| Active Directory (domain controllers) |
Account takeover, privilege changes, Kerberos and NTLM attacks |
Security (read), provider Microsoft-Windows-Security-Auditing, named data: 4624 and 4625 logons, 4740 and 4767 lockout and unlock, 4720, 4722, 4725, 4726 and 4738 account changes, 4728, 4732 and 4756 group additions, 4768, 4769 and 4771 Kerberos, 4776 NTLM credential check, 5136 directory object modified, 4662 operation on an object (DCSync detection). The agent turns on logon, lockout, user and group management. Kerberos, credential validation and directory subcategories must be set on the domain controllers: "Audit Directory Service Changes" is off by default and also needs audit entries on the objects; "Audit Directory Service Access" logs successes by default. The Directory Service channel (not read) holds LDAP signing events 2887 and 2889 (2889 uses unnamed data). The v12 ad-audit plugin already uses 4720, 4726 and 4624 for its user list. |
Partly: 5137, 5138, 5139 and 5141 (directory object created, undeleted, moved, deleted) are dropped by the parser; LDAP signing events need channel Directory Service |
log.channel is Security; log.eventCode is one of 4625, 4740, 4720, 4726, 4728, 4732, 4756, 4768, 4769, 4771, 4776, 5136 |
High |
| Microsoft Defender Antivirus |
Malware found; protection turned off or changed |
Channel Microsoft-Windows-Windows Defender/Operational (read), provider Microsoft-Windows-Windows Defender. 1116 malware detected, 1117 action taken, 1118 and 1119 action failed, 1006 to 1008 (older detection events), 1015 suspicious behavior, 1121 and 1122 attack surface reduction block and audit, 1123 and 1124 controlled folder access, 1125 and 1126 network protection, 5001 real-time protection off, 5004 and 5007 settings changed, 5010 and 5012 scanning off, 5013 Tamper Protection blocked a change. Named data (names contain spaces, for example "Threat Name"). None is dropped. |
Yes (1121 to 1126 only when those features are in audit or block mode) |
log.providerName is Microsoft-Windows-Windows Defender; log.eventCode is one of 1116, 1117, 1118, 1119, 5001, 5007, 5013 |
High |
| Microsoft SQL Server |
Database logins, brute force, configuration changes, disk errors |
Application log (read), provider MSSQLSERVER (default instance) or MSSQL$<instance> (named instance); SQL Server Agent as SQLSERVERAGENT or SQLAgent$<instance>. 18456 login failed, 18453, 18454 and 18455 login succeeded, 18470 account disabled, 18486 locked out, 18487 and 18488 password expired or must change, 17162 and 17126 starting and ready, 17147 and 17148 stopping, 15457 configuration option changed, 33205 SQL Server Audit record, 18264 and 18265 backups, 823 to 825 disk read errors, 9002 log full. None is dropped. All use unnamed data. Settings in the detail below the table. |
Partly: every event arrives with provider and event ID only; user, reason and client address are lost (unnamed data) |
log.providerName is one of MSSQLSERVER, MSSQL$<instance>; log.eventCode is one of 18456, 18470, 18486 |
High |
| Internet Information Services (IIS) |
Web server crashes and errors; request logs for web attacks |
Arrives today: System (read), provider Microsoft-Windows-WAS: 5002 application pool disabled after repeated failures, 5009 worker process ended unexpectedly, 5010 no ping reply, 5011 fatal communication error, 5013 shutdown time exceeded, 5021 pool identity invalid, 5186 idle shutdown. Application (read), provider Microsoft-Windows-IIS-W3SVC-WP: 2268, 2269, 2276, 2280 (filter, worker and module failures). Both use named data. ASP.NET (ASP.NET 4.0.30319.0, 1309 unhandled exception, 1310 configuration error) uses unnamed data. Does not arrive: request logs (W3C text files by default) and configuration changes; detail below the table. |
Partly: service and worker events arrive, but 5057 and 5059 (application pool disabled) are dropped by the parser; request logs need channel Microsoft-IIS-Logging/Logs added |
log.providerName is one of Microsoft-Windows-WAS, Microsoft-Windows-IIS-W3SVC-WP; log.eventCode is one of 5002, 5009, 5010, 5011, 2276, 2280 |
High |
| Remote Desktop (servers and workstations) |
Remote logins, lateral movement |
Security (read): 4624 with logon type 10 and 4625 carry the user (target.user) and source address (origin.ip). Session channels (read): Microsoft-Windows-TerminalServices-LocalSessionManager/Operational 21 logon, 23 logoff, 24 disconnect, 25 reconnect, and Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational 1149 keep user and address in UserData. Security 4778 and 4779 (reconnect, disconnect; generated because the agent turns on Other Logon/Logoff Events) are on the drop list. Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational 131 (connection accepted, named ClientIP) and 140 (bad user name or password from an address, named IPString) are not read. |
Partly: the session events arrive with the event ID only, and 4778 and 4779 are dropped by the parser |
log.eventCode is one of 4624, 4625; log.eventDataLogonType is one of 10 (with Network Level Authentication, failed logons show as type 3) |
High |
| Remote Desktop Gateway |
Remote access from the internet |
Channel Microsoft-Windows-TerminalServices-Gateway/Operational (not read), provider Microsoft-Windows-TerminalServices-Gateway: 200 connection policy met, 201 denied, 300 and 301 resource policy, 302 connected, 303 disconnected (bytes, duration). User and client address are in UserData. |
No: needs agent channel Microsoft-Windows-TerminalServices-Gateway/Operational added, and even then only event IDs arrive until the agent reads UserData |
After the change: log.providerName is Microsoft-Windows-TerminalServices-Gateway; log.eventCode is one of 201, 302, 303 |
High |
| Network Policy Server (RADIUS for VPN and Wi-Fi) |
VPN and Wi-Fi logins granted and denied |
Security (read), provider Microsoft-Windows-Security-Auditing, named data (SubjectUserName, CallingStationID, NASIPv4Address): 6272 granted, 6273 denied, 6274 request discarded, 6275 accounting request discarded, 6276 quarantined, 6278 full access, 6279 account locked, 6280 unlocked. "Audit Network Policy Server" logs success and failure by default (check that a Group Policy does not override it). |
Partly: 6274 and 6275 (discarded requests) are dropped by the parser; 6272 and 6273 arrive complete |
log.channel is Security; log.eventCode is one of 6272, 6273, 6279 |
High |
| Windows file access auditing |
Who read, changed or deleted sensitive files; ransomware |
Security (read): 4656, 4660 (deleted), 4663 (accessed) and 4670 (permissions changed) need "Audit File System" plus audit entries (SACLs) on the folders; 5140 (share accessed) and 5142 to 5144 (share added, changed, deleted) need "Audit File Share"; 5145 needs "Audit Detailed File Share". The agent turns none of these on (it skips Object Access on purpose). Named data (log.eventDataObjectName, log.eventDataAccessMask). |
Yes, after a setting (audit policy and folder SACLs); 5145 is dropped by the parser |
log.channel is Security; log.eventCode is one of 4660, 4663, 4670, 5140, 5142, 5144 |
High |
| Sysmon |
Process, network, registry and DNS detail for detection |
Channel Microsoft-Windows-Sysmon/Operational (read), provider Microsoft-Windows-Sysmon: 1 process created, 3 network connection, 7 image loaded, 8 remote thread, 10 process access, 11 file created, 12 to 14 registry, 22 DNS query, 23 and 26 file delete, 25 process tampering, 29 executable file detected. Named data. Not installed by default (sysmon -accepteula -i <config>, or the built-in Windows 11 feature). Events 3 and 7 are off unless the config turns them on. |
Partly: event 1 (process creation) is dropped by the parser |
log.providerName is Microsoft-Windows-Sysmon; log.eventCode is one of 3, 11, 22 |
High |
| Active Directory Certificate Services |
Certificate abuse (the ESC attacks), rogue certificates |
Security (read), named data: 4886 request received, 4887 issued, 4888 denied, 4890 certificate manager settings changed, 4896 database rows deleted, 4898 template loaded, 4899 template updated, 4900 template security updated. Needs "Audit Certification Services" (success and failure), then certutil -setreg CA\AuditFilter 127 and a restart of certsvc. 4898 to 4900 also need certutil -setreg policy\EditFlags +EDITF_AUDITCERTTEMPLATELOAD (source: a PKI consultant, not Microsoft). |
Partly: 4898 and 4899 (template loaded, template updated) are dropped by the parser; the rest arrive after the settings |
log.channel is Security; log.eventCode is one of 4886, 4887, 4888, 4890, 4900 |
High |
| Microsoft Exchange Server (on-premises) |
Admin commands on mail, such as mailbox exports and permission changes |
Channel MSExchange Management (not read), provider MSExchange CmdletLogs: 1 command succeeded, 6 command failed, 8 unhandled exception; unnamed data. The administrator audit log goes to a hidden mailbox, not to the event log. Application (read): ASP.NET 4.0.30319.0 1309 errors on web mail and admin pages. |
No: needs agent channel MSExchange Management added, event 1 taken off the parser's drop list, and unnamed data kept (4(c)(7)) |
After the changes: log.providerName is MSExchange CmdletLogs; log.eventCode is one of 1, 6 |
Medium |
| Windows DNS Server |
Zone and record changes; DNS tampering |
Channel Microsoft-Windows-DNSServer/Audit (not read; on by default), provider Microsoft-Windows-DNSServer, named data (zone, name, type, record data, and the client address for dynamic updates): 513 zone deleted, 514 zone updated, 515 and 516 record created and deleted, 519 and 520 record created and deleted by dynamic update, 521 record scavenged, 541 server setting changed, 577 to 582 policies. DNS queries are in the Analytical log, which EvtSubscribe cannot read at all. |
No: needs agent channel Microsoft-Windows-DNSServer/Audit added (then complete, because the data is named) |
After the change: log.providerName is Microsoft-Windows-DNSServer; log.eventCode is one of 513, 515, 516, 541 |
Medium |
| Windows DHCP Server |
Scope changes, filtered clients, failover problems |
Channels Microsoft-Windows-Dhcp-Server/Operational (70 to 74 scope changes, 106 and 107 reservations), Microsoft-Windows-Dhcp-Server/FilterNotifications (20096, 20097, 20100 client denied by a filter) and DhcpAdminEvents (1045, 1046, 1051 server not authorized, 1063 scope full, 20252 to 20255 failover), none read; provider Microsoft-Windows-DHCP-Server. Operational and filter events use named data (MACAddress, HostName). Lease history (which device had which address) is only in text files, %windir%\System32\Dhcp\DhcpSrvLog-<Day>.log. |
No: needs the three channels added; lease history stays out of reach |
After the change: log.providerName is Microsoft-Windows-DHCP-Server |
Medium |
| NTLM authentication auditing (domain controllers) |
Finds old NTLM use and the source of password spraying |
Channel Microsoft-Windows-NTLM/Operational (read), provider Microsoft-Windows-Security-Netlogon, event 8004 (a domain controller checked NTLM credentials) with named data UserName, DomainName, WorkstationName (the parser renames it to origin.host) and SChannelName. Needs the Group Policy "Network security: Restrict NTLM: Audit NTLM authentication in this domain" set to "Enable all" on the domain controllers. |
Yes, after a setting (Group Policy) |
log.providerName is Microsoft-Windows-Security-Netlogon; log.eventCode is one of 8004 |
Medium |
| App Control for Business (WDAC) |
Blocked or audited drivers and programs |
Channel Microsoft-Windows-CodeIntegrity/Operational (read), provider Microsoft-Windows-CodeIntegrity: 3076 audit-mode block, 3077 enforced block, 3089 signature details, 3033 and 3034 signing failures. Named data ("File Name", "Process Name", "PolicyName"). 3089 joins its block event through log.activityId (the agent keeps the correlation ID). |
Yes, after a setting (an App Control policy) |
log.providerName is Microsoft-Windows-CodeIntegrity; log.eventCode is one of 3076, 3077 |
Medium |
| AppLocker |
Blocked or audited programs and scripts |
Channels Microsoft-Windows-AppLocker/EXE and DLL, .../MSI and Script, .../Packaged app-Execution, .../Packaged app-Deployment (none read), provider Microsoft-Windows-AppLocker: 8002, 8003, 8004 (EXE and DLL allowed, audit, blocked), 8005 to 8007 (MSI and script), 8020 to 8025 (packaged apps). File path, hash and user are in UserData. Needs a policy and the Application Identity service. |
No: needs the four AppLocker channels added, and even then only event IDs arrive until the agent reads UserData |
After the change: log.providerName is Microsoft-Windows-AppLocker; log.eventCode is one of 8003, 8004, 8006, 8007 |
Medium |
| Windows LAPS |
Local admin passwords rotated, or rotation failing |
Channel Microsoft-Windows-LAPS/Operational (not read), provider Microsoft-Windows-LAPS, named data: 10003 cycle started, 10004 success, 10005 failure, 10018 password stored in Active Directory, 10029 stored in Entra ID, 10020 local account updated, 10031 outside password change blocked. |
No: needs agent channel Microsoft-Windows-LAPS/Operational added (then complete) |
After the change: log.providerName is Microsoft-Windows-LAPS; log.eventCode is one of 10005, 10031 |
Medium |
| OpenSSH Server for Windows |
SSH logins to Windows servers |
Channel OpenSSH/Operational (not read), provider OpenSSH. It logs there by default (default SyslogFacility AUTH). Every line is event 4 with named data process and payload, for example Accepted password for <user> from <ip> port <n> ssh2. |
No: needs agent channel OpenSSH/Operational added (then complete, because the data is named) |
After the change: log.providerName is OpenSSH; text Failed password |
Medium |
| Hyper-V |
Virtual machines created, deleted, started, stopped |
Channels Microsoft-Windows-Hyper-V-VMMS-Admin and Microsoft-Windows-Hyper-V-Worker-Admin (not read): 13002 created, 13003 deleted, 18303 exported, 18500 started, 18502 turned off, 18504 and 18508 shut down, 18512 and 18514 reset. The virtual machine name is in UserData. |
No: needs both channels added, and even then the virtual machine name is lost until the agent reads UserData |
After the change: log.providerName is one of Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker |
Medium |
| Microsoft Entra Connect Sync |
Password hash sync and directory sync health |
Application (read), providers Directory Synchronization and ADSync: 611 password hash sync failed for a domain, 652 and 655 sync errors, 654 heartbeat every 30 minutes (a gap means sync stopped), 656 password change request, 657 password change result. Data shape not confirmed. |
Partly (not confirmed): the event IDs arrive; details only if the data is named, which was not confirmed |
log.providerName is one of Directory Synchronization, ADSync; log.eventCode is one of 611, 652, 655 |
Medium |
| Active Directory Federation Services (AD FS) |
Federated sign-ins, password spraying, extranet lockout |
Security (read), provider AD FS Auditing: 1200 token issued, 1201 token failure, 1202 credentials validated, 1203 credential validation error, 411 token validation failed (bad password or lockout), 412 authenticated, 516 extranet lockout; unnamed data. The AD FS/Admin channel (not read; 342, 364) uses UserData. Needs the "Generate security audits" right for the service account, auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable, and Success and Failure audits ticked in AD FS Management. |
Partly: after the settings the Security events arrive with the event ID only (unnamed data); user and client address are lost |
log.providerName is AD FS Auditing; log.eventCode is one of 411, 516, 1203 |
Medium |
| ConnectWise ScreenConnect |
Remote support sessions, often abused by attackers |
Application log (read), provider ScreenConnect (older versions ScreenConnect Client (<id>)): 100 session connected, 101 disconnected, 201 file transfer or command run, 30 session ended. The details are one unnamed data value. |
Partly: event IDs only (unnamed data); older clients log with event ID 0, which the parser drops |
log.providerName contains ScreenConnect; log.eventCode is one of 100, 101, 201 |
Medium |
| Windows Event Forwarding collector |
Brings channels the agent does not read, from many servers, through one agent |
The agent reads ForwardedEvents. A subscription on a collector host that runs the agent pulls the chosen channels from the servers (section 4(b)). Forwarded events keep the source computer name. |
Yes, after a setting (a forwarding subscription) |
dataSource is <collector host>; log.computer is <source server> |
Medium |
| Print servers |
Who printed what |
Channel Microsoft-Windows-PrintService/Operational (read; the agent turns it on): 307 document printed, 316 driver added or updated. Details are in UserData. |
Partly: event IDs only (UserData) |
log.providerName is Microsoft-Windows-PrintService; log.eventCode is one of 307, 316 |
Low |
| Other antivirus products (Trellix or McAfee, Sophos Endpoint, Symantec Endpoint Protection) |
Detections on hosts without an EDR integration |
Trellix or McAfee (providers Trellix Endpoint Security, McAfee Endpoint Security, event 3) and Sophos (Sophos Anti-Virus 32 and 42) write to Application (read). Symantec writes to its own channel Symantec Endpoint Protection Client (not read; 51 security risk found). All use unnamed data. |
Partly: Trellix, McAfee and Sophos arrive with the event ID only; Symantec needs its channel added |
log.channel is Application; log.providerName is one of Trellix Endpoint Security, McAfee Endpoint Security, Sophos Anti-Virus |
Low |
Part of: #2731 · Needs first: #2732 (where the entries live, the shared guide templates and the "View logs" link)
Section numbers in the tables (for example "section 0.4" or "4(c)(7)") point to the research notes. The sections this list relies on are at the bottom of this issue; the others are in #2732.
Why
Many Windows applications and server roles already write to event log channels the UTMStack agent reads. SQL Server and IIS are the two headline examples: without a card, customers assume we don't support them. This list says, for each one, what arrives today, what needs a setting, and what needs an agent change first.
Two agent limits decide how honest each guide can be (details in 0.4 and 4(c)(7) below): the agent keeps only named event data, so SQL Server, AD FS and others arrive with the event ID but without the user or address; and the Windows parser's drop list removes some events these guides need. Both are agent and parser work for their owners, not guide work. Link the issue that fixes them from each affected guide rather than waiting.
Checklist, most valuable first
Microsoft-Windows-TerminalServices-Gateway/Operationaladded …MSExchange Managementadded, event 1 taken off the parser's drop list, and unnamed data kept (4(c)(7))Microsoft-Windows-DNSServer/Auditadded (then complete, because the data is named)UserDataMicrosoft-Windows-LAPS/Operationaladded (then complete)OpenSSH/Operationaladded (then complete, because the data is named)UserDataUserData)The list in detail
Rules for every row (section 0.4):
channelsslice inagent/collector/platform/windows_amd64.go(or the forwarding workaround in 4(b)).UserData" in a row means those details are lost and only provider, event ID, level, channel, computer and time arrive.windows-events.yaml; the row says when one is dropped.agent/dependency/auditpolicy_windows.go): Process Creation, Process Termination, Logon, Logoff, Account Lockout, Special Logon, Other Logon/Logoff Events, Security Group Management, User Account Management, Audit Policy Change and Sensitive Privilege Use. Anything else a row needs is a customer setting.dataTypeiswineventlog. The column shows the rest.Microsoft-Windows-Security-Auditing, named data: 4624 and 4625 logons, 4740 and 4767 lockout and unlock, 4720, 4722, 4725, 4726 and 4738 account changes, 4728, 4732 and 4756 group additions, 4768, 4769 and 4771 Kerberos, 4776 NTLM credential check, 5136 directory object modified, 4662 operation on an object (DCSync detection). The agent turns on logon, lockout, user and group management. Kerberos, credential validation and directory subcategories must be set on the domain controllers: "Audit Directory Service Changes" is off by default and also needs audit entries on the objects; "Audit Directory Service Access" logs successes by default. TheDirectory Servicechannel (not read) holds LDAP signing events 2887 and 2889 (2889 uses unnamed data). The v12ad-auditplugin already uses 4720, 4726 and 4624 for its user list.Directory Servicelog.channelisSecurity;log.eventCodeis one of4625, 4740, 4720, 4726, 4728, 4732, 4756, 4768, 4769, 4771, 4776, 5136Microsoft-Windows-Windows Defender/Operational(read), providerMicrosoft-Windows-Windows Defender. 1116 malware detected, 1117 action taken, 1118 and 1119 action failed, 1006 to 1008 (older detection events), 1015 suspicious behavior, 1121 and 1122 attack surface reduction block and audit, 1123 and 1124 controlled folder access, 1125 and 1126 network protection, 5001 real-time protection off, 5004 and 5007 settings changed, 5010 and 5012 scanning off, 5013 Tamper Protection blocked a change. Named data (names contain spaces, for example "Threat Name"). None is dropped.log.providerNameisMicrosoft-Windows-Windows Defender;log.eventCodeis one of1116, 1117, 1118, 1119, 5001, 5007, 5013MSSQLSERVER(default instance) orMSSQL$<instance>(named instance); SQL Server Agent asSQLSERVERAGENTorSQLAgent$<instance>. 18456 login failed, 18453, 18454 and 18455 login succeeded, 18470 account disabled, 18486 locked out, 18487 and 18488 password expired or must change, 17162 and 17126 starting and ready, 17147 and 17148 stopping, 15457 configuration option changed, 33205 SQL Server Audit record, 18264 and 18265 backups, 823 to 825 disk read errors, 9002 log full. None is dropped. All use unnamed data. Settings in the detail below the table.log.providerNameis one ofMSSQLSERVER, MSSQL$<instance>;log.eventCodeis one of18456, 18470, 18486Microsoft-Windows-WAS: 5002 application pool disabled after repeated failures, 5009 worker process ended unexpectedly, 5010 no ping reply, 5011 fatal communication error, 5013 shutdown time exceeded, 5021 pool identity invalid, 5186 idle shutdown. Application (read), providerMicrosoft-Windows-IIS-W3SVC-WP: 2268, 2269, 2276, 2280 (filter, worker and module failures). Both use named data. ASP.NET (ASP.NET 4.0.30319.0, 1309 unhandled exception, 1310 configuration error) uses unnamed data. Does not arrive: request logs (W3C text files by default) and configuration changes; detail below the table.Microsoft-IIS-Logging/Logsaddedlog.providerNameis one ofMicrosoft-Windows-WAS, Microsoft-Windows-IIS-W3SVC-WP;log.eventCodeis one of5002, 5009, 5010, 5011, 2276, 2280target.user) and source address (origin.ip). Session channels (read):Microsoft-Windows-TerminalServices-LocalSessionManager/Operational21 logon, 23 logoff, 24 disconnect, 25 reconnect, andMicrosoft-Windows-TerminalServices-RemoteConnectionManager/Operational1149 keep user and address inUserData. Security 4778 and 4779 (reconnect, disconnect; generated because the agent turns on Other Logon/Logoff Events) are on the drop list.Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational131 (connection accepted, namedClientIP) and 140 (bad user name or password from an address, namedIPString) are not read.log.eventCodeis one of4624, 4625;log.eventDataLogonTypeis one of10(with Network Level Authentication, failed logons show as type 3)Microsoft-Windows-TerminalServices-Gateway/Operational(not read), providerMicrosoft-Windows-TerminalServices-Gateway: 200 connection policy met, 201 denied, 300 and 301 resource policy, 302 connected, 303 disconnected (bytes, duration). User and client address are inUserData.Microsoft-Windows-TerminalServices-Gateway/Operationaladded, and even then only event IDs arrive until the agent readsUserDatalog.providerNameisMicrosoft-Windows-TerminalServices-Gateway;log.eventCodeis one of201, 302, 303Microsoft-Windows-Security-Auditing, named data (SubjectUserName,CallingStationID,NASIPv4Address): 6272 granted, 6273 denied, 6274 request discarded, 6275 accounting request discarded, 6276 quarantined, 6278 full access, 6279 account locked, 6280 unlocked. "Audit Network Policy Server" logs success and failure by default (check that a Group Policy does not override it).log.channelisSecurity;log.eventCodeis one of6272, 6273, 6279log.eventDataObjectName,log.eventDataAccessMask).log.channelisSecurity;log.eventCodeis one of4660, 4663, 4670, 5140, 5142, 5144Microsoft-Windows-Sysmon/Operational(read), providerMicrosoft-Windows-Sysmon: 1 process created, 3 network connection, 7 image loaded, 8 remote thread, 10 process access, 11 file created, 12 to 14 registry, 22 DNS query, 23 and 26 file delete, 25 process tampering, 29 executable file detected. Named data. Not installed by default (sysmon -accepteula -i <config>, or the built-in Windows 11 feature). Events 3 and 7 are off unless the config turns them on.log.providerNameisMicrosoft-Windows-Sysmon;log.eventCodeis one of3, 11, 22certutil -setreg CA\AuditFilter 127and a restart of certsvc. 4898 to 4900 also needcertutil -setreg policy\EditFlags +EDITF_AUDITCERTTEMPLATELOAD(source: a PKI consultant, not Microsoft).log.channelisSecurity;log.eventCodeis one of4886, 4887, 4888, 4890, 4900MSExchange Management(not read), providerMSExchange CmdletLogs: 1 command succeeded, 6 command failed, 8 unhandled exception; unnamed data. The administrator audit log goes to a hidden mailbox, not to the event log. Application (read):ASP.NET 4.0.30319.01309 errors on web mail and admin pages.MSExchange Managementadded, event 1 taken off the parser's drop list, and unnamed data kept (4(c)(7))log.providerNameisMSExchange CmdletLogs;log.eventCodeis one of1, 6Microsoft-Windows-DNSServer/Audit(not read; on by default), providerMicrosoft-Windows-DNSServer, named data (zone, name, type, record data, and the client address for dynamic updates): 513 zone deleted, 514 zone updated, 515 and 516 record created and deleted, 519 and 520 record created and deleted by dynamic update, 521 record scavenged, 541 server setting changed, 577 to 582 policies. DNS queries are in the Analytical log, whichEvtSubscribecannot read at all.Microsoft-Windows-DNSServer/Auditadded (then complete, because the data is named)log.providerNameisMicrosoft-Windows-DNSServer;log.eventCodeis one of513, 515, 516, 541Microsoft-Windows-Dhcp-Server/Operational(70 to 74 scope changes, 106 and 107 reservations),Microsoft-Windows-Dhcp-Server/FilterNotifications(20096, 20097, 20100 client denied by a filter) andDhcpAdminEvents(1045, 1046, 1051 server not authorized, 1063 scope full, 20252 to 20255 failover), none read; providerMicrosoft-Windows-DHCP-Server. Operational and filter events use named data (MACAddress,HostName). Lease history (which device had which address) is only in text files,%windir%\System32\Dhcp\DhcpSrvLog-<Day>.log.log.providerNameisMicrosoft-Windows-DHCP-ServerMicrosoft-Windows-NTLM/Operational(read), providerMicrosoft-Windows-Security-Netlogon, event 8004 (a domain controller checked NTLM credentials) with named dataUserName,DomainName,WorkstationName(the parser renames it toorigin.host) andSChannelName. Needs the Group Policy "Network security: Restrict NTLM: Audit NTLM authentication in this domain" set to "Enable all" on the domain controllers.log.providerNameisMicrosoft-Windows-Security-Netlogon;log.eventCodeis one of8004Microsoft-Windows-CodeIntegrity/Operational(read), providerMicrosoft-Windows-CodeIntegrity: 3076 audit-mode block, 3077 enforced block, 3089 signature details, 3033 and 3034 signing failures. Named data ("File Name", "Process Name", "PolicyName"). 3089 joins its block event throughlog.activityId(the agent keeps the correlation ID).log.providerNameisMicrosoft-Windows-CodeIntegrity;log.eventCodeis one of3076, 3077Microsoft-Windows-AppLocker/EXE and DLL,.../MSI and Script,.../Packaged app-Execution,.../Packaged app-Deployment(none read), providerMicrosoft-Windows-AppLocker: 8002, 8003, 8004 (EXE and DLL allowed, audit, blocked), 8005 to 8007 (MSI and script), 8020 to 8025 (packaged apps). File path, hash and user are inUserData. Needs a policy and the Application Identity service.UserDatalog.providerNameisMicrosoft-Windows-AppLocker;log.eventCodeis one of8003, 8004, 8006, 8007Microsoft-Windows-LAPS/Operational(not read), providerMicrosoft-Windows-LAPS, named data: 10003 cycle started, 10004 success, 10005 failure, 10018 password stored in Active Directory, 10029 stored in Entra ID, 10020 local account updated, 10031 outside password change blocked.Microsoft-Windows-LAPS/Operationaladded (then complete)log.providerNameisMicrosoft-Windows-LAPS;log.eventCodeis one of10005, 10031OpenSSH/Operational(not read), providerOpenSSH. It logs there by default (defaultSyslogFacility AUTH). Every line is event 4 with named dataprocessandpayload, for exampleAccepted password for <user> from <ip> port <n> ssh2.OpenSSH/Operationaladded (then complete, because the data is named)log.providerNameisOpenSSH; textFailed passwordMicrosoft-Windows-Hyper-V-VMMS-AdminandMicrosoft-Windows-Hyper-V-Worker-Admin(not read): 13002 created, 13003 deleted, 18303 exported, 18500 started, 18502 turned off, 18504 and 18508 shut down, 18512 and 18514 reset. The virtual machine name is inUserData.UserDatalog.providerNameis one ofMicrosoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-WorkerDirectory SynchronizationandADSync: 611 password hash sync failed for a domain, 652 and 655 sync errors, 654 heartbeat every 30 minutes (a gap means sync stopped), 656 password change request, 657 password change result. Data shape not confirmed.log.providerNameis one ofDirectory Synchronization, ADSync;log.eventCodeis one of611, 652, 655AD FS Auditing: 1200 token issued, 1201 token failure, 1202 credentials validated, 1203 credential validation error, 411 token validation failed (bad password or lockout), 412 authenticated, 516 extranet lockout; unnamed data. TheAD FS/Adminchannel (not read; 342, 364) usesUserData. Needs the "Generate security audits" right for the service account,auditpol /set /subcategory:"Application Generated" /success:enable /failure:enable, and Success and Failure audits ticked in AD FS Management.log.providerNameisAD FS Auditing;log.eventCodeis one of411, 516, 1203ScreenConnect(older versionsScreenConnect Client (<id>)): 100 session connected, 101 disconnected, 201 file transfer or command run, 30 session ended. The details are one unnamed data value.log.providerNamecontainsScreenConnect;log.eventCodeis one of100, 101, 201ForwardedEvents. A subscription on a collector host that runs the agent pulls the chosen channels from the servers (section 4(b)). Forwarded events keep the source computer name.dataSourceis<collector host>;log.computeris<source server>Microsoft-Windows-PrintService/Operational(read; the agent turns it on): 307 document printed, 316 driver added or updated. Details are inUserData.UserData)log.providerNameisMicrosoft-Windows-PrintService;log.eventCodeis one of307, 316Trellix Endpoint Security,McAfee Endpoint Security, event 3) and Sophos (Sophos Anti-Virus32 and 42) write to Application (read). Symantec writes to its own channelSymantec Endpoint Protection Client(not read; 51 security risk found). All use unnamed data.log.channelisApplication;log.providerNameis one ofTrellix Endpoint Security, McAfee Endpoint Security, Sophos Anti-VirusLeft out on purpose, to keep the table at 25 rows: BitLocker (channel
Microsoft-Windows-BitLocker/BitLocker Management, not read; providerMicrosoft-Windows-BitLocker-API; 768 encryption started, 775 and 776 key protector added and removed, 845 recovery key backed up to Entra ID; named data according to the manifest), Splashtop (its own channel, named data; see 4(b)), Citrix Virtual Apps and Desktops agent (Citrix Desktop Service1027 and 1049 in Application, unnamed data), and TeamViewer and AnyDesk (text files only, no event log).SQL Server in detail (one of the product owner's two headline examples)
MSSQLSERVERfor the default instance,MSSQL$<instance>for a named instance (for exampleMSSQL$SQLEXPRESS); SQL Server Agent writes asSQLSERVERAGENTorSQLAgent$<instance>. Microsoft marks these as written to the event log: logins 18452 (untrusted domain), 18453, 18454, 18455 (succeeded), 18456 (failed), 18470 (account disabled), 18486 (locked out), 18487 and 18488 (password expired, must change); backups 18264 and 18265 (trace flag 3226 hides the success entries); start and stop 17162, 17126, 17147, 17148; connection and system errors 17806, 17836, 17053; disk and log errors 823, 824, 825, 9002. 15457 (configuration option changed) also appears in real Application logs.AuditLevel= 2), but a 2011 Microsoft blog says None, so the guide should tell customers to check it. "Failed logins only" is enough for brute-force detection; "Both" adds a success event for every connection, which is noisy on busy servers.CREATE SERVER AUDIT utm_audit TO APPLICATION_LOG;thenALTER SERVER AUDIT utm_audit WITH (STATE = ON);plus a server audit specification with the action groups wanted (for exampleFAILED_LOGIN_GROUP), also switched on. Each record is event 33205.TO SECURITY_LOGwrites 33205 to Security with sourceMSSQLSERVER$AUDITinstead, and needsauditpol /set /subcategory:"application generated" /success:enable /failure:enable, the "Generate security audits" right for the service account, and a restart.IIS in detail (the product owner's second headline example)
Microsoft-Windows-WASin System (5002, 5009, 5010, 5011, 5013, 5021, 5186) andMicrosoft-Windows-IIS-W3SVC-WPin Application (2268, 2269, 2276, 2280) use named data (AppPoolID,ProcessID,ExitCode,SiteName,ModuleDll). ASP.NET 1309 and 1310 arrive with the event ID only (unnamed data). Two WAS events are lost: 5057 and 5059 ("application pool has been disabled", Microsoft Learn "Event ID 5059 — IIS Application Pool Availability") are on the parser's drop list, which was written for the Security events with the same numbers.Microsoft-IIS-Logging/Logs(providerMicrosoft-Windows-IIS-Logging), with named fields such asdate,time,c-ip,cs-username,s-sitename,cs-method,cs-uri-stem,cs-uri-query,sc-status,time-takenandcsUser-Agent. Customer settings: in IIS Manager > (server or site) > Logging, keep Format W3C and set Log Event Destination to "ETW event only" or "Both log file and ETW event"; then turn the channel on withwevtutil sl "Microsoft-IIS-Logging/Logs" /e:true(the Windows manifest declares itenabled="false").Microsoft-IIS-Logging/Logs. The formMicrosoft-Windows-IIS-Logging/Logsis only display text; a monitoring tool that subscribed with that name got "not found" (EvlWatcher issue 122), and working Winlogbeat configurations useMicrosoft-IIS-Logging/Logs. The channel is of type Admin, soEvtSubscribecan read it. Microsoft's IIS page itself names only the provider, so check withwevtutil el | findstr /i iison a test server before shipping."Microsoft-IIS-Logging/Logs"to thechannelsslice inagent/collector/platform/windows_amd64.gobrings the request logs in, complete, because the fields are named (6200 is not on the drop list). Agents on servers without IIS would log a subscription error for the missing channel and skip it, as they already do for Sysmon. Two cautions: the field names contain hyphens (log.data.c-ip), which may need a rename step for easy filtering, and a busy site produces one event per request (a Winlogbeat user reported losing most of about 5,000 events per minute), so this needs a volume test.Microsoft-IIS-Configuration/Operational(off by default;wevtutil sl Microsoft-IIS-Configuration/Operational /e:true), event 29 with namedConfigPath,OldValueandNewValue. The user who made the change is only in the event's security identifier, which the agent does keep aslog.userId(a SID, not a name). Hand edits of the configuration file are not audited.Sources checked for this list (24 Sep 2026)
Sources for 3b (checked 2026-09-24). "EvtxECmd maps" means github.com/EricZimmerman/evtx/tree/master/evtx/Maps, whose files carry real sample event XML; that is where the data shapes (named, unnamed,
UserData) come from.Microsoft-IIS-Logging/Logs); github.com/new feature: JSON output schema microsoft/windows-container-tools#103 (6200 fields); learn.microsoft.com/en-us/archive/blogs/webtopics/iis-7-5-how-to-enable-iis-configuration-auditing.Done per technology
Research notes this list relies on
0.4 Windows field names (data type
wineventlog)The agent (
agent/collector/platform/windows_amd64.go,convertEventToJSON) sends JSON keysprovider_name,eventCode,channel,computer,level,recordId,data, and so on. The pipeline'sjsonstep strips underscores from top-level keys (explained in the comment block ofdefinitions/filters/linux/linux.yaml: go-sdkSanitizeFieldkeeps only letters, digits and dots), soprovider_namearrives aslog.providername, whichwindows-events.yamlrenames. Final names to use in Log Explorer:log.providerNamelog.channellog.eventCode(cast to integer)log.computerdataSourcelog.severityLabellog.data.<Name>, some promoted tolog.eventData<Name>,origin.ip,origin.host,target.user,target.domainlog.eventIddoes not exist in practice: the filter renameslog.id, but the agent never sendsid. Uselog.eventCode.Three agent and parser limits that decide whether a Windows guide is honest:
<Data Name="X">). It drops unnamed<Data>values, ignores<UserData>blocks and does not send the rendered message text (EvtRenderwith the XML flag, noEvtFormatMessage). Many application events therefore arrive with only provider, event ID, level, channel and computer (details per technology in table 3b).windows-events.yamldrops every event whose event ID is in one list, whatever the provider or channel. The list includes 0, 1, 43, 44, 1040, 1042, 1105, 1500, 1501, 7040, 8191, 10000, 10010, 16384, 16394 and many Security IDs (for example 4798 is kept but 5145, 6274 and 6275 are dropped). Event ID 1 kills Sysmon process creation, and event ID 0 kills any application that logs with ID 0.windows_amd64.go(about lines 343-368) is read. Anything else needs code, or the Windows Event Forwarding workaround described in section 4(b).4(b) Windows channels popular applications need but the agent does not read
Adding a channel is one line in the
channelsslice ofagent/collector/platform/windows_amd64.go. It is safe on machines without the product: a missing channel is logged and skipped (the code already relies on this for Sysmon). A channel that ships turned off must also be turned on at the source; the agent already does that for two channels (disabledByDefaultChannelsinagent/dependency/auditpolicy_windows.go, which runswevtutil sl <channel> /e:true), and the IIS channels could join that list. The first group below is complete once the channel is added; the second group also needs the agent to keep unnamed data orUserData(4(c)(7)).Microsoft-IIS-Logging/Logsenabled="false"in the manifest); IIS "Log Event Destination" must also include ETWMicrosoft-Windows-DNSServer/AuditOpenSSH/Operationalprocess,payload)Microsoft-Windows-LAPS/OperationalMicrosoft-Windows-RemoteDesktopServices-RdpCoreTS/OperationalClientIP; 140 failed logon withIPString)Microsoft-Windows-Dhcp-Server/Operational,Microsoft-Windows-Dhcp-Server/FilterNotifications,DhcpAdminEventsDhcpAdminEventsnot confirmedMicrosoft-IIS-Configuration/OperationalMicrosoft-Windows-SMBServer/AuditSet-SmbServerConfiguration -AuditSmb1Access $trueClientName)Microsoft-Windows-BitLocker/BitLocker ManagementSplashtop-Splashtop Streamer-Remote Session/OperationalDirectory Service16 LDAP Interface Events= 2, and 1644 needs15 Field Engineering= 5Microsoft-Windows-TerminalServices-Gateway/OperationalUserDataMicrosoft-Windows-AppLocker/EXE and DLL,Microsoft-Windows-AppLocker/MSI and Script,Microsoft-Windows-AppLocker/Packaged app-Execution,Microsoft-Windows-AppLocker/Packaged app-DeploymentUserDataMicrosoft-Windows-Hyper-V-VMMS-Admin,Microsoft-Windows-Hyper-V-Worker-AdminUserDataMicrosoft-Windows-SMBServer/SecurityUserDataMSExchange ManagementAD FS/AdminUserDataVeeam BackupSymantec Endpoint Protection ClientNot possible with a channel at all: the DNS Server query log is an analytic channel (
Microsoft-Windows-DNSServer/Analytical), andEvtSubscriberefuses analytic channels; it needs an Event Tracing for Windows session, which is new agent code. DHCP lease history is only in text files.Workaround with no code: Windows Event Forwarding. The agent already reads
ForwardedEvents. A customer can create a Windows Event Forwarding subscription that pulls a missing channel from its servers intoForwardedEventson one collector host that runs the UTMStack agent. Facts a guide must state (Microsoft, "Use Windows Event Forwarding to help with intrusion detection", learn.microsoft.com):wevtutil sl "Microsoft-IIS-Logging/Logs" /e:true), and the Network Service account needs to be in the Event Log Readers group to forward Security.wecutil ss <subscription> /cf:Eventsis the better setting.log.computeris the original server anddataSourceis the collector host. Whetherlog.channelkeeps the original channel name was not confirmed; guides should filter onlog.providerNameandlog.computer.UserDataand unnamed event data are dropped (so Remote Desktop Gateway, AppLocker and Hyper-V events arrive without details), and the Windows parser's drop list applies to forwarded events too.