Windows event log
This document is bilingual (German and English) because ids and messages stay the same in both languages.
certmon schreibt wichtige Ereignisse in das Anwendungsprotokoll (Application), Quelle certmon. RMM- und SIEM-Systeme (NinjaOne, Datto, N-able, Microsoft Sentinel, Splunk …) können sie ohne zusätzliche Agenten abgreifen. Die Texte erscheinen in der Sprache der Installation (Setup-Parameter /LANGUAGE= bzw. Setup-Sprache, settings.json → CertMon:Language).
certmon writes important events to the Application log, source certmon. RMM and SIEM systems can collect them without additional agents. Texts use the installation language (setup parameter /LANGUAGE= or the setup language).
Stabilitätsgarantie / Stability guarantee: Eine veröffentlichte Event-ID behält ihre Bedeutung dauerhaft; neue Ereignisse bekommen neue Nummern im passenden Block, Nummern werden nie wiederverwendet. / A published event id keeps its meaning forever; new events get new numbers in their block; numbers are never reused.
- Die Ereignisquelle legt der Installer an. Fehlt sie, läuft der Dienst normal weiter und vermerkt das einmal in der Logdatei. / The installer registers the source; without it the service keeps running and notes this once in its log.
- Kategorie (Task Category) = Block (10 = Dienst, 11 = Lizenz, 12 = Anmeldung/Sicherheit, 13 = Datenbank, 14 = Konfiguration). / Category = block.
- Ereignistexte enthalten nie Passwörter, Tokens, Schlüssel oder Lizenzschlüssel. / Texts never contain secrets.
- Jedes Ereignis steht zusätzlich in der Logdatei
%ProgramData%\certmon\logs\certmon-JJJJMMTT.log.
Event-IDs
1000–1099 · Dienst / Service
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1000 | Information | certmon-Dienst gestartet (Version {0}). Dashboard: https://{1}:{2}/ | certmon service started (version {0}). Dashboard: https://{1}:{2}/ |
| 1001 | Information | certmon-Dienst beendet. | certmon service stopped. |
| 1002 | Fehler (Error) | certmon-Dienst konnte nicht starten: {0} | certmon service could not start: {0} |
1100–1199 · Lizenz / License
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1100 | Information | Testversion gestartet: {0} Tage, endet am {1:yyyy-MM-dd}. | Trial started: {0} days, ends {1:yyyy-MM-dd}. |
| 1101 | Warnung (Warning) | Die Testversion ist abgelaufen. Lizenz im Dashboard aktivieren (Einstellungen > Lizenz). | The trial has expired. Activate a license in the dashboard (Settings > License). |
| 1102 | Information | Lizenz online aktiviert: Edition {0}, durch {1}. | License activated online: edition {0}, by {1}. |
| 1103 | Information | Lizenz deaktiviert durch {0}. | License deactivated by {0}. |
| 1104 | Information | Lizenzdatei importiert: Edition {0}, Updates bis {1:yyyy-MM-dd}, durch {2}. | License file imported: edition {0}, updates until {1:yyyy-MM-dd}, by {2}. |
| 1105 | Warnung (Warning) | Lizenzdatei abgelehnt ({0}), hochgeladen durch {1}. | License file rejected ({0}), uploaded by {1}. |
| 1106 | Warnung (Warning) | Online-Lizenzprüfung fehlgeschlagen: {0}. Die Lizenz bleibt während der Kulanzfrist gültig. | Online license validation failed: {0}. The license stays valid during the grace period. |
| 1107 | Warnung (Warning) | Lizenzprüfung überfällig; Kulanzfrist endet am {0:yyyy-MM-dd}. | License validation overdue; grace period ends {0:yyyy-MM-dd}. |
| 1108 | Fehler (Error) | Die Lizenz ist nicht mehr gültig: {0}. | The license is no longer valid: {0}. |
1200–1299 · Anmeldung und Sicherheit / Sign-in and security
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1200 | Warnung (Warning) | Die Ersteinrichtung ist offen. Das Einmal-Token wurde nach {0} geschrieben (nur für Administratoren lesbar). https://{1}:{2}/setup öffnen, um den ersten Administrator anzulegen. | Initial setup is open. The one-time setup token was written to {0} (readable by administrators only). Open https://{1}:{2}/setup to create the first administrator. |
| 1201 | Information | Ersteinrichtung abgeschlossen; erster Systemadministrator „{0}“ angelegt von {1}. /setup ist jetzt gesperrt. | Initial setup completed; first system administrator "{0}" created from {1}. /setup is now locked. |
| 1202 | Information | Anmeldung erfolgreich: {0} ({1}) von {2}. | Sign-in succeeded: {0} ({1}) from {2}. |
| 1203 | Warnung (Warning) | Anmeldung fehlgeschlagen für Benutzername „{0}“ von {1}. | Sign-in failed for user name "{0}" from {1}. |
| 1204 | Warnung (Warning) | Konto „{0}“ nach wiederholten Fehlanmeldungen für {1} Minuten gesperrt (zuletzt von {2}). | Account "{0}" locked for {1} minutes after repeated failed sign-ins (last from {2}). |
| 1205 | Warnung (Warning) | Verzeichnisanmeldung (Windows oder LDAP) für {0} von {1} abgewiesen: Keine Gruppe des Benutzers ist einer certmon-Rolle zugeordnet. | Directory sign-in (Windows or LDAP) rejected for {0} from {1}: no group of the user is mapped to a certmon role. |
| 1206 | Warnung (Warning) | Zweiter Faktor (TOTP) abgelehnt für „{0}“ von {1}. | Second factor (TOTP) rejected for "{0}" from {1}. |
| 1207 | Warnung (Warning) | Wiederherstellungscode verwendet von „{0}“ von {1}; {2} Code(s) übrig. | Recovery code used by "{0}" from {1}; {2} code(s) left. |
| 1208 | Information / Warnung (Warning) | Benutzer „{0}“: {1} (durch {2}). | User "{0}": {1} (by {2}). |
| 1209 | Information | AD-Gruppenzuordnung {0}: {1} -> {2} (durch {3}). | Directory group mapping {0}: {1} -> {2} (by {3}). |
| 1210 | Fehler (Error) | Prüfung des Audit-Logs FEHLGESCHLAGEN bei Eintrag {0}: {1}. Das Audit-Log wurde möglicherweise manipuliert. | Audit log verification FAILED at entry {0}: {1}. The audit log may have been manipulated. |
| 1211 | Warnung (Warning) | Zugriff verweigert: {0} versuchte {1} {2} von {3}. | Access denied: {0} tried {1} {2} from {3}. |
1300–1399 · Datenbank / Database
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1300 | Information | Datenbank aktualisiert: {0} Migration(en) angewendet; Sicherung {1}. | Database updated: {0} migration(s) applied; backup {1}. |
| 1301 | Fehler (Error) | Die Datenbank konnte nicht geöffnet oder aktualisiert werden: {0} | The database could not be opened or updated: {0} |
| 1302 | Information | Sicherung geschrieben: {0} (von {1}). | Backup written: {0} (by {1}). |
| 1303 | Fehler (Error) | Sicherung nach {0} fehlgeschlagen: {1} | Backup to {0} failed: {1} |
| 1304 | Warnung (Warning) | Sicherung {0} wiederhergestellt (erstellt {1:yyyy-MM-dd HH:mm} UTC auf {2}) von {3}. Die bisherige Datenbank wurde aufbewahrt. | Backup {0} restored (created {1:yyyy-MM-dd HH:mm} UTC on {2}) by {3}. The previous database was kept. |
1400–1499 · Konfiguration / Configuration
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1400 | Warnung (Warning) | Kein Dashboard-Zertifikat konfiguriert. Selbstsigniertes Zertifikat erstellt (Fingerabdruck {0}, gültig bis {1:yyyy-MM-dd}). Bitte durch ein Zertifikat der eigenen CA ersetzen. | No dashboard certificate configured. Created a self-signed certificate (thumbprint {0}, valid until {1:yyyy-MM-dd}). Replace it with a certificate from your own CA. |
| 1401 | Information | Dashboard-Zertifikat geladen: {0}, Fingerabdruck {1}, gültig bis {2:yyyy-MM-dd}. | Dashboard certificate loaded: {0}, thumbprint {1}, valid until {2:yyyy-MM-dd}. |
| 1402 | Fehler (Error) | Dashboard-Zertifikat {0} nicht in LocalMachine\My gefunden oder privater Schlüssel nicht zugreifbar. | Dashboard certificate {0} not found in LocalMachine\My or without accessible private key. |
| 1403 | Warnung (Warning) | Das Dashboard-Zertifikat läuft am {0:yyyy-MM-dd} ab ({1} Tage). | The dashboard certificate expires on {0:yyyy-MM-dd} ({1} days). |
| 1404 | Information | Dashboard-Zertifikat auf {0} geändert durch {1}; wirksam nach Neustart des Dienstes. | Dashboard certificate changed to {0} by {1}; takes effect after the service restarts. |
1500–1599 · Überwachung / Monitoring
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1500 | Fehler (Error) | Überwachung: Der Lauf der Quelle „{0}“ ist fehlgeschlagen: {1} | Monitoring: the run of source "{0}" failed: {1} |
| 1501 | Warnung (Warning) | Überwachung der Quelle „{0}“ übersprungen: Die Lizenz enthält {1} nicht. Lizenz im Dashboard aktivieren (Einstellungen > Lizenz). | Monitoring of source "{0}" skipped: the license does not include {1}. Activate a license in the dashboard (Settings > License). |
1600–1699 · Benachrichtigung / Notification
| ID | Schweregrad / Severity | Deutsch | English |
|---|---|---|---|
| 1600 | Fehler (Error) | Benachrichtigung über Kanal „{0}“ nach {1} Versuchen fehlgeschlagen: {2} | Notification over channel "{0}" failed after {1} attempts: {2} |
| 1601 | Information | Testnachricht über Kanal „{0}“ gesendet (von {1}). | Test message over channel "{0}" sent (by {1}). |
| 1602 | Warnung (Warning) | Testnachricht über Kanal „{0}“ fehlgeschlagen (von {1}): {2} | Test message over channel "{0}" failed (by {1}): {2} |
| 1603 | Warnung (Warning) | Benachrichtigungen werden nicht gesendet: Die Lizenz enthält keine Benachrichtigungen. Lizenz im Dashboard aktivieren (Einstellungen > Lizenz). | Notifications are not sent: the license does not include notifications. Activate a license in the dashboard (Settings > License). |
{0}, {1} … sind Platzhalter für die jeweiligen Werte. / {0}, {1} … are placeholders.
Abfragebeispiele / Query examples
# Alle certmon-Ereignisse der letzten 24 Stunden / all certmon events of the last 24 hours
Get-WinEvent -FilterHashtable @{ LogName = 'Application'; ProviderName = 'certmon'; StartTime = (Get-Date).AddDays(-1) }
# Fehlgeschlagene Anmeldungen und Sperren / failed sign-ins and lockouts
Get-WinEvent -FilterHashtable @{ LogName = 'Application'; ProviderName = 'certmon'; Id = 1203, 1204, 1206 }
# Manipuliertes Audit-Log / tampered audit log
Get-WinEvent -FilterHashtable @{ LogName = 'Application'; ProviderName = 'certmon'; Id = 1210 }Empfohlene Alarme im RMM/SIEM / recommended alerts: 1002, 1101, 1108, 1204, 1210, 1301, 1402, 1403.
Vorbild / modelled on: docs/windows-event-log.md des UPS Hyper-V Shutdown Monitor.
More documents
Installation and setup
Requirements, firewall, service account, permissions, setup (also silent), initial setup, update, backup and troubleshooting.
JEA endpoint for Windows servers
How certmon reads Windows servers only through a restricted PowerShell endpoint: setup, permissions, testing.
Notifications
Alert logic, email over SMTP or Microsoft 365, Microsoft Teams and webhooks with an HMAC signature.
Findings
Every finding id with its meaning and severity: network scan, PKI and Windows servers.