Microsoft-Windows-Health
85 events across 4 channels
Event ID 8454: [Provider Provider] Data.
#Event ID 8454:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8455: [Provider Provider] Data.
#Event ID 8455:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8456: [Provider Provider] Data.
#Event ID 8456:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8457: [Provider Provider] Data.
#Event ID 8457:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8458: [Provider Provider] Data.
#Event ID 8458:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8464: ActivityId: ActivityId.
#Event ID 8465: ChangeType: ChangeType.
#Description
ChangeType: ChangeType.
Message #
Fields #
| Name | Description |
|---|---|
ChangeType UnicodeString | |
FaultSeverity UnicodeString | |
Source UnicodeString | |
ResourceName UnicodeString | |
ResourceType UnicodeString | |
Title UnicodeString | |
Description UnicodeString | |
Remediation UnicodeString | |
FaultTypeId UnicodeString | |
FaultId UnicodeString |
Event ID 8472: HealthServiceHealthAgent8472
#Event ID 8473: HealthServiceHealthAgent8473
#Event ID 8474: HealthServiceHealthAgent8474
#Event ID 8475: HealthServiceHealthAgent8475
#Event ID 8480: [Provider Provider] Data.
#Event ID 8480:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8481: [Provider Provider] Data.
#Event ID 8481:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8482: [Provider Provider] Data.
#Event ID 8482:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8483: [Provider Provider] Data.
#Event ID 8483:
#Description
[Provider ].
Fields #
| Name | Description |
|---|---|
Provider UnicodeString | |
Data UnicodeString |
Event ID 8496: {"ClusterInstanceId":"ClusterInstanceId","ClusterName":"ClusterName","ArmId":"ArmId","CorrelationId":"CorrelationId","PublishTime":"PublishTime","IsLastMessage":"IsLastMessage","Fault":Fault}.
#Description
{"ClusterInstanceId":"ClusterInstanceId","ClusterName":"ClusterName","ArmId":"ArmId","CorrelationId":"CorrelationId","PublishTime":"PublishTime","IsLastMessage":"IsLastMessage","Fault":Fault}.
Message #
Fields #
| Name | Description |
|---|---|
ClusterInstanceId UnicodeString | |
ClusterName UnicodeString | |
ArmId UnicodeString | |
CorrelationId UnicodeString | |
PublishTime UnicodeString | |
IsLastMessage Boolean | |
Fault UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID f0a43898-4017-4d3b-acac-ff7fb8ac63cd
Defined in healthres.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0 · captured 2026-06-02