Event Logs Flashcards
A user logged on to this computer
Event ID: 2
A user or computer logged on to this computer from the network
Event ID: 3
Batch logon type is used by batch servers, where processes may be executing on behalf of a user without their direct intervention
Event ID: 4
A service was started by the service control manager
Event ID: 5
The workstation was unlocked
Event ID: 7
A user logged on to the computer from the network. The user’s password was passed to the authentication package in its unhashed form
Event ID: 8
A caller cloned its current token and specified new credentials for outbound connections
Event ID: 9
A user logged on to this computer remotely using Terminal Services or Remote Desktop
Event ID: 10
A user logged on to this computer with network credentials that were stored locally on the computer
Event ID: 11
A new process has been created
Event ID: 4688
The Windows Filtering Platform has allowed connection
Event ID: 5156
A service was installed in the system
Event ID: 7045
A registry value was modified
Event ID: 4657
an object was deleted
Event ID: 4660
an attempt was made to access an object
Event ID: 4663