{
    "Event": {
        "xmlns": "http://schemas.microsoft.com/win/2004/08/events/event",
        "System": {
            "Provider": {
                "Name": "Microsoft-Windows-Security-Auditing",
                "Guid": "{54849625-5478-4994-a5ba-3e3b0328c30d}"
            },
            "EventID": "4700",
            "Version": "1",
            "Level": "0",
            "Task": "12804",
            "Opcode": "0",
            "Keywords": "0x8020000000000000",
            "TimeCreated": {
                "SystemTime": "2022-07-22T11:03:13.0990543Z"
            },
            "EventRecordID": "3271860",
            "Correlation": {
                "ActivityID": "{2fe8a27a-9da3-0002-dfa2-e82fa39dd801}"
            },
            "Execution": {
                "ProcessID": "1084",
                "ThreadID": "9600"
            },
            "Channel": "Security",
            "Computer": "someuser.somedomain.ru",
            "Security": null
        },
        "EventData": {
            "Data": [
                {
                    "text": "S-1-5-20",
                    "Name": "SubjectUserSid"
                },
                {
                    "text": "SOMEUSER$",
                    "Name": "SubjectUserName"
                },
                {
                    "text": "SOMEDOMAIN",
                    "Name": "SubjectDomainName"
                },
                {
                    "text": "0x3e4",
                    "Name": "SubjectLogonId"
                },
                {
                    "text": "\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTaskLogon",
                    "Name": "TaskName"
                },
                {
                    "text": "<?xml version=\"1.0\" encoding=\"UTF-16\"?>\r\n<Task xmlns=\"http://schemas.microsoft.com/windows/2004/02/mit/task\">\r\n  <RegistrationInfo>\r\n    <Version>1.0</Version>\r\n    <SecurityDescriptor>D:P(A;;FA;;;SY)(A;;FA;;;BA)(A;;FRFW;;;S-1-5-80-123231216-2592883651-3715271367-3753151631-4175906628)(A;;FR;;;S-1-5-4)</SecurityDescriptor>\r\n    <Source>$(@%systemroot%\\system32\\sppc.dll,-200)</Source>\r\n    <Author>$(@%systemroot%\\system32\\sppc.dll,-200)</Author>\r\n    <Description>$(@%systemroot%\\system32\\sppc.dll,-202)</Description>\r\n    <URI>\\Microsoft\\Windows\\SoftwareProtectionPlatform\\SvcRestartTaskLogon</URI>\r\n  </RegistrationInfo>\r\n  <Principals>\r\n    <Principal id=\"InteractiveUser\">\r\n  ClientProcessId    <GroupId>S-1-5-4</GroupId>\r\n    </Principal>\r\n  </Principals>\r\n  <Settings>\r\n    <AllowHardTerminate>false</AllowHardTerminate>\r\n    <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>\r\n    <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>\r\n    <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>\r\n    <Hidden>true</Hidden>\r\n    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>\r\n    <RestartOnFailure>\r\n      <Count>3</Count>\r\n      <Interval>PT1M</Interval>\r\n    </RestartOnFailure>\r\n    <IdleSettings>\r\n      <StopOnIdleEnd>true</StopOnIdleEnd>\r\n      <RestartOnIdle>false</RestartOnIdle>\r\n    </IdleSettings>\r\n    <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine>\r\n  </Settings>\r\n  <Triggers>\r\n    <LogonTrigger />\r\n  </Triggers>\r\n  <Actions Context=\"InteractiveUser\">\r\n    <ComHandler>\r\n      <ClassId>{B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC}</ClassId>\r\n      <Data><![CDATA[logon]]></Data>\r\n    </ComHandler>\r\n  </Actions>\r\n</Task>",
                    "Name": "TaskContent"
                },
                {
                    "text": "12384898975269789",
                    "Name": "ClientProcessStartKey"
                },
                {
                    "text": "8836",
                    "Name": "ClientProcessId"
                },
                {
                    "text": "1076",
                    "Name": "ParentProcessId"
                },
                {
                    "text": "0",
                    "Name": "RpcCallClientLocality"
                },
                {
                    "text": "someuser.somedomain.ru",
                    "Name": "FQDN"
                }
            ]
        }
    }
}