Major Event ID for System Admin & Network Admin
Here are 100 major Event IDs that may be useful for external auditors to check:
Security Event IDs:
Event ID 4624 (Logon Success): Successful user logon events.
Event ID 4625 (Logon Failure): Failed user logon attempts.
Event ID 4648 (Explicit Credential Logon): Logon using explicit credentials.
Event ID 4740 (Account Lockout): Indicates when an account is locked out due to failed logon attempts.
Event ID 4768 (Kerberos Authentication): Records Kerberos authentication events.
Event ID 4771 (Kerberos Pre-Authentication Failure): Failed Kerberos pre-authentication attempts.
Event ID 4776 (NTLM Authentication): Logs NTLM authentication events.
Event ID 4793 (The Password Policy Checking API was called): Records password policy-related events.
Event ID 4946 (A change has been made to Windows Firewall exception list): Indicates changes to the Windows Firewall exception list.
Event ID 5024 (The Windows Firewall Service has started successfully): Firewall service start event.
Event ID 5140 (File System Authorization): File system authorization events.
Event ID 5152 (Windows Filtering Platform Blocked an Application): Indicates when an application is blocked by the Windows Filtering Platform.
Event ID 5156 (Filtering Platform Connection): Records network connection events.
Event ID 517 (Audit Policy Change): Logs changes to audit policy settings.
Event ID 538 (User Logoff): User logoff events.
Event ID 560 (Object Open): Records when an object (e.g., file) is opened.
Event ID 563 (Object Open Extended): Provides additional information about object access.
Event ID 5719 (NETLOGON): Indicates NETLOGON events, important for domain authentication.
Event ID 627 (User Account Locked Out): Records user account lockout events.
Event ID 628 (User Account Unlocked): Indicates when a locked user account is unlocked.
System Event IDs:
Event ID 6005 (The Event Log Service has started): Event Log Service start event.
Event ID 6006 (The Event Log Service has stopped): Event Log Service stop event.
Event ID 6008 (Unexpected Shutdown): Records unexpected server shutdowns.
Event ID 6013 (System Uptime): Provides information about system uptime.
Event ID 7024 (Service Control Manager): Logs service start and stop events.
Event ID 7030 (Service Control Manager): Records network service start and stop events.
Event ID 7035 (Service Control Manager): Indicates service status changes.
Event ID 8003 (Browser Service Elections): Records browser election events.
Event ID 8021 (Browser Service): Logs events related to the Computer Browser service.
Event ID 8022 (Browser Service): Indicates network master browser election events.
Event ID 1040 (Perfmon): Perfmon start/stop events for performance monitoring.
Event ID 1102 (Audit Log was cleared): Records when the security event log is cleared.
Event ID 1105 (Event log automatic backup): Indicates automatic backup of event logs.
Event ID 1202 (Security policies were propagated with...): Logs application of group policy settings.
Event ID 12288 (Software Protection Platform): Records Software Protection Platform service events.
Active Directory Event IDs:
Event ID 1100 (Event log startup): Event log startup events.
Event ID 1101 (Audit events have been dropped): Indicates dropped audit events.
Event ID 12294 (SAM Account Name Conflict): Records SAM account name conflicts.
Event ID 16969 (A security-disabled local group was changed): Logs changes to security-disabled local groups.
Event ID 16970 (A security-disabled global group was changed): Records changes to security-disabled global groups.
Event ID 5136 (Directory Service Changes): Logs Active Directory object changes.
Event ID 5312 (Filtering Platform Packet Drop): Records packet drop events by the Filtering Platform.
Event ID 5632 (Windows Firewall was unable to notify the user that it blocked an application): Indicates blocked applications by Windows Firewall.
Event ID 5805 (Session Setup): Logs session setup events, important for security.
Event ID 680 (Account Logon): Account logon events.
Event ID 681 (Account Logon): Account logon events.
Event ID 682 (Account Logon): Account logon events.
Event ID 683 (Account Logon): Account logon events.
Event ID 1207 (Account logon): Account logon events.
Event ID 1221 (The database engine attached a database...): Records database engine attachment events.
DNS Event IDs:
Event ID 4000 (DNS Server): Indicates DNS server issues related to Active Directory integration.
Event ID 4010 (DNS Server): Logs critical DNS events, including server startup and configuration changes.
Event ID 5015 (DNS Server): Records DNS server service startup and shutdown.
Event ID 5501 (DNS Server): Indicates DNS server forwarder configuration changes.
Event ID 7062 (DNS Server): Logs DNS server zone transfer events.
Event ID 762 (DNS Client): Records DNS client cache events.
Event ID 11001 (DNS Client Events): Provides information about DNS client events.
Event ID 11164 (DNS Client Events): Indicates DNS client cache registration events.
Event ID 4007 (DNS Server): Logs DNS server critical errors.
Event ID 4521 (DNS Server): Records DNS server service events, including successful startups.
Group Policy Event IDs:
Event ID 1500 (User Profile Service): User Profile Service events.
Event ID 1502 (User Profile Service): Logs user profile load and unload events.
Event ID 5016 (Group Policy Settings): Records changes to Group Policy settings.
Event ID 5116 (Group Policy Settings): Indicates Group Policy processing events.
Event ID 5320 (Group Policy Initialization): Logs Group Policy initialization events.
Event ID 8001 (Group Policy Service): Records Group Policy service startup and shutdown.
Event ID 8004 (Group Policy Service): Indicates Group Policy client-side extension events.
Event ID 8005 (Group Policy Service): Records Group Policy client-side extension events.
Event ID 8016 (Group Policy Service): Logs Group Policy processing start events.
Event ID 8017 (Group Policy Service): Indicates Group Policy processing end events.
File System Event IDs:
Event ID 4663 (File System Access - Object Access): Detailed information about file and folder access.
Event ID 5145 (File System Object Change): Records changes to file system objects, including file copying and moving operations.
Event ID 5140 (File System Authorization): File system authorization events.
Event ID 4660 (File System Object Deleted): Indicates when a file system object is deleted.
Event ID 5142 (File System Access - Object Closed): Records when an object (e.g., file) is closed.
Event ID 4656 (File System Access - Object Open): Indicates when an object (e.g., file) is opened.
Event ID 4662 (File System Access - Object Handle): Logs when an object handle is requested.
Event ID 560 (Object Open): Records when an object (e.g., file) is opened.
Event ID 562 (File System Object Deleted): Logs when a file system object is deleted.
Event ID 567 (File System Object Access): Provides information about file system object access.
Print Server Event IDs:
Event ID 307 (Print Queue Job): Records print job events on a print server.
Event ID 805 (Print Services): Indicates print spooler events on a print server.
Event ID 10 (Print Queue Properties): Logs changes to print queue properties.
Event ID 12 (Print Job Management): Records print job management events.
Event ID 30 (Printer Driver Management): Indicates printer driver management events.
Event ID 40 (Printer Driver Installation): Logs printer driver installation events.
Event ID 70 (Print Queue Document): Records print queue document events.
Event ID 221 (Print Service): Indicates general print service events.
Event ID 322 (Printer Driver): Logs printer driver events on a print server.
Event ID 370 (Print Queue Properties): Records changes to print queue properties.
Remote Desktop Services (RDS) Event IDs:
Event ID 1149 (Remote Desktop Services Authentication): Logs RDS authentication events.
Event ID 1152 (Remote Desktop Services Session Disconnected): Indicates RDS session disconnection events.
Event ID 1154 (Remote Desktop Services Session Reconnected): Records RDS session reconnection events.
Event ID 1155 (Remote Desktop Services Session Ended): Logs RDS session end events.
Event ID 131 (Remote Desktop Services Listener): Indicates RDS listener events.
Event ID 101 (Remote Desktop Services Manager): Records RDS manager events.
Event ID 103 (Remote Desktop Services Manager): Logs RDS manager events.
Event ID 102 (Remote Desktop Services Manager): Records RDS manager events.
Event ID 105 (Remote Desktop Services Manager): Logs RDS manager events.
Event ID 123 (Remote Desktop Services Manager): Indicates RDS manager events.
Web Server Event ID
Event ID 1007 (IIS Application Pool Recycling): Records when an Internet Information Services (IIS) application pool is recycled, which can affect web application availability.
Event ID 1009 (IIS Application Pool Restarted): Indicates when an IIS application pool is manually restarted, often done for troubleshooting purposes.
Event ID 1010 (IIS Application Pool Stopped): Logs when an IIS application pool is manually stopped, impacting web application availability.
Event ID 1020 (IIS Application Pool Availability): Provides information about the availability of an IIS application pool.
Event ID 1001 (IIS Web Site Started): Records when an IIS web site is started, indicating its availability.
Event ID 1002 (IIS Web Site Stopped): Logs when an IIS web site is manually stopped, affecting its availability.
Event ID 1074 (IIS Worker Process Crash): Indicates when an IIS worker process (w3wp.exe) crashes, potentially causing web application failures.
Event ID 1316 (ASP.NET Runtime Error): Logs ASP.NET runtime errors, including issues affecting web applications.
Event ID 5002 (DFS Namespace): Records Distributed File System (DFS) namespace events, which can impact web application file paths.
Event ID 5050 (DFS Replication): Indicates DFS Replication service events, which can affect web application file replication.
Network administrator Useful Event ID
Event ID 27 (Network Link is Up): Indicates that a network interface card (NIC) detected that its link to the network is up.
Event ID 51 (An error was detected on device): Logs disk I/O errors that can affect network performance.
Event ID 1001 (Name resolution for the name...): Records DNS name resolution events.
Event ID 2001 (PerfOS): Provides performance monitoring information, including network-related metrics.
Event ID 2011 (Network Errors): Records network-related errors.
Event ID 2012 (Server Message Block (SMB) Redirector): Logs events related to the SMB protocol, which is used for file sharing.
Event ID 2017 (The server was unable to allocate from the system nonpaged pool...): Indicates memory allocation issues that can impact network services.
Event ID 2020 (The server was unable to find a free connection...): Logs issues related to network connection limits.
Event ID 2021 (Server was unable to allocate from the system paged pool...): Records issues related to paged pool memory allocation.
Event ID 2022 (The server was unable to register the Administration Tool discovery information...): Logs issues with registering network services.
Event ID 4000 (DNS Server): Indicates DNS server issues related to Active Directory integration.
Event ID 4010 (DNS Server): Logs critical DNS events, including server startup and configuration changes.
Event ID 4625 (Logon Failure): Logs failed logon attempts, including those related to network authentication.
Event ID 4662 (An operation was performed on an object): Provides information about object access and changes, which can include network resource access.
Event ID 4771 (Kerberos pre-authentication failed): Records failed Kerberos pre-authentication attempts.
Event ID 5002 (DFS Namespace): Logs Distributed File System (DFS) namespace events, which are critical for network file sharing.
Event ID 5027 (Firewall): Indicates Windows Firewall service events, including rule changes and firewall state.
Event ID 5061 (Security Policy Changes): Logs changes to security policies that can impact network security.
Event ID 5152 (Windows Filtering Platform Blocked an Application): Records events related to network traffic blocked by the Windows Filtering Platform.
Event ID 6011 (Performance Monitoring): Provides performance-related data, including network-related metrics.
Event ID 6013 (System Uptime): Gives information about system uptime, which can be relevant for network stability assessments.
Event ID 7030 (Service Control Manager): Logs network service start and stop events.
Event ID 7040 (Service Control Manager): Records changes to network services' startup types.
Event ID 8003 (Browser Service Elections): Logs browser election events in network environments.
Event ID 8021 (Browser Service): Indicates events related to the Computer Browser service, which helps in network browsing.
Event ID 8022 (Browser Service): Logs events related to network master browser elections.
Event ID 9003 (DNS Server): Records DNS server events and issues.
Event ID 9010 (DNS Server): Logs DNS server startup and configuration changes.
Event ID 903 (Remote Desktop Services): Provides information about Remote Desktop Services (RDS) connections and sessions.
Event ID 10000 (DCOM): Logs Distributed Component Object Model (DCOM) issues, which can affect network communication.
Event ID 1001 (Windows Error Reporting): Records application or system errors that may affect network services.
Event ID 1002 (Application Hang): Logs application hangs that can impact network applications.
Event ID 1010 (Perfmon): Indicates when Performance Monitor starts or stops collecting data, which can include network metrics.
Event ID 1014 (Name resolution for the name...): Logs DNS name resolution events.
Event ID 1074 (Shutdown initiated by...): Indicates when a server is intentionally shut down or restarted, which can affect network services.
Event ID 2013 (NTDS Replication): Provides information about Active Directory replication events, critical for network infrastructure.
Event ID 3000 (PerfOS): Logs performance monitoring data, which includes network-related metrics.
Event ID 4199 (TCP/IP): Records TCP/IP network stack events, which can be critical for network troubleshooting.
Event ID 4226 (TCP/IP Network Stack Limit Reached): Indicates when the TCP/IP network stack's maximum connection limit is reached, impacting network performance.
Event ID 5009 (Winlogon): Logs Windows logon-related events, including network logon events.
Event ID 5027 (Firewall): Records Windows Firewall events, including rule changes that affect network traffic.
Event ID 5061 (Security Policy Changes): Logs changes to security policies that impact network security.
Event ID 5156 (Windows Filtering Platform): Provides information about network traffic allowed or blocked by the Windows Filtering Platform.
Event ID 6010 (Performance Monitoring): Indicates when Performance Monitor starts or stops collecting data, including network-related metrics.
Event ID 7030 (Service Control Manager): Records network service start and stop events.
Event ID 7034 (Service Control Manager): Indicates service termination events, including network services.
Event ID 8003 (Browser Service Elections): Logs browser election events in network environments.
Event ID 8021 (Browser Service): Indicates events related to the Computer Browser service, which helps in network browsing.
Event ID 8022 (Browser Service): Logs events related to network master browser elections.
Event ID 9003 (DNS Server): Records DNS server events and issues.
Comments
Post a Comment