Windows Event Log Analysis Field Guide for Sysadmins
A practical reference guide covering the 20 most critical Windows Event IDs every sysadmin must monitor — with detection logic, triage steps, and copy-paste PowerShell queries for each.
- ▸Field Guide (guide.md) — 20 Event ID entries organized by threat category (Authentication & Account, Privilege & Access, Operational & Integrity), each with detection logic, triage steps, and a ready-to-run PowerShell query
- ▸PowerShell Query Pack (queries.ps1) — All 20 queries as dot-sourceable functions with zero-result handling and convenience wrappers — drop them into your existing scripts
- ▸Quick Reference Card (quick-reference-card.md) — A printable one-page cheat sheet: every Event ID, severity level, log source, threshold signal, and first action
- ▸Scope & Decisions (build-notes.md) — Bonus transparency doc: the six Event IDs that were considered and cut, and the technical accuracy rationale behind each query choice
## goes-well-with
From the same shelf
Active Directory Security Audit Kit for Solo IT Teams
A fillable AD audit checklist covering privileged access, stale accounts, GPO hygiene, MFA gaps, and event log review — everything an auditor expects, packaged for the sysadmin who has no security team.
Microsoft Entra ID Migration Starter Kit for Sysadmins
A practical guide + checklist bundle for IT admins migrating on-premises Active Directory to Microsoft Entra ID in 2026 — covering Cloud Sync, legacy auth deprecation, Intune join strategy, and a phased migration checklist sysadmins can actually execute.
Windows Server Patch Management Playbook
For solo sysadmins and small IT teams managing Windows Server patching at SMBs — a practical guide and checklist bundle that turns a monthly fire drill into a repeatable process.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.