Microsoft-Windows-HttpService
132 events across 3 channels
Event ID 1 — Request received (request ID RequestId) on connection (connection ID ConnectionId) from remote address RemoteAddr.
Event ID 2 — Parsed request (request pointer RequestObj, method HttpVerb) with URI Url.
Event ID 3 — Delivered request to server application (request pointer RequestObj, request ID RequestId, site ID SiteId) from request queue RequestQueueName for URI Url with status Status.
Description
Delivered request to server application (request pointer RequestObj, request ID RequestId, site ID SiteId) from request queue RequestQueueName for URI Url with status Status.
Message #
Fields #
| Name | Description |
|---|---|
RequestObj Pointer | — |
RequestId UInt64 | — |
SiteId UInt32 | — |
RequestQueueName UnicodeString | — |
Url UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 4 — Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) wi...
Description
Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) with status code StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
ConnectionId UInt64 | — |
StatusCode UInt16 | — |
Verb AnsiString | — |
HeaderLength UInt32 | — |
EntityChunkCount UInt16 | — |
CachePolicy UInt32 | — |
Event ID 5 — Server application passed the last response (corresponding to request ID RequestId).
Event ID 6 — Server application passed entity body for request ID RequestId (connection ID ConnectionId).
Event ID 7 — Server application passed the last entity body for request ID RequestId.
Event ID 8 — Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) wi...
Description
Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) with status code StatusCode.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
ConnectionId UInt64 | — |
StatusCode UInt16 | — |
Verb AnsiString | — |
HeaderLength UInt32 | — |
EntityChunkCount UInt16 | — |
CachePolicy UInt32 | — |
Event ID 9 — Server application passed the last response (corresponding to request ID RequestId).
Event ID 10 — Response ready for send (corresponding to request ID RequestId) with status code HttpStatus.
Event ID 11 — Cached the response (corresponding to request ID RequestId) with status code HttpStatus.
Event ID 12 — Queued last response (corresponding to request ID RequestId) for sending.
Event ID 13 — Response sent (corresponding to request ID RequestId) with status code HttpStatus.
Event ID 14 — Error occurred while sending the last response (corresponding to request ID RequestId) with status code HttpStatus.
Event ID 15 — Error Status occurred while sending (corresponding to request ID RequestId).
Description
Error Status occurred while sending (corresponding to request ID RequestId). A TCP Reset will be sent.
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
Reason AnsiString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 16 — Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) queued for sending from the cache.
Event ID 17 — Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) queued for sending with status code 304 (cache not modified).
Event ID 18 — Attempted to reserve URL (Url).
Event ID 19 — Successfully read the IP listen list for IP address IpAddrLength.
Event ID 20 — SSL credentials for IP address and port CertHashLength successfully created.
Description
SSL credentials for IP address and port CertHashLength successfully created.
Message #
Fields #
| Name | Description |
|---|---|
EndpointConfigObj Pointer | — |
Endpoint UnicodeString | — |
CertHashLength UInt32 | — |
CertHash Binary | — |
CertStoreName UnicodeString | — |
CertCheckMode UInt32 | — |
RevokeFreshnessTime UInt32 | — |
RevokeRetrievalTime UInt32 | — |
Flags UInt32 | — |
CtlId UnicodeString | — |
CtlStoreName UnicodeString | — |
CertificateLoadTime(ms) UInt32 | — |
CertificateLoadTimems UInt32 | — |
Event ID 21 — New connection created (local IP address LocalAddr and remote address RemoteAddr).
Event ID 22 — Connection ID (ConnectionId) assigned to connection and request (request ID RequestId) will be parsed.
Event ID 23 — Client closed the connection (connection pointer ConnectionObj).
Event ID 24 — Connection (connection pointer ConnectionObj) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange...
Event ID 25 — Successfully added entry (URI Uri) to cache.
Event ID 26 — Failed to add an entry (URI UrlBuffer) to the cache.
Event ID 27 — Flushed entry (URI Uri) from the cache.
Event ID 28 — Attempted to set URL group property: Property.
Description
Attempted to set URL group property: Property. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Property UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 29 — Attempted to set server session property: Property.
Description
Attempted to set server session property: Property. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Property UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 30 — Attempted to set request queue property: Property.
Description
Attempted to set request queue property: Property. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Property UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 31 — Attempted to add URL (Url) to URL group (UrlGroupId).
Description
Attempted to add URL (Url) to URL group (UrlGroupId). Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Url UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 32 — Removed URL (Url) from URL group (UrlGroupId).
Event ID 33 — Removed all URLs from URL group UrlGroupId.
Event ID 34 — Initiating SSL connection.
Event ID 35 — Initiating SSL handshake.
Event ID 36 — SSL handshake completed with status: Status.
Description
SSL handshake completed with status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
ConnectionObj Pointer | — |
Event ID 37 — Server application is attempting to receive the SSL client certificate, which will be provided if available.
Event ID 38 — Attempt by server application to receive client certificate failed with status: Status.
Description
Attempt by server application to receive client certificate failed with status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
ConnectionObj Pointer | — |
Event ID 39 — Raw SSL data is available for processing.
Event ID 40 — Decrypted SSL data is available for processing.
Event ID 41 — Passed plaintext data for encryption.
Event ID 43 — Attempt (on connection ID ConnectionId) to authenticate client completed.
Event ID 44 — Attempted to add entry to the AuthCacheType authentication cache.
Description
Attempted to add entry to the AuthCacheType authentication cache. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionId UInt64 | — |
AuthCacheType AnsiString | — |
AccessTokenOrHandle Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 45 — Entry successfully removed from the authentication cache.
Description
Entry successfully removed from the authentication cache.
Message #
Fields #
| Name | Description |
|---|---|
AccessTokenOrHandle Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 46 — Successfully associated QoS flow with connection (connection ID ConnectionId).
Description
Successfully associated QoS flow with connection (connection ID ConnectionId). Bandwidth throttled to: Bandwidth Bytes per second.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionId UInt64 | — |
Bandwidth UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 47 — Failed to configure the Type logging (directory Directory), Status: Status.
Description
Failed to configure the Type logging (directory Directory), Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Type UInt32 | — |
Group UInt32 | — |
Directory UnicodeString | — |
Software UnicodeString | — |
SiteId UInt32 | — |
Event ID 48 — Successfully configured Type logging (directory Directory).
Event ID 49 — Failed to create Type log file Filename.
Description
Failed to create Type log file Filename. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Type UInt32 | — |
Group UInt32 | — |
Format UInt32 | — |
Filename UnicodeString | — |
SiteId UInt32 | — |
Event ID 50 — Successfully created new Type log file Filename.
Event ID 51 — Entry has been written to Type log file.
Description
Entry has been written to Type log file.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Handle Pointer | — |
Type UInt32 | — |
Group UInt32 | — |
Format UInt32 | — |
ResType AnsiString | — |
SiteId UInt32 | — |
Event ID 52 — Parsing of request (request ID RequestId) failed due to reason: Reason.
Description
Parsing of request (request ID RequestId) failed due to reason: Reason. Request may not be compliant with HTTP/1.1.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
RequestId UInt64 | — |
Reason AnsiString | — |
ErrorCode UInt32 | — |
HintLength UInt32 | — |
HintData Binary | — |
Event ID 53 — HTTP timer Timer expired.
Event ID 56 — Failed to acquire handle for SSL credentials.
Event ID 57 — SSL connection will be disconnected as initiated by the client.
Event ID 58 — SSL connection will be disconnected as initiated by the server application.
Description
SSL connection will be disconnected as initiated by the server application. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionObj Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 59 — Attempt to decrypt SSL data failed.
Event ID 60 — Query for SSL connection parameters failed.
Event ID 61 — Cannot find SSL endpoint for inbound connection for local IP address and port Address.
Event ID 62 — Attempt to perform SSL handshake failed.
Event ID 63 — Attempt to encrypt SSL data failed.
Event ID 64 — Request (request ID RequestId) rejected due to reason: Reason.
Event ID 65 — Server application canceled the processing of its request (request ID RequestId).
Event ID 66 — Http.
Description
Http.sys failed to process CPU hot-add. Processor number: NewProcNumber, reason: ReasonString, status: Status.
Message #
Fields #
| Name | Description |
|---|---|
NewProcNumber UInt8 | — |
ReasonString AnsiString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 67 — Hot-add information: Current UxNumberOfProcessors: Hotadd_information_Current_UxNumberOfProcessors, comment: comment.
Description
Hot-add information: Current UxNumberOfProcessors: Hotadd_information_Current_UxNumberOfProcessors, comment: comment.
Message #
Fields #
| Name | Description |
|---|---|
Hotadd_information_Current_UxNumberOfProcessors UInt8 | Hot-add information: Current UxNumberOfProcessors. |
comment AnsiString | — |
NewProcNumber UInt8 | — |
Comment AnsiString | — |
Event ID 68 — Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize.
Event ID 69 — Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize.
Event ID 70 — QoS flow initialization failed: bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize, status Status.
Description
QoS flow initialization failed: bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize, status Status.
Message #
Fields #
| Name | Description |
|---|---|
Bandwidth UInt32 | — |
PeakBandwidth UInt32 | — |
BurstSize UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 71 — Setting flow: Connection Connection, FlowHandle FlowHandle.
Event ID 72 — Assign to Configuration QoS Flow: FlowHandle FlowHandle.
Event ID 73 — [re]Setting QoS Flow failed: Connection Connection, FlowHandle FlowHandle, status Status.
Description
[re]Setting QoS Flow failed: Connection Connection, FlowHandle FlowHandle, status Status.
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | — |
FlowHandle Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 74 — Response range processing done.
Description
Response range processing done. Req. RequestId, response content size ContentBytes, ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
ContentBytes UInt64 | — |
NumberOfRanges UInt32 | — |
Range1Start UInt64 | — |
Range1End UInt64 | — |
Range2Start UInt64 | — |
Range2End UInt64 | — |
Event ID 75 — Begin building slices.
Description
Begin building slices. Req. RequestId, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
NumberOfSlices UInt32 | — |
SliceIndex1 UInt32 | — |
SliceIndex2 UInt32 | — |
NumberOfRanges UInt32 | — |
Range1Start UInt64 | — |
Range1End UInt64 | — |
Range2Start UInt64 | — |
Range2End UInt64 | — |
Event ID 76 — Send cached slices.
Description
Send cached slices. Req. RequestId, CacheEntry CacheEntryPtr, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
CacheEntryPtr Pointer | — |
NumberOfSlices UInt32 | — |
SliceIndex1 UInt32 | — |
SliceIndex2 UInt32 | — |
NumberOfRanges UInt32 | — |
Range1Start UInt64 | — |
Range1End UInt64 | — |
Range2Start UInt64 | — |
Range2End UInt64 | — |
Event ID 77 — Cached slices match content.
Description
Cached slices match content. Req. RequestId, CacheEntry CacheEntryPtr, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).
Message #
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
CacheEntryPtr Pointer | — |
NumberOfSlices UInt32 | — |
SliceIndex1 UInt32 | — |
SliceIndex2 UInt32 | — |
NumberOfRanges UInt32 | — |
Range1Start UInt64 | — |
Range1End UInt64 | — |
Range2Start UInt64 | — |
Range2End UInt64 | — |
Event ID 78 — Merge slices to cache.
Event ID 79 — Sending range from flat cache entry.
Event ID 80 — Channel bind ASC parameters: connection ConnectionId, buffers NoBindBuffers, flags SecFlags.
Event ID 81 — Service bind check done.
Event ID 82 — Captured channel bind config.
Event ID 83 — Channel bind response config overwrites ReplaceConfigOf.
Event ID 84 — Policy-Based QoS: Connection Connection, FlowHandle FlowHandle.
Event ID 85 — Thread pool extension.
Event ID 86 — Thread ready.
Description
Thread ready. Pool type: Thread_ready_Pool_type, active pools: active_pools, thread count: thread_count.
Message #
Fields #
| Name | Description |
|---|---|
Thread_ready_Pool_type AnsiString | Thread ready. Pool type. |
active_pools UInt16 | — |
thread_count UInt8 | — |
PoolType AnsiString | — |
ActivePools UInt16 | — |
ThreadCount UInt8 | — |
Event ID 87 — Thread pool trim.
Event ID 88 — Thread gone.
Event ID 89 — SNI parsed for connection: ConnectionObj with status: Status.
Description
SNI parsed for connection: ConnectionObj with status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ConnectionObj Pointer | — |
Status UInt32 | — NTSTATUS reference |
SniLength UInt32 | — |
SniHost Binary | — |
NormalizedHost UnicodeString | — |
Event ID 90 — Request RequestId has initated opaque mode.
Event ID 91 — Endpoint auto-generated for EndpointName.
Event ID 92 — Deleted auto-generated endpoint for EndpointName.
Event ID 93 — Inbound connection for IP: IpAddress, SNI: SniHostname.
Event ID 94 — SSL connection with local IP address and port Address rejected due to configuration policy.
Event ID 95 — Parsing of response (response ID ResponseId) failed due to reason: Reason.
Description
Parsing of response (response ID ResponseId) failed due to reason: Reason. Request may not be compliant with HTTP/1.1.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
ResponseId UInt64 | — |
Reason AnsiString | — |
ErrorCode UInt32 | — |
HintLength UInt32 | — |
HintData Binary | — |
Event ID 96 — SSL handshake failed.
Description
SSL handshake failed. Local IP: Remote_IP, Remote IP: Thumbprint, SNI: Client_Initiated_Disconnect, Thumbprint: Connection_Status, Client Initiated Disconnect: LocalAddressLength, Abortive Disconnect: LocalAddress, Connection Status: RemoteAddressLength.
Message #
Fields #
| Name | Description |
|---|---|
SSL_handshake_failed_Local_IP | — |
Remote_IP | SSL handshake failed. Local IP. |
SNI | — |
Thumbprint Binary | — |
Client_Initiated_Disconnect | — |
Abortive_Disconnect | — |
Connection_Status | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
SniHostname UnicodeString | — |
ThumbprintLength UInt16 | — |
ClientDisconnect Boolean | — |
AbortiveDisconnect Boolean | — |
Status UInt32 | — NTSTATUS reference |
Event ID 97 — HTTP error response sent.
Message #
Fields #
| Name | Description |
|---|---|
HTTP_error_response_sent_Url UnicodeString | HTTP error response sent. Url. |
Verb UInt32 | — |
Status_Code UInt16 | — |
Cache_Send Boolean | — |
Request_Queue UnicodeString | — |
PID UInt32 | — |
TID UInt32 | — |
Image_Name AnsiString | — |
Working_SetBytes UInt64 | — |
Send_Status UInt32 | — |
Thread_Count UInt32 | — |
Reason_Phrase AnsiString | — |
Error_Cause AnsiString | — |
Verbosity UInt32 | — |
Url UnicodeString | — |
StatusCode UInt16 | — |
CacheSend Boolean | — |
RequestQueue UnicodeString | — |
ProcessId UInt32 | — |
ThreadId UInt32 | — |
ImageFileName AnsiString | — |
WorkingSetSize UInt64 | — |
SendStatus UInt32 | — |
ThreadCount UInt32 | — |
ReasonPhrase AnsiString | — |
ErrorCause AnsiString | — |
Event ID 98 — SSL renegotiate timed out.
Description
SSL renegotiate timed out. Local IP: Remote_IP, Remote IP: Thumbprint, SNI: Connection_Buffer_Full, Thumbprint: LocalAddress, Connection Buffer Full: RemoteAddressLength.
Message #
Fields #
| Name | Description |
|---|---|
SSL_renegotiate_timed_out_Local_IP | — |
Remote_IP | SSL renegotiate timed out. Local IP. |
SNI | — |
Thumbprint Binary | — |
Connection_Buffer_Full | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
SniHostname UnicodeString | — |
ThumbprintLength UInt16 | — |
ConnectionBufferFull Boolean | — |
Event ID 99 — HTTP 11 Required.
Event ID 100 — Version: Version Counts: Counts.
Event ID 101 — Version: Version Counts: Counts.
Event ID 105 — QUIC Connection.
Description
QUIC Connection. QuicConnectionId: QUIC_Connection_QuicConnectionId, Connection: Connection, Local IP: Remote_IP, Remote IP: ErrorCode, SNI: QuicConnectionId, ErrorCode: LocalAddressLength, Status: LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
QUIC_Connection_QuicConnectionId | QUIC Connection. QuicConnectionId. |
Connection Pointer | — |
Local_IP | — |
Remote_IP | — |
SNI | — |
ErrorCode | — |
Status UInt32 | — NTSTATUS reference |
QuicConnectionId UInt64 | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
SniLength UInt32 | — |
SniHost Binary | — |
ErrorLogCode UInt32 | — |
Event ID 106 — QUIC Connection Callback.
Event ID 107 — QUIC Stream.
Event ID 108 — QUIC Stream Callback.
Description
QUIC Stream Callback. Stream: QUIC_Stream_Callback_Stream, Connection: Connection, StreamType: StreamType, Event: Event, EventParam: EventParam.
Message #
Fields #
| Name | Description |
|---|---|
QUIC_Stream_Callback_Stream Pointer | QUIC Stream Callback. Stream. |
Connection Pointer | — |
StreamType AnsiString | — |
Event UInt8 | — |
EventParam UInt64 | — |
Stream Pointer | — |
Event ID 109 — QUIC Registration Failed.
Description
QUIC Registration Failed. Status: QUIC_Registration_Failed_Status.
Message #
Fields #
| Name | Description |
|---|---|
QUIC_Registration_Failed_Status UInt32 | QUIC Registration Failed. Status. |
Status UInt32 | — NTSTATUS reference |
Event ID 110 — Correlation ID for request RequestId: CorrelationId.
Event ID 111 — Create URL group UrlGroupId.
Description
Create URL group UrlGroupId. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 4,
"task": 5,
"opcode": 125,
"keywords": 4611686018427387968,
"time_created": "2026-03-13T20:06:22.592017+00:00",
"event_record_id": 2069,
"correlation": {},
"execution": {
"process_id": 4260,
"thread_id": 4596
},
"channel": "System",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"UrlGroupId": 18302628890465533953,
"Status": 0,
"ProcessId": 4260,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-18"
},
"message": ""
}
Event ID 112 — Attempted to reserve URL Url.
#Description
Attempted to reserve URL Url. Status ReserveStatus. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
Url UnicodeString | — |
ReserveStatus UInt32 | — |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 112,
"version": 0,
"level": 4,
"task": 3,
"opcode": 121,
"keywords": 4611686018427387905,
"time_created": "2023-11-06T06:25:42.192778+00:00",
"event_record_id": 1703,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 228
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Url": "http://+:10243/WMPNSSv4/",
"ReserveStatus": 0,
"ProcessId": 4,
"ExecutablePath": "",
"UserSid": "S-1-5-18"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 113 — Attempted to add URL (Url) to URL group (UrlGroupId).
Description
Attempted to add URL (Url) to URL group (UrlGroupId). Status: Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Url UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 113,
"version": 0,
"level": 4,
"task": 5,
"opcode": 122,
"keywords": 4611686018427387968,
"time_created": "2026-03-11T06:29:35.510270+00:00",
"event_record_id": 2802,
"correlation": {},
"execution": {
"process_id": 1608,
"thread_id": 1656
},
"channel": "System",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"UrlGroupId": 18302628907645403137,
"Url": "https://+:5986/wsman/",
"Status": 0,
"ProcessId": 1608,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-20"
},
"message": ""
}
Event ID 114 — Removed URL (Url) from URL group (UrlGroupId).
#Description
Removed URL (Url) from URL group (UrlGroupId). Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Url UnicodeString | — |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 114,
"version": 0,
"level": 4,
"task": 5,
"opcode": 123,
"keywords": 4611686018427387968,
"time_created": "2023-10-25T22:56:15.387118+00:00",
"event_record_id": 1477,
"correlation": {},
"execution": {
"process_id": 3840,
"thread_id": 3904
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"UrlGroupId": 18302628886170566657,
"Url": "http://*:5357/31383106-803d-411b-9763-a28cdc0f0c3f/",
"ProcessId": 3840,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-19"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 115 — Removed all URLs from URL group UrlGroupId.
Event ID 116 — Attempted to set URL group UrlGroupId property Property.
Description
Attempted to set URL group UrlGroupId property Property. Status: Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Property UInt32 | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Event ID 117 — Delete URL group UrlGroupId.
#Description
Delete URL group UrlGroupId. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
UrlGroupId UInt64 | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 117,
"version": 0,
"level": 4,
"task": 5,
"opcode": 126,
"keywords": 4611686018427387968,
"time_created": "2023-10-25T22:56:15.387403+00:00",
"event_record_id": 1478,
"correlation": {},
"execution": {
"process_id": 3840,
"thread_id": 3904
},
"channel": "System",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"UrlGroupId": 18302628886170566657,
"Status": 0,
"ProcessId": 3840,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-19"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 118 — Status Status.
Description
Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Event ID 119 — SSL Certificate Settings deleted for endpoint : Endpoint.
Description
SSL Certificate Settings deleted for endpoint : Endpoint. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 119,
"version": 0,
"level": 4,
"task": 7,
"opcode": 129,
"keywords": 4611686018427388416,
"time_created": "2025-12-31T19:35:47.939697+00:00",
"event_record_id": 419,
"correlation": {},
"execution": {
"process_id": 7104,
"thread_id": 5100
},
"channel": "System",
"computer": "WIN11-22H2-X64",
"security": {
"user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
}
},
"event_data": {
"Endpoint": "NULL",
"Status": 3221225524,
"ProcessId": 7104,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-21-3407486967-1585450050-1838039599-1000"
},
"message": ""
}
Event ID 120 — SSL Certificate Settings created by an admin process for endpoint : Endpoint.
Description
SSL Certificate Settings created by an admin process for endpoint : Endpoint. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-HttpService",
"guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
"event_source_name": "",
"event_id": 120,
"version": 0,
"level": 4,
"task": 7,
"opcode": 130,
"keywords": 4611686018427388416,
"time_created": "2025-12-31T19:35:47.964183+00:00",
"event_record_id": 420,
"correlation": {},
"execution": {
"process_id": 7104,
"thread_id": 5100
},
"channel": "System",
"computer": "WIN11-22H2-X64",
"security": {
"user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
}
},
"event_data": {
"Endpoint": "0.0.0.0:5986",
"Status": 0,
"ProcessId": 7104,
"ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
"UserSid": "S-1-5-21-3407486967-1585450050-1838039599-1000"
},
"message": ""
}
Event ID 121 — SSL Certificate Settings updated by an admin process for endpoint : Endpoint, Extended Param Type ExtendedParamType.
Description
SSL Certificate Settings updated by an admin process for endpoint : Endpoint, Extended Param Type ExtendedParamType. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint UnicodeString | — |
ExtendedParamType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Event ID 122 — Set the IP address to the listen only list IpList.
Description
Set the IP address to the listen only list IpList. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.
Message #
Fields #
| Name | Description |
|---|---|
IpList UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt64 | — |
ExecutablePath UnicodeString | — |
UserSid SID | — |
Event ID 123 — QUIC certificate load failed with status Status and was ignored due to disabled TLS 1.
Description
QUIC certificate load failed with status Status and was ignored due to disabled TLS 1.3 (status Tls13Status).
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Tls13Status UInt32 | — |
Event ID 124 — Request (request ID RequestId) rejected due to request queue overflow.
Event ID 125 — Connection Connection, Connection Id ConnectionId: Stream Created, StreamId StreamId.
Event ID 126 — Connection Connection, Connection Id ConnectionId: Stream Aborted, StreamId StreamId, HRESULT error Error, Reset Code ResetCode.
Event ID 127 — Connection Connection, Connection Id ConnectionId: Send StreamId StreamId, Length Length.
Event ID 128 — Connection Connection, Connection Id ConnectionId: Data Indincation, StreamId StreamId, BytesIndicated BytesIndicated, BytesAccepted BytesAccepted, Status Status.
Description
Connection Connection, Connection Id ConnectionId: Data Indincation, StreamId StreamId, BytesIndicated BytesIndicated, BytesAccepted BytesAccepted, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | — |
ConnectionId UInt64 | — |
StreamId UInt32 | — |
BytesIndicated UInt32 | — |
BytesAccepted UInt32 | — |
Status Int32 | — NTSTATUS reference |
Event ID 129 — Connection Connection, Connection Id ConnectionId: Header Indincation, StreamId StreamId, Headers indicated Headers, Status Status.
Description
Connection Connection, Connection Id ConnectionId: Header Indincation, StreamId StreamId, Headers indicated Headers, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | — |
ConnectionId UInt64 | — |
StreamId UInt32 | — |
Headers UInt32 | — |
Status Int32 | — NTSTATUS reference |
Event ID 130 — Connection Connection, Connection Id ConnectionId: Go Away, StreamId StreamId, ErrorCode ErrorCode, FaultCode FaultCode.
Event ID 131 — Http2 fault.
Description
Http2 fault. Connection Connection, Connection Id ConnectionId:, StreamId StreamId, Code FaultCode, Status Status.
Message #
Fields #
| Name | Description |
|---|---|
Connection Pointer | — |
ConnectionId UInt64 | — |
StreamId UInt32 | — |
FaultCode UInt32 | — |
Status Int32 | — NTSTATUS reference |
Event ID 132 — Connection Connection, Connection Id ConnectionId: Create.
Event ID 133 — Connection Connection, Connection Id ConnectionId: Detach.
Event ID 134 —
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
ReceiveStart UInt64 | — |
ReceiveHeadersEnd UInt64 | — |
ResponseStart UInt64 | — |
ResponseEnd UInt64 | — |
BufferedSend Boolean | — |
Event ID 135 —
Fields #
| Name | Description |
|---|---|
PerfCounterPeriod UInt64 | — |
Event ID 136 —
Fields #
| Name | Description |
|---|---|
RequestId UInt64 | — |
StatsType UInt32 | — |
StatsLength UInt32 | — |
StatsData Binary | — |
Event ID 137 —
Description
Query for SSL connection cipher info failed. Security status: . Connection will be reset.
Fields #
| Name | Description |
|---|---|
ConnectionObj Pointer | — |
SecStatus UInt32 | — |
Detail AnsiString | — |