Skip to content

Security Event Collection Guidance

Purpose

This WASOC guide provides recommendations for collecting security events of Windows systems based on asset criticality.

The objective is to maximise detection opportunities, support incident response activities, and maintain an appropriate balance between security visibility and log volume.

This guidance is vendor-agnostic and can be implemented using any SIEM, log management platform, managed security service, or security operations capability.

What Are Security Event Logs?

Security event logs are records generated by operating systems and applications that capture security-relevant activity, including authentication attempts, account changes, privileged actions, process execution, and service installations. These logs are a key source of information for security monitoring, incident response, threat hunting, and compliance activities.

Examples include:

  • Successful and failed logons
  • User and group management changes
  • Privileged account activity
  • Kerberos authentication events
  • Process creation events
  • Service installation events
  • Account lockouts

Further information on Windows Security Event logging can be found in the Windows Security Events Reference.


🏛️ Domain Controllers
   └─ Common Security Events + Process Creation

🔐 Tier 0 Systems
   └─ Common Security Events + Process Creation

🖥️ General Servers
   └─ Common Security Events

👨‍💼 Workstations & End User Devices
   └─ Minimal or Common Security Events (depending on risk profile)

Domain Controllers

Services / Infrastructure

  • Active Directory Domain Controllers
  • Entra ID Connect Servers
  • Authentication Infrastructure
  • Privileged Access Management Systems

Recommended Events

  • Authentication Events
  • Kerberos Events
  • Privileged Account Activity
  • Account Management Events
  • Service Installation Events
  • Process Creation Events

Logging Objectives

  • User authentication activity
  • Kerberos authentication requests
  • Privileged account usage
  • Account creation and modification
  • Service installation and persistence mechanisms
  • Suspicious process execution

Key Event IDs

  • 4624 Successful Logon
  • 4625 Failed Logon
  • 4672 Privileged Logon
  • 4720 User Account Created
  • 4726 User Account Deleted
  • 4732 User Added to Privileged Group
  • 4740 Account Locked Out
  • 4768 Kerberos TGT Request
  • 4769 Kerberos Service Ticket Request
  • 4776 NTLM Authentication
  • 7045 Service Installed
  • 4688 Process Creation
Tier 0 Systems

Services / Infrastructure

  • Certificate Authorities (CA)
  • Privileged Access Workstations (PAW)
  • Backup and Recovery Infrastructure
  • Security Management Platforms
  • SIEM and Log Collection Servers
  • VPN and Remote Access Infrastructure
  • Privileged Access Management (PAM) Systems
  • Critical Operational Technology (OT) Management Systems

Recommended Events

  • Authentication Events
  • Privileged Account Activity
  • Account Management Events
  • Service Installation Events
  • Process Creation Events

Logging Objectives

  • Administrative access and privileged actions
  • Changes to critical systems and services
  • Malware, ransomware, and attacker tooling execution
  • Lateral movement and credential misuse
  • Service installation and persistence mechanisms

Key Event IDs

  • 4624 Successful Logon
  • 4625 Failed Logon
  • 4648 Logon with Explicit Credentials
  • 4672 Privileged Logon
  • 4720 User Account Created
  • 4726 User Account Deleted
  • 4732 User Added to Privileged Group
  • 4733 User Removed from Privileged Group
  • 4740 Account Locked Out
  • 4768 Kerberos TGT Request
  • 4769 Kerberos Service Ticket Request
  • 4776 NTLM Authentication
  • 7045 Service Installed
  • 4688 Process Creation
General Servers

Services / Infrastructure

  • Application Servers
  • Web Servers
  • API Gateways
  • File Servers
  • Print Servers
  • Database Servers
  • Middleware Platforms
  • Enterprise Business Systems
  • Management Servers

Recommended Events

  • Authentication Events
  • Account Management Events
  • Privileged Account Activity
  • Service Installation Events

Logging Objectives

  • Successful and failed authentication attempts
  • Administrative activity
  • User and group management changes
  • Service installations and configuration changes
  • Potential signs of unauthorised access

Key Event IDs

  • 4624 Successful Logon
  • 4625 Failed Logon
  • 4648 Logon with Explicit Credentials
  • 4672 Privileged Logon
  • 4720 User Account Created
  • 4726 User Account Deleted
  • 4732 User Added to Privileged Group
  • 4733 User Removed from Privileged Group
  • 4740 Account Locked Out
  • 4768 Kerberos TGT Request
  • 4769 Kerberos Service Ticket Request
  • 4776 NTLM Authentication
  • 7045 Service Installed
Workstations and End User Devices

Services / Infrastructure

  • Corporate Laptops
  • Desktop Computers
  • Shared Workstations
  • Kiosk Devices
  • Virtual Desktop Infrastructure (VDI)
  • Thin Clients

Recommended Events

  • Authentication Events
  • Account Lockout Events
  • Credential Usage Events

Logging Objectives

  • User authentication activity
  • Password spraying attempts
  • Brute force activity
  • Credential misuse
  • Potential account compromise indicators

Key Event IDs

  • 4624 Successful Logon
  • 4625 Failed Logon
  • 4648 Logon with Explicit Credentials
  • 4740 Account Locked Out

Enhanced Monitoring Option - For higher-risk environments or where additional logging capacity is available, consider collecting:

  • 4672 Privileged Logon
  • 4688 Process Creation
  • 7045 Service Installed

Appendix A – Microsoft Sentinel Implementation

Organisations using Microsoft Sentinel can implement this guidance using the Windows Security Events via AMA connector.

Guidance on configuring the connector and available event sets can be found in the Windows Security Events via AMA documentation.

Azure Virtual Machines

  1. Deploy the Azure Monitor Agent (AMA) extension to the virtual machine.
  2. Create or select a Log Analytics Workspace.
  3. Enable Microsoft Sentinel on the workspace.
  4. Configure the Windows Security Events via AMA data connector.
  5. Create or assign a Data Collection Rule (DCR).
  6. Select Minimal, Common, All Events, or Custom event collection.
  7. Associate the DCR with the required servers.

Guidance for deploying and managing AMA is available in the Azure Monitor Agent Overview.

On-Premises and Non-Azure Servers

For physical servers, VMware environments, AWS, or other cloud platforms:

  1. Onboard the server to Azure Arc.
  2. Deploy the Azure Monitor Agent through Azure Arc.
  3. Configure the Windows Security Events via AMA connector.
  4. Create and assign the appropriate Data Collection Rule.
  5. Verify events are being received in the SecurityEvent table.

Microsoft provides onboarding guidance in the Azure Arc-enabled Servers documentation.

Data Flow

🖥️ Windows Server
📡 Azure Monitor Agent (AMA)
📋 Data Collection Rule (DCR)
📊 Log Analytics Workspace
🛡️ Microsoft Sentinel

Additional information on DCRs is available in the Data Collection Rules Overview, while guidance on collecting Windows Event Logs is available in the Collect Windows Events with AMA.