Microsoft-Windows-Complus
163 events across 2 channels
Event ID 774 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 775 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 776 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 777 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 778 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 779 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 780 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 781 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 781 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Example Event
system:
provider: Microsoft-Windows-Complus
guid: '{0f177893-4a9c-4709-b921-f432d67f43d5}'
event_source_name: COM+
event_id: 781
version: 0
level: 4
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2023-11-06T06:25:46.553578+00:00'
event_record_id: 1443
correlation: {}
execution:
process_id: 4608
thread_id: 0
channel: Application
computer: WinDev2310Eval
security:
user_id: ''
event_data:
param1: '86400'
param2: SuppressDuplicateDuration
param3: Software\Microsoft\COM3\Eventlog
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 782 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 783 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4433 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4434 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4435 —
Event ID 4440 —
Fields
| Name | Description |
|---|---|
Data | — |
Example Event
system:
provider: Microsoft-Windows-Complus
guid: '{0f177893-4a9c-4709-b921-f432d67f43d5}'
event_source_name: COM+
event_id: 4440
version: 0
level: 3
task: 28
opcode: 0
keywords: 36028797018963968
time_created: '2023-11-06T06:25:46.051085+00:00'
event_record_id: 1442
correlation: {}
execution:
process_id: 4608
thread_id: 0
channel: Application
computer: WinDev2310Eval
security:
user_id: ''
event_data:
Data:
Name: param1
Value: "WINDEVEVAL\r\n\r\nServer Application ID: {02D4B3F1-FD88-11D1-960D-00805FC79235}\r\nServer
Application Instance ID:\r\n{0A80C347-76E1-445F-9329-C69735827198}\r\nServer
Application Name: System Application\r\nComsvcs.dll file version: ENU 2001.12.10941.16384
shp"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4452 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4458 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4459 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4460 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4464 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4465 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4792 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4819 —
Event ID 4820 —
Event ID 4821 —
Event ID 4823 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4864 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 5485 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 5486 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 5488 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742598 — The mtstocom launching routine has started.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742599 — The mtstocom launching routine has completed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742600 — The mtstocom migration utility is attempting to retry populating the packages collection because it failed its first attempt.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742601 — Application image succesfully dumped.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742602 — Application image dump failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742603 — MSMQ Workgroup configuration does not provide sender identity for a COM+ application that has security enabled.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742604 — MSMQ Message Authentication disabled for a COM+ application that has security enabled.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742605 — The COM+ sub system is suppressing duplicate event log entries for a duration of %1 seconds.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073742606 — The average call duration has exceeded the configured threshold.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073742607 — The average call duration has exceeded 10 minutes.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073873667 — A new CRM log file was created.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073873668 — A new CRM log file was created.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073873669 — A new CRM log file was created for the System Application.
Message
Event ID 2147488081 — An error occurred in your COM+ component.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488082 — A method call to an object in a COM+ application was rejected because the caller is not properly authorized to make this call.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488083 — A method call to an object in a COM+ application was rejected because the caller is not properly authorized to make this call.
Message
Event ID 2147488100 — Failures have occurred during migration of MTS packages and program settings to COM+ applications and program settings.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488106 — A registry value was changed while installing the following component into a COM+ Application.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488107 — Controlled registration of this component failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488108 — You have installed an application which contains one or more private components into the base partition.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488112 — During controlled registration of this component the component cancelled registry redirection.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488113 — The
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147489133 — COM+ failed to find the correct partition for the admin SDK.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147489134 — Unable to load file %1 during component registration.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147489136 — Unable to load DLL %1 during component registration.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619160 — The CRM log file was originally created on a computer with a different name.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619161 — The CRM log file was originally created with a different application ID.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619162 — A log information record was not found in the existing CRM log file.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619163 — An unexpected method call was received.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619164 — An empty CRM log file was detected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619165 — An incompletely initialized CRM log file was detected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619166 — The application attempted to use the CRM but the CRM is not enabled for this application.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619168 — Some transactions could not be completed because they are in-doubt.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619169 — The system has called the CRM Compensator custom component and that component has failed and generated an exception.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619170 — The system has called the CRM Compensator custom component and that component has returned an error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619171 — The CRM log file for this application is located on a disk which is low on space.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619173 — CRM Worker custom components require a transaction.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619174 — Event class failed Query Interface.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619175 — Failed to create event class.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619176 — Event failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619177 — A previous instance of this server application has been terminated.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619182 — The attempt to trace an event has failed with E_OUTOFMEMORY.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619183 — During initialization, the System Application stopped an open COM+ tracing session.
Message
Event ID 2147619516 — COM+ Services was unable to obtain local SAM information.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619547 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed an ApplicationFree event.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619548 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed an ApplicationShutdown event.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619550 — COM+ has determined that your machine is running very low on available memory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619551 — COM+ failed an activation because the creation of a context property returned E_OUTOFMEMORY %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147619554 — The shutdown process of COM+ surrogate failed because of an unknown ApplId.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147620098 — An external error has been reported to COM+ services.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147620099 — The server process has lost its connection with MS-DTC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221230264 — The current registration database is corrupt.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221230291 — Error creating security descriptor.
Message
Event ID 3221230292 — Failed to initialize registration database server.
Message
Event ID 3221230293 — Failed to initialize registration database API.
Message
Event ID 3221230295 — COM Replication: An unexpected error occurred.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221230336 — You have attempted to install an application which contains one or more imported components into a non-base partition.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361233 — The run-time environment has detected an inconsistency in its internal state.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361234 — The run-time environment has detected the absence of a critical resource and has caused the process that hosted it to terminate.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361235 — The run-time environment was unable to initialize for transactions required to support transactional components.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361241 — Could not obtain a proxy/stub class factory for given interface.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361242 — Failed to create a stub object for given interface.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361268 — Replication: Invalid machine name supplied for %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361273 — The run-time environment was unable to create a new UUID.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361285 — An attempt was made to access a SPM Property Group in LockMethod mode, by an object without JIT Activation, or by an object with a lock on another ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361311 — The class ID of the proxy stub DLL for the interface is not available, or failed to load the proxy stub DLL, or failed to create a proxy.
Message
Event ID 3221361313 — An unexpected error occurred.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361315 — COM+ Queued Components failed to obtain necessary information from the catalog.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361316 — The COM+ Queued Components Player was unable to create an instance of a Queued Component.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361317 — An unauthenticated message was received by an application that accepts only authenticated messages.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361330 — The system has called a custom component and that component has failed and generated an exception.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361332 — An error occurred while checking to see if a queued message was sent by a trusted partner.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361333 — The server was unable to determine if a queued message was sent by a trusted partner due to a lack of available memory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361334 — The server was unable to determine if a queued message was sent by a trusted partner due to an unexpected failure in a Windows API call.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361335 — The COM+ Services DLL.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361338 — COM+ Services was unable to load a required string resource.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361341 — COM+ Services was unable to initialize due to a failure in the system API shown below.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361342 — The system has called the CRM Compensator custom component and that component has failed and generated an exception.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361343 — The application cannot access the CRM log file because it is being used by another process, probably because another server process is running for ...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361344 — COM+ Services was unable to authorize the incoming call due to an unexpected failure.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361345 — COM+ Services was unable to determine the caller's identity because of an unexpected error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361346 — COM+ Services was unable to process a component's call to IsCallerInRole due to an unexpected failure.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361347 — The system has called the CRM Compensator custom component and that component has returned an error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361348 — The system failed to create the CRM Compensator custom component.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361349 — The system failed to create the CRM Compensator because the system is out of memory.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361350 — The Queued Components Listener received an improperly formatted message.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361352 — An unexpected error was returned by the Message Queuing API %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361354 — The server was unable to determine if a queued message was sent by a trusted partner due to an unexpected failure in a COM+ catalog component.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361355 — An unexpected error was returned by Message Queuing API indicated.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361360 — The Synchronization property is required for the Transaction property.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361361 — The Synchronization property is required for the JIT property.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361362 — The following component is configured for Construction, and either the IObjectConstruct::Construct() method failed, or the component does not suppo...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361366 — A condition has occurred that indicates this COM+ application is in an unstable state or is not functioning correctly.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361369 — Output arguments are not supported by queued methods.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361370 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed an ApplicationLaunch event.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361373 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed to start.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361376 — A request for a callback on a MTA thread failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361377 — The initialization of the COM+ surrogate failed -- the CApplication object failed to initialize.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361379 — The BYOT Gateway failed to import the transaction using TIP.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361380 — The BYOT Gateway failed to create the component.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361381 — The BYOT Gateway could not set transactional property in new object context.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361382 — The BYOT Gateway could not delegate the activation.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361383 — The BYOT Gateway component is incorrectly configured.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361384 — The IObjectControl::Activate() method failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361385 — Queued Components has detected an invalid Marshaled object.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361386 — Object reference passed as a method parameter to a Queued Component does not implement IPersistStream.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361387 — The CRM has lost its connection with MS-DTC.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361388 — COM+ Services was unable to initialize security infrastructure due to a failure in the system API shown below.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361392 — A non-empty queue could not be deleted.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361393 — Queued Application has an invalid catalog entry.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361394 — Queued Application has an invalid catalog entry.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361395 — Queued Components requires Message Queuing.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361396 — GetProcAddress for a Message Queuing API failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361397 — Unknown event ID.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361398 — Unable to instantiate Exception Class.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361399 — COM+ requires that ODBC version 2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361400 — COM+ was unable to set up the ODBC shared environment, which means that automatic transaction enlistment will not work.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361401 — A CRM checkpoint has failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361402 — The threading model of the component specified in the registry is inconsistent with the registration database.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361403 — CRM recovery has failed because MS-DTC thinks that the previous instance of this application is still connected.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361404 — The CRM Compensator custom component has timed out out waiting for the CRM Worker custom component to complete.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361405 — CRM recovery has failed because the device is not ready.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361406 — You have attempted to use COM+ Conversation support, and an error was generated accessing the database.
Message
Event ID 3221361407 — TransactionManager->GetWhereabouts failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361409 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed in its PauseProcess method.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361410 — A COM+ service (such as Queued Components or Compensating Resource Manager) failed in its ResumeProcess method.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361411 — The COM+ tracing GUIDs couldn't be registered.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361412 — The COM+ tracing session failed to initialize.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361413 — The COM+ event filter encountered an unexpected error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361920 — This is the first external error message in this file.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361921 — An external error has been reported to COM+ services.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361924 — COM+ could not create a new thread due to a low memory situation.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 3221361925 — This is the last external error message in this file.
Message
Fields
| Name | Description |
|---|---|
param1 | — |