System Event ID 104: Event log cleared
- Event ID
- 104
- Channel
- System
- Provider
- Microsoft-Windows-Eventlog
- Log file
- System.evtx
- Category
- Log integrity
- Default logging
- Logged by default
What event 104 means
Event 104 is written by the Event Log service to the System log whenever a log other than Security is cleared — with wevtutil cl, Clear-EventLog, the Event Viewer "Clear Log" action, or the underlying API. The Security log has its own record, 1102, written into the Security log itself.
Channel names the log that was wiped and SubjectUserName / SubjectDomainName the account that did it. If the System log itself was cleared, the 104 is the first record of the fresh log. A burst of 104 events for many channels within seconds is the classic footprint of a script that clears every log on the host.
Clearing does not remove all traces: the 104 survives, other logs keep their records, and deleted records can sometimes be carved from unallocated EVTX chunks or disk.
When it is logged
Always logged to the System log when a non-Security log is cleared.
Stopping the Event Log service or deleting .evtx files does not produce 104. Look for 6006 and gaps in record IDs for those.
Key fields
| Field | What it tells you |
|---|---|
| Channel | Name of the log that was cleared, e.g. Application, Windows PowerShell, Microsoft-Windows-Sysmon/Operational. |
| SubjectUserName | Account that cleared the log. |
| SubjectDomainName | Domain or computer name of that account. |
| BackupPath | Path of the backup file when the log was saved before clearing; usually empty. |
Common benign sources
- Administrators clearing noisy logs during troubleshooting or before building a lab image.
- Some management or imaging tools reset logs as part of deployment.
What attackers do that produces it
- Anti-forensics after an intrusion:
wevtutil cl System,wevtutil cl "Windows PowerShell"or a loop overwevtutil el, producing many 104 records in a few seconds. - Ransomware operators clearing logs before encryption to slow down the response.
Investigation tips
- List every 104 with its
ChannelandSubjectUserName; clears of Sysmon, PowerShell or RDP logs are high-signal. - Check the Security log for a 1102 at the same time and for the logon (4624) of the subject account.
- Look for the clearing command in process creation events (4688, Sysmon 1) and PowerShell 4104.
- Remember that everything before the clear is missing from that channel; widen the search to other logs and hosts.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1685.005 Disable or Modify Tools: Clear Windows Event Logs | Defense Impairment |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
2 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 1
- Medium · 1
- HighImportant Windows Eventlog ClearedRule by Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), SigmaHQ, DRL 1.1
- MediumEventlog ClearedRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.