Microsoft-Windows-HostGuardianService-Client
182 events across 4 channels
Event ID 100 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 100 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 101 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 101 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 102 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 102 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 103 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 103 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 104 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 104 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 105 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 105 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 106 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 107 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 108 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 109 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 109 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 110 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 110 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 111 —
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 111 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 112 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 112 — Started operation '.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 113 —
Fields
| Name | Description |
|---|---|
OperationName | — |
StatusCode | — |
Event ID 113 — Operation '.
Message
Fields
| Name | Description |
|---|---|
OperationName | — |
StatusCode | — |
Event ID 200 — A new ActivityID has been generated.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 1002 — Remote attestation initiated.
Message
Event ID 1003 — Remote attestation completed.
Message
Fields
| Name | Description |
|---|---|
OperationMode | — |
AttestationStatus | — |
AttestationSubstatus | — |
Event ID 1004 —
Fields
| Name | Description |
|---|---|
HostId | — |
Event ID 1004 — ClientAttestationHttpRequestSend: ActivityID %1.
Message
Fields
| Name | Description |
|---|---|
HostId | — |
Event ID 1005 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1005 — ClientAttestationHttpResponseReceived.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1006 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1006 — ClientAttestationHttpError.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1007 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1008 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1009 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1010 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1012 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1012 — Determining TPM endorsement key failed.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1013 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1013 — The remote attestation request failed because of a TPM error.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1014 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1014 — Connection to %1 failed.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1015 — Switching to Active Directory attestation mode.
Message
Event ID 1016 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1016 — Connecting to Remote Attestation service at %1.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1017 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1017 — Reconnecting to Remote Attestation service at %1.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1018 — Remote attestation succeeded and returned a health certificate with the thumbprint %1.
Message
Fields
| Name | Description |
|---|---|
CertThumbprint | — |
Event ID 1019 —
Event ID 1019 — The remote attestation request failed because the Remote Attestation Service could not be reached.
Message
Event ID 1020 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1020 — The remote attestation request failed.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1021 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1021 — The remote attestation request failed because this host was not booted correctly.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1022 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1023 — Determining TPM endorsement key failed.
Message
Event ID 1024 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1024 — The remote attestation request failed because this host was not configured properly.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1025 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1025 — The remote attestation request failed because Isolated User Mode could not be detected.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1026 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1026 — The remote attestation request failed because the TPM measurements were not valid.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1027 —
Event ID 1027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message
Event ID 1028 —
Event ID 1028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message
Event ID 1029 —
Event ID 1029 — The remote attestation request failed because IOMMU was not required by the hypervisor.
Message
Event ID 1030 —
Event ID 1030 — The remote attestation request failed because the host did not start with BitLocker enabled.
Message
Event ID 1031 —
Event ID 1031 — The remote attestation request failed because code integrity was not required by the hypervisor.
Message
Event ID 1032 —
Event ID 1032 — The remote attestation request failed but no reason was given.
Message
Event ID 1033 — Switching to TPM attestation mode.
Message
Event ID 1034 —
Event ID 1034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
Message
Event ID 1035 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1035 — The remote attestation request failed because the Host Guardian Service could not be contacted.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1036 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1037 —
Event ID 1037 — The remote attestation request failed because the host started with hibernation enabled.
Message
Event ID 1038 —
Event ID 1038 — The remote attestation request failed because the host started with dumps enabled.
Message
Event ID 1039 —
Event ID 1039 — The remote attestation request failed because the host did not start with dump encryption enabled.
Message
Event ID 1040 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1041 — Local attestation initiated.
Message
Event ID 1042 — No local health signing certificate was found.
Message
Event ID 1043 —
Event ID 1043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.
Message
Event ID 1044 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1044 — The endorsement key certificate could not be found in the TPM.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1045 —
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1045 — The issuing intermediate certificate could not be found in the TPM for the endorsement key certificate.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 1046 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 1046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2000 — The requested WMI operation failed because access is denied.
Message
Event ID 2001 —
Fields
| Name | Description |
|---|---|
FirstMessage | — |
SecondMessage | — |
Event ID 2001 — The required value '.
Message
Fields
| Name | Description |
|---|---|
FirstMessage | — |
SecondMessage | — |
Event ID 2002 — Successfully opened Shielded VM Local Certificates store.
Message
Event ID 2003 — No health signing certificate was found.
Message
Event ID 2004 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2004 — The Host Guardian Service Client is unable to retrieve the encryption key (IDK) because Virtualization Based Security is not running on this system.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2005 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2005 — Unable to retrieve the local health certificate.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2006 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2006 — Failed to roll the transport key.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2007 —
Event ID 2007 — No signing certificates were found in the Shielded VM Local Certificates store.
Message
Event ID 2008 —
Event ID 2008 — No encryption certificates were found in the Shielded VM Local Certificates store.
Message
Event ID 2009 — Initiating unwrap of key protector.
Message
Event ID 2010 — Initiating creation of a new of key protector.
Message
Event ID 2011 — Adding a guardian with signing certificate %1 and encryption certificate %2 to a key protector.
Message
Fields
| Name | Description |
|---|---|
FirstMessage | — |
SecondMessage | — |
Event ID 2012 — Initiating privileged unwrap of key protector.
Message
Event ID 2013 — Instantiating Host Guardian Service client in %1 mode.
Message
Fields
| Name | Description |
|---|---|
Mode | — |
Event ID 2014 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2014 — The Host Guardian Service Client failed to unwrap a Key Protector on behalf of a calling process.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 2015 —
Event ID 2015 — The Host Guardian Service Client successfully unwrapped a Key Protector on behalf of a calling process.
Message
Event ID 2016 —
Event ID 2016 — The signing certificate need set 'DigitalSignature' key usage.
Message
Event ID 2017 —
Event ID 2017 — The encryption certificate need set 'DataEncipherment' key usage.
Message
Event ID 2018 — Failures rolling the transport key as the health certificate is invalid.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ValidationStatus | — |
Message | — |
Event ID 2019 —
Fields
| Name | Description |
|---|---|
CertificateDataLength | — |
CertificateData | — |
Event ID 2019 — Raw certificate dump.
Message
Fields
| Name | Description |
|---|---|
CertificateDataLength | — |
CertificateData | — |
Event ID 2020 — The Host Guardian Service Client reused a cached health certificate issued in %1 mode that is valid until %2.
Message
Fields
| Name | Description |
|---|---|
OperationMode | — |
CertificateValidTo | — |
Event ID 2021 — The Host Guardian Service Client could not contact the Host Guardian Service.
Message
Fields
| Name | Description |
|---|---|
FirstMessage | — |
SecondMessage | — |
Event ID 3007 — The remote attestation request failed because this host is not included in the authorized list of host endorsement keys (EKs) on the attestation se...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3008 — The remote attestation request failed because the host did not start with Secure Boot enabled or the Secure Boot settings and TPM measurements did ...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3009 — The remote attestation request failed because this host's Code Integrity policy does not match a valid Code Integrity policy on the attestation ser...
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3010 — The remote attestation request failed because this host is not part of an Active Directory host group which is authorized by the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3013 — The remote attestation request failed because of a TPM error.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3019 — The remote attestation request failed because the Remote Attestation Service could not be reached.
Message
Event ID 3020 — The remote attestation request failed.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3021 — The remote attestation request failed because this host was not booted correctly.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3022 — The remote attestation request failed because at least one Debug Mode is enabled among Hypervisor, Boot, UEFI, and Kernel.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3024 — The remote attestation request failed because this host was not configured properly.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3025 — The remote attestation request failed because Isolated User Mode could not be detected.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3026 — The remote attestation request failed because the TPM measurements were not valid.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3027 — The remote attestation request failed because the Host Guardian Service did not return a health certificate, but no reason was given.
Message
Event ID 3028 — The remote attestation request failed because the host did not start with pagefile encryption enabled.
Message
Event ID 3029 — The remote attestation request failed because IOMMU was not required by the hypervisor.
Message
Event ID 3030 — The remote attestation request failed because the host did not start with BitLocker enabled.
Message
Event ID 3031 — The remote attestation request failed because code integrity was not required by the hypervisor.
Message
Event ID 3032 — The remote attestation request failed but no reason was given.
Message
Event ID 3034 — The remote attestation request failed because the Host Guardian Service is using TPM-based attestation, but this host lacks the required TPM 2.
Message
Event ID 3035 — The remote attestation request failed because the Host Guardian Service could not be contacted.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3036 — The remote attestation request failed because it could not authenticate to the Host Guardian Service.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3037 — The remote attestation request failed because the host started with hibernation enabled.
Message
Event ID 3038 — The remote attestation request failed because the host started with dumps enabled.
Message
Event ID 3039 — The remote attestation request failed because the host did not start with dump encryption enabled.
Message
Event ID 3040 — The remote attestation request failed because the host's dump encryption key protector does not match any registered with the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 3043 — Remote attestation failed due to an invalid payload received by the Host Guardian Service.
Message
Event ID 3044 — The endorsement key certificate could not be found in the TPM.
Message
Fields
| Name | Description |
|---|---|
StatusCode | — |
Event ID 3046 — The remote attestation request failed because the host key is not inclued in the authorized list of host keys on the attestation server.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 4001 — The HGAttest API completed the operation with status code.
Message
Fields
| Name | Description |
|---|---|
Operation | — |
ResultCode | — |
Event ID 4002 —
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 4002 — The URL provided for SHS attestation is invalid.
Message
Fields
| Name | Description |
|---|---|
Message | — |
Event ID 4003 —
Event ID 4003 — Attestation is not supported in this configuration.
Message
Event ID 4004 —
Event ID 4004 — Remote attestation for a Certified Virtual Secure Mode Identity Signing Key is currently not supported.
Message
Event ID 4005 —
Event ID 4005 — Remote attestation for a CA Intermediate Certificate is currently not supported.
Message
Event ID 4006 —
Fields
| Name | Description |
|---|---|
ClientOperationMode | — |
ServerOperationMode | — |
Event ID 4006 — This host attempted a remote attestation in %1 mode, but the targeted HGS server is operating in %2 mode.
Message
Fields
| Name | Description |
|---|---|
ClientOperationMode | — |
ServerOperationMode | — |
Event ID 5000 —
Fields
| Name | Description |
|---|---|
CertThumbprint | — |
Event ID 5000 — A host key was set from certificate with thumbprint %1.
Message
Fields
| Name | Description |
|---|---|
CertThumbprint | — |
Event ID 5001 —
Fields
| Name | Description |
|---|---|
CertThumbprint | — |
Event ID 5001 — A host key was removed.
Message
Fields
| Name | Description |
|---|---|
CertThumbprint | — |