About
Why this site exists
Vendor documentation tells you what an event is. It almost never tells you whether you should care. That gap is the whole reason Log Dejargonizer exists.
What you will find here
98 entries, each covering one log line or event ID. Every entry answers the same questions in the same order: what the line means in plain words, how worried to be, the ordinary reasons it happens, the less ordinary ones, and what to actually do next.
Ordinary explanations come before alarming ones, deliberately. Most people reading a log entry arrived worried, and most of the time the answer is that nothing is wrong.
Who it is for
Two people, on the same page. Someone who opened Event Viewer, saw something red, and wants to know whether their computer is dying. And someone triaging an alert who wants the field table, a query they can paste, and to get on with their day. Each entry is written so both can find what they came for without wading through the other's half.
How entries are researched
Descriptions are written from scratch rather than copied from vendor documentation, and every entry links out to the vendor's own page so you can check the primary source. Sample log lines are fabricated and sanitised — addresses come from the RFC 5737 documentation ranges, hostnames are fictional, and hashes are zeroed. Nothing here is taken from a real capture.
Entries carry the date they were last reviewed. Log formats and vendor guidance change, and an entry that has not been looked at in a year should be read with that in mind.
What this site does not do
It does not scan anything, connect to anything, or ask you to install anything. It is a reference work. There is no offensive tooling here and no instruction in attacking systems — everything is framed around understanding your own logs and defending your own machines.
Corrections
If an entry is wrong, incomplete, or unclear, please say so. Corrections are the fastest way this gets better — see the contact page.