> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-artifacts/account-usage/crowdstrike-searches/event-name-userlogonfailed.md).

# Event Name - UserLogonFailed

**Description**

**Platforms:** *Windows*

This event is generated when a user logon fails.

**Fields: Windows**

| Field            | Description                                                                                                                                                                                                                                                 |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ContextTimeStamp | System time of event creation.                                                                                                                                                                                                                              |
| ContextProcessId | UPID of process originating this event.                                                                                                                                                                                                                     |
| ContextThreadId  | UTID of thread originating this event                                                                                                                                                                                                                       |
| TreeId           | If this event is part of a detection tree, the tree ID it is part of.                                                                                                                                                                                       |
| UserSid          | <p>The User Security Identifier (UserSID) of the user who executed the command. A <code>UserSID</code> uniquely identifies a user in a system.</p><p>Values:</p><ul><li>SELF\_RID (0x01010000000000050A000000)</li></ul>                                    |
| UserName         |                                                                                                                                                                                                                                                             |
| LogonTime        |                                                                                                                                                                                                                                                             |
| PasswordLastSet  |                                                                                                                                                                                                                                                             |
| UserLogonFlags   | <p>Values:</p><ul><li>NONE (0x00000000)</li><li>LOGON\_IS\_SYNTHETIC (0x00000001)</li><li>USER\_IS\_ADMIN (0x00000002)</li><li>USER\_IS\_LOCAL (0x00000004)</li><li>USER\_IS\_BUILT\_IN (0x00000008)</li><li>USER\_IDENTITY\_MISSING (0x00000010)</li></ul> |
