Found 4 results for 'Microsoft-Windows-Security-Auditing'

4634

Microsoft-Windows-Security-Auditing

Logoff

An account was logged off.

Subject:
Security ID: TESTGROUND\cacheduser
Account Name: cacheduser
Account Domain: TESTGROUND
Logon ID: 0xbed3f1

Logon Type: 2

This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.


More information


4647

Microsoft-Windows-Security-Auditing

Logoff

User initiated logoff:

Subject:
Security ID: TESTGROUND\cacheduser
Account Name: cacheduser
Account Domain: TESTGROUND
Logon ID: 0xbed3f1

This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event.


More information


5032

Microsoft-Windows-Security-Auditing

Other System Events

Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network.

Error Code: 2


More information


6281

Microsoft-Windows-Security-Auditing

System Integrity

Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error.

File Name: \Device\HarddiskVolume2\Windows\System32\l3codeca.acm


More information