Microsoft-Windows-DfsSvc
102 events across 2 channels
Event ID 14318 —
Fields #
| Name | Description |
|---|---|
unused UnicodeString | — |
path UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14500 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14501 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14503 —
Fields #
| Name | Description |
|---|---|
childDirectory UnicodeString | — |
parentDirectory UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14504 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
path UnicodeString | — |
Event ID 14505 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
directory UnicodeString | — |
Event ID 14508 —
Event ID 14509 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
Event ID 14510 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14511 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14512 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14513 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14514 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14515 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14516 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14517 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14518 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14519 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14520 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14521 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14522 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14523 —
Event ID 14524 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14526 —
Fields #
| Name | Description |
|---|---|
dc UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14529 —
Fields #
| Name | Description |
|---|---|
dc UnicodeString | — |
Event ID 14530 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14531 —
Event ID 14531 —
#Fields #
| Name | Description |
|---|---|
Name | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DfsSvc",
"guid": "{7DA4FE0E-FD42-4708-9AA5-89B77A224885}",
"event_source_name": "DfsSvc",
"event_id": 14531,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T17:06:56.167835+00:00",
"event_record_id": 433,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": ""
}
},
"event_data": {
"Name": "DfsFinishInit"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 14532 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
Event ID 14533 —
Event ID 14533 —
#Fields #
| Name | Description |
|---|---|
Name | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DfsSvc",
"guid": "{7DA4FE0E-FD42-4708-9AA5-89B77A224885}",
"event_source_name": "DfsSvc",
"event_id": 14533,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T17:06:56.166883+00:00",
"event_record_id": 432,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": ""
}
},
"event_data": {
"Name": "DfsFinishBuildingNamespace"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 14534 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14535 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14536 —
Event ID 14537 —
Event ID 14538 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
oldPath UnicodeString | — |
newPath UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14539 —
Fields #
| Name | Description |
|---|---|
share UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14540 —
Fields #
| Name | Description |
|---|---|
path UnicodeString | — |
share UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14541 —
Fields #
| Name | Description |
|---|---|
DFSLink UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14542 —
Fields #
| Name | Description |
|---|---|
DFSLink UnicodeString | — |
DFSRoot UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14543 —
Fields #
| Name | Description |
|---|---|
DFSLinkDN UnicodeString | — |
Event ID 14544 —
Fields #
| Name | Description |
|---|---|
DFSNamespace UnicodeString | — |
DFSLink1 UnicodeString | — |
DFSLink2 UnicodeString | — |
Event ID 14545 —
Fields #
| Name | Description |
|---|---|
DFSNamespace UnicodeString | — |
DFSLink1 UnicodeString | — |
Event ID 14546 —
Fields #
| Name | Description |
|---|---|
childDirectory UnicodeString | — |
parentDirectory UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14547 —
Fields #
| Name | Description |
|---|---|
DFSNamespace UnicodeString | — |
DFSFolderPath UnicodeString | — |
DFSLinkDN1 UnicodeString | — |
DFSLinkDN2 UnicodeString | — |
Event ID 14548 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14549 —
Event ID 14550 —
Fields #
| Name | Description |
|---|---|
__binLength UInt32 | — |
binary Binary | — |
Event ID 14551 —
Event ID 14552 —
Fields #
| Name | Description |
|---|---|
DFSRoot UnicodeString | — |
Event ID 14553 —
Fields #
| Name | Description |
|---|---|
SMBShare UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 14554 —
Fields #
| Name | Description |
|---|---|
SMBShare UnicodeString | — |
Event ID 1073756142 — Dfs received a referral request for "path".
Event ID 1073756324 — NetrDfsEnum received an enumeration.
Event ID 1073756325 — NetrDfsEnumEx received an enumeration.
Event ID 1073756332 — DFS re-established a connection to the PDC to initiate Domain DFS operations.
Description
DFS re-established a connection to the PDC to initiate Domain DFS operations.
Message #
Event ID 1073756353 — DFS has connected to the dc Active Directory.
Event ID 1073756355 — DFS server has finished initializing.
Description
DFS server has finished initializing.
Message #
Event ID 1073756356 — DFS has recovered from an error and is able to read its private data from the Active Directory.
Event ID 1073756357 — DFS has finished building all namespaces.
Description
DFS has finished building all namespaces.
Message #
Event ID 1073756361 — DFS is requesting the client for a larger buffer for trusted domain information.
Description
DFS is requesting the client for a larger buffer for trusted domain information. Some Win98 clients may not be able to access DFS namespaces.
Message #
Event ID 1073756373 — The DFS Namespace service successfully initialized the trusted domain information on this domain controller.
Description
The DFS Namespace service successfully initialized the trusted domain information on this domain controller.
Message #
Event ID 1073756375 — The DFS Namespace service successfully initialized cross forest trust information on this domain controller.
Description
The DFS Namespace service successfully initialized cross forest trust information on this domain controller.
Message #
Event ID 1073756376 — The DFS Namespaces service has successfully initialized the following namespace: DFSRoot.
Event ID 1073756378 — The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root.
Event ID 2147498174 — DFS could not contact the dc Active Directory.
Event ID 2147498182 — DFS Root share failed during initialization.
Event ID 2147498184 — DFS is unable to return the entire list of trusted domains to the client.
Description
DFS is unable to return the entire list of trusted domains to the client. There are too many trusted domains.
Message #
Event ID 2147498186 — DFS was unable to move all matching links of root: share for path oldPath to new path newPath.
Event ID 2147498189 — DFS link DFSLink was marked incorrectly as a DFS root.
Event ID 2147498190 — DFS metadata object DFSLink is empty in the metadata for DFS root DFSRoot.
Event ID 2147498201 — The DFS Namespaces service failed to initialize the shared folder that hosts the namespace root.
Event ID 3221239975 — Dfs could not create reparse point for directory childDirectory under directory parentDirectory.
Event ID 3221239976 — Share share mapped to path does not support reparse points.
Event ID 3221239977 — Share share mapped to directory directory overlaps an existing root.
Event ID 3221239981 — Root share has too many errors.
Event ID 3221239982 — DFS could not initialize winsock library.
Event ID 3221239983 — DFS could not initialize security library.
Event ID 3221239984 — DFS could not create DFS support thread.
Event ID 3221239985 — DFS could not initialize IP site cache.
Event ID 3221239986 — DFS could not synchronize all DFS roots.
Event ID 3221239987 — DFS could not create event handle.
Event ID 3221239988 — DFS could not get required computer information.
Event ID 3221239989 — DFS could not get required cluster information.
Event ID 3221239990 — DFS could not get required DC information.
Event ID 3221239991 — DFS could not initialize prefix table.
Event ID 3221239992 — DFS could not initialize DFS namespace.
Event ID 3221239993 — DFS could not Register DFS Namespaces.
Event ID 3221239994 — DFS could not initialize User/kernel communication package.
Event ID 3221239995 — DFS could not contact any DC for Domain DFS operations.
Description
DFS could not contact any DC for Domain DFS operations. This operation will be retried periodically.