PrintService Event ID 307: Document printed
- Event ID
- 307
- Channel
- Microsoft-Windows-PrintService/Operational
- Provider
- Microsoft-Windows-PrintService
- Log file
- Microsoft-Windows-PrintService%4Operational.evtx
- Category
- Devices and drivers
- Default logging
- Needs configuration
What event 307 means
Event 307 is written to Microsoft-Windows-PrintService/Operational by the print spooler of the machine that processed the job — the print server for shared printers, or the workstation itself for local ones. It records who printed (Param3), from which computer (Param4), on which printer and port, the size in bytes and the number of pages.
The document name (Param2) is recorded as the generic Print Document unless the Allow job name in event logs policy is enabled, so on many systems you will see the volume and timing of printing but not the file titles.
Printing is a classic insider exfiltration channel. 307 records are the Windows-native way to show that a user printed large jobs from a sensitive system, and when.
When it is logged
Enable the Microsoft-Windows-PrintService/Operational log (Event Viewer or wevtutil sl Microsoft-Windows-PrintService/Operational /e:true). Document names additionally require Computer Configuration > Administrative Templates > Printers > Allow job name in event logs.
Data is in UserData with positional parameters Param1 to Param8.
Key fields
| Field | What it tells you |
|---|---|
| Param1 | Job ID; links the job with other PrintService events for the same job. |
| Param2 | Document name, or Print Document if job names are not allowed in event logs. |
| Param3 | User who submitted the job. |
| Param4 | Client computer that sent the job (e.g. \\WS042). |
| Param5 | Printer name. |
| Param6 | Printer port. |
| Param7 | Size of the job in bytes. |
| Param8 | Number of pages printed. |
Common benign sources
- Everyday printing by users; print servers log thousands of 307 events per day.
- Printing to virtual printers such as Microsoft Print to PDF.
What attackers do that produces it
- Insider data theft by printing large volumes of documents, often outside working hours or before resignation.
- Printing to PDF or file ports to extract content from restricted systems.
Investigation tips
- Aggregate pages and bytes per user and per day; look for spikes and unusual hours.
- Check
Param4for jobs from servers or hosts the user does not normally use. - If document names are logged, search
Param2for sensitive project or client names.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.