Event ID: 1100The event logging service has shut down
The event logging service has shut down
This event generates every time Windows Event Log service has shut down.
It also generates during normal system shutdown. This event doesn’t generate during emergency system reset. If the event was generated due to a normal system shutdown it will be preceded by event ID 1074 in the System log.
This event can be a sign of malicious action if someone shut down the Windows Event Log service to cover their activity.
PCI 3.2.1: 10.2.6
Lookup Audit Policy Configuration Settings
C:\> AuditPol.exe /get /subcategory:"Other System Events"
LEFT/RIGHT arrow keys for navigationBack to List