Microsoft-Windows-Forwarding
8 events across 1 channel
| Event ID | Title | Channel |
|---|---|---|
| 100 | The subscription Id is created successfully. | Operational |
| 101 | The subscription Id is created, but one or more channels in the query could not … | Operational |
| 102 | The subscription Id can not be created. | Operational |
| 103 | The subscription Id is unsubscribed. | Operational |
| 104 | The forwarder has successfully connected to the subscription manager at address … | Operational |
| 105 | The forwarder is having a problem communicating with subscription manager at … | Operational |
| 106 | Subscription policy has changed. | Operational |
| 107 | A subscription policy contains invalid configuration. | Operational |
Event ID 100 — The subscription Id is created successfully.
Event ID 101 — The subscription Id is created, but one or more channels in the query could not be read at this time.
Description
The subscription Id is created, but one or more channels in the query could not be read at this time.
Message #
Fields #
| Name | Description |
|---|---|
Id UnicodeString | — |
Query UnicodeString | — |
Status UnicodeString | — NTSTATUS reference |
Event ID 102 — The subscription Id can not be created.
Event ID 103 — The subscription Id is unsubscribed.
Event ID 104 — The forwarder has successfully connected to the subscription manager at address SubscriptionManagerAddress.
Event ID 105 — The forwarder is having a problem communicating with subscription manager at address SubscriptionManagerAddress.
Event ID 106 — Subscription policy has changed.
#Description
Subscription policy has changed. Forwarder is adjusting its subscriptions according to the subscription manager(s) in the updated policy.
Message #
Fields #
| Name | Description |
|---|---|
Name | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Forwarding",
"guid": "699E309C-E782-4400-98C8-E21D162D7B7B",
"event_source_name": "",
"event_id": 106,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:34:38.286788+00:00",
"event_record_id": 7,
"correlation": {
"ActivityID": "E0AAB88C-4A9F-0001-35B9-AAE09F4AD801"
},
"execution": {
"process_id": 2416,
"thread_id": 1084
},
"channel": "Microsoft-Windows-Forwarding/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"Name": "SubscriptionPolicyChanged"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline