What event ID means?
What event ID means?
Event identifiers uniquely identify a particular event. Each event source can define its own numbered events and the description strings to which they are mapped in its message file. Event viewers can present these strings to the user.
What is the ID for a log that pertains to an attempted logon with explicit credentials?
Windows Security Log Event ID 4648
Operating Systems | Windows 2008 R2 and 7 Windows 2012 R2 and 8.1 Windows 2016 and 10 Windows Server 2019 and 2022 |
---|---|
Category • Subcategory | Logon/Logoff • Logon |
Type | Success |
Corresponding events in Windows 2003 and before | 552 |
How many Windows event IDs are there?
Windows Security Log Events
Windows | 1100 | The event logging service has shut down |
---|---|---|
Windows | 4719 | System audit policy was changed |
Windows | 4720 | A user account was created |
Windows | 4722 | A user account was enabled |
Windows | 4723 | An attempt was made to change an account’s password |
What are the default Windows event logs?
They are Information, Warning, Error, Success Audit (Security Log) and Failure Audit (Security Log).
What Eventcode 4648?
When an account logon is attempted by a process by explicitly specifying the credentials of that account, event 4648 is generated. This is usually generated by batch-type configurations.
What is network share object?
5140: A network share object was accessed. Windows logs this event the first time you access a given network share during a given logon session. Be aware that Windows Server 2008 logs off network logon sessions even sooner than past versions of Windows.
How do I find my Windows event ID?
Right click on the Start button and select Control Panel > System & Security and double-click Administrative tools. Double-click Event Viewer.