Microsoft-Windows-Application-Experience
116 events across 10 channels
Event ID 50 — PCA was requested to refresh the program cache.
Description
PCA was requested to refresh the program cache.
Message #
Event ID 51 — PCA was informed that the program cache was refreshed.
Description
PCA was informed that the program cache was refreshed.
Message #
Event ID 60 — PCA dialog button response ChainId.
Event ID 70 — PCA triggered SIUF question was asked.
Event ID 71 —
Event ID 72 —
Event ID 73 —
Event ID 74 —
Event ID 75 —
Event ID 76 —
Event ID 77 —
Event ID 78 —
Event ID 79 —
Event ID 80 —
Event ID 81 — PCA triggered SIUF question was answered.
Event ID 100 — The Program Compatibility Assistant was invoked to correct a compatibility problem.
Description
The Program Compatibility Assistant was invoked to correct a compatibility problem. Information about the application is below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name UnicodeString | — |
Application_version UnicodeString | — |
Executable_path UnicodeString | — |
Scenario_ID UnicodeString | — |
User_action UnicodeString | — |
User_action_ID UnicodeString | — |
Compatibility_layer UnicodeString | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
ScenarioId UnicodeString | — |
UserAction UnicodeString | — |
UserActionID UnicodeString | — |
CompatibilityLayer UnicodeString | — |
Event ID 101 — The Program Compatibility Assistant was invoked to correct a compatibility problem.
Event ID 102 — The Program Compatibility Assistant was invoked due to an unsigned driver install.
Event ID 103 — The Program Compatibility Assistant was not invoked because the application has been already handled previously.
Description
The Program Compatibility Assistant was not invoked because the application has been already handled previously. Information about the application is below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name | — |
Application_version | — |
Executable_path | — |
Scenario_ID | — |
User_action | — |
Compatibility_layer | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
ScenarioId UnicodeString | — |
UserAction UnicodeString | — |
UserActionID UnicodeString | — |
CompatibilityLayer UnicodeString | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
Event ID 104 — The Program Compatibility Assistant was not invoked as the application executed correctly.
Description
The Program Compatibility Assistant was not invoked as the application executed correctly. Information about the application is below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name | — |
Application_version | — |
Executable_path | — |
Scenario_ID | — |
User_action | — |
Compatibility_layer | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
ScenarioId UnicodeString | — |
UserAction UnicodeString | — |
UserActionID UnicodeString | — |
CompatibilityLayer UnicodeString | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
Event ID 105 — The Program Compatibility Assistant was invoked to correct a compatibility problem.
Description
The Program Compatibility Assistant was invoked to correct a compatibility problem. Information about the application is below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name UnicodeString | — |
Application_version UnicodeString | — |
Executable_path UnicodeString | — |
Scenarios_code UnicodeString | — |
Deprecated_Components UnicodeString | — |
User_action_ID UnicodeString | — |
Compatibility_layers_recommended UnicodeString | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
ScenarioId UnicodeString | — |
UserAction UnicodeString | — |
UserActionID UnicodeString | — |
CompatibilityLayer UnicodeString | — |
Event ID 201 —
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application-Experience",
"guid": "EEF54E71-0661-422D-9A98-82FD4940B820",
"event_source_name": "",
"event_id": 201,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2013-10-23T16:24:25.239375Z",
"event_record_id": 380,
"correlation": {},
"execution": {
"process_id": 892,
"thread_id": 3532
},
"channel": "System",
"computer": "IE8Win7",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {}
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 206 —
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application-Experience",
"guid": "EEF54E71-0661-422D-9A98-82FD4940B820",
"event_source_name": "",
"event_id": 206,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2013-10-23T22:03:32.528125Z",
"event_record_id": 2787,
"correlation": {},
"execution": {
"process_id": 808,
"thread_id": 2792
},
"channel": "System",
"computer": "IE8Win7",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {}
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 207 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application is excluded in the registry.
Event ID 208 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because of the extension of the executable.
Event ID 209 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the executable has a UAC manifest.
Event ID 210 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application has a compatibility fix applied to...
Event ID 211 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application depends on the Windows Installer s...
Event ID 212 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the executable has a current SwitchBack context.
Event ID 213 — The Program Compatibility Assistant has added ExecutablePath to quarantine.
Event ID 214 — The Program Compatibility Assistant has removed ExecutablePath from quarantine.
Event ID 215 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the executable has a UAC manifest.
Event ID 300 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the PCA is disabled by group policy.
Event ID 301 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application already exists within a job object.
Event ID 302 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application is a 64-bit application.
Event ID 303 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application is on a network path.
Event ID 304 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application compatibility infrastructure is di...
Event ID 305 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application is protected by Windows Resource P...
Event ID 306 — The Program Compatibility Assistant was requested to monitor ExecutablePath, but ignored the request because the application has been excluded from the PCA by ...
Event ID 400 — The Program Compatibility Assistant attempted to connect an event for process ID ProcessId, but the Program Compatibility Assistant service was unable to ...
Event ID 500 — Compatibility fix applied to CompatibilityFixEvent.ExePath.
#Description
Compatibility fix applied to CompatibilityFixEvent.ExePath.
Message #
Fields #
| Name | Description |
|---|---|
CompatibilityFixEvent.ProcessId | — |
CompatibilityFixEvent.StartTime | — |
CompatibilityFixEvent.FixID | — |
CompatibilityFixEvent.Flags | — |
CompatibilityFixEvent.ExePath | — |
CompatibilityFixEvent.FixName | Fix information. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application-Experience",
"guid": "EEF54E71-0661-422D-9A98-82FD4940B820",
"event_source_name": "",
"event_id": 500,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423488,
"time_created": "2023-11-06T02:01:06.316061+00:00",
"event_record_id": 268,
"correlation": {},
"execution": {
"process_id": 10532,
"thread_id": 16892
},
"channel": "Microsoft-Windows-Application-Experience/Program-Telemetry",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"user_data": {
"CompatibilityFixEvent": {
"ProcessId": 10532,
"StartTime": 1699236066.0862,
"FixID": "AD24F32A-1C4D-4D71-AF4E-1D9031C04F14",
"Flags": 65793,
"ExePath": "C:\\Program Files (x86)\\OpenOffice 4\\program\\soffice.bin",
"FixName": "Apache OpenOffice"
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 501 — Compatibility fix applied to Flags.
Event ID 502 — Compatibility fix applied to PackageCode.
Event ID 503 — Compatibility fix applied to PackageCode.
Event ID 504 — PCA was informed about fix FixName applied to process.
Event ID 505 — Compatibility fix applied to CompatibilityFixEvent.ExePath.
#Description
Compatibility fix applied to CompatibilityFixEvent.ExePath.
Message #
Fields #
| Name | Description |
|---|---|
CompatibilityFixEvent.ProcessId | — |
CompatibilityFixEvent.StartTime | — |
CompatibilityFixEvent.FixID | — |
CompatibilityFixEvent.Flags | — |
CompatibilityFixEvent.ExePath | — |
CompatibilityFixEvent.FixName | Fix information. |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application-Experience",
"guid": "EEF54E71-0661-422D-9A98-82FD4940B820",
"event_source_name": "",
"event_id": 505,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 576460752303423488,
"time_created": "2023-11-06T01:51:42.489178+00:00",
"event_record_id": 265,
"correlation": {},
"execution": {
"process_id": 21364,
"thread_id": 8156
},
"channel": "Microsoft-Windows-Application-Experience/Program-Telemetry",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
}
},
"user_data": {
"CompatibilityFixEvent": {
"ProcessId": 21364,
"StartTime": 1699235502.3153903,
"FixID": "6F36AB95-595F-497D-9001-86DAD299B6FA",
"Flags": 2147549701,
"ExePath": "C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe",
"FixName": "AppDefaults"
}
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 600 — An instance of the Steps Recorder ran with the following information.
Description
An instance of the Steps Recorder ran with the following information.
Message #
Fields #
| Name | Description |
|---|---|
StartTime FILETIME | [An instance of the Steps Recorder ran with the following information] StartTime. |
StopTime FILETIME | [An instance of the Steps Recorder ran with the following information] StopTime. |
Action_Count UInt32 | [An instance of the Steps Recorder ran with the following information] Action Count. |
Missed_Action_Count UInt32 | [An instance of the Steps Recorder ran with the following information] Missed Action Count. |
Output_file_location UnicodeString | [An instance of the Steps Recorder ran with the following information] Output file location. |
ActionCount UInt32 | — |
MissedActionCount UInt32 | — |
OutputFileLocation UnicodeString | — |
Event ID 601 — An instance of the Steps Recorder terminated with the following error code: ErrorCode.
Event ID 700 — The Application Impact Telemetry (AIT) Agent terminated with the following error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent terminated with the following error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 701 — The Application Impact Telemetry (AIT) Agent is not running because AIT is disabled.
Description
The Application Impact Telemetry (AIT) Agent is not running because AIT is disabled.
Message #
Event ID 702 — The Application Impact Telemetry (AIT) Agent is stopping because another instance is already running.
Description
The Application Impact Telemetry (AIT) Agent is stopping because another instance is already running.
Message #
Event ID 703 — The Application Impact Telemetry (AIT) Agent was unable to parse the command-line options with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to parse the command-line options with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 704 — The Application Impact Telemetry (AIT) Agent was unable to process the logs files with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to process the logs files with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 705 — The Application Impact Telemetry (AIT) Agent was unable to start application impact SQM with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to start application impact SQM with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 706 — The Application Impact Telemetry (AIT) Agent was unable to log application impact data to SQM with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to log application impact data to SQM with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 707 — The Application Impact Telemetry (AIT) Agent was unable to start system telemetry with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to start system telemetry with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 708 — The Application Impact Telemetry (AIT) Agent was unable to log system telemetry data to SQM with error code: FailureCode.
Description
The Application Impact Telemetry (AIT) Agent was unable to log system telemetry data to SQM with error code: FailureCode.
Message #
Fields #
| Name | Description |
|---|---|
FailureCode HexInt32 | — NTSTATUS reference |
Event ID 800 — An instance of Program Data Updater (PDU) ran with the following information: StartTime: {StartTime}; StopTime: {StopTime}; ExitCode: {ExitCode}; N...
Event ID 900 — An Internet Explorer add-on was installed on the system.
Event ID 901 — An Internet Explorer add-on was updated on the system.
Event ID 902 — An Internet Explorer add-on was removed from the system.
Event ID 903 — A program was installed on the system.
Event ID 904 — A program was installed on the system.
Event ID 905 — A program was updated on the system.
Event ID 906 — A program was updated on the system.
Event ID 907 — A program was removed from the system.
Event ID 908 — A program was removed from the system.
Event ID 909 — AMI cache update failure.
Event ID 910 —
Fields #
| Name | Description |
|---|---|
ProgramID UnicodeString | — |
Name UnicodeString | — |
Publisher UnicodeString | — |
Version UnicodeString | — |
Language UnicodeString | — |
ProgramType UnicodeString | — |
Event ID 911 —
Fields #
| Name | Description |
|---|---|
ProgramID UnicodeString | — |
FilePath UnicodeString | — |
Event ID 1003 — Installer cancel click detected.
Event ID 1004 — InstallerShield detected.
Event ID 1005 — File installed.
Event ID 1006 — New arp key.
Event ID 1100 — DirectX detection: HighDPIAware.
Event ID 1101 — DirectX detection: MaximizedWindowedMode.
Event ID 1102 — DirectX detection: AdaptWindowToDisplayMode.
Event ID 2001 — The Application Impact Telemetry (AIT) Static Analysis tool ran with the following results.
Description
The Application Impact Telemetry (AIT) Static Analysis tool ran with the following results.
Message #
Fields #
| Name | Description |
|---|---|
cchIdAnalyzedIncludingNull UInt16 | — |
cchProgramIdIncludingNull UInt16 | — |
ExitCode UInt32 | — |
IdTypeAnalyzed UInt32 | — |
NumFilesAnalyzed UInt32 | — |
NumFilesFailed UInt32 | — |
StartTime FILETIME | — |
StopTime FILETIME | — |
RunTime UInt64 | — |
IdAnalyzed UnicodeString | — |
ProgramId UnicodeString | — |
Event ID 2003 — The Application Impact Telemetry (AIT) Static Analysis tool ran with the following results.
Description
The Application Impact Telemetry (AIT) Static Analysis tool ran with the following results.
Message #
Fields #
| Name | Description |
|---|---|
cchIdAnalyzedIncludingNull UInt16 | — |
cchProgramIdIncludingNull UInt16 | — |
ExitCode UInt32 | — |
IdTypeAnalyzed UInt32 | — |
NumFilesAnalyzed UInt32 | — |
NumFilesFailed UInt32 | — |
StartTime FILETIME | — |
StopTime FILETIME | — |
RunTime UInt64 | — |
IdAnalyzed UnicodeString | — |
ProgramId UnicodeString | — |
Event ID 2005 — QuirkName.
Event ID 5001 — The Program Compatibility Troubleshooter was invoked to correct a compatibility problem.
Description
The Program Compatibility Troubleshooter was invoked to correct a compatibility problem. Information about the application is below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name UnicodeString | — |
Application_version UnicodeString | — |
Executable_path UnicodeString | — |
Scenario_ID UnicodeString | — |
Result UnicodeString | — |
Result_ID UnicodeString | — |
Compatibility_layer UnicodeString | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
ScenarioId UnicodeString | — |
ResultID UnicodeString | — |
CompatibilityLayer UnicodeString | — |
Event ID 5002 — The Program Compatibility Troubleshooter queried the Compatibility Online Service for information about an application.
Description
The Program Compatibility Troubleshooter queried the Compatibility Online Service for information about an application. Results are below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name UnicodeString | — |
Application_version UnicodeString | — |
Executable_path UnicodeString | — |
Recommended_layer UnicodeString | — |
URL UnicodeString | — |
Compatibility_status UInt32 | — |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
RecommendedLayer UnicodeString | — |
CompatStatus UInt32 | — |
Event ID 5003 — The Program Compatibility Troubleshooter queried the application genome for information about an application.
Description
The Program Compatibility Troubleshooter queried the application genome for information about an application. Results are below.
Message #
Fields #
| Name | Description |
|---|---|
Application_name UnicodeString | — |
Application_version UnicodeString | — |
Executable_path UnicodeString | — |
Recommended_layer UnicodeString | — |
Vista UInt32 | Vista+. |
FileID UnicodeString | — |
ProgramID UnicodeString | — |
ApplicationName UnicodeString | — |
ApplicationVersion UnicodeString | — |
ExecutablePath UnicodeString | — |
RecommendedLayer UnicodeString | — |
VistaPlus UInt32 | — |
Event ID 5004 — Program Compatibility Troubleshooter debug event.
Event ID 8000 — Detector shim: SHORT_RUN_TIME.
Event ID 8001 — Detector shim: ACCESS_DENIED.
Event ID 8002 — Detector shim: BLACK_SCREEN.
Event ID 8003 — Detector shim: WIN32_EXCEPTION: ExtraDataSize.
Event ID 8004 — Detector shim: GLOBAL_OBJECT.
Event ID 8005 — Detector shim: PRIVILEGE_CHECK.
Event ID 8006 — Detector shim: MESSAGE_BOX_VERSION.
Event ID 8007 — Detector shim: MESSAGE_BOX_PRIVILEGE.
Event ID 8008 — Detector shim: MESSAGE_BOX_ERROR_ICON.
Event ID 8010 — Detector shim: REG_EXPAND_SZ.
Event ID 8011 — Detector shim: DWM_8AND16_MODE.
Event ID 8012 — Detector shim: KERNEL_DRIVER.
Event ID 16000 —
Fields #
| Name | Description |
|---|---|
Name UnicodeString | — |
CommandLine UnicodeString | — |
RoutingMode UnicodeString | — |
Class UnicodeString | — |
HostDll UnicodeString | — |
InExMode UnicodeString | — |
InExIncludes UnicodeString | — |
InExExcludes UnicodeString | — |
Event ID 16001 —
Fields #
| Name | Description |
|---|---|
Name UnicodeString | — |
Type UnicodeString | — |
Event ID 16002 —
Fields #
| Name | Description |
|---|---|
Name UnicodeString | — |
Event ID 16003 —
Fields #
| Name | Description |
|---|---|
Name UnicodeString | — |
CommandLine UnicodeString | — |
Enabled Boolean | — |
Event ID 16010 —
Fields #
| Name | Description |
|---|---|
ModuleToHook UnicodeString | — |
HookModule AnsiString | — |
HookApi AnsiString | — |
Hooked Boolean | — |
Reason UnicodeString | — |
Event ID 16011 —
Fields #
| Name | Description |
|---|---|
Name UnicodeString | — |
Patched Boolean | — |
Reason UnicodeString | — |
Event ID 16012 —
Fields #
| Name | Description |
|---|---|
Class UnicodeString | — |
Interface UnicodeString | — |
ApiIndex UInt32 | — |
Hooked Boolean | — |
Reason UnicodeString | — |
Event ID 16100 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
Message AnsiString | — |
Event ID 16101 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
Message AnsiString | — |
Event ID 16102 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
Message AnsiString | — |
Event ID 16103 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
Message AnsiString | — |
Event ID 16110 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
ModuleName AnsiString | — |
ApiName AnsiString | — |
Info AnsiString | — |
Event ID 16111 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
ModuleName AnsiString | — |
ApiName AnsiString | — |
Info AnsiString | — |
Event ID 16112 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
ModuleName AnsiString | — |
ApiName AnsiString | — |
Info AnsiString | — |
Event ID 16113 —
Fields #
| Name | Description |
|---|---|
ShimName AnsiString | — |
ModuleName AnsiString | — |
ApiName AnsiString | — |
Info AnsiString | — |