EventPeeker
Event ID 6005InformationSystem

Windows Event ID 6005Event Log Service Started

Logged when the Windows Event Log service starts — effectively marks system startup.

Why It Matters

Acts as a startup marker. Unexpected 6005 events (especially mid-day without a preceding shutdown event) can indicate the system was rebooted by an attacker to apply changes or clear log state.

Investigation Tips

  1. 1.Look for 6005 without a preceding clean 6006 (controlled shutdown) — indicates an unexpected restart.
  2. 2.Correlate the startup time with user activity — a 3am restart on a server is worth investigating.

Seeing Event ID 6005 in your own logs? Upload an .evtx file — EventPeeker flags event log service started automatically, maps it to MITRE ATT&CK, and writes the triage report. No account, files auto-deleted.

Analyze my logs →

Related Event IDs

6006Event Log service stopped — marks planned shutdown
6008Unexpected shutdown event
41Kernel crash — may have caused the restart
1074Clean shutdown/restart — names the process and user that initiated it

Have Event ID 6005 open in Event Viewer?

In Event Viewer: right-click the event → Copy Copy Details as XML, then paste it below. Parsing happens entirely in your browser — the event itself is never uploaded or stored, and it is excluded from session recording. We log only the numeric Event ID.

No account. Your event data never leaves your browser.

See Event ID 6005 in your logs

Upload a Windows Event Log (.evtx) file — EventPeeker automatically detects event log service started patterns, maps findings to MITRE ATT&CK, and generates an AI triage report.

Analyze EVTX Logs Free →