User32

10 events across 1 channel

Event ID 1073: The attempt by user param2 to restart/shutdown computer param1 failed

#
Provider
User32
Channel
System

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 1074: The process param1 has initiated the param5 of computer param2 on behalf of user param7 for the following reason:

#
Provider
User32
Channel
System
Level
Informational
Collection Priority
Recommended (JSCU-NL)

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString

Example Event #

{
  "system": {
    "provider": "User32",
    "guid": "{B0AA8734-56F7-41CC-B2F4-DE228E98B946}",
    "event_source_name": "",
    "event_id": 1074,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9187343239835811840,
    "time_created": "2026-06-13T05:22:28.8755699+00:00",
    "event_record_id": 7349,
    "correlation": {},
    "execution": {
      "process_id": 584,
      "thread_id": 600
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "wininit.exe (TELEMETRY-DC-C)",
    "param2": "TELEMETRY-DC-C",
    "param3": "No title for this reason could be found",
    "param4": "0x800000ff",
    "param5": "restart",
    "param6": "",
    "param7": "cell-c\\domainadmin"
  },
  "message": "The process wininit.exe (TELEMETRY-DC-C) has initiated the restart of computer TELEMETRY-DC-C on behalf of user cell-c\\domainadmin for the following reason: No title for this reason could be found\r\n Reason Code: 0x800000ff\r\n Shutdown Type: restart\r\n Comment: "
}

Detection Rules #

View all rules referencing this event →

Splunk # view in coverage

Event ID 1075: The last restart/shutdown request of computer param1 was aborted by user

#
Provider
User32
Channel
System

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 1076: The reason supplied by user param6 for the last unexpected shutdown of this computer is:

#
Provider
User32
Channel
System
Level
Warning

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString

Example Event #

{
  "system": {
    "provider": "User32",
    "guid": "{b0aa8734-56f7-41cc-b2f4-de228e98b946}",
    "event_source_name": "User32",
    "event_id": 1076,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9259400833873739776,
    "time_created": "2026-03-08T22:34:36.922571+00:00",
    "event_record_id": 10013,
    "correlation": {},
    "execution": {
      "process_id": 768,
      "thread_id": 876
    },
    "channel": "System",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "param1": "Other (Unplanned)",
    "param2": "0xa000000",
    "param3": "",
    "param4": "",
    "param5": "\n",
    "param6": "ludus\\domainadmin"
  },
  "message": ""
}

Event ID 1077: The attempt by user param2 to logoff computer param1 failed

#
Provider
User32
Channel
System

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2147484721: The attempt by user param2 to restart/shutdown computer param1 failed.

#
Provider
User32
Channel
System

Description

The attempt by user param2 to restart/shutdown computer param1 failed.

Message #

The attempt by user %2 to restart/shutdown computer %1 failed

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2147484722: The process param1 has initiated the ShutdownType of computer param2 on behalf of user param7 for the following reason: param3.

#
Provider
User32
Channel
System

Description

The process param1 has initiated the ShutdownType of computer param2 on behalf of user param7 for the following reason: param3.

Message #

The process %1 has initiated the %5 of computer %2 on behalf of user %7 for the following reason: %3
 Reason Code: %4
 Shutdown Type: %5
 Comment: %6

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString

Example Event #

{
  "system": {
    "provider": "User32",
    "event_id": 1074,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-04-23T15:32:05.4926192+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": "power off",
    "param3": "Other (Planned)",
    "param6": null,
    "param1": "qemu-ga.exe",
    "param4": "0x80000000",
    "param7": "NT AUTHORITY\\SYSTEM",
    "param2": "JD-DC01-2022"
  }
}

Event ID 2147484723: The last restart/shutdown request of computer param1 was aborted by user param2.

#
Provider
User32
Channel
System

Description

The last restart/shutdown request of computer param1 was aborted by user param2.

Message #

The last restart/shutdown request of computer %1 was aborted by user %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2147484724: The reason supplied by user param6 for the last unexpected shutdown of this computer is: param1.

#
Provider
User32
Channel
System

Description

The reason supplied by user param6 for the last unexpected shutdown of this computer is: param1.

Message #

The reason supplied by user %6 for the last unexpected shutdown of this computer is: %1
 Reason Code: %2
 Problem ID: %3
 Bugcheck String: %4
 Comment: %5

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString

Example Event #

{
  "system": {
    "provider": "User32",
    "event_id": 1076,
    "level": "Warning",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-14T00:03:47.6624769+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {
    "param5": null,
    "param3": null,
    "param6": "ludus\\domainadmin",
    "param1": "Other (Unplanned)",
    "param4": null,
    "param2": "0xa000000"
  }
}

Event ID 2147484725: The attempt by user param2 to logoff computer param1 failed.

#
Provider
User32
Channel
System

Description

The attempt by user param2 to logoff computer param1 failed.

Message #

The attempt by user %2 to logoff computer %1 failed

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString