name: Windows Event Log Security 1100 id: 2a25dafa-691e-4cb2-ae59-07a48867ed9a version: 4 creation_date: '2024-05-22' modification_date: '2026-05-13' author: Patrick Bareiss, Splunk description: Logs an event when the event logging service has shut down. mitre_components: - Host Status - System Configuration Changes source: XmlWinEventLog:Security sourcetype: XmlWinEventLog separator: EventCode separator_value: '1100' supported_TA: - name: Splunk Add-on for Microsoft Windows url: https://splunkbase.splunk.com/app/742 version: 10.0.1 fields: - _time - Channel - Computer - Error_Code - EventCode - EventID - EventRecordID - Guid - Keywords - Level - Name - Opcode - ProcessID - RecordNumber - SystemTime - System_Props_Xml - Task - ThreadID - UserData_Xml - Version - action - app - change_type - date_hour - date_mday - date_minute - date_month - date_second - date_wday - date_year - date_zone - dest - dvc - dvc_nt_host - event_id - eventtype - host - id - index - linecount - name - object_attrs - object_category - product - punct - service - service_name - signature - signature_id - source - sourcetype - splunk_server - status - subject - ta_windows_action - tag - tag::eventtype - timeendpos - timestartpos - vendor - vendor_product output_fields: - action - app - change_type - dest - dvc - name - object_attrs - object_category - service - service_name - signature - signature_id - status - subject - vendor_product example_log: 11000410300x4020000000000000140874Securityar-win-2