← Event ID reference
6005

The Event Log service was started (6005) or stopped (6006)

  • Log: System
  • Source: EventLog
  • System & crashes
  • Info

What it means

6005 marks each startup and 6006 a clean shutdown.

Why it matters

An easy way to list every boot and shutdown time.

What to do

  • A 6005 without a preceding 6006 means the shutdown wasn’t clean; look for 41 and 6008.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'System'; Id = 6005
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us