Skip to content
Security

Event ID 1100: Event logging service shut down

The event logging service has shut downSecurity event 1100 marks the Windows Event Log service stopping, normally at shutdown. Outside a reboot it can mean logging was stopped on purpose.
1100
Event ID
1100
Channel
Security
Provider
Microsoft-Windows-Eventlog
Log file
Security.evtx
Category
Log integrity
Default logging
Logged by default

What event 1100 means

Event 1100 is written into the Security log by the Windows Event Log service itself (provider Microsoft-Windows-Eventlog, not the auditing subsystem) when the service shuts down. In practice almost every instance is an orderly system shutdown or restart, and the record is the last thing the Security log says before the machine goes down.

That makes it a useful timeline marker: a 1100 followed by 4608 (Windows is starting up) brackets a clean reboot. A startup without a preceding 1100 points to a crash, power loss or hard reset — confirm with System events 6008 and 41. The event has no payload beyond the UserData/ServiceShutdown element, so the who and why must come from surrounding events.

The interesting case is a 1100 that is not followed by a reboot: someone stopped the Event Log service, and the Security log goes silent until it restarts. Note the opposite trap too — tools that suspend the service's threads or patch it in memory stop logging without ever producing a 1100.

When it is logged

Audit policy / configuration

Always logged by the Windows Event Log service; no audit policy is involved and it cannot be turned off through Advanced Audit Policy.

Not written on an emergency reset, crash or power loss. Microsoft files it under the "Other Events" group of the Security log.

Key fields

FieldWhat it tells you
ServiceShutdownEmpty UserData element that identifies the record. The event carries no account or process information — use the surrounding records for context.

Common benign sources

  • Planned restarts and shutdowns, including reboots triggered by Windows Update or software installers.
  • Host shutdowns of virtual machines by the hypervisor or orchestration tooling.

What attackers do that produces it

  • Stopping the Event Log service (for example net stop eventlog or sc stop eventlog from an elevated shell) to blind the Security log before further actions.
  • A 1100 shortly before a 1102 or a long gap in the log, as part of an anti-forensics sequence.

Investigation tips

  • Check what follows: a 4608 and System 6005/12 within a minute or two mean a normal reboot; a 1100 with the machine still running (later records, no boot) means the service was stopped.
  • Look at System events 1074 and 13 around the same time to identify who or what initiated a shutdown.
  • Measure the gap until the next Security record. Missing hours on a server that normally logs every minute deserve an explanation.
  • Search 4688 or Sysmon 1 just before the 1100 for net, sc, taskkill or PowerShell commands touching the service.

MITRE ATT&CK techniques

TechniqueTactics
T1685.001 Disable or Modify Tools: Disable or Modify Windows Event LogDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading