Microsoft-Windows-IIS-IisMetabaseAudit
13 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 4500 | Metabase Add Key. | Operational | N |
| 4501 | Metabase Delete Key. | Operational | N |
| 4502 | Metabase Delete Child Keys. | Operational | N |
| 4503 | Metabase Copy Key. | Operational | N |
| 4504 | Metabase Rename Key. | Operational | N |
| 4505 | Metabase Set Data. | Operational | N |
| 4506 | Metabase Delete Data. | Operational | N |
| 4507 | Metabase Delete All Data. | Operational | N |
| 4508 | Metabase Copy Data. | Operational | N |
| 4509 | Metabase Set Last Change Time. | Operational | N |
| 4510 | Metabase Restore. | Operational | N |
| 4511 | Metabase Delete Backup. | Operational | N |
| 4512 | Metabase Import. | Operational | N |
Event ID 4500: Metabase Add Key.
#Event ID 4501: Metabase Delete Key.
#Event ID 4502: Metabase Delete Child Keys.
#Event ID 4503: Metabase Copy Key.
#Event ID 4504: Metabase Rename Key.
#Event ID 4505: Metabase Set Data.
#Description
Metabase Set Data.
Message #
Fields #
| Name | Description |
|---|---|
UserName UnicodeString | |
Domain UnicodeString | |
LogonID UnicodeString | |
MetabasePath UnicodeString | |
PropertyID UnicodeString | |
PropertyName UnicodeString | |
OldValue UnicodeString | |
NewValue UnicodeString | |
CallerPID UnicodeString | |
CallerImagePath UnicodeString | |
Result UnicodeString |
Event ID 4506: Metabase Delete Data.
#Event ID 4507: Metabase Delete All Data.
#Event ID 4508: Metabase Copy Data.
#Event ID 4509: Metabase Set Last Change Time.
#Event ID 4510: Metabase Restore.
#Event ID 4511: Metabase Delete Backup.
#Event ID 4512: Metabase Import.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID bbb924b8-f415-4f57-aa45-1007f704c9b1
Defined in iisres.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02