List of Event IDs

mv 0 Reputation points
2026-07-27T17:47:54.1233333+00:00

Hello Team.

Security — standard Windows Security event log - can you please confirm this Event ID

System — captures Event ID 7045 (new service installed) - Can you please confirm this Event ID?

Task Scheduler/Operational — captures scheduled task creation/modification events, can you please confirm these event ids?

....

As far excluding event ids, can you also please confirm the below event ids.

The following are excluded to avoid unnecessary volume inflation: Please confirm Event IDs.

• Object Access – File System / Registry (global): Extremely high volume, low signal unless scoped to specific sensitive paths, what would be the event id?

• Filtering Platform Connection: Every network connection per process — very noisy; what these event ids, would be?

Network visibility is better addressed via Palo Alto and Meraki logs already ingested

• Audit Process Termination: No meaningful detection benefit beyond Process Creation, what these event ids would be?

• Detailed File Share: High noise; only appropriate for targeted investigations , what these event ids would be?

Microsoft Security | Intune | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-07-27T17:48:15.0933333+00:00

    Supported event IDs from the available context are:

    • Security log / standard Windows Security events
      • 4688 — A new process has been created.
      • 4689 — A process has exited.
      • 4657 — A registry value was modified.
      • 4663 — An attempt was made to access an object.
      • 4670 — Permissions on an object were changed.
      • 4697 — Attempt to install a service.
      • 4698 — A scheduled task was created.
      • 4699 — A scheduled task was deleted.
      • 4700 — A scheduled task was enabled.
      • 4701 — A scheduled task was disabled.
      • 4702 — A scheduled task was updated.
      • 5140 — A network share object was accessed.
      • 5156 — The Windows Filtering Platform has allowed a connection.
      • 5157 — The Windows Filtering Platform has blocked a connection.
      • 5158 — The Windows Filtering Platform has permitted a bind to a local port.
    • System log / new service installed
      • The available context does not confirm System event ID 7045.
      • The context does confirm Security event ID 4697 as Attempt to install a service.
    • Task Scheduler/Operational — scheduled task creation/modification
      • 4698 — A scheduled task was created.
      • 4702 — A scheduled task was updated.
      • Related task events also present in the context:
        • 4699 — deleted
        • 4700 — enabled
        • 4701 — disabled
    • Excluded high-volume categories
      • Object Access – File System / Registry
        • 4657 — A registry value was modified.
        • 4663 — An attempt was made to access an object.
      • Filtering Platform Connection
        • 5156 — allowed a connection.
        • 5157 — blocked a connection.
        • 5158 — permitted a bind to a local port.
        • Related filtering platform events in the context:
          • 5152 — blocked a packet
          • 5153 — more restrictive filter blocked a packet
          • 5154 — permitted an application or service to listen on a port
          • 5155 — blocked an application or service from listening on a port
      • Audit Process Termination
        • 4689 — A process has exited.
      • Detailed File Share
        • 5140 — A network share object was accessed.

    The available context does not provide confirmation for any additional event IDs beyond the list above.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.