountered an error while initializing publishing …SystemN
23The event logging service encountered an error (res=ErrorCode) while …SystemN
25The event logging service encountered a corrupt log file for channel …SystemN
26The event logging service encountered a log file for channel ChannelPath which …SystemN
27The event logging service encountered an error (res=ErrorCode) while opening log …SystemN
28The event logging service encountered an error (res=ErrorCode) while parsing …SystemN
29The event logging service encountered a fatal error (res=ErrorCode) when …SystemN
30The event logging service encountered an error …SystemY
31The event logging service encountered an error (res=ErrorCode) while opening …SystemN
40The event logging service encountered an error when attempting to apply one or …SystemN
100The event logging service encountered an error while processing an incoming …AnalyticN
102The event logging service encountered an error while processing an incoming …AnalyticN
103Events have been dropped by the transport.AnalyticN
104The LogFileCleared.Channel log file was cleared.SystemY
105Event log automatic backup.SystemY
106Corruption was detected in the log for the Channel channel and some data was …SystemN
107The event logging service encountered an error ErrorCode while going through …AnalyticN
108The previous system shutdown was unexpected.SystemN
109The event logging service encountered an error while processing an incoming …AnalyticN
110Loading metadata for publisher PublisherName (PublisherGuid) and trying to …DebugN
111Finished loading metadata for publisher PublisherName (PublisherGuid), with …DebugN
112Failed to load metadata for publisher PublisherName (PublisherGuid).DebugN
200Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.AnalyticN
201A push subscription was created for ChannelName.AnalyticN
202A pull subscription was created for ChannelName.AnalyticN
203OpenEventLog legacy API was used to open ModuleName.AnalyticN
204RegisterEventSource legacy API was used to register ModuleName.AnalyticY
205ReportEvent legacy API was used to write an event to ModuleName.AnalyticY
517The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by …SecurityN
1100The event logging service has shut down.SecurityY
1101Audit events have been dropped by the transport.SecurityY
1102The audit log was cleared.SecurityY
1103The security log is now PercentFull percent full.SecurityN
1104The security log is now full.SecurityN
1105Event log automatic backup.SecurityN
1106Events have been dropped by the event logging service.SecurityN
1107The event logging service encountered an error while processing an incoming …SecurityY
1108The event logging service encountered an error while processing an incoming …SecurityY
6000The Channel log file is full.SystemN

Event ID 20: The event logging service encountered an error ErrorCode while obtaining or processing configuration for channel Path.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error ErrorCode while obtaining or processing configuration for channel Path.

Message #

The event logging service encountered an error %1 while obtaining or processing configuration for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 21: The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a configuration-related error (res=ErrorCode) for channel ChannelPath. The error was encountered while processing the ConfigProperty configuration property.

Message #

The event logging service encountered a configuration-related error (res=%1) for channel %2. The error was encountered while processing the %3 configuration property.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
ConfigProperty UnicodeString

Event ID 22: The event logging service encountered an error while initializing publishing resources for channel Path.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error while initializing publishing resources for channel Path. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Message #

The event logging service encountered an error while initializing publishing resources for channel %2. If channel type is Analytic or Debug, then this could mean there was an error initializing logging resources as well.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 23: The event logging service encountered an error (res=ErrorCode) while initializing logging resources for channel Path.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while initializing logging resources for channel Path.

Message #

The event logging service encountered an error (res=%1) while initializing logging resources for channel %2.

Fields #

NameDescription
ErrorCode UInt32
Path UnicodeString

Event ID 25: The event logging service encountered a corrupt log file for channel ChannelPath.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a corrupt log file for channel ChannelPath. The log was renamed with a .corrupt extension.

Message #

The event logging service encountered a corrupt log file for channel %1. The log was renamed with a .corrupt extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 26: The event logging service encountered a log file for channel ChannelPath which is an unsupported version.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered a log file for channel ChannelPath which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Message #

The event logging service encountered a log file for channel %1 which is an unsupported version. The log was renamed with a .UnsupportedVer extension.

Fields #

NameDescription
ChannelPath UnicodeString

Event ID 27: The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while opening log file for channel ChannelPath. Trying again using default log file path FailedLogFilePath.

Message #

The event logging service encountered an error (res=%1) while opening log file for channel %2. Trying again using default log file path %3.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
FailedLogFilePath UnicodeString
NewLogFilePath UnicodeString

Event ID 28: The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while parsing filter for channel ChannelPath. Will continue without filter.

Message #

The event logging service encountered an error (res=%1) while parsing filter for channel %2. Will continue without filter.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 29: The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel.

#
Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The event logging service encountered a fatal error (res=ErrorCode) when applying settings to the ChannelPath channel. The service is shutting down since this channel is vital to its operation.

Message #

The event logging service encountered a fatal error (res=%1) when applying settings to the %2 channel. The service is shutting down since this channel is vital to its operation.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 30: The event logging service encountered an error (InitChannelPublisherEnableFailure.ErrorCode) while enabling publisher InitChannelPublisherEnableFailure.PublisherGuid to channel InitChannelPublisher...

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Error
Task
Servicestartup

Description

The event logging service encountered an error (ErrorCode) while enabling publisher PublisherGuid to channel ChannelPath. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Message #

The event logging service encountered an error (%1) while enabling publisher %3 to channel %2. This does not affect channel operation, but does affect the ability of the publisher to raise events to the channel. One common reason for this error is that the Provider is using ETW Provider Security and has not granted enable permissions to the Event Log service identity.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString
PublisherGuid GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148",
    "event_source_name": "",
    "event_id": 30,
    "version": 0,
    "level": 2,
    "task": 100,
    "opcode": 0,
    "keywords": 9223372036854906880,
    "time_created": "2026-03-13T19:59:15.259008+00:00",
    "event_record_id": 11634,
    "correlation": {},
    "execution": {
      "process_id": 1844,
      "thread_id": 8176
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "user_data": {
    "InitChannelPublisherEnableFailure": {
      "ErrorCode": 5,
      "ChannelPath": "Microsoft-Windows-WinINet-Capture/Analytic",
      "PublisherGuid": "A70FF94F-570B-4979-BA5C-E59C9FEAB61B"
    }
  },
  "message": ""
}

Event ID 31: The event logging service encountered an error (res=ErrorCode) while opening configuration for primary channel ChannelPath.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
Servicestartup

Description

The event logging service encountered an error (res=ErrorCode) while opening configuration for primary channel ChannelPath. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Message #

The event logging service encountered an error (res=%1) while opening configuration for primary channel %2. Trying again using default configuration. This problem usually occurs if registry has been corrupted or explicitly misconfigured.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 40: The event logging service encountered an error when attempting to apply one or more policy settings.

#
Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The event logging service encountered an error when attempting to apply one or more policy settings.

Message #

The event logging service encountered an error when attempting to apply one or more policy settings.

Fields #

NameDescription
ErrorCode UInt32
ChannelPath UnicodeString

Event ID 100: The event logging service encountered an error while processing an incoming event published from PubID.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event published from PubID.

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Event ID 102: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Event ID 103: Events have been dropped by the transport.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

Events have been dropped by the transport. The session name is SessionName and the reason code is Reason.

Message #

Events have been dropped by the transport.  The session name is %2 and the reason code is %1.

Fields #

NameDescription
Reason UInt8
SessionName UnicodeString

Event ID 104: The LogFileCleared.Channel log file was cleared.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
Logclear

Description

The LogFileCleared.Channel log file was cleared.

Message #

The %3 log file was cleared.

Fields #

NameDescriptionRules
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.Channel
LogFileCleared.BackupPath
SubjectUserName
SubjectDomainName
Channel12 detection rules
BackupPath
ClientProcessId
ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-28T00:50:57.4445174+00:00",
    "event_record_id": 6146,
    "correlation": {},
    "execution": {
      "process_id": 1616,
      "thread_id": 3308
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1000"
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserName": "localuser",
      "SubjectDomainName": "cell-a",
      "Channel": "Windows PowerShell",
      "BackupPath": ""
    }
  },
  "message": "The Windows PowerShell log file was cleared."
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_NameeqMicrosoft-Windows-Eventlog2 rulessigma

Community Notes #

This will show System, Application, and other non-Security logs being cleared. Review the event to identify which one.

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 105: Event log automatic backup.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Level
Informational
Task
Logautomaticbackup

Description

Event log automatic backup.

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Channel
BackupPath

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 105,
    "version": 0,
    "level": 4,
    "task": 105,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2012-03-26T05:50:08.470644Z",
    "event_record_id": 13049,
    "correlation": {},
    "execution": {
      "process_id": 772,
      "thread_id": 4256
    },
    "channel": "System",
    "computer": "WKS-WIN764BITB.shieldbase.local",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AutoBackup": {
      "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
      "Channel": "Application",
      "BackupPath": "C:\\Windows\\System32\\Winevt\\Logs\\Archive-Application-2012-03-26-05-50-01-755.evtx"
    }
  }
}

Event ID 106: Corruption was detected in the log for the Channel channel and some data was erased.

#
Provider
Microsoft-Windows-Eventlog
Channel
System

Description

Corruption was detected in the log for the Channel channel and some data was erased.

Message #

Corruption was detected in the log for the %1 channel and some data was erased.

Fields #

NameDescription
Channel UnicodeString

Event ID 107: The event logging service encountered an error ErrorCode while going through publisher configuration.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic

Description

The event logging service encountered an error ErrorCode while going through publisher configuration. The publisher ProviderName is already installed with GUID PublisherGuid.

Message #

The event logging service encountered an error %1 while going through publisher configuration. The publisher %2 is already installed with GUID %3.

Fields #

NameDescription
ErrorCode UInt32
ProviderName UnicodeString
PublisherGuid GUID

Event ID 108: The previous system shutdown was unexpected.

#
Provider
Microsoft-Windows-Eventlog
Channel
System
Task
SystemAbnormalShutdown

Description

The previous system shutdown was unexpected.

Message #

The previous system shutdown was unexpected.

Fields #

NameDescription
ShutdownTime SYSTEMTIME
ActualMaxInterval UInt32
DiskPmDisabledMaxInterval UInt32
DiskPmEnabledFlag UInt32
DiskPmEnabledMaxInterval UInt32
TimestampForced UInt32
DiskPmPolicy UInt32
BiasValid UInt32
StartBias UInt32

Event ID 109: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32
EventName UnicodeString

Event ID 110: Loading metadata for publisher PublisherName (PublisherGuid) and trying to process the metadata for it.

#
Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Start

Description

Loading metadata for publisher PublisherName (PublisherGuid) and trying to process the metadata for it.

Message #

Loading metadata for publisher %2 (%1) and trying to process the metadata for it.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString

Event ID 111: Finished loading metadata for publisher PublisherName (PublisherGuid), with EventMetaDataCount event metadatas processed.

#
Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Description

Finished loading metadata for publisher PublisherName (PublisherGuid), with EventMetaDataCount event metadatas processed.

Message #

Finished loading metadata for publisher %2 (%1), with %3 event metadatas processed.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
EventMetaDataCount UInt32

Event ID 112: Failed to load metadata for publisher PublisherName (PublisherGuid).

#
Provider
Microsoft-Windows-Eventlog
Channel
Debug
Task
Eventprocessing
Opcode
Stop

Description

Failed to load metadata for publisher PublisherName (PublisherGuid). The reason code is ErrorCode.

Message #

Failed to load metadata for publisher %2 (%1). The reason code is %3.

Fields #

NameDescription
PublisherGuid GUID
PublisherName UnicodeString
ErrorCode UInt32

Event ID 200: Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

Channel ChannelName (ChannelType) was enabled (Enabled) programmatically.

Message #

Channel %1 (%2) was enabled (%3) programmatically.

Fields #

NameDescription
ChannelName UnicodeString
ChannelType UInt8
Enabled Boolean

Event ID 201: A push subscription was created for ChannelName.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

A push subscription was created for ChannelName.

Message #

A push subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 202: A pull subscription was created for ChannelName.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

A pull subscription was created for ChannelName.

Message #

A pull subscription was created for %1.

Fields #

NameDescription
ChannelName UnicodeString
Query UnicodeString

Event ID 203: OpenEventLog legacy API was used to open ModuleName.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Task
ServiceUsageAudit

Description

OpenEventLog legacy API was used to open ModuleName.

Message #

OpenEventLog legacy API was used to open %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Event ID 204: RegisterEventSource legacy API was used to register ModuleName.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
ServiceUsageAudit

Description

RegisterEventSource legacy API was used to register ModuleName.

Message #

RegisterEventSource legacy API was used to register %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "204",
    "version": "0",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.389555800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 205: ReportEvent legacy API was used to write an event to ModuleName.

#
Provider
Microsoft-Windows-Eventlog
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose
Task
ServiceUsageAudit

Description

ReportEvent legacy API was used to write an event to ModuleName.

Message #

ReportEvent legacy API was used to write an event to %2.

Fields #

NameDescription
ModuleNameLen UInt8
ModuleName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": "205",
    "version": "1",
    "level": "5",
    "task": "109",
    "opcode": "0",
    "keywords": 576460752304472064,
    "time_created": "2026-03-15T04:33:36.390335800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{00102311-0000-0000-0000-0000bebcad59}"
    },
    "execution": {
      "process_id": "5820",
      "thread_id": "8064"
    },
    "channel": "Microsoft-Windows-EventLog/Analytic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ModuleNameLen": "10",
    "ModuleName": "PowerShell"
  },
  "message": ""
}

Event ID 517: The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102).

#
Provider
Microsoft-Windows-Eventlog
Channel
Security

Description

Legacy security-log clear event from Windows 2000/XP/2003. Superseded by EventID 1102 in Vista+.

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Provider_NameeqMicrosoft-Windows-Eventlog1 rulesigma

Event ID 1100: The event logging service has shut down.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Informational
Collection Priority
Recommended (JSCU-NL)
Task
Serviceshutdown

Description

The event logging service has shut down.

Message #

The event logging service has shut down.

Fields #

NameDescription
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 1100,
    "version": 0,
    "level": 4,
    "task": 103,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-06-13T05:22:34.5804660+00:00",
    "event_record_id": 2929211,
    "correlation": {},
    "execution": {
      "process_id": 1468,
      "thread_id": 7088
    },
    "channel": "Security",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "ServiceShutdown": {}
  },
  "message": "The event logging service has shut down."
}

Detection Rules #

View all rules referencing this event →

Splunk # view in coverage

  • Windows Event Logging Service Has Shutdown source: The following analytic detects the shutdown of the Windows Event Log service by leveraging Windows Event ID 1100. This event is logged every time the service stops, including during normal system shutdowns. Monitoring this activity is…

References #

Event ID 1101: Audit events have been dropped by the transport.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

Audit events have been dropped by the transport. AuditEventsDropped.Reason.

Message #

Audit events have been dropped by the transport.  %1

Fields #

NameDescription
Reason UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1101,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-06T19:18:41.161306+00:00",
    "event_record_id": 13453892,
    "correlation": {},
    "execution": {
      "process_id": 1788,
      "thread_id": 2828
    },
    "channel": "Security",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "AuditEventsDropped": {
      "Reason": 0
    }
  },
  "message": ""
}

References #

Event ID 1102: The audit log was cleared.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Informational
Collection Priority
Recommended (ASD, others)
Task
Logclear

Description

The audit log was cleared.

Message #

The audit log was cleared.
Subject:
	Security ID: %1
	Account Name: %2
	Domain Name: %3
	Logon ID: %4

Fields #

NameDescription
LogFileCleared.SubjectUserSid
LogFileCleared.SubjectUserName
LogFileCleared.SubjectDomainName
LogFileCleared.SubjectLogonId
SubjectUserSid
SubjectUserName
SubjectDomainName
SubjectLogonId
ClientProcessId
ClientProcessStartKey

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}",
    "event_source_name": "",
    "event_id": 1102,
    "version": 0,
    "level": 4,
    "task": 104,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-05-28T00:50:56.9132673+00:00",
    "event_record_id": 1401962,
    "correlation": {},
    "execution": {
      "process_id": 1616,
      "thread_id": 3308
    },
    "channel": "Security",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "LogFileCleared": {
      "SubjectUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1000",
      "SubjectUserName": "localuser",
      "SubjectDomainName": "cell-a",
      "SubjectLogonId": "0x196099a"
    }
  },
  "message": "The audit log was cleared.\r\nSubject:\r\n\tSecurity ID:\tS-1-5-21-1006758700-2167138679-1475694448-1000\r\n\tAccount Name:\tlocaluser\r\n\tDomain Name:\tcell-a\r\n\tLogon ID:\t0x196099A"
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
CategoryeqMicrosoft-Windows-Eventlog2 ruleskusto
Provider_NameeqMicrosoft-Windows-Eventlog1 rulesigma

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

  • Security Event log cleared source medium: Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.
  • NRT Security Event log cleared source medium: Checks for event id 1102 which indicates the security event log was cleared. It uses Event Source Name "Microsoft-Windows-Eventlog" to avoid generating false positives from other sources, like AD FS servers for instance.

YARA-L # view in coverage

References #

Event ID 1103: The security log is now PercentFull percent full.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Eventprocessing

Description

The security log is now PercentFull percent full.

Message #

The security log is now %1 percent full.

Fields #

NameDescription
PercentFull UInt32

Event ID 1104: The security log is now full.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Collection Priority
Recommended (Palantir)
Task
Eventprocessing

Description

The security log is now full.

Message #

The security log is now full.

References #

Event ID 1105: Event log automatic backup.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Logautomaticbackup

Description

Event log automatic backup.

Message #

Event log automatic backup
	Log: %1
	File: %2

Fields #

NameDescription
Channel UnicodeString
BackupPath UnicodeString

References #

Event ID 1106: Events have been dropped by the event logging service.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Task
Eventprocessing

Description

Events have been dropped by the event logging service. The reason code is Reason.

Message #

Events have been dropped by the event logging service. The reason code is %1.

Fields #

NameDescription
Reason HexInt32

Event ID 1107: The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event from publisher PublisherName and trying to process the metadata for it.

Message #

The event logging service encountered an error while processing an incoming event from publisher %3 and trying to process the metadata for it.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PublisherName UnicodeString
PublisherGuid GUID
ProcessID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1107,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2016-08-18T16:53:04.313375Z",
    "event_record_id": 5538,
    "correlation": {},
    "execution": {
      "process_id": 716,
      "thread_id": 1128
    },
    "channel": "Security",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventPublisherMetaDataFailure": {
      "#attributes": {
        "xmlns:auto-ns3": "http://schemas.microsoft.com/win/2004/08/events",
        "xmlns": "http://manifests.microsoft.com/win/2004/08/windows/eventlog"
      },
      "Error": {
        "#attributes": {
          "Code": 15002
        }
      },
      "EventID": 0,
      "PublisherName": null,
      "PublisherGuid": "54849625-5478-4994-A5BA-3E3B0328C30D",
      "ProcessID": 0
    }
  }
}

References #

Event ID 1108: The event logging service encountered an error while processing an incoming event published from EventProcessingFailure.PublisherID.

#
Provider
Microsoft-Windows-Eventlog
Channel
Security
Level
Error
Task
Eventprocessing

Description

The event logging service encountered an error while processing an incoming event published from EventProcessingFailure.PublisherID.

Message #

The event logging service encountered an error while processing an incoming event published from %3.

Fields #

NameDescription
ErrorCode UInt32
EventID UInt16
PubID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Eventlog",
    "guid": "{fc65ddd8-d6ef-4962-83d5-6e5cfe9ce148}",
    "event_source_name": "",
    "event_id": 1108,
    "version": 0,
    "level": 2,
    "task": 101,
    "opcode": 0,
    "keywords": 4620693217682128896,
    "time_created": "2026-03-12T03:08:47.632904+00:00",
    "event_record_id": 2761579,
    "correlation": {},
    "execution": {
      "process_id": 1916,
      "thread_id": 2348
    },
    "channel": "Security",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventProcessingFailure": {
      "ErrorCode": 15003,
      "EventID": 4688,
      "PublisherID": "Microsoft-Windows-Security-Auditing"
    }
  },
  "message": ""
}

References #

Event ID 6000: The Channel log file is full.

#
Provider
Microsoft-Windows-Eventlog
Channel
System

Description

The Channel log file is full.

Message #

The %1 log file is full.

Fields #

NameDescription
Channel UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {FC65DDD8-D6EF-4962-83D5-6E5CFE9CE148}

Defined in wevtsvc.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4946, captured 2026-06-02

Downloads