Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

389 events
Windows Event ID 8224 – Kernel-EventTracing: ETW Session Start Failure
8224ErrorKernel-EventTracing

Windows Event ID 8224 – Kernel-EventTracing: ETW Session Start Failure

Event ID 8224 indicates an Event Tracing for Windows (ETW) session failed to start, typically due to insufficient system resources, permission issues, or conflicting trace sessions.

Mar 18, 2026579m
Windows Event ID 8216 – Kernel-EventTracing: ETW Session Start Failed
8216ErrorKernel-EventTracing

Windows Event ID 8216 – Kernel-EventTracing: ETW Session Start Failed

Event ID 8216 indicates that an Event Tracing for Windows (ETW) session failed to start, typically due to insufficient permissions, resource constraints, or provider conflicts in the Windows kernel event tracing subsystem.

Mar 18, 20266212m
Windows Event ID 8197 – Microsoft-Windows-Kernel-General: System Time Change Detected
8197InformationMicrosoft-Windows-Kernel-General

Windows Event ID 8197 – Microsoft-Windows-Kernel-General: System Time Change Detected

Event ID 8197 fires when Windows detects a significant system time change, either manual adjustment or automatic synchronization. Critical for security auditing and troubleshooting time-related issues.

Mar 18, 2026609m
Windows Event ID 8194 – DNS Client: DNS Query Response Validation Failure
8194WarningDNS Client

Windows Event ID 8194 – DNS Client: DNS Query Response Validation Failure

Event ID 8194 indicates DNS query response validation failures in Windows DNS Client service, typically caused by DNSSEC validation errors or corrupted DNS responses.

Mar 18, 2026509m
Windows Event ID 6006 – EventLog: Event Log Service Stopped
6006InformationEventLog

Windows Event ID 6006 – EventLog: Event Log Service Stopped

Event ID 6006 indicates the Windows Event Log service has stopped. This informational event fires during normal system shutdown or when the EventLog service is manually stopped.

Mar 18, 2026498m
Windows Event ID 6004 – EventLog: Event Log Service Started
6004InformationEventLog

Windows Event ID 6004 – EventLog: Event Log Service Started

Event ID 6004 indicates the Windows Event Log service has successfully started. This informational event confirms the logging subsystem is operational and ready to record system events.

Mar 18, 2026528m
Windows Event ID 6005 – EventLog: Event Log Service Started
6005InformationEventLog

Windows Event ID 6005 – EventLog: Event Log Service Started

Event ID 6005 indicates the Windows Event Log service has successfully started. This informational event appears in the System log during system boot and service restarts.

Mar 18, 2026489m
Windows Event ID 6003 – EventLog: Event Log Service Started
6003InformationEventLog

Windows Event ID 6003 – EventLog: Event Log Service Started

Event ID 6003 indicates the Windows Event Log service has successfully started. This informational event appears in the System log during boot and confirms the logging subsystem is operational.

Mar 18, 2026438m
Windows Event ID 6000 – EventLog: Event Log Service Started
6000InformationEventLog

Windows Event ID 6000 – EventLog: Event Log Service Started

Event ID 6000 indicates the Windows Event Log service has successfully started. This informational event fires during system boot and confirms the logging subsystem is operational.

Mar 18, 2026448m
Windows Event ID 5615 – Security: Credential Manager Vault Access
5615InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 5615 – Security: Credential Manager Vault Access

Event ID 5615 logs when a user or process accesses the Windows Credential Manager vault to retrieve stored credentials, passwords, or certificates for authentication purposes.

Mar 18, 20265112m
Windows Event ID 5617 – Winlogon: User Logon Session Destroyed
5617InformationWinlogon

Windows Event ID 5617 – Winlogon: User Logon Session Destroyed

Event ID 5617 indicates that a user logon session has been destroyed by the Windows Logon service, typically occurring during normal user logoff or session termination processes.

Mar 18, 20267312m
Windows Event ID 4113 – Microsoft-Windows-Kernel-General: System Time Changed
4113InformationMicrosoft-Windows-Kernel-General

Windows Event ID 4113 – Microsoft-Windows-Kernel-General: System Time Changed

Event ID 4113 fires when the Windows system time is changed, either manually by a user or automatically by time synchronization services. Critical for security auditing and compliance tracking.

Mar 18, 2026609m
Windows Event ID 4112 – Kerberos: Kerberos Authentication Service (AS) Started
4112InformationMicrosoft-Windows-Security-Kerberos

Windows Event ID 4112 – Kerberos: Kerberos Authentication Service (AS) Started

Event ID 4112 indicates the Kerberos Authentication Service (AS) has successfully started on a domain controller, enabling authentication ticket granting for domain users and services.

Mar 18, 2026479m
Windows Event ID 4111 – Microsoft-Windows-Kernel-Process: Process Creation Auditing Event
4111InformationMicrosoft-Windows-Kernel-Process

Windows Event ID 4111 – Microsoft-Windows-Kernel-Process: Process Creation Auditing Event

Event ID 4111 tracks process creation events in Windows when advanced auditing is enabled. This security-focused event provides detailed information about new processes, including parent process details and command line arguments.

Mar 18, 20265612m
Windows Event ID 4109 – Microsoft-Windows-Wininit: User Logoff Notification
4109InformationMicrosoft-Windows-Wininit

Windows Event ID 4109 – Microsoft-Windows-Wininit: User Logoff Notification

Event ID 4109 records user logoff events initiated by the Windows initialization process, providing audit trail for session termination and system security monitoring.

Mar 18, 20265312m
Windows Event ID 4108 – Microsoft-Windows-Eventlog: Event Log Service Encountered an Error
4108ErrorMicrosoft-Windows-Eventlog

Windows Event ID 4108 – Microsoft-Windows-Eventlog: Event Log Service Encountered an Error

Event ID 4108 indicates the Windows Event Log service encountered an error while processing event logs, often related to log file corruption, disk space issues, or service configuration problems.

Mar 18, 2026469m
Windows Event ID 4097 – Microsoft-Windows-Kernel-General: System Time Change Detected
4097InformationMicrosoft-Windows-Kernel-General

Windows Event ID 4097 – Microsoft-Windows-Kernel-General: System Time Change Detected

Event ID 4097 fires when Windows detects a system time change, either manual or automatic. Critical for security auditing and troubleshooting time synchronization issues.

Mar 18, 2026529m
Windows Event ID 4096 – Microsoft-Windows-Wininit: System Initialization Process Started
4096InformationMicrosoft-Windows-Wininit

Windows Event ID 4096 – Microsoft-Windows-Wininit: System Initialization Process Started

Event ID 4096 indicates the Windows initialization process (wininit.exe) has started during system boot. This informational event marks the beginning of critical system service initialization and user session preparation.

Mar 18, 2026539m