Windows Serializer
Purpose
Usage
Examples
Serialize Windows Security Log (JSON Format)
Feb 26 12:50:00 WIN-SERVER1 Security 4624 An account was successfully logged on. Subject: Security ID: S-1-5-18 Account Name: SYSTEM Logon ID: 0x3E7. New Logon: Security ID: S-1-5-21-123456789-123456789-123456789-1001 Account Name: user1 Logon Type: 2 Source Network Address: 192.168.1.100
Feb 26 12:51:10 WIN-SERVER1 Security 4625 An account failed to log on. Account Name: user2 Logon Type: 3 Failure Reason: Unknown user name or bad password Source Network Address: 192.168.1.101
Feb 26 12:52:20 WIN-SERVER1 Security 4670 Object access attempted. Object Name: C:\SensitiveFile.txt Accesses: WRITE_OWNER, WRITE_DAC Account Name: admin1
Feb 26 12:53:30 WIN-SERVER1 Security 4688 A new process has been created. New Process Name: C:\Windows\System32\cmd.exe Creator Process Name: C:\Windows\explorer.exe Account Name: user3
Feb 26 12:54:40 WIN-SERVER1 Security 4720 A user account was created. Account Name: new_user Account Enabled: Yes Creator: admin2Windows Serialization Best Practices
Related Functions
Last updated
Was this helpful?

