4624
An account was successfully logged on
- Log: Security
- Source: Microsoft-Windows-Security-Auditing
- Logons
- Info
What it means
A user, computer or service signed in. The Logon Type field tells you how: 2 interactive (at the keyboard), 3 network (file shares), 4 batch, 5 service, 7 unlock, 10 Remote Desktop, 11 cached credentials.
Why it matters
The baseline for "who accessed what, when". Type 10 logons from unexpected sources and logons outside business hours are worth alerting on.
What to do
- Filter by Logon Type to separate people from services.
- Check Source Network Address on type 3 and 10 logons.
- Alert on admin accounts logging on to workstations.
Find it with PowerShell
Get-WinEvent -MaxEvents 20 -FilterHashtable @{
LogName = 'Security'; Id = 4624
} | Select-Object TimeCreated, ProviderName, MessageAdd -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.
Source
Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.
Talk to us