Windows Security Log Event ID 5382

Operating Systems Windows Server 2019 and 2022
 • Subcategory
 • Other System Events
Type Success
Corresponding events
in Windows 2003
and before
Discussions on Event ID 5382

5382: Vault credentials were read

On this page

This event is new in Server 2019.  It is very similar to 5381. This event occurs when a user reads a stored vault credential.

Free Security Log Resources by Randy

Description Fields in 5382


The user and logon session that performed the action.

  • Security ID:  The SID of the account.
  • Account Name: The account logon name.
  • Account Domain: The domain or - in the case of local accounts - computer name.
  • Logon ID is a semi-unique (unique between reboots) number that identifies the logon session.  Logon ID allows you to correlate backwards to the logon event (4624) as well as with other events logged during the same logon session.

Supercharger Free Edition

Your entire Windows Event Collection environment on a single pane of glass.



Examples of 5382


Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
This event occurs when a user reads a stored vault credential.

Top 10 Windows Security Events to Monitor

Free Tool for Windows Event Collection


Additional Resources