6009 System log · Event Log Service info severity low volume

System Event ID 6009 — Microsoft Windows version

System version information logged at startup. Contains OS version, build, processor architecture.

Why event 6009 matters

Minimal threat relevance. Useful for asset inventory and detecting operating system changes (unauthorized OS upgrades/downgrades).

How to detect it

No alerting. Use for system inventory and change detection.

Log source
System
Logged by default in the System channel; no audit policy required.
Fields to pivot on
param1param2Computer

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
Event
| where EventLog == "System" and EventID == 6009   // Microsoft Windows version
// EventData holds: param1, param2, Computer
| project TimeGenerated, Computer, RenderedDescription
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:System" EventCode=6009
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# Microsoft Windows version — add EventData fields: param1, param2, Computer`
Hunt event 6009 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Event Log Service events

6005 The Event Log service was started 6006 The Event Log service was stopped 6008 The previous system shutdown was unexpected 6013 The system uptime is

Frequently asked questions

What is System Event ID 6009?

Microsoft Windows version. System version information logged at startup. Contains OS version, build, processor architecture.

Which log records event 6009?

Event 6009 is written to the System channel by Service Control Manager / Kernel. Logged by default in the System channel; no audit policy required.

How do you detect activity around event 6009?

No alerting. Use for system inventory and change detection.