Microsoft-Windows-DNS-Client
107 events across 2 channels
Event ID 1000 — There are currently no IPv4 DNS servers configured for any interface on this host.
Message
Fields
| Name | Description |
|---|---|
Location | — |
Context | — |
Event ID 1001 — Interface: %1 Total DNS Server Count: %2 Index: %3 Address: %6 (%4).
Message
Fields
| Name | Description |
|---|---|
Interface | — |
Total_DNS_Server_Count | — |
Index | — |
Address | — |
TotalServerCount | — |
DynamicAddress | — |
AddressLength | — |
Event ID 1002 — The DNS server being queried for interface %1 has changed to %3.
Message
Fields
| Name | Description |
|---|---|
Interface | — |
AddressLength | — |
Address | — |
ClientPID | — |
Event ID 1003 — The following DNS server(s) were successfully validated as active servers that can service this client.
Message
Fields
| Name | Description |
|---|---|
AddressLength | — |
Address | — |
Event ID 1004 — The following DNS server(s) were successfully validated as active servers that can service this client.
Message
Fields
| Name | Description |
|---|---|
Address | — |
Event ID 1005 — The client was unable to validate the following as active DNS server(s) that can service this client.
Message
Fields
| Name | Description |
|---|---|
AddressLength | — |
Address | — |
Event ID 1006 — The client was unable to validate the following as active DNS server(s) that can service this client.
Message
Fields
| Name | Description |
|---|---|
Address | — |
Event ID 1007 — The primary DNS suffix for this machine is missing.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 1008 — The primary DNS suffix for this machine is missing.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 1009 — The primary DNS suffix for this machine does not match the Active Directory domain that it is currently joined to.
Message
Fields
| Name | Description |
|---|---|
DnsSuffix | — |
AdSuffix | — |
Event ID 1010 — The primary DNS suffix for this machine does not match the Active Directory domain that it is currently joined to.
Message
Fields
| Name | Description |
|---|---|
DnsSuffix | — |
AdSuffix | — |
Event ID 1011 — There was an error while attempting to read the local hosts file.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 1012 — There was an error while attempting to read the local hosts file.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 1013 — Name resolution for the name %1 timed out after none of the configured DNS servers responded.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
Event ID 1014 — Name resolution for the name %1 timed out after none of the configured DNS servers responded.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
Example Event
system:
provider: Microsoft-Windows-DNS-Client
guid: 1C95126E-7EEA-49A9-A3FE-A378B03DDB4D
event_source_name: ''
event_id: 1014
version: 1
level: 3
task: 1014
opcode: 0
keywords: 4611686018695823360
time_created: '2023-11-06T06:25:49.753506+00:00'
event_record_id: 1706
correlation: {}
execution:
process_id: 1916
thread_id: 3540
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-20
event_data:
QueryName: wpad
AddressLength: 128
Address: 02000000C0A85C02000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
ClientPID: 2556
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1015 — Name resolution for the name %1 timed out after the DNS server %3 did not respond.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
Event ID 1016 — A name not found error was returned for the name %1.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1017 — The DNS server's response to a query for name %1 indicates that no records of the type queried are available, but could indicate that other records...
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1018 — The response for the query %1 was a Link Local IP address %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
DnsAddressLength | — |
DnsAddress | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1019 — There are currently no IPv6 DNS servers configured for any interface on this host.
Message
Fields
| Name | Description |
|---|---|
Location | — |
Context | — |
Event ID 1020 — Read DNS Name Resolution Policy Table: Key Name %1: DNSSEC Settings: DnsSecValidationRequired %2, DnsQueryOverIPSec %3, DnsEncryption %4 Direct Acc...
Message
Fields
| Name | Description |
|---|---|
KeyName | — |
DnsSecValidationRequired | — |
DnsQueryOverIPSec | — |
DnsEncryption | — |
DirectAccessServerList | — |
RemoteIPSEC | — |
RemoteEncryption | — |
ProxyType | — |
ProxyName | — |
Event ID 1021 — Matched Effective policy for query name %1: Key Name %2: DnsSecValidationRequired %3, DnsQueryOverIPSec %4, DnsEncryption %5 DirectAccessServerList...
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
KeyName | — |
DnsSecValidationRequired | — |
DnsQueryOverIPSec | — |
DnsEncryption | — |
DirectAccessServerList | — |
ProxyType | — |
ProxyName | — |
Event ID 1022 — Name resolution for the name, %1, will not fall back to LLMNR or NetBIOS.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
ClientPID | — |
QueryBlob | — |
Event ID 1023 — Name resolution policy table has been corrupted.
Message
Fields
| Name | Description |
|---|---|
RuleName | — |
ErrorCode | — |
Event ID 1024 — Transaction ID of the response for query %1 from server %3 did not match.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1025 — The DNS server IP %3 of the response for query %1 is not configured on the client.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
AddressLength | — |
Address | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1026 — The question (%2) in the response from server %4 does not match the original question %1.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
ResponseQuestion | — |
AddressLength | — |
Address | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 1027 — DNS Name resolution for the name, %1, failed because the client was unable to contact DNS servers.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
ClientPID | — |
QueryBlob | — |
Event ID 1028 — Matched effective policy for query name %1: Key Name %2: DnsSecValidationRequired %3, DnsQueryOverIPSec %4, DnsEncryption %5 DirectAccessServerList...
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
KeyName | — |
DnsSecValidationRequired | — |
DnsQueryOverIPSec | — |
DnsEncryption | — |
DirectAccessServerList | — |
ProxyType | — |
ProxyName | — |
GenericServerList | — |
IdnConfig | — |
ClientPID | — |
QueryBlob | — |
Event ID 3000 — DNS Query is initiated for the name %1 and for the type %2 with query options %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
Event ID 3001 — DNS Query operation is completed with result %1.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 3002 — DNS Cache lookup is initiated for the name %1 and for the type %2 with query options %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
Event ID 3003 — DNS Cache lookup operation for the name %1 and for the type %2 is completed with result %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
Status | — |
Event ID 3004 — DNS FQDN Query is initiated for the name %1 and for the type %2 with query options %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
Event ID 3005 — DNS FQDN Query operation for the name %1 and for the type %2 is completed with result %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
Status | — |
Event ID 3006 — DNS query is called for the name %1, type %2, query options %3, Server List %4, isNetwork query %5, network index %6, interface index %7, is asynch...
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
ServerList | — |
IsNetworkQuery | — |
NetworkQueryIndex | — |
InterfaceIndex | — |
IsAsyncQuery | — |
Event ID 3007 — DnsQueryEx for the name %1 is pending.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
Event ID 3008 — DNS query is completed for the name %1, type %2, query options %3 with status %4 Results %5.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
QueryStatus | — |
QueryResults | — |
Sigma Rules
- DNS Query for Anonfiles.com Domain - DNS Client
Detects DNS queries for anonfiles.com, which is an anonymous file upload platform often used for malicious purposes - Suspicious Cobalt Strike DNS Beaconing - DNS Client
Detects a program that invoked suspicious DNS queries known from Cobalt Strike beacons - DNS Query To MEGA Hosting Website - DNS Client
Detects DNS queries for subdomains related to MEGA sharing website - DNS Query To Put.io - DNS Client
Detects DNS queries for subdomains related to "Put.io" sharing website. - Query Tor Onion Address - DNS Client
Detects DNS resolution of an .onion address related to Tor routing networks
Showing 5 of 6 matching Sigma rules.
Event ID 3009 — Network query initiated for the name %1 (is parallel query %2) on network index %3 with interface count %4 with first interface name %5, local addr...
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
IsParallelNetworkQuery | — |
NetworkIndex | — |
InterfaceCount | — |
AdapterName | — |
LocalAddress | — |
DNSServerAddress | — |
ClientPID | — |
QueryBlob | — |
ParentBlob | — |
Event ID 3010 — DNS Query sent to DNS Server %3 for name %1 and type %2.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
DnsServerIpAddress | — |
ClientPID | — |
Event ID 3011 — Received response from DNS Server %3 for name %1 and type %2 with response status %4.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
DnsServerIpAddress | — |
ResponseStatus | — |
ClientPID | — |
SendBlob | — |
SendBlobContext | — |
Event ID 3012 — NETBIOS query is initiated for name %1 on network index %2 with inteface count %3 with first interface name %4 and local addresses %5.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
NetworkIndex | — |
InterfaceCount | — |
AdapterName | — |
LocalAddress | — |
ClientPID | — |
QueryBlob | — |
Event ID 3013 — NETBIOS query is completed for name %1 with status %2 and results %3.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
Status | — |
QueryResults | — |
ClientPID | — |
QueryBlob | — |
Event ID 3014 — NETBIOS query for the name %1 is pending.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
ClientPID | — |
QueryBlob | — |
Event ID 3015 — DnsQueryEx is canceled for the name %1.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
Event ID 3016 — Cache lookup called for name %1, type %2, options %3 and interface index %4.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
InterfaceIndex | — |
ClientPID | — |
QueryBlob | — |
Event ID 3018 — Cache lookup for name %1, type %2 and option %3 returned %4 with results %5.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
QueryOptions | — |
Status | — |
QueryResults | — |
ClientPID | — |
QueryBlob | — |
Event ID 3019 — Query wire called for name %1, type %2, interface index %3 and network index %4.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
InterfaceIndex | — |
NetworkIndex | — |
ClientPID | — |
QueryBlob | — |
Event ID 3020 — Query response for name %1, type %2, interface index %3 and network index %4 returned %5 with results %6.
Message
Fields
| Name | Description |
|---|---|
QueryName | — |
QueryType | — |
NetworkIndex | — |
InterfaceIndex | — |
Status | — |
QueryResults | — |
ClientPID | — |
QueryBlob | — |
Event ID 3023 — Initiating resolver operation %1, name %2, flag %3, client PID %4.
Message
Fields
| Name | Description |
|---|---|
OperationName | — |
Name | — |
Flag | — |
ClientPID | — |
Event ID 3024 — Server %1 failed to validate DDR certificate for original address %2 with status %3.
Message
Fields
| Name | Description |
|---|---|
ActualServer | — |
OriginalServer | — |
Status | — |
Event ID 8001 — Unable to start DNS Client service.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 8002 — Unable to start DNS Client service because the system failed to allocate memory and may be out of available memory.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 8003 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS Server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8004 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8005 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8006 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8007 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8008 — The system failed to register network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain Suffix : %3 DNS server list :...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8009 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8010 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8011 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8012 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8013 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8014 — The system failed to register pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-spec...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8015 — The system failed to register host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary D...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8016 — The system failed to register host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary D...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8017 — The system failed to register host (A or AAAA) resource records for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary Domain ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8018 — The system failed to register host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary D...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8019 — The system failed to register host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary D...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8020 — The system failed to register host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Primary D...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8021 — The system failed to update and remove registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8022 — The system failed to update and remove registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8023 — The system failed to update and remove registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8024 — The system failed to update and remove registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8025 — The system failed to update and remove registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specific Domain...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8026 — The system failed to update and remove the DNS registration for the network adapter with settings: Adapter Name : %1 Host Name : %2 Adapter-specifi...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8027 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8028 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8029 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8030 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8031 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8032 — The system failed to update and remove pointer (PTR) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 Ada...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8033 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8034 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8035 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8036 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8037 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8038 — The system failed to update and remove host (A or AAAA) resource records (RRs) for network adapter with settings: Adapter Name : %1 Host Name : %2 ...
Message
Fields
| Name | Description |
|---|---|
AdapterName | — |
HostName | — |
AdapterSuffixName | — |
DnsServerList | — |
SentUpdateServer | — |
Ipaddress | — |
ErrorCode | — |
Event ID 8040 — A DNS interception provider has been loaded.
Message
Fields
| Name | Description |
|---|---|
Interception_Dll | — |
DllName | — |
Event ID 8042 — A DNS interception provider performed an illegal operation.
Message
Fields
| Name | Description |
|---|---|
Interception_Dll | — |
DllName | — |
Event ID 8043 — DNS-over-HTTPS query initiated to server %1 for the name %2, on interface %3, using template %4, client PID %5.
Message
Fields
| Name | Description |
|---|---|
Server | — |
NameQuery | — |
InterfaceName | — |
Template | — |
ClientPID | — |
Event ID 8044 — DNS-over-TLS query initiated to server %1 for the name %2, on interface %3, with hostname %4, client PID %5.
Message
Fields
| Name | Description |
|---|---|
Server | — |
NameQuery | — |
InterfaceName | — |
Hostname | — |
ClientPID | — |
Event ID 8045 — DNS-over-HTTPS request to server %1 with template %2 returned HTTP status $3.
Message
Fields
| Name | Description |
|---|---|
Server | — |
TemplateName | — |
StatusCode | — |
Event ID 8046 — DNS-over-HTTPS request to server %1 with template %2 failed with error %3.
Message
Fields
| Name | Description |
|---|---|
Server | — |
TemplateName | — |
ErrorCode | — |
Event ID 8047 — DNS-over-TLS request to server %1 with hostname %2 failed with error %3.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Hostname | — |
ErrorCode | — |
Event ID 8048 — DNS-over-HTTPS request failed to obtain valid SSL certificate from server %1, with template %2, due to: %3.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Template | — |
Error | — |
ErrorBits | — |
Event ID 8049 — DNS-over-TLS request failed to obtain valid SSL certificate from server %1, with hostname %2, due to: %3.
Message
Fields
| Name | Description |
|---|---|
Server | — |
Hostname | — |
Error | — |
ErrorBits | — |
Event ID 8050 — Windows DNS Client process mitigations: SystemCall: %1, ExtensionPoint: %2, DynamicCode: %3, CFG: %4, BinarySignature: %5, FontDisable: %6, ImageLo...
Message
Fields
| Name | Description |
|---|---|
SystemCallDisable | — |
ExtensionPointDisable | — |
DynamicCode | — |
ControlFlowGuard | — |
BinarySignature | — |
FontDisable | — |
ImageFlow | — |
ChildProcess | — |
EnforcementKey | — |
Event ID 60004 — Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Location | — |
Context | — |
ErrorCode | — |
Event ID 60005 — Warning: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
Warning | — |
Location | — |
Context | — |
WarningCode | — |
Event ID 60006 — Transitioned to State: %1 Context: %2.
Message
Fields
| Name | Description |
|---|---|
NextState | — |
Context | — |
Event ID 60007 — Updated Context: %1 Update Reason: %2.
Message
Fields
| Name | Description |
|---|---|
Updated_Context | — |
Update_Reason | — |
Context | — |
UpdateReasonCode | — |
Event ID 60008 — Name resolution policy table has been corrupted.
Message
Fields
| Name | Description |
|---|---|
RuleName | — |
ErrorCode | — |
Event ID 60101 — SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6.
Message
Fields
| Name | Description |
|---|---|
SourceAddress | — |
SourcePort | — |
DestinationAddress | — |
DestinationPort | — |
Protocol | — |
ReferenceContext | — |
Event ID 60102 — SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6.
Message
Fields
| Name | Description |
|---|---|
SourceAddress | — |
SourcePort | — |
DestinationAddress | — |
DestinationPort | — |
Protocol | — |
ReferenceContext | — |
Event ID 60103 — Interface Guid: %1 IfIndex: %2 Interface Luid: %3 ReferenceContext: %4.
Message
Fields
| Name | Description |
|---|---|
Interface_Guid | — |
IfIndex | — |
Interface_Luid | — |
ReferenceContext | — |
IfGuid | — |
IfLuid | — |