Skip to content
System

System Event ID 6013: Uptime report

The system uptime is N secondsSystem event 6013 reports the system uptime in seconds and the time zone, at boot and once a day. Helps spot reboots and log gaps.
6013
Event ID
6013
Channel
System
Provider
EventLog
Log file
System.evtx
Category
System
Default logging
Logged by default

What event 6013 means

Event 6013 is a heartbeat from the Event Log service: it records how many seconds the system has been running. It is written shortly after each boot and then once a day, so a steady series of increasing values shows continuous uptime, and a small value marks a recent boot.

The last insertion string also carries the host time zone (the bias in minutes and the zone name, e.g. 480 Pacific Standard Time). That is useful when other artifacts record local time, as 6008 does.

6013 is not a security event, but it helps validate a timeline: uptime that resets without a matching 12/6005 pair, or that is inconsistent with the record time, can point to gaps or tampering with the log or clock.

When it is logged

Audit policy / configuration

Always logged to the System log.

The data is a set of unnamed insertion strings; this viewer shows them joined in Data1.

Key fields

FieldWhat it tells you
Data1Insertion strings; the fifth is the uptime in seconds and the last one the time zone bias in minutes followed by the zone name (e.g. ,,,,22,60,480 Pacific Standard Time).

Common benign sources

  • Daily heartbeat on every running system.

What attackers do that produces it

  • Not an attacker action, but uptime values that do not match boot events (12, 6005) or the record timestamps can reveal log gaps or clock changes during an intrusion.

Investigation tips

  • Subtract the uptime from the record time to estimate the boot time and compare with 12.
  • Read the time zone to convert local timestamps (6008, application logs) to UTC.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading