Windows Security Audit Events

Windows Security Events als Tabelle

Filterbare und sortierbare Tabelle

Nicht immer hat man die Tabelle mit den Security Events zur Einsicht zur Hand. Hier eine Online Tabelle mit allen Einträgen. Gültig bis hin zu Windows Server 2019.

CategorySubcategoryEvent IDMessage SummaryMinimum Operating System Requirement
SystemSecurity State Change4608Windows is starting up.Windows Vista, Windows Server 2008
SystemSecurity State Change4609Windows is shutting down.Windows Vista, Windows Server 2008
SystemSecurity System Extension4610An authentication package has been loaded by the Local Security Authority.Windows Vista, Windows Server 2008
SystemSecurity System Extension4611A trusted logon process has been registered with the Local Security Authority.Windows Vista, Windows Server 2008
SystemSystem Integrity4612Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.Windows Vista, Windows Server 2008
SystemSecurity System Extension4614A notification package has been loaded by the Security Account Manager.Windows Vista, Windows Server 2008
SystemSystem Integrity4615Invalid use of LPC port.Windows Vista, Windows Server 2008
SystemSecurity State Change4616The system time was changed.Windows Vista, Windows Server 2008
SystemSystem Integrity4618A monitored security event pattern has occurred.Windows Vista, Windows Server 2008
SystemSecurity State Change4621Administrator recovered system from CrashOnAuditFail. Users who are not administrators will now be allowed to log on. Some auditable activity might not have been recorded.Windows Vista, Windows Server 2008
SystemSecurity System Extension4622A security package has been loaded by the Local Security Authority.Windows Vista, Windows Server 2008
Logon/LogoffLogon4624An account was successfully logged on.Windows Vista, Windows Server 2008
Logon/LogoffLogon4625An account failed to log on.Windows Vista, Windows Server 2008
Logon/LogoffLogon4626User/Device claims information.Windows 8, Windows Server 2012
Logon/LogoffGroup Membership4627Group membership information. Windows 10
Logon/LogoffLogoff4634An account was logged off.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4646%1Windows Vista, Windows Server 2008
Logon/LogoffLogoff4647User initiated logoff.Windows Vista, Windows Server 2008
Logon/LogoffLogon4648A logon was attempted using explicit credentials.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4649A replay attack was detected.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4650An IPsec Main Mode security association was established. Extended Mode was not enabled. Certificate authentication was not used.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4651An IPsec Main Mode security association was established. Extended Mode was not enabled. A certificate was used for authentication.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4652An IPsec Main Mode negotiation failed.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4653An IPsec Main Mode negotiation failed.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Quick Mode4654An IPsec Quick Mode negotiation failed.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4655An IPsec Main Mode security association ended.Windows Vista, Windows Server 2008
Object AccessHandle Manipulation4656A handle to an object was requested.Windows Vista, Windows Server 2008
Object AccessRegistry4657A registry value was modified.Windows Vista, Windows Server 2008
Object AccessHandle Manipulation4658The handle to an object was closed.Windows Vista, Windows Server 2008
Object AccessSAM4659A handle to an object was requested with intent to delete.Windows Vista, Windows Server 2008
Object AccessKernel4659A handle to an object was requested with intent to delete.Windows Vista, Windows Server 2008
Object AccessSAM4660An object was deleted.Windows Vista, Windows Server 2008
Object AccessKernel4660An object was deleted.Windows Vista, Windows Server 2008
Object AccessSAM4661A handle to an object was requested.Windows Vista, Windows Server 2008
Object AccessKernel4661A handle to an object was requested.Windows Vista, Windows Server 2008
DS AccessDirectory Service Access4662An operation was performed on an object.Windows Vista, Windows Server 2008
Object AccessSAM4663An attempt was made to access an object.Windows Vista, Windows Server 2008
Object AccessKernel4663An attempt was made to access an object.Windows Vista, Windows Server 2008
Object AccessFile System4664An attempt was made to create a hard link.Windows Vista, Windows Server 2008
Object AccessApplication Generated4665An attempt was made to create an application client context.Windows Vista, Windows Server 2008
Object AccessApplication Generated4666An application attempted an operation:Windows Vista, Windows Server 2008
Object AccessApplication Generated4667An application client context was deleted.Windows Vista, Windows Server 2008
Object AccessApplication Generated4668An application was initialized.Windows Vista, Windows Server 2008
Policy ChangeSubcategory (special)4670Permissions on an object were changed.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4671An application attempted to access a blocked ordinal through the TBS.Windows Vista, Windows Server 2008
Privilege UseSensitive Privilege Use / Non Sensitive Privilege Use4672Special privileges assigned to new logon.Windows Vista, Windows Server 2008
Privilege UseSensitive Privilege Use / Non Sensitive Privilege Use4673A privileged service was called.Windows Vista, Windows Server 2008
Privilege UseSensitive Privilege Use / Non Sensitive Privilege Use4674An operation was attempted on a privileged object.Windows Vista, Windows Server 2008
Logon/LogoffLogon4675SIDs were filtered.Windows Vista, Windows Server 2008
Detailed TrackingProcess Creation4688A new process has been created.Windows Vista, Windows Server 2008
Detailed TrackingProcess Termination4689A process has exited.Windows Vista, Windows Server 2008
Object AccessHandle Manipulation4690An attempt was made to duplicate a handle to an object.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4691Indirect access to an object was requested.Windows Vista, Windows Server 2008
Detailed TrackingDPAPI Activity4692Backup of data protection master key was attempted.Windows Vista, Windows Server 2008
Detailed TrackingDPAPI Activity4693Recovery of data protection master key was attempted.Windows Vista, Windows Server 2008
Detailed TrackingDPAPI Activity4694Protection of auditable protected data was attempted.Windows Vista, Windows Server 2008
Detailed TrackingDPAPI Activity4695Unprotection of auditable protected data was attempted.Windows Vista, Windows Server 2008
Detailed TrackingProcess Creation4696A primary token was assigned to process.Windows Vista, Windows Server 2008
SystemSecurity System Extension4697A service was installed in the system.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4698A scheduled task was created.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4699A scheduled task was deleted.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4700A scheduled task was enabled.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4701A scheduled task was disabled.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events4702A scheduled task was updated.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4703A user right was adjusted.Windows 10
Policy ChangeAuthorization Policy Change4704A user right was assigned.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4705A user right was removed.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4706A new trust was created to a domain.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4707A trust to a domain was removed.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change4709IPsec Services was started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change4710IPsec Services was disabled.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change4711May contain any one of the following: PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.
PAStore Engine applied Active Directory storage IPsec policy on the computer.
PAStore Engine applied local registry storage IPsec policy on the computer.
PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.
PAStore Engine failed to apply Active Directory storage IPsec policy on the computer.
PAStore Engine failed to apply local registry storage IPsec policy on the computer.
PAStore Engine failed to apply some rules of the active IPsec policy on the computer.
PAStore Engine failed to load directory storage IPsec policy on the computer.
PAStore Engine loaded directory storage IPsec policy on the computer.
PAStore Engine failed to load local storage IPsec policy on the computer.
PAStore Engine loaded local storage IPsec policy on the computer.
PAStore Engine polled for changes to the active IPsec policy and detected no changes.
Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change4712IPsec Services encountered a potentially serious failure.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4713Kerberos policy was changed.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4714Encrypted data recovery policy was changed.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4715The audit policy (SACL) on an object was changed.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4716Trusted domain information was modified.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4717System security access was granted to an account.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4718System security access was removed from an account.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4719System audit policy was changed.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4720A user account was created.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4722A user account was enabled.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4723An attempt was made to change an account's password.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4724An attempt was made to reset an account's password.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4725A user account was disabled.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4726A user account was deleted.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4727A security-enabled global group was created.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4728A member was added to a security-enabled global group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4729A member was removed from a security-enabled global group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4730A security-enabled global group was deleted.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4731A security-enabled local group was created.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4732A member was added to a security-enabled local group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4733A member was removed from a security-enabled local group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4734A security-enabled local group was deleted.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4735A security-enabled local group was changed.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4737A security-enabled global group was changed.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4738A user account was changed.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4739Domain Policy was changed.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4740A user account was locked out.Windows Vista, Windows Server 2008
Account ManagementComputer Account Management4742A computer account was changed.Windows Vista, Windows Server 2008
Account ManagementComputer Account Management4743A computer account was deleted.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4744A security-disabled local group was created.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4745A security-disabled local group was changed.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4746A member was added to a security-disabled local group.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4747A member was removed from a security-disabled local group.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4748A security-disabled local group was deleted.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4749A security-disabled global group was created.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4750A security-disabled global group was changed.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4751A member was added to a security-disabled global group.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4752A member was removed from a security-disabled global group.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4753A security-disabled global group was deleted.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4754A security-enabled universal group was created.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4755A security-enabled universal group was changed.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4756A member was added to a security-enabled universal group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4757A member was removed from a security-enabled universal group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4758A security-enabled universal group was deleted.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4759A security-disabled universal group was created.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4760A security-disabled universal group was changed.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4761A member was added to a security-disabled universal group.Windows Vista, Windows Server 2008
Account ManagementDistribution Group Management4762A member was removed from a security-disabled universal group.Windows Vista, Windows Server 2008
Account ManagementSecurity Group Management4764A group’s type was changed.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4765SID History was added to an account.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4766An attempt to add SID History to an account failed.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4767A user account was unlocked.Windows Vista, Windows Server 2008
Account LogonKerberos Authentication Service4768A Kerberos authentication ticket (TGT) was requested.Windows Vista, Windows Server 2008
Account LogonKerberos Service Ticket Operations4769A Kerberos service ticket was requested.Windows Vista, Windows Server 2008
Account LogonKerberos Service Ticket Operations4770A Kerberos service ticket was renewed.Windows Vista, Windows Server 2008
Account LogonKerberos Authentication Service4771Kerberos pre-authentication failed.Windows Vista, Windows Server 2008
Account LogonKerberos Authentication Service4772A Kerberos authentication ticket request failed.Windows Vista, Windows Server 2008
Account LogonKerberos Authentication Service4773A Kerberos service ticket request failed.Windows Vista, Windows Server 2008
Account LogonCredential Validation4774An account was mapped for logon.Windows Vista, Windows Server 2008
Account LogonCredential Validation4775An account could not be mapped for logon.Windows Vista, Windows Server 2008
Account LogonCredential Validation4776The domain controller attempted to validate the credentials for an account.Windows Vista, Windows Server 2008
Account LogonCredential Validation4777The domain controller failed to validate the credentials for an account.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4778A session was reconnected to a Window Station.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4779A session was disconnected from a Window Station.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4780The ACL was set on accounts which are members of administrators groups.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4781The name of an account was changed:Windows Vista, Windows Server 2008
Account ManagementOther Account Management Events4782The password hash an account was accessed.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4783A basic application group was created.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4784A basic application group was changed.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4785A member was added to a basic application group.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4786A member was removed from a basic application group.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4787A non-member was added to a basic application group.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4788A non-member was removed from a basic application group.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4789A basic application group was deleted.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4790An LDAP query group was created.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4791A basic application group was changed.Windows Vista, Windows Server 2008
Account ManagementApplication Group Management4792An LDAP query group was deleted.Windows Vista, Windows Server 2008
Account ManagementOther Account Management Events4793The Password Policy Checking API was called.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4794An attempt was made to set the Directory Services Restore Mode.Windows Vista, Windows Server 2008
Account ManagementUser Account Management4797An attempt was made to query the existence of a blank password for an account.Windows 8, Windows Server 2012
Account ManagementUser Account Management4798A user's local group membership was enumerated. Windows 10
Account ManagementSecurity Group Management4799A security-enabled local group membership was enumerated.Windows 10
Logon/LogoffOther Logon/Logoff Events4800The workstation was locked.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4801The workstation was unlocked.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4802The screen saver was invoked.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events4803The screen saver was dismissed.Windows Vista, Windows Server 2008
SystemSystem Integrity4816RPC detected an integrity violation while decrypting an incoming message.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4817Auditing settings on an object were changed.Windows 7, Windows Server 2008 R2
Object AccessCentral Access Policy Staging4818Proposed Central Access Policy does not grant the same access permissions as the current Central Access PolicyWindows 8, Windows Server 2012
Policy ChangeOther Policy Change Events4819Central Access Policies on the machine have been changed.Windows 8, Windows Server 2012
Account LogonKerberos Authentication Service4820A Kerberos Ticket-granting-ticket (TGT) was denied because the device does not meet the access control restrictions.Windows 8, Windows Server 2012
Account LogonKerberos Service Ticket Operations4821A Kerberos service ticket was denied because the user, device, or both does not meet the access control restrictions.Windows 8.1, Windows Server 2012 R2
Account LogonCredential Validation4822NTLM authentication failed because the account was a member of the Protected User group.Windows 8.1, Windows Server 2012 R2
Account LogonCredential Validation4823NTLM authentication failed because access control restrictions are required.Windows 8.1, Windows Server 2012 R2
Account LogonKerberos Authentication Service4824Kerberos preauthentication by using DES or RC4 failed because the account was a member of the Protected User group.Windows 8.1, Windows Server 2012 R2
Logon/LogoffOther Logon/Logoff Events4825A user was denied the access to Remote Desktop. Windows Vista SP2, Windows Server 2008 SP2
Policy ChangeOther Policy Change Events4826Boot Configuration Data loaded.Windows 10
Policy ChangeAuthentication Policy Change4864A namespace collision was detected.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4865A trusted forest information entry was added.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4866A trusted forest information entry was removed.Windows Vista, Windows Server 2008
Policy ChangeAuthentication Policy Change4867A trusted forest information entry was modified.Windows Vista, Windows Server 2008
Object AccessCertification Services4868The certificate manager denied a pending certificate request.Windows Vista, Windows Server 2008
Object AccessCertification Services4869Certificate Services received a resubmitted certificate request.Windows Vista, Windows Server 2008
Object AccessCertification Services4870Certificate Services revoked a certificate.Windows Vista, Windows Server 2008
Object AccessCertification Services4871Certificate Services received a request to publish the certificate revocation list (CRL).Windows Vista, Windows Server 2008
Object AccessCertification Services4872Certificate Services published the certificate revocation list (CRL).Windows Vista, Windows Server 2008
Object AccessCertification Services4873A certificate request extension changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4874One or more certificate request attributes changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4875Certificate Services received a request to shut down.Windows Vista, Windows Server 2008
Object AccessCertification Services4876Certificate Services backup started.Windows Vista, Windows Server 2008
Object AccessCertification Services4877Certificate Services backup completed.Windows Vista, Windows Server 2008
Object AccessCertification Services4878Certificate Services restore started.Windows Vista, Windows Server 2008
Object AccessCertification Services4879Certificate Services restore completed.Windows Vista, Windows Server 2008
Object AccessCertification Services4880Certificate Services started.Windows Vista, Windows Server 2008
Object AccessCertification Services4881Certificate Services stopped.Windows Vista, Windows Server 2008
Object AccessCertification Services4882The security permissions for Certificate Services changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4883Certificate Services retrieved an archived key.Windows Vista, Windows Server 2008
Object AccessCertification Services4884Certificate Services imported a certificate into its database.Windows Vista, Windows Server 2008
Object AccessCertification Services4885The audit filter for Certificate Services changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4886Certificate Services received a certificate request.Windows Vista, Windows Server 2008
Object AccessCertification Services4887Certificate Services approved a certificate request and issued a certificate.Windows Vista, Windows Server 2008
Object AccessCertification Services4888Certificate Services denied a certificate request.Windows Vista, Windows Server 2008
Object AccessCertification Services4889Certificate Services set the status of a certificate request to pending.Windows Vista, Windows Server 2008
Object AccessCertification Services4890The certificate manager settings for Certificate Services changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4891A configuration entry changed in Certificate Services.Windows Vista, Windows Server 2008
Object AccessCertification Services4892A property of Certificate Services changed.Windows Vista, Windows Server 2008
Object AccessCertification Services4893Certificate Services archived a key.Windows Vista, Windows Server 2008
Object AccessCertification Services4894Certificate Services imported and archived a key.Windows Vista, Windows Server 2008
Object AccessCertification Services4895Certificate Services published the CA certificate to Active Directory Domain Services.Windows Vista, Windows Server 2008
Object AccessCertification Services4896One or more rows have been deleted from the certificate database.Windows Vista, Windows Server 2008
Object AccessCertification Services4897Role separation enabled:Windows Vista, Windows Server 2008
Object AccessCertification Services4898Certificate Services loaded a template.Windows Vista, Windows Server 2008
Object AccessCertification Services4899A Certificate Services template was updated.Windows Vista, Windows Server 2008
Object AccessCertification Services4900Certificate Services template security was updated.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4902The Per-user audit policy table was created.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4904An attempt was made to register a security event source.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4905An attempt was made to unregister a security event source.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4906The CrashOnAuditFail value has changed.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4907Auditing settings on object were changed.Windows Vista, Windows Server 2008
Policy ChangeAudit Policy Change4908Special Groups Logon table modified.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events4909The local policy settings for the TBS were changed.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events4910The group policy settings for the TBS were changed.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4911Resource attributes of the object were changed.Windows 8, Windows Server 2012
Policy ChangeAudit Policy Change4912Per User Audit Policy was changed.Windows Vista, Windows Server 2008
Policy ChangeAuthorization Policy Change4913Central Access Policy on the object was changed.Windows 8, Windows Server 2012
DS AccessDetailed Directory Service Replication4928An Active Directory replica source naming context was established.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4929An Active Directory replica source naming context was removed.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4930An Active Directory replica source naming context was modified.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4931An Active Directory replica destination naming context was modified.Windows Vista, Windows Server 2008
DS AccessDirectory Service Replication4932Synchronization of a replica of an Active Directory naming context has begun.Windows Vista, Windows Server 2008
DS AccessDirectory Service Replication4933Synchronization of a replica of an Active Directory naming context has ended.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4934Attributes of an Active Directory object were replicated.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4935Replication failure begins.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4936Replication failure ends.Windows Vista, Windows Server 2008
DS AccessDetailed Directory Service Replication4937A lingering object was removed from a replica.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4944The following policy was active when the Windows Firewall started.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4945A rule was listed when the Windows Firewall started.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4946A change has been made to Windows Firewall exception list. A rule was added.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4947A change has been made to Windows Firewall exception list. A rule was modified.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4948A change has been made to Windows Firewall exception list. A rule was deleted.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4949Windows Firewall settings were restored to the default values.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4950A Windows Firewall setting has changed.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4951A rule has been ignored because its major version number was not recognized by Windows Firewall.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4952Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall. The other parts of the rule will be enforced.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4953A rule has been ignored by Windows Firewall because it could not parse the rule.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4954Windows Firewall Group Policy settings have changed. The new settings have been applied.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4956Windows Firewall has changed the active profile.Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4957Windows Firewall did not apply the following rule:Windows Vista, Windows Server 2008
Policy ChangeMPSSVC Rule-Level Policy Change4958Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer:Windows Vista, Windows Server 2008
SystemIPsec Driver4960IPsec dropped an inbound packet that failed an integrity check. If this problem persists, it could indicate a network issue or that packets are being modified in transit to this computer. Verify that the packets sent from the remote computer are the same as those received by this computer. This error might also indicate interoperability problems with other IPsec implementations.Windows Vista, Windows Server 2008
SystemIPsec Driver4961IPsec dropped an inbound packet that failed a replay check. If this problem persists, it could indicate a replay attack against this computer.Windows Vista, Windows Server 2008
SystemIPsec Driver4962IPsec dropped an inbound packet that failed a replay check. The inbound packet had too low a sequence number to ensure it was not a replay.Windows Vista, Windows Server 2008
SystemIPsec Driver4963IPsec dropped an inbound clear text packet that should have been secured. This is usually due to the remote computer changing its IPsec policy without informing this computer. This could also be a spoofing attack attempt.Windows Vista, Windows Server 2008
Logon/LogoffSpecial Logon4964Special groups have been assigned to a new logon.Windows Vista, Windows Server 2008
SystemIPsec Driver4965IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI). This is usually caused by malfunctioning hardware that is corrupting packets. If these errors persist, verify that the packets sent from the remote computer are the same as those received by this computer. This error may also indicate interoperability problems with other IPsec implementations. In that case, if connectivity is not impeded, then these events can be ignored.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode4976During Main Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Quick Mode4977During Quick Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4978During Extended Mode negotiation, IPsec received an invalid negotiation packet. If this problem persists, it could indicate a network issue or an attempt to modify or replay this negotiation.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4979IPsec Main Mode and Extended Mode security associations were established.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4980IPsec Main Mode and Extended Mode security associations were established.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4981IPsec Main Mode and Extended Mode security associations were established.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4982IPsec Main Mode and Extended Mode security associations were established.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4983An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Extended Mode4984An IPsec Extended Mode negotiation failed. The corresponding Main Mode security association has been deleted.Windows Vista, Windows Server 2008
Object AccessFile System4985The state of a transaction has changed.Windows Vista, Windows Server 2008
SystemOther System Events5024The Windows Firewall Service has started successfully.Windows Vista, Windows Server 2008
SystemOther System Events5025The Windows Firewall Service has been stopped.Windows Vista, Windows Server 2008
SystemOther System Events5027The Windows Firewall Service was unable to retrieve the security policy from the local storage. The service will continue enforcing the current policy.Windows Vista, Windows Server 2008
SystemOther System Events5028The Windows Firewall Service was unable to parse the new security policy. The service will continue with currently enforced policy.Windows Vista, Windows Server 2008
SystemOther System Events5029The Windows Firewall Service failed to initialize the driver. The service will continue to enforce the current policy.Windows Vista, Windows Server 2008
SystemOther System Events5030The Windows Firewall Service failed to start.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5031The Windows Firewall Service blocked an application from accepting incoming connections on the network.Windows Vista, Windows Server 2008
SystemOther System Events5032Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.Windows Vista, Windows Server 2008
SystemOther System Events5033The Windows Firewall Driver has started successfully.Windows Vista, Windows Server 2008
SystemOther System Events5034The Windows Firewall Driver has been stopped.Windows Vista, Windows Server 2008
SystemOther System Events5035The Windows Firewall Driver failed to start.Windows Vista, Windows Server 2008
SystemOther System Events5037The Windows Firewall Driver detected critical runtime error. Terminating.Windows Vista, Windows Server 2008
SystemSystem Integrity5038Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.Windows Vista, Windows Server 2008
Object AccessRegistry5039A registry key was virtualized.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5040A change has been made to IPsec settings. An Authentication Set was added.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5041A change has been made to IPsec settings. An Authentication Set was modified.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5042A change has been made to IPsec settings. An Authentication Set was deleted.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5043A change has been made to IPsec settings. A Connection Security Rule was added.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5044A change has been made to IPsec settings. A Connection Security Rule was modified.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5045A change has been made to IPsec settings. A Connection Security Rule was deleted.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5046A change has been made to IPsec settings. A Crypto Set was added.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5047A change has been made to IPsec settings. A Crypto Set was modified.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5048A change has been made to IPsec settings. A Crypto Set was deleted.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode5049An IPsec Security Association was deleted.Windows Vista, Windows Server 2008
SystemOther System Events5050An attempt to programmatically disable the Windows Firewall was rejected because this API is not supported on Windows Vista.Windows Vista, Windows Server 2008
Object AccessFile System5051A file was virtualized.Windows Vista, Windows Server 2008
SystemSystem Integrity5056A cryptographic self test was performed.Windows Vista, Windows Server 2008
SystemSystem Integrity5057A cryptographic primitive operation failed.Windows Vista, Windows Server 2008
SystemOther System Events5058Key file operation.Windows Vista, Windows Server 2008
SystemOther System Events5059Key migration operation.Windows Vista, Windows Server 2008
SystemSystem Integrity5060Verification operation failed.Windows Vista, Windows Server 2008
SystemSystem Integrity5061Cryptographic operation.Windows Vista, Windows Server 2008
SystemSystem Integrity5062A kernel-mode cryptographic self test was performed.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5063A cryptographic provider operation was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5064A cryptographic context operation was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5065A cryptographic context modification was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5066A cryptographic function operation was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5067A cryptographic function modification was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5068A cryptographic function provider operation was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5069A cryptographic function property operation was attempted.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5070A cryptographic function property modification was attempted.Windows Vista, Windows Server 2008
SystemOther System Events5071Key access denied by Microsoft key distribution service.Windows 8, Windows Server 2012
Object AccessCertification Services5120OCSP Responder Service Started.Windows Vista, Windows Server 2008
Object AccessCertification Services5121OCSP Responder Service Stopped.Windows Vista, Windows Server 2008
Object AccessCertification Services5122A Configuration entry changed in the OCSP Responder Service.Windows Vista, Windows Server 2008
Object AccessCertification Services5123A configuration entry changed in the OCSP Responder Service.Windows Vista, Windows Server 2008
Object AccessCertification Services5124A security setting was updated on OCSP Responder Service.Windows Vista, Windows Server 2008
Object AccessCertification Services5125A request was submitted to OCSP Responder Service.Windows Vista, Windows Server 2008
Object AccessCertification Services5126Signing Certificate was automatically updated by the OCSP Responder Service.Windows Vista, Windows Server 2008
Object AccessCertification Services5127The OCSP Revocation Provider successfully updated the revocation information.Windows Vista, Windows Server 2008
DS AccessDirectory Service Changes5136A directory service object was modified.Windows Vista, Windows Server 2008
DS AccessDirectory Service Changes5137A directory service object was created.Windows Vista, Windows Server 2008
DS AccessDirectory Service Changes5138A directory service object was undeleted.Windows Vista, Windows Server 2008
DS AccessDirectory Service Changes5139A directory service object was moved.Windows Vista, Windows Server 2008
Object AccessFile Share5140A network share object was accessed.Windows Vista, Windows Server 2008
DS AccessDirectory Service Changes5141A directory service object was deleted.Windows Vista SP1, Windows Server 2008
Object AccessFile Share5142A network share object was added.Windows 7, Windows Server 2008 R2
Object AccessFile Share5143A network share object was modified.Windows 7, Windows Server 2008 R2
Object AccessFile Share5144A network share object was deleted.Windows 7, Windows Server 2008 R2
Object AccessDetailed File Share5145A network share object was checked to see whether the client can be granted desired access.Windows 7, Windows Server 2008 R2
Object AccessFiltering Platform Packet Drop 5146The Windows Filtering Platform has blocked a packet.Windows 8, Windows Server 2012
Object AccessFiltering Platform Packet Drop 5147A more restrictive Windows Filtering Platform filter has blocked a packet.Windows 8, Windows Server 2012
Object AccessOther Object Access Events5148The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.Windows 7, Windows Server 2008 R2
Object AccessOther Object Access Events5149The DoS attack has subsided and normal processing is being resumed.Windows 7, Windows Server 2008 R2
Object AccessFiltering Platform Connection5150The Windows Filtering Platform has blocked a packet.Windows 7, Windows Server 2008 R2
Object AccessFiltering Platform Connection5151A more restrictive Windows Filtering Platform filter has blocked a packet.Windows 7, Windows Server 2008 R2
Object AccessFiltering Platform Packet Drop 5152The Windows Filtering Platform blocked a packet.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Packet Drop 5153A more restrictive Windows Filtering Platform filter has blocked a packet.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5156The Windows Filtering Platform has allowed a connection.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5157The Windows Filtering Platform has blocked a connection.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5158The Windows Filtering Platform has permitted a bind to a local port.Windows Vista, Windows Server 2008
Object AccessFiltering Platform Connection5159The Windows Filtering Platform has blocked a bind to a local port.Windows Vista, Windows Server 2008
Object AccessFile Share5168Spn check for SMB/SMB2 failed.Windows 7, Windows Server 2008 R2
DS AccessDirectory Service Access5169A directory service object was modified. Windows 10
Account ManagementUser Account Management5376Credential Manager credentials were backed up.Windows Vista, Windows Server 2008
Account ManagementUser Account Management5377Credential Manager credentials were restored from a backup.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events5378The requested credentials delegation was disallowed by policy.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5440The following callout was present when the Windows Filtering Platform Base Filtering Engine started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5441The following filter was present when the Windows Filtering Platform Base Filtering Engine started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5442The following provider was present when the Windows Filtering Platform Base Filtering Engine started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5443The following provider context was present when the Windows Filtering Platform Base Filtering Engine started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5444The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5446A Windows Filtering Platform callout has been changed.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events5447A Windows Filtering Platform filter has been changed.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5448A Windows Filtering Platform provider has been changed.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5449A Windows Filtering Platform provider context has been changed.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5450A Windows Filtering Platform sub-layer has been changed.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Quick Mode5451An IPsec Quick Mode security association was established.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Quick Mode5452An IPsec Quick Mode security association ended.Windows Vista, Windows Server 2008
Logon/LogoffIPsec Main Mode5453An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5456PAStore Engine applied Active Directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5457PAStore Engine failed to apply Active Directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5458PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5459PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5460PAStore Engine applied local registry storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5461PAStore Engine failed to apply local registry storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5462PAStore Engine failed to apply some rules of the active IPsec policy on the computer. Use the IP Security Monitor snap-in to diagnose the problem.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5463PAStore Engine polled for changes to the active IPsec policy and detected no changes.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5464PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5465PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5466PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead. Any changes made to the Active Directory IPsec policy since the last poll could not be applied.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5467PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy. The cached copy of the Active Directory IPsec policy is no longer being used.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5468PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes. The cached copy of the Active Directory IPsec policy is no longer being used.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5471PAStore Engine loaded local storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5472PAStore Engine failed to load local storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5473PAStore Engine loaded directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5474PAStore Engine failed to load directory storage IPsec policy on the computer.Windows Vista, Windows Server 2008
Policy ChangeFiltering Platform Policy Change5477PAStore Engine failed to add quick mode filter.Windows Vista, Windows Server 2008
SystemIPsec Driver5478IPsec Services has started successfully.Windows Vista, Windows Server 2008
SystemIPsec Driver5479IPsec Services has been shut down successfully. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.Windows Vista, Windows Server 2008
SystemIPsec Driver5480IPsec Services failed to get the complete list of network interfaces on the computer. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.Windows Vista, Windows Server 2008
SystemIPsec Driver5483IPsec Services failed to initialize RPC server. IPsec Services could not be started.Windows Vista, Windows Server 2008
SystemIPsec Driver5484IPsec Services has experienced a critical failure and has been shut down. The shutdown of IPsec Services can put the computer at greater risk of network attack or expose the computer to potential security risks.Windows Vista, Windows Server 2008
SystemIPsec Driver5485IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces. This poses a potential security risk because some of the network interfaces may not get the protection provided by the applied IPsec filters. Use the IP Security Monitor snap-in to diagnose the problem.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events5632A request was made to authenticate to a wireless network.Windows Vista, Windows Server 2008
Logon/LogoffOther Logon/Logoff Events5633A request was made to authenticate to a wired network.Windows Vista, Windows Server 2008
Detailed TrackingRPC Events5712A Remote Procedure Call (RPC) was attempted.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events5888An object in the COM+ Catalog was modified.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events5889An object was deleted from the COM+ Catalog.Windows Vista, Windows Server 2008
Object AccessOther Object Access Events5890An object was added to the COM+ Catalog.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events6144Security policy in the group policy objects has been applied successfully.Windows Vista, Windows Server 2008
Policy ChangeOther Policy Change Events6145One or more errors occurred while processing security policy in the group policy objects.Windows Vista, Windows Server 2008
Logon/LogoffNetwork Policy Server6272Network Policy Server granted access to a user.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6273Network Policy Server denied access to a user.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6274Network Policy Server discarded the request for a user.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6275Network Policy Server discarded the accounting request for a user.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6276Network Policy Server quarantined a user.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6278Network Policy Server granted full access to a user because the host met the defined health policy.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6279Network Policy Server locked the user account due to repeated failed authentication attempts.Windows Vista SP1, Windows Server 2008
Logon/LogoffNetwork Policy Server6280Network Policy Server unlocked the user account.Windows Vista SP1, Windows Server 2008
SystemSystem Integrity6281Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device errorWindows 7, Windows Server 2008 R2
SystemOther System Events6400BranchCache: Received an incorrectly formatted response while discovering availability of content. Windows 7, Windows Server 2008 R2
SystemOther System Events6401BranchCache: Received invalid data from a peer. Data discarded. Windows 7, Windows Server 2008 R2
SystemOther System Events6402BranchCache: The message to the hosted cache offering it data is incorrectly formatted. Windows 7, Windows Server 2008 R2
SystemOther System Events6403BranchCache: The hosted cache sent an incorrectly formatted response to the client.Windows 7, Windows Server 2008 R2
SystemOther System Events6404BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate. Windows 7, Windows Server 2008 R2
SystemOther System Events6405BranchCache: %2 instance(s) of event id %1 occurred.Windows 7, Windows Server 2008 R2
SystemOther System Events6406%1 registered to Windows Firewall to control filtering for the following: %2Windows 7, Windows Server 2008 R2
SystemOther System Events64071%Windows 7, Windows Server 2008 R2
SystemOther System Events6408Registered product %1 failed and Windows Firewall is now controlling the filtering for %2Windows 7, Windows Server 2008 R2
SystemOther System Events6409BranchCache: A service connection point object could not be parsed.Windows 8.1, Windows Server 2012 R2
SystemSystem Integrity6410Code integrity determined that a file does not meet the security requirements to load into a process.Windows 8.1, Windows Server 2012 R2
SystemPlug and Play Events6416A new external device was recognized by the SystemWindows 10
SystemSystem Integrity6417The FIPS mode crypto selftests succeeded.Windows 10 [Version 1511]
SystemSystem Integrity6418The FIPS mode crypto selftests failed.Windows 10 [Version 1511]
SystemPlug and Play Events6419A request was made to disable a deviceWindows 10 [Version 1511]
SystemPlug and Play Events6420A device was disabled.Windows 10 [Version 1511]
SystemPlug and Play Events6421A request was made to enable a device.Windows 10 [Version 1511]
SystemPlug and Play Events6422A device was enabled.Windows 10 [Version 1511]
SystemPlug and Play Events6423The installation of this device is forbidden by system policyWindows 10 [Version 1511]
SystemPlug and Play Events6424The installation of this device was allowed, after having previously been forbidden by policy.Windows 10 [Version 1511]