Microsoft-Windows-HttpService
132 events across 3 channels
Event ID 1 — Request received (request ID %1) on connection (connection ID %2) from remote address %4.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ConnectionId | — |
RemoteAddrLength | — |
RemoteAddr | — |
Event ID 2 — Parsed request (request pointer %1, method %2) with URI %3.
Message
Fields
| Name | Description |
|---|---|
RequestObj | — |
HttpVerb | — |
Url | — |
Event ID 3 — Delivered request to server application (request pointer %1, request ID %2, site ID %3) from request queue %4 for URI %5 with status %6.
Message
Fields
| Name | Description |
|---|---|
RequestObj | — |
RequestId | — |
SiteId | — |
RequestQueueName | — |
Url | — |
Status | — |
Event ID 4 — Server application passed response.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ConnectionId | — |
StatusCode | — |
Verb | — |
HeaderLength | — |
EntityChunkCount | — |
CachePolicy | — |
Event ID 5 — Server application passed the last response (corresponding to request ID %1).
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Event ID 6 — Server application passed entity body for request ID %1 (connection ID %2).
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ConnectionId | — |
Event ID 7 — Server application passed the last entity body for request ID %1.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Event ID 8 — Server application passed response.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ConnectionId | — |
StatusCode | — |
Verb | — |
HeaderLength | — |
EntityChunkCount | — |
CachePolicy | — |
Event ID 9 — Server application passed the last response (corresponding to request ID %1).
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Event ID 10 — Response ready for send (corresponding to request ID %1) with status code %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
HttpStatus | — |
Event ID 11 — Cached the response (corresponding to request ID %1) with status code %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
HttpStatus | — |
Event ID 12 — Queued last response (corresponding to request ID %1) for sending.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
HttpStatus | — |
Event ID 13 — Response sent (corresponding to request ID %1) with status code %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
HttpStatus | — |
Event ID 14 — Error occurred while sending the last response (corresponding to request ID %1) with status code %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
HttpStatus | — |
Event ID 15 — Error %3 occurred while sending (corresponding to request ID %1).
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Reason | — |
Status | — |
Event ID 16 — Response (request pointer %1, site ID %2, number of bytes %3) queued for sending from the cache.
Message
Fields
| Name | Description |
|---|---|
RequestObj | — |
SiteId | — |
BytesSent | — |
RequestId | — |
Encoding | — |
Event ID 17 — Response (request pointer %1, site ID %2, number of bytes %3) queued for sending with status code 304 (cache not modified).
Message
Fields
| Name | Description |
|---|---|
RequestObj | — |
SiteId | — |
BytesSent | — |
RequestId | — |
Encoding | — |
Event ID 18 — Attempted to reserve URL.
Message
Fields
| Name | Description |
|---|---|
Url | — |
ReserveStatus | — |
Event ID 19 — Successfully read the IP listen list for IP address %1.
Message
Fields
| Name | Description |
|---|---|
IpAddrLength | — |
IpAddress | — |
Event ID 20 — SSL credentials for IP address and port %3 successfully created.
Message
Fields
| Name | Description |
|---|---|
EndpointConfigObj | — |
Endpoint | — |
CertHashLength | — |
CertHash | — |
CertStoreName | — |
CertCheckMode | — |
RevokeFreshnessTime | — |
RevokeRetrievalTime | — |
Flags | — |
CtlId | — |
CtlStoreName | — |
CertificateLoadTime(ms) | — |
CertificateLoadTimems | — |
Event ID 21 — New connection created (local IP address %3 and remote address %5).
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
LocalAddrLength | — |
LocalAddr | — |
RemoteAddrLength | — |
RemoteAddr | — |
Event ID 22 — Connection ID (%2) assigned to connection and request (request ID %1) will be parsed.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ConnectionId | — |
ConnectionObj | — |
Event ID 23 — Client closed the connection (connection pointer %1).
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Abortive | — |
Event ID 24 — Connection (connection pointer %1) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange...
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Event ID 25 — Successfully added entry (URI %1) to cache.
Message
Fields
| Name | Description |
|---|---|
Uri | — |
StatusCode | — |
Verb | — |
HeaderLength | — |
ContentLength | — |
ExpirationTime | — |
Encoding | — |
Event ID 26 — Failed to add an entry (URI %1) to the cache.
Message
Fields
| Name | Description |
|---|---|
UrlBuffer | — |
ErrorStatus | — |
Encoding | — |
Event ID 27 — Flushed entry (URI %1) from the cache.
Message
Fields
| Name | Description |
|---|---|
Uri | — |
StatusCode | — |
Verb | — |
HeaderLength | — |
ContentLength | — |
ExpirationTime | — |
Event ID 28 — Attempted to set URL group property.
Message
Fields
| Name | Description |
|---|---|
Property | — |
Status | — |
Event ID 29 — Attempted to set server session property.
Message
Fields
| Name | Description |
|---|---|
Property | — |
Status | — |
Event ID 30 — Attempted to set request queue property.
Message
Fields
| Name | Description |
|---|---|
Property | — |
Status | — |
Event ID 31 — Attempted to add URL to URL group.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Url | — |
Status | — |
Event ID 32 — Removed URL from URL group.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Url | — |
Event ID 33 — Removed all URLs from URL group %1.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Event ID 34 — Initiating SSL connection.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Event ID 35 — Initiating SSL handshake.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Event ID 36 — SSL handshake completed with status.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ConnectionObj | — |
Event ID 37 — Server application is attempting to receive the SSL client certificate, which will be provided if available.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Event ID 38 — Attempt by server application to receive client certificate failed with status.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ConnectionObj | — |
Event ID 39 — Raw SSL data is available for processing.
Message
Fields
| Name | Description |
|---|---|
DataLength | — |
ConnectionObj | — |
Event ID 40 — Decrypted SSL data is available for processing.
Message
Fields
| Name | Description |
|---|---|
DataLength | — |
ConnectionObj | — |
Event ID 41 — Passed plaintext data for encryption.
Message
Fields
| Name | Description |
|---|---|
DataLength | — |
ConnectionObj | — |
Event ID 43 — Attempt (on connection ID %1) to authenticate client completed.
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
AuthType | — |
SecStatus | — |
AuthStatus | — |
ContextAttributes | — |
Event ID 44 — Attempted to add entry to the %2 authentication cache.
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
AuthCacheType | — |
AccessTokenOrHandle | — |
Status | — |
Event ID 45 — Entry successfully removed from the authentication cache.
Message
Fields
| Name | Description |
|---|---|
AccessTokenOrHandle | — |
Status | — |
Event ID 46 — Successfully associated QoS flow with connection (connection ID %1).
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
Bandwidth | — |
Status | — |
Event ID 47 — Failed to configure the %2 logging (directory %4), Status: %1.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Type | — |
Group | — |
Directory | — |
Software | — |
SiteId | — |
Event ID 48 — Successfully configured %2 logging (directory %5).
Message
Fields
| Name | Description |
|---|---|
Present | — |
Type | — |
Group | — |
Format | — |
Directory | — |
Software | — |
SiteId | — |
Event ID 49 — Failed to create %2 log file %5.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Type | — |
Group | — |
Format | — |
Filename | — |
SiteId | — |
Event ID 50 — Successfully created new %2 log file %5.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
Type | — |
Group | — |
Format | — |
Filename | — |
SiteId | — |
Event ID 51 — Entry has been written to %3 log file.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Handle | — |
Type | — |
Group | — |
Format | — |
ResType | — |
SiteId | — |
Event ID 52 — Parsing of request (request ID %2) failed due to reason: %3.
Message
Fields
| Name | Description |
|---|---|
Status | — |
RequestId | — |
Reason | — |
ErrorCode | — |
HintLength | — |
HintData | — |
Event ID 53 — HTTP timer %3 expired.
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
ConnectionObj | — |
Timer | — |
Event ID 56 — Failed to acquire handle for SSL credentials.
Message
Fields
| Name | Description |
|---|---|
EndpointConfigObj | — |
SecStatus | — |
Detail | — |
Event ID 57 — SSL connection will be disconnected as initiated by the client.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Event ID 58 — SSL connection will be disconnected as initiated by the server application.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Status | — |
Event ID 59 — Attempt to decrypt SSL data failed.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Event ID 60 — Query for SSL connection parameters failed.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Detail | — |
Event ID 61 — Cannot find SSL endpoint for inbound connection for local IP address and port %3.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
AddressLength | — |
Address | — |
Event ID 62 — Attempt to perform SSL handshake failed.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Event ID 63 — Attempt to encrypt SSL data failed.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Event ID 64 — Request (request ID %1) rejected due to reason: %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Reason | — |
RequestQueueName | — |
Event ID 65 — Server application canceled the processing of its request (request ID %1).
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Reason | — |
RequestQueueName | — |
Event ID 66 — Http.
Message
Fields
| Name | Description |
|---|---|
NewProcNumber | — |
ReasonString | — |
Status | — |
Event ID 67 — Hot-add information: Current UxNumberOfProcessors: %1, comment: %2.
Message
Fields
| Name | Description |
|---|---|
Hotadd_information_Current_UxNumberOfProcessors | Hot-add information: Current UxNumberOfProcessors. |
comment | — |
NewProcNumber | — |
Comment | — |
Event ID 68 — Initialized QoS flow: FlowHandle %1, bandwidth %2, peak bandwidth %3, burst size %4.
Message
Fields
| Name | Description |
|---|---|
FlowHandle | — |
Bandwidth | — |
PeakBandwidth | — |
BurstSize | — |
Event ID 69 — Initialized QoS flow: FlowHandle %1, bandwidth %2, peak bandwidth %3, burst size %4.
Message
Fields
| Name | Description |
|---|---|
FlowHandle | — |
Bandwidth | — |
PeakBandwidth | — |
BurstSize | — |
Event ID 70 — QoS flow initialization failed: bandwidth %1, peak bandwidth %2, burst size %3, status %4.
Message
Fields
| Name | Description |
|---|---|
Bandwidth | — |
PeakBandwidth | — |
BurstSize | — |
Status | — |
Event ID 71 — Setting flow: Connection %1, FlowHandle %2.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
FlowHandle | — |
Event ID 72 — Assign to Configuration QoS Flow: FlowHandle %1.
Message
Fields
| Name | Description |
|---|---|
FlowHandle | — |
Event ID 73 — [re]Setting QoS Flow failed: Connection %1, FlowHandle %2, status %3.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
FlowHandle | — |
Status | — |
Event ID 74 — Response range processing done.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
ContentBytes | — |
NumberOfRanges | — |
Range1Start | — |
Range1End | — |
Range2Start | — |
Range2End | — |
Event ID 75 — Begin building slices.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
NumberOfSlices | — |
SliceIndex1 | — |
SliceIndex2 | — |
NumberOfRanges | — |
Range1Start | — |
Range1End | — |
Range2Start | — |
Range2End | — |
Event ID 76 — Send cached slices.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
CacheEntryPtr | — |
NumberOfSlices | — |
SliceIndex1 | — |
SliceIndex2 | — |
NumberOfRanges | — |
Range1Start | — |
Range1End | — |
Range2Start | — |
Range2End | — |
Event ID 77 — Cached slices match content.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
CacheEntryPtr | — |
NumberOfSlices | — |
SliceIndex1 | — |
SliceIndex2 | — |
NumberOfRanges | — |
Range1Start | — |
Range1End | — |
Range2Start | — |
Range2End | — |
Event ID 78 — Merge slices to cache.
Message
Fields
| Name | Description |
|---|---|
CacheEntryPtr | — |
NofSlicesToMerge | — |
NofSlicesInCache | — |
Event ID 79 — Sending range from flat cache entry.
Message
Fields
| Name | Description |
|---|---|
CacheEntryPtr | — |
Range1Start | — |
Range1End | — |
Event ID 80 — Channel bind ASC parameters: connection %1, buffers %2, flags %3.
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
NoBindBuffers | — |
SecFlags | — |
Event ID 81 — Service bind check done.
Message
Fields
| Name | Description |
|---|---|
ConnectionId | — |
SecContextL | — |
SecContextH | — |
SecStatus | — |
Target | — |
Event ID 82 — Captured channel bind config.
Message
Fields
| Name | Description |
|---|---|
Hardening | — |
Flags | — |
ServiceNameCount | — |
Event ID 83 — Channel bind response config overwrites %1.
Message
Fields
| Name | Description |
|---|---|
ReplaceConfigOf | — |
Event ID 84 — Policy-Based QoS: Connection %1, FlowHandle %2.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
FlowHandle | — |
Event ID 85 — Thread pool extension.
Message
Fields
| Name | Description |
|---|---|
Thread_pool_extension_Pool_type | Thread pool extension. Pool type. |
active_pools | — |
PoolType | — |
ActivePools | — |
Event ID 86 — Thread ready.
Message
Fields
| Name | Description |
|---|---|
Thread_ready_Pool_type | Thread ready. Pool type. |
active_pools | — |
thread_count | — |
PoolType | — |
ActivePools | — |
ThreadCount | — |
Event ID 87 — Thread pool trim.
Message
Fields
| Name | Description |
|---|---|
Thread_pool_trim_Pool_type | Thread pool trim. Pool type. |
active_pools | — |
PoolType | — |
ActivePools | — |
Event ID 88 — Thread gone.
Message
Fields
| Name | Description |
|---|---|
Thread_gone_Pool_type | Thread gone. Pool type. |
active_pools | — |
thread_count | — |
PoolType | — |
ActivePools | — |
ThreadCount | — |
Event ID 89 — SNI parsed for connection: %1 with status: %2.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
Status | — |
SniLength | — |
SniHost | — |
NormalizedHost | — |
Event ID 90 — Request %1 has initated opaque mode.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
Event ID 91 — Endpoint auto-generated for %2.
Message
Fields
| Name | Description |
|---|---|
EndpointConfigObj | — |
EndpointName | — |
Event ID 92 — Deleted auto-generated endpoint for %2.
Message
Fields
| Name | Description |
|---|---|
EndpointConfigObj | — |
EndpointName | — |
Event ID 93 — Inbound connection for IP: %3, SNI: %4.
Message
Fields
| Name | Description |
|---|---|
EndpointConfigObj | — |
IpAddrLength | — |
IpAddress | — |
SniHostname | — |
MatchingEndpointName | — |
AutoGeneratedEndpoint | — |
Event ID 94 — SSL connection with local IP address and port %2 rejected due to configuration policy.
Message
Fields
| Name | Description |
|---|---|
AddressLength | — |
Address | — |
Event ID 95 — Parsing of response (response ID %2) failed due to reason: %3.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ResponseId | — |
Reason | — |
ErrorCode | — |
HintLength | — |
HintData | — |
Event ID 96 — SSL handshake failed.
Message
Fields
| Name | Description |
|---|---|
SSL_handshake_failed_Local_IP | — |
Remote_IP | SSL handshake failed. Local IP. |
SNI | — |
Thumbprint | — |
Client_Initiated_Disconnect | — |
Abortive_Disconnect | — |
Connection_Status | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
SniHostname | — |
ThumbprintLength | — |
ClientDisconnect | — |
AbortiveDisconnect | — |
Status | — |
Event ID 97 — HTTP error response sent.
Message
Fields
| Name | Description |
|---|---|
HTTP_error_response_sent_Url | HTTP error response sent. Url. |
Verb | — |
Status_Code | — |
Cache_Send | — |
Request_Queue | — |
PID | — |
TID | — |
Image_Name | — |
Working_SetBytes | — |
Send_Status | — |
Thread_Count | — |
Reason_Phrase | — |
Error_Cause | — |
Verbosity | — |
Url | — |
StatusCode | — |
CacheSend | — |
RequestQueue | — |
ProcessId | — |
ThreadId | — |
ImageFileName | — |
WorkingSetSize | — |
SendStatus | — |
ThreadCount | — |
ReasonPhrase | — |
ErrorCause | — |
Event ID 98 — SSL renegotiate timed out.
Message
Fields
| Name | Description |
|---|---|
SSL_renegotiate_timed_out_Local_IP | — |
Remote_IP | SSL renegotiate timed out. Local IP. |
SNI | — |
Thumbprint | — |
Connection_Buffer_Full | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
SniHostname | — |
ThumbprintLength | — |
ConnectionBufferFull | — |
Event ID 99 — HTTP 11 Required.
Message
Fields
| Name | Description |
|---|---|
HTTP_11_Required_Verb | HTTP 11 Required. Verb. |
Fault_Code | — |
Verb | — |
FaultCode | — |
Event ID 100 — Version: %1 Counts: %2.
Message
Fields
| Name | Description |
|---|---|
Version | — |
Counts | — |
CountsLength | — |
Event ID 101 — Version: %1 Counts: %2.
Message
Fields
| Name | Description |
|---|---|
Version | — |
Counts | — |
CountsLength | — |
Event ID 105 — QUIC Connection.
Message
Fields
| Name | Description |
|---|---|
QUIC_Connection_QuicConnectionId | QUIC Connection. QuicConnectionId. |
Connection | — |
Local_IP | — |
Remote_IP | — |
SNI | — |
ErrorCode | — |
Status | — |
QuicConnectionId | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
SniLength | — |
SniHost | — |
ErrorLogCode | — |
Event ID 106 — QUIC Connection Callback.
Message
Fields
| Name | Description |
|---|---|
QUIC_Connection_Callback_Connection | QUIC Connection Callback. Connection. |
Event | — |
EventParam | — |
Connection | — |
Event ID 107 — QUIC Stream.
Message
Fields
| Name | Description |
|---|---|
QUIC_Stream_QuicStreamId | QUIC Stream. QuicStreamId. |
Connection | — |
Stream | — |
QuicStreamId | — |
Event ID 108 — QUIC Stream Callback.
Message
Fields
| Name | Description |
|---|---|
QUIC_Stream_Callback_Stream | QUIC Stream Callback. Stream. |
Connection | — |
StreamType | — |
Event | — |
EventParam | — |
Stream | — |
Event ID 109 — QUIC Registration Failed.
Message
Fields
| Name | Description |
|---|---|
QUIC_Registration_Failed_Status | QUIC Registration Failed. Status. |
Status | — |
Event ID 110 — Correlation ID for request %1: %2.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
CorrelationId | — |
Event ID 111 — Create URL group %1.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 112 — Attempted to reserve URL %1.
Message
Fields
| Name | Description |
|---|---|
Url | — |
ReserveStatus | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Example Event
system:
provider: Microsoft-Windows-HttpService
guid: DD5EF90A-6398-47A4-AD34-4DCECDEF795F
event_source_name: ''
event_id: 112
version: 0
level: 4
task: 3
opcode: 121
keywords: 4611686018427387905
time_created: '2023-11-06T06:25:42.192778+00:00'
event_record_id: 1703
correlation: {}
execution:
process_id: 4
thread_id: 228
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
Url: http://+:10243/WMPNSSv4/
ReserveStatus: 0
ProcessId: 4
ExecutablePath: ''
UserSid: S-1-5-18
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 113 — Attempted to add URL to URL group.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Url | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 114 — Removed URL from URL group.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Url | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Example Event
system:
provider: Microsoft-Windows-HttpService
guid: DD5EF90A-6398-47A4-AD34-4DCECDEF795F
event_source_name: ''
event_id: 114
version: 0
level: 4
task: 5
opcode: 123
keywords: 4611686018427387968
time_created: '2023-10-25T22:56:15.387118+00:00'
event_record_id: 1477
correlation: {}
execution:
process_id: 3840
thread_id: 3904
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
UrlGroupId: 18302628886170566657
Url: http://*:5357/31383106-803d-411b-9763-a28cdc0f0c3f/
ProcessId: 3840
ExecutablePath: \Device\HarddiskVolume4\Windows\System32\svchost.exe
UserSid: S-1-5-19
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 115 — Removed all URLs from URL group %1.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 116 — Attempted to set URL group %1 property %2.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Property | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 117 — Delete URL group %1.
Message
Fields
| Name | Description |
|---|---|
UrlGroupId | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Example Event
system:
provider: Microsoft-Windows-HttpService
guid: DD5EF90A-6398-47A4-AD34-4DCECDEF795F
event_source_name: ''
event_id: 117
version: 0
level: 4
task: 5
opcode: 126
keywords: 4611686018427387968
time_created: '2023-10-25T22:56:15.387403+00:00'
event_record_id: 1478
correlation: {}
execution:
process_id: 3840
thread_id: 3904
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
UrlGroupId: 18302628886170566657
Status: 0
ProcessId: 3840
ExecutablePath: \Device\HarddiskVolume4\Windows\System32\svchost.exe
UserSid: S-1-5-19
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 118 — Status %1.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 119 — SSL Certificate Settings deleted for endpoint.
Message
Fields
| Name | Description |
|---|---|
Endpoint | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 120 — SSL Certificate Settings created by an admin process for endpoint.
Message
Fields
| Name | Description |
|---|---|
Endpoint | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 121 — SSL Certificate Settings updated by an admin process for endpoint : %1, Extended Param Type %2.
Message
Fields
| Name | Description |
|---|---|
Endpoint | — |
ExtendedParamType | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 122 — Set the IP address to the listen only list %1.
Message
Fields
| Name | Description |
|---|---|
IpList | — |
Status | — |
ProcessId | — |
ExecutablePath | — |
UserSid | — |
Event ID 123 — QUIC certificate load failed with status %1 and was ignored due to disabled TLS 1.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Tls13Status | — |
Event ID 124 — Request (request ID %1) rejected due to request queue overflow.
Message
Fields
| Name | Description |
|---|---|
RequestId | — |
RequestQueueName | — |
LastPendingReceiveRequest | — |
LastSucceededReceiveRequest | — |
LastFailedReceiveRequest | — |
Event ID 125 — Connection %1, Connection Id %2: Stream Created, StreamId %3.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
Event ID 126 — Connection %1, Connection Id %2: Stream Aborted, StreamId %3, HRESULT error %4, Reset Code %5.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
Error | — |
ResetCode | — |
Event ID 127 — Connection %1, Connection Id %2: Send StreamId %3, Length %4.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
Length | — |
Event ID 128 — Connection %1, Connection Id %2: Data Indincation, StreamId %3, BytesIndicated %4, BytesAccepted %5, Status %6.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
BytesIndicated | — |
BytesAccepted | — |
Status | — |
Event ID 129 — Connection %1, Connection Id %2: Header Indincation, StreamId %3, Headers indicated %4, Status %5.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
Headers | — |
Status | — |
Event ID 130 — Connection %1, Connection Id %2: Go Away, StreamId %3, ErrorCode %4, FaultCode %5.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
ErrorCode | — |
FaultCode | — |
Event ID 131 — Http2 fault.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
StreamId | — |
FaultCode | — |
Status | — |
Event ID 132 — Connection %1, Connection Id %2: Create.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
Event ID 133 — Connection %1, Connection Id %2: Detach.
Message
Fields
| Name | Description |
|---|---|
Connection | — |
ConnectionId | — |
Event ID 134 —
Fields
| Name | Description |
|---|---|
RequestId | — |
ReceiveStart | — |
ReceiveHeadersEnd | — |
ResponseStart | — |
ResponseEnd | — |
BufferedSend | — |
Event ID 135 —
Fields
| Name | Description |
|---|---|
PerfCounterPeriod | — |
Event ID 136 —
Fields
| Name | Description |
|---|---|
RequestId | — |
StatsType | — |
StatsLength | — |
StatsData | — |
Event ID 137 —
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Detail | — |
Event ID 137 — Query for SSL connection cipher info failed.
Message
Fields
| Name | Description |
|---|---|
ConnectionObj | — |
SecStatus | — |
Detail | — |