Forum
16

What Windows event IDs are actually worth collecting?

asked by javiiw 1 month ago

Full auditing on a DC produces gigabytes a day. Which IDs earn their keep?

3 answers

Sign in to answer.
aklaha 20 points 1 month ago

4624, 4625, 4634 for logon activity
4720 / 4726 / 4738 account lifecycle
4728 / 4732 / 4756 group membership
4740 lockouts
4672 special privileges, your admin logon signal
1102 log cleared, this one should page somebody
4688 process creation if you can afford it, and turn on command line auditing or it is half useless

4688 is the expensive one and the most useful. Servers first, see what it costs, then decide about workstations.

shadepl 10 points 1 month ago

4662 if you care about AD object access, but be warned it is a firehose and mostly unreadable

gerald (Gerald) 6 points 1 month ago

Add 4776 if you still have anything doing NTLM. Often the only place a failed authentication against a local account shows up.

Guidelines Newest Search Back to Trunc