Microsoft-Windows-DeviceSetupManager
102 events across 4 channels
Event ID 10 — DSM service feature %1 is %2.
Message
Fields
| Name | Description |
|---|---|
Prop_FeatureId | — |
Prop_FeatureEnablement | — |
Event ID 11 — DSM service is idle and waiting for %1.
Message
Fields
| Name | Description |
|---|---|
Prop_IdleWait | — |
Event ID 20 — DSM service is running in special OOBE based on OS product policy.
Message
Event ID 21 — Auto download settings have been committed in OOBE: Store App Updates %1, Windows Updates %2.
Message
Fields
| Name | Description |
|---|---|
Prop_AppUpdatesEnablement | — |
Prop_WindowsUpdatesEnablement | — |
Event ID 30 — Device container %1 is queued for setup.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 40 — %1 search started.
Message
Fields
| Name | Description |
|---|---|
Prop_ServerSelection | — |
Event ID 41 — %1 search completed.
Message
Fields
| Name | Description |
|---|---|
Prop_ServerSelection | — |
Event ID 42 — %1 search failed with error %2.
Message
Fields
| Name | Description |
|---|---|
Prop_ServerSelection | — |
HRESULT | — |
Event ID 43 — Driver update search is being cancelled.
Message
Event ID 44 — %1 search was cancelled.
Message
Fields
| Name | Description |
|---|---|
Prop_ServerSelection | — |
Event ID 50 —
Fields
| Name | Description |
|---|---|
Prop_TaskEnablement | — |
Event ID 50 — Driver recovery on reboot task is %1.
Message
Fields
| Name | Description |
|---|---|
Prop_TaskEnablement | — |
Event ID 51 —
Event ID 51 — Driver recovery action is requested since it was queued for the next reboot.
Message
Event ID 52 —
Fields
| Name | Description |
|---|---|
Prop_DriverRecoveryRequest | — |
Event ID 52 — Driver recovery request is received.
Message
Fields
| Name | Description |
|---|---|
Prop_DriverRecoveryRequest | — |
Event ID 100 — DSM service started, mode is %1, last session (or boot) was %2 seconds ago.
Message
Fields
| Name | Description |
|---|---|
Prop_CoreServiceMode | — |
Prop_Event_Window_Seconds | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 100
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:40.195484+00:00'
event_record_id: 71
correlation: {}
execution:
process_id: 1856
thread_id: 2020
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Prop_CoreServiceMode: 3
Prop_Event_Window_Seconds: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 101 — DSM Service is shutting down.
Message
Fields
| Name | Description |
|---|---|
Prop_UpTime_Seconds | — |
Prop_WorkTime_MilliSeconds | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 101
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:27.668358+00:00'
event_record_id: 80
correlation:
ActivityID: 59A0D65F-1037-0002-780C-A1593710DA01
execution:
process_id: 3256
thread_id: 5088
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Prop_UpTime_Seconds: 45
Prop_WorkTime_MilliSeconds: 943
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 102 — DSM Service dll has loaded.
Message
Event ID 103 — DSM Service dll is unloading.
Message
Event ID 104 — DSM Service failed to start, result=.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 105 — DSM Service is entering a retry sequence because soft (retryable) errors were encountered
Message
Fields
| Name | Description |
|---|---|
Prop_RetryCycleCount | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 105
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T22:48:32.040193+00:00'
event_record_id: 61
correlation: {}
execution:
process_id: 1028
thread_id: 2344
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 106 — DSM Service is leaving the retry state, there have been %1 retry cycles in this session.
Message
Fields
| Name | Description |
|---|---|
Prop_RetryCycleCount | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 106
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T22:49:06.917617+00:00'
event_record_id: 63
correlation: {}
execution:
process_id: 1028
thread_id: 2344
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_RetryCycleCount: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 107 — DSM service has shut down.
Message
Event ID 108 — The DSM service has entered service state '.
Message
Fields
| Name | Description |
|---|---|
Prop_CoreServiceState | — |
Event ID 109 — DSM service has entered service mode '.
Message
Fields
| Name | Description |
|---|---|
Prop_CoreServiceMode | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 109
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:39.185383+00:00'
event_record_id: 70
correlation: {}
execution:
process_id: 1856
thread_id: 2020
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Prop_CoreServiceMode: 3
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 110 — Job (%2) has started for device container '%1', type=%3.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_JobId | — |
Prop_JobType | — |
Event ID 111 — Job (%2) has completed for device container '%1', status=%3.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_JobId | — |
Prop_JobStatus | — |
Event ID 112 — Device container '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
Prop_TaskCount | — |
Prop_PropertyCount | — |
Prop_WorkTime_MilliSeconds | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 112
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:42.670052+00:00'
event_record_id: 79
correlation: {}
execution:
process_id: 3256
thread_id: 4616
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Prop_DeviceName: Generic Monitor
Prop_ContainerId: 1074B24D-B986-5A01-B420-B3D39C2F9286
Prop_TaskCount: 4
Prop_PropertyCount: 34
Prop_WorkTime_MilliSeconds: 928
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 120 — Driver update(s) was downloaded for device '.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Prop_MilliSeconds | — |
Event ID 121 — Driver install failed, result=.
Message
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
HRESULT | — |
Event ID 122 — Access to drivers on Windows Update was blocked by policy
Message
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 123 — DSM service was delayed by %1 seconds for a driver query/download/install on device '%2'.
Message
Fields
| Name | Description |
|---|---|
Prop_Seconds | — |
Prop_DeviceId | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 123
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:25:33.223885+00:00'
event_record_id: 10
correlation: {}
execution:
process_id: 2076
thread_id: 3168
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_Seconds: 36
Prop_DeviceId: PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&61AAA01&0&3F
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 124 — Driver %1 was installed on device '%2' in %3 ms.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Prop_DeviceInstanceId | — |
Prop_MilliSeconds | — |
Event ID 125 — Driver install on device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 126 — Device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceInstanceId | — |
Prop_PackageId | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 126
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:25:25.745333+00:00'
event_record_id: 8
correlation: {}
execution:
process_id: 2076
thread_id: 3168
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_DeviceInstanceId: PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&61AAA01&0&3F
Prop_PackageId: b5857a80-fd07-4a9d-9adf-2a3a6db94b7e
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 127 — Device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 130 — Metadata package %1 was staged for device container %2 in %3 ms.
Message
Fields
| Name | Description |
|---|---|
Prop_MetadataPackageId | — |
Prop_ContainerId | — |
Prop_StageTimeMilliSeconds | — |
Event ID 131 — Metadata staging failed, result=.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
HRESULT | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 131
version: 0
level: 2
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:34:20.832199+00:00'
event_record_id: 21
correlation: {}
execution:
process_id: 6296
thread_id: 5380
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_ContainerId: '{00000000-0000-0000-FFFF-FFFFFFFFFFFF}'
HRESULT: 2147943623
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 132 — Metadata package search for device container %1 on Windows Metadata and Internet Services (WMIS) failed with error %2, HTTP status code: %3.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
HRESULT | — |
HTTPCode | — |
Event ID 133 — Metadata package %1 download for device container %2 failed with error %3.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Prop_ContainerId | — |
HRESULT | — |
Event ID 134 — Metadata package search for device container %1 completed.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 135 — Metadata package search for device container %1 completed.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 136 — Metadata package %1 was blocked.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Event ID 137 — Signature verification failed for metadata package %1 from metadata store, error %2.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Error | — |
Event ID 138 — Metadata package %1 was not fully staged due to signature verification: %2 for '%3' had result %4, %5 for '%6' had result %7.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Prop_IsLegacySigCheckForFile1 | — |
Prop_FileName1 | — |
HRESULT1 | — |
Prop_IsLegacySigCheckForFile2 | — |
Prop_FileName2 | — |
HRESULT2 | — |
Event ID 150 — The device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
Event ID 151 — The device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
Event ID 152 — Removal of device node '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
HRESULT | — |
Event ID 160 — Software %1 was installed for device '%2' in %3 ms.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_DeviceInstanceId | — |
Prop_InstallTime | — |
Event ID 161 — Software %1 was not newer, Version: '%2.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_HiHighPartNew | — |
Prop_LoHighPartNew | — |
Prop_HiLowPartNew | — |
Prop_LoLowPartNew | — |
Prop_HiHighPartOld | — |
Prop_LoHighPartOld | — |
Prop_HiLowPartOld | — |
Prop_LoLowPartOld | — |
Event ID 162 — Software %1 failed installation with error %2.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_DeviceInstanceId | — |
HRESULT | — |
Event ID 163 — Software %1 failed installation with error %2 and process exit code %3.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_DeviceInstanceId | — |
Error | — |
HRESULT | — |
Event ID 164 — Software %1 had non-critical error %2 during installation, will retry later.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_DeviceInstanceId | — |
HRESULT | — |
Event ID 165 — Software %1 is being launched with command line: '%2'.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwareName | — |
Prop_CommandLine | — |
Event ID 166 — Device '%1' requested Store App for '%2'.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceInstanceId | — |
Prop_SoftwareLinks | — |
Event ID 167 — Product for pfn %1 located: ProductId: %2, IsFramework: %3.
Message
Fields
| Name | Description |
|---|---|
IsFramework | 1 located: ProductId. |
Prop_ProductId | — |
Prop_SoftwarePfn | — |
Event ID 168 — Uninstalling existing pfn %1 failed with error %2.
Message
Fields
| Name | Description |
|---|---|
Prop_SoftwarePfn | — |
ErrorCode | — |
Event ID 169 — Store product %1 is already installed and is being checked for updates.
Message
Fields
| Name | Description |
|---|---|
Prop_ProductId | — |
Event ID 170 — Store product %1 is being installed.
Message
Fields
| Name | Description |
|---|---|
Prop_ProductId | — |
Event ID 171 — ProductId %1 done processing, install %2 completed with error %3.
Message
Fields
| Name | Description |
|---|---|
Prop_ProductId | — |
Prop_InstallType | — |
Event ID 172 — Store product %1 install (%2) failed with error %3.
Message
Fields
| Name | Description |
|---|---|
Prop_ProductId | — |
Prop_InstallType | — |
HRESULT | — |
Event ID 180 — Retrieving entitlement for Store product %1 failed with error %2.
Message
Fields
| Name | Description |
|---|---|
Prop_ProductId | — |
ErrorCode | — |
Event ID 190 — Property heuristics for device container '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
Prop_MilliSeconds | — |
Event ID 191 — Property heuristics for device container '.
Message
Fields
| Name | Description |
|---|---|
Prop_DeviceName | — |
Prop_ContainerId | — |
HRESULT | — |
Prop_MilliSeconds | — |
Event ID 200 — Connection to the Windows Update service could not be established.
Message
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 200
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T22:48:31.260287+00:00'
event_record_id: 56
correlation: {}
execution:
process_id: 1028
thread_id: 2300
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 201 — Connection to the Windows Metadata and Internet Services (WMIS) could not be established.
Message
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 201
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T22:48:32.032702+00:00'
event_record_id: 59
correlation: {}
execution:
process_id: 1028
thread_id: 2344
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 202 — The Network List Manager reports no connectivity to the internet.
Message
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 202
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T22:48:32.030724+00:00'
event_record_id: 58
correlation: {}
execution:
process_id: 1028
thread_id: 2344
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 203 — The Network List Manager reports connection to the internet has been established.
Message
Event ID 220 — Registered the handler %3 for the app %2 to handle notifications from the device container %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Prop_NotificationHandler | — |
Event ID 221 — App %2 already has a handler registered for the device container %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 222 — Device container %1 and app %2 specify background task information, but registration failed with error %3.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
HRESULT | — |
Event ID 223 — Unregistered for the Print background task after uninstalling the app %1.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Event ID 224 — Unregistered for the Mobile Operator background task after uninstalling the app %1.
Message
Fields
| Name | Description |
|---|---|
Prop_PackageId | — |
Event ID 230 — Requested download of the app %2 from the store for device %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 231 — Successfully installed the app %2 from the store for device %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 232 — Encountered error trying to install app %2 from the store for device %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 233 — Encountered error trying to install app %2 from the store for device %1.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_PackageId | — |
Event ID 234 — Driver update(s) was installed on device '.
Message
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Prop_MilliSeconds | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 234
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-10-25T21:25:33.223883+00:00'
event_record_id: 9
correlation: {}
execution:
process_id: 2076
thread_id: 3168
channel: Microsoft-Windows-DeviceSetupManager/Admin
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_DevnodeId: PCI\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\3&61AAA01&0&3F
Prop_MilliSeconds: 36967
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — Device container '.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 300
version: 0
level: 4
task: 0
opcode: 10
keywords: 9223372036854775808
time_created: '2023-10-25T22:50:55.529095+00:00'
event_record_id: 19
correlation: {}
execution:
process_id: 3156
thread_id: 4092
channel: Microsoft-Windows-DeviceSetupManager/Operational
computer: WinDevEval
security:
user_id: S-1-5-18
event_data:
Prop_ContainerId: '{FF3C9BFC-6A33-58E1-8CFA-A12CE4352D2F}'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 301 — Device setup for device container '.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Example Event
system:
provider: Microsoft-Windows-DeviceSetupManager
guid: FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2
event_source_name: ''
event_id: 301
version: 0
level: 4
task: 0
opcode: 11
keywords: 9223372036854775808
time_created: '2023-11-05T22:30:42.666470+00:00'
event_record_id: 22
correlation: {}
execution:
process_id: 3256
thread_id: 4616
channel: Microsoft-Windows-DeviceSetupManager/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Prop_ContainerId: '{1074B24D-B986-5A01-B420-B3D39C2F9286}'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 302 — Device metadata that contains an extension namespace has been parsed for container '.
Message
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Prop_ServiceInfoNamespace | — |
Prop_CultureCode | — |
Event ID 400 —
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 401 —
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 402 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 403 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
HRESULT | — |
Event ID 404 —
Fields
| Name | Description |
|---|---|
Prop_PackagePath | — |
Event ID 405 —
Fields
| Name | Description |
|---|---|
Prop_PackagePath | — |
Event ID 406 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 407 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
HRESULT | — |
Event ID 408 —
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 409 —
Fields
| Name | Description |
|---|---|
Prop_ContainerId | — |
Event ID 410 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 411 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
HRESULT | — |
Event ID 412 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |
Event ID 413 —
Fields
| Name | Description |
|---|---|
Prop_DevnodeId | — |