name: Windows Event Log Application 3000 id: 3911945d-9222-408d-b851-9b1bce4c2d24 version: 3 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs the termination of a process, including details about the process, its termination code, and timestamp. mitre_components: - Process Termination - Process Metadata - Application Log Content - OS API Execution source: XmlWinEventLog:Application sourcetype: XmlWinEventLog separator: EventCode separator_value: '3000' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - _time - Channel - Computer - Error_Code - EventCode - EventData_Xml - EventRecordID - EventSourceName - Guid - Keywords - Level - Name - Opcode - ProcessID - Qualifiers - RecordNumber - SystemTime - System_Props_Xml - Task - ThreadID - UserID - Version - dest - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - param1 - param2 - param3 - punct - signature_id - source - sourcetype - splunk_server - tag - tag::eventtype - timestamp - user_id - vendor_product output_fields: - dest example_log: 300004000x8000000000000021334Applicationwin-host-mhaag-attack-range-117C:\Windows\System32\klist.exe001d8c3afcf370d13