Microsoft-Windows-Winlogon

151 events across 4 channels

EventTitleChannelSample
1Authentication started.OperationalY
2Authentication stopped.OperationalY
3UpdatePerUserSystemParametersStartDiagnosticN
4UpdatePerUserSystemParametersStopDiagnosticN
5CheckWindowsLicenseStatusStartDiagnosticN
6CheckWindowsLicenseStatusStopDiagnosticN
7RestoringNetConnectionsStartDiagnosticN
8RestoringNetConnectionsStopDiagnosticN
9ExecuteShellCommandListStartDiagnosticN
10ExecuteShellCommandListStopDiagnosticN
11ThemesOnLogonPreStartDiagnosticN
12ThemesOnLogonPreStopDiagnosticN
13ThemesOnLogonPostStartDiagnosticN
14ThemesOnLogonPostStopDiagnosticN
51ThemesOnLogoffStartDiagnosticN
52ThemesOnLogoffStopDiagnosticN
61DwmpCreateSessionProcessStartDiagnosticN
62DwmpCreateSessionProcessStopDiagnosticN
64DwmpTerminateSessionProcessStartDiagnosticN
65DwmpTerminateSessionProcessStopDiagnosticN
67DwmpNotifyUserLogonStartDiagnosticN
68DwmpNotifyUserLogonStopDiagnosticN
70ThemesOnEarlyCreateSessionStartDiagnosticN
71ThemesOnEarlyCreateSessionStopDiagnosticN
72DwmpNotifyUserLogoffStartDiagnosticN
73DwmpNotifyUserLogoffStopDiagnosticN
101CreatePrimaryTerminalStartDiagnosticN
102CreatePrimaryTerminalStopDiagnosticN
103StartLogonUIStartDiagnosticN
104StartLogonUIStopDiagnosticN
105RunStateMachineStartDiagnosticN
106RunStateMachineStopDiagnosticN
107WaitForLSMStartDiagnosticN
108WaitForLSMStopDiagnosticN
201DisplayWelcomeScreenStartDiagnosticN
202DisplayWelcomeScreenStopDiagnosticN
203RequestCredentialsStartDiagnosticN
204RequestCredentialsStopDiagnosticN
205ThemesOnCreateSessionStartDiagnosticN
206ThemesOnCreateSessionStopDiagnosticN
207ThemesOnTerminateSessionStartDiagnosticN
208ThemesOnTerminateSessionStopDiagnosticN
301ReceivedLogoffRequestDiagnosticN
401ShutdownWindowsStartDiagnosticN
402ShutdownWindowsStopDiagnosticN
403InitiateShutdownStartDiagnosticN
404InitiateShutdownStopDiagnosticN
501WluiServerStartupStartDiagnosticN
502WluiServerStartupStopDiagnosticN
503WluiServerShutdownStartDiagnosticN
504WluiServerShutdownStopDiagnosticN
505WluiServerStartupOperationalN
801NotifyExecuteStartDiagnosticN
802NotifyExecuteStopDiagnosticN
803NotifyServicesStartDiagnosticN
804NotifyServicesStopDiagnosticN
805NotifySubscriberStartDiagnosticN
806NotifySubscriberStopDiagnosticN
807NotifySubscriberNotificationPendedDiagnosticN
808NotifySubscriberNotificationFailedDiagnosticN
809ConnectToSubscriberStartDiagnosticN
810ConnectToSubscriberStopDiagnosticN
811The winlogon notification subscriber <SubscriberName> began handling the …OperationalY
812The winlogon notification subscriber <SubscriberName> finished handling the …OperationalY
1001Logon hours expiration warning.OperationalN
1002The shell stopped unexpectedly and Data_0 was restartedApplicationY
1002The shell stopped unexpectedly and %1 was restartedOperationalY
1101The computer will be locked because the user has exceeded the maximum number of …OperationalN
1102The computer will be rebooted because the user has exceeded the maximum number …OperationalN
1103The user is approaching the threshold for maximum number of failed logon …OperationalN
1104Encryption Provider initialization failed.OperationalN
4002The logon hours restriction policy is applied to the logged on userOperationalN
4003The Windows logon process has failed to switch the desktopOperationalN
4004The Windows logon process has failed to terminate the currently logged on user's …ApplicationY
4004The Windows logon process has failed to terminate the currently logged on user's …OperationalN
4005The Windows logon process has unexpectedly terminatedOperationalN
4006The Windows logon process has failed to spawn a user applicationOperationalN
4007The Windows logon process has failed to disconnect the user sessionOperationalN
4008The Windows logon process has failed to connect the user sessionOperationalN
4101Windows license validated.ApplicationY
4101Windows license validatedOperationalN
4102Windows license is invalidOperationalN
4103Windows license activation failedOperationalN
4104Accessing Windows in Notification periodApplicationY
4104Accessing Windows in Notification periodOperationalN
4105Windows is in Notification periodApplicationY
4105Windows is in Notification periodOperationalN
5001UserBootStartDiagnosticN
5002UserBootStopDiagnosticN
5003UserBootDiagnosticN
5005UserShellLaunchDiagnosticN
5007SystemBootStop_V2DiagnosticN
6000The winlogon notification subscriber <SessionEnv> was unavailable to handle a …ApplicationY
6000The winlogon notification subscriber <Data_0> was unavailable to handle a …OperationalY
6001The winlogon notification subscriber <SessionEnv> failed a notification event.ApplicationY
6001The winlogon notification subscriber <Flags> failed a notification eventDiagnosticN
6002The winlogon notification subscriber registration database cannot be loadedOperationalN
6003The winlogon notification subscriber <SessionEnv> was unavailable to handle a …ApplicationY
6003The winlogon notification subscriber <Data_0> was unavailable to handle a …OperationalY
6004The winlogon notification subscriber <TrustedInstaller> failed a critical …ApplicationY
6004The winlogon notification subscriber <Data_0> failed a critical notification …OperationalY
6005The winlogon notification subscriber <GPClient> is taking long time to handle …ApplicationY
6005The winlogon notification subscriber <Data_0> is taking long time to handle the …OperationalY
6006The winlogon notification subscriber <GPClient> took 119 second(s) to handle the …ApplicationY
6006The winlogon notification subscriber <Data_0> took Data_1 second(s) to handle …OperationalY
6101LogoffRequestToUserFeedbackStartDiagnosticN
6102LogoffRequestToUserFeedbackStopDiagnosticN
6103LogoffAppsTerminationToSessionEndStartDiagnosticN
6104LogoffAppsTerminationToSessionEndStopDiagnosticN
6105UnlockStartDiagnosticN
6106UnlockStopDiagnosticN
6107UnlockStop6107DiagnosticN
6108LogonStartDiagnosticN
6109LogonStopDiagnosticN
6110LogonStop6110DiagnosticN
6111LogonStop6111DiagnosticN
6112LogonStop6112DiagnosticN
6113LockStartDiagnosticN
6114LockStopDiagnosticN
6115LockStop6115DiagnosticN
6116LogoffDiagnosticN
6117DelayLockDisplayLockScreenDiagnosticN
6118KillingScreenSaverToLockWorkStationDiagnosticN
6119AutomaticRestartSignOnDiagnosticN
6120HotKeyLockDesktopInvokedDiagnosticN
6121PINResetLogonDiagnosticN
6122PINResetUnlockDiagnosticN
6123AssignedAccessLogonDiagnosticN
6124AssignedAccessUnlockDiagnosticN
7001User Logon Notification for Customer Experience Improvement ProgramSystemY
7002User Logoff Notification for Customer Experience Improvement ProgramSystemY
1073742826The shell stopped unexpectedly and %1 was restarted.OperationalY
1073745826The logon hours restriction policy is applied to the logged on user.OperationalN
1073745925Windows license validated.OperationalN
1073745928Accessing Windows in Notification period.OperationalN
2147487654The Windows logon process has failed to spawn a user application.OperationalN
2147487655The Windows logon process has failed to disconnect the user session.OperationalN
2147487656The Windows logon process has failed to connect the user session.OperationalN
2147487753Windows is in Notification period.OperationalN
2147489648The winlogon notification subscriber <.OperationalY
2147489649The winlogon notification subscriber <.OperationalN
2147489650The winlogon notification subscriber registration database cannot be loaded.OperationalN
2147489651The winlogon notification subscriber <.OperationalN
2147489652The winlogon notification subscriber <.OperationalN
2147489653The winlogon notification subscriber <.OperationalY
2147489654The winlogon notification subscriber <.OperationalY
3221229475The Windows logon process has failed to switch the desktop.OperationalN
3221229476The Windows logon process has failed to terminate the currently logged on user's …OperationalN
3221229477The Windows logon process has unexpectedly terminated.OperationalN
3221229574Windows license is invalid.OperationalN
3221229575Windows license activation failed.OperationalN

Event ID 1: Authentication started.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
AuthenticateUser
Opcode
Start

Description

Authentication started.

Message #

Authentication started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": 4611721202799542272,
    "time_created": "2026-05-29T16:33:48.0082811+00:00",
    "event_record_id": 533,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 1104
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Authentication started."
}

Event ID 2: Authentication stopped.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
AuthenticateUser
Opcode
Stop

Description

Authentication stopped. Result Win32Status.

Message #

Authentication stopped. Result %1

Fields #

NameDescription
Win32Status UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": 4611721202799542272,
    "time_created": "2026-05-29T16:33:48.1550444+00:00",
    "event_record_id": 534,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 1104
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Win32Status": "0"
  },
  "message": "Authentication stopped. Result 0"
}

Event ID 3: UpdatePerUserSystemParametersStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UpdatePerUserSystemParameters
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 4: UpdatePerUserSystemParametersStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UpdatePerUserSystemParameters
Opcode
Stop

Fields #

NameDescription
Flags UInt32

Event ID 5: CheckWindowsLicenseStatusStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CheckWindowsLicenseStatus
Opcode
Start

Event ID 6: CheckWindowsLicenseStatusStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CheckWindowsLicenseStatus
Opcode
Stop

Event ID 7: RestoringNetConnectionsStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RestoringNetConnections
Opcode
Start

Event ID 8: RestoringNetConnectionsStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RestoringNetConnections
Opcode
Stop

Event ID 9: ExecuteShellCommandListStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ExecuteShellCommandList
Opcode
Start

Fields #

NameDescription
CommandList UnicodeString

Event ID 10: ExecuteShellCommandListStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ExecuteShellCommandList
Opcode
Stop

Event ID 11: ThemesOnLogonPreStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPre
Opcode
Start

Event ID 12: ThemesOnLogonPreStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPre
Opcode
Stop

Event ID 13: ThemesOnLogonPostStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPost
Opcode
Start

Event ID 14: ThemesOnLogonPostStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogonPost
Opcode
Stop

Event ID 51: ThemesOnLogoffStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogoff
Opcode
Start

Event ID 52: ThemesOnLogoffStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnLogoff
Opcode
Stop

Event ID 61: DwmpCreateSessionProcessStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpCreateSessionProcess
Opcode
Start

Event ID 62: DwmpCreateSessionProcessStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpCreateSessionProcess
Opcode
Stop

Event ID 64: DwmpTerminateSessionProcessStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpTerminateSessionProcess
Opcode
Start

Event ID 65: DwmpTerminateSessionProcessStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpTerminateSessionProcess
Opcode
Stop

Event ID 67: DwmpNotifyUserLogonStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogon
Opcode
Start

Event ID 68: DwmpNotifyUserLogonStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogon
Opcode
Stop

Event ID 70: ThemesOnEarlyCreateSessionStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnEarlyCreateSession
Opcode
Start

Event ID 71: ThemesOnEarlyCreateSessionStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnEarlyCreateSession
Opcode
Stop

Event ID 72: DwmpNotifyUserLogoffStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogoff
Opcode
Start

Event ID 73: DwmpNotifyUserLogoffStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DwmpNotifyUserLogoff
Opcode
Stop

Event ID 101: CreatePrimaryTerminalStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CreatePrimaryTerminal
Opcode
Start

Event ID 102: CreatePrimaryTerminalStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
CreatePrimaryTerminal
Opcode
Stop

Event ID 103: StartLogonUIStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
StartLogonUI
Opcode
Start

Event ID 104: StartLogonUIStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
StartLogonUI
Opcode
Stop

Event ID 105: RunStateMachineStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RunStateMachine
Opcode
Start

Event ID 106: RunStateMachineStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RunStateMachine
Opcode
Stop

Event ID 107: WaitForLSMStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WaitForLSM
Opcode
Start

Event ID 108: WaitForLSMStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WaitForLSM
Opcode
Stop

Event ID 201: DisplayWelcomeScreenStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DisplayWelcomeScreen
Opcode
Start

Event ID 202: DisplayWelcomeScreenStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DisplayWelcomeScreen
Opcode
Stop

Event ID 203: RequestCredentialsStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RequestCredentials
Opcode
Start

Event ID 204: RequestCredentialsStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
RequestCredentials
Opcode
Stop

Event ID 205: ThemesOnCreateSessionStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnCreateSession
Opcode
Start

Event ID 206: ThemesOnCreateSessionStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnCreateSession
Opcode
Stop

Event ID 207: ThemesOnTerminateSessionStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnTerminateSession
Opcode
Start

Event ID 208: ThemesOnTerminateSessionStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ThemesOnTerminateSession
Opcode
Stop

Event ID 301: ReceivedLogoffRequest

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ReceivedLogoffRequest

Fields #

NameDescription
Flags UInt32

Event ID 401: ShutdownWindowsStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 402: ShutdownWindowsStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownWindows
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 403: InitiateShutdownStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
InitiateShutdown
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 404: InitiateShutdownStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
InitiateShutdown
Opcode
Stop

Fields #

NameDescription
Win32Status UInt32

Event ID 501: WluiServerStartupStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerStartup
Opcode
Start

Event ID 502: WluiServerStartupStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerStartup
Opcode
Stop

Event ID 503: WluiServerShutdownStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerShutdown
Opcode
Start

Event ID 504: WluiServerShutdownStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
WluiServerShutdown
Opcode
Stop

Event ID 505: WluiServerStartup

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
WluiServerStartup

Event ID 801: NotifyExecuteStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyExecute
Opcode
Start

Fields #

NameDescription
Event UInt32

Event ID 802: NotifyExecuteStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyExecute
Opcode
Stop

Fields #

NameDescription
Event UInt32

Event ID 803: NotifyServicesStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyServices
Opcode
Start

Fields #

NameDescription
EventCode UInt32
SessionId UInt32

Event ID 804: NotifyServicesStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifyServices
Opcode
Stop

Fields #

NameDescription
EventCode UInt32
SessionId UInt32

Event ID 805: NotifySubscriberStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
Start

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Event ID 806: NotifySubscriberStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
Stop

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Event ID 807: NotifySubscriberNotificationPended

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
NotificationPended

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString
Message UnicodeString

Event ID 808: NotifySubscriberNotificationFailed

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
NotifySubscriber
Opcode
NotificationFailed

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString
Message UnicodeString

Event ID 809: ConnectToSubscriberStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ConnectToSubscriber
Opcode
Start

Fields #

NameDescription
SubscriberName UnicodeString

Event ID 810: ConnectToSubscriberStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ConnectToSubscriber
Opcode
Stop

Fields #

NameDescription
SubscriberName UnicodeString

Event ID 811: The winlogon notification subscriber <SubscriberName> began handling the notification event (Event).

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
CallSubscriber
Opcode
Start

Description

The winlogon notification subscriber <SubscriberName> began handling the notification event (Event).

Message #

The winlogon notification subscriber <%2> began handling the notification event (%1).

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 811,
    "version": 0,
    "level": 4,
    "task": 811,
    "opcode": 1,
    "keywords": 4611686018427453440,
    "time_created": "2026-05-29T16:33:57.4787633+00:00",
    "event_record_id": 553,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 1104
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Event": "12",
    "SubscriberName": "TermSrv"
  },
  "message": "The winlogon notification subscriber <TermSrv> began handling the notification event (12)."
}

Event ID 812: The winlogon notification subscriber <SubscriberName> finished handling the notification event (Event).

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
Informational
Task
CallSubscriber
Opcode
Stop

Description

The winlogon notification subscriber <SubscriberName> finished handling the notification event (Event).

Message #

The winlogon notification subscriber <%2> finished handling the notification event (%1).

Fields #

NameDescription
Event UInt32
SubscriberName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 812,
    "version": 0,
    "level": 4,
    "task": 811,
    "opcode": 2,
    "keywords": 4611686018427453440,
    "time_created": "2026-05-29T16:33:57.4792609+00:00",
    "event_record_id": 554,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 1104
    },
    "channel": "Microsoft-Windows-Winlogon/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Event": "12",
    "SubscriberName": "TermSrv"
  },
  "message": "The winlogon notification subscriber <TermSrv> finished handling the notification event (12)."
}

Event ID 1001: Logon hours expiration warning.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
LogonHours

Description

Logon hours expiration warning.

Message #

Logon hours expiration warning.

Fields #

NameDescription
ActionId UInt32
TimeLeft UInt32

Event ID 1002: The shell stopped unexpectedly and Data_0 was restarted

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data_0
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 1002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T23:53:34.619082+00:00",
    "event_record_id": 1811,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "explorer.exe",
    "Binary": ""
  },
  "message": ""
}

References #

Event ID 1002: The shell stopped unexpectedly and %1 was restarted

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "event_id": 1002,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-15T03:00:56.5858172+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1101: The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer. A recovery key is required to unlock the device.

Message #

The computer will be locked because the user has exceeded the maximum number of failed logon attempts allowed on this computer. A recovery key is required to unlock the device.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1102: The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.

Message #

The computer will be rebooted because the user has exceeded the maximum number of failed logon attempts allowed on this computer.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1103: The user is approaching the threshold for maximum number of failed logon attempts.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

The user is approaching the threshold for maximum number of failed logon attempts. Once the maximum limit is reached the computer will be locked or rebooted.

Message #

The user is approaching the threshold for maximum number of failed logon attempts. Once the maximum limit is reached the computer will be locked or rebooted.
UserSid: %1 
UserName: %2 
UserDomain: %3

Fields #

NameDescription
UserSid SID
UserName UnicodeString
UserDomain UnicodeString

Event ID 1104: Encryption Provider initialization failed.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Task
EAS

Description

Encryption Provider initialization failed. Error Win32Status.

Message #

Encryption Provider initialization failed. Error %1

Fields #

NameDescription
Win32Status UInt32

Event ID 4002: The logon hours restriction policy is applied to the logged on user

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4003: The Windows logon process has failed to switch the desktop

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4004: The Windows logon process has failed to terminate the currently logged on user's processes

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4004,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2016-08-21T21:00:34.000000Z",
    "event_record_id": 1596,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE10Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4004: The Windows logon process has failed to terminate the currently logged on user's processes

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4005: The Windows logon process has unexpectedly terminated

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4006: The Windows logon process has failed to spawn a user application

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4007: The Windows logon process has failed to disconnect the user session

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4008: The Windows logon process has failed to connect the user session

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4101: Windows license validated.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4101,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T17:51:18+00:00",
    "event_record_id": 232,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "0x00000000",
      "0x00000001"
    ]
  },
  "message": "Windows license validated."
}

References #

Event ID 4101: Windows license validated

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4102: Windows license is invalid

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4103: Windows license activation failed

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4104: Accessing Windows in Notification period

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4104,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2014-11-21T23:44:00.000000Z",
    "event_record_id": 812,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4104: Accessing Windows in Notification period

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 4105: Windows is in Notification period

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Winlogon",
    "event_id": 4105,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2014-11-21T23:43:09.000000Z",
    "event_record_id": 811,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {}
}

References #

Event ID 4105: Windows is in Notification period

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 5001: UserBootStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot
Opcode
Start

Fields #

NameDescription
SessionId UInt32

Event ID 5002: UserBootStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot
Opcode
Stop

Event ID 5003: UserBoot

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserBoot

Fields #

NameDescription
SessionId UInt32

Event ID 5005: UserShellLaunch

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
UserShellLaunch

Event ID 5007: SystemBootStop_V2

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
SystemBoot
Opcode
Stop

Fields #

NameDescription
SessionId UInt32
ReadyBootTrainingCountSinceLastServicing UInt32
SyncPrefetchErrorCode UInt32
SyncPrefetchDurationMs UInt32

Event ID 6000: The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:22.560419+00:00",
    "event_record_id": 1545,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "SessionEnv"
    ],
    "Binary": "2QYAAA=="
  },
  "message": "The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event."
}

Event ID 6000: The winlogon notification subscriber <Data_0> was unavailable to handle a notification event

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 6000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T05:22:33.7521344+00:00",
    "event_record_id": 1011,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "WSearch"
  },
  "message": "The winlogon notification subscriber <WSearch> was unavailable to handle a notification event."
}

Event ID 6001: The winlogon notification subscriber <SessionEnv> failed a notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
3

Fields #

NameDescription
Flags

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6001,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-09 21:09:30.700144+00:00",
    "event_record_id": 146,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "EX-SUBCA",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "<string>SessionEnv</string>\n",
    "Binary": "2QYAAA=="
  },
  "message": "The winlogon notification subscriber <SessionEnv> failed a notification event."
}

Event ID 6001: The winlogon notification subscriber <Flags> failed a notification event

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
ShutdownDiagnostics
Opcode
Start

Fields #

NameDescription
Flags UInt32

Event ID 6002: The winlogon notification subscriber registration database cannot be loaded

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Event ID 6003: The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Informational

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2023-11-05T22:32:20.495672+00:00",
    "event_record_id": 1542,
    "correlation": {},
    "execution": {
      "process_id": 736,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "SessionEnv"
    ],
    "Binary": "2QYAAA=="
  },
  "message": "The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event."
}

Event ID 6003: The winlogon notification subscriber <Data_0> was unavailable to handle a critical notification event

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
4

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 6003,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-04-18T00:27:34.0707520+00:00",
    "event_record_id": 20,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "SessionEnv"
  },
  "message": "The winlogon notification subscriber <SessionEnv> was unavailable to handle a critical notification event."
}

Event ID 6004: The winlogon notification subscriber <TrustedInstaller> failed a critical notification event.

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6004,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2013-10-23T17:32:12+00:00",
    "event_record_id": 181,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "IE8Win7",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "TrustedInstaller"
    ],
    "Binary": "aQYAAA=="
  },
  "message": "The winlogon notification subscriber <TrustedInstaller> failed a critical notification event."
}

Event ID 6004: The winlogon notification subscriber <Data_0> failed a critical notification event

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
3

Fields #

NameDescription
Data_0

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 6004,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-06-13T13:42:47.3224679+00:00",
    "event_record_id": 5090,
    "correlation": {},
    "execution": {
      "process_id": 860,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "TrustedInstaller"
  },
  "message": "The winlogon notification subscriber <TrustedInstaller> failed a critical notification event."
}

Event ID 6005: The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession).

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6005,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:16:03.529427+00:00",
    "event_record_id": 116,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "GPClient",
      "CreateSession"
    ],
    "Binary": "SNCCJg=="
  },
  "message": "The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession)."
}

Event ID 6005: The winlogon notification subscriber <Data_0> is taking long time to handle the notification event (Data_1)

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
3

Fields #

NameDescription
Data_0
Data_1

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 6005,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-28T22:42:48.5496626+00:00",
    "event_record_id": 619,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "GPClient",
    "Data_1": "CreateSession"
  },
  "message": "The winlogon notification subscriber <GPClient> is taking long time to handle the notification event (CreateSession)."
}

Event ID 6006: The winlogon notification subscriber <GPClient> took 119 second(s) to handle the notification event (CreateSession).

#
Provider
Microsoft-Windows-Winlogon
Channel
Application
Level
Warning

Fields #

NameDescription
Data
Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "Wlclntfy",
    "event_id": 6006,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T08:17:03.466560+00:00",
    "event_record_id": 120,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data": [
      "GPClient",
      "119",
      "CreateSession"
    ],
    "Binary": "AAAAAA=="
  },
  "message": "The winlogon notification subscriber <GPClient> took 119 second(s) to handle the notification event (CreateSession)."
}

Event ID 6006: The winlogon notification subscriber <Data_0> took Data_1 second(s) to handle the notification event (Data_2)

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
3

Fields #

NameDescription
Data_0
Data_1
Data_2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 6006,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-28T22:42:49.3308868+00:00",
    "event_record_id": 620,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Data_0": "GPClient",
    "Data_1": "60",
    "Data_2": "CreateSession"
  },
  "message": "The winlogon notification subscriber <GPClient> took 60 second(s) to handle the notification event (CreateSession)."
}

Event ID 6101: LogoffRequestToUserFeedbackStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffRequestToUserFeedback
Opcode
Start

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6102: LogoffRequestToUserFeedbackStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffRequestToUserFeedback
Opcode
Stop

Fields #

NameDescription
Flags UInt32

Event ID 6103: LogoffAppsTerminationToSessionEndStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffAppsTerminationToSessionEnd
Opcode
Start

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6104: LogoffAppsTerminationToSessionEndStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
LogoffAppsTerminationToSessionEnd
Opcode
Stop

Fields #

NameDescription
LogoffFlags UInt32

Event ID 6105: UnlockStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Start

Event ID 6106: UnlockStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Stop

Event ID 6107: UnlockStop6107

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Unlock
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6108: LogonStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Start

Event ID 6109: LogonStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 6110: LogonStop6110

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6111: LogonStop6111

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6112: LogonStop6112

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logon
Opcode
Stop

Event ID 6113: LockStart

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Start

Event ID 6114: LockStop

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Stop

Event ID 6115: LockStop6115

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Lock
Opcode
Stop

Event ID 6116: Logoff

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
Logoff

Fields #

NameDescription
Duration UInt32
ResolverData UInt32

Event ID 6117: DelayLockDisplayLockScreen

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
DelayLockDisplayLockScreen

Event ID 6118: KillingScreenSaverToLockWorkStation

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
KillingScreenSaverToLockWorkStation

Event ID 6119: AutomaticRestartSignOn

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AutomaticRestartSignOn

Event ID 6120: HotKeyLockDesktopInvoked

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
HotKeyLockDesktopInvoked

Event ID 6121: PINResetLogon

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
PINResetLogon

Event ID 6122: PINResetUnlock

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
PINResetUnlock

Event ID 6123: AssignedAccessLogon

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AssignedAccessLogon

Event ID 6124: AssignedAccessUnlock

#
Provider
Microsoft-Windows-Winlogon
Channel
Diagnostic
Task
AssignedAccessUnlock

Event ID 7001: User Logon Notification for Customer Experience Improvement Program

#
Provider
Microsoft-Windows-Winlogon
Channel
System
Level
Informational
Task
WinSqmUserLogin

Description

User Logon Notification for Customer Experience Improvement Program.

Message #

User Logon Notification for Customer Experience Improvement Program

Fields #

NameDescription
TSId UInt32
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 7001,
    "version": 0,
    "level": 4,
    "task": 1101,
    "opcode": 0,
    "keywords": 2305878193585782784,
    "time_created": "2026-05-29T16:33:48.1843872+00:00",
    "event_record_id": 6808,
    "correlation": {},
    "execution": {
      "process_id": 760,
      "thread_id": 1104
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TSId": "1",
    "UserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105"
  },
  "message": "User Logon Notification for Customer Experience Improvement Program"
}

Event ID 7002: User Logoff Notification for Customer Experience Improvement Program

#
Provider
Microsoft-Windows-Winlogon
Channel
System
Level
Informational
Task
WinSqmUserLogoff

Description

User Logoff Notification for Customer Experience Improvement Program.

Message #

User Logoff Notification for Customer Experience Improvement Program

Fields #

NameDescription
TSId UInt32
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "guid": "{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}",
    "event_source_name": "",
    "event_id": 7002,
    "version": 0,
    "level": 4,
    "task": 1102,
    "opcode": 0,
    "keywords": 2305878193585782784,
    "time_created": "2026-06-13T05:22:33.8971346+00:00",
    "event_record_id": 7354,
    "correlation": {},
    "execution": {
      "process_id": 756,
      "thread_id": 1120
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "TSId": "1",
    "UserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105"
  },
  "message": "User Logoff Notification for Customer Experience Improvement Program"
}

Event ID 1073742826: The shell stopped unexpectedly and %1 was restarted.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
4
Opcode
Info

Description

The shell stopped unexpectedly and was restarted.

Message #

The shell stopped unexpectedly and %1 was restarted.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "event_id": 1002,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-15T03:00:56.5858172+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073745826: The logon hours restriction policy is applied to the logged on user.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Opcode
Info

Description

The logon hours restriction policy is applied to the logged on user. The user's session has been locked, disconnected or logged off depending on the policy setting. User Name: Domain Name.

Message #

The logon hours restriction policy is applied to the logged on user. The user's session has been locked, disconnected or logged off depending on the policy setting. User Name: %1 Domain Name: %2

Event ID 1073745925: Windows license validated.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license validated.

Message #

Windows license validated.

Event ID 1073745928: Accessing Windows in Notification period.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Accessing Windows in Notification period.

Message #

Accessing Windows in Notification period.

Event ID 2147487654: The Windows logon process has failed to spawn a user application.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to spawn a user application. Application name: . Command line parameters: .

Message #

The Windows logon process has failed to spawn a user application. Application name: %1. Command line parameters: %2.

Event ID 2147487655: The Windows logon process has failed to disconnect the user session.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to disconnect the user session.

Message #

The Windows logon process has failed to disconnect the user session.

Event ID 2147487656: The Windows logon process has failed to connect the user session.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to connect the user session.

Message #

The Windows logon process has failed to connect the user session.

Event ID 2147487753: Windows is in Notification period.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows is in Notification period.

Message #

Windows is in Notification period.

Event ID 2147489648: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
4

Description

The winlogon notification subscriber <> was unavailable to handle a notification event.

Message #

The winlogon notification subscriber <%1> was unavailable to handle a notification event.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "event_id": 6000,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-14T21:57:32.6042462+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 2147489649: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> failed a notification event.

Message #

The winlogon notification subscriber <%1> failed a notification event.

Event ID 2147489650: The winlogon notification subscriber registration database cannot be loaded.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber registration database cannot be loaded. Reason: <>.

Message #

The winlogon notification subscriber registration database cannot be loaded. Reason: <%1>.

Event ID 2147489651: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> was unavailable to handle a critical notification event.

Message #

The winlogon notification subscriber <%1> was unavailable to handle a critical notification event.

Event ID 2147489652: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The winlogon notification subscriber <> failed a critical notification event.

Message #

The winlogon notification subscriber <%1> failed a critical notification event.

Event ID 2147489653: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
3

Description

The winlogon notification subscriber <> is taking long time to handle the notification event ().

Message #

The winlogon notification subscriber <%1> is taking long time to handle the notification event (%2).

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "event_id": 6005,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:09:59.4874940+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 2147489654: The winlogon notification subscriber <.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational
Level
3

Description

The winlogon notification subscriber <> took second(s) to handle the notification event ().

Message #

The winlogon notification subscriber <%1> took %2 second(s) to handle the notification event (%3).

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winlogon",
    "event_id": 6006,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T19:10:07.8783185+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 3221229475: The Windows logon process has failed to switch the desktop.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to switch the desktop.

Message #

The Windows logon process has failed to switch the desktop.

Event ID 3221229476: The Windows logon process has failed to terminate the currently logged on user's processes.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has failed to terminate the currently logged on user's processes.

Message #

The Windows logon process has failed to terminate the currently logged on user's processes.

Event ID 3221229477: The Windows logon process has unexpectedly terminated.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

The Windows logon process has unexpectedly terminated.

Message #

The Windows logon process has unexpectedly terminated.

Event ID 3221229574: Windows license is invalid.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license is invalid. Error . Policy Value .

Message #

Windows license is invalid. Error %1. Policy Value %2.

Event ID 3221229575: Windows license activation failed.

#
Provider
Microsoft-Windows-Winlogon
Channel
Operational

Description

Windows license activation failed. Error .

Message #

Windows license activation failed. Error %1.

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID dbe9b383-7cf3-4331-91cc-a3cb16a3b538

Defined in winlogon.exe, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02

Downloads