Microsoft-Windows-Dhcp-Client
164 events across 3 channels
Event ID 1000 — Your computer has lost the lease to its IP address %1 on the Network Card with network address %3.
Message
Fields
| Name | Description |
|---|---|
Address | — |
HWLength | — |
HWAddress | — |
Event ID 1001 — Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address %2.
Message
Fields
| Name | Description |
|---|---|
HWLength | — |
HWAddress | — |
StatusCode | — |
Event ID 1002 — The IP address lease %1 for the Network Card with network address %3 has been denied by the DHCP server %4 (The DHCP Server sent a DHCPNACK message).
Message
Fields
| Name | Description |
|---|---|
Address1 | — |
HWLength | — |
HWAddress | — |
Address2 | — |
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 1002
version: 0
level: 2
task: 3
opcode: 76
keywords: 4611686018427387905
time_created: '2023-10-25T22:48:31.191302+00:00'
event_record_id: 7
correlation: {}
execution:
process_id: 2076
thread_id: 2312
channel: Microsoft-Windows-Dhcp-Client/Admin
computer: WinDevEval
security:
user_id: S-1-5-19
event_data:
Address1: 2182457536
HWLength: 6
HWAddress: 000C29B19818
Address2: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1003 — Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address %2.
Message
Fields
| Name | Description |
|---|---|
HWLength | — |
HWAddress | — |
StatusCode | — |
Event ID 1004 — Error occurred in stopping the Dhcpv4 Client service.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
DwordVal | — |
Event ID 1005 — Your computer has detected that the IP address %1 for the Network Card with network address %3 is already in use on the network.
Message
Fields
| Name | Description |
|---|---|
Address | — |
HWLength | — |
HWAddress | — |
Event ID 1006 — Your computer was unable to automatically configure the IP parameters for the Network Card with the network address %2.
Message
Fields
| Name | Description |
|---|---|
HWLength | — |
HWAddress | — |
StatusCode | — |
Event ID 1007 — Your computer has automatically configured the IP address for the Network Card with network address %2.
Message
Fields
| Name | Description |
|---|---|
HWLength | — |
HWAddress | — |
Address | — |
Event ID 1008 — Your computer was unable to initialize a Network Interface attached to the system.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1018 — Dhcpv6 Initialization has failed on the computer with the error code %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1019 — Unplumbing OLD Config for the adapter.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1020 — Stack Media Connect.
Message
Fields
| Name | Description |
|---|---|
Stack_Media_Connect | — |
AdapterName | — |
Event ID 1021 — MEDIA DISCONNECT: Someone still using context.
Message
Event ID 1022 — Updating Stack with CACHED config %1 on %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
AdapterName | — |
ErrorCode | — |
Event ID 1023 — Updating Stack at address %1 on %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
AdapterName | — |
ErrorCode | — |
Event ID 1024 — Handling ip conflct on %1.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1025 — Waiting for Offer on %1.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
TimeToWaitLeft | — |
Event ID 1026 — Receiving a DHCP message on %1.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
ErrorCode | — |
Event ID 1027 — Received DHCP message on %1 is NOT Offer.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1028 — Waiting for ACK on %1.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1029 — Waiting for Renew ACK on %1.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1030 — OBTAIN LEASE - AdapterName: %1 Interface LUID: %2.
Message
Fields
| Name | Description |
|---|---|
OBTAIN_LEASE__AdapterName | OBTAIN LEASE - AdapterName. |
Interface_LUID | — |
AdapterName | — |
InterfaceLUID | — |
Event ID 1031 — DhcpRenewState.
Message
Fields
| Name | Description |
|---|---|
DhcpRenewState | — |
AdapterName | — |
Event ID 1032 — InitRebootState.
Message
Fields
| Name | Description |
|---|---|
InitRebootState | — |
AdapterName | — |
Event ID 1033 — DhcpSetGatewaysAndStaticRoutes for the adapter: %1, Error: %2.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
ErrorCode | — |
Event ID 1034 — DhcpDeleteGatewaysAndStaticRoutes for the adapter: %1, Error: %2.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
ErrorCode | — |
Event ID 1035 — Route is added with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4.
Message
Fields
| Name | Description |
|---|---|
Address1 | — |
Address2 | — |
Address3 | — |
Address4 | — |
Event ID 1036 — Route is deleted with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4.
Message
Fields
| Name | Description |
|---|---|
Address1 | — |
Address2 | — |
Address3 | — |
Address4 | — |
Event ID 1037 — Locking Dhcp Context: [.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1038 — Unlocking Dhcp Context: [.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1039 — Destroying Dhcp Context: [.
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
Event ID 1040 — Successfully Plumbed the address.
Message
Fields
| Name | Description |
|---|---|
Address | — |
Event ID 1041 — Successfully Deleted the address.
Message
Fields
| Name | Description |
|---|---|
Address | — |
Event ID 1042 — Successfully Plumbed the CACHED address using network identifier (Network Hint).
Message
Fields
| Name | Description |
|---|---|
Address | — |
Event ID 1043 — DhcpRegReadOptionCache returned %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1044 — RegOpenKeyEx returned %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1045 — Fallback Params Read Fail.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1046 — Successfully read fallback configuration
Message
Event ID 1047 — RegQueryValueEx returned %1, Fallback config name type %2.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ConfigNameType | — |
Event ID 1048 — Registering AdapterName: %1 Address: %2 Flags : [%3] Error : %4.
Message
Fields
| Name | Description |
|---|---|
Registering_AdapterName | — |
Address | — |
AdapterName | — |
Flags | — |
ErrorCode | — |
Event ID 1049 — Deregistering AdapterName.
Message
Fields
| Name | Description |
|---|---|
Deregistering_AdapterName | — |
AdapterName | — |
ErrorCode | — |
Event ID 1050 — Deregistering AdapterName: [Dynamic DNS disabled].
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1051 — Failed to Acquire Wcm in Disconnected Standby.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 50001 — Media Connect notification received on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50002 — Media Disconnect notification received on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50003 — Media Reconnect notification received on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50004 — DHCP is enabled on the interface with Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50005 — DHCP is disabled on the interface with Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50006 — Request-Ack is initiated on the interface with Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50007 — Discover-Offer-Request-Ack is initiated on the interface with Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50008 — Interface is converted from static to DHCP on the interface with Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50009 — Discover is sent from the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50010 — Offer is accepted on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 50011 — Offer is discarded on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50012 — Request is sent from the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50013 — Ack is accepted on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 50014 — Ack is discarded on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50015 — Nack is received on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50016 — Unknown message is discarded on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50017 — Decline is sent on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50018 — Inform is sent on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50019 — Release is sent on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50020 — The broadcast bit was toggled on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
BoolFlag | — |
Event ID 50021 — Error occurred in extracting the options on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50022 — Setting up a Fallback configuration on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
StatusCode | — |
Event ID 50023 — Offer Receive Timeout has happened on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50024 — Ack Receive Timeout has happened on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50025 — Cancelling pending renewals on the interface with the Interface Id %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50028 — Address %1 is plumbed on the interface %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
InterfaceId | — |
StatusCode | — |
Event ID 50029 — Address %1 is unplumbed on the interface %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
InterfaceId | — |
StatusCode | — |
Event ID 50030 — Plumbing error has occurred on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50032 — Lease is expired on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
Event ID 50033 — An interface is added whose interface index is %1 and Status Code is %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50034 — An error has occurred in initializing the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50035 — Routes are updated on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50036 — DHCPv4 client service is started
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50036
version: 0
level: 4
task: 4
opcode: 68
keywords: 2305843009213693952
time_created: '2023-11-06T06:25:39.972933+00:00'
event_record_id: 1675
correlation: {}
execution:
process_id: 2372
thread_id: 2408
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 50037 — DHCPv4 client service is stopped. ShutDown Flag value is DwordVal
Message
Fields
| Name | Description |
|---|---|
DwordVal | — |
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50037
version: 0
level: 4
task: 4
opcode: 69
keywords: 2305843009213693952
time_created: '2023-11-05T22:31:37.010108+00:00'
event_record_id: 1858
correlation: {}
execution:
process_id: 2232
thread_id: 2328
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
DwordVal: 1
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 50038 — An error occurred in initializing DHCPv4.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 50039 — An error has occurred in opening the socket on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50040 — An error has occurred in closing the socket on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50041 — Domain change notification is received from DNS
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50041
version: 0
level: 4
task: 6
opcode: 71
keywords: 4611686018427387904
time_created: '2023-10-26T04:17:38.252255+00:00'
event_record_id: 1
correlation: {}
execution:
process_id: 2228
thread_id: 2320
channel: Microsoft-Windows-Dhcp-Client/Admin
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50042 — DNS registration has happened for the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Dword | — |
Event ID 50043 — DNS Deregistration has happened for the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50044 — Inform ack is received on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50053 — A network error occurred when trying to send a message on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50055 — Gateway address %1 is reachable on the interface %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
InterfaceId | — |
Event ID 50056 — Gateway is not reachable on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50058 — Your computer was successfully assigned an address from the network, and it can now connect to other computers.
Message
Event ID 50059 — Route is added with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4.
Message
Fields
| Name | Description |
|---|---|
Str1 | — |
Str2 | — |
Str3 | — |
Str4 | — |
Event ID 50060 — Route is deleted with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4.
Message
Fields
| Name | Description |
|---|---|
Str1 | — |
Str2 | — |
Str3 | — |
Str4 | — |
Event ID 50061 — An offer is received for the dummy discovers that are sent for Diagnostics on the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50062 — Checking reachability of gateway %1 on the the interface %2.
Message
Fields
| Name | Description |
|---|---|
Address | — |
InterfaceId | — |
Event ID 50063 — DHCP has notified NLA for the configuration changes for the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50064 — DHCP has run the cache scavenger for the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50065 — DHCP has found a match in the cache for Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network addres...
Message
Fields
| Name | Description |
|---|---|
NetworkHintString | — |
NetworkHint | — |
HWLength | — |
HWAddress | — |
Event ID 50066 — DHCP has plumbed an address using Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4.
Message
Fields
| Name | Description |
|---|---|
NetworkHintString | — |
NetworkHint | — |
HWLength | — |
HWAddress | — |
Event ID 50067 — DHCP has received a Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4.
Message
Fields
| Name | Description |
|---|---|
NetworkHintString | — |
NetworkHint | — |
HWLength | — |
HWAddress | — |
Event ID 50068 — Address %1 being plumbed for adapter %2 already exists.
Message
Fields
| Name | Description |
|---|---|
Address | — |
InterfaceId | — |
Event ID 50069 — The broadcast bit %1 was successfully set and cached on the interface %2.
Message
Fields
| Name | Description |
|---|---|
BoolFlag | — |
InterfaceId | — |
Event ID 50070 — DHCP has not received a Service Set Identifier(SSID) for the interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50071 — DHCP has not found a match in the cache for Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the interface %3.
Message
Fields
| Name | Description |
|---|---|
NetworkHintString | — |
NetworkHint | — |
InterfaceId | — |
Event ID 50072 — Network Diagnostics Framework(NDF) discovery is being initiated on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50073 — Network Diagnostics Framework(NDF) discovery failed to discover a DHCP server on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50074 — Firewall port %1 is exempted on interface %2.
Message
Fields
| Name | Description |
|---|---|
DwordVal | — |
InterfaceId | — |
DwordVal1 | — |
Event ID 50075 — Firewall port %1 is closed on interface %2.
Message
Fields
| Name | Description |
|---|---|
DwordVal | — |
InterfaceId | — |
DwordVal1 | — |
Event ID 50076 — DHCP has not plumbed an address using Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address ...
Message
Fields
| Name | Description |
|---|---|
NetworkHintString | — |
NetworkHint | — |
HWLength | — |
HWAddress | — |
Event ID 50077 — Regular address acquisition will be done on interface %1 because aggressive address acquisition is turned ON.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50081 — DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state...
Message
Fields
| Name | Description |
|---|---|
DwordVal1 | — |
InterfaceId | — |
Address | — |
Event ID 50083 — Attempting to acquire a reference for interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50084 — Attempting to release the reference for interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
StatusCode | — |
Event ID 50085 — Registered duplicate address detection on interface %1 for IP address %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
Event ID 50086 — Completed duplicate address detection on interface %1 for IP address %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
StatusCode | — |
Event ID 50087 — Duplicate address detection on interface %1 for IP address %2 timed out - reattempting.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
Event ID 50088 — Parameter change request registered for process %1 with descriptor %2.
Message
Fields
| Name | Description |
|---|---|
ProcID | — |
UniqueID | — |
EventPath | — |
ClassIDSize | — |
ClassID | — |
OptListSize | — |
OptList | — |
IsVendor | — |
Event ID 50089 — Parameter change request unregistered for process %1 with descriptor %2.
Message
Fields
| Name | Description |
|---|---|
ProcID | — |
UniqueID | — |
Event ID 50090 — Parameter change request notified for process %1 with descriptor %2.
Message
Fields
| Name | Description |
|---|---|
ProcID | — |
UniqueID | — |
StatusCode | — |
Event ID 50091 — Parameter request received on interface with LUID %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceLUID | — |
ClassIDSize | — |
ClassID | — |
StandardOptListSize | — |
StandardOptList | — |
VendorOptListSize | — |
VendorOptList | — |
Event ID 50092 — Parameter request unblocked on interface with LUID %1 and index %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceLUID | — |
InterfaceId | — |
Event ID 50093 — Parameter request completed on interface with LUID %1 and index %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceLUID | — |
InterfaceId | — |
StatusCode | — |
OptDataSize | — |
OptData | — |
Event ID 50094 — Firewall port %2 exemption triggered on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
DwordVal1 | — |
Event ID 50095 — Firewall port %2 close triggered on interface %1.
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
DwordVal1 | — |
Event ID 50096 — DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state...
Message
Fields
| Name | Description |
|---|---|
DwordVal1 | — |
InterfaceId | — |
Address | — |
Event ID 50097 — DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state...
Message
Fields
| Name | Description |
|---|---|
DwordVal1 | — |
InterfaceId | — |
Address | — |
Event ID 50098 — DHCP will not try regular IPv4 address acquisition on interface %1 since the machine is in Connected Standby state and the interface has the IPv6 a...
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Address | — |
Event ID 50099 — DHCP will try regular IPv4 address acquisition on interface %1 even though the machine is in Connected Standby state since the interface has no IPv...
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50100 — DHCP will try regular IPv4 address acquisition on interface %1 due to registry settings even though the machine is in Connected Standby state and t...
Message
Fields
| Name | Description |
|---|---|
InterfaceId | — |
Event ID 50101 — The DHCPv4 client received connected standby entry notification.
Message
Event ID 50102 — The DHCPv4 client received connected standby exit notification.
Message
Event ID 50103 — DHCPv4 client registered for shutdown notification
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50103
version: 0
level: 4
task: 4
opcode: 129
keywords: 2305843009213693952
time_created: '2023-11-06T06:25:39.972458+00:00'
event_record_id: 1674
correlation: {}
execution:
process_id: 2372
thread_id: 2408
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50104 — DHCPv4 client received shutdown notification
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50104
version: 0
level: 4
task: 4
opcode: 129
keywords: 2305843009213693952
time_created: '2023-11-05T22:31:36.636619+00:00'
event_record_id: 1852
correlation: {}
execution:
process_id: 2232
thread_id: 2236
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50105 — DHCPv4 client ProcessDHCPRequestForever received TERMINATE_EVENT
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50105
version: 0
level: 4
task: 4
opcode: 129
keywords: 2305843009213693952
time_created: '2023-11-05T22:31:36.639339+00:00'
event_record_id: 1853
correlation: {}
execution:
process_id: 2232
thread_id: 2328
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50106 — DHCPv4 is waiting on DHCPv6 service to stop
Message
Example Event
system:
provider: Microsoft-Windows-Dhcp-Client
guid: 15A7A4F8-0072-4EAB-ABAD-F98A4D666AED
event_source_name: ''
event_id: 50106
version: 0
level: 4
task: 4
opcode: 129
keywords: 2305843009213693952
time_created: '2023-11-05T22:31:37.009976+00:00'
event_record_id: 1857
correlation: {}
execution:
process_id: 2232
thread_id: 2328
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50107 — Firewall port exemption is in progress but incomplete.
Message
Fields
| Name | Description |
|---|---|
DwordVal | — |
Event ID 60000 — PERFTRACK (Request-Ack): Address confirmed for the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60001 — PERFTRACK (DORA): Offer is accepted on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60002 — PERFTRACK: Gateway is reachable on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60003 — PERFTRACK: DHCP is not enabled on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60004 — PERFTRACK: Setting up Fallback configuration on the interface %2 since no response is received for request.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
StatusCode | — |
Event ID 60005 — PERFTRACK (Request-Ack): Address confirmed for the interface %2 after toggling the broadcast bit in INIT-REBOOT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60006 — PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT-REBOOT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60007 — PERFTRACK (Init-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60010 — PERFTRACK (Request-Ack): Address confirmed for the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60011 — PERFTRACK (DORA): Offer is accepted on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60012 — PERFTRACK: Gateway is reachable on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60013 — PERFTRACK: DHCP is not enabled on the interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60014 — PERFTRACK: Setting up Fallback configuration on the interface %2 since no response is received for request.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
StatusCode | — |
Event ID 60015 — PERFTRACK (Request-Ack): Address confirmed for the interface %2 after toggling the broadcast bit in INIT-REBOOT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60016 — PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT-REBOOT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60017 — PERFTRACK (Init-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Address1 | — |
Address2 | — |
Event ID 60018 — PERFTRACK (DHCPv4): Media Connect on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60019 — PERFTRACK (DHCPv4): End of Media Connect on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60020 — PERFTRACK (Media Reconnect): Media reconnect notification was received on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60021 — PERFTRACK (Discover-DelayedResponse): Offer/Ack is not received for first discover/request on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60022 — PERFTRACK (Discover-Timeout): No response is received for all 8 discovers on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60023 — PERFTRACK (Request-DelayedAck): Ack is not received for first request on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60024 — PERFTRACK (Request-NoResponse): There is no response for INIT-REBOOT Request on interface %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
InterfaceId | — |
Event ID 60025 — PERFTRACK: Fallback address %2 is plumbed on interface %3 after DHCP did not get response for discover.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Address | — |
InterfaceId | — |
Event ID 60026 — Entered ProcessDhcpRequestForever.
Message
Event ID 60027 — ProcessDhcpRequestForever Timed out.
Message
Event ID 60028 — CreateRenewalSignalHandle failed with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 60029 — DeleteRenewTimer failed with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 60030 — ResetRenewalSignalHandle failed with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 60031 — CreateRenewTimer failed with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 60032 — ProcessDhcpRequestForever failed with error %1.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |