Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

389 events
Windows Event ID 4673 – Security: Sensitive Privilege Use
4673InformationSecurity

Windows Event ID 4673 – Security: Sensitive Privilege Use

Event ID 4673 logs when a user or process attempts to use a sensitive privilege on Windows systems. This security audit event helps track privileged operations and potential security risks.

Mar 18, 20267512m
Windows Event ID 4649 – Microsoft-Windows-Security-Auditing: A replay attack was detected
4649WarningMicrosoft-Windows-Security-Auditing

Windows Event ID 4649 – Microsoft-Windows-Security-Auditing: A replay attack was detected

Event ID 4649 indicates Windows detected a potential Kerberos replay attack where authentication credentials were reused maliciously. This security audit event requires immediate investigation to prevent unauthorized access.

Mar 18, 20264912m
Windows Event ID 4621 – LSA: Administrator Recovery Agent Policy Changed
4621InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4621 – LSA: Administrator Recovery Agent Policy Changed

Event ID 4621 fires when the Administrator Recovery Agent policy for Encrypting File System (EFS) is modified, indicating changes to data recovery capabilities on the system.

Mar 18, 2026449m
Windows Event ID 4618 – Security: A Monitored Security Event Pattern Has Occurred
4618InformationSecurity

Windows Event ID 4618 – Security: A Monitored Security Event Pattern Has Occurred

Event ID 4618 indicates that Windows Security has detected a monitored security event pattern, typically related to audit policy changes or security monitoring configuration updates.

Mar 18, 20265112m
Windows Event ID 4616 – Security: System Time Changed
4616InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4616 – Security: System Time Changed

Event ID 4616 logs when the system time is changed on a Windows machine. This security audit event tracks time modifications for compliance and forensic purposes.

Mar 18, 20265212m
Windows Event ID 4611 – LSA: A trusted logon process has been assigned to an authentication package
4611InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4611 – LSA: A trusted logon process has been assigned to an authentication package

Event ID 4611 fires when the Local Security Authority (LSA) assigns a trusted logon process to an authentication package, indicating normal authentication subsystem initialization or configuration changes.

Mar 18, 2026519m
Windows Event ID 4610 – LSA: Authentication Package Loaded
4610InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 4610 – LSA: Authentication Package Loaded

Event ID 4610 records when the Local Security Authority (LSA) loads an authentication package during system startup, indicating security subsystem initialization.

Mar 18, 2026529m
Windows Event ID 4609 – Security: Windows is Starting Up
4609InformationSecurity

Windows Event ID 4609 – Security: Windows is Starting Up

Event ID 4609 records when Windows begins its startup process. This security audit event fires during system boot and provides critical timing information for security monitoring and forensic analysis.

Mar 18, 2026489m
Windows Event ID 1503 – Group Policy: Group Policy Processing Failed
1503ErrorGroup Policy

Windows Event ID 1503 – Group Policy: Group Policy Processing Failed

Event ID 1503 indicates Group Policy processing has failed during startup or refresh cycles. This error prevents policy settings from applying correctly to the computer or user.

Mar 18, 2026529m
Windows Event ID 1502 – WinLogon: User Profile Service Failed to Load User Profile
1502ErrorWinLogon

Windows Event ID 1502 – WinLogon: User Profile Service Failed to Load User Profile

Event ID 1502 indicates the User Profile Service failed to load a user profile during logon, typically due to corrupted profile data, insufficient permissions, or registry corruption.

Mar 18, 2026499m
Windows Event ID 1501 – MsiInstaller: Windows Installer Reconfiguration Started
1501InformationMsiInstaller

Windows Event ID 1501 – MsiInstaller: Windows Installer Reconfiguration Started

Event ID 1501 indicates Windows Installer has begun reconfiguring an installed application or feature, typically triggered by repair operations, feature modifications, or automatic maintenance tasks.

Mar 18, 20265212m
Windows Event ID 1125 – User32: User Logon Session Notification
1125InformationUser32

Windows Event ID 1125 – User32: User Logon Session Notification

Event ID 1125 from User32 indicates a user logon session notification event, typically fired during interactive logon processes or session state changes in Windows environments.

Mar 18, 2026468m
Windows Event ID 1085 – EventLog: Event Log Service Automatic Backup
1085InformationEventLog

Windows Event ID 1085 – EventLog: Event Log Service Automatic Backup

Event ID 1085 indicates the Windows Event Log service has automatically backed up a log file when it reached maximum size or retention limits.

Mar 18, 2026479m
Windows Event ID 1074 – User32: System Restart or Shutdown Initiated
1074InformationUser32

Windows Event ID 1074 – User32: System Restart or Shutdown Initiated

Event ID 1074 records when a system restart or shutdown is initiated by a user or application. This informational event tracks who initiated the action and the reason code.

Mar 18, 20261208m
Windows Event ID 51 – Disk: Page Fault in Nonpaged Area
51ErrorDisk

Windows Event ID 51 – Disk: Page Fault in Nonpaged Area

Event ID 51 indicates a critical disk error where Windows encountered a page fault in the nonpaged memory area, typically caused by hardware failures, driver issues, or memory corruption.

Mar 18, 20265412m
Windows Event ID 44 – Kernel-Power: Critical System Power Event
44CriticalKernel-Power

Windows Event ID 44 – Kernel-Power: Critical System Power Event

Event ID 44 from Kernel-Power indicates a critical system power event, typically recording unexpected shutdowns, power failures, or system crashes that prevent proper shutdown procedures.

Mar 18, 20266312m
Windows Event ID 43 – Kernel-PnP: Device Installation Failure
43ErrorKernel-PnP

Windows Event ID 43 – Kernel-PnP: Device Installation Failure

Event ID 43 from Kernel-PnP indicates a critical device installation or driver failure. This error occurs when Windows cannot properly initialize a hardware device, typically due to driver issues, hardware conflicts, or corrupted device configurations.

Mar 18, 2026609m
Windows Event ID 22 – Application Error: Application Hang Detection
22WarningApplication Error

Windows Event ID 22 – Application Error: Application Hang Detection

Event ID 22 indicates Windows has detected an application hang or unresponsive program. This event fires when applications stop responding to user input or system messages for extended periods.

Mar 18, 2026959m