EVID 4826 : Boot Configuration Data Loaded

Event Details

Event Type

Boot Configuration Data Loaded

Event Description

4826(S) : Boot Configuration Data Loaded

Event ID

4826

Vendor Documentation

https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4826

Log Fields and Parsing

This section details the log fields available in this log message type, along with values parsed for both LogRhythm Default and LogRhythm Default v2.0 policies. A value of "N/A" (not applicable) means that there isNo value parsed for a specified log field.

Log Field

LogRhythm Default

LogRhythm Default v2.0

Provider

N/A

N/A

EventID

N/A

<vmid>

Version

N/A

N/A

Level

N/A

<severity>

Task

N/A

<vendorinfo>

Opcode

N/A

N/A

Keywords

N/A

<result>

TimeCreated

N/A

N/A

EventRecordID

N/A

N/A

Correlation

N/A

N/A

Execution

N/A

N/A

Channel

N/A

N/A

Computer

N/A

<dname>

SubjectUserSid

N/A

N/A

SubjectUserName

N/A

N/A

SubjectDomainName

N/A

N/A

SubjectLogonId

N/A

N/A

LoadOptions

N/A

N/A

AdvancedOptions

N/A

N/A

ConfigAccessPolicy

N/A

<policy>

RemoteEventLogging

N/A

N/A

KernelDebug

N/A

N/A

VsmLaunchType

N/A

N/A

TestSigning

N/A

N/A

FlightSigning

N/A

N/A

DisableIntegrityChecks

N/A

<status>

HypervisorLoadOptions

N/A

N/A

HypervisorLaunchType

N/A

N/A

HypervisorDebug

N/A

N/A

Log Processing Settings

This section details log processing changes made from the LogRhythm Default policy to LogRhythm Default v2.0. In some cases, base rules are broken down into sub-rules to appropriately parse log message types by their event types.

LogRhythm Default

N/A

LogRhythm Default v2.0

Regex ID

Rule Name

Rule Type

Common Event

Classification

1012327

V 2.0 : EVID 4826 : Boot Configuration Data Loaded

Base Rule

Configuration Loaded : System

Configuration