Microsoft-Windows-Bits-Client

114 events across 3 channels

Event IDTitleChannel
0Analytic
1BITS job ".Operational
2BITS job ".Operational
3The BITS service created a new job.Operational
4The transfer job is complete.Operational
5Job cancelled.Operational
6Command-line command set for job %1 with owner %2.Operational
10BITS started listening for peer-client requests.Analytic
11BITS was not able to listen for peer-client requests.Analytic
12BITS stopped listening for peer-client requests.Analytic
13BITS started listening for peer-server announcements.Analytic
14BITS was not able to listen for peer-server announcements.Analytic
15BITS stopped listening for peer-server announcements.Analytic
16BITS has sent an inquiry for peer servers.Analytic
17BITS has read the policy parameters for peer-caching.Operational
18The peer list rejected an incoming server announcement.Operational
19A new peer was added.Analytic
20A peer was updated.Analytic
21A peer was removed from the peer list.Analytic
22A cached peer was restored from disk.Analytic
23An application cleared the peer list.Operational
24BITS has replied to a client's inquiry for peer servers.Analytic
25The server received a peer inquiry but rejected it.Analytic
27A peer search for an URL has begun.Analytic
28A peer search ended.Analytic
29A search request is being sent.Analytic
30A search request has completed.Analytic
31A search request has completed unsuccessfully.Analytic
32The peer's record %2 matched the request.Analytic
33BITS updated the set of IP addresses used for peer-caching.Analytic
34Job cannot be transferred because job transfer cost policy preventing it.Analytic
37The cost state has changed.Analytic
59BITS started the %2 transfer job that is associated with the %4 URL.Operational
60BITS stopped transferring the %2 transfer job that is associated with the %4 …Operational
61BITS stopped transferring the %2 transfer job that is associated with the %4 …Operational
62The BITS job named ".Operational
63The BITS job %1 is configured to launch %3 after transfer of %2.Operational
64The BITS job %1 is configured to launch %3 after transfer of %2.Operational
70BITS received a peer-cache request from a client at address %1.Analytic
71The client's search request is for ".Analytic
72The cache found a matching cache record with ID %1.Analytic
73While processing the client's request, BITS encountered error %1.Analytic
74BITS rejected the client's request with HTTP status %1.Analytic
75BITS has finished processing the client request.Analytic
76The request includes the client's event-log activity ID.Analytic
77BITS search for peer-servers has started.Analytic
78BITS has encountered %1 error while reading the peer-cache information.Operational
79BITS has successfully deleted the peer-cache.Operational
80BITS has successfully enabled peer-client and/or peer-server related components.Operational
81BITS has encountered %1 error while starting one or more peer-client or …Operational
82BITS accessed group policy value %1 : %2.Analytic
83BITS defaulted group policy value %1 : %2.Analytic
101The peer's response to a search was invalid.Analytic
102The file ranges associated with a transfer attemptAnalytic
200While transferring %1, BITS encountered error %2 using %3 as the HTTP proxy …Analytic
201The BITS job named ".Operational
202While transferring %1, BITS encountered error %7 using %6 as the HTTP proxy …Operational
203The BITS service provided job credentials in response to an authentication …Operational
204The BITS service provided job credentials in response to an authentication …Operational
205A bandwidth slot transition occurred.Analytic
206The URL ".Operational
207The URL ".Operational
208A flash-Crowd situation is detected for the URL ".Operational
209High performance property for BITS job ".Operational
210The URL ".Operational
211BITS job ".Operational
212BITS service has detected a '.Analytic
213Job is not currently transferring because one of its transfer policies conflicts …Analytic
281The service is generating its common global data.Analytic
282The service is reading its group policy settings.Analytic
283The service is creating its performance counters.Analytic
284The service is searching for gateway devices.Analytic
285The service is starting the peer-caching client.Analytic
286The service is starting the peer-caching server.Analytic
287The service is reading the job list from the disk.Analytic
288The service is updating its list of active network connections.Analytic
289The service is updating its list of logged-in users.Analytic
290The service is creating the Volume Shadow Copy writer.Analytic
291The service is registering its COM objects.Analytic
301The BITS service has started successfully.Analytic
302The BITS service has started successfully, but it was delayed long enough that …Operational
303The peer-cache client startup phase of startup has completed.Operational
304The service is shutting down.Analytic
305The service shutdown is complete.Analytic
306The BITS service loaded the job list from disk.Operational
307It took %1 seconds to write a change file to the BITS job list.Operational
308The BITS service shut down successfully, but it was delayed for %1 seconds.Operational
309The BITS peer cache was unable to find any peers in the network.Operational
310The initialization of the peer helper modules failed with the following error.Operational
311The BITS peer transfer with the %1 ID for the %2 transfer job resulted in the …Operational
312The Network List Manager Cost Interface is not available on this system.Operational
313The Network List Manager Cost Interface is reporting no network connectivity.Operational
16384The administrator %4 canceled job "%2" on behalf of %3.Operational
16385While canceling job ".System
16386While canceling job ".System
16387The administrator %3 modified the %4 property of job "%2".Operational
16388The administrator %4 took ownership of job "%2" from %3.Operational
16389Job ".Operational
16390Job ".System
16391The BITS job list is not in a recognized format.Operational
16392The BITS service failed to start.System
16393BITS has encountered an error communicating with an Internet Gateway Device.System
16394BITS Peer-caching protocolOperational
16395Web Services-Discovery protocolOperational
16396Error %3 occurred when BITS tried to change the state of firewall rule "%1" to …System
16397The Per-user job limit specified through Group Policy must be less than or equal …System
16398A new BITS job could not be created.System
16400A new BITS job could not be created.System
16401BITS could not add file(s) to %1 job.System
16402BITS could not add ranges to %1 file.System
16403Operational
16404The BITS service has detected an exception, Function: %1, Line: %2 Error code: …System
16405A bandwidth profile is not configured correctly.System
17005The BITS service is configured to run as %1.System

Event ID 0 —

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Event ID 1 — BITS job ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS job "%2" with ID %1 has been resumed.

Fields

NameDescription
JobGuid
Title

Event ID 2 — BITS job ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS job "%2" with ID %1 has been suspended.

Fields

NameDescription
JobGuid
Title

Event ID 3 — The BITS service created a new job.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

The BITS service created a new job: %1, with owner %2

Fields

NameDescription
jobTitleTransfer job.
jobId
jobOwnerOwner.
processPath
processId
ClientProcessStartKey

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 3
  version: 3
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T01:45:20.897391+00:00'
  event_record_id: 432
  correlation:
    ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
  execution:
    process_id: 16164
    thread_id: 17248
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  jobTitle: Chrome Component Updater
  jobId: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
  jobOwner: WINDEV2310EVAL\User
  processPath: C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.222.982.0_x64__zpdnekdrzrea0\Spotify.exe
  processId: 2208
  ClientProcessStartKey: 3659174697241209
message: ''

Sigma Rules

References

Event ID 4 — The transfer job is complete.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

The transfer job is complete.
User: %1
Transfer job: %2
Job ID: %3
Owner: %4
File count: %5

Fields

NameDescription
User
jobTitleTransfer job.
jobId
jobOwnerOwner.
fileCount
bytesTransferred
bytesTransferredFromPeer

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 4
  version: 1
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T02:02:24.353689+00:00'
  event_record_id: 436
  correlation:
    ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
  execution:
    process_id: 16164
    thread_id: 5192
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  User: WINDEV2310EVAL\User
  jobTitle: Edge Component Updater
  jobId: 3C77FC9E-C30A-4FC3-804B-82E48B3059B6
  jobOwner: WINDEV2310EVAL\User
  fileCount: 1
  bytesTransferred: 201001
  bytesTransferredFromPeer: 0
message: ''

References

Event ID 5 — Job cancelled.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

Job cancelled. User: %1, job: %2, jobID: %3, owner: %4, filecount: %5

Fields

NameDescription
UserJob cancelled. User.
jobTitle
jobId
jobOwner
fileCount
processId
ClientProcessStartKey

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 5
  version: 1
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-10-25T21:23:18.455184+00:00'
  event_record_id: 20
  correlation:
    ActivityID: DE03B784-07C3-0003-32C2-03DEC307DA01
  execution:
    process_id: 4816
    thread_id: 4860
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDevEval
  security:
    user_id: S-1-5-19
event_data:
  User: NT AUTHORITY\LOCAL SERVICE
  jobTitle: Font Download
  jobId: BF87B9AA-D285-46CB-89FF-C6C111F0E4CB
  jobOwner: NT AUTHORITY\LOCAL SERVICE
  fileCount: 1
  processId: 2948
  ClientProcessStartKey: 562949953421373
message: ''

References

Event ID 6 — Command-line command set for job %1 with owner %2.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

Command-line command set for job %1 with owner %2. Program: %3 Args: %4.

Fields

NameDescription
jobId
jobOwner
program2. Program.
parametersArgs.

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 6
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-10-25T21:25:55.426533+00:00'
  event_record_id: 32
  correlation:
    ActivityID: DE03B784-07C3-0003-E610-04DEC307DA01
  execution:
    process_id: 4940
    thread_id: 5896
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDevEval
  security:
    user_id: S-1-5-18
event_data:
  jobId: F36CA3CE-3AEB-4592-B4ED-D23E59938DF9
  jobOwner: NT AUTHORITY\SYSTEM
  program: C:\Windows\system32\directxdatabaseupdater.exe
  parameters: C:\Windows\system32\directxdatabaseupdater.exe -DatabaseComplete {F36CA3CE-3AEB-4592-B4ED-D23E59938DF9}
message: ''

References

Event ID 10 — BITS started listening for peer-client requests.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS started listening for peer-client requests.

Event ID 11 — BITS was not able to listen for peer-client requests.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS was not able to listen for peer-client requests.  The error code was %1.  BITS jobs from other machines will not be able to use this machine as a peer server.  To fix this problem, try stopping the BITS service and restarting it.

Fields

NameDescription
ErrorCode

Event ID 12 — BITS stopped listening for peer-client requests.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS stopped listening for peer-client requests.

Event ID 13 — BITS started listening for peer-server announcements.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS started listening for peer-server announcements.

Event ID 14 — BITS was not able to listen for peer-server announcements.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS was not able to listen for peer-server announcements.  The error code was %1.  BITS jobs on this machine will not be able to use peer-caching.  To fix this problem, try stopping the BITS service and restarting it.

Fields

NameDescription
ErrorCode

Event ID 15 — BITS stopped listening for peer-server announcements.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS stopped listening for peer-server announcements.

Event ID 16 — BITS has sent an inquiry for peer servers.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS has sent an inquiry for peer servers.

Event ID 17 — BITS has read the policy parameters for peer-caching.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS has read the policy parameters for peer-caching.

Fields

NameDescription
peerCacheEnabled
peerClientEnabled
peerServerEnabled
maxPeers
maxClients
maxContentAge
maxCacheSize
minCacheDiskSize
cacheDenyUrls
denyUrlCount
denyUrls

Event ID 18 — The peer list rejected an incoming server announcement.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The peer list rejected an incoming server announcement. This event is generated if the request is not valid, not if the server is merely in a different Windows domain.

Fields

NameDescription
packet
hr
fqdn
sourceAddress
addressCount
addresses

Event ID 19 — A new peer was added.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A new peer was added.

Fields

NameDescription
fqdn
authenticated
online
addressCount
addressLength

Event ID 20 — A peer was updated.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A peer was updated.

Fields

NameDescription
fqdn
authenticated
online
addressCount
addressLength

Event ID 21 — A peer was removed from the peer list.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A peer was removed from the peer list.

Fields

NameDescription
fqdn
authenticated
online
addressCount
addressLength

Event ID 22 — A cached peer was restored from disk.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A cached peer was restored from disk.

Fields

NameDescription
fqdn
authenticated
online
addressCount
addressLength

Event ID 23 — An application cleared the peer list.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

An application cleared the peer list.

Fields

NameDescription
user

Event ID 24 — BITS has replied to a client's inquiry for peer servers.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS has replied to a client's inquiry for peer servers.

Fields

NameDescription
sourceAddress

Event ID 25 — The server received a peer inquiry but rejected it.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The server received a peer inquiry but rejected it.

Fields

NameDescription
sourceAddress
packet
hr

Event ID 27 — A peer search for an URL has begun.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A peer search for an URL has begun.

Fields

NameDescription
searchId
jobId
url
timestamp

Event ID 28 — A peer search ended.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A peer search ended.

Fields

NameDescription
searchId
jobId

Event ID 29 — A search request is being sent.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A search request is being sent.

Fields

NameDescription
requestId
searchId
peer

Event ID 30 — A search request has completed.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A search request has completed.

Fields

NameDescription
requestId
SearchId
hr

Event ID 31 — A search request has completed unsuccessfully.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A search request has completed unsuccessfully.

Fields

NameDescription
requestId
SearchId
hr

Event ID 32 — The peer's record %2 matched the request.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The peer's record %2 matched the request.

Fields

NameDescription
requestId
id
url
rangecount
Range

Event ID 33 — BITS updated the set of IP addresses used for peer-caching.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS updated the set of IP addresses used for peer-caching.

Fields

NameDescription
count
addresses

Event ID 34 — Job cannot be transferred because job transfer cost policy preventing it.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

Job cannot be transferred because job transfer cost policy preventing it. job: %1, jobID: %2, filecount: %3, jobs transfer policy: %4, global transfer policy: %5.

Fields

NameDescription
jobName
jobId
FileCount
jobTransferPolicy
globalTransferPolicy

Event ID 37 — The cost state has changed.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The cost state has changed.  NLM reports the following: 
Cost: %1
 Usage: %2 MB
 Cap: %3 MB
 Throttled: %4
 Overcap: %5
 Roaming: %6

The resultant BITS Cost state is : %7.

Fields

NameDescription
nlmCost
usage
cap
isThrottled
isOvercap
isRoaming
globalTransferPolicy

Event ID 59 — BITS started the %2 transfer job that is associated with the %4 URL.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

BITS started the %2 transfer job that is associated with the %4 URL.

Fields

NameDescription
transferId
name
Id
url
peer
fileTime
fileLength
bytesTotal
bytesTransferred
bytesTransferredFromPeer

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 59
  version: 1
  level: 4
  task: 0
  opcode: 1
  keywords: 4611686018427387904
  time_created: '2023-11-06T01:45:21.457190+00:00'
  event_record_id: 434
  correlation:
    ActivityID: 837C306A-427B-4022-ABDF-56DD359EB862
  execution:
    process_id: 16164
    thread_id: 12700
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  transferId: 837C306A-427B-4022-ABDF-56DD359EB862
  name: Chrome Component Updater
  Id: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
  url: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
  peer: ''
  fileTime: '2023-09-22T20:52:50.000000Z'
  fileLength: 14317402
  bytesTotal: 14317402
  bytesTransferred: 0
  bytesTransferredFromPeer: 0
message: ''

References

Event ID 60 — BITS stopped transferring the %2 transfer job that is associated with the %4 URL.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

BITS stopped transferring the %2 transfer job that is associated with the %4 URL. The status code is %6.

Fields

NameDescription
transferId
name
Id
url
peer
hr
fileTime
fileLength
bytesTotal
bytesTransferred
proxy
peerProtocolFlags
bytesTransferredFromPeer
AdditionalInfoHr
PeerContextInfo
bandwidthLimit
ignoreBandwidthLimitsOnLan

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 60
  version: 1
  level: 4
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-11-06T01:45:52.846707+00:00'
  event_record_id: 435
  correlation:
    ActivityID: 837C306A-427B-4022-ABDF-56DD359EB862
  execution:
    process_id: 16164
    thread_id: 12832
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  transferId: 837C306A-427B-4022-ABDF-56DD359EB862
  name: Chrome Component Updater
  Id: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
  url: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
  peer: ''
  hr: 0
  fileTime: '2023-09-22T20:52:50.000000Z'
  fileLength: 14317402
  bytesTotal: 14317402
  bytesTransferred: 14317402
  proxy: ''
  peerProtocolFlags: 0
  bytesTransferredFromPeer: 0
  AdditionalInfoHr: 0
  PeerContextInfo: 0
  bandwidthLimit: 18446744073709551615
  ignoreBandwidthLimitsOnLan: false
message: ''

Community Notes

Surfaces Background Intelligent Transfer Service misuse for exfil or downloads.

References

Event ID 61 — BITS stopped transferring the %2 transfer job that is associated with the %4 URL.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
3
Samples
1

Message

BITS stopped transferring the %2 transfer job that is associated with the %4 URL. The status code is %6.

Fields

NameDescription
transferId
name
Id
url
peer
hr
fileTime
fileLength
bytesTotal
bytesTransferred
proxy
peerProtocolFlags
bytesTransferredFromPeer
AdditionalInfoHr
PeerContextInfo
bandwidthLimit
ignoreBandwidthLimitsOnLan

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 61
  version: 1
  level: 3
  task: 0
  opcode: 2
  keywords: 4611686018427387904
  time_created: '2023-10-25T21:23:18.535833+00:00'
  event_record_id: 25
  correlation:
    ActivityID: B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C
  execution:
    process_id: 4816
    thread_id: 2800
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDevEval
  security:
    user_id: S-1-5-18
event_data:
  transferId: B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C
  name: Font Download
  Id: 0732C691-11CC-4489-AA3A-006D80128165
  url: https://fs.microsoft.com/fs/windows/fontset-2017-04.json
  peer: ''
  hr: 2149580817
  fileTime: '1601-01-01T00:00:00.000000Z'
  fileLength: 18446744073709551615
  bytesTotal: 18446744073709551615
  bytesTransferred: 0
  proxy: ''
  peerProtocolFlags: 0
  bytesTransferredFromPeer: 0
  AdditionalInfoHr: 0
  PeerContextInfo: 0
  bandwidthLimit: 18446744073709551615
  ignoreBandwidthLimitsOnLan: false
message: ''

References

Event ID 62 — The BITS job named ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS job named "%1" belonging to user %2 received inconsistent data while downloading. The URL was "%3". The transfer will continue using a different server.  If the problem occurs often, an administrator should scan the peer server for viruses or corruption in its hard drive.

Fields

NameDescription
Title
Owner
Url
Id

Event ID 63 — The BITS job %1 is configured to launch %3 after transfer of %2.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS job %1 is configured to launch %3 after transfer of %2. The notification program returned error %4, BITS will continue to launch the program periodically until it succeeds.

Fields

NameDescription
Job
Url
Pgm
hr

Event ID 64 — The BITS job %1 is configured to launch %3 after transfer of %2.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS job %1 is configured to launch %3 after transfer of %2. The service failed to launch the program with error %4, BITS will continue trying to launch the program periodically until it succeeds.

Fields

NameDescription
Job
Url
Pgm
hr

Event ID 70 — BITS received a peer-cache request from a client at address %1.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS received a peer-cache request from a client at address %1.

Fields

NameDescription
clientAddress

Event ID 71 — The client's search request is for ".

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The client's search request is for "%1" with timestamp %2.

Fields

NameDescription
url
timestamp

Event ID 72 — The cache found a matching cache record with ID %1.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The cache found a matching cache record with ID %1.

Fields

NameDescription
id
url
rangecount
Range

Event ID 73 — While processing the client's request, BITS encountered error %1.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

While processing the client's request, BITS encountered error %1.

Fields

NameDescription
ErrorCode

Event ID 74 — BITS rejected the client's request with HTTP status %1.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS rejected the client's request with HTTP status %1.

Fields

NameDescription
status

Event ID 75 — BITS has finished processing the client request.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS has finished processing the client request.

Event ID 76 — The request includes the client's event-log activity ID.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The request includes the client's event-log activity ID.

Event ID 77 — BITS search for peer-servers has started.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS search for peer-servers has started.

Event ID 78 — BITS has encountered %1 error while reading the peer-cache information.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS has encountered %1 error while reading the peer-cache information. BITS will now attempt to delete and re-create the peer-cache.

Fields

NameDescription
ErrorCode

Event ID 79 — BITS has successfully deleted the peer-cache.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS has successfully deleted the peer-cache. All the files cached until this point have been removed. The peer-cache will be re-created again as needed for handling the future requests.

Event ID 80 — BITS has successfully enabled peer-client and/or peer-server related components.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS has successfully enabled peer-client and/or peer-server related components.

Event ID 81 — BITS has encountered %1 error while starting one or more peer-client or peer-server components.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS has encountered %1 error while starting one or more peer-client or peer-server components.

Fields

NameDescription
ErrorCode

Event ID 82 — BITS accessed group policy value %1 : %2.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS accessed group policy value %1 : %2.

Fields

NameDescription
Title
PolicyValue

Event ID 83 — BITS defaulted group policy value %1 : %2.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS defaulted group policy value %1 : %2.

Fields

NameDescription
Title
PolicyValue

Event ID 101 — The peer's response to a search was invalid.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The peer's response to a search was invalid.

Fields

NameDescription
requestId
responseXml

Event ID 102 — The file ranges associated with a transfer attempt

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The file ranges associated with a transfer attempt

Fields

NameDescription
xferId
count
ranges

Event ID 200 — While transferring %1, BITS encountered error %2 using %3 as the HTTP proxy server.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

While transferring %1, BITS encountered error %2 using %3 as the HTTP proxy server.  This may indicate a problem with the proxy server or with the client's network configuration.  If this error occurs frequently, then an administrator should investigate. Details: {Job: %4}, {owner: %5}, {jobid: %6}, {URL: %1}, {xferId: %7}, {proxyServerList: %8}, {hr: %2}.

Fields

NameDescription
URL}, {URL.
hr}, {hr.
owner3 as the HTTP proxy server. This may indicate a problem with the proxy server or with the client's network configuration. If this error occurs frequently, then an administrator should investigate. Details: {Job.
jobid}, {owner.
xferId}, {jobid.
proxyServerList}, {xferId.
url
proxy
job
jobId

Event ID 201 — The BITS job named ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS job named "%1" was unable to contact any HTTP proxy server in its proxy list.  This may indicate a problem with the proxy servers or with the client's network configuration.  An administrator should verify whether the proxy list is correct.  BITS will periodically try to transfer the job.  The HTTP proxy list is "%6".  The proxy-bypass list is "%7".

Fields

NameDescription
job
jobId
jobOwner
url
transferId
proxyServerList
proxyBypassList
error

Event ID 202 — While transferring %1, BITS encountered error %7 using %6 as the HTTP proxy server.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

While transferring %1, BITS encountered error %7 using %6 as the HTTP proxy server.  The web server or proxy server does not support an HTTP feature required by BITS.  This problem can only be corrected by the administrator of the web server or proxy server.  Details: {job: %1}, {owner: %2}, {jobId: %3}, {url: %4}, {xferId: %5}, {proxyServer: %6}, {hr: %7}, {urlContentLength: %8}, {urlHttpVersion: %9}, {urlRange: %10}

Fields

NameDescription
owner}, {owner.
jobId}, {jobId.
url}, {url.
xferId}, {xferId.
proxyServer}, {proxyServer.
hr}, {hr.
urlContentLength}, {urlContentLength.
urlHttpVersion}, {urlHttpVersion.
urlRange}, {urlRange.
jobName
jobOwner
proxy
fileLength
HTTPVersion
URLRange

Event ID 203 — The BITS service provided job credentials in response to an authentication challenge from the %1 server for the %2 transfer job that is associated ...

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS service provided job credentials in response to an authentication challenge from the %1 server for the %2 transfer job that is associated with the following URL: %3.
The credentials were accepted.

Fields

NameDescription
server
job
url
scheme
user

Event ID 204 — The BITS service provided job credentials in response to an authentication challenge from %1 for job %2, url %3.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS service provided job credentials in response to an authentication challenge from %1 for job %2, url %3. The credentials were rejected.

Fields

NameDescription
server
job
url2 transfer job that is associated with the following URL.
scheme
user

Event ID 205 — A bandwidth slot transition occurred.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

A bandwidth slot transition occurred.

Fields

NameDescription
profileType
currSlotStartTime
currSlotBandwidthLimit
nextSlotStartTime
nextSlotBandwidthLimit

Event ID 206 — The URL ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The URL "%2" in BITS job "%1" does not support the HTTP HEAD verb, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields

NameDescription
jobName
url

Event ID 207 — The URL ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The URL "%2" in BITS job "%1" does not support the HTTP Content-Length header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields

NameDescription
jobName
url

Event ID 208 — A flash-Crowd situation is detected for the URL ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

A flash-Crowd situation is detected for the URL "%2" in BITS job "%1".

Fields

NameDescription
jobName
url

Event ID 209 — High performance property for BITS job ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Message

High performance property for BITS job "%1" with ID "%2" %3.

Fields

NameDescription
jobName
jobId
isRoaming

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 209
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-05T22:27:06.012810+00:00'
  event_record_id: 121
  correlation:
    ActivityID: F590C418-1079-0000-98E3-90F57910DA01
  execution:
    process_id: 5620
    thread_id: 4004
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  jobName: Font Download
  jobId: 45827C8A-7310-400E-A51E-179189C5AC76
  isRoaming: 1
message: ''

References

Event ID 210 — The URL ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The URL "%2" in BITS job "%1" does not support the HTTP Content-Range header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields

NameDescription
jobName
url

Event ID 211 — BITS job ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS job "%2" with ID "%1" encountered an error %3. %4

Fields

NameDescription
JobGuid
Title
ErrorCode
Message

Event ID 212 — BITS service has detected a '.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

BITS service has detected a '%1' system event

Fields

NameDescription
SystemEvent

Event ID 213 — Job is not currently transferring because one of its transfer policies conflicts with current system state.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

Job is not currently transferring because one of its transfer policies conflicts with current system state. job: %1, jobID: %2, filecount: %3, block reason: %4.

Fields

NameDescription
jobName
jobId
FileCount
BlockReasonErrorCode

Event ID 281 — The service is generating its common global data.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is generating its common global data.

Event ID 282 — The service is reading its group policy settings.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is reading its group policy settings.

Event ID 283 — The service is creating its performance counters.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is creating its performance counters.

Event ID 284 — The service is searching for gateway devices.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is searching for gateway devices.

Event ID 285 — The service is starting the peer-caching client.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is starting the peer-caching client.

Event ID 286 — The service is starting the peer-caching server.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is starting the peer-caching server.

Event ID 287 — The service is reading the job list from the disk.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is reading the job list from the disk.

Event ID 288 — The service is updating its list of active network connections.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is updating its list of active network connections.

Event ID 289 — The service is updating its list of logged-in users.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is updating its list of logged-in users.

Event ID 290 — The service is creating the Volume Shadow Copy writer.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is creating the Volume Shadow Copy writer.

Event ID 291 — The service is registering its COM objects.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is registering its COM objects.

Event ID 301 — The BITS service has started successfully.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The BITS service has started successfully.

Event ID 302 — The BITS service has started successfully, but it was delayed long enough that there may be a problem.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS service has started successfully, but it was delayed long enough that there may be a problem. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Event ID 303 — The peer-cache client startup phase of startup has completed.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The peer-cache client startup phase of startup has completed.

Event ID 304 — The service is shutting down.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service is shutting down.

Event ID 305 — The service shutdown is complete.

Provider
Microsoft-Windows-Bits-Client
Channel
Analytic

Message

The service shutdown is complete.

Event ID 306 — The BITS service loaded the job list from disk.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
5
Samples
1

Message

The BITS service loaded the job list from disk.

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 306
  version: 0
  level: 5
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T00:47:39.589942+00:00'
  event_record_id: 416
  correlation: {}
  execution:
    process_id: 16164
    thread_id: 16220
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 307 — It took %1 seconds to write a change file to the BITS job list.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

It took %1 seconds to write a change file to the BITS job list. If this is excessive, the number of BITS jobs may be larger than this machine can handle quickly.

Fields

NameDescription
number

Event ID 308 — The BITS service shut down successfully, but it was delayed for %1 seconds.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
3
Samples
1

Message

The BITS service shut down successfully, but it was delayed for %1 seconds. This might cause delays when you turn off your computer. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Fields

NameDescription
number

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 308
  version: 0
  level: 3
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2021-06-13T06:19:28.351119Z'
  event_record_id: 17
  correlation:
    '#attributes':
      ActivityID: 9E13646C-6014-0001-5C6E-139E1460D701
  execution:
    process_id: 1140
    thread_id: 356
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: sv-dc.hinokabegakure-no-sato.local
  security:
    user_id: S-1-5-18
event_data:
  number: '3199.234'

References

Event ID 309 — The BITS peer cache was unable to find any peers in the network.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS peer cache was unable to find any peers in the network.

Event ID 310 — The initialization of the peer helper modules failed with the following error.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
3
Samples
1

Message

The initialization of the peer helper modules failed with the following error:  %1.

Fields

NameDescription
ErrorCodeThe initialization of the peer helper modules failed with the following error.

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 310
  version: 0
  level: 3
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T00:48:24.805665+00:00'
  event_record_id: 419
  correlation: {}
  execution:
    process_id: 16164
    thread_id: 15644
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  ErrorCode: 2147942450
message: ''

References

Event ID 311 — The BITS peer transfer with the %1 ID for the %2 transfer job resulted in the following error: %4.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS peer transfer with the %1 ID for the %2 transfer job resulted in the following error: %4.

Fields

NameDescription
JobId
JobName
url
ErrorCode
ErrorContext
bytesTransferredFromPeer
PeerProtocolFlags

Event ID 312 — The Network List Manager Cost Interface is not available on this system.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The Network List Manager Cost Interface is not available on this system. (This is expected on Windows Server.)  BITS will not consider Transfer Policy when scheduling jobs.

Fields

NameDescription
ErrorCode

Event ID 313 — The Network List Manager Cost Interface is reporting no network connectivity.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The Network List Manager Cost Interface is reporting no network connectivity. BITS will try to retrieve the network state again at a later time.

Fields

NameDescription
ErrorCode

Event ID 16384 — The administrator %4 canceled job "%2" on behalf of %3.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The administrator %4 canceled job "%2" on behalf of %3.  The job ID was %1.

Fields

NameDescription
Id
Title
Owner
User
processId
ClientProcessStartKey

Event ID 16385 — While canceling job ".

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

While canceling job "%2", BITS was unable to remove some temporary files. To recover disk space, delete the files listed below.  The job ID was %1.  %3

Fields

NameDescription
Id
Title
FileList

Event ID 16386 — While canceling job ".

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

While canceling job "%2", BITS was unable to remove some temporary files. To recover disk space, delete the temporary files. Note: Due to space limitations, not all files are listed.  Check for additional files of the form BITxxx.TMP in the same directory.  The job ID was %1.  %3

Fields

NameDescription
Id
Title
FileList

Event ID 16387 — The administrator %3 modified the %4 property of job "%2".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The administrator %3 modified the %4 property of job "%2".  The job ID was %1.

Fields

NameDescription
Id
Title
Owner
PropertyName

Event ID 16388 — The administrator %4 took ownership of job "%2" from %3.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The administrator %4 took ownership of job "%2" from %3.  The job ID was %1.

Fields

NameDescription
Id
Title
Owner
User
processId
ClientProcessStartKey

Event ID 16389 — Job ".

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

Job "%2" owned by %3 was canceled after being inactive for more than %4 days.  The job ID was %1.

Fields

NameDescription
Id
Title
Owner
DayCount

Event ID 16390 — Job ".

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

Job "%2" owned by %3 failed to notify its associated application.  BITS will retry in %4 minutes.  The job ID was %1.

Fields

NameDescription
Id
Title
Owner
RetryWaitTime

Event ID 16391 — The BITS job list is not in a recognized format.

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

The BITS job list is not in a recognized format.  It may have been created by a different version of BITS.  The job list has been cleared.

Event ID 16392 — The BITS service failed to start.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

The BITS service failed to start.  Error %1.

Fields

NameDescription
ErrorCode

Event ID 16393 — BITS has encountered an error communicating with an Internet Gateway Device.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

BITS has encountered an error communicating with an Internet Gateway Device.  Please check that the device is functioning properly. BITS will not attempt to use this device until the next system reboot. Error code: %1.

Fields

NameDescription
ErrorCode

Event ID 16394 — BITS Peer-caching protocol

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

BITS Peer-caching protocol

Event ID 16395 — Web Services-Discovery protocol

Provider
Microsoft-Windows-Bits-Client
Channel
Operational

Message

Web Services-Discovery protocol

Event ID 16396 — Error %3 occurred when BITS tried to change the state of firewall rule "%1" to %2.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

Error %3 occurred when BITS tried to change the state of firewall rule "%1" to %2.  Restarting the BITS service may correct the problem.

Fields

NameDescription
rule
enabled
status

Event ID 16397 — The Per-user job limit specified through Group Policy must be less than or equal to Per-computer job Limit.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

The Per-user job limit (%2) specified through Group Policy must be less than or equal to Per-computer job Limit (%3).  To correct the problem, modify BITS Group Policy settings and restart the BITS service.

Fields

NameDescription
entityName
currentSize
currentLimit

Event ID 16398 — A new BITS job could not be created.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

A new BITS job could not be created. The current job count for the user %1 (%2) is equal to or greater than the job limit (%3) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.

Fields

NameDescription
entityName
currentSize
currentLimit

Event ID 16400 — A new BITS job could not be created.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

A new BITS job could not be created. The current job count for this computer (%2) is equal to or greater than the per-computer job limit (%3) specified through Group Policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error and restarting the BITS service. If this error recurs, contact your system administrator and increase the per-computer Group Policy job limits.

Fields

NameDescription
entityName
currentSize
currentLimit

Event ID 16401 — BITS could not add file(s) to %1 job.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

BITS could not add file(s) to %1 job. The file count for %1 job (%2) has exceeded the per-job file limit (%3) specified through Group Policy.  To correct the problem, increase the Computer?s per-job file limit Group Policy settings and restart the BITS service.

Fields

NameDescription
entityName
currentSize
currentLimit

Event ID 16402 — BITS could not add ranges to %1 file.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

BITS could not add ranges to %1 file. The range count for %1 file (%2) has exceeded the per-file range limit (%3) specified through group policy.  To correct the problem, increase the per-file range limit Group Policy setting and restart the BITS service.

Fields

NameDescription
entityName
currentSize
currentLimit

Event ID 16403 —

Provider
Microsoft-Windows-Bits-Client
Channel
Operational
Level
4
Samples
1

Fields

NameDescription
User
jobTitle
jobId
jobOwner
fileCount
RemoteName
LocalName
processId
ClientProcessStartKey

Example Event

system:
  provider: Microsoft-Windows-Bits-Client
  guid: EF1CC15B-46C1-414E-BB95-E76B077BD51E
  event_source_name: ''
  event_id: 16403
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686018427387904
  time_created: '2023-11-06T01:45:21.024078+00:00'
  event_record_id: 433
  correlation:
    ActivityID: E4DB489E-1037-0002-3588-E4E43710DA01
  execution:
    process_id: 16164
    thread_id: 18264
  channel: Microsoft-Windows-Bits-Client/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  User: WINDEV2310EVAL\User
  jobTitle: Chrome Component Updater
  jobId: 9A25D168-24E6-4C66-AC78-5ED0E6007F1A
  jobOwner: WINDEV2310EVAL\User
  fileCount: 1
  RemoteName: http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
  LocalName: C:\Users\User\AppData\Local\Temp\chrome_BITS_2208_583787314\oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3
  processId: 2208
  ClientProcessStartKey: 3659174697241209
message: ''

Community Notes

May indicate download/staging. See this Google Cloud post Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer Service

Sigma Rules

References

Event ID 16404 — The BITS service has detected an exception, Function: %1, Line: %2 Error code: %3.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

The BITS service has detected an exception, Function: %1, Line: %2 Error code: %3.

Fields

NameDescription
function
line
hr

Event ID 16405 — A bandwidth profile is not configured correctly.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

A bandwidth profile is not configured correctly. The value of a Group Policy setting is missing or is not within the allowed range. Make sure that you configure the Group Policy settings correctly, and then try again.

Fields

NameDescription
Key
SubKeyOrValueName

Event ID 17005 — The BITS service is configured to run as %1.

Provider
Microsoft-Windows-Bits-Client
Channel
System

Message

The BITS service is configured to run as %1. BITS works correctly only when configured to run as the system account.

Fields

NameDescription
string
string2
string3