Microsoft-Windows-DeviceSetupManager
102 events across 4 channels
Event ID 10 — DSM service feature Prop_FeatureId is Prop_FeatureEnablement.
Event ID 11 — DSM service is idle and waiting for Prop_IdleWait.
Event ID 20 — DSM service is running in special OOBE based on OS product policy.
Description
DSM service is running in special OOBE based on OS product policy.
Message #
Event ID 21 — Auto download settings have been committed in OOBE: Store App Updates Prop_AppUpdatesEnablement, Windows Updates Prop_WindowsUpdatesEnablement.
Event ID 30 — Device container Prop_ContainerId is queued for setup.
Event ID 40 — Prop_ServerSelection search started.
Event ID 41 — Prop_ServerSelection search completed.
Event ID 42 — Prop_ServerSelection search failed with error HRESULT.
Event ID 43 — Driver update search is being cancelled.
Description
Driver update search is being cancelled.
Message #
Event ID 44 — Prop_ServerSelection search was cancelled.
Event ID 50 — Driver recovery on reboot task is Prop_TaskEnablement.
Event ID 50 —
Description
Driver recovery on reboot task is .
Fields #
| Name | Description |
|---|---|
Prop_TaskEnablement UInt8 | — |
Event ID 51 — Driver recovery action is requested since it was queued for the next reboot.
Description
Driver recovery action is requested since it was queued for the next reboot.
Message #
Event ID 51 —
Description
Driver recovery action is requested since it was queued for the next reboot.
Event ID 52 — Driver recovery request is received.
Event ID 52 —
Description
Driver recovery request is received. Last trigger: .
Fields #
| Name | Description |
|---|---|
Prop_DriverRecoveryRequest UInt32 | — |
Event ID 100 — DSM service started, mode is Prop_CoreServiceMode, last session (or boot) was Prop_Event_Window_Seconds seconds ago.
#Description
DSM service started, mode is Prop_CoreServiceMode, last session (or boot) was Prop_Event_Window_Seconds seconds ago.
Message #
Fields #
| Name | Description |
|---|---|
Prop_CoreServiceMode UInt32 | — |
Prop_Event_Window_Seconds Int64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 100,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:40.195484+00:00",
"event_record_id": 71,
"correlation": {},
"execution": {
"process_id": 1856,
"thread_id": 2020
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_CoreServiceMode": 3,
"Prop_Event_Window_Seconds": 0
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 101 — DSM Service is shutting down.
#Description
DSM Service is shutting down. Service uptime was Prop_UpTime_Seconds seconds, active worktime was Prop_WorkTime_MilliSeconds ms.
Message #
Fields #
| Name | Description |
|---|---|
Prop_UpTime_Seconds Int64 | — |
Prop_WorkTime_MilliSeconds Int64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 101,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-05T22:31:27.668358+00:00",
"event_record_id": 80,
"correlation": {
"ActivityID": "59A0D65F-1037-0002-780C-A1593710DA01"
},
"execution": {
"process_id": 3256,
"thread_id": 5088
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_UpTime_Seconds": 45,
"Prop_WorkTime_MilliSeconds": 943
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 102 — DSM Service dll has loaded.
Description
DSM Service dll has loaded.
Message #
Event ID 103 — DSM Service dll is unloading.
Description
DSM Service dll is unloading.
Message #
Event ID 104 — DSM Service failed to start, result=HRESULT.
Event ID 105 — DSM Service is entering a retry sequence because soft (retryable) errors were encountered
#Description
DSM Service is entering a retry sequence because soft (retryable) errors were encountered.
Message #
Fields #
| Name | Description |
|---|---|
Prop_RetryCycleCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 105,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T22:48:32.040193+00:00",
"event_record_id": 61,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 2344
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 106 — DSM Service is leaving the retry state, there have been Prop_RetryCycleCount retry cycles in this session.
#Description
DSM Service is leaving the retry state, there have been Prop_RetryCycleCount retry cycles in this session.
Message #
Fields #
| Name | Description |
|---|---|
Prop_RetryCycleCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T22:49:06.917617+00:00",
"event_record_id": 63,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 2344
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_RetryCycleCount": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 107 — DSM service has shut down.
Description
DSM service has shut down.
Message #
Event ID 108 — DSM service has entered service state 'Prop_CoreServiceState'.
Event ID 109 — DSM service has entered service mode 'Prop_CoreServiceMode'.
#Description
DSM service has entered service mode 'Prop_CoreServiceMode'.
Message #
Fields #
| Name | Description |
|---|---|
Prop_CoreServiceMode UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 109,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-06T06:25:39.185383+00:00",
"event_record_id": 70,
"correlation": {},
"execution": {
"process_id": 1856,
"thread_id": 2020
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_CoreServiceMode": 3
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 110 — Job (Prop_JobId) has started for device container 'Prop_ContainerId', type=Prop_JobType.
Event ID 111 — Job (Prop_JobId) has completed for device container 'Prop_ContainerId', status=Prop_JobStatus.
Event ID 112 — Device container 'Prop_DeviceName' (Prop_ContainerId) has been serviced, processed Prop_TaskCount tasks, and wrote Prop_PropertyCount properties in Prop_WorkTime_MilliSeconds ms.
#Description
Device container 'Prop_DeviceName' (Prop_ContainerId) has been serviced, processed Prop_TaskCount tasks, and wrote Prop_PropertyCount properties in Prop_WorkTime_MilliSeconds ms.
Message #
Fields #
| Name | Description |
|---|---|
Prop_DeviceName UnicodeString | — |
Prop_ContainerId GUID | — |
Prop_TaskCount Int32 | — |
Prop_PropertyCount Int32 | — |
Prop_WorkTime_MilliSeconds Int64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 112,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-11-05T22:30:42.670052+00:00",
"event_record_id": 79,
"correlation": {},
"execution": {
"process_id": 3256,
"thread_id": 4616
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_DeviceName": "Generic Monitor",
"Prop_ContainerId": "1074B24D-B986-5A01-B420-B3D39C2F9286",
"Prop_TaskCount": 4,
"Prop_PropertyCount": 34,
"Prop_WorkTime_MilliSeconds": 928
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 120 — Driver update(s) was downloaded for device 'Prop_PackageId' in Prop_MilliSeconds ms.
Event ID 121 — Driver update(s) install on device 'Prop_DevnodeId' failed with error HRESULT.
Event ID 122 — Access to drivers on Windows Update was blocked by policy
Event ID 123 — DSM service was delayed by Prop_Seconds seconds for a driver query/download/install on device 'Prop_DeviceId'.
#Description
DSM service was delayed by Prop_Seconds seconds for a driver query/download/install on device 'Prop_DeviceId'.
Message #
Fields #
| Name | Description |
|---|---|
Prop_Seconds Int32 | — |
Prop_DeviceId UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 123,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T21:25:33.223885+00:00",
"event_record_id": 10,
"correlation": {},
"execution": {
"process_id": 2076,
"thread_id": 3168
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_Seconds": 36,
"Prop_DeviceId": "PCI\\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\\3&61AAA01&0&3F"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 124 — Driver Prop_PackageId was installed on device 'Prop_DeviceInstanceId' in Prop_MilliSeconds ms.
Event ID 125 — Driver install on device 'Prop_DevnodeId' was blocked by PnP restriction policy.
Event ID 126 — Device 'Prop_DeviceInstanceId' matched driver update Prop_PackageId.
#Description
Device 'Prop_DeviceInstanceId' matched driver update Prop_PackageId.
Message #
Fields #
| Name | Description |
|---|---|
Prop_DeviceInstanceId UnicodeString | — |
Prop_PackageId UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 126,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T21:25:25.745333+00:00",
"event_record_id": 8,
"correlation": {},
"execution": {
"process_id": 2076,
"thread_id": 3168
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_DeviceInstanceId": "PCI\\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\\3&61AAA01&0&3F",
"Prop_PackageId": "b5857a80-fd07-4a9d-9adf-2a3a6db94b7e"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 127 — Device 'Prop_DevnodeId' does not match any driver updates that are not optional.
Event ID 130 — Metadata package Prop_MetadataPackageId was staged for device container Prop_ContainerId in Prop_StageTimeMilliSeconds ms.
Event ID 131 — Metadata package staging for device container Prop_ContainerId failed with error HRESULT.
#Description
Metadata package staging for device container Prop_ContainerId failed with error HRESULT.
Message #
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
HRESULT UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 131,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T21:34:20.832199+00:00",
"event_record_id": 21,
"correlation": {},
"execution": {
"process_id": 6296,
"thread_id": 5380
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_ContainerId": "{00000000-0000-0000-FFFF-FFFFFFFFFFFF}",
"HRESULT": 2147943623
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 132 — Metadata package search for device container Prop_ContainerId on Windows Metadata and Internet Services (WMIS) failed with error HRESULT, HTTP status code: HTTPCode.
Event ID 133 — Metadata package Prop_PackageId download for device container Prop_ContainerId failed with error HRESULT.
Event ID 134 — Metadata package search for device container Prop_ContainerId completed.
Event ID 135 — Metadata package search for device container Prop_ContainerId completed.
Event ID 136 — Metadata package Prop_PackageId was blocked.
Event ID 137 — Signature verification failed for metadata package Prop_PackageId from metadata store, error Error.
Event ID 138 — Metadata package Prop_PackageId was not fully staged due to signature verification: Prop_IsLegacySigCheckForFile1 for 'Prop_FileName1' had result HRESULT1, Prop_IsLegacySigCheckForFile2 for 'Prop_F...
Description
Metadata package Prop_PackageId was not fully staged due to signature verification: Prop_IsLegacySigCheckForFile1 for 'Prop_FileName1' had result HRESULT1, Prop_IsLegacySigCheckForFile2 for 'Prop_FileName2' had result HRESULT2.
Message #
Fields #
| Name | Description |
|---|---|
Prop_PackageId UnicodeString | — |
Prop_IsLegacySigCheckForFile1 UInt8 | — |
Prop_FileName1 UnicodeString | — |
HRESULT1 HexInt32 | — |
Prop_IsLegacySigCheckForFile2 UInt8 | — |
Prop_FileName2 UnicodeString | — |
HRESULT2 HexInt32 | — |
Event ID 150 — Device 'Prop_DeviceName' (Prop_ContainerId) was removed.
Event ID 151 — Device 'Prop_DeviceName' (Prop_ContainerId) failed to respond to a device removal request.
Event ID 152 — Device 'Prop_DeviceName' (Prop_ContainerId) removal failed with error HRESULT.
Event ID 160 — Software Prop_SoftwareName was installed for device 'Prop_DeviceInstanceId' in Prop_InstallTime ms.
Event ID 161 — Software Prop_SoftwareName was not newer, Version: 'Prop_HiHighPartNew.
Description
Software Prop_SoftwareName was not newer, Version: 'Prop_HiHighPartNew.Prop_LoHighPartNew.Prop_HiLowPartNew.Prop_LoLowPartNew'. Current Version: 'Prop_HiHighPartOld.Prop_LoHighPartOld.Prop_HiLowPartOld.Prop_LoLowPartOld'.
Message #
Fields #
| Name | Description |
|---|---|
Prop_SoftwareName UnicodeString | — |
Prop_HiHighPartNew UInt32 | — |
Prop_LoHighPartNew UInt32 | — |
Prop_HiLowPartNew UInt32 | — |
Prop_LoLowPartNew UInt32 | — |
Prop_HiHighPartOld UInt32 | — |
Prop_LoHighPartOld UInt32 | — |
Prop_HiLowPartOld UInt32 | — |
Prop_LoLowPartOld UInt32 | — |
Event ID 162 — Software Prop_SoftwareName failed installation with error Prop_DeviceInstanceId.
Event ID 163 — Software Prop_SoftwareName failed installation with error Prop_DeviceInstanceId and process exit code Error.
Event ID 164 — Software Prop_SoftwareName had non-critical error Prop_DeviceInstanceId during installation, will retry later.
Event ID 165 — Software Prop_SoftwareName is being launched with command line: 'Prop_CommandLine'.
Event ID 166 — Device 'Prop_DeviceInstanceId' requested Store App for 'Prop_SoftwareLinks'.
Event ID 167 — Product for pfn IsFramework located: ProductId: Prop_ProductId, IsFramework: Prop_SoftwarePfn.
Event ID 168 — Uninstalling existing pfn Prop_SoftwarePfn failed with error ErrorCode.
Event ID 169 — Store product Prop_ProductId is already installed and is being checked for updates.
Event ID 170 — Store product Prop_ProductId is being installed.
Event ID 171 — ProductId Prop_ProductId done processing, install Prop_InstallType completed with error %3.
Event ID 172 — Store product Prop_ProductId install (Prop_InstallType) failed with error HRESULT.
Event ID 180 — Retrieving entitlement for Store product Prop_ProductId failed with error ErrorCode.
Event ID 190 — Property heuristics for device container 'Prop_DeviceName' (Prop_ContainerId) completed in Prop_MilliSeconds ms.
Event ID 191 — Property heuristics for device container 'Prop_DeviceName' (Prop_ContainerId) failed with error HRESULT.
Event ID 200 — Connection to the Windows Update service could not be established.
#Description
Connection to the Windows Update service could not be established.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 200,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T22:48:31.260287+00:00",
"event_record_id": 56,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 2300
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 201 — Connection to the Windows Metadata and Internet Services (WMIS) could not be established.
#Description
Connection to the Windows Metadata and Internet Services (WMIS) could not be established.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 201,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T22:48:32.032702+00:00",
"event_record_id": 59,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 2344
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 202 — The Network List Manager reports no connectivity to the internet.
#Description
The Network List Manager reports no connectivity to the internet.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 202,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T22:48:32.030724+00:00",
"event_record_id": 58,
"correlation": {},
"execution": {
"process_id": 1028,
"thread_id": 2344
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 203 — The Network List Manager reports connection to the internet has been established.
Description
The Network List Manager reports connection to the internet has been established.
Message #
Event ID 220 — Registered the handler Prop_NotificationHandler for the app Prop_PackageId to handle notifications from the device container Prop_ContainerId.
Event ID 221 — App Prop_PackageId already has a handler registered for the device container Prop_ContainerId.
Event ID 222 — Device container Prop_ContainerId and app Prop_PackageId specify background task information, but registration failed with error HRESULT.
Event ID 223 — Unregistered for the Print background task after uninstalling the app Prop_PackageId.
Event ID 224 — Unregistered for the Mobile Operator background task after uninstalling the app Prop_PackageId.
Event ID 230 — Requested download of the app Prop_PackageId from the store for device Prop_ContainerId.
Event ID 231 — Successfully installed the app Prop_PackageId from the store for device Prop_ContainerId.
Event ID 232 — Encountered error trying to install app Prop_PackageId from the store for device Prop_ContainerId.
Event ID 233 — Encountered error trying to install app Prop_PackageId from the store for device Prop_ContainerId.
Event ID 234 — Driver update(s) was installed on device 'Prop_DevnodeId' in Prop_MilliSeconds ms.
#Description
Driver update(s) was installed on device 'Prop_DevnodeId' in Prop_MilliSeconds ms.
Message #
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Prop_MilliSeconds Int64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 234,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2023-10-25T21:25:33.223883+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 2076,
"thread_id": 3168
},
"channel": "Microsoft-Windows-DeviceSetupManager/Admin",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_DevnodeId": "PCI\\VEN_15AD&DEV_0740&SUBSYS_074015AD&REV_10\\3&61AAA01&0&3F",
"Prop_MilliSeconds": 36967
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — Device container 'Prop_ContainerId' has entered the ready state.
#Description
Device container 'Prop_ContainerId' has entered the ready state.
Message #
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 300,
"version": 0,
"level": 4,
"task": 0,
"opcode": 10,
"keywords": 9223372036854775808,
"time_created": "2023-10-25T22:50:55.529095+00:00",
"event_record_id": 19,
"correlation": {},
"execution": {
"process_id": 3156,
"thread_id": 4092
},
"channel": "Microsoft-Windows-DeviceSetupManager/Operational",
"computer": "WinDevEval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_ContainerId": "{FF3C9BFC-6A33-58E1-8CFA-A12CE4352D2F}"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 301 — Device setup for device container 'Prop_ContainerId' has been completed.
#Description
Device setup for device container 'Prop_ContainerId' has been completed.
Message #
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DeviceSetupManager",
"guid": "FCBB06BB-6A2A-46E3-ABAA-246CB4E508B2",
"event_source_name": "",
"event_id": 301,
"version": 0,
"level": 4,
"task": 0,
"opcode": 11,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:30:42.666470+00:00",
"event_record_id": 22,
"correlation": {},
"execution": {
"process_id": 3256,
"thread_id": 4616
},
"channel": "Microsoft-Windows-DeviceSetupManager/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Prop_ContainerId": "{1074B24D-B986-5A01-B420-B3D39C2F9286}"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 302 — Device metadata that contains an extension namespace has been parsed for device container 'Prop_ContainerId', ExtensionNamespace = 'Prop_ServiceInfoNamespace', Culture = 'Prop_CultureCode'.
Description
Device metadata that contains an extension namespace has been parsed for device container 'Prop_ContainerId', ExtensionNamespace = 'Prop_ServiceInfoNamespace', Culture = 'Prop_CultureCode'.
Message #
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
Prop_ServiceInfoNamespace UnicodeString | — |
Prop_CultureCode UnicodeString | — |
Event ID 400 —
Fields #
| Name | Description |
|---|---|
Prop_ContainerId GUID | — |
Event ID 401 —
Fields #
| Name | Description |
|---|---|
Prop_ContainerId GUID | — |
Event ID 402 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Event ID 403 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
HRESULT UInt32 | — |
Event ID 404 —
Fields #
| Name | Description |
|---|---|
Prop_PackagePath UnicodeString | — |
Event ID 405 —
Fields #
| Name | Description |
|---|---|
Prop_PackagePath UnicodeString | — |
Event ID 406 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Event ID 407 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
HRESULT UInt32 | — |
Event ID 408 —
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
Event ID 409 —
Fields #
| Name | Description |
|---|---|
Prop_ContainerId UnicodeString | — |
Event ID 410 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Event ID 411 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
HRESULT UInt32 | — |
Event ID 412 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Event ID 413 —
Fields #
| Name | Description |
|---|---|
Prop_DevnodeId UnicodeString | — |
Event ID 7710 — ENTER: Searching WU for driver updates.
Description
ENTER: Searching WU for driver updates.
Message #
Event ID 7711 — EXIT: Searching WU for driver updates.
Description
EXIT: Searching WU for driver updates.
Message #
Event ID 7712 — ENTER: Downloading driver update from WU.
Description
ENTER: Downloading driver update from WU.
Message #
Event ID 7713 — EXIT: Downloading driver update from WU.
Description
EXIT: Downloading driver update from WU.
Message #
Event ID 7714 — ENTER: Installing driver update from WU.
Description
ENTER: Installing driver update from WU.
Message #
Event ID 7715 — EXIT: Installing driver update from WU.
Description
EXIT: Installing driver update from WU.