Skip to content
Security

Event ID 1104: Security log full

The security log is now fullSecurity event 1104 means the Security log reached its maximum size and is set not to overwrite, so new audit events can no longer be written.
1104
Event ID
1104
Channel
Security
Provider
Microsoft-Windows-Eventlog
Log file
Security.evtx
Category
Log integrity
Default logging
Logged by default

What event 1104 means

Event 1104 is written by the Windows Event Log service when the Security log hits its configured maximum size while the retention method is Do not overwrite events (Clear logs manually). From that point new audit records cannot be stored until someone archives or clears the log.

It is an operational alarm first: a host in this state is effectively not auditing. For an investigator it also marks a hard boundary — whatever happened after the 1104 and before the next clear (1102) is not in the local Security log at all.

With the default retention method (overwrite as needed) the event does not occur; the oldest records are silently rolled over instead. Check the log's maximum size and retention settings before drawing conclusions from its absence.

When it is logged

Audit policy / configuration

Always logged by the Windows Event Log service when the condition occurs. It only occurs when the Security log retention is set to not overwrite events.

The record carries only an empty UserData/FileIsFull element and is logged at Error level.

Key fields

FieldWhat it tells you
FileIsFullEmpty UserData element identifying the record; the event has no other data.

Common benign sources

  • Hosts hardened to never overwrite audit records, where the log fills up before an operator archives it.
  • Undersized log settings on busy servers, typically domain controllers with verbose auditing.

What attackers do that produces it

  • Generating a flood of auditable activity to fill a non-overwriting log, so that later actions are not recorded locally.

Investigation tips

  • Treat the time after the 1104 as unaudited on this host until the following 1102; rely on forwarded events, EDR telemetry and logs on other machines for that window.
  • Look at the event volume just before the 1104 — a sudden spike of one event ID suggests deliberate flooding rather than normal growth.
  • Review the log's size and retention settings and whether a 1102 followed, and by whom.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading