System Event ID 6013: Uptime report
- Event ID
- 6013
- Channel
- System
- Provider
- EventLog
- Log file
- System.evtx
- Category
- System
- Default logging
- Logged by default
What event 6013 means
Event 6013 is a heartbeat from the Event Log service: it records how many seconds the system has been running. It is written shortly after each boot and then once a day, so a steady series of increasing values shows continuous uptime, and a small value marks a recent boot.
The last insertion string also carries the host time zone (the bias in minutes and the zone name, e.g. 480 Pacific Standard Time). That is useful when other artifacts record local time, as 6008 does.
6013 is not a security event, but it helps validate a timeline: uptime that resets without a matching 12/6005 pair, or that is inconsistent with the record time, can point to gaps or tampering with the log or clock.
When it is logged
Always logged to the System log.
The data is a set of unnamed insertion strings; this viewer shows them joined in Data1.
Key fields
| Field | What it tells you |
|---|---|
| Data1 | Insertion strings; the fifth is the uptime in seconds and the last one the time zone bias in minutes followed by the zone name (e.g. ,,,,22,60,480 Pacific Standard Time). |
Common benign sources
- Daily heartbeat on every running system.
What attackers do that produces it
- Not an attacker action, but uptime values that do not match boot events (12, 6005) or the record timestamps can reveal log gaps or clock changes during an intrusion.
Investigation tips
- Subtract the uptime from the record time to estimate the boot time and compare with 12.
- Read the time zone to convert local timestamps (6008, application logs) to UTC.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.