Microsoft-Windows-HttpEvent
56 events across 2 channels
Event ID 15000 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
__binLength | — |
binary | — |
Event ID 15001 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
SiteId | — |
__binLength | — |
binary | — |
Event ID 15002 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
SiteId | — |
__binLength | — |
binary | — |
Event ID 15003 —
Event ID 15004 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
__binLength | — |
binary | — |
Event ID 15005 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Address | — |
__binLength | — |
binary | — |
Event ID 15006 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Directory | — |
__binLength | — |
binary | — |
Event ID 15007 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Event ID 15007 — Reservation for namespace identified by URL prefix http://+:80/116B50EB-ECE2-41ac-8429-9F9E963361B7/ was successfully added.
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Example Event
system:
provider: Microsoft-Windows-HttpEvent
guid: '{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}'
event_source_name: HTTP
event_id: 15007
version: 0
level: 4
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T08:31:04.679734+00:00'
event_record_id: 1020
correlation: {}
execution:
process_id: 4
thread_id: 128
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
DeviceObject: ''
Url: https://+:3392/rdp/
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 15008 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Event ID 15008 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Example Event
system:
provider: Microsoft-Windows-HttpEvent
guid: '{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}'
event_source_name: HTTP
event_id: 15008
version: 0
level: 4
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T08:30:58.023418+00:00'
event_record_id: 1014
correlation: {}
execution:
process_id: 4
thread_id: 268
channel: System
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: ''
event_data:
DeviceObject: ''
Url: https://+:3392/rdp/
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 15009 —
Event ID 15010 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
__binLength | — |
binary | — |
Event ID 15011 —
Event ID 15012 —
Event ID 15013 —
Event ID 15014 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Address | — |
__binLength | — |
binary | — |
Event ID 15015 —
Event ID 15016 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
SecurityPackage | — |
__binLength | — |
binary | — |
Event ID 15017 —
Event ID 15018 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
__binLength | — |
binary | — |
Event ID 15019 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Host | — |
Event ID 15020 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Host | — |
Event ID 15021 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
__binLength | — |
binary | — |
Event ID 15022 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Status | — |
Event ID 15300 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 15301 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 15302 —
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 1073756831 — Reservation for namespace identified by URL prefix %2 was successfully added.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Event ID 1073756832 — Reservation for namespace identified by URL prefix %2 was successfully deleted.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Event ID 1073756839 — Unable to convert all entries on IP Listen-Only list.
Message
Event ID 2147498667 — The host %2 has gone down as a result of the change in the IP Listen-Only list.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Host | — |
Event ID 2147498668 — The host %2 has come up as a result of the change in the IP Listen-Only list.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Host | — |
Event ID 2147498948 — SSL Certificate Settings deleted for endpoint.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 2147498949 — SSL Certificate Settings created by an admin process for endpoint.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 2147498950 — SSL Certificate Settings updated by an admin process for endpoint.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Event ID 3221240472 — Unable to create log file %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
binary | — |
Event ID 3221240473 — Unable to create the log file for site W3SVC.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
SiteId | — |
binary | — |
Event ID 3221240474 — Unable to write to the log file %2 for site W3SVC%3.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
SiteId | — |
binary | — |
Event ID 3221240475 — Unable to create the centralized binary log file.
Message
Event ID 3221240476 — Unable to write to the centralized binary log file %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
binary | — |
Event ID 3221240477 — Unable to bind to the underlying transport for %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Address | — |
binary | — |
Event ID 3221240478 — Owner of the log file or directory %2 is invalid.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Directory | — |
binary | — |
Event ID 3221240481 — An error occurred while initializing namespace reservations.
Message
Event ID 3221240482 — An error occured while initializing namespace reservation identified by URL prefix %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
binary | — |
Event ID 3221240483 — Unable to create the error log file.
Message
Event ID 3221240484 — Unable to write to the error log file.
Message
Event ID 3221240485 — Error logging configuration failed.
Message
Event ID 3221240486 — Unable to convert IP Listen-Only list entry %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Address | — |
binary | — |
Event ID 3221240488 — Unable to initialize the security package %2 for server side authentication.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
SecurityPackage | — |
binary | — |
Event ID 3221240489 — Unable to create the centralized W3C log file.
Message
Event ID 3221240490 — Unable to write to the centralized W3C log file %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
LogFile | — |
binary | — |
Event ID 3221240491 — The host {Host} has gone down as a result of the change in the IP Listen-Only list.
Message
Fields
| Name | Description |
|---|---|
Host | — |
Event ID 3221240492 — The host {Host} has come up as a result of the change in the IP Listen-Only list.
Message
Fields
| Name | Description |
|---|---|
Host | — |
Event ID 3221240493 — An error occurred while using SSL configuration for endpoint %2.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
binary | — |
Event ID 3221240494 — Http.
Message
Fields
| Name | Description |
|---|---|
DeviceObject | — |
Status | — |