How to find out who restarted Windows Server

In this post I will show you the steps to find out who restart Windows Server. If you are working for a big organization, you might have lot of Windows servers in your setup. Ensuring the servers are up and working fine is the duty of system administrators.

Sometimes things don’t go well. Suppose you get an email saying that a server has been restarted and this needs to be investigated.

You cannot ask each IT individual about who initiated the server restart. So how do you find who restarted Windows Server ?.

Yes there is a way to do that. This post will come handy if you looking to find who restarted windows server. Of course event viewer is where we look for the information.

There is something called as Shutdown event tracker. This will allow the admins to track why a user initiated shutdown or a restart.

It also gathers the reason why the users restarted or shutdown the computer. More info about it is documented here.

How to find out who restarted Windows Server

To find out who restarted windows server :-

  • Login to Windows Server.
  • Launch the Event Viewer (type eventvwr in run).
  • In the event viewer console expand Windows Logs.
  • Click System and in the right pane click Filter Current Log.

How to find out who restarted Windows ServerIn the Filter Current log box, type 1074 as the event ID. This will filter the events and you will see events only with ID 1074.

How to find out who restarted Windows ServerWe can now see the event with ID 1074.

How to find out who restarted Windows ServerDouble click the recent event. In the event properties box, you can see the person who initiated the restart of server.

The process C:\Windows\System32\RuntimeBroker.exe (CORPAD) has initiated the restart of computer CORPAD on behalf of user PRAJWAL\sccmadmin for the following reason: Other (Unplanned)
Reason Code: 0x5000000
Shutdown Type: restart
Comment:

Click Close.

How to find out who restarted Windows Server

You might also like

2
Leave a Reply

2 Comment threads
0 Thread replies
0 Followers
 
Most reacted comment
Hottest comment thread
newest oldest most voted
Jagdessh

Excellent post. Thank you Prajwal

Subrahmanyam

Hi Prajwal,
In my organization many people are working on configuration changes and restarts the application services in Windows server 2012R2.But when i check in the event viewer it’s just showing the “service is entered the stopped state” or “service is entered the running state” and i can’t able to find who restarted the service.Can you please suggest me how can i able to find/configure the audit policy to track the users who is stopping/Starting the services i windows server 2012 R2.

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. AcceptRead More