Skip to main content

Windows Security event log

1channels
67curated reasons
5themes fed
Livestatus

Classic Windows Event Log Security channel, the host audit record. Covers failed logons and lockouts with the failure cause decoded from NTSTATUS, Kerberos and NTLM failures including the RC4 service-ticket downgrade signal, audit-infrastructure tampering (log cleared or full, policy changes), account, group and directory lifecycle, persistence surfaces (service install, scheduled tasks, registry values, shares, firewall rules), and AD CS / NPS hand-offs. High-volume events are retained at the Debug severity tier; a short exact-keyed list of ids whose whole population answers no investigative question is dropped instead, and those events remain in the endpoint's own log.

Feed id: win.eventlog.security.

Channels​

This feed reads one Windows Event Log channel, Security.

Fields​

FieldTypeUnitMeaning
win.eventlog.security.logon_guidstringCross-host auth correlation GUID from 4624, 4768 and 4769: joins a sign-in to the ticket requests made for the same authentication.
win.eventlog.security.logon_typeintLogon mechanism code from 4624/4625 (2 interactive, 3 network, 5 service, 7 unlock, 10 RDP, 11 cached; locale-stable numeric).
win.eventlog.security.logon_type_namestringBounded meaning token decoded from the logon type (logon_system, logon_interactive, logon_network, logon_service, logon_batch, logon_unlock, logon_network_cleartext, logon_new_credentials, logon_remote_interactive, logon_cached_interactive, logon_cached_remote_interactive, logon_cached_unlock). An unlisted code leaves this unset.
win.eventlog.security.auth_packagestringAuthentication package that answered the sign-in on 4624/4625, downcased as the provider names it (kerberos, ntlm, negotiate, negoextender, and any package outside the curated set). The provider dash sentinel leaves this unset.
win.eventlog.security.lm_packagestringLAN Manager package variant on 4624/4625 as the provider names it (for example NTLM V2): the NTLM downgrade inventory. Not a curated vocabulary, so it stays a raw value.
win.eventlog.security.token_elevatedboolWhether the sign-in minted a full-privilege token on 4624, decoded from the message-catalog reference. False is stored as false, so a negative is distinguishable from an event that states nothing; an unrecognized reference leaves this unset. Same name as the pattern token that renders when this is true.
win.eventlog.security.privilegesarraySensitive privileges assigned to the new session on 4672, as the list of literal Se* constants the provider named. Locale-invariant, so unknown privileges pass through verbatim and no decode table applies.
win.eventlog.security.workstationstringSource machine name of the attempt in the provider NetBIOS form (WorkstationName on 4624/4625, Workstation on 4776/4777/4794), on the succeeding rows as well as the failing ones. Kept verbatim in the provider spelling; the portable origin host carries the same end as the cross-feed join key.
win.eventlog.security.caller_computerstringMachine the bad attempts came from in the provider NetBIOS form (CallerComputerName on 4740): the lockout-source forensic pivot, the highest-ticket-value field in the channel. Kept verbatim in the provider spelling; the portable origin host carries the same end as the cross-feed join key.
win.eventlog.security.statusstringFailure code as logged, downcased hex: NTSTATUS on 4625/4776/4777, Kerberos result code on 4768/4769/4770/4771. The raw code is the classify key and the provider fidelity; the portable error code carries the normalized value and its number space.
win.eventlog.security.substatusstringDetailed NTSTATUS on 4625 (usually the real cause; 0x0 means the Status field carries it).
win.eventlog.security.status_meaningstringBounded meaning token decoded from the status code (NTSTATUS and SSPI causes on 4625/4776/4777, Kerberos result codes on 4768/4769/4770/4771). Also rendered as a bare inline token on those arms, so the cause forms part of the pattern instead of variabilizing away. An undecoded code leaves this unset; a meaning is never invented. Not a synonym of the portable sparklogs.result.code_name, which carries the VENDOR constant name (STATUS_WRONG_PASSWORD) decoded from the same table row: two vocabularies with different owners and different jobs, so both exist. This one is ours and is chosen for the message head; that one is the published name an engineer searches for and transfers to every source speaking the space.
win.eventlog.security.psdirect_handshakestringHyper-V PowerShell Direct legacy handshake constant on 4625, read back as ASCII. The emitting integration service fuses byte pairs of the constant into single UTF-16 code units, so the provider records it as unreadable mojibake in the domain field; this is the same bytes in the encoding they were written in. Set only on the handshake arm, and only when every character reverses cleanly, so a value that does not fit the pattern leaves this unset rather than shipping a partial reading.
win.eventlog.security.kerberos_targetstringService principal the Kerberos request named (ServiceName, casefolded) on 4768/4769/4770/4771: which service a ticket was asked for, and the kerberoast target join on 4769.
win.eventlog.security.ticket_encryption_typestringKerberos ticket encryption type (hex enum) on every ticket row of 4768/4769/4770 that states one; 0x17 RC4-HMAC and 0x18 RC4-HMAC-EXP are the downgrade pair the RC4 arm labels.
win.eventlog.security.etype_meaningstringDecoded encryption-type token (rc4_hmac, rc4_hmac_exp): the meaning behind ticket_encryption_type. Only the RC4 pair decodes, so every other encryption type leaves this unset and the raw enum answers instead.
win.eventlog.security.target_serverstringServer the explicit credential was presented to (TargetServerName on 4648), kept verbatim in the provider spelling; the portable destination host carries the same end as the cross-feed join key, the routine localhost form included.
win.eventlog.security.audit_subcategory_guidstringAudit subcategory GUID from 4719/4912 (SubcategoryGuid): the locale-invariant key of WHICH audit policy changed.
win.eventlog.security.new_process_idstringCreated process id from 4688 in the hex form the provider logged. Where a matching 4689 exit is stored it carries the same hex in ProcessId, so this is the join key at rest; exits are stored only when the process ended on a non-zero status, so most creations have no exit to join to. The portable process id carries the same number in decimal.
win.eventlog.security.uac_token_typestringUAC split of the created process token on 4688, decoded from TokenElevationType (unsplit, full, limited). unsplit is TokenElevationTypeDefault: UAC produced no filtered pair. full is TokenElevationTypeFull (type 2), not Default. An unrecognized reference leaves this unset.
win.eventlog.security.integrity_levelstringMIC integrity level of the created process token on 4688, decoded from MandatoryLabel (untrusted, low, medium, high, system). An unrecognized SID leaves this unset and stamps the raw SID on integrity_level_sid.
win.eventlog.security.integrity_level_sidstringRaw MandatoryLabel SID from 4688, kept beside the decoded token so an unrecognized integrity SID remains queryable.
win.eventlog.security.parent_process_namestringCreator process image path from 4688 (present on modern builds only; 2012R2-era 4688 lacks it).
win.eventlog.security.service_namestringInstalled service name from 4697. Same join semantics as the System-channel 7045 record of the same fact.
win.eventlog.security.service_image_pathstringInstalled service IMAGE path from 4697, with the arguments of the ServiceFileName command line removed. Unset where the image cannot be split off unambiguously (an unterminated quote, or an unquoted path containing spaces), so the value is always a path and never a command line.
win.eventlog.security.service_accountstringAccount the installed service runs as, from 4697 (blank in the event means LocalSystem; stored only when present).
win.eventlog.security.task_namestringScheduled task path from 4698/4699/4701/4702. The task XML blob is not promoted.
win.eventlog.security.exit_statusstringExit status a process returned on 4689, verbatim from the provider (Status), on the rows whose value is non-zero and is not one of the named crash statuses. A value only the program that returned it, or the kernel outcome it ended on, can interpret.
win.eventlog.security.object_namestringAudited object path (ObjectName): the registry key the audited value lives under on 4657, and the object whose auditing settings changed on 4907.
win.eventlog.security.object_typestringKind of object whose auditing settings changed on 4907 (ObjectType: File, Key, and the other object-server types), verbatim from the provider.
win.eventlog.security.object_value_namestringRegistry value name that was created/modified/deleted (4657 ObjectValueName). Old/new DATA are not promoted (credential hazard).
win.eventlog.security.operation_meaningstringRegistry operation on 4657 decoded from the message-catalog reference (value_created, value_modified, value_deleted): distinguishes a new value from a rewritten or removed one.
win.eventlog.security.previous_timestringSystem clock value before a 4616 time change, ISO-8601 UTC with microsecond precision, read from the PreviousTime payload value in either the ISO-8601 string form the provider writes or an epoch-microsecond integer (the rendered template strings carry bidi control characters; the named payload field is clean). A value in neither form leaves this unset.
win.eventlog.security.new_timestringSystem clock value after a 4616 time change, ISO-8601 UTC with microsecond precision, read from the NewTime payload value in either the ISO-8601 string form the provider writes or an epoch-microsecond integer. A value in neither form leaves this unset.
win.eventlog.security.insecure_boot_flagsstringComma-joined boot-chain weaknesses found true on 4826 (TestSigning, KernelDebug, DisableIntegrityChecks): which setting makes the boot chain accept unsigned or debugger-attached kernel code.
win.eventlog.security.rule_namestringFirewall rule display name from the MPSSVC rule-change family.
win.eventlog.security.rule_idstringFirewall rule id from the MPSSVC rule-change family (stable across renames).
win.eventlog.security.share_namestringNetwork share name, from 5142 (share added) and from the write-class 5145 access checks.
win.eventlog.security.share_pathstringLocal filesystem path backing the share (5142 and 5145 ShareLocalPath); a system-root share is a higher-concern surface.
win.eventlog.security.share_relative_targetstringPath of the object inside the share that a 5145 access check was made against (RelativeTargetName): what was written, renamed, deleted or re-permissioned.
win.eventlog.security.share_access_maskstringAccess requested on a 5145 check, as the hex string the provider logged. The keep rule reads the same value as bits and stores no reading of it, so this is what a query pivots on and what lets the keep decision be re-derived from the row.
win.eventlog.security.old_target_userstringAccount name before a rename (4781).
win.eventlog.security.new_target_userstringAccount name after a rename (4781).
win.eventlog.security.object_dnstringDirectory object distinguished name from 5136-5141 (ObjectDN). Attribute VALUES are not promoted (sensitive directory data).
win.eventlog.security.attribute_namestringLDAP display name of the changed directory attribute (5136 AttributeLDAPDisplayName).
win.eventlog.security.nps_reason_codeintNPS/RADIUS reason code on 6273/6274/6279 (16 bad credentials, 36 lockout, 48/49 no matching policy, 4/5/6 upstream DC trouble). A policy DECISION code, not a failure code from any Windows number space, so it stays module-namespaced rather than claiming the portable error family.
win.eventlog.security.nps_reason_meaningstringDecoded meaning of the NPS reason code on 6273/6274/6279: the same value the inline cause token renders, so the token maps one to one onto a queryable field. Unset when the code does not decode.
win.eventlog.security.nps_policystringNetwork policy that matched the NPS request (NetworkPolicyName on 6273/6274): the pivot a RADIUS ticket needs, since a denial reads differently depending on which policy decided it.
win.eventlog.security.publisher_idstringProvider whose event the logging service failed to process (Eventlog 1108): which audit source is silently losing records.
win.eventlog.security.pua_countintNumber of entries in the per-user audit policy table built at boot (4902 PuaCount). Zero means this host has no per-user audit policy at all; any other value means auditing is aimed at named principals.
win.eventlog.security.wfp_directionstringWhich way the refused connection was going (5157 Direction): inbound or outbound. An unrecognized message-catalog reference leaves this unset.
win.eventlog.security.wfp_dest_addressstringPeer address the refused connection was aimed at (5157 DestAddress), verbatim, on every kept row including loopback and same-host refusals. sparklogs.destination.* carries the same endpoint when it names a machine other than the reporting host.
win.eventlog.security.wfp_dest_portintPeer port the refused connection was aimed at (5157 DestPort), on every kept row including loopback and same-host refusals. sparklogs.destination.* carries the same endpoint when it names a machine other than the reporting host. Unset when the provider value is not a number.
win.eventlog.security.wfp_protocolintIANA protocol number of the refused connection (5157 Protocol), 6 for TCP and 17 for UDP. Unset when the provider value is not a number.
win.eventlog.security.dropped_countintNumber of audit records the event log transport discarded before they reached the log (Eventlog 1101). Zero means nothing was lost. Read from the message tail on the known template, and left unset on any other template.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
account_changedsecurity_auditNotice
account_createdsecurity_auditNotice
account_deletedsecurity_auditNotice
account_disabledsecurity_auditNotice
account_enabledsecurity_auditNotice
account_locked_outauthError (privileged account) / Warning
account_password_change_failedsecurity_auditInfo
account_password_resetsecurity_auditWarning
account_password_reset_failedsecurity_auditWarning
adcs_audit_evidence_tamperedcertificatesSerious
adcs_config_changedcertificatesError
adcs_request_failedcertificatesWarning
anonymous_remote_sign_inauthNotice
audit_event_processing_failedsecurity_auditWarning
audit_events_droppedsecurity_auditError when records were discarded; Debug when the count is zero
audit_log_clearedsecurity_auditCritical (non-system clearer) / Error
audit_log_fullsecurity_auditSerious
audit_policy_changedsecurity_auditWarning
crypto_selftest_failedos_stabilityError
directory_object_access_denieddirectory_servicesNotice
directory_object_changeddirectory_servicesWarning
directory_object_createddirectory_servicesWarning
directory_object_deleteddirectory_servicesWarning
directory_replication_access_requesteddirectory_servicesWarning (any other account) / Info (a domain controller, a platform identity, or a directory-sync connector under its default name)
domain_policy_changedsecurity_auditWarning; Debug for the platform writing a new machine's own setup policy
dsrm_password_change_failedsecurity_auditError
dsrm_password_changedsecurity_auditSerious
event_logging_stoppedsecurity_auditInfo
explicit_credential_usedauthInfo
firewall_rule_changednetworkingWarning
firewall_rule_creatednetworkingWarning
firewall_rule_deletednetworkingWarning
firewall_service_stoppednetworkingWarning or Info
group_member_addedsecurity_auditError (privileged group) / Notice (any other security group)
group_member_removedsecurity_auditWarning (privileged group) / Notice (any other security group)
guest_account_sign_inauthNotice
kerberos_preauth_failedauthWarning (account state or broken infrastructure) / Notice (wrong password, unknown client, undecoded)
kerberos_rc4_ticket_issuedauthWarning
kerberos_ticket_failedauthWarning (account state or broken infrastructure) / Notice (wrong password, unknown principal, expired, undecoded)
logon_right_grantedsecurity_auditNotice
logon_right_removedsecurity_auditNotice
network_share_addedfile_sharingWarning
nps_access_deniedauthWarning (policy or infrastructure defect) / Notice (credentials, account state, undecoded)
nps_lockoutauthError (privileged account) / Warning
nps_request_discardedauthWarning
ntlm_validation_failedauthWarning (account state) / Notice (wrong password, unknown username, undecoded)
principal_renamedsecurity_auditNotice for a rename that changed the name; Debug when the old and new names are identical
process_exited_abnormallysecurity_auditNotice
psdirect_handshake_probeauthDebug
replay_attack_detectedauthError
scheduled_task_createdscheduled_tasksWarning
scheduled_task_deletedscheduled_tasksWarning
scheduled_task_disabledscheduled_tasksInfo
scheduled_task_updatedscheduled_tasksWarning
security_group_changedsecurity_auditWarning for a privileged group, Notice for any other security group, Info when Windows configures its own builtin groups.
security_group_createdsecurity_auditWarning for a privileged group, Notice for any other security group, Info when Windows provisions its own builtin groups.
security_group_deletedsecurity_auditWarning for a privileged group, Notice for any other security group.
service_installedsecurity_auditNotice
sid_history_add_failedsecurity_auditError
sid_history_addedsecurity_auditSerious
sign_in_failedauthWarning (account-state) / Notice (other) / Verbose (credential-less probe)
special_group_sign_insecurity_auditWarning
system_time_changedtime_syncWarning (non-time-service) / Debug (routine time service)
win_insecure_boot_configsecurity_auditWarning
win_registry_value_changedsecurity_auditWarning
win_registry_value_createdsecurity_auditWarning
win_registry_value_deletedsecurity_auditWarning

account_changed​

An attribute on an existing user or computer account was modified.

Severity: Notice

Impact: The principal still exists and still authenticates; what changed is one of its properties, so read the row as a timestamped record of an administrative edit rather than as a failure.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4738, 4742

Where to look next:

  • Join on the actor (who edited) and the target (which principal was edited)
  • The id can fire without a visible attribute change; treat one occurrence as weak evidence

Related reasons:

The target is the principal that was edited and the actor is the principal that edited it. config_change.target names the same account again, as the identity of what changed rather than as a principal join key; the two answer different questions and both are populated.

account_created​

A user or computer account was created in the directory or local SAM.

Severity: Notice

Impact: A new principal can authenticate and may receive group rights. Unexpected creates on DCs or privileged naming patterns deserve follow-up.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4720, 4741

Where to look next:

  • Join on Subject (who created) and TargetUserName (what was created)
  • Computer account creates (4741) are common on domain join; still notable-normal

Related reasons:

account_deleted​

A user or computer account was deleted from the directory or local SAM.

Severity: Notice

Impact: That principal can no longer authenticate. Orphaned ACLs, service logons, and scheduled tasks that still reference the account may fail.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4726, 4743

Where to look next:

  • Confirm Subject expected for that delete
  • Check dependent services and tasks after computer-account deletes

Related reasons:

account_disabled​

A user or computer account was disabled and can no longer authenticate.

Severity: Notice

Impact: The named principal cannot sign in from this point on. Services, scheduled tasks and mapped resources still configured to use it will start failing, and those failures appear as their own events rather than here.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4725

Where to look next:

  • Join on the actor to see who disabled it, and on the target to see what was disabled
  • Look for later failures naming the same principal as a service or task identity

Related reasons:

account_enabled​

A user or computer account that was disabled has been enabled and can authenticate again.

Severity: Notice

Impact: The named principal can sign in from this point on. An enable nobody expected on a privileged or long-dormant account is worth confirming against the change that requested it.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4722

Where to look next:

  • Join on the actor to see who enabled it, and on the target to see what was enabled
  • Compare against the sign-in history of the same principal after this time

Related reasons:

account_locked_out​

An account was locked out after failed sign-ins. CallerComputerName names the machine that caused the lockout (often a stale cached credential).

Severity: Error (privileged account) / Warning

Impact: User cannot authenticate until unlock. Privileged lockout can block admin recovery paths.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4740

What you see: Event 4740, "account locked out", naming the locked account and CallerComputerName, the machine the failed attempts came from.

What it means: The account passed the lockout threshold and cannot authenticate until it is unlocked. The caller machine is usually where a stale cached credential keeps retrying on its own. A lockout of the built-in Administrator or a domain-admin account can block the recovery path used to fix it.

What to do: Remediate the machine CallerComputerName names, not only the user: clear or update the credential it keeps presenting, then clear the lockout on the account.

References:

Example

A user account was locked out.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4740
event_data.TargetUserName: Administrator
event_data.TargetSid: S-1-5-21-1111111111-2222222222-3333333333-500
event_data.CallerComputerName: EXAMPLEPC7

SparkLogs: account_locked_out, Error, account_locked_out: NOTABLE: account locked out | target=Administrator origin_host=EXAMPLEPC7 caller_computer=EXAMPLEPC7

Where to look next:

  • Treat CallerComputerName as the device to remediate (password/cache), not only the locked user
  • Privileged RID lockouts deserve faster response than routine user lockouts

Related reasons:

Fields it can set: win.eventlog.security.caller_computer

Highest ticket-value auth pivot on many fleets: find the noisy device, fix the credential.

account_password_change_failed​

A principal tried to change its own password and the change was rejected.

Severity: Info

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4723

Where to look next:

  • One occurrence is ordinary; a rate against one account is the readable signal
  • The successful half of the same id is not labeled, so absence here does not mean absence of changes

Related reasons:

account_password_reset​

One principal reset the password of another principal, and the reset completed.

Severity: Warning

Impact: The account holder can no longer sign in with the credential they were using, and whoever performed the reset chose the replacement. A reset nobody requested is one of the standard ways an identity is taken over.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4724

Where to look next:

  • Confirm a ticket or request exists for the reset, especially on privileged targets
  • Compare the actor against the set of principals expected to perform resets

Related reasons:

The value the credential was set to is never recorded by the event and never reaches any field.

account_password_reset_failed​

One principal attempted to reset the password of another principal and the reset did not complete.

Severity: Warning

Impact: The target credential is unchanged, so nobody lost access. What the row records is that an override of somebody else credential was attempted, which is worth attributing whether it succeeded or not.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4724

Where to look next:

  • Repeated failures from one actor against many targets is a different shape from one failure
  • Confirm the actor is a principal expected to perform resets at all

Related reasons:

An event that states neither success nor failure is reported here rather than as a completed reset.

adcs_audit_evidence_tampered​

The Certification Authority audit filter was changed, or rows were deleted from the CA database.

Severity: Serious

Impact: Less of what the CA does can be reconstructed afterwards. A narrowed audit filter stops recording issuance events, and a deleted database row removes the record of a certificate that may still be trusted wherever it was presented.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4885, 4896

Where to look next:

  • Confirm change window against approved CA maintenance
  • Remember these events only appear when CA auditing is fully enabled
  • Check what issuance records exist either side of the change

Related reasons:

These two ids carry the higher band because they reduce what can be audited later. Permission and certificate-manager changes are adcs_config_changed.

adcs_config_changed​

Certification Authority control settings changed: the security permissions on Certificate Services, or who may act as a certificate manager.

Severity: Error

Impact: Who can administer the CA or approve certificates has changed, and it stays changed until somebody changes it back. On an enterprise CA that is a control-plane change worth confirming.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4882, 4890

Where to look next:

  • Confirm change window against approved CA maintenance
  • Remember these events only appear when CA auditing is fully enabled

Related reasons:

Permissions and certificate-manager changes have routine administrative forms, which is why they carry a lower band than the audit-filter and database-deletion pair.

adcs_request_failed​

A certification authority denied or failed a certificate request.

Severity: Warning

Impact: The requester did not receive a certificate. May be expected policy denial or a broken enrollment path for that template/host.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4888

Where to look next:

  • Confirm whether the denial matches intended enrollment policy
  • Absence of these events does not prove quiet CA activity (auditing is double-gated)

Related reasons:

anonymous_remote_sign_in​

A sign-in succeeded with no identity, from a machine other than this one. Windows uses anonymous logons routinely for its own local plumbing, but those name no source machine; this one did.

Severity: Notice

Impact: Something on the network authenticated as nobody. That is normal for a deliberately public share and abnormal otherwise, where it is the shape null-session enumeration takes.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4624

What you see: A successful sign-in, event 4624, whose account is the anonymous well-known identity and whose payload names an address and a machine other than this host.

What it means: Something on the network authenticated as no identity at all and this host accepted the session. Windows's own local plumbing uses anonymous logons too but names no source machine; this one did. A host that publishes an anonymous share produces this legitimately; on one that should not answer strangers, it is the shape null-session enumeration takes, and the event cannot tell the two apart.

What to do: Check whether the named endpoint is expected to reach this machine at all, and whether a share or pipe here is meant to be open to anonymous access.

When to ignore it: Ignore it on a host that serves an anonymous share on purpose; the configuration produces these at volume.

References:

Example

An account was successfully logged on.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4624
event_data.LogonType: 3
event_data.SubjectUserSid: S-1-0-0
event_data.TargetUserName: ANONYMOUS LOGON
event_data.TargetUserSid: S-1-5-7
event_data.TargetDomainName: NT AUTHORITY
event_data.TargetLogonId: 0xA02
event_data.AuthenticationPackageName: NTLM
event_data.WorkstationName: REMOTEBOX
event_data.IpAddress: 203.0.113.60

SparkLogs: anonymous_remote_sign_in, Notice, anonymous_remote_sign_in: NOTABLE: anonymous sign-in from a remote endpoint; logon_network by_anonymous auth_ntlm | actor="ANONYMOUS LOGON" actor_domain="NT AUTHORITY" session=0xA02 origin_ip=203.0.113.60 origin_port=49512 workstation=REMOTEBOX

Where to look next:

  • Check whether the named endpoint is expected to reach this machine at all
  • Confirm whether a share or pipe on this host is deliberately open to anonymous access
  • Pivot on the endpoint to see what else it did in the same window

Related reasons:

Fields it can set: win.eventlog.security.auth_package, win.eventlog.security.lm_package, win.eventlog.security.logon_guid, win.eventlog.security.logon_type, win.eventlog.security.logon_type_name, win.eventlog.security.token_elevated, win.eventlog.security.workstation

audit_event_processing_failed​

The Windows logging service failed to process an incoming audit event. Some security events may not have been recorded.

Severity: Warning

Impact: Audit coverage has holes for the failed publisher/event window. Gaps can hide activity that would otherwise appear in the Security log.

Channel: Security

Provider: Microsoft-Windows-Eventlog

Event ids: 1108

Where to look next:

  • Use PublisherID when present to see which source failed
  • Correlate with Event Log service health and disk errors

Related reasons:

Fields it can set: win.eventlog.security.publisher_id

audit_events_dropped​

The Windows event log transport discarded audit records before they reached the log. The number discarded rides the event.

Severity: Error when records were discarded; Debug when the count is zero

Impact: The audit record for that window on that host is permanently incomplete, and nothing replays it. Read the absence of expected security events around this time as loss rather than as quiet.

Channel: Security

Provider: Microsoft-Windows-Eventlog

Event ids: 1101

Where to look next:

  • The count states how many records were lost; zero means nothing was
  • Investigate what generated enough audit volume to overrun the transport

Related reasons:

Fields it can set: win.eventlog.security.dropped_count

The count is read from the message text and only from the known template, so any row whose text does not match that template ships with no count. A row with no count is reported at the failure band rather than the healthy one.

audit_log_cleared​

The Security audit log was cleared. When a non-system account cleared it, treat as critical; system-account clears stay high but admit automated log management.

Severity: Critical (non-system clearer) / Error

Impact: Audit trail truncated; later investigation on this host is incomplete for the cleared window.

Channel: Security

Provider: Microsoft-Windows-Eventlog

Event ids: 1102

What you see: Event 1102, "The audit log was cleared", written by the Eventlog provider rather than Security-Auditing, with the account that cleared it in the payload.

What it means: The Security audit trail on this host was truncated for that window. Who cleared it separates two readings: an account other than SYSTEM destroys evidence, while SYSTEM can also be scheduled log management.

What to do: Identify the clearing account, then look for what the clear left behind: gaps beside it, a missing 1100, and administrator sessions nobody expected.

When to ignore it: A clear by SYSTEM can be automated log management doing its job; confirm which before treating it as tampering.

References:

Example

The audit log was cleared.

channel: Security
provider_name: Microsoft-Windows-Eventlog
event_id: 1102

SparkLogs: audit_log_cleared, Critical, audit_log_cleared: NOTABLE: The audit log was cleared.

Where to look next:

  • Identify the clearer SubjectUserSid / SubjectUserName
  • Look for adjacent gaps, 1100 absence, and unexpected admin sessions

Related reasons:

Provider is Microsoft-Windows-Eventlog, not Security-Auditing. Who cleared the log is what the event itself proves, and it is what separates the two bands.

audit_log_full​

The Security log is full. This usually means retention is set to do-not-overwrite and new audit events may be lost.

Severity: Serious

Impact: New security events may stop recording until space is freed or retention policy changes. Investigation coverage on this host is at risk.

Channel: Security

Provider: Microsoft-Windows-Eventlog

Event ids: 1104

Where to look next:

  • Check log size and retention (do-not-overwrite vs overwrite-as-needed)
  • Expand capacity or archive before clearing if forensics matter

Related reasons:

audit_policy_changed​

Local audit policy changed (system, object security descriptor, or per-user). These events are dependable even when other audit subcategories are off.

Severity: Warning

Impact: What gets logged (or silenced) on this host can change. Unexpected policy edits can hide later activity or flood the log.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4715, 4719, 4912

What you see: Event 4719, 4715 or 4912: the system audit policy, an object security descriptor, or per-user auditing changed. The subcategory rides a fixed identifier that reads the same in every display language.

What it means: What this host writes to its Security log, or stops writing, has changed. An edit nobody expected can hide later activity or flood the log. These events keep arriving even when other audit subcategories are switched off.

What to do: Read the subcategory identifier to see which part of the policy moved, and on a domain controller line it up against a Group Policy refresh before treating it as tampering.

When to ignore it: A Group Policy refresh re-applying the same policy on a domain controller produces this event with nothing having changed.

References:

Where to look next:

  • Use SubcategoryGuid to see which subcategory changed
  • On DCs, correlate with GPO refresh before treating every hit as tamper

Related reasons:

Fields it can set: win.eventlog.security.audit_subcategory_guid

crypto_selftest_failed​

A FIPS cryptographic self-test failed. The platform could not verify its crypto primitives.

Severity: Error

Impact: Cryptographic operations on the host may be untrustworthy until the failure is explained and fixed. Rare on healthy fleets.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 6418

Where to look next:

  • Inspect ProcessName when present
  • Correlate with recent firmware, driver, or policy changes

Related reasons:

directory_object_access_denied​

Something asked for access to a directory service object and was refused. Windows records this only for objects an administrator chose to audit, so the object itself was considered worth watching.

Severity: Notice

Impact: Nothing was changed or read: the refusal is the outcome. Repeated refusals from one account usually mean a service is misconfigured, and refusals against sensitive objects are worth a closer look.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4662

Where to look next:

  • Check whether the requesting account is expected to touch this object at all
  • Repeated identical refusals usually point at an application or service account, not at a person
  • Remember these rows exist only for objects with auditing configured, so absence proves nothing

Related reasons:

directory_object_changed​

A directory service object was modified or moved. Typical on domain controllers when Directory Service Changes auditing is enabled for the object.

Severity: Warning

Impact: Directory state that apps and auth depend on may have changed. Unexpected attribute edits or moves can alter access control or break dependent services.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 5136, 5139

Where to look next:

  • Pivot on ObjectDN and AttributeLDAPDisplayName; do not expect AttributeValue in curated fields
  • Confirm the change Subject against approved admin or sync tooling

Related reasons:

Fields it can set: win.eventlog.security.attribute_name, win.eventlog.security.object_dn

config_change.action names the direction the event recorded, so pivot on the action rather than assuming one value.

directory_object_created​

A directory service object was created. Typical on domain controllers when Directory Service Changes auditing is enabled for the object.

Severity: Warning

Impact: Directory state that apps and auth depend on may have changed. An unexpected new object can alter access control or break dependent services.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 5137, 5138

Where to look next:

  • Pivot on ObjectDN and AttributeLDAPDisplayName; do not expect AttributeValue in curated fields
  • Confirm the change Subject against approved admin or sync tooling

Related reasons:

Fields it can set: win.eventlog.security.attribute_name, win.eventlog.security.object_dn

directory_object_deleted​

A directory service object was deleted.

Severity: Warning

Impact: Directory state that apps and auth depend on has changed. Dependent grants, policy links, or lookups may now resolve to nothing.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 5141

Where to look next:

  • Pivot on ObjectDN and AttributeLDAPDisplayName; do not expect AttributeValue in curated fields
  • Confirm the change Subject against approved admin or sync tooling

Related reasons:

Fields it can set: win.eventlog.security.attribute_name, win.eventlog.security.object_dn

directory_replication_access_requested​

An account asked a domain controller for directory replication rights, the access that lets a caller read directory content in bulk. Domain controllers do this with each other constantly; almost nothing else has a reason to.

Severity: Warning (any other account) / Info (a domain controller, a platform identity, or a directory-sync connector under its default name)

Impact: Replication access can expose directory content wholesale, including password material, which is why it is the access an attacker seeks after gaining a foothold. It is also exactly what directory sync tooling uses, so the question is always which account asked.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4662

Where to look next:

  • Identify the requesting account: a machine account or your identity-sync service account is expected, anything else is not
  • Confirm the account against the sync tooling your estate actually runs before treating it as hostile
  • A connector-shaped account name is not proof of anything: the name is chosen by whoever created the account
  • Pivot on the account across the same window: a credential dump is preceded by a sign-in from somewhere

Related reasons:

The rights ride the Properties field as a GUID list whose brace wrapping and letter case vary across builds, so a query against the raw payload should casefold and match inside the list rather than compare a formatted value. Every replication access carries this same reason whatever its band, so a query on the reason returns all of it; the band records how routine the requester looked, never whether it was authorized.

domain_policy_changed​

Password or lockout policy for a domain was changed.

Severity: Warning; Debug for the platform writing a new machine's own setup policy

Impact: Credential strength and lockout protection for every principal under that domain differ from this point on. A weakening shows up nowhere else, since no host reports being easier to attack.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4739

Where to look next:

  • Compare the settings in the retained payload against the intended policy baseline
  • Confirm a change request exists, since the row states that policy moved and not why

Related reasons:

The domain the policy belongs to rides the config-change target. The full before-and-after setting list stays in the retained event payload rather than becoming fields.

dsrm_password_change_failed​

An attempt to set the Directory Services Restore Mode (DSRM) password on a domain controller did not succeed. That password unlocks offline DC recovery.

Severity: Error

Impact: The offline recovery credential is unchanged. The attempt itself is worth accounting for, since the same action succeeding would hand its holder offline access to the controller.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4794

Where to look next:

  • Confirm change window and Subject against approved DC maintenance
  • Use Workstation when present to locate where the attempt ran
  • Repeated failures from one source are worth separating from a single mistyped attempt

Related reasons:

Fields it can set: win.eventlog.security.workstation

DC-only in practice. The event proves the attempt, not that any password was used.

dsrm_password_changed​

The Directory Services Restore Mode (DSRM) password was set on a domain controller. That password unlocks offline DC recovery.

Severity: Serious

Impact: Whoever holds the DSRM password can recover or manipulate that DC offline. Unexpected changes are a high-priority integrity concern.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4794

Where to look next:

  • Confirm change window and Subject against approved DC maintenance
  • Use Workstation when present to locate where the change ran

Related reasons:

Fields it can set: win.eventlog.security.workstation

DC-only in practice. The event proves the change, not that the password was used.

event_logging_stopped​

The Windows event logging service stopped, which is what a clean shutdown or restart of the host looks like in this channel.

Severity: Info

Channel: Security

Provider: Microsoft-Windows-Eventlog

Event ids: 1100

Where to look next:

  • A gap in this channel that starts at one of these rows is explained by the host being down
  • A gap with no such row before it is the shape worth looking at

Related reasons:

This row describes the HOST event log service, not the SparkLogs collector.

explicit_credential_used​

A process used another account's credentials to sign on (explicit credential use), and the caller was not a routine OS component. Often runas, remote tools, or lateral movement.

Severity: Info

Impact: May be legitimate admin or automation activity. Unexpected processes warrant follow-up for credential misuse; do not treat a single event as proof of compromise.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4648

Where to look next:

  • Inspect ProcessName, Subject, and TargetUserName together
  • Allowlist maturity varies by estate; tune before raising severity

Related reasons:

  • sign_in_failed: failed attempts may appear nearby in an attack chain

Fields it can set: win.eventlog.security.target_server

Low severity by design: the reason token is the durable signal on this row, not the band. Pivot on the reason and read the calling process, rather than filtering by severity.

firewall_rule_changed​

A Windows Firewall rule or related policy was modified, enabled, or disabled. This Security-channel copy fires when that audit subcategory is enabled.

Also reported by: Windows network event channels

Severity: Warning

Impact: What traffic is allowed or blocked can change. Unexpected opens can expose services; unexpected closes can break apps.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4947, 4950, 4954, 4956, 4957

CaseSeverityTicket classEvent ids
updatedWarningnetworking4947, 4950, 4957
enabledWarningnetworking4956
disabledWarningnetworking4954

Where to look next:

  • Pivot on RuleName / RuleId and Subject
  • The change action names the direction: updated, enabled, or disabled
  • Prefer the Firewall operational channel when Security auditing is off

Related reasons:

Fields it can set: win.eventlog.security.rule_id, win.eventlog.security.rule_name

firewall_rule_created​

A Windows Firewall rule was added to the exception list. This Security-channel copy fires when that audit subcategory is enabled.

Also reported by: Windows network event channels

Severity: Warning

Impact: What traffic is allowed can change. Unexpected opens can expose services.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4946

Where to look next:

  • Pivot on RuleName / RuleId and Subject
  • Prefer the Firewall operational channel when Security auditing is off

Related reasons:

Fields it can set: win.eventlog.security.rule_id, win.eventlog.security.rule_name

firewall_rule_deleted​

A Windows Firewall rule was deleted from the exception list. This Security-channel copy fires when that audit subcategory is enabled.

Also reported by: Windows network event channels

Severity: Warning

Impact: What traffic is allowed or blocked can change. Unexpected closes can break apps.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4948

Where to look next:

  • Pivot on RuleName / RuleId and Subject
  • Prefer the Firewall operational channel when Security auditing is off

Related reasons:

Fields it can set: win.eventlog.security.rule_id, win.eventlog.security.rule_name

firewall_service_stopped​

The Windows Firewall service or driver stopped, or came back (RECOVERED).

Severity: Warning or Info

Impact: Packet filtering and some connection protections are unavailable while stopped. Unexpected stops can expose the host or hide lateral movement.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 5024, 5025, 5033, 5034

CaseSeverityTicket class
stoppedWarningnetworking
recoveredInfonetworking

Where to look next:

  • Confirm whether stop was planned maintenance
  • Check for paired start events and adjacent rule changes

Related reasons:

group_member_added​

A member was added to a security-enabled group. Adds to privileged groups (Administrators, Domain Admins, and similar) carry the highest band, because they grant rights nothing takes back on its own.

Severity: Error (privileged group) / Notice (any other security group)

Impact: The member gains every right the group carries, immediately and until somebody reverses the membership. A privileged-group add can grant code-execution or broad data-access equivalence.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4728, 4732, 4756

What you see: Event 4728, 4732 or 4756, "member added to security group", naming the account that made the change, the group and the member that joined it.

What it means: The member holds every right the group carries from the next time it authenticates, and keeps them until removed. An add to Administrators, Domain Admins or an operator group is the case to read first; any other group is routine directory work. The event proves the grant, not that it was unwanted.

What to do: For a privileged group, confirm today who made the change and why. For any other group, keep the row for later access history.

References:

Example

A member was added to a security-enabled local group.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4732
event_data.TargetUserName: Administrators
event_data.TargetSid: S-1-5-32-544
event_data.MemberName: -
event_data.SubjectUserName: ExampleAdmin

SparkLogs: group_member_added, Error, group_member_added: NOTABLE: member added to security group | actor=ExampleAdmin target=Administrators

Where to look next:

  • The group is the target (kind group): every change to it is one target.id query
  • The added principal is the member family; group-in-group nesting reads member.kind
  • Locale-safe: the privilege test uses SID/RID, not the group display name

Related reasons:

group_member_removed​

A member was removed from a security-enabled group. Removals from privileged groups carry a higher band than ordinary group churn, because losing the last administrator or leaving Protected Users weakens the host in ways nothing else reports.

Severity: Warning (privileged group) / Notice (any other security group)

Impact: The member loses every right the group carried. A privileged removal can leave a machine with nobody able to administer it, or strip an account of the credential protections it relied on.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4729, 4733, 4757

Where to look next:

  • The group is the target (kind group): every change to it is one target.id query
  • The removed principal is the member family; group-in-group nesting reads member.kind
  • Scheduled deprovisioning produces this row too; the event cannot tell it from tampering

Related reasons:

guest_account_sign_in​

The built-in guest account signed in successfully. Windows disables that account by default, so a sign-in on it means somebody enabled it.

Severity: Notice

Impact: An account with no password and no owner can reach this machine. Whether that matters depends on what it can reach, which the sign-in type and the session on this row are the start of answering.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4624

Where to look next:

  • Check whether the account was enabled deliberately: kiosk and lab builds do this on purpose
  • A network sign-in over the legacy file-sharing package is usually guest fallback from an older storage or sharing target rather than somebody sitting at the machine

Related reasons:

Fields it can set: win.eventlog.security.auth_package, win.eventlog.security.lm_package, win.eventlog.security.logon_guid, win.eventlog.security.logon_type, win.eventlog.security.logon_type_name, win.eventlog.security.token_elevated, win.eventlog.security.workstation

Guest is a real account with a fixed allocation, and it is not the anonymous well-known identity that the identity-less sign-in surfaces cover: those name the absence of a principal, this names a principal that exists and is normally switched off.

kerberos_preauth_failed​

Kerberos pre-authentication failed at the domain controller. The decoded reason is on the line, so a wrong password reads differently from a disabled account or a clock that has drifted.

Severity: Warning (account state or broken infrastructure) / Notice (wrong password, unknown client, undecoded)

Impact: Authentication to the domain is failing for that principal from the reported client address. Can precede account lockout.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4771

Where to look next:

  • Join IpAddress to lockout CallerComputerName when both fire
  • Group by the cause token before reading volume: one cause is usually most of it

Related reasons:

Fields it can set: win.eventlog.security.kerberos_target, win.eventlog.security.status, win.eventlog.security.status_meaning

kerberos_rc4_ticket_issued​

A Kerberos service ticket used weak RC4 encryption for a user-backed service principal. Often a credential-theft / downgrade signal when unexpected.

Severity: Warning

Impact: Ticket material may be easier to crack offline (kerberoasting). Indicates weak crypto still accepted for that SPN.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4769

Where to look next:

  • Confirm ServiceName is unexpected for RC4 in your estate
  • Prefer AES-only policy for service accounts where feasible

Related reasons:

Fields it can set: win.eventlog.security.etype_meaning, win.eventlog.security.kerberos_target, win.eventlog.security.ticket_encryption_type

kerberos_ticket_failed​

A Kerberos ticket request, service-ticket request or renewal was denied. The reason the domain gave is on the line, and the variant says which of the three operations failed.

Severity: Warning (account state or broken infrastructure) / Notice (wrong password, unknown principal, expired, undecoded)

Impact: The principal cannot obtain or renew Kerberos tickets for the reported service, which blocks domain-authenticated access until the cause is fixed.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4768, 4769, 4770

CaseSeverityTicket class
tgt_requestWarningauth
service_ticketWarningauth
ticket_renewalWarningauth

Where to look next:

  • Group by the cause token first: one cause is usually most of the volume
  • On the service-ticket variant, group by the service principal: a decommissioned service shows up as one name repeating
  • Confirm the host is a domain controller or ticket-issuing authority before over-weighting volume

Related reasons:

Fields it can set: win.eventlog.security.kerberos_target, win.eventlog.security.status, win.eventlog.security.status_meaning

logon_right_granted​

A system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was granted to a principal in local security policy.

Severity: Notice

Impact: The set of principals allowed to sign in to this machine, and by which path, widened. A grant of remote or service sign-in rights to an unexpected principal is a persistence surface.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4717

What you see: Event 4717, "system logon right granted", with the right named inline (interactive, network, batch, service or remote desktop sign-in, or one of their deny counterparts) and the principal it was granted to.

What it means: Local security policy now lets one more principal sign in to this machine by that path. A grant of remote or service sign-in to an unexpected principal is a way to keep access.

What to do: Check the principal and the right against what this machine is meant to allow, and explain any grant that was not the machine restating its own policy at boot.

When to ignore it: Boot-time policy application by SYSTEM onto built-in group identifiers restates existing policy.

References:

Where to look next:

  • The modified principal is the target; built-in group SIDs are the common form
  • The decoded right rides inline; an undecoded value means the raw constant is in event_data
  • Boot-time runs by SYSTEM are routine policy application, not an administrator acting

Related reasons:

logon_right_removed​

A system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was removed from a principal in local security policy.

Severity: Notice

Impact: The set of principals allowed to sign in to this machine narrowed. A service or scheduled job relying on the removed right will fail its next sign-in; a removed deny right silently widens access.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4718

Where to look next:

  • The modified principal is the target; built-in group SIDs are the common form
  • The decoded right rides inline; an undecoded value means the raw constant is in event_data
  • Removing a deny_* right WIDENS access even though the event reads as a removal

Related reasons:

network_share_added​

A new network share was created on the host.

Severity: Warning

Impact: Remote clients may read or write the shared path. Unexpected shares are a common persistence and data-exposure path.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 5142

Where to look next:

  • Inspect ShareName, ShareLocalPath, and Subject
  • Confirm the share is expected inventory for that host role

Related reasons:

Fields it can set: win.eventlog.security.share_name, win.eventlog.security.share_path

nps_access_denied​

Network Policy Server denied a connection request. The decoded decision is on the line, so a wrong password reads differently from a request that matched no policy at all.

Severity: Warning (policy or infrastructure defect) / Notice (credentials, account state, undecoded)

Impact: The client did not gain network access through RADIUS. Repeated denials can lock users out of VPN or wireless access.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 6273

Where to look next:

  • Group by the decision token before reading volume: one decision is usually most of it
  • Grants (6272) can mask MFA-extension denials upstream; do not treat grant-only as proof of MFA success
  • Rows with no decision token still carry the raw code in the tail and in the field, so they stay countable

Related reasons:

Fields it can set: win.eventlog.security.nps_policy, win.eventlog.security.nps_reason_code, win.eventlog.security.nps_reason_meaning

nps_lockout​

Network Policy Server locked an account after repeated failed authentication attempts, so the account cannot authenticate through RADIUS until the lockout clears.

Severity: Error (privileged account) / Warning

Impact: The user cannot authenticate through the network policy plane until unlock or lockout expiry. Can block VPN or wireless access even when the directory account looks healthy.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 6279

Where to look next:

  • Join to the directory lockout and to the denials on the same principal inside the window
  • Identify the network access server generating the failures, not only the locked account

Related reasons:

Fields it can set: win.eventlog.security.nps_reason_code, win.eventlog.security.nps_reason_meaning

nps_request_discarded​

Network Policy Server discarded a connection request without processing it, which is different from denying one: the request never reached a policy decision.

Severity: Warning

Impact: The client did not authenticate. Discard storms usually mean a mismatched RADIUS shared secret, an unregistered network access server, or malformed requests.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 6274

Where to look next:

  • Group by the origin host first: a discard storm from one client is a configuration fix, not a user problem
  • Check the RADIUS client definitions and the shared secret before looking at policies

Related reasons:

Fields it can set: win.eventlog.security.nps_policy, win.eventlog.security.nps_reason_code, win.eventlog.security.nps_reason_meaning

A decision code this module does not decode renders no token, and the raw value still reaches the tail and the field, so those rows stay countable.

ntlm_validation_failed​

NTLM credential validation failed for an account. Can appear on workstations (local accounts) as well as domain controllers, and the decoded reason is on the line.

Severity: Warning (account state) / Notice (wrong password, unknown username, undecoded)

Impact: Sign-in using NTLM is failing for that account from the reported workstation, which blocks access until credentials or account state are fixed.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4776, 4777

Where to look next:

  • Use Workstation as the client to investigate
  • Group by the cause token before reading volume: one cause is usually most of it

Related reasons:

Fields it can set: win.eventlog.security.status, win.eventlog.security.status_meaning, win.eventlog.security.workstation

principal_renamed​

A security principal was renamed. The identifier is unchanged, so events before and after this row describe the same principal under two different names.

Severity: Notice for a rename that changed the name; Debug when the old and new names are identical

Impact: Reports, dashboards and saved queries keyed on the NAME stop matching the principal after this point, while anything keyed on the identifier is unaffected. Renaming a well-known account is also a recognized way to make a privileged identity harder to spot by name.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4781

Where to look next:

  • The old and new names ride the event; join on the identifier rather than the name across it
  • A rename of a built-in or privileged principal is worth confirming against the request for it

Related reasons:

Fields it can set: win.eventlog.security.new_target_user, win.eventlog.security.old_target_user

The id covers any SAM principal, groups included, so read the principal class off the event rather than assuming a user account.

process_exited_abnormally​

A process was stopped by Windows part way through something it could not execute, such as a bad memory access or a corrupted heap. The program did not exit on its own terms.

Severity: Notice

Impact: Whatever the process was doing did not finish. One row does not say anything is still wrong: a crash and a missing library both end a process this way, and most of them are background work that simply started again.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4689

Where to look next:

  • Look for an app_crash row on the same host and minute, then read the application log around it
  • The exit status names the kind of crash: the result code and its constant name ride the event
  • One abnormal exit is ordinary; the same image ending this way again and again, or across many hosts, is the shape to chase
  • Join to the process creation record on the host to see what started it and with what arguments

Related reasons:

  • app_crash: the Windows Error Reporting record for the same termination, when one exists

psdirect_handshake_probe​

Hyper-V opened a PowerShell Direct channel to a guest virtual machine. The legacy handshake negotiates through the sign-in path, so Windows records it as a failed sign-in, but no account was involved and no action is needed.

Severity: Debug

Impact: None. The channel negotiation is how the host reaches a guest for management; the row exists so the negotiation is datable, not because anything is wrong. It appears on hypervisors with guests that use the legacy handshake and stops when those guests move to the modern one.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4625

Where to look next:

  • Read these rows as hypervisor-to-guest channel activity, not as sign-in failures
  • Exclude them before counting failed sign-ins on a Hyper-V host

Related reasons:

Fields it can set: win.eventlog.security.auth_package, win.eventlog.security.lm_package, win.eventlog.security.logon_type, win.eventlog.security.logon_type_name, win.eventlog.security.psdirect_handshake, win.eventlog.security.status, win.eventlog.security.status_meaning, win.eventlog.security.substatus, win.eventlog.security.workstation

The account name on these rows is a fixed protocol constant, not a principal, and the domain field carries handshake bytes rather than a domain name. Neither is a value to pivot on.

replay_attack_detected​

Windows reported a Kerberos authentication replay. Rare; treat as high-signal even as a single event.

Severity: Error

Impact: Credentials or tickets may be reused by an attacker. Investigate immediately; do not assume compromise is proven from this event alone.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4649

Where to look next:

  • Correlate time skew, duplicate authenticators, and the Subject fields
  • Check for concurrent lateral movement or ticket anomalies on the same principals

Related reasons:

One event is enough to act on. The event reports a detected replay; it does not show that any access succeeded.

scheduled_task_created​

A scheduled task was created.

Severity: Warning

Impact: The new task can run code on a schedule or at logon, under whatever identity it was registered with. Unexpected creates are a common persistence path.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4698

Example

A scheduled task was created.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4698
event_data.TaskName: \Example\SyncTask
event_data.SubjectUserName: ExampleAdmin
event_data.SubjectUserSid: S-1-5-21-1111111111-2222222222-3333333333-1001
event_data.TaskContent: task definition xml omitted

SparkLogs: scheduled_task_created, Warning, scheduled_task_created: NOTABLE: A scheduled task was created.

Where to look next:

  • Pivot on TaskName and Subject
  • Task XML stays in the raw payload; do not expect it as a curated field
  • The run-as password is not in the XML; Command and Arguments may still hold secrets and are swept with other event_data strings

Related reasons:

Fields it can set: win.eventlog.security.task_name

scheduled_task_deleted​

A scheduled task was deleted.

Severity: Warning

Impact: Whatever the task did on its schedule will not happen again, and nothing on the host restores it. A deletion can equally be routine housekeeping or an attacker removing their own task after it ran.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4699

Where to look next:

  • Pivot on TaskName and Subject
  • Check whether the same task name was created shortly before
  • Task XML stays in the raw payload; do not expect it as a curated field

Related reasons:

Fields it can set: win.eventlog.security.task_name

scheduled_task_disabled​

A scheduled task was disabled. The task still exists and no longer runs.

Severity: Info

Impact: Whatever the task did on its schedule stops until it is enabled again. Most disables are routine, but disabling a monitoring or backup job is also how it is switched off quietly.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4701

Where to look next:

  • Pivot on TaskName and Subject
  • A re-enable is not labeled on its own; read the disable next to the surrounding activity
  • Task XML stays in the raw payload; do not expect it as a curated field

Related reasons:

Fields it can set: win.eventlog.security.task_name

scheduled_task_updated​

An existing scheduled task's definition was updated.

Severity: Warning

Impact: The task keeps its name and now runs something else, on a different schedule, or as a different identity. An edit to a trusted task is a quieter persistence path than a new one.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4702

Where to look next:

  • Pivot on TaskName and Subject
  • Compare against the last create or update of the same task name
  • Task XML stays in the raw payload; do not expect it as a curated field

Related reasons:

Fields it can set: win.eventlog.security.task_name

security_group_changed​

A security group's scope, type, or attributes changed. Changes to privileged groups (Administrators, Domain Admins, and similar) carry a higher band.

Severity: Warning for a privileged group, Notice for any other security group, Info when Windows configures its own builtin groups.

Impact: What the group reaches changes everywhere it is referenced, for every member at once. A retype or re-scope carries the existing members into a different set of resources.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4735, 4737, 4755, 4764

Where to look next:

  • The group is the target (kind group): every change to it is one target.id query
  • Locale-safe: privilege test uses SID/RID, not group display name
  • These ids grant nothing: a membership change is a different reason

Related reasons:

security_group_created​

A security group was created. Creation of a privileged group (Administrators, Domain Admins, and similar) carries a higher band.

Severity: Warning for a privileged group, Notice for any other security group, Info when Windows provisions its own builtin groups.

Impact: A new grant surface exists. Nothing has been granted through it yet: everything added to the group later inherits whatever the group carries.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4727, 4731, 4754

Where to look next:

  • The group is the target (kind group): every change to it is one target.id query
  • Locale-safe: privilege test uses SID/RID, not group display name
  • Windows creating its own builtin groups during setup is the everyday-tier population

Related reasons:

security_group_deleted​

A security group was deleted. Deletion of a privileged group (Administrators, Domain Admins, and similar) carries a higher band.

Severity: Warning for a privileged group, Notice for any other security group.

Impact: Every account that held rights through the group loses them at once, and permission references to the group elsewhere stop resolving. Nothing on the host reconciles that.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4730, 4734, 4758

Where to look next:

  • The group is the target (kind group): every change to it is one target.id query
  • Locale-safe: privilege test uses SID/RID, not group display name
  • Windows never deletes its own builtin groups, so a SYSTEM delete of one is not provisioning

Related reasons:

service_installed​

A Windows service was installed. This Security-channel event appears when service-install auditing is enabled; the System channel often carries the same fact by default.

Also reported by: Windows System event log

Severity: Notice

Impact: A new service can run code at boot or on demand under a chosen account. Unexpected installs are a common persistence path.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4697

Where to look next:

  • Inspect the service name, the installed image path, and the account it runs as together
  • Cross-check System SCM install events when Security auditing is off

Related reasons:

Fields it can set: command_line, win.eventlog.security.service_account, win.eventlog.security.service_image_path, win.eventlog.security.service_name

sid_history_add_failed​

An attempt to add SID History to an account did not succeed. Rare outside migrations.

Severity: Error

Impact: The account's rights are unchanged. The attempt is still worth accounting for, since the same action succeeding would give the account rights carried by another domain SID.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4766

Where to look next:

  • Confirm whether a domain migration or SID-history tooling is in progress
  • Inspect Subject and TargetUserName together
  • Repeated failures against one target read differently from a single tooling error

Related reasons:

The event proves the attempt, not that any rights were inherited.

sid_history_added​

SID History was added to an account. Rare outside migrations; often a privilege-inheritance or persistence tell.

Severity: Serious

Impact: The account inherits rights carried by the added SID, including rights granted in another domain. Treat unexpected adds as high-signal until migration context is confirmed.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4765

Where to look next:

  • Confirm whether a domain migration or SID-history tooling is in progress
  • Inspect Subject and TargetUserName together

Related reasons:

One event is enough to act on. The event proves the SID History write; it does not show that the inherited rights were used.

sign_in_failed​

A sign-in attempt failed. Account-state failures (disabled, locked, expired, denied by policy) are more actionable than a single bad password.

Severity: Warning (account-state) / Notice (other) / Verbose (credential-less probe)

Impact: User or service may be unable to authenticate. Repeated failures can precede lockout; source IP and workstation identify where attempts originate.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4625

What you see: A sign-in failure on the Security channel, event 4625, rendered as "sign-in failed" with the decoded cause, the logon type and the package that answered. The account that failed, the machine and address the attempt came from, and the failure code ride the same line.

What it means: Something presented credentials this host rejected. A bad password, unknown username or expired password is one failed attempt, and the account and host are unchanged. A disabled, locked or expired account, a denied logon right, an hours or workstation restriction, or an authentication-firewall refusal means that principal cannot authenticate at all until the account state changes.

What to do: Read the cause first. Fix the account state if that is the cause; otherwise check whether the account, source address and machine show one mistype or a burst.

When to ignore it: Ignore a single mistyped password and the credential-less probe common on backup and management agents, which names no account or source machine.

References:

Example

An account failed to log on.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4625
event_data.Status: 0xC000006E
event_data.SubStatus: 0xC0000072
event_data.LogonType: 3
event_data.TargetUserName: ExampleSvc
event_data.TargetUserSid: S-1-5-21-1111111111-2222222222-3333333333-1002
event_data.SubjectUserSid: S-1-5-21-1111111111-2222222222-3333333333-1001
event_data.SubjectUserName: ExampleAdmin
event_data.AuthenticationPackageName: NTLM
event_data.LmPackageName: NTLM V2
event_data.IpAddress: 203.0.113.11

SparkLogs: sign_in_failed, Warning, sign_in_failed: NOTABLE: sign-in failed; account_disabled logon_network by_account auth_ntlm | actor=ExampleSvc running_as=ExampleAdmin error_code=0xc0000072 lm_package="NTLM V2" origin_ip=203.0.113.11

CaseSeverityTicket class
account_attemptWarningauth
sspi_probeVerboseauth

Where to look next:

  • Decode Status/SubStatus for the failure cause
  • Pivot on TargetUserName, IpAddress, and WorkstationName
  • A lone mistyped password is common; look for bursts before treating as attack

Related reasons:

Fields it can set: win.eventlog.security.auth_package, win.eventlog.security.lm_package, win.eventlog.security.logon_type, win.eventlog.security.logon_type_name, win.eventlog.security.status, win.eventlog.security.status_meaning, win.eventlog.security.substatus, win.eventlog.security.workstation

Auth semantics: the interesting principal is the Target (who failed to authenticate), not the Subject (often NULL/SYSTEM on network failures). The Target is therefore the curated actor on this id; when the Subject names a real account it is the calling context and rides running_as, so its presence says the attempt came from somewhere other than the failing principal.

special_group_sign_in​

A logon matched an administrator-configured special-groups watchlist. These events exist only where that watchlist is enabled.

Severity: Warning

Impact: A watched principal or group membership appeared in a logon. Investigate against the local special-groups policy to see why it tripped.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4964

Where to look next:

  • Confirm the special-groups list on the host before treating volume as attack
  • Use TargetUserName and ParticularLogonId when present

Related reasons:

system_time_changed​

The system clock was changed. Routine time-service adjustments are quiet; changes from other processes are treated as integrity events.

Severity: Warning (non-time-service) / Debug (routine time service)

Impact: Clock skew can break Kerberos and confuse timelines used in investigation. Unexpected non-service changes deserve immediate review.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4616

CaseSeverityTicket class
routine_time_serviceDebugtime_sync
other_callerWarningtime_sync

Where to look next:

  • Inspect the process path and the actor together
  • previous_time and new_time carry the decoded before and after clock values in UTC

Related reasons:

Fields it can set: win.eventlog.security.new_time, win.eventlog.security.previous_time

win_insecure_boot_config​

The host booted with insecure Boot Configuration Data flags (test signing, kernel debug, or integrity checks disabled). The boot chain may accept unsigned or debugger-attached code.

Severity: Warning

Impact: Kernel integrity guarantees are weakened until the flags are cleared and the host reboots cleanly. Treat as a standing security-posture issue, not a one-shot exploit proof.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4826

Where to look next:

  • Confirm whether test-signing or kernel debugging is expected on that host class
  • Remediate BCD flags, then verify on next boot

Related reasons:

Fields it can set: win.eventlog.security.insecure_boot_flags

Flag names ride the message kv tail (InsecureBootFlags) when labeled.

win_registry_value_changed​

An audited registry value was modified. These events appear only where a SACL and the registry audit subcategory are aimed at that object.

Severity: Warning

Impact: Host configuration under that key changed. Persistence, policy, and credential material can live in registry values; unexpected edits deserve review of ObjectName and value name.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4657

Example

A registry value was modified.

channel: Security
provider_name: Microsoft-Windows-Security-Auditing
event_id: 4657
event_data.ObjectName: \REGISTRY\MACHINE\SOFTWARE\Example
event_data.ObjectValueName: Run
event_data.OperationType: %%1905
event_data.ProcessName: C:\Windows\regedit.exe
event_data.SubjectUserName: ExampleAdmin

SparkLogs: win_registry_value_changed, Warning, win_registry_value_changed: NOTABLE: A registry value was modified. | operation_meaning=value_modified

Where to look next:

  • Use ObjectName, ObjectValueName, and ProcessName
  • Do not expect Old/New value contents in curated fields

Related reasons:

Fields it can set: win.eventlog.security.object_name, win.eventlog.security.object_value_name, win.eventlog.security.operation_meaning

win_registry_value_created​

An audited registry value was created. These events appear only where a SACL and the registry audit subcategory are aimed at that object.

Severity: Warning

Impact: Host configuration under that key changed. Persistence, policy, and credential material can live in registry values; unexpected new values deserve review of ObjectName and value name.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4657

Where to look next:

  • Use ObjectName, ObjectValueName, and ProcessName
  • Do not expect Old/New value contents in curated fields

Related reasons:

Fields it can set: win.eventlog.security.object_name, win.eventlog.security.object_value_name, win.eventlog.security.operation_meaning

win_registry_value_deleted​

An audited registry value was deleted. These events appear only where a SACL and the registry audit subcategory are aimed at that object.

Severity: Warning

Impact: Host configuration under that key changed. A removed value can reopen a default that was deliberately overridden; unexpected deletions deserve review of ObjectName and value name.

Channel: Security

Provider: Microsoft-Windows-Security-Auditing

Event ids: 4657

Where to look next:

  • Use ObjectName, ObjectValueName, and ProcessName
  • Do not expect Old/New value contents in curated fields

Related reasons:

Fields it can set: win.eventlog.security.object_name, win.eventlog.security.object_value_name, win.eventlog.security.operation_meaning

Vocabularies​

These token sets are closed: a value outside the set leaves its field unset instead of invented.

auth_package​

Which authentication package answered. Only the curated packages render; any other package leaves the slot absent and stays queryable through the module auth_package field. auth_negoextender is the Entra negotiate-extension package (NegoExtender), the one cloud-joined endpoints authenticate through.

  • auth_kerberos
  • auth_ntlm
  • auth_negotiate
  • auth_negoextender

logon_right​

Which system logon right a policy change granted or removed, decoded from the Se*Right literal constant the provider writes into AccessGranted or AccessRemoved. A closed set of ten: the five ways Windows lets a principal sign in, and the five deny counterparts that block each of them. No token carries a digit, so every value is tokenizer-safe. A value the map does not carry renders no token and the raw value stays in the retained payload, so a decode gap reads as a token-less pattern rather than an invented meaning.

  • interactive
  • network
  • batch
  • service
  • remote_interactive
  • deny_interactive
  • deny_network
  • deny_batch
  • deny_service
  • deny_remote_interactive

subject_kind​

What sort of principal acted. Wider than the portable kind vocabulary, which collapses the three platform service identities into one service value: they are different operational shapes and scanning them apart is the point of the token. by_account states an ordinary directory account and never a person: no identifier proves a person without a directory lookup, so the token under-claims. by_anonymous states that the source said there was NO identity, which is a positive fact rather than an absent one, so the portable kind anonymous is written beside the token wherever a branch renders it. by_group reaches the sign-in id and the two ticket ids because the kind ladder reads group SID shapes on every principal pair, and every surface it can reach claims nothing about the principal in prose: a group cannot authenticate, so no headline naming a principal class could be true of one. It is the one rung with no portable kind beside it on the actor family.

  • by_account
  • by_machine
  • by_system
  • by_service
  • by_local_service
  • by_network_service
  • by_anonymous
  • by_group

target_kind​

What sort of principal was ACTED UPON, on the account-administration lines. Same value space as subject_kind and a separate slot on purpose: subject_kind states who acted, and one name meaning the acting principal on some lines and the object of the action on others would make every reading of it depend on which line it came from. The headline on these lines names the ACTION, so this token is where the principal is described: a group renamed, a computer account created and an ordinary account disabled are three patterns rather than one. A principal the ladder cannot read renders no token, so a gap in the reading shows as an absent token rather than as a wrong one.

  • by_account
  • by_machine
  • by_system
  • by_service
  • by_local_service
  • by_network_service
  • by_anonymous
  • by_group

token_elevated​

A flag, not a vocabulary: rendered only when the sign-in minted a full-privilege token. Absence means not-elevated or not-stated, and the presence of the token is what splits the admin-session pattern from the ordinary one. Same name as the module bool field.

  • token_elevated

uac_token_type​

What UAC did to the created process token, decoded from TokenElevationType: the same three values the promoted module field carries, so the token maps one to one onto a queryable field. Inline so a full token separates from ambient creation in the pattern. unsplit is TokenElevationTypeDefault (no filtered pair). full is TokenElevationTypeFull (type 2), not Default. An unrecognized reference renders no token and leaves the field unset.

  • unsplit
  • full
  • limited

Portable vocabularies​

Library-wide sets, so the same token means the same thing on every data feed.

sparklogs.actor.kind​

  • account: an ordinary directory account and never any other kind, not resolved any further
  • anonymous: a session opened under no identity, where the source states that no principal was named
  • machine: a computer account acting as itself (Windows names these with a trailing dollar sign; a group Managed Service Account name ends in one too, so a source reading the name alone reports a gMSA here when it is a service identity)
  • service: a service or daemon account, including the platform service identities
  • system: the operating system itself acting with no delegating principal

sparklogs.actor.type​

  • samaccountname: bare logon name with no domain suffix (the ordinary Windows account name)
  • sid: Windows security identifier (S-1-5-...)
  • upn: user principal name (user@domain email-shaped identity)

sparklogs.result.code_space​

  • kerberos: Kerberos protocol result code (KDC_ERR_*), a protocol space of its own, not an NTSTATUS
  • ntstatus: Windows NTSTATUS code (kernel and security subsystem)
  • sspi: Windows SSPI security result (SEC_E_*/SEC_I_*), the security-package half of HRESULT facility 9

sparklogs.running_as.kind​

  • account: an ordinary directory account and never any other kind, not resolved any further
  • anonymous: a session opened under no identity, where the source states that no principal was named
  • machine: a computer account acting as itself (Windows names these with a trailing dollar sign; a group Managed Service Account name ends in one too, so a source reading the name alone reports a gMSA here when it is a service identity)
  • service: a service or daemon account, including the platform service identities
  • system: the operating system itself acting with no delegating principal

sparklogs.running_as.type​

  • samaccountname: bare logon name with no domain suffix (the ordinary Windows account name)
  • sid: Windows security identifier (S-1-5-...)
  • upn: user principal name (user@domain email-shaped identity)

sparklogs.target.kind​

  • account: an ordinary directory account and never any other kind, not resolved any further
  • group: a security group as the subject, acted upon or nested as a member of another group
  • machine: a computer account acting as itself (Windows names these with a trailing dollar sign; a group Managed Service Account name ends in one too, so a source reading the name alone reports a gMSA here when it is a service identity)
  • service: a service or daemon account, including the platform service identities
  • system: the operating system itself acting with no delegating principal

sparklogs.target.type​

  • samaccountname: bare logon name with no domain suffix (the ordinary Windows account name)
  • sid: Windows security identifier (S-1-5-...)
  • upn: user principal name (user@domain email-shaped identity)

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.