Skip to content

TechDirectArchive

Hands-on IT, Cloud, Security, Veeam & DevOps

  • Home
  • About
  • Advertise With US
  • Reviews
  • Contact
  • Toggle search form

How to find out who restarted Windows Server

Posted on 27/10/202220/08/2024 Matthew By Matthew No Comments on How to find out who restarted Windows Server
  1. Home
  2. Windows
  3. How to find out who restarted Windows Server
Featured-image_new
Windows Server Event Log Viewer

If your organization has many system administrators, you may want to know who restarted the server at certain times. This post will show you How to find out who restarted Windows Server. This is to view shutdown/reboot/startup logs on Windows servers.

Windows has a great application called Windows Event Viewer that records all actions that occur on the computer.

The event log service, which is a Windows core service, manages the Windows Event Viewer. The event viewer records the event log service’s startup and shutdown history. It tracks each user’s activity while the machine is working. On the Windows Server/Desktop, and PCs, it logs errors, information messages, and warnings.

Here are other related guides on Windows Server: How to uninstall Internet Explorer from your Windows PC or Windows Server, How to install Windows Server 2022 on VirtualBox, How to Install Web Server IIS in Windows Server 2019, Network File System: How to install NFS Server on Windows Server, and how to Migrate Roles and Features to Windows Server 2022 using WSMT.

The Most Frequent Startup and Shutdown Events

There are several events associated with shutting down and restarting a Windows PC. However, in this post, we will show you the most common events:

  • Event ID 41: indicates that your Windows machine rebooted without completely shutting down.
  • Event ID 6005: This code indicates the starting of the event log service.
  • Event ID 1074: Your computer logs this event whenever a program makes your laptop restart or shut down. Additionally, this event lets you know when a user rebooted or shut down the machine using the Start menu or the CTRL+ALT+DEL keyboard shortcut.
  • Event ID 6006: If your Windows PC shuts down properly, this event is recorded.
  • Event ID 6008: This event occasionally appears in your system log when your machine abruptly or unexpectedly shuts down.
  • Event ID 6009: Identifies the name of the Windows product, version, build number, service pack number, and operating system type that is detected during boot.
  • Event ID 1076: Keeps track of the first time a user with shutdown permissions logs in to the computer after an unexpected restart or shutdown, along with a reason for the occurrence.

Please see how to detect if an application was uninstalled on Windows: Find out who has uninstalled an application via Windows Event Viewer, How to view Scheduled Events on AW using the Command Line (CLI), How to prevent a remote shutdown and restart in Windows, How to prevent users from shutting down in a Virtual Machine, and How to use command prompt to shutdown and restart your computer.

How to find out who restarted Windows Server

In this section, I will show you how to view Shutdown and Restart Log from Event Viewer. Let’s go over the whole process of getting this data from the Windows event viewer.

To open the Event Viewer, press Win + R to launch the Run dialog box and type eventvwr.

image0-1
Run dialog box

In the left pane, click on Windows Logs and select System. You’ll see a list of events that occurred while Windows was operating in the center pane. Click on the Event ID label to sort the data by the Event ID column.

image1-5
Event Viewer

If the event log is large, the sorting will fail. You can also make a filter using the Actions pane on the right. Simply choose “Filter current log.”

image2-3
Filtering the Event log

In the Event IDs field, enter 1074 or any Event ID. Under Logged, you can also choose a time period.

image3-3
Event log filter

After you have completed all of the procedures, the Windows Event Viewer will only show events connected to the shutdown.

How to View Shutdown and Restart Log Using Windows PowerShell

The PowerShell command Get-EventLog can be used to get the shutdown and reboot logs in Windows from the command line.

Enter the following command, for example, to filter the 10,000 most recent entries in the System Event Log:

Get-EventLog System -Newest 10000 | ` Where EventId -in 41,1074,1076,6005,6006,6008,6009,6013 | ` Format-Table TimeGenerated,EventId,UserName,Message -AutoSize -wrap

Run the following command to view just events related to Windows shutdowns and restarts:

Get-WinEvent -FilterHashtable @{logname = 'System'; id = 1074} | Format-Table -wrap

Query Via WMI

To query a remote device to get the last reboot time with Get-WmiObject

Get-WmiObject -ClassName win32_operatingsystem -ComputerName techdaPC2 | Select-Object csname, lastbootuptime

I hope you find this post helpful. If you have any questions, feel free to leave them in the comment section below.

5/5 - (1 vote)

Thank you for reading this post. Kindly share it with others.

  • Share on X (Opens in new window) X
  • Share on Reddit (Opens in new window) Reddit
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Facebook (Opens in new window) Facebook
  • Share on Pinterest (Opens in new window) Pinterest
  • Share on Tumblr (Opens in new window) Tumblr
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Share on Bluesky (Opens in new window) Bluesky
  • Share on Threads (Opens in new window) Threads
  • Share on Nextdoor (Opens in new window) Nextdoor
Windows, Windows Server Tags:Event Viewer, eventlog, Windows 10, Windows 11, Windows Server 2016

Post navigation

Previous Post: FoneTool is the best iPhone backup software
Next Post: Apache JMeter Load Testing: Test Mobile Apps on Windows

Related Posts

  • Remote desktop
    Is RDP enabled? Enable and disable Remote Desktop in Windows 10 for all users or selected users Windows
  • slide office 365 79
    Configure WSUS Email Notification for Office365 Windows Server
  • Setup FSx File System 1
    Create and mount FSx File System: Join EC2 instance to AWS Managed AD AWS/Azure/OpenShift
  • microsoft edge
    How to forcefully remove Microsoft Edge Browser the hard way from your Windows device Windows
  • MBAM Reports
    Microsoft BitLocker Administration and Monitoring Report Fields Windows Server
  • 1 kAUgwdVYmcVgUSXiwUkObw
    Error 0x801c001d – Automatic registration failed: Failed to look up the registration service from AD Windows Server

More Related Articles

Remote desktop Is RDP enabled? Enable and disable Remote Desktop in Windows 10 for all users or selected users Windows
slide office 365 79 Configure WSUS Email Notification for Office365 Windows Server
Setup FSx File System 1 Create and mount FSx File System: Join EC2 instance to AWS Managed AD AWS/Azure/OpenShift
microsoft edge How to forcefully remove Microsoft Edge Browser the hard way from your Windows device Windows
MBAM Reports Microsoft BitLocker Administration and Monitoring Report Fields Windows Server
1 kAUgwdVYmcVgUSXiwUkObw Error 0x801c001d – Automatic registration failed: Failed to look up the registration service from AD Windows Server

Leave a Reply Cancel reply

You must be logged in to post a comment.

Microsoft MVP

VEEAMLEGEND

vexpert-badge-stars-5

Virtual Background

GoogleNews

Categories

veeaam100

Veeam Vanguard

  • ADUC Appcrash fix
    Faulting Application Name: mmc.exe: Unable to launch ADUC Windows Server
  • prettier boot image
    How to stop Cisco Webex Meetings from starting up automatically on macOS Mac
  • macrestart
    How to Enable or Prevent Reopen Windows when logging back in after Restart or Shutdown on Mac Mac
  • Fix Operating System Loader Failed Signature Verification
    Fix Operating System Loader failed signature verification” on Dell Safe BIOS Systems via PXE [Part 3] Windows
  • Windows 10 new Start menu
    Make Cortana search with a different web browser instead of Edge Windows
  • Windows10 11
    Block Upgrade to Windows 11 via Group Policy or Registry Windows
  • asdfgh
    Install RSAT on Windows via Windows features Windows
  • LiveCaption
    Enable or disable automatic Google Chrome Live Caption on macOS Mac

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Join 1,796 other subscribers
  • RSS - Posts
  • RSS - Comments
  • About
  • Authors
  • Write for us
  • Advertise with us
  • General Terms and Conditions
  • Privacy policy
  • Feedly
  • Telegram
  • Youtube
  • Facebook
  • Instagram
  • LinkedIn
  • Tumblr
  • Pinterest
  • Twitter
  • mastodon

Tags

Active Directory Azure Bitlocker Microsoft Windows PowerShell WDS Windows 10 Windows 11 Windows Deployment Services Windows Server 2016

Copyright © 2025 TechDirectArchive

Loading Comments...

You must be logged in to post a comment.