Application Event ID 18456: SQL Server login failed
- Event ID
- 18456
- Channel
- Application
- Provider
- MSSQLSERVER
- Log file
- Application.evtx
- Category
- Logon
- Default logging
- Logged by default
What event 18456 means
Event 18456 is written to the Windows Application log by the SQL Server Database Engine when a login attempt fails. The source is MSSQLSERVER for the default instance and MSSQL$<InstanceName> for named instances. The message includes the login name, a reason and the client address in the form [CLIENT: 10.0.0.5].
The reason text explains the failure — for example "Password did not match that for the login provided" (wrong password for an existing SQL login) or "Could not find a login matching the name provided" (unknown login). The SQL Server error log records the same failure with a numeric state (8 = wrong password, 2 and 5 = invalid user ID, 7 = login disabled with a wrong password, 18 = password must be changed, 38 = requested database not found, 58 = SQL authentication attempted on a Windows-only server).
Internet-exposed SQL Servers receive constant sa brute force. Inside a network, bursts of 18456 from one client against many logins, or against sa, point to password spraying or lateral movement attempts.
When it is logged
SQL Server "Login auditing" set to "Failed logins only" (the default) or "Both failed and successful logins".
The data is a set of unnamed insertion strings; this viewer shows them joined in Data1. The state number is not in the message text; read it from the SQL Server error log.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Insertion strings — the login name, then the reason text with the client address ([CLIENT: <ip>]). |
Common benign sources
- Applications with outdated connection strings or expired passwords retrying in a loop.
- Users mistyping passwords in SQL Server Management Studio.
- Monitoring tools probing with default or disabled accounts.
What attackers do that produces it
- Brute force of
saand other SQL logins from the internet or from a compromised host, often hundreds of attempts per minute. - Password spraying with a few passwords across many logins.
- A success after many failures, followed by
xp_cmdshelluse for code execution.
Investigation tips
- Group by login name and client IP; count attempts per minute to separate brute force from misconfiguration.
- Check whether the client IP is internal, and if so investigate that host.
- Look for a successful login from the same source (SQL audit, 18453/18454 when success auditing is on) and for
xp_cmdshellchild processes ofsqlservr.exe(4688, Sysmon 1).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- Low · 1
- MediumMSSQL Server Failed Logon From External NetworkRule by j4son, SigmaHQ, DRL 1.1
- LowMSSQL Server Failed LogonRule by Nasreddine Bencherchali (Nextron Systems), j4son, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.