1102
The audit log was cleared
- Log: Security
- Source: Microsoft-Windows-Eventlog
- Tampering & persistence
- Critical
What it means
Someone cleared the Security log.
Why it matters
Almost never done legitimately. Attackers clear logs to hide what they did.
What to do
- Find who cleared it (Subject) and from where.
- Pull copies of logs from your SIEM or log collector.
- Treat it as a possible incident.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 1102
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us