Microsoft-Windows-AppReadiness
174 events across 3 channels
Event ID 10 — The Appx operation '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Operation | — |
PackageId | — |
Result | 5. (Error. |
Error | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 10
version: 0
level: 2
task: 6
opcode: 0
keywords: 9223372036854775936
time_created: '2023-11-05T22:29:17.204020+00:00'
event_record_id: 445
correlation:
ActivityID: 59A0D65F-1037-0001-E4F0-A0593710DA01
execution:
process_id: 5660
thread_id: 5712
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-21-1992711665-1655669231-58201500-1000
Operation: RegisterPackageAsync
PackageId: Microsoft.VCLibs.140.00_14.0.30704.0_x64__8wekyb3d8bbwe
Result: -2147009274
Error: Windows cannot install package Microsoft.VCLibs.140.00_14.0.30704.0_x64__8wekyb3d8bbwe
because it has version 14.0.30704.0. A higher version 14.0.32530.0 of this package
is already installed.
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 11 — A exception was caught.
Message
Fields
| Name | Description |
|---|---|
Error | A exception was caught. |
Expression | — |
Function | — |
File | — |
Line | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 11
version: 0
level: 3
task: 6
opcode: 0
keywords: 4611686018427388032
time_created: '2023-11-05T22:33:30.809965+00:00'
event_record_id: 23
correlation:
ActivityID: E4DB489E-1037-0002-3975-DBE43710DA01
execution:
process_id: 4952
thread_id: 7936
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Error: "2\0\a�"
Expression: result
Function: AppReadiness::Tasks::RegisterPackage::OnExecute
File: onecoreuap\shell\appreadiness\src\tasks\registerpackage.cpp
Line: "\x1A\x01"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 12 — The Appx preview tile generation failed for user '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Error | — |
Result | — |
Event ID 100 — App Readiness service has started.
Message
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 100
version: 0
level: 4
task: 13
opcode: 1
keywords: 9223372036854775809
time_created: '2023-10-26T04:21:52.496522+00:00'
event_record_id: 10
correlation: {}
execution:
process_id: 1844
thread_id: 1960
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 101 — App Readiness service has stopped.
Message
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 101
version: 0
level: 4
task: 13
opcode: 2
keywords: 9223372036854775809
time_created: '2023-10-26T04:20:51.148587+00:00'
event_record_id: 9
correlation: {}
execution:
process_id: 2956
thread_id: 788
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 102 —
Event ID 103 —
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 103
version: 0
level: 4
task: 14
opcode: 2
keywords: 4611686018427387905
time_created: '2023-11-05T23:51:40.799865+00:00'
event_record_id: 31
correlation: {}
execution:
process_id: 10560
thread_id: 3968
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 104 — App Readiness status changed to '.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ExitCode | — |
Event ID 105 — Checking for service idle.
Message
Fields
| Name | Description |
|---|---|
IsIdle | — |
Reason | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 105
version: 0
level: 4
task: 7
opcode: 0
keywords: 4611686018427387905
time_created: '2023-11-05T23:51:40.726163+00:00'
event_record_id: 30
correlation: {}
execution:
process_id: 10560
thread_id: 3968
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsIdle: true
Reason: None
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 106 — '.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 106
version: 0
level: 4
task: 7
opcode: 0
keywords: 4611686018427387905
time_created: '2023-10-25T21:23:46.541840+00:00'
event_record_id: 3
correlation: {}
execution:
process_id: 1844
thread_id: 1848
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-2533829718-189860685-2477588761-500
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 107 — '.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 107
version: 0
level: 4
task: 7
opcode: 0
keywords: 4611686018427387905
time_created: '2023-11-05T22:31:33.744555+00:00'
event_record_id: 20
correlation: {}
execution:
process_id: 5660
thread_id: 5664
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-1992711665-1655669231-58201500-1000
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 108 —
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 108
version: 0
level: 4
task: 17
opcode: 1
keywords: 4611686018427387905
time_created: '2023-11-05T23:49:11.255658+00:00'
event_record_id: 29
correlation: {}
execution:
process_id: 10560
thread_id: 5420
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: Source
Value: 2
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 109 — App Readiness service has been notified of new apps.
Message
Fields
| Name | Description |
|---|---|
Source | App Readiness service has been notified of new apps. (Source. |
Result | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 109
version: 0
level: 4
task: 17
opcode: 2
keywords: 9223372036854775809
time_created: '2023-10-26T04:18:47.728320+00:00'
event_record_id: 4
correlation: {}
execution:
process_id: 2956
thread_id: 1308
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
Source: 2
Result: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 110 — App Readiness service has leaked %1 references.
Message
Fields
| Name | Description |
|---|---|
ReferencesLeaked | — |
ShutdownDelayMsec | — |
Event ID 111 — App Readiness service failed to DisconnectAll COM Disconnectable Objects.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 200 — Started processing tasks for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 201 — Finished processing tasks for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 205 — Loaded queue for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
NumPackages | — |
PackageInfo | — |
Event ID 206 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Priority | — |
Event ID 207 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Result | — |
Event ID 209 — For '.
Message
Fields
| Name | Description |
|---|---|
User | — |
From | — |
To | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 209
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-26T04:20:51.133929+00:00'
event_record_id: 8
correlation: {}
execution:
process_id: 2956
thread_id: 788
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
User: S-1-5-18
From: 2
To: 3
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 210 — App Readiness service has found new tasks for %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 210
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-25T21:40:47.762141+00:00'
event_record_id: 325
correlation: {}
execution:
process_id: 5240
thread_id: 5296
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-2533829718-189860685-2477588761-500
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 211 — App Readiness service has completed tasks for %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 211
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-26T04:18:47.728560+00:00'
event_record_id: 7
correlation: {}
execution:
process_id: 2956
thread_id: 700
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-18
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 212 — %2 pre-installed apps found for %1.
Message
Fields
| Name | Description |
|---|---|
SID | — |
NumPackages | — |
PackageFamilyName | — |
Event ID 213 — '.
Message
Fields
| Name | Description |
|---|---|
Username | — |
Package | — |
Operation | — |
Elapsed | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 213
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-25T21:40:47.742338+00:00'
event_record_id: 323
correlation: {}
execution:
process_id: 5240
thread_id: 5296
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Username: S-1-5-21-2533829718-189860685-2477588761-500
Package: CanonicalGroupLimited.UbuntuonWindows_79rhkp1fndgsc
Operation: 1
Elapsed: f���f��?
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 214 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Package | — |
Operation | — |
Error | — |
Elapsed | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 214
version: 0
level: 2
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-11-05T22:33:30.819207+00:00'
event_record_id: 604
correlation: {}
execution:
process_id: 4952
thread_id: 2436
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-21-1992711665-1655669231-58201500-1000
Package: Microsoft.MicrosoftEdge.Stable_8wekyb3d8bbwe
Operation: 1
Error: -2147024846
Elapsed: '0.2400311'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 215 — '.
Message
Fields
| Name | Description |
|---|---|
Username | — |
Task | — |
Error | — |
Elapsed | — |
Event ID 216 — Activity for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ResumeAt | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 216
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-25T21:39:08.142987+00:00'
event_record_id: 207
correlation: {}
execution:
process_id: 5240
thread_id: 5308
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-21-2533829718-189860685-2477588761-500
ResumeAt: 1698244778.141
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 217 — Activity for '.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 217
version: 0
level: 4
task: 1
opcode: 0
keywords: 4611686018427387906
time_created: '2023-11-05T22:33:01.409803+00:00'
event_record_id: 22
correlation: {}
execution:
process_id: 4952
thread_id: 5104
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-1992711665-1655669231-58201500-1000
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 218 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Package | — |
Operation | — |
Error | — |
AttemptAfter | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 218
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-11-05T22:33:30.819200+00:00'
event_record_id: 602
correlation: {}
execution:
process_id: 4952
thread_id: 2436
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-21-1992711665-1655669231-58201500-1000
Package: Microsoft.MicrosoftEdge.Stable_8wekyb3d8bbwe
Operation: 1
Error: -2147024846
AttemptAfter: '2023-11-05T22:38:30.805815Z'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 219 — %2 pre-installed apps found for %1.
Message
Fields
| Name | Description |
|---|---|
SID | — |
NumPackages | — |
PackageFamilyName | — |
Event ID 220 — '.
Message
Fields
| Name | Description |
|---|---|
Username | — |
Task | — |
Elapsed | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 220
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775810
time_created: '2023-10-26T04:22:06.119006+00:00'
event_record_id: 13
correlation: {}
execution:
process_id: 1844
thread_id: 2164
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Username: S-1-5-18
Task: ART:AppxPreRegistration
Elapsed: "�/E^{\x13\x14@"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 221 — Task '.
Message
Fields
| Name | Description |
|---|---|
Username | — |
Task | — |
Event ID 222 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
OpposingOperation | — |
TaskCanceled | — |
Event ID 223 — Shutdown for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 224 — Shutdown for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 225 — Canceling '.
Message
Fields
| Name | Description |
|---|---|
Username | — |
Task | — |
Event ID 226 — During shutdown '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 227 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Priority | — |
Event ID 228 — '.
Message
Fields
| Name | Description |
|---|---|
Task | — |
Elapsed | — |
Event ID 229 — '.
Message
Fields
| Name | Description |
|---|---|
TaskId | — |
Priority | — |
Event ID 230 — App Readiness service has completed all tasks for user.
Message
Event ID 231 — FWOpenPolicyStore starts.
Message
Event ID 232 — FWOpenPolicyStore returns %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 232
version: 0
level: 4
task: 1
opcode: 2
keywords: 9223372036854775810
time_created: '2023-10-25T21:39:04.309206+00:00'
event_record_id: 148
correlation: {}
execution:
process_id: 5240
thread_id: 5308
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Data:
Name: ExitCode
Value: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 233 — FWClosePolicyStore starts.
Message
Event ID 234 — FWClosePolicyStore returns %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 234
version: 0
level: 4
task: 1
opcode: 2
keywords: 9223372036854775810
time_created: '2023-10-25T21:39:15.324728+00:00'
event_record_id: 213
correlation: {}
execution:
process_id: 5240
thread_id: 5308
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Data:
Name: ExitCode
Value: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 235 — OnDemandRegisterAsync starts.
Message
Event ID 236 — OnDemandRegisterAsync returns %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 236
version: 0
level: 4
task: 1
opcode: 2
keywords: 9223372036854775812
time_created: '2023-10-25T21:39:06.662792+00:00'
event_record_id: 149
correlation:
ActivityID: 8865F308-078B-0002-72FE-65888B07DA01
execution:
process_id: 5240
thread_id: 5296
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-21-2533829718-189860685-2477588761-500
event_data:
Data:
Name: ExitCode
Value: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 237 — OnDemandRegisterWaitForCompletion starts.
Message
Event ID 238 — OnDemandRegisterWaitForCompletion returns %1.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 238
version: 0
level: 4
task: 1
opcode: 2
keywords: 9223372036854775812
time_created: '2023-10-25T21:39:08.044160+00:00'
event_record_id: 150
correlation:
ActivityID: 8865F308-078B-0002-72FE-65888B07DA01
execution:
process_id: 5240
thread_id: 5296
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-21-2533829718-189860685-2477588761-500
event_data:
Data:
Name: ExitCode
Value: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 239 — OnDemandRegister returns error %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Event ID 240 — Task '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
TaskCount | 1, tasks. |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 240
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775812
time_created: '2023-10-26T04:21:59.768043+00:00'
event_record_id: 11
correlation: {}
execution:
process_id: 1844
thread_id: 2072
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-18
TaskId: ART:AppxPreRegistration
TaskCount: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 241 — Task '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
TaskCount | 1, tasks. |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 241
version: 0
level: 4
task: 1
opcode: 0
keywords: 9223372036854775812
time_created: '2023-10-26T04:22:06.119005+00:00'
event_record_id: 12
correlation: {}
execution:
process_id: 1844
thread_id: 2164
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
User: S-1-5-18
TaskId: ART:AppxPreRegistration
TaskCount: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — Started '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Event ID 301 — Finished '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Result | — |
Duration | — |
Event ID 302 — Started group '.
Message
Fields
| Name | Description |
|---|---|
User | — |
GroupId | — |
Event ID 303 — Finished group '.
Message
Fields
| Name | Description |
|---|---|
User | — |
GroupId | — |
Result | — |
Duration | — |
Event ID 304 — During execution of '.
Message
Fields
| Name | Description |
|---|---|
User | — |
GroupId | — |
TaskId | — |
Result | — |
Event ID 305 — Package '.
Message
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Reason | — |
Event ID 306 — For '.
Message
Fields
| Name | Description |
|---|---|
User | — |
TaskId | — |
Event ID 307 — Finished activation of '.
Message
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Reason | — |
Event ID 308 — Preview tile creation failed '.
Message
Fields
| Name | Description |
|---|---|
Error | — |
User | — |
PackageFamilyName | — |
Source | — |
Result | — |
Event ID 309 — Starting registry flush for '.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 309
version: 0
level: 4
task: 2
opcode: 1
keywords: 4611686018427387908
time_created: '2023-11-05T22:29:25.993515+00:00'
event_record_id: 17
correlation: {}
execution:
process_id: 5660
thread_id: 5744
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-1992711665-1655669231-58201500-1000
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 310 — Finished registry flush for '.
Message
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 310
version: 0
level: 4
task: 2
opcode: 2
keywords: 4611686018427387908
time_created: '2023-11-05T22:29:26.031718+00:00'
event_record_id: 18
correlation: {}
execution:
process_id: 5660
thread_id: 5744
channel: Microsoft-Windows-AppReadiness/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Data:
Name: User
Value: S-1-5-21-1992711665-1655669231-58201500-1000
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 311 — Failed to flush registry key '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Key | — |
Result | — |
Event ID 312 — Successfully created %3 preview tiles for %1.
Message
Fields
| Name | Description |
|---|---|
User | — |
Source | — |
NumPackages | — |
PackageFamilyName | — |
Event ID 313 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Group | — |
Task | — |
Event ID 314 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
Group | — |
Task | — |
Event ID 315 — '.
Message
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Reason | — |
Event ID 316 — Installing '.
Message
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Event ID 317 — Starting pre-registration of '.
Message
Fields
| Name | Description |
|---|---|
PackageId | — |
Event ID 318 — Completed pre-registration of '.
Message
Fields
| Name | Description |
|---|---|
PackageId | — |
Event ID 319 — Pre-registration for '.
Message
Fields
| Name | Description |
|---|---|
PackageId | — |
Result | 1' failed. (Error. |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 319
version: 0
level: 2
task: 23
opcode: 0
keywords: 9223372036854775812
time_created: '2023-11-05T22:33:30.809891+00:00'
event_record_id: 601
correlation:
ActivityID: E4DB489E-1037-0002-3975-DBE43710DA01
execution:
process_id: 4952
thread_id: 7936
channel: Microsoft-Windows-AppReadiness/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PackageId: Microsoft.MicrosoftEdge.Stable_118.0.2088.61_neutral__8wekyb3d8bbwe
Result: -2147024846
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 320 — Failed to flush registry key '.
Message
Fields
| Name | Description |
|---|---|
Key | — |
Result | — |
Event ID 321 — OnDemandRegisterAsync starts.
Message
Event ID 322 — OnDemandRegisterAsync returns %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 322
version: 0
level: 4
task: 2
opcode: 2
keywords: 9223372036854775812
time_created: '2022-04-07T16:48:31.584808+00:00'
event_record_id: 69
correlation:
ActivityID: DD7B0B6A-4A9E-0000-8126-7BDD9E4AD801
execution:
process_id: 2304
thread_id: 4244
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ExitCode: '0x0'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 323 — OnDemandRegisterWaitForCompletion starts.
Message
Event ID 324 — OnDemandRegisterWaitForCompletion returns %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Example Event
system:
provider: Microsoft-Windows-AppReadiness
guid: F0BE35F8-237B-4814-86B5-ADE51192E503
event_source_name: ''
event_id: 324
version: 0
level: 4
task: 2
opcode: 2
keywords: 9223372036854775812
time_created: '2022-04-07T16:48:31.708898+00:00'
event_record_id: 70
correlation:
ActivityID: DD7B0B6A-4A9E-0000-8126-7BDD9E4AD801
execution:
process_id: 2304
thread_id: 4244
channel: Microsoft-Windows-AppReadiness/Admin
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ExitCode: '0x0'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 325 — OnDemandRegister returns error %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Event ID 326 — OnDemandRegisterAsync starts.
Message
Event ID 327 — OnDemandRegisterAsync returns %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Event ID 328 — OnDemandRegisterWaitForCompletion starts.
Message
Event ID 329 — OnDemandRegisterWaitForCompletion returns %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Event ID 330 — OnDemandRegister returns error %1.
Message
Fields
| Name | Description |
|---|---|
ExitCode | — |
Event ID 331 — Importing package status for user %1 completed with hr=%2.
Message
Fields
| Name | Description |
|---|---|
userSid | — |
Result | — |
numImported | — |
numFailed | — |
Event ID 332 — Task '.
Message
Fields
| Name | Description |
|---|---|
PackageFullName | — |
TaskType | — |
Event ID 1001 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1002 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1003 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1004 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1005 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1006 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1009 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1010 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1013 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1014 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1015 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1016 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1017 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1018 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1019 — API Enter for '.
Message
Fields
| Name | Description |
|---|---|
User | — |
ProcessId | — |
Event ID 1020 — API Exit for '.
Message
Fields
| Name | Description |
|---|---|
Result | 1' (Process. |
User | — |
ProcessId | — |
Event ID 1021 — DisableInAuditMode registry value set to block API calls while in audit mode (audit mode: %1).
Message
Fields
| Name | Description |
|---|---|
IsAuditMode | — |
Event ID 2000 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Event ID 2001 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2002 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2003 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2005 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2006 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2007 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2008 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2009 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2010 —
Fields
| Name | Description |
|---|---|
User | — |
PackageFamilyName | — |
Score | — |
Event ID 2500 —
Fields
| Name | Description |
|---|---|
User | — |
Event ID 2501 —
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 2502 —
Fields
| Name | Description |
|---|---|
User | — |
Package | — |
Result | — |
Event ID 2503 —
Fields
| Name | Description |
|---|---|
User | — |
Package | — |
Result | — |
Event ID 2504 —
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 3000 —
Fields
| Name | Description |
|---|---|
TaskId | — |
Event ID 3001 —
Fields
| Name | Description |
|---|---|
TaskId | — |
Event ID 4000 —
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 4001 —
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 5000 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5001 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5002 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5003 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5004 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5005 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5006 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5007 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5008 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5009 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5010 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5011 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5012 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5013 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5014 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5015 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5016 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5017 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5018 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5019 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5020 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5021 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5022 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5023 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5024 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5025 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5026 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5027 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5028 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5029 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5030 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5031 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5032 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5033 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5034 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5035 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5036 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5037 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5038 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5039 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5040 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5041 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5042 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5043 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5044 — %1 : failed determine if tiles are missing.
Message
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 5045 — %1 : failed to repair missing tiles.
Message
Fields
| Name | Description |
|---|---|
User | — |
Result | — |
Event ID 5046 — %1 : missing tiles detected.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 5047 — %1 : missing tiles repaired.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 5048 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5049 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5050 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |
Event ID 5051 —
Fields
| Name | Description |
|---|---|
UserId | — |
PackageFamilyName | — |
ActivityId | — |