Microsoft-Windows-Diagnosis-Scripted

25 events across 4 channels

Event IDTitleChannel
1The scripted diagnostic engine executed a diagnostic package located at …Admin
101The scripted diagnostic engine started initializing a diagnostic package located …Operational
102The scripted diagnostic engine completed initializing a diagnostic package …Operational
103The scripted diagnostic engine started diagnosing the diagnostic package …Operational
104The scripted diagnostic engine completed diagnosing the diagnostic package …Operational
105The scripted diagnostic engine started running the resolution ResolutionId in …Operational
106The scripted diagnostic engine completed running the resolution ResolutionId in …Operational
107The scripted diagnostic engine started verifying the diagnostic package …Operational
108The scripted diagnostic engine completed verifying the diagnostic package …Operational
201The scripted diagnostic engine has encountered an error Status.Operational
301The scripted diagnostic engine has encountered an error in function …Debug
401Rootcause RootCauseId was detected in package PackageId.Operational
402Rootcause RootCauseId was resolved in package PackageId.Operational
1000The scripted diagnostic engine has entered a performance tracing section.Analytic
1002The scripted diagnostic engine has exited a performance tracing section.Analytic
1004The scripted diagnostic engine has entered a performance tracing section.Analytic
1006The scripted diagnostic engine has exited a performance tracing section.Analytic
1008The scripted diagnostic engine has entered a performance tracing section.Analytic
1010The scripted diagnostic engine has exited a performance tracing section.Analytic
1012The scripted diagnostic engine has entered a performance tracing section.Analytic
1014The scripted diagnostic engine has exited a performance tracing section.Analytic
1016The scripted diagnostic engine has entered a performance tracing section.Analytic
1018The scripted diagnostic engine has exited a performance tracing section.Analytic
1020The scripted diagnostic engine has entered a performance tracing section.Analytic
1022The scripted diagnostic engine has exited a performance tracing section.Analytic

Event ID 1 — The scripted diagnostic engine executed a diagnostic package located at PackagePath with ID PackageId.

#
Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Admin
Level
Informational

Description

The scripted diagnostic engine executed a diagnostic package located at PackagePath with ID PackageId.

Message #

The scripted diagnostic engine executed a diagnostic package located at %1 with ID %2.

Fields #

NameDescription
PackagePath UnicodeString
PackageId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scripted",
    "guid": "E1DD7E52-621D-44E3-A1AD-0370C2B25946",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372054034644992,
    "time_created": "2022-04-04T07:40:10.131934+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scripted/Admin",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance",
    "PackageId": "MaintenanceDiagnostic"
  },
  "message": ""
}

References #

Event ID 101 — The scripted diagnostic engine started initializing a diagnostic package located at PackagePath.

#
Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
Informational

Description

The scripted diagnostic engine started initializing a diagnostic package located at PackagePath.

Message #

The scripted diagnostic engine started initializing a diagnostic package located at %1.

Fields #

NameDescription
PackagePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scripted",
    "guid": "E1DD7E52-621D-44E3-A1AD-0370C2B25946",
    "event_source_name": "",
    "event_id": 101,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686052787126272,
    "time_created": "2022-04-04T07:40:09.755421+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance"
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Sigma # view in reference

References #

Event ID 102 — The scripted diagnostic engine completed initializing a diagnostic package located at PackagePath.

#
Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
Informational

Description

The scripted diagnostic engine completed initializing a diagnostic package located at PackagePath.

Message #

The scripted diagnostic engine completed initializing a diagnostic package located at %1.

Fields #

NameDescription
PackagePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scripted",
    "guid": "E1DD7E52-621D-44E3-A1AD-0370C2B25946",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686052787126272,
    "time_created": "2022-04-04T07:40:10.131933+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance"
  },
  "message": ""
}

References #

Event ID 103 — The scripted diagnostic engine started diagnosing the diagnostic package PackageId.

#
Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
Informational

Description

The scripted diagnostic engine started diagnosing the diagnostic package PackageId.

Message #

The scripted diagnostic engine started diagnosing the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scripted",
    "guid": "E1DD7E52-621D-44E3-A1AD-0370C2B25946",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686052787126272,
    "time_created": "2022-04-04T07:40:10.133706+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackageId": "MaintenanceDiagnostic"
  },
  "message": ""
}

References #

Event ID 104 — The scripted diagnostic engine completed diagnosing the diagnostic package PackageId.

#
Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational
Level
Informational

Description

The scripted diagnostic engine completed diagnosing the diagnostic package PackageId.

Message #

The scripted diagnostic engine completed diagnosing the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-Scripted",
    "guid": "E1DD7E52-621D-44E3-A1AD-0370C2B25946",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686052787126272,
    "time_created": "2022-04-04T07:40:22.886890+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 4124,
      "thread_id": 4192
    },
    "channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
    }
  },
  "event_data": {
    "PackageId": "MaintenanceDiagnostic"
  },
  "message": ""
}

References #

Event ID 105 — The scripted diagnostic engine started running the resolution ResolutionId in the diagnostic package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

The scripted diagnostic engine started running the resolution ResolutionId in the diagnostic package PackageId.

Message #

The scripted diagnostic engine started running the resolution %2 in the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString
ResolutionId UnicodeString

Event ID 106 — The scripted diagnostic engine completed running the resolution ResolutionId in the diagnostic package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

The scripted diagnostic engine completed running the resolution ResolutionId in the diagnostic package PackageId.

Message #

The scripted diagnostic engine completed running the resolution %2 in the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString
ResolutionId UnicodeString

Event ID 107 — The scripted diagnostic engine started verifying the diagnostic package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

The scripted diagnostic engine started verifying the diagnostic package PackageId.

Message #

The scripted diagnostic engine started verifying the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString

Event ID 108 — The scripted diagnostic engine completed verifying the diagnostic package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

The scripted diagnostic engine completed verifying the diagnostic package PackageId.

Message #

The scripted diagnostic engine completed verifying the diagnostic package %1.

Fields #

NameDescription
PackageId UnicodeString

Event ID 201 — The scripted diagnostic engine has encountered an error Status.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

The scripted diagnostic engine has encountered an error Status.

Message #

The scripted diagnostic engine has encountered an error %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 301 — The scripted diagnostic engine has encountered an error in function FunctionName, line LineNumber: ErrorCode.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Debug

Description

The scripted diagnostic engine has encountered an error in function FunctionName, line LineNumber: ErrorCode.

Message #

The scripted diagnostic engine has encountered an error in function %1, line %2: %3.

Fields #

NameDescription
FunctionName UnicodeString
LineNumber Int32
ErrorCode UInt32

Event ID 401 — Rootcause RootCauseId was detected in package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

Rootcause RootCauseId was detected in package PackageId.

Message #

Rootcause %2 was detected in package %1.

Fields #

NameDescription
PackageId UnicodeString
RootCauseId UnicodeString

Event ID 402 — Rootcause RootCauseId was resolved in package PackageId.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Operational

Description

Rootcause RootCauseId was resolved in package PackageId.

Message #

Rootcause %2 was resolved in package %1.

Fields #

NameDescription
PackageId UnicodeString
RootCauseId UnicodeString

Event ID 1000 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_HOST
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1002 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_HOST
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1004 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_SERIALIZE
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1006 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_SERIALIZE
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1008 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_INITIALIZE
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1010 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_INITIALIZE
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1012 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_VALIDATE
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1014 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_VALIDATE
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1016 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_SCRIPT
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1018 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_SCRIPT
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..

Event ID 1020 — The scripted diagnostic engine has entered a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_TRUST
Opcode
Start

Description

The scripted diagnostic engine has entered a performance tracing section.

Message #

The scripted diagnostic engine has entered a performance tracing section.

Event ID 1022 — The scripted diagnostic engine has exited a performance tracing section.

Provider
Microsoft-Windows-Diagnosis-Scripted
Channel
Analytic
Task
SCRIPTED_DIAGNOSTICS_TASK_TRUST
Opcode
Stop

Description

The scripted diagnostic engine has exited a performance tracing section..

Message #

The scripted diagnostic engine has exited a performance tracing section..