Anavem
Languagefr

Windows Events — Event ID Reference & Troubleshooting

Complete Windows Event ID reference. Understand every system event, its causes and solutions.

Our Windows Events reference centralizes documentation on Windows Event IDs. Each article explains a specific system event: what it means, its possible causes, and recommended troubleshooting steps.

389 events
Windows Event ID 24582 – Unknown: Application or Service Initialization Failure
24582ErrorUnknown

Windows Event ID 24582 – Unknown: Application or Service Initialization Failure

Event ID 24582 indicates a critical initialization failure in an application or service component during system startup or service launch, requiring immediate investigation to identify the failing component.

Mar 18, 20266012m
Windows Event ID 24580 – Application Error: Critical Application Failure
24580ErrorApplication Error

Windows Event ID 24580 – Application Error: Critical Application Failure

Event ID 24580 indicates a critical application failure or unexpected termination. This error typically occurs when applications crash due to memory violations, corrupted files, or system resource exhaustion.

Mar 18, 20265512m
Windows Event ID 24579 – Unknown: System Component Registration or Service Initialization Event
24579InformationUnknown

Windows Event ID 24579 – Unknown: System Component Registration or Service Initialization Event

Event ID 24579 typically indicates a system component registration, service initialization, or driver loading event. This informational event appears during system startup or when specific Windows services are starting.

Mar 18, 2026549m
Windows Event ID 24577 – Kernel-EventTracing: ETW Session Configuration Error
24577ErrorKernel-EventTracing

Windows Event ID 24577 – Kernel-EventTracing: ETW Session Configuration Error

Event ID 24577 indicates an Event Tracing for Windows (ETW) session configuration error, typically occurring when ETW providers fail to start or when session parameters are invalid during system boot or service initialization.

Mar 18, 2026629m
Windows Event ID 11708 – Microsoft-Windows-Kernel-General: System Time Change Detected
11708InformationMicrosoft-Windows-Kernel-General

Windows Event ID 11708 – Microsoft-Windows-Kernel-General: System Time Change Detected

Event ID 11708 indicates the system time was changed, either manually by a user or automatically by time synchronization services. Critical for security auditing and troubleshooting time-related issues.

Mar 18, 2026649m
Windows Event ID 7011 – Service Control Manager: Service Timeout Error
7011ErrorService Control Manager

Windows Event ID 7011 – Service Control Manager: Service Timeout Error

Event ID 7011 indicates a Windows service failed to respond within the configured timeout period during startup, shutdown, or control operations, requiring investigation of service dependencies and system performance.

Mar 18, 2026629m
Windows Event ID 7001 – Service Control Manager: Service Dependency Failure
7001ErrorService Control Manager

Windows Event ID 7001 – Service Control Manager: Service Dependency Failure

Event ID 7001 indicates a Windows service failed to start because one or more of its dependent services are not running or failed to initialize properly.

Mar 18, 20266512m
Windows Event ID 6280 – Microsoft-Windows-Kernel-Process: Process Creation Notification
6280InformationMicrosoft-Windows-Kernel-Process

Windows Event ID 6280 – Microsoft-Windows-Kernel-Process: Process Creation Notification

Event ID 6280 records process creation events in the Microsoft-Windows-Kernel-Process ETW provider, capturing detailed process startup information for security monitoring and system analysis.

Mar 18, 2026619m
Windows Event ID 6279 – WinLogon: User Logon Session Destroyed
6279InformationWinLogon

Windows Event ID 6279 – WinLogon: User Logon Session Destroyed

Event ID 6279 indicates that a user logon session has been destroyed in Windows. This informational event fires when a user logs off, disconnects from a remote session, or when the system terminates a session due to timeout or policy enforcement.

Mar 18, 20266012m
Windows Event ID 6276 – Microsoft-Windows-Security-Auditing: Special Privileges Assigned to New Logon
6276InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 6276 – Microsoft-Windows-Security-Auditing: Special Privileges Assigned to New Logon

Event ID 6276 records when special privileges are assigned to a user account during logon, indicating elevated access rights have been granted for the session.

Mar 18, 2026589m
Windows Event ID 6274 – Microsoft-Windows-Security-Auditing: Special Privileges Assigned to New Logon
6274InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 6274 – Microsoft-Windows-Security-Auditing: Special Privileges Assigned to New Logon

Event ID 6274 records when special privileges are assigned to a new user logon session, indicating elevated access rights have been granted for security-sensitive operations.

Mar 18, 2026569m
Windows Event ID 6273 – Microsoft-Windows-Security-Auditing: Network Policy Server Granted Access
6273InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 6273 – Microsoft-Windows-Security-Auditing: Network Policy Server Granted Access

Event ID 6273 indicates that Network Policy Server (NPS) has granted network access to a user or device after successful authentication and authorization through RADIUS protocols.

Mar 18, 2026729m
Windows Event ID 6272 – Microsoft-Windows-Security-Auditing: Network Policy Server Granted Access
6272InformationMicrosoft-Windows-Security-Auditing

Windows Event ID 6272 – Microsoft-Windows-Security-Auditing: Network Policy Server Granted Access

Event ID 6272 indicates that Network Policy Server (NPS) has granted network access to a user or device after successful authentication and authorization through RADIUS protocols.

Mar 18, 20266312m
Windows Event ID 6145 – WinLogon: User Logon Session Destroyed
6145InformationWinLogon

Windows Event ID 6145 – WinLogon: User Logon Session Destroyed

Event ID 6145 indicates a user logon session has been destroyed by the Windows Logon service, typically occurring during normal logoff, system shutdown, or forced session termination.

Mar 18, 2026529m
Windows Event ID 6144 – Kernel-General: System Performance Counter Collection Started
6144InformationKernel-General

Windows Event ID 6144 – Kernel-General: System Performance Counter Collection Started

Event ID 6144 indicates that Windows has started collecting system performance counters. This informational event fires during system startup or when performance monitoring services initialize.

Mar 18, 2026659m
Windows Event ID 6013 – EventLog: System Uptime Information
6013InformationEventLog

Windows Event ID 6013 – EventLog: System Uptime Information

Event ID 6013 records system uptime information in the System log, indicating how long Windows has been running since the last boot or restart.

Mar 18, 2026828m
Windows Event ID 6009 – EventLog: Microsoft Windows Kernel Boot Information
6009InformationEventLog

Windows Event ID 6009 – EventLog: Microsoft Windows Kernel Boot Information

Event ID 6009 records Windows kernel boot information including processor details, memory configuration, and system architecture during system startup.

Mar 18, 2026618m
Windows Event ID 5889 – Microsoft-Windows-Kernel-General: System Time Change Detected
5889InformationMicrosoft-Windows-Kernel-General

Windows Event ID 5889 – Microsoft-Windows-Kernel-General: System Time Change Detected

Event ID 5889 indicates the system time was changed, either manually by a user or automatically by time synchronization services. This event helps track time modifications for security and audit purposes.

Mar 18, 20265712m