Microsoft-Windows-Security-Netlogon
31 events across 2 channels
Event ID 4004: Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
#Event ID 4005: Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
#Event ID 4006: Domain Controller Blocked: NTLM authentication to this domain controller is blocked.
#Event ID 4030: The DC DCName processed a network NTLM authentication involving an account from this domain.
#Description
The DC DCName processed a network NTLM authentication involving an account from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ForwarderType UnicodeString | |
ForwarderName UnicodeString | |
ForwarderDomain UnicodeString | |
ForwarderIP UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4030: The DC DCName processed a network NTLM authentication involving an account from this domain
#Description
The DC processed a network NTLM authentication involving an account from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ForwarderType UnicodeString | |
ForwarderName UnicodeString | |
ForwarderDomain UnicodeString | |
ForwarderIP UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4031: The DC DCName processed a network NTLM authentication involving an account from this domain.
#Description
The DC DCName processed a network NTLM authentication involving an account from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ForwarderType UnicodeString | |
ForwarderName UnicodeString | |
ForwarderDomain UnicodeString | |
ForwarderIP UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4031: The DC DCName processed a network NTLM authentication involving an account from this domain
#Description
The DC processed a network NTLM authentication involving an account from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ForwarderType UnicodeString | |
ForwarderName UnicodeString | |
ForwarderDomain UnicodeString | |
ForwarderIP UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4032: The DC DCName processed a forwarded NTLM authentication request originating from this domain.
#Description
The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ServerIP UnicodeString | |
ServerOS UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4032: The DC DCName processed a forwarded NTLM authentication request originating from this domain
#Description
The DC processed a forwarded NTLM authentication request originating from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ServerIP UnicodeString | |
ServerOS UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4033: The DC DCName processed a forwarded NTLM authentication request originating from this domain.
#Description
The DC DCName processed a forwarded NTLM authentication request originating from this domain.
Message #
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ServerIP UnicodeString | |
ServerOS UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 4033: The DC DCName processed a forwarded NTLM authentication request originating from this domain
#Description
The DC processed a forwarded NTLM authentication request originating from this domain.
Fields #
| Name | Description |
|---|---|
DCName UnicodeString | |
AccountName UnicodeString | |
AccountDomain UnicodeString | |
AccountMachine UnicodeString | |
ServerName UnicodeString | |
ServerDomain UnicodeString | |
ServerIP UnicodeString | |
ServerOS UnicodeString | |
NtlmVersion UnicodeString | |
ServiceBinding UnicodeString | |
TargetMachine UnicodeString | |
TargetDomain UnicodeString | |
MicStatus UnicodeString | |
AvFlags HexInt32 | |
AvFlagsStr UnicodeString | |
Status HexInt32 | NTSTATUS reference |
StatusMsg UInt32 |
Event ID 8004: Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
#Event ID 8005: Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
#Event ID 8006: Domain Controller Blocked Audit: Audit NTLM authentication to this domain controller.
#Event ID 9000: Netlogon failed to retrieve the password for account AccountName in domain AccountDomain.
#Description
Netlogon failed to retrieve the password for account AccountName in domain AccountDomain. Status.
Message #
Fields #
| Name | Description |
|---|---|
AccountName UnicodeString | |
AccountDomain UnicodeString | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"guid": "E5BA83F6-07D0-46B1-8BC7-7E669A1D31DC",
"event_source_name": "",
"event_id": 9000,
"version": 0,
"level": 2,
"task": 3,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:17:37.552321+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 968,
"thread_id": 7024
},
"channel": "Microsoft-Windows-Security-Netlogon/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"AccountName": ".\\domainadmin",
"AccountDomain": "NULL",
"Status": 3221225524
},
"message": ""
}
Event ID 9001: The account Account cannot be used as managed service account on the local machine because not all the supported encryption types of the account are sup...
#Event ID 9002: Netlogon failed to add Account as a managed service account to this local machine.
#Description
Netlogon failed to add Account as a managed service account to this local machine. Status.
Message #
Fields #
| Name | Description |
|---|---|
Account UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 9003: Netlogon failed to remove the managed service account Account from this local machine.
#Description
Netlogon failed to remove the managed service account Account from this local machine. Status.
Message #
Fields #
| Name | Description |
|---|---|
Account UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 9004: A total of RequestsRejected DC locator queries were rejected since the last reported event because they would have exceeded the configured maximum on concurrent ...
#Event ID 9005: Secure channel setup has failed with Kerberos: Status.
#Description
Secure channel setup has failed with Kerberos: Status. Falling back to Netlogon.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"event_id": 9005,
"level": 3,
"task": 5,
"opcode": 0,
"time_created": "2026-05-27T16:18:19.3522580+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Security-Netlogon"
},
"event_data": {
"Status": "3221225701"
}
}
Event ID 9006: Secure channel setup has failed : Status.
#Description
Secure channel setup has failed : Status. Protocol used: Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Protocol UnicodeString | Known values
|
Event ID 9007: Netlogon is currently configured to allow mailslot messages to be used when locating domain controllers.
#Description
Netlogon is currently configured to allow mailslot messages to be used when locating domain controllers. This mode is unsecure and will be deprecated and removed in a future release.
Message #
Event ID 9008: Netlogon is currently configured to listen for mailslot messages sent by clients during a domain controller location operation.
#Description
Netlogon is currently configured to listen for mailslot messages sent by clients during a domain controller location operation. This mode is unsecure and will be deprecated and removed in a future release. See https://aka.ms/dclocatornetbiosdeprecation for more information.
Message #
Event ID 9009: Netlogon was unable to find the domain name 'DomainName' using any of the known domain name mapping sources.
#Event ID 9010: Netlogon discovered a DC using the Netbios protocol.
#Event ID 9011: Netlogon successfully downloaded the latest administrator-configured domain name mappings.
#Description
Netlogon successfully downloaded the latest administrator-configured domain name mappings. Run 'nltest.exe /list_dclocmappings' to view the data.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"event_id": 9011,
"level": 4,
"task": 4,
"opcode": 0,
"time_created": "2026-05-27T16:39:09.7356702+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Security-Netlogon"
},
"event_data": {}
}
Event ID 9012: Netlogon failed to download the latest administrator-configured domain name mappings.
#Description
Netlogon failed to download the latest administrator-configured domain name mappings.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"event_id": 9012,
"level": 3,
"task": 4,
"opcode": 0,
"time_created": "2026-04-28T02:33:43.2316720+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Security-Netlogon"
},
"event_data": {}
}
Event ID 9013: Netlogon successfully downloaded the latest trusted-domain-based domain name mappings.
#Description
Netlogon successfully downloaded the latest trusted-domain-based domain name mappings. Run 'nltest.exe /list_dclocmappings' to view the data.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"event_id": 9013,
"level": 4,
"task": 4,
"opcode": 0,
"time_created": "2026-05-27T16:39:09.8609039+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Security-Netlogon"
},
"event_data": {}
}
Event ID 9014: Netlogon failed to download the latest trusted-domain-based domain name mappings.
#Description
Netlogon failed to download the latest trusted-domain-based domain name mappings.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Security-Netlogon",
"event_id": 9014,
"level": 3,
"task": 4,
"opcode": 0,
"time_created": "2026-04-28T02:33:43.2346256+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Security-Netlogon"
},
"event_data": {}
}
Event ID 9015: Netlogon denied an RPC call.
#Event ID 9016: Netlogon allowed an RPC call that normally would have been denied.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID e5ba83f6-07d0-46b1-8bc7-7e669a1d31dc
Defined in netlogon.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4050, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4946, captured 2026-06-02