Microsoft-Windows-EventSystem
62 events across 2 channels
Event ID 512 —
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4354 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 4355 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4356 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4357 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4358 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4359 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 4361 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4362 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4609 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4610 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4611 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4612 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4613 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4614 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4615 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4616 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4619 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4620 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 4621 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4622 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4623 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 4624 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 4625 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4625 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Example Event
system:
provider: Microsoft-Windows-EventSystem
guid: '{899daace-4868-4295-afcd-9eb8fb497561}'
event_source_name: EventSystem
event_id: 4625
version: 0
level: 4
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2023-11-06T06:25:40.864290+00:00'
event_record_id: 1434
correlation: {}
execution:
process_id: 2696
thread_id: 0
channel: Application
computer: WinDev2310Eval
security:
user_id: ''
event_data:
param1: '86400'
param2: SuppressDuplicateDuration
param3: Software\Microsoft\EventSystem\EventLog
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4626 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 4627 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
Event ID 4628 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4629 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
Event ID 1073746449 — The EventSystem sub system is suppressing duplicate event log entries for a duration of %1 seconds.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073746450 — The COM+ Event System fired the %2 method on event class %3 for publisher %4 and subscriber %5 but the subscriber returned an error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 2147488002 — The COM+ Event System failed to fire the %2 method on event class %3 for publisher %4 and subscriber %5.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
Event ID 2147488003 — The COM+ Event System could not determine the name of the current user.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488004 — The COM+ Event System failed to create an instance of the subscriber %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488005 — The COM+ Event System could not fire an EventObjectChange event to subscription %2 because the query criteria string "%3" contained an error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 2147488006 — The COM+ Event System could not fire an EventObjectChange event to subscription %2 because a bad HRESULT was detected during filtering.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488007 — The type library ".
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147488009 — The COM+ Event System detected a corrupt IEventClass object.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488010 — The COM+ Event System detected a corrupt IEventSubscription object.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488257 — The COM+ Event System detected a bad return code during its internal processing.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488259 — The COM+ Event System detected an unexpected null pointer during its internal processing, at line %2 of %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488261 — The COM+ Event System detected an unexpected error from a Win32 API call at line %2 of %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 2147488262 — The COM+ Event System detected an inconsistency in its internal state.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488275 — The COM+ Event System timed out attempting to fire the %2 method on event class %3 for publisher %4 and subscriber %5.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
Event ID 2147488276 — The COM+ Event System service blocked the creation of a subscription to the event class with CLSID
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488277 — The COM+ Event System did not fire the
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
Event ID 3221230081 — The COM+ Event System detected a bad return code during its internal processing.
Message
Fields
| Name | Description |
|---|---|
param3 | — |
param2 | — |
param1 | — |
Event ID 3221230082 — The COM+ Event System detected a bad return code during its internal processing.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221230083 — The COM+ Event System detected an unexpected null pointer during its internal processing; at line {param2} of {param1}.
Message
Fields
| Name | Description |
|---|---|
param2 | — |
param1 | — |
Event ID 3221230084 — The COM+ Event System ran out of memory during its internal processing, at line %2 of %1.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221230085 — The COM+ Event System detected an unexpected error from a Win32 API call at line {param2} of {param1}.
Message
Fields
| Name | Description |
|---|---|
param2 | — |
param1 | — |
param3 | — |
param5 | — |
param4 | — |
Event ID 3221230086 — The COM+ Event System detected an inconsistency in its internal state.
Message
Fields
| Name | Description |
|---|---|
param3 | — |
param2 | — |
param1 | — |
Event ID 3221230087 — The COM+ Event System caught an exception %1 at address %2 within method %3 of interface %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 3221230088 — The COM+ Event System caught an access violation at address %1 within method %3 of interface %4.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 3221230089 — The COM+ Event System raised an unexpected exception {param1} at address {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221230090 — The COM+ Event System raised an unexpected access violation at address {param1}; attempting to access address {param2}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221230091 — The COM+ Event System could not store the per-user subscription %2 because the registry key HKEY_USERS\%3 could not be opened.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 3221230092 — The COM+ Event System detected an error trying to query an %1 object because the criteria string "%2" contained an error.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221230093 — The COM+ Event System could not remove the %2 object %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
Event ID 3221230094 — The COM+ Event System could not marshal the subscriber for subscription %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 3221230095 — The COM+ Event System failed to create an instance of the MultiInterfacePublisherFilter %2 defined in event class %3.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 3221230096 — The COM+ Event System could not apply the filter criteria to subscription %2 with display name "%6" because the criteria string "%3" contained an e...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |