Who restarted my Windows server?

135,150

Solution 1

In the System event log, filter by event id 1074, this will show by which process and on behalf of which user a reboot was initiated.

This was tested on Windows Server 2008.

Solution 2

There should be a log at:

%windir%\system32\LogFiles\Shutdown

(which should be C:\WINDOWS\system32\LogFiles\Shutdown on a "standard" Windows Server 2000/2003 install)

Share:
135,150

Related videos on Youtube

joar
Author by

joar

Python/bash/JavaScript/YAML hacker at 5 Monkeys.

Updated on September 18, 2022

Comments

  • joar
    joar almost 2 years

    Is it possible on Windows Server 2000/2003/2008 machines to see which user rebooted the server?

    I have found the shutdown event in the System event log, but it does not show which user initiated the reboot.

    • MrGigu
      MrGigu about 12 years
    • Wesley
      Wesley about 12 years
    • user1364702
      user1364702 about 12 years
      No, What rebooted the server. Who installed the malware.
    • Harry Johnston
      Harry Johnston about 12 years
      Was more than one person logged in at the time?
    • KJ-SRS
      KJ-SRS about 12 years
      So who was it that restarted the server?
    • joar
      joar about 12 years
      As I said, it was Who.
  • joar
    joar about 12 years
    That folder does not exist on Windows Server 2008.
  • Lucas Kauffman
    Lucas Kauffman about 12 years
    well you did specify for 2000/2003 as well :)
  • joar
    joar over 11 years
    I give you that!
  • Deruijter
    Deruijter almost 11 years
    Also works on Windows Server 2003 (SP 2)