Skip to content

Microsoft Windows Event Log

You can integrate Microsoft Windows Event Log with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Microsoft Windows Event Log product overview

Microsoft Windows Event Log is the native logging framework in Windows that records security, system, and application events across Windows hosts and domain controllers. Its Security channel captures audit events—successful and failed logons, privilege and resource use, account and policy changes, and process activity—as defined by Windows audit policy.

What we ingest

A Sophos XDR data collector accepts Windows Event Log data in the Snare-over-syslog format, forwarded from your Windows hosts by NXLog, Snare Enterprise, or a compatible agent. Depending on which events your hosts are configured to forward, this integration can collect the following log categories:

  • Authentication and account activity: Security-auditing logon and logoff events and Active Directory account, group, and policy changes.
  • Process activity: Process creation and object-access events.
  • Malware detections: Microsoft Defender Antivirus events.
  • Configuration and management: Scheduled tasks, system time, and administrative change events.
  • Directory object audit: Directory-service object-access audit events.
  • Threat and encrypted-channel events: Attack detections and certificate or encrypted-channel events.
  • Network activity1: Windows Filtering Platform connection events.

Event and data types

We ingest the following event and data types from Microsoft Windows Event Log:

  • Authentication and account activity: Windows Security Auditing logon and logoff events (for example, Event IDs 4624 and 4625), credential and privilege use, and Active Directory account, group, and policy changes, with the user, host, and result. Normalized to authentication telemetry.
  • Process activity: Process creation (Event ID 4688) and object-access events (Event ID 4663), including the process, command line, and target. Normalized to process telemetry.
  • Malware detections: Microsoft Defender Antivirus detection and remediation events, including the threat and action. Normalized to antivirus telemetry.
  • Configuration and management: Scheduled-task (Event IDs 4698–4702), system-time (Event ID 4616), and other administrative configuration-change events. Normalized to management event telemetry.
  • Directory object audit: Directory-service object-access operations (Event ID 4662). Normalized to cloud audit telemetry.
  • Threat and encrypted-channel events: Attack detections such as replay attacks (Event ID 4649) and certificate or encrypted-channel events. Normalized to third-party security alert and encrypted-traffic telemetry.
  • Network activity1: Windows Filtering Platform connection and firewall events (for example 5156), including source and destination addresses and ports. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Microsoft Windows Event Log gets normalized to the following schemas:

  • antivirus
  • auth
  • cloudaudit
  • encrypt
  • managementevent
  • netflow 1
  • process
  • thirdpartyalert

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation


  1. Netflow telemetry is only available with a Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview