Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

389 events
Windows Event ID 6008 – EventLog: Unexpected System Shutdown Detection
6008ErrorEventLog

Windows Event ID 6008 – EventLog: Unexpected System Shutdown Detection

Event ID 6008 indicates Windows detected an unexpected system shutdown. The system was not properly shut down before the previous boot, suggesting power loss, hardware failure, or forced restart.

Mar 17, 20267412m
Windows Event ID 4608 – Security: Windows System Startup Initialization
4608InformationSecurity

Windows Event ID 4608 – Security: Windows System Startup Initialization

Event ID 4608 logs when Windows starts up and the Local Security Authority Subsystem Service (LSASS.EXE) initializes the auditing subsystem during system boot.

Mar 17, 2026618m
Windows Event ID 4723 – Microsoft-Windows-Security-Auditing: User Account Password Change Attempt
4723InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4723 – Microsoft-Windows-Security-Auditing: User Account Password Change Attempt

Event ID 4723 logs when a user attempts to change another user's password. This security audit event tracks administrative password reset operations and helps monitor unauthorized password modifications across Windows domains.

Mar 17, 20268912m
Windows Event ID 4625 – Microsoft-Windows-Security-Auditing: An Account Failed to Log On
4625InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4625 – Microsoft-Windows-Security-Auditing: An Account Failed to Log On

Event ID 4625 records failed logon attempts in Windows Security logs. Critical for detecting brute force attacks, credential issues, and unauthorized access attempts across domain and local accounts.

Mar 17, 20268112m
Windows Event ID 4624 – Microsoft-Windows-Security-Auditing: An Account Was Successfully Logged On
4624InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4624 – Microsoft-Windows-Security-Auditing: An Account Was Successfully Logged On

Event ID 4624 records successful user authentication attempts in Windows. This security audit event fires whenever a user, service, or computer account successfully logs on to the system, providing detailed logon session information.

Mar 17, 20267412m
Windows Event ID 10010 – DistributedCOM: DCOM Server Process Launcher Access Denied
10010ErrorDistributedCOM

Windows Event ID 10010 – DistributedCOM: DCOM Server Process Launcher Access Denied

Event ID 10010 indicates DCOM server process launcher encountered access denied errors when attempting to start COM+ applications or services, typically due to permission issues or corrupted DCOM configurations.

Mar 17, 202612212m