6008 System log · Event Log Service medium severity low volume

System Event ID 6008 — The previous system shutdown was unexpected

The system was shut down unexpectedly (no prior clean shutdown event). Indicates crash, power failure, or forced power off.

Why event 6008 matters

Unexpected shutdowns can indicate: hardware failure, BSOD caused by rootkit/malicious driver, physical access/hard power off, or hypervisor-level attack. Correlate with crash dumps if available.

How to detect it

Alert: unexpected shutdown on servers or critical systems. Correlate with BSOD (BugcheckCode in WER) and crash dumps. Multiple unexpected shutdowns = instability or active attack.

Log source
System
Logged by default in the System channel; no audit policy required.
Fields to pivot on
param1param2Computer

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
Event
| where EventLog == "System" and EventID == 6008   // The previous system shutdown was unexpected
// EventData holds: param1, param2, Computer
| project TimeGenerated, Computer, RenderedDescription
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:System" EventCode=6008
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# The previous system shutdown was unexpected — add EventData fields: param1, param2, Computer`
Hunt event 6008 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Event Log Service events

6005 The Event Log service was started 6006 The Event Log service was stopped 6009 Microsoft Windows version 6013 The system uptime is

Frequently asked questions

What is System Event ID 6008?

The previous system shutdown was unexpected. The system was shut down unexpectedly (no prior clean shutdown event). Indicates crash, power failure, or forced power off.

Which log records event 6008?

Event 6008 is written to the System channel by Service Control Manager / Kernel. Logged by default in the System channel; no audit policy required.

How do you detect activity around event 6008?

Alert: unexpected shutdown on servers or critical systems. Correlate with BSOD (BugcheckCode in WER) and crash dumps. Multiple unexpected shutdowns = instability or active attack.