Microsoft-Windows-GroupPolicy
177 events across 2 channels
Event ID 1002 — The processing of Group Policy failed because of a system allocation failure.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1006 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1007 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1030 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1052 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Event ID 1053 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Event ID 1054 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Event ID 1055 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Event ID 1058 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
GPOCNName | — |
FilePath | — |
Event ID 1065 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
GPOCNName | — |
Event ID 1068 — The processing of Group Policy was interrupted.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
Event ID 1079 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1080 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1085 — Windows failed to apply the %8 settings.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
ExtensionName | — |
ExtensionId | — |
References
Event ID 1088 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1089 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1090 — Windows failed to record Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied to the computer or u...
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
Event ID 1091 — Windows could not record the Resultant Set of Policy (RSoP) information for the Group Policy extension <.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
ExtensionName | — |
ExtensionId | — |
Event ID 1095 — Windows encountered an error while recording Resultant Set of Policy (RSoP) information, which describes the scope of Group Policy objects applied ...
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1096 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
GPOCNName | — |
FilePath | — |
Event ID 1097 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1101 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
DSObjectName | — |
Event ID 1104 — Windows was unable to read the Windows Management Instrumentation (WMI) filter information associated with the Group Policy object %8.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
GPOCNName | — |
Event ID 1109 — The user account is in a different forest than the computer account.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
Event ID 1110 — The processing of Group Policy failed.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Event ID 1112 — The Group Policy Client Side Extension %8 was unable to apply one or more settings because the changes must be processed before system startup or u...
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
ExtensionName | — |
ExtensionId | — |
Event ID 1125 — The processing of Group Policy failed because of an internal system error.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
References
Event ID 1126 — Windows was unable to determine whether new Group Policy settings defined by a network administrator should be enforced for this user or computer b...
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1127 — The processing of Group Policy failed due to an internal error.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
DCName | — |
Event ID 1128 — The Group Policy Client Side Extension %3 may have caused the Group Policy Service to terminate unexpectedly.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ExtensionName | — |
ExtensionId | — |
Event ID 1129 — The processing of Group Policy failed because of lack of network connectivity to a domain controller.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
ErrorCode | — |
ErrorDescription | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 1129
version: 0
level: 2
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T16:57:06.407574+00:00'
event_record_id: 1271
correlation:
ActivityID: B87F014A-16D6-49C2-8037-BBF193577383
execution:
process_id: 1352
thread_id: 2676
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
SupportInfo1: 1
SupportInfo2: 2044
ProcessingMode: 1
ProcessingTimeInMilliseconds: 4078
ErrorCode: 1222
ErrorDescription: 'The network is not present or not started. '
message: ''
References
- Microsoft Learn https://learn.microsoft.com/en-us/troubleshoot/windows-server/group-policy/netlogon-event-id-5719-or-group-policy-event-1129
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1130 — %5 failed.
Message
Fields
| Name | Description |
|---|---|
GPO_Name | — |
GPO_File_System_Path | — |
Script_Name | — |
SupportInfo1 | — |
SupportInfo2 | — |
ErrorCode | — |
ErrorDescription | — |
ScriptType | — |
GPODisplayName | — |
GPOFileSystemPath | — |
GPOScriptCommandString | — |
Event ID 1500 — The Group Policy settings for the computer were processed successfully.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 1500
version: 0
level: 4
task: 0
opcode: 1
keywords: 9223372036854775808
time_created: '2023-11-05T22:44:13.952441+00:00'
event_record_id: 1973
correlation:
ActivityID: 73911CA3-27B1-475D-92EC-CBFA1D10EB35
execution:
process_id: 1132
thread_id: 2268
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
SupportInfo1: 1
SupportInfo2: 4214
ProcessingMode: 0
ProcessingTimeInMilliseconds: 156
DCName: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1501 — The Group Policy settings for the user were processed successfully.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 1501
version: 0
level: 4
task: 0
opcode: 1
keywords: 9223372036854775808
time_created: '2023-11-05T22:28:54.475787+00:00'
event_record_id: 1832
correlation:
ActivityID: 5D6D5E8D-CE04-46CB-BF83-231A8B295C46
execution:
process_id: 1860
thread_id: 4880
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
SupportInfo1: 1
SupportInfo2: 4214
ProcessingMode: 1
ProcessingTimeInMilliseconds: 734
DCName: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1502 — The Group Policy settings for the computer were processed successfully.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
NumberOfGroupPolicyObjects | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 1502
version: 0
level: 4
task: 0
opcode: 1
keywords: 9223372036854775808
time_created: '2023-11-05T23:49:58.052759+00:00'
event_record_id: 2033
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
SupportInfo1: 1
SupportInfo2: 4195
ProcessingMode: 0
ProcessingTimeInMilliseconds: 906
DCName: ''
NumberOfGroupPolicyObjects: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1503 — The Group Policy settings for the user were processed successfully.
Message
Fields
| Name | Description |
|---|---|
SupportInfo1 | — |
SupportInfo2 | — |
ProcessingMode | — |
ProcessingTimeInMilliseconds | — |
DCName | — |
NumberOfGroupPolicyObjects | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 1503
version: 0
level: 4
task: 0
opcode: 1
keywords: 9223372036854775808
time_created: '2022-04-07T17:34:38.149825+00:00'
event_record_id: 1319
correlation:
ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
execution:
process_id: 1352
thread_id: 1684
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
SupportInfo1: 1
SupportInfo2: 4195
ProcessingMode: 0
ProcessingTimeInMilliseconds: 671
DCName: \\WIN-FPV0DSIC9O6.sigma.fr
NumberOfGroupPolicyObjects: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4000 — Starting computer boot policy processing for %2.
Message
Fields
| Name | Description |
|---|---|
PolicyActivityId | Activity id. |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4000
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:17.280621+00:00'
event_record_id: 479
correlation:
ActivityID: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
execution:
process_id: 1132
thread_id: 1348
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyActivityId: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
IsMachine: 1
IsDomainJoined: false
IsBackgroundProcessing: false
IsAsyncProcessing: true
IsServiceRestart: false
ReasonForSyncProcessing: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4001 — Starting user logon Policy processing for %2.
Message
Fields
| Name | Description |
|---|---|
PolicyActivityId | Activity id. |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4001
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:20.905356+00:00'
event_record_id: 495
correlation:
ActivityID: DE67DFB7-B871-42E1-B68C-4175341DA657
execution:
process_id: 1132
thread_id: 3904
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyActivityId: DE67DFB7-B871-42E1-B68C-4175341DA657
PrincipalSamName: WINDEV2310EVAL\User
IsMachine: 0
IsDomainJoined: false
IsBackgroundProcessing: false
IsAsyncProcessing: true
IsServiceRestart: false
ReasonForSyncProcessing: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4002 — Starting policy processing due to network state change for computer %2.
Message
Fields
| Name | Description |
|---|---|
Activity_id | — |
PolicyActivityId | — |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Event ID 4003 — Starting policy processing due to network state change for user %2.
Message
Fields
| Name | Description |
|---|---|
Activity_id | — |
PolicyActivityId | — |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Event ID 4004 — Starting manual processing of policy for computer %2.
Message
Fields
| Name | Description |
|---|---|
PolicyActivityId | Activity id. |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4004
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.126023+00:00'
event_record_id: 1152
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyActivityId: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
IsMachine: 1
IsDomainJoined: false
IsBackgroundProcessing: true
IsAsyncProcessing: false
IsServiceRestart: false
ReasonForSyncProcessing: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4005 — Starting manual processing of policy for user %2.
Message
Fields
| Name | Description |
|---|---|
PolicyActivityId | Activity id. |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4005
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2022-04-07T17:34:37.483672+00:00'
event_record_id: 835
correlation:
ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
execution:
process_id: 1352
thread_id: 1684
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PolicyActivityId: DCA9073D-A053-4D86-A71A-A22443FB751F
PrincipalSamName: SIGMA\Administrator
IsMachine: 0
IsDomainJoined: true
IsBackgroundProcessing: true
IsAsyncProcessing: false
IsServiceRestart: false
ReasonForSyncProcessing: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4006 — Starting periodic policy processing for computer %2.
Message
Fields
| Name | Description |
|---|---|
PolicyActivityId | Activity id. |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4006
version: 1
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.484458+00:00'
event_record_id: 866
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PolicyActivityId: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
IsMachine: 1
IsDomainJoined: true
IsBackgroundProcessing: true
IsAsyncProcessing: false
IsServiceRestart: false
ReasonForSyncProcessing: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4007 — Starting periodic policy processing for user %2.
Message
Fields
| Name | Description |
|---|---|
Activity_id | — |
PolicyActivityId | — |
PrincipalSamName | — |
IsMachine | — |
IsDomainJoined | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
IsServiceRestart | — |
ReasonForSyncProcessing | — |
Event ID 4016 — Starting %2 Extension Processing.
Message
Fields
| Name | Description |
|---|---|
CSEExtensionId | — |
CSEExtensionName | — |
IsExtensionAsyncProcessing | — |
IsGPOListChanged | — |
GPOListStatusString | — |
DescriptionString | — |
ApplicableGPOList | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4016
version: 0
level: 4
task: 0
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.906053+00:00'
event_record_id: 1165
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
CSEExtensionId: F3CCC681-B74C-4060-9F26-CD84525DCA2A
CSEExtensionName: Audit Policy Configuration
IsExtensionAsyncProcessing: true
IsGPOListChanged: true
GPOListStatusString: '%%4102'
DescriptionString: 'Local Group Policy
'
ApplicableGPOList: <GPO ID="Local Group Policy"><Name>Local Group Policy</Name></GPO>
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4017 —
Message
Fields
| Name | Description |
|---|---|
OperationDescription | — |
Parameter | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4017
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.551157+00:00'
event_record_id: 886
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
OperationDescription: '%%4131'
Parameter: \\sigma.fr\sysvol\sigma.fr\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\gpt.ini
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4018 — Starting %2 for %1.
Message
Fields
| Name | Description |
|---|---|
PrincipalSamName | — |
ScriptType | — |
IsScriptHidden | — |
IsScriptSync | — |
IsScriptMinimized | — |
SessionId | — |
Event ID 4019 — Running script name %1.
Message
Fields
| Name | Description |
|---|---|
ScriptName | — |
ScriptFileSystemPath | — |
ScriptArguments | — |
Event ID 4115 — Group Policy Service started.
Message
Fields
| Name | Description |
|---|---|
IsServiceRestart | — |
IsMachineBoot | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4115
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:40.340217+00:00'
event_record_id: 415
correlation: {}
execution:
process_id: 2412
thread_id: 2516
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsServiceRestart: false
IsMachineBoot: true
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4116 — Started the Group Policy service initialization phase.
Message
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4116
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:40.239882+00:00'
event_record_id: 414
correlation: {}
execution:
process_id: 2412
thread_id: 2516
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4117 — Group Policy Session started.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4117
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:23.115992+00:00'
event_record_id: 1272
correlation: {}
execution:
process_id: 21104
thread_id: 4724
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: false
IsBackgroundProcessing: true
IsAsyncProcessing: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4126 — Group Policy receiving applicable GPOs from the domain controller.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4126
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.214177+00:00'
event_record_id: 1155
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: true
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4216 — Starting to save policies to the local datastore.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
Event ID 4217 — Starting to load policies from the local datastore.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
Event ID 4218 — Starting the first WMI query for the policy.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
Event ID 4257 — Starting to download policies.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4257
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.495445+00:00'
event_record_id: 882
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
IsMachine: true
IsBackgroundProcessing: true
IsAsyncProcessing: true
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4326 — Group Policy is trying to discover the Domain Controller information.
Message
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 4326
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.485405+00:00'
event_record_id: 872
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5016 — Completed %3 Extension Processing in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
CSEElaspedTimeInMilliSeconds | — |
ErrorCode | — |
CSEExtensionName | — |
CSEExtensionId | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5016
version: 0
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:58.046318+00:00'
event_record_id: 1166
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
CSEElaspedTimeInMilliSeconds: 140
ErrorCode: 2147483658
CSEExtensionName: Audit Policy Configuration
CSEExtensionId: F3CCC681-B74C-4060-9F26-CD84525DCA2A
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5017 — %3 %4 The call completed in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
OperationElaspedTimeInMilliSeconds | — |
ErrorCode | — |
OperationDescription | — |
Parameter | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5017
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.553922+00:00'
event_record_id: 887
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
OperationElaspedTimeInMilliSeconds: 0
ErrorCode: 0
OperationDescription: '%%4132'
Parameter: \\sigma.fr\sysvol\sigma.fr\Policies\{6AC1786C-016F-11D2-945F-00C04fB984F9}\gpt.ini
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5018 — Completed %4 for %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
ScriptElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
ScriptType | — |
Event ID 5019 — Completed %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
ScriptElaspedTimeInSeconds | — |
ErrorCode | — |
ScriptName | — |
Event ID 5115 — Group Policy Service stopped.
Message
Fields
| Name | Description |
|---|---|
IsServiceRestart | — |
IsMachineBoot | — |
GpsvcTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5115
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:34.542622+00:00'
event_record_id: 468
correlation: {}
execution:
process_id: 1860
thread_id: 1836
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsServiceRestart: false
IsMachineBoot: true
GpsvcTimeElapsedInMilliseconds: 175484
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5116 — Successfully completed the Group Policy Service initialization phase.
Message
Fields
| Name | Description |
|---|---|
GpsvcInitTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5116
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:40.434301+00:00'
event_record_id: 416
correlation: {}
execution:
process_id: 2412
thread_id: 2548
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
GpsvcInitTimeElapsedInMilliseconds: 203
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5117 — Group policy session completed successfully.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
SessionTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5117
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:23.611150+00:00'
event_record_id: 1279
correlation:
ActivityID: 30469375-F951-41D9-8DD5-460652667F6C
execution:
process_id: 21104
thread_id: 18128
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: true
SessionTimeElapsedInMilliseconds: 719
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5126 — Group Policy successfully got applicable GPOs from the domain controller.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
IsBackgroundProcessing | — |
IsAsyncProcessing | — |
NumberOfGPOsDownloaded | — |
NumberOfGPOsApplicable | — |
GPODownloadTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5126
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.224158+00:00'
event_record_id: 1157
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: true
IsBackgroundProcessing: true
IsAsyncProcessing: false
NumberOfGPOsDownloaded: 1
NumberOfGPOsApplicable: 0
GPODownloadTimeElapsedInMilliseconds: 0
message: ''
References
- Ultimate Windows Security https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=5126
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5216 — Successfully saved policies to the local datastore.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
SaveToCacheTimeElapsedInMilliseconds | — |
Event ID 5217 — Successfully loaded policies from the local datastore.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
LoadFromCacheTimeElapsedInMilliseconds | — |
Event ID 5218 — Successfully completed the first WMI query.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
FirstWmiQueryTimeElapsedInMilliseconds | — |
Event ID 5257 — Successfully completed downloading policies.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
PolicyDownloadTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5257
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.215760+00:00'
event_record_id: 1156
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: true
PolicyDownloadTimeElapsedInMilliseconds: 4681812
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5308 — Domain Controller details: Domain Controller Name : %1 Domain Controller IP Address : %2.
Message
Fields
| Name | Description |
|---|---|
DCName | [Domain Controller details] Domain Controller Name. |
DCIPAddress | [Domain Controller details] Domain Controller IP Address. |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5308
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.488998+00:00'
event_record_id: 876
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
DCName: WIN-FPV0DSIC9O6.sigma.fr
DCIPAddress: 10.0.2.133
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5309 — Computer details: Computer role : %1 Network name : %2.
Message
Fields
| Name | Description |
|---|---|
MachineRole | [Computer details] Computer role. |
NetworkName | [Computer details] Network name. |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5309
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.489467+00:00'
event_record_id: 878
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
MachineRole: 3
NetworkName: localdomain
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5310 — Account details: Account Name : %1 Account Domain Name : %2 DC Name : %3 DC Domain Name : %4.
Message
Fields
| Name | Description |
|---|---|
PrincipalCNName | [Account details] Account Name. |
PrincipalDomainName | [Account details] Account Domain Name. |
DCName | [Account details] DC Name. |
DCDomainName | [Account details] DC Domain Name. |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5310
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.489469+00:00'
event_record_id: 879
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PrincipalCNName: CN=WIN-FPV0DSIC9O6,OU=Domain Controllers,DC=sigma,DC=fr
PrincipalDomainName: sigma.fr
DCName: \\WIN-FPV0DSIC9O6.sigma.fr
DCDomainName: sigma.fr
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5311 — The loopback policy processing mode is %1.
Message
Fields
| Name | Description |
|---|---|
PolicyProcessingMode | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5311
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.213591+00:00'
event_record_id: 1154
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyProcessingMode: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5312 — List of applicable Group Policy objects.
Message
Fields
| Name | Description |
|---|---|
DescriptionString | List of applicable Group Policy objects |
GPOInfoList | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5312
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.225593+00:00'
event_record_id: 1158
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
DescriptionString: 'Local Group Policy
'
GPOInfoList: <GPO ID="Local Group Policy"><Name>Local Group Policy</Name><Version>2621480</Version><SOM>Local</SOM><FSPath>C:\Windows\System32\GroupPolicy\Machine</FSPath><Extensions>[{35378EAC-683F-11D2-A89A-00C04FBBCFA2}{D02B1F72-3407-48AE-BA88-E8213C6761F1}][{F3CCC681-B74C-4060-9F26-CD84525DCA2A}{0F3F3735-573D-9804-99E4-AB2A69BA5FD4}]</Extensions></GPO>
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5313 — The following Group Policy objects were not applicable because they were filtered out.
Message
Fields
| Name | Description |
|---|---|
DescriptionString | The following Group Policy objects were not applicable because they were filtered out |
GPOInfoList | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5313
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.225627+00:00'
event_record_id: 1159
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
DescriptionString: None
GPOInfoList: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5314 — A %6 link was detected.
Message
Fields
| Name | Description |
|---|---|
BandwidthInkbps | — |
IsSlowLink | — |
ThresholdInkbps | — |
PolicyApplicationMode | — |
ErrorCode | — |
LinkDescription | — |
Event ID 5315 — Next policy processing for %1 will be attempted in %2 %3.
Message
Fields
| Name | Description |
|---|---|
PrincipalSamName | — |
NextPolicyApplicationTime | — |
NextPolicyApplicationTimeUnit | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5315
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.580689+00:00'
event_record_id: 898
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
NextPolicyApplicationTime: 5
NextPolicyApplicationTimeUnit: '%%4100'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5320 —
Message
Fields
| Name | Description |
|---|---|
InfoDescription | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5320
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:47.222709+00:00'
event_record_id: 419
correlation: {}
execution:
process_id: 2412
thread_id: 2548
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
InfoDescription: '%%4166'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5321 — %1 Parameter: %2.
Message
Fields
| Name | Description |
|---|---|
InfoDescription | — |
OperationParameter1 | 1 Parameter. |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5321
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T06:25:47.223028+00:00'
event_record_id: 420
correlation: {}
execution:
process_id: 2412
thread_id: 2548
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
InfoDescription: '%%4167'
OperationParameter1: 9c6b0019-6984-4ded-a867-f9ffb55eb5bf
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5322 — Group Policy waited for %3 milliseconds for the network subsystem at computer boot.
Message
Fields
| Name | Description |
|---|---|
IsPolicyConfigured | — |
MaxTimeToWait | — |
TimeWaitedAtStartup | — |
PrevAvgWaitTimeout | — |
NewAvgWaitTimeout | — |
DidWaitTimeout | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5322
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T16:54:16.476862+00:00'
event_record_id: 500
correlation: {}
execution:
process_id: 1352
thread_id: 3688
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
IsPolicyConfigured: false
MaxTimeToWait: 120000
TimeWaitedAtStartup: 35110
PrevAvgWaitTimeout: 60000
NewAvgWaitTimeout: 60000
DidWaitTimeout: true
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5323 — Invalid Error Message.
Message
Event ID 5324 — Group Policy received the notification %1 from Winlogon for session %2.
Message
Fields
| Name | Description |
|---|---|
NotificationType | — |
SessionId | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5324
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:22.822586+00:00'
event_record_id: 1268
correlation: {}
execution:
process_id: 21104
thread_id: 14860
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
NotificationType: 0
SessionId: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5325 — Group Policy received %1 notification from Service Control Manager.
Message
Fields
| Name | Description |
|---|---|
NotificationType | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5325
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:34.541162+00:00'
event_record_id: 467
correlation: {}
execution:
process_id: 1860
thread_id: 1864
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
NotificationType: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5326 — Group Policy successfully discovered the Domain Controller in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
DCDiscoveryTimeInMilliSeconds | — |
ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5326
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.489000+00:00'
event_record_id: 877
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
DCDiscoveryTimeInMilliSeconds: 0
ErrorCode: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5327 — Estimated network bandwidth on one of the connections: %1 kbps.
Message
Fields
| Name | Description |
|---|---|
NetworkBandwidthInKbps | — |
Event ID 5331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating ...
Message
Fields
| Name | Description |
|---|---|
UpdateCauseExtensionName | — |
UpdateCauseExtensionId | — |
ErrorCode | — |
Event ID 5332 — Group Policy waited for %3 milliseconds for the Direct Access CorpNet connectivity at computer boot.
Message
Fields
| Name | Description |
|---|---|
IsPolicyConfigured | — |
MaxTimeToWait | — |
TimeWaitedAtStartup | — |
DidWaitTimeout | — |
Event ID 5340 — The Group Policy processing mode is %1.
Message
Fields
| Name | Description |
|---|---|
PolicyApplicationMode | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5340
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:57.141137+00:00'
event_record_id: 1153
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyApplicationMode: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5351 — Group policy session returned to winlogon.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
WinlogonReturnTimeElapsedInMilliseconds | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 5351
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:22.915005+00:00'
event_record_id: 1271
correlation: {}
execution:
process_id: 21104
thread_id: 14860
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
IsMachine: true
WinlogonReturnTimeElapsedInMilliseconds: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6000 — Invalid Error Message.
Message
Event ID 6001 — Invalid Error Message.
Message
Event ID 6002 — Invalid Error Message.
Message
Event ID 6003 — Invalid Error Message.
Message
Event ID 6004 — Invalid Error Message.
Message
Event ID 6005 — Invalid Error Message.
Message
Event ID 6006 — Invalid Error Message.
Message
Event ID 6007 — Invalid Error Message.
Message
Event ID 6016 — Completed %3 Extension Processing in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
CSEElaspedTimeInMilliSeconds | — |
ErrorCode | — |
CSEExtensionName | — |
CSEExtensionId | — |
Event ID 6017 — Invalid Error Message.
Message
Event ID 6018 — Invalid Error Message.
Message
Event ID 6019 — Invalid Error Message.
Message
Event ID 6033 — Skipped %1 Extension based on Group Policy client-side processing rules.
Message
Fields
| Name | Description |
|---|---|
CSEExtensionName | — |
CSEExtensionID | — |
Event ID 6034 — Group Policy changed from synchronous foreground to asynchronous foreground based on slow link detection.
Message
Event ID 6035 — %1 Extension deferred processing until next synchronous foreground.
Message
Fields
| Name | Description |
|---|---|
CSEExtensionName | — |
CSEExtensionID | — |
Event ID 6226 — Invalid Error Message.
Message
Event ID 6308 — Invalid Error Message.
Message
Event ID 6309 — Invalid Error Message.
Message
Event ID 6310 — Invalid Error Message.
Message
Event ID 6311 — Invalid Error Message.
Message
Event ID 6312 — Invalid Error Message.
Message
Event ID 6313 — Invalid Error Message.
Message
Event ID 6314 — Group Policy bandwidth estimation failed.
Message
Fields
| Name | Description |
|---|---|
BandwidthInkbps | — |
IsSlowLink | — |
ThresholdInkbps | — |
PolicyApplicationMode | — |
ErrorCode | — |
LinkDescription | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 6314
version: 0
level: 3
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.507287+00:00'
event_record_id: 883
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
BandwidthInkbps: 1
IsSlowLink: false
ThresholdInkbps: 500
PolicyApplicationMode: 0
ErrorCode: 1
LinkDescription: '%%4113'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6315 — Invalid Error Message.
Message
Event ID 6320 — Warning: %1 Warning code %2.
Message
Fields
| Name | Description |
|---|---|
Warning | — |
WarningDescription | — |
WarningCode | — |
Event ID 6321 — Warning: %1 Parameter: %3 : Warning code %2.
Message
Fields
| Name | Description |
|---|---|
Warning | — |
Parameter | — |
WarningDescription | — |
WarningCode | — |
OperationParameter1 | — |
Event ID 6322 — Invalid Error Message.
Message
Event ID 6323 — Group Policy dependency did not start.
Message
Fields
| Name | Description |
|---|---|
DisplayName | — |
Event ID 6324 — Invalid Error Message.
Message
Event ID 6325 — Invalid Error Message.
Message
Event ID 6326 — Invalid Error Message.
Message
Event ID 6327 — Invalid Error Message.
Message
Event ID 6330 — An unfinished invocation of the Group Policy Client Side Extension %1 from a previous instance of the Group Policy Service was detected.
Message
Fields
| Name | Description |
|---|---|
InfoDescription | — |
OperationParameter1 | — |
Event ID 6331 — Invalid Error Message.
Message
Fields
| Name | Description |
|---|---|
UpdateCauseExtensionName | — |
UpdateCauseExtensionId | — |
ErrorCode | — |
Event ID 6332 — Invalid Error Message.
Message
Event ID 6337 — Group Policy network connection is via Direct Access.
Message
Event ID 6338 — Group Policy Winlogon status reporting has completed.
Message
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 6338
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:28:54.477711+00:00'
event_record_id: 461
correlation: {}
execution:
process_id: 1860
thread_id: 2032
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6339 — Group Policy Winlogon Start Shell handling completed.
Message
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 6339
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:22.754428+00:00'
event_record_id: 509
correlation: {}
execution:
process_id: 1132
thread_id: 1332
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6341 — A Group Policy setting was used to override the fast/slow link detection.
Message
Event ID 6342 — The network connection is using a WWAN device for connectivity.
Message
Event ID 6344 — Group Policy detected a slow link during sync mode processing.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
SlowlinkThresholdInMilliseconds | — |
DcResponseTimeInMilliseconds | — |
Event ID 6345 — The connection to DC timed out during the Group Policy sync mode process.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
DcResponseTimeInMilliseconds | — |
Event ID 6346 — Group Policy switched the sync mode process to async mode.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
CSEExtensionName | — |
CSEExtensionID | — |
Event ID 7000 — Computer boot policy processing failed for %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7001 — User logon policy processing failed for %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7002 — Policy processing due to network state change failed for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7003 — Policy processing due to network state change failed for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7004 — Manual processing of policy failed for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7005 — Manual processing of policy failed for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7006 — Periodic policy processing failed for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7007 — Periodic policy processing failed for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 7016 — Completed %3 Extension Processing in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
CSEElaspedTimeInMilliSeconds | — |
ErrorCode | — |
CSEExtensionName | — |
CSEExtensionId | — |
Event ID 7017 — %3 %4 The call failed after %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
OperationElaspedTimeInMilliSeconds | — |
ErrorCode | — |
OperationDescription | — |
Parameter | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 7017
version: 0
level: 2
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T16:59:24.588821+00:00'
event_record_id: 562
correlation:
ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
OperationElaspedTimeInMilliSeconds: 2000
ErrorCode: 58
OperationDescription: '%%4120'
Parameter: WIN-FPV0DSIC9O6.sigma.fr
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7018 — Script for %3 failed in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
ScriptElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
ScriptType | — |
Event ID 7019 — Invalid Error Message.
Message
Event ID 7117 — Group policy session completed with error.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
ErrorCode | — |
SessionTimeElapsedInMilliseconds | — |
Event ID 7126 — Group Policy could not get applicable GPOs from the domain controller.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
ErrorCode | — |
GPODownloadTimeElapsedInMilliseconds | — |
Event ID 7216 — Saved policies to the local datastore with error.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
ErrorCode | — |
SessionTimeElapsedInMilliseconds | — |
Event ID 7217 — Loaded policies from the local datastore with error.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
ErrorCode | — |
LoadFromCacheTimeElapsedInMilliseconds | — |
Event ID 7257 — Downloaded policies with error.
Message
Fields
| Name | Description |
|---|---|
IsMachine | — |
ErrorCode | — |
PolicyDownloadTimeElapsedInMilliseconds | — |
Event ID 7308 — Invalid Error Message.
Message
Event ID 7309 — Invalid Error Message.
Message
Event ID 7310 — Invalid Error Message.
Message
Event ID 7311 — Invalid Error Message.
Message
Event ID 7312 — Invalid Error Message.
Message
Event ID 7313 — Invalid Error Message.
Message
Event ID 7314 — Invalid Error Message.
Message
Event ID 7315 — Invalid Error Message.
Message
Event ID 7320 — Error: %1 Error code %2.
Message
Fields
| Name | Description |
|---|---|
ErrorDescription | Error. |
ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 7320
version: 0
level: 2
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T16:59:24.590503+00:00'
event_record_id: 564
correlation:
ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
ErrorDescription: '%%4125'
ErrorCode: 50
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7321 — Error: %1 Parameter: %3 : Error code %2.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Parameter | — |
ErrorDescription | — |
ErrorCode | — |
OperationParameter1 | — |
Event ID 7322 — Invalid Error Message.
Message
Event ID 7323 — Invalid Error Message.
Message
Event ID 7324 — Invalid Error Message.
Message
Event ID 7325 — Invalid Error Message.
Message
Event ID 7326 — Group Policy failed to discover the Domain Controller details in %1 milliseconds.
Message
Fields
| Name | Description |
|---|---|
DCDiscoveryTimeInMilliSeconds | — |
ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 7326
version: 0
level: 2
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T16:59:24.588837+00:00'
event_record_id: 563
correlation:
ActivityID: 178B5CEF-A5EC-4DF9-951A-EF713A1FE2F6
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
DCDiscoveryTimeInMilliSeconds: 4000
ErrorCode: 58
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7327 — Invalid Error Message.
Message
Event ID 7331 — Service configuration update to standalone was attempted due to the presence of Group Policy client extension %1 that is not part of the operating ...
Message
Fields
| Name | Description |
|---|---|
UpdateCauseExtensionName | — |
UpdateCauseExtensionId | — |
ErrorCode | — |
Event ID 7332 — Invalid Error Message.
Message
Event ID 8000 — Completed computer boot policy processing for %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 8000
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:17.445743+00:00'
event_record_id: 490
correlation:
ActivityID: 70C9A908-A206-406D-8A5D-D1CA7FEE9E13
execution:
process_id: 1132
thread_id: 1348
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyElaspedTimeInSeconds: 0
ErrorCode: 0
PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
IsMachine: 1
IsConnectivityFailure: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8001 — Completed user logon policy processing for %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 8001
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:22.302154+00:00'
event_record_id: 506
correlation:
ActivityID: DE67DFB7-B871-42E1-B68C-4175341DA657
execution:
process_id: 1132
thread_id: 3904
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyElaspedTimeInSeconds: 0
ErrorCode: 0
PrincipalSamName: WINDEV2310EVAL\User
IsMachine: 0
IsConnectivityFailure: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8002 — Completed policy processing due to network state change for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 8003 — Completed policy processing due to network state change for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 8004 — Completed manual processing of policy for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 8004
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T23:49:58.061228+00:00'
event_record_id: 1167
correlation:
ActivityID: AA63BEC0-3996-4133-A97D-DB5DB9617FF3
execution:
process_id: 8540
thread_id: 9876
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
PolicyElaspedTimeInSeconds: 0
ErrorCode: 0
PrincipalSamName: WORKGROUP\WINDEV2310EVAL$
IsMachine: 1
IsConnectivityFailure: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8005 — Completed manual processing of policy for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 8005
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2022-04-07T17:34:38.174229+00:00'
event_record_id: 864
correlation:
ActivityID: DCA9073D-A053-4D86-A71A-A22443FB751F
execution:
process_id: 1352
thread_id: 1684
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PolicyElaspedTimeInSeconds: 0
ErrorCode: 0
PrincipalSamName: SIGMA\Administrator
IsMachine: 0
IsConnectivityFailure: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8006 — Completed periodic policy processing for computer %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Example Event
system:
provider: Microsoft-Windows-GroupPolicy
guid: AEA1B4FA-97D1-45F2-A64C-4D69FFFD92C9
event_source_name: ''
event_id: 8006
version: 1
level: 4
task: 0
opcode: 2
keywords: 4611686018427387904
time_created: '2022-04-07T17:39:37.570483+00:00'
event_record_id: 897
correlation:
ActivityID: 2CF6CF52-0A34-47C3-987B-53FCBD5B6234
execution:
process_id: 1352
thread_id: 4040
channel: Microsoft-Windows-GroupPolicy/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
PolicyElaspedTimeInSeconds: 0
ErrorCode: 0
PrincipalSamName: SIGMA\WIN-FPV0DSIC9O6$
IsMachine: 1
IsConnectivityFailure: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8007 — Completed periodic policy processing for user %3 in %1 seconds.
Message
Fields
| Name | Description |
|---|---|
PolicyElaspedTimeInSeconds | — |
ErrorCode | — |
PrincipalSamName | — |
IsMachine | — |
IsConnectivityFailure | — |
Event ID 8016 — %1 Extension (%2) requests a sync mode process.
Message
Fields
| Name | Description |
|---|---|
CSEExtensionName | — |
CSEExtensionId | — |
Event ID 9001 — This machine is configured to retrieve Group Policy files from a file share in an insecure way.
Message
Fields
| Name | Description |
|---|---|
UNC_Path | UNC Path. Contains logon scripts and/or files that control system security policies. |
Mutual_Authentication_Enforced | — |
Integrity_Enforced | — |
UncPath | — |
MutualAuthenticationEnforced | — |
IntegrityEnforced | — |