IT Toolbox

Event ID 1102 — Effacement of the security journal

View my favorites

Security’s been erased.

Source of event

Microsoft-Windows-Eventlog — Security category.

Possible causes

  • Voluntary maintenance
  • Re-optimization of a system
  • Attempt to hide traces

Verifications to be carried out

  1. Identify the account that made the action
  2. Check Centralized Newspapers
  3. Search for events prior to,efacement

Useful orders….

Get-WinEvent -FilterHashtable @{LogName='Security'; Id=1102} -MaxEvents 10

To be retained….

An Event ID must always be interpreted with its source, its full message, its timing and the context of the system. The same number may exist in several providers of events.

♡ 0