Skip to main content

Windows Logon Types

12rows
12rows with meaning
1lookups that use it
Livestatus

The logon type Windows records on every sign-in event, which says how the session was established: at the keyboard, over the network, as a service, over remote desktop. Filtering on it is how a failed-sign-in spike separates a broken service account from a person at a console.

This table decodes 12 codes.

SparkLogs decodes these codes on every event that carries one, regardless of feed. The Windows Security event log feed reads these codes while curating an event.

How to read this

Codes are listed in numeric order. Windows publishes no constant for this space, so Name is the short label SparkLogs puts on the event, and it is what a question groups by. The last column is our one-line summary of what the code means in plain words.

Codes 0 to 13

CodeNameWhat it means
0logon_systemused only by the operating system itself before anyone signs in
2logon_interactivesigned in at the console keyboard
3logon_networkreached the machine over the network
4logon_batchran under the batch scheduler
5logon_servicestarted as a Windows service
7logon_unlockunlocked an existing session
8logon_network_cleartextnetwork logon with the password sent in cleartext
9logon_new_credentialsran with alternate credentials for network access
10logon_remote_interactivesigned in over remote desktop
11logon_cached_interactivesigned in with cached domain credentials
12logon_cached_remote_interactivesigned in over remote desktop with cached credentials
13logon_cached_unlockunlocked an existing session with cached credentials

Ask about these codes

Connect your AI and ask in plain language, or open the same events in Explore.