Splunk Enterprise Security

How to set up a custom search/alert to track when Windows event log service start/stop for Windows Server 2008+?

metalgear138
Engager

Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012

With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.

0 Karma

Bselberg
Explorer

6005 & 6006 - Applies to 2012,R2, 2016,2019.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee
0 Karma

metalgear138
Engager

Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.

0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100

There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)

0 Karma

metalgear138
Engager

Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...