Microsoft-Windows-CloudStore
60 events across 3 channels
Event ID 1 — Error %3 occurred.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
Type | — |
ErrorCode | — |
File | — |
LineNumber | — |
Example Event
system:
provider: Microsoft-Windows-CloudStore
guid: 741BB90C-A7A3-49D6-BD82-1E6B858403F7
event_source_name: ''
event_id: 1
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T16:58:26.480434+00:00'
event_record_id: 54
correlation: {}
execution:
process_id: 4128
thread_id: 4196
channel: Microsoft-Windows-CloudStore/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ProcessName: explorer.exe
Type: 2
ErrorCode: 2147746053
File: onecoreuap\shell\cloudstore\store\cache\src\cloudcacheinvalidatorsso.cpp
LineNumber: 504
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2 — Error %3 occurred.
Message
Fields
| Name | Description |
|---|---|
ProcessName | — |
Type | — |
ErrorCode | — |
File | — |
LineNumber | — |
Context | — |
Event ID 1000 — Discovered schema provider %1.
Message
Fields
| Name | Description |
|---|---|
SchemaProvider | — |
Event ID 1001 — Successfully loaded %1 schemas.
Message
Fields
| Name | Description |
|---|---|
ProviderCount | — |
Event ID 2001 — Ignoring ommitted field %1 with unknown type %2.
Message
Fields
| Name | Description |
|---|---|
FieldId | — |
BondDataType | — |
Event ID 2003 — Conflict resolution of type {QualifiedTypeName} started.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
YoursVersion | — |
YoursSize | — |
Event ID 2004 — Conflict resolution of type %2 complete.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
QualifiedTypeName | — |
SchemaSize | — |
Schema | — |
ForceLastWriterWins | — |
OriginalVersion | — |
OriginalTombstoned | — |
OriginalSize | — |
OriginalData | — |
TheirsVersion | — |
TheirsTombstoned | — |
TheirsSize | — |
TheirsData | — |
YoursVersion | — |
YoursTombstoned | — |
YoursSize | — |
YoursData | — |
ResolvedVersion | — |
ResolvedTombstoned | — |
ResolvedSize | — |
ResolvedData | — |
Event ID 2005 — Conflict resolution of type {QualifiedTypeName} complete.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Version | — |
Size | — |
Event ID 2006 — Conflict resolution of type {CorrelationVector} complete.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
Event ID 2007 — Resolved a set containing duplicated values.
Message
Fields
| Name | Description |
|---|---|
Index | — |
Event ID 2008 — The 'original' version (%2) of type %1 is more recent than the 'theirs' version (%3) or the 'yours' version (%4).
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
OriginalVersion | — |
TheirsVersion | — |
YoursVersion | — |
ResolvedVersion | — |
Event ID 2009 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Base64String | — |
Event ID 2010 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Event ID 2011 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Size | — |
Data | — |
Event ID 2012 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Event ID 2013 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Base64String | — |
Event ID 2014 — The data of type %1 was corrupted and ignored.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Event ID 2015 — The AppExtension of name %1 having type %2 failed with error code %3 found.
Message
Fields
| Name | Description |
|---|---|
AppExtensionName | — |
TypeName | — |
ErrorCode | — |
Event ID 2016 — The AppExtension of name %1 having type %2 failed with error code %3 found.
Message
Fields
| Name | Description |
|---|---|
AppExtensionName | — |
TypeName | — |
ErrorCode | — |
Event ID 2017 — Found an list item instance with a missing index value while merging vector as a map.
Message
Fields
| Name | Description |
|---|---|
Index | — |
Event ID 2018 — Conflict resolution policy of VectorAsMap requires an index field to be defined on the list item structure.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Event ID 2019 — Conflict resolution policy of VectorAsMap requires index fields to be an integer or string.
Message
Fields
| Name | Description |
|---|---|
QualifiedTypeName | — |
Event ID 2020 — Conflict resolution policy of VectorAsMap the list items to be a structure.
Message
Fields
| Name | Description |
|---|---|
BondDataType | — |
Event ID 3002 — Sucessfully deleted %2.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Version | — |
Event ID 3003 — Saving %1 and merging with 'theirs' data.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Version | — |
Size | — |
Event ID 3004 — Saving %1 without 'theirs' data.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 3005 — Overwriting %1 with 'yours' data to repair inaccessible store (access failed with error code %2).
Message
Fields
| Name | Description |
|---|---|
Id | — |
ErrorCode | — |
Event ID 3006 — Uploading %1 failed with error code %2.
Message
Fields
| Name | Description |
|---|---|
Id | — |
ErrorCode | — |
Event ID 3007 — Successfully loaded %2.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
Id | — |
Version | — |
Size | — |
Data | — |
Event ID 3008 — Successfully saved %2.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
Id | — |
Version | — |
Size | — |
Data | — |
Event ID 3010 — Successfully saved cloud data for {Id}.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 3012 — Successfully saved merged cloud data for {Id}.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 3013 — Downloading %1 failed with error code %2.
Message
Fields
| Name | Description |
|---|---|
Id | — |
ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-CloudStore
guid: 741BB90C-A7A3-49D6-BD82-1E6B858403F7
event_source_name: ''
event_id: 3013
version: 0
level: 3
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T01:48:34.113221+00:00'
event_record_id: 57
correlation:
ActivityID: E4DB489E-1037-0000-DAED-EDE43710DA01
execution:
process_id: 16236
thread_id: 22096
channel: Microsoft-Windows-CloudStore/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Id: default$windows.data.settings.settingsusagehistory|windows.data.settings.settingsusagehistory
ErrorCode: 2147746053
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3014 — Delete of %1 was ignored because the data changed after it was deleted.
Message
Fields
| Name | Description |
|---|---|
Id | — |
TheirsVersion | — |
YoursVersion | — |
Event ID 3015 — The attempt to load %1 failed because the data was corrupt.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
Id | — |
Version | — |
Size | — |
Data | — |
Event ID 3016 — The value {Id} was garbage collected from the local cache because it was not reachable.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 3017 — The object %1 has an unexpected security descriptor.
Message
Fields
| Name | Description |
|---|---|
ObjectName | — |
CurrentAcl | — |
ExpectedAcl | — |
Event ID 3018 — The cache invalidator has started.
Message
Event ID 3019 — The cache invalidator has stopped.
Message
Event ID 3020 — The cache invalidator is processing %2 activities.
Message
Fields
| Name | Description |
|---|---|
CorrelationVector | — |
ActivitiesCount | — |
Event ID 3021 — The Backup master policy is set.
Message
Example Event
system:
provider: Microsoft-Windows-CloudStore
guid: 741BB90C-A7A3-49D6-BD82-1E6B858403F7
event_source_name: ''
event_id: 3021
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:29:02.865478+00:00'
event_record_id: 17
correlation: {}
execution:
process_id: 5784
thread_id: 6016
channel: Microsoft-Windows-CloudStore/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3022 — Backup policy name %1 set failed with error code %2.
Message
Fields
| Name | Description |
|---|---|
Id | — |
ErrorCode | — |
Event ID 3023 — The transport layer reported a failure: %1 with error code %2.
Message
Fields
| Name | Description |
|---|---|
Id | — |
ErrorCode | — |
Event ID 3032 — Error %2 occurred trying to perform file copy operation for schema %1.
Message
Fields
| Name | Description |
|---|---|
Type | — |
TranslatedErrorCode | — |
Stage | — |
Path | — |
Event ID 3033 — Error %1 occurred trying to retrive the device profile during an operation on a backup/restore schema.
Message
Fields
| Name | Description |
|---|---|
TranslatedErrorCode | — |
IsProfileUpdate | — |
ProfileCollection | — |
ProfileInstance | — |
SchemaCollection | — |
Cv | — |
Event ID 4000 — Attempting to save device profile %1.
Message
Fields
| Name | Description |
|---|---|
BackupProfileId | — |
ProcessName | — |
IsDelete | — |
Cv | — |
Example Event
system:
provider: Microsoft-Windows-CloudStore
guid: 741BB90C-A7A3-49D6-BD82-1E6B858403F7
event_source_name: ''
event_id: 4000
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693952
time_created: '2023-11-05T22:29:03.009433+00:00'
event_record_id: 3
correlation: {}
execution:
process_id: 5784
thread_id: 6016
channel: Microsoft-Windows-CloudStore/Initialization
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
BackupProfileId: '{8dcb8207-c294-40da-82e0-ce8f415acdb8}'
ProcessName: taskhostw.exe
IsDelete: false
Cv: /FVp6ocjxkiUITaIBQcllQ.0.1.2
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4001 — Error saving internal type %1: %2.
Message
Fields
| Name | Description |
|---|---|
TypeName | — |
StatusCode | — |
Cv | — |
Event ID 4002 — Successfully setup Cloud Store backup/restore partition information.
Message
Fields
| Name | Description |
|---|---|
BackupProfileId | — |
RestoreProfileId | — |
DeviceDisplayName | — |
Cv | — |
TypeName | — |
Event ID 4003 — Failed to setup Cloud Store backup/restore partition information at stage %2 with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Stage | — |
Cv | — |
TypeName | — |
Event ID 4004 — Timed out after mirroring %2 settings sync policies in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
Elapsed | — |
UpdateCount | — |
LastSource | — |
LastTarget | — |
Event ID 4005 — Completed mirroring %2 settings sync policies in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
Elapsed | — |
UpdateCount | — |
Example Event
system:
provider: Microsoft-Windows-CloudStore
guid: 741BB90C-A7A3-49D6-BD82-1E6B858403F7
event_source_name: ''
event_id: 4005
version: 0
level: 4
task: 0
opcode: 0
keywords: 2305843009213693952
time_created: '2023-11-05T22:29:03.084800+00:00'
event_record_id: 4
correlation: {}
execution:
process_id: 5784
thread_id: 6016
channel: Microsoft-Windows-CloudStore/Initialization
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Elapsed: 62
UpdateCount: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4006 — Set policy %1 to %2.
Message
Fields
| Name | Description |
|---|---|
Target | — |
Enabled | — |
Forced | — |
Event ID 4007 — Failed to set policy %1 to %2: %4.
Message
Fields
| Name | Description |
|---|---|
Target | — |
Enabled | — |
Forced | — |
ErrorCode | — |
Event ID 4008 — Restore data successfully copied from restore partition %1 to backup partition %2.
Message
Fields
| Name | Description |
|---|---|
RestorePartitionId | — |
BackupPartitionId | — |
Event ID 4009 — Failed to copy restore data successfully copied from restore partition %1 to backup partition %2: %3.
Message
Fields
| Name | Description |
|---|---|
RestorePartitionId | — |
BackupPartitionId | — |
ErrorCode | — |
Event ID 4010 — Copied single restore partition data item from %1 to backup partition as %2.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Id | — |
Event ID 4011 — Skipped copying single restore partition at %1 to backup partition as %2 as it already exists.
Message
Fields
| Name | Description |
|---|---|
Path | — |
Id | — |
Event ID 4012 — Error processing type %1.
Message
Fields
| Name | Description |
|---|---|
TypeName | — |
ErrorCode | — |
Stage | — |