Skip to content
PrintService

PrintService Event ID 307: Document printed

Document owned by user on computer was printed on printer through portPrintService event 307 logs each printed job: document, user, client, printer, size and pages. Off by default; key for insider print exfiltration.
307
Event ID
307
Channel
Microsoft-Windows-PrintService/Operational
Provider
Microsoft-Windows-PrintService
Log file
Microsoft-Windows-PrintService%4Operational.evtx
Category
Devices and drivers
Default logging
Needs configuration

What event 307 means

Event 307 is written to Microsoft-Windows-PrintService/Operational by the print spooler of the machine that processed the job — the print server for shared printers, or the workstation itself for local ones. It records who printed (Param3), from which computer (Param4), on which printer and port, the size in bytes and the number of pages.

The document name (Param2) is recorded as the generic Print Document unless the Allow job name in event logs policy is enabled, so on many systems you will see the volume and timing of printing but not the file titles.

Printing is a classic insider exfiltration channel. 307 records are the Windows-native way to show that a user printed large jobs from a sensitive system, and when.

When it is logged

Audit policy / configuration

Enable the Microsoft-Windows-PrintService/Operational log (Event Viewer or wevtutil sl Microsoft-Windows-PrintService/Operational /e:true). Document names additionally require Computer Configuration > Administrative Templates > Printers > Allow job name in event logs.

Data is in UserData with positional parameters Param1 to Param8.

Key fields

FieldWhat it tells you
Param1Job ID; links the job with other PrintService events for the same job.
Param2Document name, or Print Document if job names are not allowed in event logs.
Param3User who submitted the job.
Param4Client computer that sent the job (e.g. \\WS042).
Param5Printer name.
Param6Printer port.
Param7Size of the job in bytes.
Param8Number of pages printed.

Common benign sources

  • Everyday printing by users; print servers log thousands of 307 events per day.
  • Printing to virtual printers such as Microsoft Print to PDF.

What attackers do that produces it

  • Insider data theft by printing large volumes of documents, often outside working hours or before resignation.
  • Printing to PDF or file ports to extract content from restricted systems.

Investigation tips

  • Aggregate pages and bytes per user and per day; look for spikes and unusual hours.
  • Check Param4 for jobs from servers or hosts the user does not normally use.
  • If document names are logged, search Param2 for sensitive project or client names.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading