Skip to content

v12 integrations: guides for Windows applications the agent already collects #2734

Description

@kryonsx

Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)

Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.

Why

Many Windows applications and server roles already write to event log channels the UTMStack agent reads. SQL Server and IIS are the two headline examples: without a card, customers assume we don't support them. This list says, for each one, what arrives today, what needs a setting, and what needs an agent change first.

Two agent limits decide how honest each guide can be (details in 0.4 and 4(c)(7) below): the agent keeps only named event data, so SQL Server, AD FS and others arrive with the event ID but without the user or address; and the Windows parser's drop list removes some events these guides need. Both are agent and parser work for their owners, not guide work. Link the issue that fixes them from each affected guide rather than waiting.

Checklist, most valuable first

  • Active Directory (domain controllers) (High): Partly: 5137, 5138, 5139 and 5141 (directory object created, undeleted, moved, deleted) are dropped by the parser …
  • Microsoft Defender Antivirus (High): Yes (1121 to 1126 only when those features are in audit or block mode)
  • Microsoft SQL Server (High): Partly: every event arrives with provider and event ID only; user, reason and client address are lost (unnamed data)
  • Internet Information Services (IIS) (High): Partly: service and worker events arrive, but 5057 and 5059 (application pool disabled) are dropped by the parser …
  • Remote Desktop (servers and workstations) (High): Partly: the session events arrive with the event ID only, and 4778 and 4779 are dropped by the parser
  • Remote Desktop Gateway (High): No: needs agent channel Microsoft-Windows-TerminalServices-Gateway/Operational added …
  • Network Policy Server (RADIUS for VPN and Wi-Fi) (High): Partly: 6274 and 6275 (discarded requests) are dropped by the parser; 6272 and 6273 arrive complete
  • Windows file access auditing (High): Yes, after a setting (audit policy and folder SACLs); 5145 is dropped by the parser
  • Sysmon (High): Partly: event 1 (process creation) is dropped by the parser
  • Active Directory Certificate Services (High): Partly: 4898 and 4899 (template loaded, template updated) are dropped by the parser; the rest arrive after the settings
  • Microsoft Exchange Server (on-premises) (Medium): No: needs agent channel MSExchange Management added, event 1 taken off the parser's drop list, and unnamed data kept (4(c)(7))
  • Windows DNS Server (Medium): No: needs agent channel Microsoft-Windows-DNSServer/Audit added (then complete, because the data is named)
  • Windows DHCP Server (Medium): No: needs the three channels added; lease history stays out of reach
  • NTLM authentication auditing (domain controllers) (Medium): Yes, after a setting (Group Policy)
  • App Control for Business (WDAC) (Medium): Yes, after a setting (an App Control policy)
  • AppLocker (Medium): No: needs the four AppLocker channels added, and even then only event IDs arrive until the agent reads UserData
  • Windows LAPS (Medium): No: needs agent channel Microsoft-Windows-LAPS/Operational added (then complete)
  • OpenSSH Server for Windows (Medium): No: needs agent channel OpenSSH/Operational added (then complete, because the data is named)
  • Hyper-V (Medium): No: needs both channels added, and even then the virtual machine name is lost until the agent reads UserData
  • Microsoft Entra Connect Sync (Medium): Partly (not confirmed): the event IDs arrive; details only if the data is named, which was not confirmed
  • Active Directory Federation Services (AD FS) (Medium): Partly: after the settings the Security events arrive with the event ID only (unnamed data); user and client address are lost
  • ConnectWise ScreenConnect (Medium): Partly: event IDs only (unnamed data); older clients log with event ID 0, which the parser drops
  • Windows Event Forwarding collector (Medium): Yes, after a setting (a forwarding subscription)
  • Print servers (Low): Partly: event IDs only (UserData)
  • Other antivirus products (Trellix or McAfee, Sophos Endpoint, Symantec Endpoint Protection) (Low): Partly: Trellix, McAfee and Sophos arrive with the event ID only; Symantec needs its channel added

The list in detail

Rules for every row (section 0.4):

  • "(read)" after a channel means it is in the agent's fixed list; "(not read)" means it is not, and the row needs that channel added to the channels slice in agent/collector/platform/windows_amd64.go (or the forwarding workaround in 4(b)).
  • The agent keeps only named event data. "Unnamed data" or "UserData" in a row means those details are lost and only provider, event ID, level, channel, computer and time arrive.
  • Every event ID below was checked against the drop step in windows-events.yaml; the row says when one is dropped.
  • The agent turns on only these audit subcategories itself (agent/dependency/auditpolicy_windows.go): Process Creation, Process Termination, Logon, Logoff, Account Lockout, Special Logon, Other Logon/Logoff Events, Security Group Management, User Account Management, Audit Policy Change and Sensitive Privilege Use. Anything else a row needs is a customer setting.
  • Base filter for every row: dataType is wineventlog. The column shows the rest.
Technology Why customers care How its logs reach UTMStack today Works today? Log Explorer filter Priority
Active Directory (domain controllers) Account takeover, privilege changes, Kerberos and NTLM attacks Security (read), provider Microsoft-Windows-Security-Auditing, named data: 4624 and 4625 logons, 4740 and 4767 lockout and unlock, 4720, 4722, 4725, 4726 and 4738 account changes, 4728, 4732 and 4756 group additions, 4768, 4769 and 4771 Kerberos, 4776 NTLM credential check, 5136 directory object modified, 4662 operation on an object (DCSync detection). The agent turns on logon, lockout, user and group management. Kerberos, credential validation and directory subcategories must be set on the domain controllers: "Audit Directory Service Changes" is off by default and also needs audit entries on the objects; "Audit Directory Service Access" logs successes by default. The Directory Service channel (not read) holds LDAP signing events 2887 and 2889 (2889 uses unnamed data). The v12 ad-audit plugin already uses 4720, 4726 and 4624 for its user list. Partly: 5137, 5138, 5139 and 5141 (directory object created, undeleted, moved, deleted) are dropped by the parser; LDAP signing events need channel Directory Service log.channel is Security; log.eventCode is one of 4625, 4740, 4720, 4726, 4728, 4732, 4756, 4768, 4769, 4771, 4776, 5136 High
Microsoft Defender Antivirus Malware found; protection turned off or changed Channel Microsoft-Windows-Windows Defender/Operational (read), provider Microsoft-Windows-Windows Defender. 1116 malware detected, 1117 action taken, 1118 and 1119 action failed, 1006 to 1008 (older detection events), 1015 suspicious behavior, 1121 and 1122 attack surface reduction block and audit, 1123 and 1124 controlled folder access, 1125 and 1126 network protection, 5001 real-time protection off, 5004 and 5007 settings changed, 5010 and 5012 scanning off, 5013 Tamper Protection blocked a change. Named data (names contain spaces, for example "Threat Name"). None is dropped. Yes (1121 to 1126 only when those features are in audit or block mode) log.providerName is Microsoft-Windows-Windows Defender; log.eventCode is one of 1116, 1117, 1118, 1119, 5001, 5007, 5013 High
Microsoft SQL Server Database logins, brute force, configuration changes, disk errors Application log (read), provider MSSQLSERVER (default instance) or MSSQL$<instance> (named instance); SQL Server Agent as SQLSERVERAGENT or SQLAgent$<instance>. 18456 login failed, 18453, 18454 and 18455 login succeeded, 18470 account disabled, 18486 locked out, 18487 and 18488 password expired or must change, 17162 and 17126 starting and ready, 17147 and 17148 stopping, 15457 configuration option changed, 33205 SQL Server Audit record, 18264 and 18265 backups, 823 to 825 disk read errors, 9002 log full. None is dropped. All use unnamed data. Settings in the detail below the table. Partly: every event arrives with provider and event ID only; user, reason and client address are lost (unnamed data) log.providerName is one of MSSQLSERVER, MSSQL$<instance>; log.eventCode is one of 18456, 18470, 18486 High
Internet Information Services (IIS) Web server crashes and errors; request logs for web attacks Arrives today: System (read), provider Microsoft-Windows-WAS: 5002 application pool disabled after repeated failures, 5009 worker process ended unexpectedly, 5010 no ping reply, 5011 fatal communication error, 5013 shutdown time exceeded, 5021 pool identity invalid, 5186 idle shutdown. Application (read), provider Microsoft-Windows-IIS-W3SVC-WP: 2268, 2269, 2276, 2280 (filter, worker and module failures). Both use named data. ASP.NET (ASP.NET 4.0.30319.0, 1309 unhandled exception, 1310 configuration error) uses unnamed data. Does not arrive: request logs (W3C text files by default) and configuration changes; detail below the table. Partly: service and worker events arrive, but 5057 and 5059 (application pool disabled) are dropped by the parser; request logs need channel Microsoft-IIS-Logging/Logs added log.providerName is one of Microsoft-Windows-WAS, Microsoft-Windows-IIS-W3SVC-WP; log.eventCode is one of 5002, 5009, 5010, 5011, 2276, 2280 High
Remote Desktop (servers and workstations) Remote logins, lateral movement Security (read): 4624 with logon type 10 and 4625 carry the user (target.user) and source address (origin.ip). Session channels (read): Microsoft-Windows-TerminalServices-LocalSessionManager/Operational 21 logon, 23 logoff, 24 disconnect, 25 reconnect, and Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational 1149 keep user and address in UserData. Security 4778 and 4779 (reconnect, disconnect; generated because the agent turns on Other Logon/Logoff Events) are on the drop list. Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational 131 (connection accepted, named ClientIP) and 140 (bad user name or password from an address, named IPString) are not read. Partly: the session events arrive with the event ID only, and 4778 and 4779 are dropped by the parser log.eventCode is one of 4624, 4625; log.eventDataLogonType is one of 10 (with Network Level Authentication, failed logons show as type 3) High
Remote Desktop Gateway Remote access from the internet Channel Microsoft-Windows-TerminalServices-Gateway/Operational (not read), provider Microsoft-Windows-TerminalServices-Gateway: 200 connection policy met, 201 denied, 300 and 301 resource policy, 302 connected, 303 disconnected (bytes, duration). User and client address are in UserData. No: needs agent channel Microsoft-Windows-TerminalServices-Gateway/Operational added, and even then only event IDs arrive until the agent reads UserData After the change: log.providerName is Microsoft-Windows-TerminalServices-Gateway; log.eventCode is one of 201, 302, 303 High
Network Policy Server (RADIUS for VPN and Wi-Fi) VPN and Wi-Fi logins granted and denied Security (read), provider Microsoft-Windows-Security-Auditing, named data (SubjectUserName, CallingStationID, NASIPv4Address): 6272 granted, 6273 denied, 6274 request discarded, 6275 accounting request discarded, 6276 quarantined, 6278 full access, 6279 account locked, 6280 unlocked. "Audit Network Policy Server" logs success and failure by default (check that a Group Policy does not override it). Partly: 6274 and 6275 (discarded requests) are dropped by the parser; 6272 and 6273 arrive complete log.channel is Security; log.eventCode is one of 6272, 6273, 6279 High
Windows file access auditing Who read, changed or deleted sensitive files; ransomware Security (read): 4656, 4660 (deleted), 4663 (accessed) and 4670 (permissions changed) need "Audit File System" plus audit entries (SACLs) on the folders; 5140 (share accessed) and 5142 to 5144 (share added, changed, deleted) need "Audit File Share"; 5145 needs "Audit Detailed File Share". The agent turns none of these on (it skips Object Access on purpose). Named data (log.eventDataObjectName, log.eventDataAccessMask). Yes, after a setting (audit policy and folder SACLs); 5145 is dropped by the parser log.channel is Security; log.eventCode is one of 4660, 4663, 4670, 5140, 5142, 5144 High
Sysmon Process, network, registry and DNS detail for detection Channel Microsoft-Windows-Sysmon/Operational (read), provider Microsoft-Windows-Sysmon: 1 process created, 3 network connection, 7 image loaded, 8 remote thread, 10 process access, 11 file created, 12 to 14 registry, 22 DNS query, 23 and 26 file delete, 25 process tampering, 29 executable file detected. Named data. Not installed by default (sysmon -accepteula -i <config>, or the built-in Windows 11 feature). Events 3 and 7 are off unless the config turns them on. Partly: event 1 (process creation) is dropped by the parser log.providerName is Microsoft-Windows-Sysmon; log.eventCode is one of 3, 11, 22 High
Active Directory Certificate Services Certificate abuse (the ESC attacks), rogue certificates Security (read), named data: 4886 request received, 4887 issued, 4888 denied, 4890 certificate manager settings changed, 4896 database rows deleted, 4898 template loaded, 4899 template updated, 4900 template security updated. Needs "Audit Certification Services" (success and failure), then certutil -setreg CA\AuditFilter 127 and a restart of certsvc. 4898 to 4900 also need certutil -setreg policy\EditFlags +EDITF_AUDITCERTTEMPLATELOAD (source: a PKI consultant, not Microsoft). Partly: 4898 and 4899 (template loaded, template updated) are dropped by the parser; the rest arrive after the settings log.channel is Security; log.eventCode is one of 4886, 4887, 4888, 4890, 4900 High
Microsoft Exchange Server (on-premises) Admin commands on mail, such as mailbox exports and permission changes Channel MSExchange Management (not read), provider MSExchange CmdletLogs: 1 command succeeded, 6 command failed, 8 unhandled exception; unnamed data. The administrator audit log goes to a hidden mailbox, not to the event log. Application (read): ASP.NET 4.0.30319.0 1309 errors on web mail and admin pages. No: needs agent channel MSExchange Management added, event 1 taken off the parser's drop list, and unnamed data kept (4(c)(7)) After the changes: log.providerName is MSExchange CmdletLogs; log.eventCode is one of 1, 6 Medium
Windows DNS Server Zone and record changes; DNS tampering Channel Microsoft-Windows-DNSServer/Audit (not read; on by default), provider Microsoft-Windows-DNSServer, named data (zone, name, type, record data, and the client address for dynamic updates): 513 zone deleted, 514 zone updated, 515 and 516 record created and deleted, 519 and 520 record created and deleted by dynamic update, 521 record scavenged, 541 server setting changed, 577 to 582 policies. DNS queries are in the Analytical log, which EvtSubscribe cannot read at all. No: needs agent channel Microsoft-Windows-DNSServer/Audit added (then complete, because the data is named) After the change: log.providerName is Microsoft-Windows-DNSServer; log.eventCode is one of 513, 515, 516, 541 Medium
Windows DHCP Server Scope changes, filtered clients, failover problems Channels Microsoft-Windows-Dhcp-Server/Operational (70 to 74 scope changes, 106 and 107 reservations), Microsoft-Windows-Dhcp-Server/FilterNotifications (20096, 20097, 20100 client denied by a filter) and DhcpAdminEvents (1045, 1046, 1051 server not authorized, 1063 scope full, 20252 to 20255 failover), none read; provider Microsoft-Windows-DHCP-Server. Operational and filter events use named data (MACAddress, HostName). Lease history (which device had which address) is only in text files, %windir%\System32\Dhcp\DhcpSrvLog-<Day>.log. No: needs the three channels added; lease history stays out of reach After the change: log.providerName is Microsoft-Windows-DHCP-Server Medium
NTLM authentication auditing (domain controllers) Finds old NTLM use and the source of password spraying Channel Microsoft-Windows-NTLM/Operational (read), provider Microsoft-Windows-Security-Netlogon, event 8004 (a domain controller checked NTLM credentials) with named data UserName, DomainName, WorkstationName (the parser renames it to origin.host) and SChannelName. Needs the Group Policy "Network security: Restrict NTLM: Audit NTLM authentication in this domain" set to "Enable all" on the domain controllers. Yes, after a setting (Group Policy) log.providerName is Microsoft-Windows-Security-Netlogon; log.eventCode is one of 8004 Medium
App Control for Business (WDAC) Blocked or audited drivers and programs Channel Microsoft-Windows-CodeIntegrity/Operational (read), provider Microsoft-Windows-CodeIntegrity: 3076 audit-mode block, 3077 enforced block, 3089 signature details, 3033 and 3034 signing failures. Named data ("File Name", "Process Name", "PolicyName"). 3089 joins its block event through log.activityId (the agent keeps the correlation ID). Yes, after a setting (an App Control policy) log.providerName is Microsoft-Windows-CodeIntegrity; log.eventCode is one of 3076, 3077 Medium
AppLocker Blocked or audited programs and scripts Channels Microsoft-Windows-AppLocker/EXE and DLL, .../MSI and Script, .../Packaged app-Execution, .../Packaged app-Deployment (none read), provider Microsoft-Windows-AppLocker: 8002, 8003, 8004 (EXE and DLL allowed, audit, blocked), 8005 to 8007 (MSI and script), 8020 to 8025 (packaged apps). File path, hash and user are in UserData. Needs a policy and the Application Identity service. No: needs the four AppLocker channels added, and even then only event IDs arrive until the agent reads UserData After the change: log.providerName is Microsoft-Windows-AppLocker; log.eventCode is one of 8003, 8004, 8006, 8007 Medium
Windows LAPS Local admin passwords rotated, or rotation failing Channel Microsoft-Windows-LAPS/Operational (not read), provider Microsoft-Windows-LAPS, named data: 10003 cycle started, 10004 success, 10005 failure, 10018 password stored in Active Directory, 10029 stored in Entra ID, 10020 local account updated, 10031 outside password change blocked. No: needs agent channel Microsoft-Windows-LAPS/Operational added (then complete) After the change: log.providerName is Microsoft-Windows-LAPS; log.eventCode is one of 10005, 10031 Medium
OpenSSH Server for Windows SSH logins to Windows servers Channel OpenSSH/Operational (not read), provider OpenSSH. It logs there by default (default SyslogFacility AUTH). Every line is event 4 with named data process and payload, for example Accepted password for <user> from <ip> port <n> ssh2. No: needs agent channel OpenSSH/Operational added (then complete, because the data is named) After the change: log.providerName is OpenSSH; text Failed password Medium
Hyper-V Virtual machines created, deleted, started, stopped Channels Microsoft-Windows-Hyper-V-VMMS-Admin and Microsoft-Windows-Hyper-V-Worker-Admin (not read): 13002 created, 13003 deleted, 18303 exported, 18500 started, 18502 turned off, 18504 and 18508 shut down, 18512 and 18514 reset. The virtual machine name is in UserData. No: needs both channels added, and even then the virtual machine name is lost until the agent reads UserData After the change: log.providerName is one of Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker Medium
Microsoft Entra Connect Sync Password hash sync and directory sync health Application (read), providers Directory Synchronization and ADSync: 611 password hash sync failed for a domain, 652 and 655 sync errors, 654 heartbeat every 30 minutes (a gap means sync stopped), 656 password change request, 657 password change result. Data shape not confirmed. Partly (not confirmed): the event IDs arrive; details only if the data is named, which was not confirmed log.providerName is one of Directory Synchronization, ADSync; log.eventCode is one of 611, 652, 655 Medium
Active Directory Federation Services (AD FS) Federated sign-ins, password spraying, extranet lockout Security (read), provider AD FS Auditing: 1200 token issued, 1201 token failure, 1202 credentials validated, 1203 credential validation error, 411 token validation failed (bad password or lockout), 412 authenticated, 516 extranet lockout; unnamed data. The AD FS/Admin channel (not read; 342, 364) uses UserData. Needs the "Generate security audits" right for the service account, auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable, and Success and Failure audits ticked in AD FS Management. Partly: after the settings the Security events arrive with the event ID only (unnamed data); user and client address are lost log.providerName is AD FS Auditing; log.eventCode is one of 411, 516, 1203 Medium
ConnectWise ScreenConnect Remote support sessions, often abused by attackers Application log (read), provider ScreenConnect (older versions ScreenConnect Client (<id>)): 100 session connected, 101 disconnected, 201 file transfer or command run, 30 session ended. The details are one unnamed data value. Partly: event IDs only (unnamed data); older clients log with event ID 0, which the parser drops log.providerName contains ScreenConnect; log.eventCode is one of 100, 101, 201 Medium
Windows Event Forwarding collector Brings channels the agent does not read, from many servers, through one agent The agent reads ForwardedEvents. A subscription on a collector host that runs the agent pulls the chosen channels from the servers (section 4(b)). Forwarded events keep the source computer name. Yes, after a setting (a forwarding subscription) dataSource is <collector host>; log.computer is <source server> Medium
Print servers Who printed what Channel Microsoft-Windows-PrintService/Operational (read; the agent turns it on): 307 document printed, 316 driver added or updated. Details are in UserData. Partly: event IDs only (UserData) log.providerName is Microsoft-Windows-PrintService; log.eventCode is one of 307, 316 Low
Other antivirus products (Trellix or McAfee, Sophos Endpoint, Symantec Endpoint Protection) Detections on hosts without an EDR integration Trellix or McAfee (providers Trellix Endpoint Security, McAfee Endpoint Security, event 3) and Sophos (Sophos Anti-Virus 32 and 42) write to Application (read). Symantec writes to its own channel Symantec Endpoint Protection Client (not read; 51 security risk found). All use unnamed data. Partly: Trellix, McAfee and Sophos arrive with the event ID only; Symantec needs its channel added log.channel is Application; log.providerName is one of Trellix Endpoint Security, McAfee Endpoint Security, Sophos Anti-Virus Low

Left out on purpose, to keep the table at 25 rows: BitLocker (channel Microsoft-Windows-BitLocker/BitLocker Management, not read; provider Microsoft-Windows-BitLocker-API; 768 encryption started, 775 and 776 key protector added and removed, 845 recovery key backed up to Entra ID; named data according to the manifest), Splashtop (its own channel, named data; see 4(b)), Citrix Virtual Apps and Desktops agent (Citrix Desktop Service 1027 and 1049 in Application, unnamed data), and TeamViewer and AnyDesk (text files only, no event log).

SQL Server in detail (one of the product owner's two headline examples)

  • What lands in the Application log. Provider MSSQLSERVER for the default instance, MSSQL$<instance> for a named instance (for example MSSQL$SQLEXPRESS); SQL Server Agent writes as SQLSERVERAGENT or SQLAgent$<instance>. Microsoft marks these as written to the event log: logins 18452 (untrusted domain), 18453, 18454, 18455 (succeeded), 18456 (failed), 18470 (account disabled), 18486 (locked out), 18487 and 18488 (password expired, must change); backups 18264 and 18265 (trace flag 3226 hides the success entries); start and stop 17162, 17126, 17147, 17148; connection and system errors 17806, 17836, 17053; disk and log errors 823, 824, 825, 9002. 15457 (configuration option changed) also appears in real Application logs.
  • Login auditing. SQL Server Management Studio > Server Properties > Security > Login auditing: None, Failed logins only, Successful logins only, or Both failed and successful logins. A change needs a service restart. The default is reported as "Failed logins only" (a Microsoft protocols-team blog; the CIS benchmark, registry value AuditLevel = 2), but a 2011 Microsoft blog says None, so the guide should tell customers to check it. "Failed logins only" is enough for brute-force detection; "Both" adds a success event for every connection, which is noisy on busy servers.
  • SQL Server Audit into the Application log. CREATE SERVER AUDIT utm_audit TO APPLICATION_LOG; then ALTER SERVER AUDIT utm_audit WITH (STATE = ON); plus a server audit specification with the action groups wanted (for example FAILED_LOGIN_GROUP), also switched on. Each record is event 33205. TO SECURITY_LOG writes 33205 to Security with source MSSQLSERVER$AUDIT instead, and needs auditpol /set /subcategory:"application generated" /success:enable /failure:enable, the "Generate security audits" right for the service account, and a restart.
  • Drop list. None of these IDs is dropped by the Windows parser.
  • The limit that matters. No SQL Server event has named data. 18456 carries three unnamed values (user, reason, client address); 33205 carries the whole audit record as one unnamed value. The v12 agent drops unnamed data, so a guide can promise only "failed login on server X at time T", not who or from where. Keeping unnamed data (section 4(c)(7)) fixes this for every SQL Server event. 18456 is stored at level 0 with the "Audit Failure" keyword, not as an error, so a guide must not filter on the level.

IIS in detail (the product owner's second headline example)

  • Arrives today, no change needed: the service and worker events. Microsoft-Windows-WAS in System (5002, 5009, 5010, 5011, 5013, 5021, 5186) and Microsoft-Windows-IIS-W3SVC-WP in Application (2268, 2269, 2276, 2280) use named data (AppPoolID, ProcessID, ExitCode, SiteName, ModuleDll). ASP.NET 1309 and 1310 arrive with the event ID only (unnamed data). Two WAS events are lost: 5057 and 5059 ("application pool has been disabled", Microsoft Learn "Event ID 5059 — IIS Application Pool Availability") are on the parser's drop list, which was written for the Security events with the same numbers.
  • Does not arrive: request logs. By default IIS writes them only to W3C text files, and the v12 agent does not read files. IIS 8.5 and later can also send each request as event 6200 to the channel Microsoft-IIS-Logging/Logs (provider Microsoft-Windows-IIS-Logging), with named fields such as date, time, c-ip, cs-username, s-sitename, cs-method, cs-uri-stem, cs-uri-query, sc-status, time-taken and csUser-Agent. Customer settings: in IIS Manager > (server or site) > Logging, keep Format W3C and set Log Event Destination to "ETW event only" or "Both log file and ETW event"; then turn the channel on with wevtutil sl "Microsoft-IIS-Logging/Logs" /e:true (the Windows manifest declares it enabled="false").
  • Exact channel name. Microsoft-IIS-Logging/Logs. The form Microsoft-Windows-IIS-Logging/Logs is only display text; a monitoring tool that subscribed with that name got "not found" (EvlWatcher issue 122), and working Winlogbeat configurations use Microsoft-IIS-Logging/Logs. The channel is of type Admin, so EvtSubscribe can read it. Microsoft's IIS page itself names only the provider, so check with wevtutil el | findstr /i iis on a test server before shipping.
  • The agent change. Adding "Microsoft-IIS-Logging/Logs" to the channels slice in agent/collector/platform/windows_amd64.go brings the request logs in, complete, because the fields are named (6200 is not on the drop list). Agents on servers without IIS would log a subscription error for the missing channel and skip it, as they already do for Sysmon. Two cautions: the field names contain hyphens (log.data.c-ip), which may need a rename step for easy filtering, and a busy site produces one event per request (a Winlogbeat user reported losing most of about 5,000 events per minute), so this needs a volume test.
  • Configuration changes go to Microsoft-IIS-Configuration/Operational (off by default; wevtutil sl Microsoft-IIS-Configuration/Operational /e:true), event 29 with named ConfigPath, OldValue and NewValue. The user who made the change is only in the event's security identifier, which the agent does keep as log.userId (a SID, not a name). Hand edits of the configuration file are not audited.
Sources checked for this list (24 Sep 2026)

Sources for 3b (checked 2026-09-24). "EvtxECmd maps" means github.com/EricZimmerman/evtx/tree/master/evtx/Maps, whose files carry real sample event XML; that is where the data shapes (named, unnamed, UserData) come from.

  • Microsoft Defender: learn.microsoft.com/en-us/defender-endpoint/troubleshoot-microsoft-defender-antivirus; .../attack-surface-reduction-windows-events; EvtxECmd maps 1006, 1008, 1116, 1117, 5001, 5007.
  • Sysmon: learn.microsoft.com/en-us/sysinternals/downloads/sysmon; learn.microsoft.com/en-us/windows/security/operating-system-security/sysmon/how-to-enable-sysmon.
  • Remote Desktop and Remote Desktop Gateway: EvtxECmd maps for LocalSessionManager 21 to 25, 39, 40, RemoteConnectionManager 1149, RdpCoreTS 131 and 140, Gateway 200 to 312; learn.microsoft.com auditing pages for events 4778 and 4779.
  • File servers: learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-10/security/threat-protection/auditing/audit-file-system, .../audit-file-share, .../audit-detailed-file-share.
  • App Control and AppLocker: learn.microsoft.com/en-us/windows/security/application-security/application-control/app-control-for-business/operations/event-id-explanations; .../applocker/using-event-viewer-with-applocker; EvtxECmd AppLocker maps.
  • OpenSSH for Windows: github.com/PowerShell/openssh-portable/blob/latestw_all/contrib/win32/openssh/Openssh-events.man; learn.microsoft.com/en-us/windows-server/administration/openssh/openssh-server-configuration.
  • Hyper-V, print, ScreenConnect, BitLocker, antivirus products: EvtxECmd maps for each; learn.microsoft.com/en-us/troubleshoot/windows-client/windows-security/bitlocker-issues-troubleshooting.
  • NTLM: research.splunk.com/sources/fd08cb77-c26e-464c-a43e-2867e232127e/ (NTLM Operational 8004, sample XML with named data).
  • Windows Event Forwarding: learn.microsoft.com/en-us/windows/security/operating-system-security/device-management/use-windows-event-forwarding-to-assist-in-intrusion-detection.
  • SQL Server: learn.microsoft.com/en-us/sql/relational-databases/errors-events/database-engine-events-and-errors-18000-to-18999, ...-16000-to-17999, ...-0-to-999, ...-9000-to-9999; learn.microsoft.com/en-us/ssms/server-properties/security-page; learn.microsoft.com/en-us/sql/t-sql/statements/create-server-audit-transact-sql; learn.microsoft.com/en-us/sql/relational-databases/security/auditing/write-sql-server-audit-events-to-the-security-log; github.com/DigitalRuby/IPBan test data (real 18456 and 18454 XML); EvtxECmd maps 18453, 18456, 15457, 33205.
  • IIS: learn.microsoft.com/en-us/iis/get-started/whats-new-in-iis-85/logging-to-etw-in-iis-85; learn.microsoft.com/en-us/iis/configuration/system.applicationhost/sites/sitedefaults/logfile/; learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc735276(v=ws.10) (WAS 5059); Microsoft TechNet Austria archive "IIS und Web Teil 2" (Event Viewer path); github.com/RDWEB logging - Event Log Microsoft-Windows-IIS-Logging/Logs was not found devnulli/EvlWatcher#122; discuss.elastic.co thread 227513 (Winlogbeat on Microsoft-IIS-Logging/Logs); github.com/new feature: JSON output schema microsoft/windows-container-tools#103 (6200 fields); learn.microsoft.com/en-us/archive/blogs/webtopics/iis-7-5-how-to-enable-iis-configuration-auditing.
  • Active Directory, AD CS, NPS: learn.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/advanced-audit-policy-configuration; learn.microsoft.com/en-us/troubleshoot/windows-server/active-directory/enable-ldap-signing-in-windows-server; learn.microsoft.com/en-us/defender-for-identity/deploy/configure-windows-event-collection; learn.microsoft.com auditing pages "Audit Certification Services" and "Audit Network Policy Server".
  • AD FS: learn.microsoft.com/en-us/windows-server/identity/ad-fs/troubleshooting/ad-fs-tshoot-logging; learn.microsoft.com/en-us/security/operations/incident-response-playbook-password-spray.
  • DNS and DHCP: learn.microsoft.com/en-us/windows-server/networking/dns/dns-logging-and-diagnostics; learn.microsoft.com/en-us/windows/win32/api/winevt/nf-winevt-evtsubscribe; learn.microsoft.com/en-us/windows-server/networking/technologies/dhcp/dhcp-server-events.
  • Exchange: learn.microsoft.com/en-us/exchange/policy-and-compliance/admin-audit-logging/admin-audit-logging; docs.logrhythm.com "MS Windows Event Logging - MSExchange Management".
  • Entra Connect and LAPS: learn.microsoft.com/en-us/entra/identity/hybrid/connect/tshoot-connect-password-hash-synchronization; learn.microsoft.com/en-us/windows-server/identity/laps/laps-management-event-log.

Done per technology

  • A guide-only entry with a real display name, a one-line description (all seven languages) and an icon.
  • A guide built from the shared template, with the vendor steps from the table, the exact setting, and how to check the logs arrived.
  • A "View logs" link that opens the Log Explorer with the filter from the table.
  • Checked once with the real product, or with a realistic sample sent the same way, and the logs show up under that filter.
  • Where the table says "Partly" or "No", the guide says plainly what the customer does not get yet.

Research notes this list relies on

0.4 Windows field names (data type wineventlog)

The agent (agent/collector/platform/windows_amd64.go, convertEventToJSON) sends JSON keys provider_name, eventCode, channel, computer, level, recordId, data, and so on. The pipeline's json step strips underscores from top-level keys (explained in the comment block of definitions/filters/linux/linux.yaml: go-sdk SanitizeField keeps only letters, digits and dots), so provider_name arrives as log.providername, which windows-events.yaml renames. Final names to use in Log Explorer:

What Field
Provider (event source) log.providerName
Channel log.channel
Event ID log.eventCode (cast to integer)
Computer named inside the event log.computer
Host running the agent dataSource
Level (numeric) log.severityLabel
Named event data log.data.<Name>, some promoted to log.eventData<Name>, origin.ip, origin.host, target.user, target.domain

log.eventId does not exist in practice: the filter renames log.id, but the agent never sends id. Use log.eventCode.

Three agent and parser limits that decide whether a Windows guide is honest:

  1. The agent keeps only named event data (<Data Name="X">). It drops unnamed <Data> values, ignores <UserData> blocks and does not send the rendered message text (EvtRender with the XML flag, no EvtFormatMessage). Many application events therefore arrive with only provider, event ID, level, channel and computer (details per technology in table 3b).
  2. windows-events.yaml drops every event whose event ID is in one list, whatever the provider or channel. The list includes 0, 1, 43, 44, 1040, 1042, 1105, 1500, 1501, 7040, 8191, 10000, 10010, 16384, 16394 and many Security IDs (for example 4798 is kept but 5145, 6274 and 6275 are dropped). Event ID 1 kills Sysmon process creation, and event ID 0 kills any application that logs with ID 0.
  3. Only the fixed channel list in windows_amd64.go (about lines 343-368) is read. Anything else needs code, or the Windows Event Forwarding workaround described in section 4(b).

4(b) Windows channels popular applications need but the agent does not read

Adding a channel is one line in the channels slice of agent/collector/platform/windows_amd64.go. It is safe on machines without the product: a missing channel is logged and skipped (the code already relies on this for Sysmon). A channel that ships turned off must also be turned on at the source; the agent already does that for two channels (disabledByDefaultChannels in agent/dependency/auditpolicy_windows.go, which runs wevtutil sl <channel> /e:true), and the IIS channels could join that list. The first group below is complete once the channel is added; the second group also needs the agent to keep unnamed data or UserData (4(c)(7)).

Channel (exact name) Table 3b row Turned on by default? Data shape Adding the channel is enough?
Microsoft-IIS-Logging/Logs IIS request logs (event 6200) No (enabled="false" in the manifest); IIS "Log Event Destination" must also include ETW Named Yes
Microsoft-Windows-DNSServer/Audit Windows DNS Server Yes Named Yes
OpenSSH/Operational OpenSSH Server for Windows Yes Named (process, payload) Yes
Microsoft-Windows-LAPS/Operational Windows LAPS Not confirmed Named Yes
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational Remote Desktop (131 connection accepted with ClientIP; 140 failed logon with IPString) Not confirmed Named Yes
Microsoft-Windows-Dhcp-Server/Operational, Microsoft-Windows-Dhcp-Server/FilterNotifications, DhcpAdminEvents Windows DHCP Server Not confirmed (NXLog says each must be turned on) Named for Operational and FilterNotifications; DhcpAdminEvents not confirmed Yes for the first two
Microsoft-IIS-Configuration/Operational IIS configuration changes (event 29) No Named Yes
Microsoft-Windows-SMBServer/Audit Windows file access auditing (3000: a client used SMB1) The events need Set-SmbServerConfiguration -AuditSmb1Access $true Named (ClientName) Yes
Microsoft-Windows-BitLocker/BitLocker Management (not a row) BitLocker: 768, 775, 776, 845, 846 Yes (Microsoft lists it as a default log) Named according to the manifest Yes (no raw sample seen)
Splashtop-Splashtop Streamer-Remote Session/Operational (not a row) Splashtop remote sessions: 1000, 1001, 1100, 1101 Created by the product Named Yes
Directory Service Active Directory (LDAP signing 2887 and 2889, expensive searches 1644) The channel yes; 2889 needs the diagnostics value 16 LDAP Interface Events = 2, and 1644 needs 15 Field Engineering = 5 2889 unnamed; 2887 and 1644 not confirmed No: 2889 also needs unnamed data kept
Microsoft-Windows-TerminalServices-Gateway/Operational Remote Desktop Gateway Not confirmed UserData No
Microsoft-Windows-AppLocker/EXE and DLL, Microsoft-Windows-AppLocker/MSI and Script, Microsoft-Windows-AppLocker/Packaged app-Execution, Microsoft-Windows-AppLocker/Packaged app-Deployment AppLocker Log when a policy exists UserData No
Microsoft-Windows-Hyper-V-VMMS-Admin, Microsoft-Windows-Hyper-V-Worker-Admin Hyper-V Yes, with the role UserData No
Microsoft-Windows-SMBServer/Security Windows file access auditing (551: SMB session setup failed) Not confirmed UserData No
MSExchange Management Microsoft Exchange Server Not confirmed Unnamed No: also event 1 off the drop list
AD FS/Admin AD FS (342, 364) Yes UserData No
Veeam Backup Veeam (syslog in 3a is the better route) Yes, with the product Unnamed No
Symantec Endpoint Protection Client Other antivirus products Yes, with the product Unnamed No

Not possible with a channel at all: the DNS Server query log is an analytic channel (Microsoft-Windows-DNSServer/Analytical), and EvtSubscribe refuses analytic channels; it needs an Event Tracing for Windows session, which is new agent code. DHCP lease history is only in text files.

Workaround with no code: Windows Event Forwarding. The agent already reads ForwardedEvents. A customer can create a Windows Event Forwarding subscription that pulls a missing channel from its servers into ForwardedEvents on one collector host that runs the UTMStack agent. Facts a guide must state (Microsoft, "Use Windows Event Forwarding to help with intrusion detection", learn.microsoft.com):

  • Forwarding reads any operational or administrative channel, but it cannot enable a disabled channel, change channel permissions or change audit policy. Each channel must be enabled on the source servers first (for example wevtutil sl "Microsoft-IIS-Logging/Logs" /e:true), and the Network Service account needs to be in the Event Log Readers group to forward Security.
  • The default content format is "Rendered Text", which roughly doubles the size by adding the message text. The agent ignores that text, so wecutil ss <subscription> /cf:Events is the better setting.
  • Forwarded events keep the source computer name, so log.computer is the original server and dataSource is the collector host. Whether log.channel keeps the original channel name was not confirmed; guides should filter on log.providerName and log.computer.
  • The agent's limits still apply: UserData and unnamed event data are dropped (so Remote Desktop Gateway, AppLocker and Hyper-V events arrive without details), and the Windows parser's drop list applies to forwarded events too.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions