Skip to main content

 none
can anyone explain what this "special logon" is in my windows event viewer RRS feed

  • Question

  • - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
      <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
      <EventID>4672</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>12548</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8020000000000000</Keywords>
      <TimeCreated SystemTime="2018-04-02T11:09:39.131024900Z" />
      <EventRecordID>267097</EventRecordID>
      <Correlation ActivityID="{64E15077-CA6D-0003-C050-E1646DCAD301}" />
      <Execution ProcessID="804" ThreadID="992" />
      <Channel>Security</Channel>
      <Computer>Trooper-10</Computer>
      <Security />
      </System>
    - <EventData>
      <Data Name="SubjectUserSid">S-1-5-18</Data>
      <Data Name="SubjectUserName">SYSTEM</Data>
      <Data Name="SubjectDomainName">NT AUTHORITY</Data>
      <Data Name="SubjectLogonId">0x3e7</Data>
      <Data Name="PrivilegeList">SeAssignPrimaryTokenPrivilege SeTcbPrivilege SeSecurityPrivilege SeTakeOwnershipPrivilege SeLoadDriverPrivilege SeBackupPrivilege SeRestorePrivilege SeDebugPrivilege SeAuditPrivilege SeSystemEnvironmentPrivilege SeImpersonatePrivilege SeDelegateSessionUserImpersonatePrivilege</Data>
      </EventData>
      </Event>
    Tuesday, April 3, 2018 1:45 PM