Windows Group Policy Operational
Microsoft-Windows-GroupPolicy/Operational computer policy refreshes (periodic and manual gpupdate) and client-side extension processing from a fleet of 1,000 domain members (800 workstations, 200 servers), as Winlogbeat-style ECS JSON with the native Event XML in event.original, for SIEM content that watches whether Group Policy, and security policy in particular, is actually applied. About 40,000 events a day follow a working-day curve. Recurring episodes break the Security extension on three hosts that apply the same changed GPO; each host recovers at its next Security run.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/windows-group-policy-operational/generator.yml \
--id gpo \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| 4006 | Periodic computer policy processing started | 19.40% of events | configuration |
| 8006 | Periodic computer policy processing completed | 19.39% of events | configuration |
| 7006 | Periodic computer policy processing failed | 0.012% of events | configuration |
| 4004 | Manual computer policy processing (gpupdate) started | 0.17% of events | configuration |
| 8004 | Manual computer policy processing completed | 0.17% of events | configuration |
| 7004 | Manual computer policy processing failed | 0.001% of events | configuration |
| 4016 | Client-side extension processing started, with applicable GPOs | 30.43% of events | configuration |
| 5016 | Client-side extension processing completed | 30.42% of events | configuration |
| 7016 | Client-side extension processing completed with an error | 0.013% of events | configuration |
Realism Features
- A fleet of 800 workstations and 200 servers applies 10 GPOs. Every host refreshes computer policy every 90 minutes plus a random 0-30 minute offset, the Windows default: intervals have a median of 104-112 minutes and range from about 70 to about 150 minutes, and there are no refreshes while a workstation is switched off. Each refresh has one Activity ID shared by all of its events.
- About 40,000 events a day (+/- 3% from day to day) on a working-day curve in the generator timezone (UTC by default): servers and the 120 workstations left on overnight give about 900 events an hour around the clock; the other 680 workstations switch on between about 07:25 and 08:35 and shut down between about 17:20 and 18:40, a little differently every day, raising the volume to about 2,950 events an hour from 09:00 to 18:00. A workstation gets a new Group Policy service process ID at every start-up while its EventRecordID keeps counting. Every day follows the same curve, with no weekends or holidays, and hourly volume changes in steps at 09:00 and 18:00.
- Each refresh runs the extensions of the host's GPOs that have work (Registry, Security, Audit Policy Configuration, Group Policy Registry, Group Policy Folders, Group Policy Scheduled Tasks, EFS recovery), Registry first and the rest in extension-GUID order; a manual refresh runs all of them, and a refresh is 5.1 events on average. Audit Policy Configuration completes with ErrorCode 2147483658 (E_PENDING), which Microsoft documents as expected. Administrators run gpupdate about 60 times a day, mostly between 09:00 and 18:00, and one run in five is repeated within minutes.
- Security extension errors (7016, ErrorCode 1252) come in short background spells, about three a day: one host fails once (65%) or twice (35%), or one shared cause breaks the next Security run of two hosts that apply the same GPO. A failed refresh ends with 7006/7004 and is often followed within minutes by a manual gpupdate; failed refreshes are about 0.07% of refreshes. The chain is not recognisable from any single event.
- Events of one refresh are further apart than on a real host: a median 1.8 s by day and 4.4 s at night, so a refresh takes a median 15 s by day and 27 s at night, and extension run times are mostly 1-2 s (Security about 4 s) instead of tens of milliseconds.
- Fields, versions, levels, opcodes and messages follow the Windows Server 2022 manifest (gpsvc.dll 10.0.20348) and Microsoft's published 4016 and 7016 Event XML. Version 1 of the refresh events, several EventData values, multi-GPO list concatenation and 7006/7004 after an extension error are inferred; GPOListStatusString is always "No changes were detected." event.category, event.type, event.action and event.outcome are ECS normalisation.
- Only computer policy and these nine event IDs are modelled: other Operational events of a refresh appear as EventRecordID gaps, user logon, start-up, script and connectivity processing are out of scope, and Security errors always carry ErrorCode 1252. On a day with an episode, 7016 and 7006/7004 counts are one to three higher. Rates, extension run shares, durations and the fleet are synthetic.
Sample Output
{
"@timestamp": "2026-09-01T20:16:30.552Z",
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "cse-processing-failed",
"category": [
"configuration"
],
"code": "7016",
"kind": "event",
"original": "\u003cEvent xmlns=\"http://schemas.microsoft.com/win/2004/08/events/event\"\u003e\u003cSystem\u003e\u003cProvider Name=\"Microsoft-Windows-GroupPolicy\" Guid=\"{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}\"/\u003e\u003cEventID\u003e7016\u003c/EventID\u003e\u003cVersion\u003e0\u003c/Version\u003e\u003cLevel\u003e2\u003c/Level\u003e\u003cTask\u003e0\u003c/Task\u003e\u003cOpcode\u003e2\u003c/Opcode\u003e\u003cKeywords\u003e0x4000000000000000\u003c/Keywords\u003e\u003cTimeCreated SystemTime=\"2026-09-01T20:16:30.5526290Z\"/\u003e\u003cEventRecordID\u003e124365\u003c/EventRecordID\u003e\u003cCorrelation ActivityID=\"{EBC0C866-9163-41BD-BDD1-215F596AF73B}\"/\u003e\u003cExecution ProcessID=\"6804\" ThreadID=\"10936\"/\u003e\u003cChannel\u003eMicrosoft-Windows-GroupPolicy/Operational\u003c/Channel\u003e\u003cComputer\u003esrv-rds06.corp.contoso.com\u003c/Computer\u003e\u003cSecurity UserID=\"S-1-5-18\"/\u003e\u003c/System\u003e\u003cEventData\u003e\u003cData Name=\"CSEElaspedTimeInMilliSeconds\"\u003e3024\u003c/Data\u003e\u003cData Name=\"ErrorCode\"\u003e1252\u003c/Data\u003e\u003cData Name=\"CSEExtensionName\"\u003eSecurity\u003c/Data\u003e\u003cData Name=\"CSEExtensionId\"\u003e{827D319E-6EAC-11D2-A4EA-00C04F79F83A}\u003c/Data\u003e\u003c/EventData\u003e\u003c/Event\u003e",
"outcome": "failure",
"provider": "Microsoft-Windows-GroupPolicy",
"type": [
"info"
]
},
"host": {
"name": "srv-rds06.corp.contoso.com"
},
"log": {
"level": "error"
},
"message": "Completed Security Extension Processing in 3024 milliseconds.",
"winlog": {
"activity_id": "{EBC0C866-9163-41BD-BDD1-215F596AF73B}",
"channel": "Microsoft-Windows-GroupPolicy/Operational",
"computer_name": "srv-rds06.corp.contoso.com",
"event_data": {
"CSEElaspedTimeInMilliSeconds": "3024",
"CSEExtensionId": "{827D319E-6EAC-11D2-A4EA-00C04F79F83A}",
"CSEExtensionName": "Security",
"ErrorCode": "1252"
},
"event_id": "7016",
"opcode": "Stop",
"process": {
"pid": 6804,
"thread": {
"id": 10936
}
},
"provider_guid": "{AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9}",
"provider_name": "Microsoft-Windows-GroupPolicy",
"record_id": "124365",
"user": {
"identifier": "S-1-5-18"
},
"version": 0
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Add recurring episodes to the background; false emits background only |
| anomaly_interval_hours | 24 | Hours of event time between episode starts, 12 to 8,760 |
Related Generators
Windows Security Event Log
The Security channel of Windows Event Log — logon/logoff sessions, process creation, privilege escalation, account management, and audit policy changes from a 120-host Active Directory fleet.
Windows PowerShell
PowerShell classic and operational channels — engine lifecycle, script block logging, module invocations, pipeline execution, and provider starts. Includes obfuscated command detection and suspicious script patterns.
Windows Sysmon
Sysmon (System Monitor) operational channel — process creation with full command lines, network connections, file creates, registry modifications, DNS queries, and WMI events. SwiftOnSecurity-style tuning.