skip to content

Search

Syspirit
EN

Event ID

The Windows security log event IDs worth knowing: logons, lockouts, Kerberos, Get-WinEvent queries and how to turn auditing on!

Windows
Published on
Karl Certa

The Windows security log records every authentication, account change and access attempt. The hard part is knowing which ID to look at. The IDs below apply to Windows Server 2016 through 2025.

🔐 Logons and sessions

📌 ID🧠 Meaning📊 When to look at it
4624Successful logonTrack who connected and from where
4625Failed logonBrute force, wrong password
4634LogoffWork out a session duration
4647User-initiated logoffTell a real RDP disconnect apart
4648Logon with explicit credentialsrunas, elevation, lateral movement
4672Special privileges assignedAn administrative session just opened
4776NTLM credential validationOn the DC, when the 4625 says nothing

🚪 Logon types

The “Logon Type” field on 4624 and 4625 tells you how the connection happened.

📌 Type🧠 Origin📊 Concrete example
2InteractiveKeyboard, physical console
3NetworkSMB share, remote access
4BatchScheduled task
5ServiceService startup
7UnlockBack from sleep
8Network cleartextIIS basic authentication
9New credentialsrunas /netonly
10Remote interactiveRDP
11Cached interactiveLaptop off the domain

❌ 4625 failure codes

The Sub Status field carries the real reason, the Status field usually showing the generic 0xC000006D.

📌 Code🧠 Actual cause
0xC0000064The account does not exist
0xC000006AWrong password
0xC0000072Account disabled
0xC0000234Account locked out
0xC0000070Workstation not allowed
0xC000006FLogon outside allowed hours
0xC0000071Password expired
0xC0000193Account expired
0xC0000133Clock skew between client and DC

🔒 Account lockout

📌 ID🧠 Meaning📊 Where to look
4740Account locked outOn the domain’s PDC emulator
4767Account unlockedWho unblocked it, and when
4771Kerberos pre-auth failureThe guilty host when 4740 is bare

👤 Accounts and groups

📌 ID🧠 Meaning
4720Account created
4722Account enabled
4725Account disabled
4726Account deleted
4738Account changed
4723Password changed by the user
4724Password reset by an administrator
4728Member added to a global group
4732Member added to a local group
4756Member added to a universal group

🎫 Kerberos

📌 ID🧠 Meaning
4768Authentication ticket requested (TGT)
4769Service ticket requested (TGS)
4771Pre-authentication failed
📌 Failure code🧠 Cause
0x6User unknown to the domain
0x12Account disabled, locked or expired
0x17Password expired
0x18Wrong password
0x25Clock skew over 5 minutes

🚨 Signals that should raise an eyebrow

📌 ID🧠 Meaning📊 Log
1102The audit log was clearedSecurity
4697A service was installedSecurity, 2016 and up
7045A service was installedSystem, on by default
4688New process createdSecurity
4719Audit policy was changedSecurity
4798Local group membership enumeratedSecurity, 2016 and up
5136An Active Directory object changedSecurity
4104PowerShell script block executedPowerShell/Operational

4697 and 7045 describe the same service installation seen from two subsystems. 7045 is on by default but does not say who did it, while 4697 needs auditing enabled and carries the account behind it.

🔎 Querying the log

📌 Action🧠 Command
🔍 Filter on an IDGet-WinEvent -FilterHashtable @{LogName='Security'; Id=4625}
🕐 Over the last 24 hGet-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)}
🖥️ On the PDC emulatorGet-WinEvent -ComputerName (Get-ADDomain).PDCEmulator -FilterHashtable @{LogName='Security'; Id=4740}
🔢 Cap the number of events... -MaxEvents 20
📖 Read the full detail... | Format-List TimeCreated, Message
🎯 Pull one field out... | ForEach-Object { $_.Properties[1].Value }
⚡ Without PowerShellwevtutil qe Security /q:"*[System[(EventID=4625)]]" /f:text /c:5 /rd:true
📏 Size and retentionGet-WinEvent -ListLog Security

⚙️ Turning auditing on

An ID missing from the log does not mean nothing happened: the subcategory is most likely not enabled.

📌 Action🧠 Command
📋 State of every categoryauditpol /get /category:*
📝 List the subcategoriesauditpol /list /subcategory:*
✅ Enable a subcategoryauditpol /set /subcategory:"Logon" /success:enable /failure:enable
📦 Grow the log (1 GB)wevtutil sl Security /ms:1073741824

Through group policy it all lives in Computer Configuration > Policies > Windows Settings > Security Settings > Advanced Audit Policy Configuration. To get the command line inside 4688 events, you also need to enable “Include command line in process creation events”.

🛠️ Common troubleshooting

🆘 Problem🧠 Solution
❌ The ID never shows upSubcategory not enabled, check with auditpol /get
🔍 No 4740 on the controller you queriedQuery the PDC emulator, it alone records it
📭 Events vanish quicklyLog full and wrapping, increase its size
🖥️ 4625 with no source machineNetwork logon, cross-check with 4776 on the DC
🌐 auditpol rejects a subcategoryNames are translated on a localised Windows
⏰ Unexplained Kerberos failuresClock skew, compare with w32tm /query /status

⚰️ IDs still quoted online that no longer exist

Plenty of guides still list three-digit identifiers. They belong to Windows Server 2003 and have not been generated since Vista and Server 2008. The conversion is mechanical: old identifier plus 4096.

📌 Old🧠 Current📊 Meaning
5284624Logon
5294625Failed logon
5384634Logoff
6244720Account created
6324728Added to a global group
6444740Account locked out
6754771Pre-authentication failure
6804776NTLM validation