Microsoft-Windows-Diagnosis-Scripted

25 events across 4 channels

Event IDTitleChannel
1The scripted diagnostic engine executed a diagnostic package located at %1 with …Admin
101The scripted diagnostic engine started initializing a diagnostic package located …Operational
102The scripted diagnostic engine completed initializing a diagnostic package …Operational
103The scripted diagnostic engine started diagnosing the diagnostic package %1.Operational
104The scripted diagnostic engine completed diagnosing the diagnostic package %1.Operational
105The scripted diagnostic engine started running the resolution %2 in the …Operational
106The scripted diagnostic engine completed running the resolution %2 in the …Operational
107The scripted diagnostic engine started verifying the diagnostic package %1.Operational
108The scripted diagnostic engine completed verifying the diagnostic package %1.Operational
201The scripted diagnostic engine has encountered an error %1.Operational
301The scripted diagnostic engine has encountered an error in function %1, line %2: …Debug
401Rootcause %2 was detected in package %1.Operational
402Rootcause %2 was resolved in package %1.Operational
1000The scripted diagnostic engine has entered a performance tracing section.Analytic
1002The scripted diagnostic engine has exited a performance tracing section.Analytic
1004The scripted diagnostic engine has entered a performance tracing section.Analytic
1006The scripted diagnostic engine has exited a performance tracing section.Analytic
1008The scripted diagnostic engine has entered a performance tracing section.Analytic
1010The scripted diagnostic engine has exited a performance tracing section.Analytic
1012The scripted diagnostic engine has entered a performance tracing section.Analytic
1014The scripted diagnostic engine has exited a performance tracing section.Analytic
1016The scripted diagnostic engine has entered a performance tracing section.Analytic
1018The scripted diagnostic engine has exited a performance tracing section.Analytic
1020The scripted diagnostic engine has entered a performance tracing section.Analytic
1022The scripted diagnostic engine has exited a performance tracing section.Analytic

Event ID 1 — The scripted diagnostic engine executed a diagnostic package located at %1 with ID %2.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Admin
Level
4
Samples
1

Message

The scripted diagnostic engine executed a diagnostic package located at %1 with ID %2.

Fields

NameDescription
PackagePath
PackageId

Example Event

system:
  provider: Microsoft-Windows-Diagnosis-Scripted
  guid: E1DD7E52-621D-44E3-A1AD-0370C2B25946
  event_source_name: ''
  event_id: 1
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 9223372054034644992
  time_created: '2022-04-04T07:40:10.131934+00:00'
  event_record_id: 1
  correlation: {}
  execution:
    process_id: 4124
    thread_id: 4192
  channel: Microsoft-Windows-Diagnosis-Scripted/Admin
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
  PackagePath: C:\Windows\diagnostics\scheduled\Maintenance
  PackageId: MaintenanceDiagnostic
message: ''

References

Event ID 101 — The scripted diagnostic engine started initializing a diagnostic package located at %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
4
Samples
1

Message

The scripted diagnostic engine started initializing a diagnostic package located at %1.

Fields

NameDescription
PackagePath

Example Event

system:
  provider: Microsoft-Windows-Diagnosis-Scripted
  guid: E1DD7E52-621D-44E3-A1AD-0370C2B25946
  event_source_name: ''
  event_id: 101
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686052787126272
  time_created: '2022-04-04T07:40:09.755421+00:00'
  event_record_id: 1
  correlation: {}
  execution:
    process_id: 4124
    thread_id: 4192
  channel: Microsoft-Windows-Diagnosis-Scripted/Operational
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
  PackagePath: C:\Windows\diagnostics\scheduled\Maintenance
message: ''

Sigma Rules

References

Event ID 102 — The scripted diagnostic engine completed initializing a diagnostic package located at %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
4
Samples
1

Message

The scripted diagnostic engine completed initializing a diagnostic package located at %1.

Fields

NameDescription
PackagePath

Example Event

system:
  provider: Microsoft-Windows-Diagnosis-Scripted
  guid: E1DD7E52-621D-44E3-A1AD-0370C2B25946
  event_source_name: ''
  event_id: 102
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686052787126272
  time_created: '2022-04-04T07:40:10.131933+00:00'
  event_record_id: 2
  correlation: {}
  execution:
    process_id: 4124
    thread_id: 4192
  channel: Microsoft-Windows-Diagnosis-Scripted/Operational
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
  PackagePath: C:\Windows\diagnostics\scheduled\Maintenance
message: ''

References

Event ID 103 — The scripted diagnostic engine started diagnosing the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
4
Samples
1

Message

The scripted diagnostic engine started diagnosing the diagnostic package %1.

Fields

NameDescription
PackageId

Example Event

system:
  provider: Microsoft-Windows-Diagnosis-Scripted
  guid: E1DD7E52-621D-44E3-A1AD-0370C2B25946
  event_source_name: ''
  event_id: 103
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686052787126272
  time_created: '2022-04-04T07:40:10.133706+00:00'
  event_record_id: 3
  correlation: {}
  execution:
    process_id: 4124
    thread_id: 4192
  channel: Microsoft-Windows-Diagnosis-Scripted/Operational
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
  PackageId: MaintenanceDiagnostic
message: ''

References

Event ID 104 — The scripted diagnostic engine completed diagnosing the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
4
Samples
1

Message

The scripted diagnostic engine completed diagnosing the diagnostic package %1.

Fields

NameDescription
PackageId

Example Event

system:
  provider: Microsoft-Windows-Diagnosis-Scripted
  guid: E1DD7E52-621D-44E3-A1AD-0370C2B25946
  event_source_name: ''
  event_id: 104
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 4611686052787126272
  time_created: '2022-04-04T07:40:22.886890+00:00'
  event_record_id: 4
  correlation: {}
  execution:
    process_id: 4124
    thread_id: 4192
  channel: Microsoft-Windows-Diagnosis-Scripted/Operational
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
  PackageId: MaintenanceDiagnostic
message: ''

References

Event ID 105 — The scripted diagnostic engine started running the resolution %2 in the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

The scripted diagnostic engine started running the resolution %2 in the diagnostic package %1.

Fields

NameDescription
PackageId
ResolutionId

Event ID 106 — The scripted diagnostic engine completed running the resolution %2 in the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

The scripted diagnostic engine completed running the resolution %2 in the diagnostic package %1.

Fields

NameDescription
PackageId
ResolutionId

Event ID 107 — The scripted diagnostic engine started verifying the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

The scripted diagnostic engine started verifying the diagnostic package %1.

Fields

NameDescription
PackageId

Event ID 108 — The scripted diagnostic engine completed verifying the diagnostic package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

The scripted diagnostic engine completed verifying the diagnostic package %1.

Fields

NameDescription
PackageId

Event ID 201 — The scripted diagnostic engine has encountered an error %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

The scripted diagnostic engine has encountered an error %1.

Fields

NameDescription
Status

Event ID 301 — The scripted diagnostic engine has encountered an error in function %1, line %2: %3.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Debug

Message

The scripted diagnostic engine has encountered an error in function %1, line %2: %3.

Fields

NameDescription
FunctionName
LineNumber
ErrorCode

Event ID 401 — Rootcause %2 was detected in package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

Rootcause %2 was detected in package %1.

Fields

NameDescription
PackageId
RootCauseId

Event ID 402 — Rootcause %2 was resolved in package %1.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Message

Rootcause %2 was resolved in package %1.

Fields

NameDescription
PackageId
RootCauseId

Event ID 1000 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1002 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1004 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1006 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1008 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1010 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1012 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1014 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1016 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1018 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1020 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1022 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic

Message

The scripted diagnostic engine has exited a performance tracing section..