Event ID 1104: Security log full
- Event ID
- 1104
- Channel
- Security
- Provider
- Microsoft-Windows-Eventlog
- Log file
- Security.evtx
- Category
- Log integrity
- Default logging
- Logged by default
What event 1104 means
Event 1104 is written by the Windows Event Log service when the Security log hits its configured maximum size while the retention method is Do not overwrite events (Clear logs manually). From that point new audit records cannot be stored until someone archives or clears the log.
It is an operational alarm first: a host in this state is effectively not auditing. For an investigator it also marks a hard boundary — whatever happened after the 1104 and before the next clear (1102) is not in the local Security log at all.
With the default retention method (overwrite as needed) the event does not occur; the oldest records are silently rolled over instead. Check the log's maximum size and retention settings before drawing conclusions from its absence.
When it is logged
Always logged by the Windows Event Log service when the condition occurs. It only occurs when the Security log retention is set to not overwrite events.
The record carries only an empty UserData/FileIsFull element and is logged at Error level.
Key fields
| Field | What it tells you |
|---|---|
| FileIsFull | Empty UserData element identifying the record; the event has no other data. |
Common benign sources
- Hosts hardened to never overwrite audit records, where the log fills up before an operator archives it.
- Undersized log settings on busy servers, typically domain controllers with verbose auditing.
What attackers do that produces it
- Generating a flood of auditable activity to fill a non-overwriting log, so that later actions are not recorded locally.
Investigation tips
- Treat the time after the 1104 as unaudited on this host until the following 1102; rely on forwarded events, EDR telemetry and logs on other machines for that window.
- Look at the event volume just before the 1104 — a sudden spike of one event ID suggests deliberate flooding rather than normal growth.
- Review the log's size and retention settings and whether a 1102 followed, and by whom.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.