← Event ID reference
1102

The audit log was cleared

  • Log: Security
  • Source: Microsoft-Windows-Eventlog
  • Tampering & persistence
  • Critical

What it means

Someone cleared the Security log.

Why it matters

Almost never done legitimately. Attackers clear logs to hide what they did.

What to do

  • Find who cleared it (Subject) and from where.
  • Pull copies of logs from your SIEM or log collector.
  • Treat it as a possible incident.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 1102
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us