Forum
16

What Windows event IDs are actually worth collecting?

asked by javiiw 19 days ago

Full auditing on a DC produces gigabytes a day. Which IDs earn their keep?

3 answers

Sign in to answer.
aklaha 20 points 19 days ago

4624, 4625, 4634 for logon activity
4720 / 4726 / 4738 account lifecycle
4728 / 4732 / 4756 group membership
4740 lockouts
4672 special privileges, your admin logon signal
1102 log cleared, this one should page somebody
4688 process creation if you can afford it, and turn on command line auditing or it is half useless

4688 is the expensive one and the most useful. Servers first, see what it costs, then decide about workstations.

shadepl 10 points 18 days ago

4662 if you care about AD object access, but be warned it is a firehose and mostly unreadable

gerald (Gerald) 6 points 17 days ago

Add 4776 if you still have anything doing NTLM. Often the only place a failed authentication against a local account shows up.

Guidelines Newest Search Back to Trunc