Event Id | 4624 |
Source | Microsoft-Windows-Security-Auditing |
Description | An account was successfully logged on. Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain Name> Logon ID:<Logon ID> Logon Type:<Logon Type> New Logon: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain Name> Logon ID:<Logon ID> Logon GUID:<Logon GUID> Process Information: Process ID: <Process ID> Process Name:<Process Name> Network Information: Workstation Name:<Workstation Name> Source Network Address:<Source Network Address> Source Port:<Source Port> Detailed Authentication Information: Logon Process:<Logon Process> Authentication Package:<Authentication Package> Transited Services:<Transited Services> Package Name (NTLM only):<Package Name (NTLM only)> Key Length:<Key Length> |
Event Information | Cause : This event is generated when a logon session is created. It is generated on the computer that was accessed. Resolution : No user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.