Skip to content
Logmanager
Windows Event ID lookup

Windows Event ID Lookup Tool

Search Windows Security, System, Application, Active Directory, DNS/DHCP Server, Sysmon and PowerShell event IDs by number or keyword. Get a plain-language explanation, why it matters for monitoring, and what typically causes it.

Windows logs thousands of distinct event IDs across its many components — this isn’t a complete catalog. It’s a curated reference of the IDs most frequently searched for and relied on in security and IT monitoring.

Descriptions, severity guidance, and common causes on this page are original summaries written for quick triage, not reproductions of Microsoft’s official event documentation. They cover commonly encountered IDs across Windows Server and Windows 10/11 Security, System, and Application logs, Active Directory trust/AD DS events, DNS and DHCP Server audit logging, Sysmon, and PowerShell logging — not every event ID Windows or these components can ever emit. DHCP Server entries reference the DHCP audit-log codes written to its own CSV log file, not standard Event Viewer IDs. Exact IDs, fields, and behavior can vary by OS version, audit policy, and provider version. For authoritative field-level detail, refer to Microsoft’s own Windows Security documentation.