Skip to content
Application

Application Event ID 18456: SQL Server login failed

Login failed for userApplication event 18456 from SQL Server logs a failed database login with user, reason and client IP. Brute force against MSSQL.
18456
Event ID
18456
Channel
Application
Provider
MSSQLSERVER
Log file
Application.evtx
Category
Logon
Default logging
Logged by default

What event 18456 means

Event 18456 is written to the Windows Application log by the SQL Server Database Engine when a login attempt fails. The source is MSSQLSERVER for the default instance and MSSQL$<InstanceName> for named instances. The message includes the login name, a reason and the client address in the form [CLIENT: 10.0.0.5].

The reason text explains the failure — for example "Password did not match that for the login provided" (wrong password for an existing SQL login) or "Could not find a login matching the name provided" (unknown login). The SQL Server error log records the same failure with a numeric state (8 = wrong password, 2 and 5 = invalid user ID, 7 = login disabled with a wrong password, 18 = password must be changed, 38 = requested database not found, 58 = SQL authentication attempted on a Windows-only server).

Internet-exposed SQL Servers receive constant sa brute force. Inside a network, bursts of 18456 from one client against many logins, or against sa, point to password spraying or lateral movement attempts.

When it is logged

Audit policy / configuration

SQL Server "Login auditing" set to "Failed logins only" (the default) or "Both failed and successful logins".

The data is a set of unnamed insertion strings; this viewer shows them joined in Data1. The state number is not in the message text; read it from the SQL Server error log.

Key fields

FieldWhat it tells you
Data1Insertion strings — the login name, then the reason text with the client address ([CLIENT: <ip>]).

Common benign sources

  • Applications with outdated connection strings or expired passwords retrying in a loop.
  • Users mistyping passwords in SQL Server Management Studio.
  • Monitoring tools probing with default or disabled accounts.

What attackers do that produces it

  • Brute force of sa and other SQL logins from the internet or from a compromised host, often hundreds of attempts per minute.
  • Password spraying with a few passwords across many logins.
  • A success after many failures, followed by xp_cmdshell use for code execution.

Investigation tips

  • Group by login name and client IP; count attempts per minute to separate brute force from misconfiguration.
  • Check whether the client IP is internal, and if so investigate that host.
  • Look for a successful login from the same source (SQL audit, 18453/18454 when success auditing is on) and for xp_cmdshell child processes of sqlservr.exe (4688, Sysmon 1).

MITRE ATT&CK techniques

TechniqueTactics
T1110 Brute ForceCredential Access
T1110.001 Brute Force: Password GuessingCredential Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading