Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

389 events
Windows Event ID 4912 – Microsoft-Windows-Kernel-General: Object Manager Symbolic Link Creation
4912InformationMicrosoft-Windows-Kernel-General

Windows Event ID 4912 – Microsoft-Windows-Kernel-General: Object Manager Symbolic Link Creation

Event ID 4912 logs when the Windows Object Manager creates symbolic links in the kernel namespace, typically during system startup or driver initialization processes.

Mar 18, 2026479m
Windows Event ID 4908 – Security: Trusted Domain Information Changed
4908InformationSecurity

Windows Event ID 4908 – Security: Trusted Domain Information Changed

Event ID 4908 indicates that trusted domain information has been modified on a domain controller, typically during domain trust establishment, modification, or removal operations.

Mar 18, 2026459m
Windows Event ID 4906 – Microsoft-Windows-Security-Auditing: An attempt was made to register a security event source
4906InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4906 – Microsoft-Windows-Security-Auditing: An attempt was made to register a security event source

Event ID 4906 fires when an application or service attempts to register itself as a security event source in the Windows Event Log system, typically during software installation or service startup.

Mar 18, 20264512m
Windows Event ID 4897 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Changed
4897InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4897 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Changed

Event ID 4897 fires when security permissions on a Certificate Authority template are modified, indicating changes to who can request, manage, or enroll certificates from that template.

Mar 18, 20264312m
Windows Event ID 4896 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Modified
4896InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4896 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Descriptor Modified

Event ID 4896 fires when security permissions on a Certificate Authority template are modified, indicating changes to who can request, approve, or manage specific certificate types.

Mar 18, 2026449m
Windows Event ID 4892 – Microsoft-Windows-Kernel-General: System Time Change Detected
4892InformationMicrosoft-Windows-Kernel-General

Windows Event ID 4892 – Microsoft-Windows-Kernel-General: System Time Change Detected

Event ID 4892 fires when Windows detects a system time change, typically during time synchronization, manual adjustments, or hardware clock drift corrections.

Mar 18, 20264312m
Windows Event ID 4890 – Microsoft-Windows-Security-Auditing: A handle to an object was requested
4890InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4890 – Microsoft-Windows-Security-Auditing: A handle to an object was requested

Event ID 4890 logs when a process requests a handle to a system object. This security audit event tracks object access attempts for compliance and security monitoring purposes.

Mar 18, 20264712m
Windows Event ID 4888 – Kernel-Power: System Power State Transition
4888InformationKernel-Power

Windows Event ID 4888 – Kernel-Power: System Power State Transition

Event ID 4888 from Kernel-Power indicates a system power state transition, typically logged when Windows enters or exits sleep, hibernate, or shutdown states during power management operations.

Mar 18, 20265212m
Windows Event ID 5028 – Windows Filtering Platform: Failed to Load Security Policy
5028ErrorWindows Filtering Platform

Windows Event ID 5028 – Windows Filtering Platform: Failed to Load Security Policy

Event ID 5028 indicates Windows Filtering Platform (WFP) failed to load security policy during system startup, potentially affecting firewall rules and network filtering capabilities.

Mar 18, 20262512m
Windows Event ID 4881 – Security: Certificate Services Template Security Permissions Changed
4881InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4881 – Security: Certificate Services Template Security Permissions Changed

Event ID 4881 logs when security permissions on a Certificate Authority template are modified, indicating changes to who can request or manage specific certificate types in your PKI infrastructure.

Mar 18, 20265312m
Windows Event ID 4880 – Security: Certificate Services Template Security Permissions Changed
4880InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4880 – Security: Certificate Services Template Security Permissions Changed

Event ID 4880 logs when security permissions on a Certificate Authority template are modified, indicating changes to who can request or manage specific certificate types in your PKI infrastructure.

Mar 18, 2026459m
Windows Event ID 4877 – Security-Auditing: Certificate Services Template Security Permissions Changed
4877InformationSecurity-Auditing

Windows Event ID 4877 – Security-Auditing: Certificate Services Template Security Permissions Changed

Event ID 4877 fires when security permissions on a Certificate Authority template are modified. Critical for PKI security monitoring and compliance auditing in enterprise environments.

Mar 18, 20265412m
Windows Event ID 4876 – Security: Special Privileges Assigned to New Logon
4876InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4876 – Security: Special Privileges Assigned to New Logon

Event ID 4876 records when special privileges are assigned to a new user logon session, indicating elevated access rights have been granted during authentication.

Mar 18, 2026499m
Windows Event ID 4872 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Permissions Changed
4872InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4872 – Microsoft-Windows-Security-Auditing: Certificate Services Template Security Permissions Changed

Event ID 4872 fires when security permissions on a Certificate Authority template are modified. This audit event tracks changes to certificate template access control lists and helps monitor PKI security modifications.

Mar 18, 2026479m
Windows Event ID 4871 – Microsoft-Windows-Security-Auditing: Certificate Services Denied Request
4871WarningMicrosoft-Windows-Security-Auditing

Windows Event ID 4871 – Microsoft-Windows-Security-Auditing: Certificate Services Denied Request

Event ID 4871 fires when Active Directory Certificate Services denies a certificate request due to policy violations, insufficient permissions, or template restrictions.

Mar 18, 20264712m
Windows Event ID 4870 – Kerberos: TGT Renewal Failure
4870WarningKerberos

Windows Event ID 4870 – Kerberos: TGT Renewal Failure

Event ID 4870 indicates a Kerberos Ticket Granting Ticket (TGT) renewal failure, typically occurring when domain authentication encounters issues with ticket refresh operations.

Mar 18, 20264912m
Windows Event ID 4869 – Kerberos: Certificate Services Client Operation Failed
4869ErrorKerberos

Windows Event ID 4869 – Kerberos: Certificate Services Client Operation Failed

Event ID 4869 indicates a Kerberos certificate services client operation has failed, typically during certificate enrollment or renewal processes in Active Directory environments.

Mar 18, 20265012m
Windows Event ID 5378 – SCHANNEL: TLS/SSL Certificate Chain Validation Error
5378ErrorSCHANNEL

Windows Event ID 5378 – SCHANNEL: TLS/SSL Certificate Chain Validation Error

Event ID 5378 indicates SCHANNEL encountered a certificate chain validation error during TLS/SSL handshake, typically due to untrusted root certificates or incomplete certificate chains.

Mar 18, 20265412m