Microsoft-Windows-HttpEvent
58 events across 2 channels
Event ID 15000 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
LogFile UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15001 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
SiteId UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15002 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
LogFile UnicodeString | — |
SiteId UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15003 —
Event ID 15004 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
LogFile UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15005 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Address UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15006 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Directory UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15007 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Url UnicodeString | — |
Event ID 15007 — Reservation for namespace identified by URL prefix http://+:80/116B50EB-ECE2-41ac-8429-9F9E963361B7/ was successfully added.
#Fields #
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpEvent",
"guid": "{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}",
"event_source_name": "HTTP",
"event_id": 15007,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:31:04.679734+00:00",
"event_record_id": 1020,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 128
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": ""
}
},
"event_data": {
"DeviceObject": "",
"Url": "https://+:3392/rdp/"
},
"message": ""
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 15008 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Url UnicodeString | — |
Event ID 15008 —
#Fields #
| Name | Description |
|---|---|
DeviceObject | — |
Url | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpEvent",
"guid": "{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}",
"event_source_name": "HTTP",
"event_id": 15008,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2022-04-07T08:30:58.023418+00:00",
"event_record_id": 1014,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 268
},
"channel": "System",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": ""
}
},
"event_data": {
"DeviceObject": "",
"Url": "https://+:3392/rdp/"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 15009 —
Event ID 15010 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Url UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15011 —
Event ID 15012 —
Event ID 15013 —
Event ID 15014 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Address UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15015 —
Event ID 15016 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
SecurityPackage UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15017 —
Event ID 15018 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
LogFile UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15019 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Host UnicodeString | — |
Event ID 15020 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Host UnicodeString | — |
Event ID 15021 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Endpoint UnicodeString | — |
__binLength UInt32 | — |
binary Binary | — |
Event ID 15022 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Status UnicodeString | — NTSTATUS reference |
Event ID 15300 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Endpoint UnicodeString | — |
Event ID 15300 —
Fields #
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpEvent",
"guid": "{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}",
"event_source_name": "HTTP",
"event_id": 15300,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T23:13:38.970375+00:00",
"event_record_id": 12418,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 3408
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"DeviceObject": "",
"Endpoint": "adfs.ludus.domain:443"
},
"message": ""
}
Event ID 15301 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Endpoint UnicodeString | — |
Event ID 15301 —
Fields #
| Name | Description |
|---|---|
DeviceObject | — |
Endpoint | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpEvent",
"guid": "{7b6bc78c-898b-4170-bbf8-1a469ea43fc5}",
"event_source_name": "HTTP",
"event_id": 15301,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2025-12-31T19:35:47.955598+00:00",
"event_record_id": 421,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 356
},
"channel": "System",
"computer": "WIN11-22H2-X64",
"security": {
"user_id": ""
}
},
"event_data": {
"DeviceObject": "",
"Endpoint": "0.0.0.0:5986"
},
"message": ""
}
Event ID 15302 —
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Endpoint UnicodeString | — |
Event ID 1073756831 — Reservation for namespace identified by URL prefix Url was successfully added.
Event ID 1073756832 — Reservation for namespace identified by URL prefix Url was successfully deleted.
Event ID 1073756839 — Unable to convert all entries on IP Listen-Only list.
Description
Unable to convert all entries on IP Listen-Only list. Driver will listen on all available interfaces.
Message #
Event ID 2147498667 — The host Host has gone down as a result of the change in the IP Listen-Only list.
Event ID 2147498668 — The host Host has come up as a result of the change in the IP Listen-Only list.
Event ID 2147498948 — SSL Certificate Settings deleted for endpoint : Endpoint .
Event ID 2147498949 — SSL Certificate Settings created by an admin process for endpoint : Endpoint .
Event ID 2147498950 — SSL Certificate Settings updated by an admin process for endpoint : Endpoint .
Event ID 3221240472 — Unable to create log file LogFile.
Event ID 3221240473 — Unable to create the log file for site W3SVCSiteId.
Event ID 3221240474 — Unable to write to the log file LogFile for site W3SVCSiteId.
Event ID 3221240475 — Unable to create the centralized binary log file.
Description
Unable to create the centralized binary log file. Make sure that the logging directory is correct and this computer has write access to that directory.
Message #
Event ID 3221240476 — Unable to write to the centralized binary log file LogFile.
Event ID 3221240477 — Unable to bind to the underlying transport for Address.
Description
Unable to bind to the underlying transport for Address. The IP Listen-Only list may contain a reference to an interface which may not exist on this machine. The data field contains the error number.
Message #
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Address UnicodeString | — |
binary Binary | — |
Event ID 3221240478 — Owner of the log file or directory Directory is invalid.
Event ID 3221240481 — An error occurred while initializing namespace reservations.
Description
An error occurred while initializing namespace reservations. The error status code is contained within the returned data.
Message #
Event ID 3221240482 — An error occured while initializing namespace reservation identified by URL prefix Url.
Event ID 3221240483 — Unable to create the error log file.
Description
Unable to create the error log file. Make sure that the error logging directory is correct.
Message #
Event ID 3221240484 — Unable to write to the error log file.
Description
Unable to write to the error log file. Disk may be full. The data field contains the error number.
Message #
Event ID 3221240485 — Error logging configuration failed.
Description
Error logging configuration failed. The data field contains the error number.
Message #
Event ID 3221240486 — Unable to convert IP Listen-Only list entry Address.
Event ID 3221240488 — Unable to initialize the security package SecurityPackage for server side authentication.
Event ID 3221240489 — Unable to create the centralized W3C log file.
Description
Unable to create the centralized W3C log file. Make sure that the logging directory is correct and this computer has write access to that directory.
Message #
Event ID 3221240490 — Unable to write to the centralized W3C log file LogFile.
Event ID 3221240491 — The host {Host} has gone down as a result of the change in the IP Listen-Only list.
Event ID 3221240492 — The host {Host} has come up as a result of the change in the IP Listen-Only list.
Event ID 3221240493 — An error occurred while using SSL configuration for endpoint Endpoint.
Event ID 3221240494 — Http.
Description
Http.sys failed to process a CPU hot-add event. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceObject UnicodeString | — |
Status UnicodeString | — NTSTATUS reference |