6006 System log · Event Log Service info severity low volume

System Event ID 6006 — The Event Log service was stopped

Event Log service stopped — typically indicates clean system shutdown.

Why event 6006 matters

Clean shutdown indicator. If 6005 (start) does not follow within reasonable time, the system may have crashed or been hard-reset.

How to detect it

Use to establish shutdown timeline. Missing 6006 before next 6005 = unclean shutdown (crash, power loss, or forced off).

Log source
System
Logged by default in the System channel; no audit policy required.
Fields to pivot on
param1param2Computer

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
Event
| where EventLog == "System" and EventID == 6006   // The Event Log service was stopped
// EventData holds: param1, param2, Computer
| project TimeGenerated, Computer, RenderedDescription
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:System" EventCode=6006
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The Event Log service was stopped — add EventData fields: param1, param2, Computer`
Hunt event 6006 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Event Log Service events

6005 The Event Log service was started 6008 The previous system shutdown was unexpected 6009 Microsoft Windows version 6013 The system uptime is

Frequently asked questions

What is System Event ID 6006?

The Event Log service was stopped. Event Log service stopped — typically indicates clean system shutdown.

Which log records event 6006?

Event 6006 is written to the System channel by Service Control Manager / Kernel. Logged by default in the System channel; no audit policy required.

How do you detect activity around event 6006?

Use to establish shutdown timeline. Missing 6006 before next 6005 = unclean shutdown (crash, power loss, or forced off).