Windows Security Log Events
All Sources
Windows Audit
SharePoint Audit
(
LOGbinder for SharePoint
)
SQL Server Audit
(
LOGbinder for SQL Server
)
Exchange Audit
(
LOGbinder for Exchange
)
Sysmon
(
MS Sysinternals Sysmon
)
Windows Audit Categories:
All categories
Account Logon
Account Management
Directory Service
Logon/Logoff
Non Audit (Event Log)
Object Access
Policy Change
Privilege Use
Process Tracking
System
Uncategorized
Subcategories:
All subcategories
IPsec Driver
Other System Events
Security State Change
Security System Extension
System Integrity
Windows Versions:
All events
Win2000, XP and Win2003 only
Win2008, Win2012R2, Win2016 and Win10+, Win2019
Required when sub-category selected.
Category:
System
Subcategory:
IPsec Driver
Windows
5478
IPsec Services has started successfully
Windows
5479
IPsec Services has been shut down successfully
Windows
5480
IPsec Services failed to get the complete list of network interfaces on the computer
Windows
5483
IPsec Services failed to initialize RPC server. IPsec Services could not be started
Windows
5484
IPsec Services has experienced a critical failure and has been shut down
Windows
5485
IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
Stay up-to-date on the Latest in Cybersecurity
Sign up for the Ultimate IT Security newsletter to hear about the latest webinars, patches, CVEs, attacks, and more.
Work Email:
Upcoming Webinars
Identifying the Tier 0 Assets in Your Active Directory Environment is Step #1 in ITDR
Additional Resources
Encyclopedia
•
Event IDs
•
All Event IDs
•
Audit Policy
Go To Event ID:
Security Log
Quick Reference
Chart
Download now!
Tweet
User name:
Password:
/
Forgot?
Register
January 2025
Patch Tuesday
"Patch Tuesday - 8 Zero Days and 14 Critical " - sponsored by Supercharger
Home
Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.