Skip to content
System

System Event ID 104: Event log cleared

The log file was clearedSystem event 104 records that an event log (System, Application, Sysmon, PowerShell...) was cleared, and by whom. Security log clears are event 1102 instead.
104
Event ID
104
Channel
System
Provider
Microsoft-Windows-Eventlog
Log file
System.evtx
Category
Log integrity
Default logging
Logged by default

What event 104 means

Event 104 is written by the Event Log service to the System log whenever a log other than Security is cleared — with wevtutil cl, Clear-EventLog, the Event Viewer "Clear Log" action, or the underlying API. The Security log has its own record, 1102, written into the Security log itself.

Channel names the log that was wiped and SubjectUserName / SubjectDomainName the account that did it. If the System log itself was cleared, the 104 is the first record of the fresh log. A burst of 104 events for many channels within seconds is the classic footprint of a script that clears every log on the host.

Clearing does not remove all traces: the 104 survives, other logs keep their records, and deleted records can sometimes be carved from unallocated EVTX chunks or disk.

When it is logged

Audit policy / configuration

Always logged to the System log when a non-Security log is cleared.

Stopping the Event Log service or deleting .evtx files does not produce 104. Look for 6006 and gaps in record IDs for those.

Key fields

FieldWhat it tells you
ChannelName of the log that was cleared, e.g. Application, Windows PowerShell, Microsoft-Windows-Sysmon/Operational.
SubjectUserNameAccount that cleared the log.
SubjectDomainNameDomain or computer name of that account.
BackupPathPath of the backup file when the log was saved before clearing; usually empty.

Common benign sources

  • Administrators clearing noisy logs during troubleshooting or before building a lab image.
  • Some management or imaging tools reset logs as part of deployment.

What attackers do that produces it

  • Anti-forensics after an intrusion: wevtutil cl System, wevtutil cl "Windows PowerShell" or a loop over wevtutil el, producing many 104 records in a few seconds.
  • Ransomware operators clearing logs before encryption to slow down the response.

Investigation tips

  • List every 104 with its Channel and SubjectUserName; clears of Sysmon, PowerShell or RDP logs are high-signal.
  • Check the Security log for a 1102 at the same time and for the logon (4624) of the subject account.
  • Look for the clearing command in process creation events (4688, Sysmon 1) and PowerShell 4104.
  • Remember that everything before the clear is missing from that channel; widen the search to other logs and hosts.

MITRE ATT&CK techniques

TechniqueTactics
T1685.005 Disable or Modify Tools: Clear Windows Event LogsDefense Impairment

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

2 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading