Microsoft-Windows-Diagnosis-Scheduled

20 events across 1 channel

Event IDTitleChannel
1The scheduled diagnostic task has detected a change in state for a check …Operational
2Scheduled diagnostics have started.Operational
3Scheduled diagnostics have been completed.Operational
4Scheduled diagnostics have been disabled.Operational
5The scheduled diagnostic task has started initializing a diagnostic package.Operational
6The scheduled diagnostic task has completed initialization of a diagnostic …Operational
7The scheduled diagnostic task has started troubleshooting a diagnostic package.Operational
8The scheduled diagnostic task has completed troubleshooting a diagnostic …Operational
9The scheduled diagnostic task has detected a root cause.Operational
10The scheduled diagnostic task has started resolving a detected root cause.Operational
11The scheduled diagnostic task has completed resolving a detected root cause.Operational
12The scheduled diagnostic task has started verifying the fix applied for a …Operational
13The scheduled diagnostic task has determined that the root cause no longer …Operational
14The scheduled diagnostic task has determined that the root cause continues to …Operational
15The scheduled diagnostic task has encountered an error.Operational
96TEST: One or more rootcauses were detected and a package wide notification was …Operational
97TEST: No rootcauses were detected and a package wide reset notification was …Operational
98TEST: A rootcause was detected and a rootcause wide notification was raised.Operational
99TEST: A root cause does not exist and a root cause reset notification was …Operational
100System maintenance detected issues requiring your attention.Operational

Event ID 1 — The scheduled diagnostic task has detected a change in state for a check registered in Security and Maintenance.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has detected a change in state for a check registered in Security and Maintenance.

Message #

The scheduled diagnostic task has detected a change in state for a check registered in Security and Maintenance.

Event ID 2 — Scheduled diagnostics have started.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

Scheduled diagnostics have started.

Message #

Scheduled diagnostics have started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:09.731501+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4168
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 3 — Scheduled diagnostics have been completed.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

Scheduled diagnostics have been completed.

Message #

Scheduled diagnostics have been completed.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:22.892108+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 4 — Scheduled diagnostics have been disabled.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

Scheduled diagnostics have been disabled.

Message #

Scheduled diagnostics have been disabled.

Event ID 5 — The scheduled diagnostic task has started initializing a diagnostic package.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

The scheduled diagnostic task has started initializing a diagnostic package.

Message #

The scheduled diagnostic task has started initializing a diagnostic package.

Fields #

NameDescription
PackagePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 5,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:09.738416+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance"
  },
  "message": ""
}

References #

Event ID 6 — The scheduled diagnostic task has completed initialization of a diagnostic package.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

The scheduled diagnostic task has completed initialization of a diagnostic package.

Message #

The scheduled diagnostic task has completed initialization of a diagnostic package.

Fields #

NameDescription
PackageID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 6,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:10.133702+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackageID": "MaintenanceDiagnostic"
  },
  "message": ""
}

References #

Event ID 7 — The scheduled diagnostic task has started troubleshooting a diagnostic package.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

The scheduled diagnostic task has started troubleshooting a diagnostic package.

Message #

The scheduled diagnostic task has started troubleshooting a diagnostic package.

Fields #

NameDescription
PackageID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 7,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:10.133704+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackageID": "MaintenanceDiagnostic"
  },
  "message": ""
}

References #

Event ID 8 — The scheduled diagnostic task has completed troubleshooting a diagnostic package.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Informational

Description

The scheduled diagnostic task has completed troubleshooting a diagnostic package.

Message #

The scheduled diagnostic task has completed troubleshooting a diagnostic package.

Fields #

NameDescription
PackageID UnicodeString
RootCauseCount Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372071214514176,
    "time_created": "2022-04-04T07:40:22.888106+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackageID": "MaintenanceDiagnostic",
    "RootCauseCount": 2
  },
  "message": ""
}

References #

Event ID 9 — The scheduled diagnostic task has detected a root cause.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has detected a root cause.

Message #

The scheduled diagnostic task has detected a root cause.

Fields #

NameDescription
RootCauseID UnicodeString
RootCauseName UnicodeString
RootCauseDescription UnicodeString

Event ID 10 — The scheduled diagnostic task has started resolving a detected root cause.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has started resolving a detected root cause.

Message #

The scheduled diagnostic task has started resolving a detected root cause.

Fields #

NameDescription
RootCauseID UnicodeString
ResolutionID UnicodeString

Event ID 11 — The scheduled diagnostic task has completed resolving a detected root cause.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has completed resolving a detected root cause.

Message #

The scheduled diagnostic task has completed resolving a detected root cause.

Fields #

NameDescription
RootCauseID UnicodeString
ResolutionID UnicodeString

Event ID 12 — The scheduled diagnostic task has started verifying the fix applied for a detected root cause.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has started verifying the fix applied for a detected root cause.

Message #

The scheduled diagnostic task has started verifying the fix applied for a detected root cause.

Fields #

NameDescription
RootCauseID UnicodeString

Event ID 13 — The scheduled diagnostic task has determined that the root cause no longer exists.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has determined that the root cause no longer exists.

Message #

The scheduled diagnostic task has determined that the root cause no longer exists.

Fields #

NameDescription
RootCauseID UnicodeString

Event ID 14 — The scheduled diagnostic task has determined that the root cause continues to exist.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has determined that the root cause continues to exist.

Message #

The scheduled diagnostic task has determined that the root cause continues to exist.

Fields #

NameDescription
RootCauseID UnicodeString

Event ID 15 — The scheduled diagnostic task has encountered an error.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

The scheduled diagnostic task has encountered an error.

Message #

The scheduled diagnostic task has encountered an error.

Fields #

NameDescription
PackageID UnicodeString
ErrorCode UInt32

Event ID 96 — TEST: One or more rootcauses were detected and a package wide notification was raised.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

TEST: One or more rootcauses were detected and a package wide notification was raised.

Message #

TEST: One or more rootcauses were detected and a package wide notification was raised.

Fields #

NameDescription
hc_stateid UInt32
Data1 UnicodeString
Data2 UnicodeString

Event ID 97 — TEST: No rootcauses were detected and a package wide reset notification was raised.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

TEST: No rootcauses were detected and a package wide reset notification was raised.

Message #

TEST: No rootcauses were detected and a package wide reset notification was raised.

Fields #

NameDescription
hc_stateid UInt32

Event ID 98 — TEST: A rootcause was detected and a rootcause wide notification was raised.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

TEST: A rootcause was detected and a rootcause wide notification was raised.

Message #

TEST: A rootcause was detected and a rootcause wide notification was raised.

Fields #

NameDescription
hc_stateid UInt32
Data1 UnicodeString
Data2 UnicodeString

Event ID 99 — TEST: A root cause does not exist and a root cause reset notification was raised.

Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational

Description

TEST: A root cause does not exist and a root cause reset notification was raised.

Message #

TEST: A root cause does not exist and a root cause reset notification was raised.

Fields #

NameDescription
hc_stateid UInt32

Event ID 100 — System maintenance detected issues requiring your attention.

#
Provider
Microsoft-Windows-Diagnosis-Scheduled
Channel
Operational
Level
Critical

Description

System maintenance detected issues requiring your attention. A notification was sent to Security and Maintenance.

Message #

System maintenance detected issues requiring your attention. A notification was sent to Security and Maintenance.

Fields #

NameDescription
hc_stateid UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scheduled",
    "guid": "40AB57C2-1C53-4DF9-9324-FF7CF898A02C",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 1,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372054034644992,
    "time_created": "2022-04-04T07:40:22.888110+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scheduled/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "hc_stateid": 0
  },
  "message": ""
}

References #