Just wanted to put this out there to the universe... Has anyone set up a custom search/alert to track when the Windows event log service is started/stopped? Windows Server 2008/2008R2/2012
With WIN2003, I could search for event IDs 6005 & 6006, but not sure for the new platforms.
6005 & 6006 - Applies to 2012,R2, 2016,2019.
Event Code 4608 is for Windows starting up
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4608
Event Code 4609 is Windows is shutting down
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=4608
Hmm... close but not quite. Need to monitor Windows event log service for start/stop, not necessarily when the system is shutdown.
Event Log is shutdown is 1100
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventID=1100
There doesn't appear to be a corresponding event for it starting up again (I suppose you would just get events to indicate it has restarted)
Thanks for the update, sduff_splunk! Yea, idk why MS doesn't have a corresponding eventID for startup!