Microsoft-Windows-EventSystem
62 events across 2 channels
Event ID 4354 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
Event ID 4355 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4356 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4357 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4358 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4359 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 4361 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4362 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4609 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4610 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4611 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4612 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4613 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4614 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4615 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4616 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4619 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4620 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 4621 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4622 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4623 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 4624 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
Event ID 4625 —
#Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EventSystem",
"guid": "{899daace-4868-4295-afcd-9eb8fb497561}",
"event_source_name": "EventSystem",
"event_id": 4625,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-06T06:25:40.864290+00:00",
"event_record_id": 1434,
"correlation": {},
"execution": {
"process_id": 2696,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "86400",
"param2": "SuppressDuplicateDuration",
"param3": "Software\\Microsoft\\EventSystem\\EventLog"
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 4625 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4626 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
Event ID 4627 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
Event ID 4628 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4629 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
Event ID 1073746449 — The EventSystem sub system is suppressing duplicate event log entries for a duration of param1 seconds.
Event ID 1073746450 — The COM+ Event System fired the param2 method on event class param3 for publisher param4 and subscriber param5 but the subscriber returned an error.
Event ID 2147488002 — The COM+ Event System failed to fire the param2 method on event class param3 for publisher param4 and subscriber param5.
Description
The COM+ Event System failed to fire the param2 method on event class param3 for publisher param4 and subscriber param5. The display name of the subscription is "param6". The HRESULT was param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
Event ID 2147488003 — The COM+ Event System could not determine the name of the current user.
Event ID 2147488004 — The COM+ Event System failed to create an instance of the subscriber param2.
Event ID 2147488005 — The COM+ Event System could not fire an EventObjectChange event to subscription param2 because the query criteria string "param3" contained an error.
Event ID 2147488006 — The COM+ Event System could not fire an EventObjectChange event to subscription param2 because a bad HRESULT was detected during filtering.
Event ID 2147488007 — The type library "param2" specified in EventClass param3 ("param4") could not be loaded, or is not correct for this EventClass.
Event ID 2147488009 — The COM+ Event System detected a corrupt IEventClass object.
Event ID 2147488010 — The COM+ Event System detected a corrupt IEventSubscription object.
Event ID 2147488257 — The COM+ Event System detected a bad return code during its internal processing.
Event ID 2147488259 — The COM+ Event System detected an unexpected null pointer during its internal processing, at line param2 of param1.
Event ID 2147488261 — The COM+ Event System detected an unexpected error from a Win32 API call at line param2 of param1.
Event ID 2147488262 — The COM+ Event System detected an inconsistency in its internal state.
Event ID 2147488275 — The COM+ Event System timed out attempting to fire the param2 method on event class param3 for publisher param4 and subscriber param5.
Event ID 2147488276 — The COM+ Event System service blocked the creation of a subscription to the event class with CLSID
Event ID 2147488277 — The COM+ Event System did not fire the
Event ID 3221230081 — The COM+ Event System detected a bad return code during its internal processing.
Event ID 3221230082 — The COM+ Event System detected a bad return code during its internal processing.
Event ID 3221230083 — The COM+ Event System detected an unexpected null pointer during its internal processing; at line {param2} of {param1}.
Event ID 3221230084 — The COM+ Event System ran out of memory during its internal processing, at line param2 of param1.
Event ID 3221230085 — The COM+ Event System detected an unexpected error from a Win32 API call at line {param2} of {param1}.
Event ID 3221230086 — The COM+ Event System detected an inconsistency in its internal state.
Event ID 3221230087 — The COM+ Event System caught an exception param1 at address param2 within method param3 of interface param4.
Event ID 3221230088 — The COM+ Event System caught an access violation at address param1 within method param3 of interface param4.
Description
The COM+ Event System caught an access violation at address param1 within method param3 of interface param4. The method attempted to access address param2.param5.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |