Event ID: 1100

The event logging service has shut down

The event logging service has shut down

This event generates every time Windows Event Log service has shut down.

It also generates during normal system shutdown. This event doesn’t generate during emergency system reset. If the event was generated due to a normal system shutdown it will be preceded by event ID 1074 in the System log.

This event can be a sign of malicious action if someone shut down the Windows Event Log service to cover their activity.

Auditing:     Always

Volume:     Low

PCI 3.2.1: 10.2.6

Microsoft Documentation

Event ID - 1100

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Other System Events"

LEFT/RIGHT arrow keys for navigation

Back to List