Home
Resources
Training
About Us
eStore

>

resources > security log resource center > encyclopedia > event 593

 

 

 

 

 

 

 

Latest Blog: Log monitoring and the Terry Childs/City of San Francisco debacle

 

Windows Security Log Events by ID

look up more events by Event ID or Category

Event ID

593

Title

A process has exited

Type: Example: Randy's Comments:
Success

OS:

All versions

Category:

Detailed Tracking

A process has exited:
Process ID:2084

Windows Server 2003 inserts the following field:
Image File Name:C:\WINDOWS\system32\notepad.exe

All versions log the following fields:
User Name:administrator
Domain:ELM
Logon ID:(0x0,0x158EB7)

The program identified in Image File Name was closed or terminated. To find out when the program started, look for the preceding 592 with the same Process ID.

In Windows 2000 there is no image file Name field. So to determine the name of the program you must find the preceding event 592.

To identify the program on Windows Server 2003 you can simply use the image name which is supplied in this event.

Next:

Get all the tools you need in one newsletter!
Free log parser scripts, clear explanations of Microsoft's latest security bulletins, and more. View a sample issue.
Email Address:
Your email address will not be shared. You may unsubscribe at any time.


Upcoming Webinars by Randy Franklin Smith


Additional Links

A
D
V