Posted On: December 3, 2020

Who Rebooted Windows Server?

A simple step by step method to identify who rebooted Windows Server.

It is common to be troubleshooting an issue and notice the server was rebooted or crashed and rebooted itself. Finding out the reason why can be important in certain issue investigations.

This article describes an easy method to determine who initiated a system restart and possibly gather more information from the user. For example, why was the system restarted? Or were there any changes made that caused the restart to be initiated?

The answer to these questions can help the troubleshooting process and determine a resolution to the problem.

To quickly and easily identify who rebooted Windows Server follow these simple steps:

  1. Login to Windows Server.
  2. Launch the Event Viewer (type eventvwr in run).
  3. In the event viewer console expand Windows Logs.
  4. Click System and in the right pane click Filter Current Log.

  1. In the Filter Current Log box, type 1074 as the event ID.
    Filtering on the Windows Server Event ID 1074 will only display events associated with ID 1074 – identifying that the system has been shut down by a process/user.

  1. We can now see the events associated with ID 1074.
    The user that initiated the shutdown is listed in the General section of the event

As you can see in the last screenshot, the user that initiated the last restart is listed as e1441. By having this information, you can determine the reason for the restart and any changes that might have happened that triggered the restart.