RDP Event ID 21: Session logon succeeded
- Event ID
- 21
- Channel
- Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
- Provider
- Microsoft-Windows-TerminalServices-LocalSessionManager
- Log file
- Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 21 means
Event 21 is written by the Local Session Manager when a user session is created and the logon completes — for Remote Desktop and for local console logons alike. The Address field separates them: an IP address for RDP, LOCAL for the console.
Where 1149 only shows that an RDP connection got through, 21 shows that a desktop session was actually created for the user. It is typically followed by 22 (shell start) and, when the session ends, by 23 (logoff) or 24 (disconnect). A reconnection to an existing session is logged as 25 instead.
When it is logged
None — the Microsoft-Windows-TerminalServices-LocalSessionManager/Operational channel is enabled by default.
Fields sit under UserData/EventXML (User, SessionID, Address).
Key fields
| Field | What it tells you |
|---|---|
| User | Account that logged on, in DOMAIN\user form. |
| SessionID | Terminal Services session number; ties together 21, 22, 23, 24 and 25 for the same session. |
| Address | Source IP address of the RDP client, or LOCAL for console logons. |
Common benign sources
- Interactive console logons and routine RDP logons by administrators and users.
- Jump-host and VDI environments with many RDP sessions per day.
What attackers do that produces it
- Hands-on-keyboard access over RDP with stolen credentials, from external IPs or internal hosts that do not normally RDP.
- Tunneled RDP, where Address shows
127.0.0.1or::1.
Investigation tips
- Pair with Security 4624 LogonType 10 at the same second to get the logon ID and authentication details.
- Group sessions by SessionID to measure duration (21 → 23/24).
- Compare Address with the 1149 entries just before; they should match.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- HighNgrok Usage with Remote Desktop ServiceRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.