Microsoft-Windows-IIS-Configuration
104 events across 5 channels
Event ID 3 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigCacheAddress | — |
ConfigPath | — |
FileChangeNotificationMonitorAddress | — |
ConfigFileAddress | — |
PhysicalPath | — |
Event ID 3 — A cache node for '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigCacheAddress | — |
ConfigPath | — |
FileChangeNotificationMonitorAddress | — |
ConfigFileAddress | — |
PhysicalPath | — |
Event ID 7 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 7 — Configuration cache is handling change notification for '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 8 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 8 — Configuration cache is polling for changes at '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 9 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 9 — Configuration cache is discarding all config files whose configuration path is equal to or a subpath of '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 10 —
Fields
| Name | Description |
|---|---|
HRESULT | — |
PhysicalPath | — |
Type | — |
Message | — |
LineNumber | — |
PreviousLine | — |
ErrorLine | — |
NextLine | — |
Event ID 10 — An error has occurred.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
PhysicalPath | — |
Type | — |
Message | — |
LineNumber | — |
PreviousLine | — |
ErrorLine | — |
NextLine | — |
Event ID 12 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
EffectiveLocationPath | — |
SectionPath | — |
Event ID 12 — Unable to find schema for config section '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
EffectiveLocationPath | — |
SectionPath | — |
Event ID 13 —
Fields
| Name | Description |
|---|---|
ConfigFileObjectAddress | — |
PhysicalPath | — |
ConfigPath | — |
CryptoImpersonationToken | — |
FileImpersonationToken | — |
LastModifiedTime | — |
FileSize | — |
Event ID 13 — Parsing config file '.
Message
Fields
| Name | Description |
|---|---|
ConfigFileObjectAddress | — |
PhysicalPath | — |
ConfigPath | — |
CryptoImpersonationToken | — |
FileImpersonationToken | — |
LastModifiedTime | — |
FileSize | — |
Event ID 14 —
Fields
| Name | Description |
|---|---|
RedirectionPath | — |
Username | — |
Password | — |
Event ID 14 — MACHINE/WEBROOT/APPHOST configuration redirection has been enabled.
Message
Fields
| Name | Description |
|---|---|
RedirectionPath | — |
Username | — |
Password | — |
Event ID 15 —
Fields
| Name | Description |
|---|---|
CallSite | — |
lpFileName | — |
dwDesiredAccess | — |
dwShareMode | — |
dwCreationDisposition | — |
dwFlagsAndAttributes | — |
IsTransacted | — |
Handle | — |
GetLastError | — |
Event ID 15 — Attempting to open file or directory '.
Message
Fields
| Name | Description |
|---|---|
CallSite | — |
lpFileName | — |
dwDesiredAccess | — |
dwShareMode | — |
dwCreationDisposition | — |
dwFlagsAndAttributes | — |
IsTransacted | — |
Handle | — |
GetLastError | — |
Event ID 16 —
Fields
| Name | Description |
|---|---|
Domain | — |
User | — |
Password | — |
TokenHandle | — |
Event ID 16 — An impersonation token with handle '.
Message
Fields
| Name | Description |
|---|---|
Domain | — |
User | — |
Password | — |
TokenHandle | — |
Event ID 17 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 17 — File change notification monitor that watches for changes in '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 18 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 18 — File change notification monitor that watches for changes in '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 19 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 19 — File change notification monitor that watches for changes in '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 20 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 20 — File change notification monitor that watches for changes in '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 21 —
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 21 — File change notification monitor that watches for changes in '.
Message
Fields
| Name | Description |
|---|---|
Address | — |
ConfigPath | — |
Directory | — |
File | — |
WatchSubPaths | — |
IsPollingMonitor | — |
IsSchemaFileMonitor | — |
Event ID 23 —
Fields
| Name | Description |
|---|---|
TargetAddress | — |
TargetType | — |
ConfigPath | — |
IsGranular | — |
IsApplicationSpecific | — |
IsLocationTag | — |
Event ID 23 — A change listener of type '.
Message
Fields
| Name | Description |
|---|---|
TargetAddress | — |
TargetType | — |
ConfigPath | — |
IsGranular | — |
IsApplicationSpecific | — |
IsLocationTag | — |
Event ID 24 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
LastModifiedTime | — |
FileSize | — |
Event ID 24 — During schema file enumeration, the file '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
LastModifiedTime | — |
FileSize | — |
Event ID 25 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
Event ID 25 — The virtual path '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
Event ID 27 —
Fields
| Name | Description |
|---|---|
FileConfigPath | — |
EffectiveLocationPath | — |
CallSite | — |
Address | — |
TargetName | — |
MetadataName | — |
Value | — |
Event ID 27 — The '.
Message
Fields
| Name | Description |
|---|---|
FileConfigPath | — |
EffectiveLocationPath | — |
CallSite | — |
Address | — |
TargetName | — |
MetadataName | — |
Value | — |
Event ID 28 —
Fields
| Name | Description |
|---|---|
OriginalImpersonationTokenHandle | — |
ImpersonationTokenHandle | — |
Event ID 28 — Thread is impersonating an access token belonging to handle '.
Message
Fields
| Name | Description |
|---|---|
OriginalImpersonationTokenHandle | — |
ImpersonationTokenHandle | — |
Event ID 29 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
ConfigPath | — |
EffectiveLocationPath | — |
Configuration | — |
EditOperationType | — |
OldValue | — |
NewValue | — |
Sigma Rules
- ETW Logging/Processing Option Disabled On IIS Server
Detects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option. - HTTP Logging Disabled On IIS Server
Detects changes to of the IIS server configuration in order to disable HTTP logging for successful requests. - New Module Module Added To IIS Server
Detects the addition of a new module to an IIS server. - Previously Installed IIS Module Was Removed
Detects the removal of a previously installed IIS module.
Event ID 29 — Changes to '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
ConfigPath | — |
EffectiveLocationPath | — |
Configuration | — |
EditOperationType | — |
OldValue | — |
NewValue | — |
Sigma Rules
- ETW Logging/Processing Option Disabled On IIS Server
Detects changes to of the IIS server configuration in order to disable/remove the ETW logging/processing option. - HTTP Logging Disabled On IIS Server
Detects changes to of the IIS server configuration in order to disable HTTP logging for successful requests. - New Module Module Added To IIS Server
Detects the addition of a new module to an IIS server. - Previously Installed IIS Module Was Removed
Detects the removal of a previously installed IIS module.
Event ID 30 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
ConfigPath | — |
EffectiveLocationPath | — |
Configuration | — |
EditOperationType | — |
OldValue | — |
NewValue | — |
Event ID 30 — Failed to commit changes to '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
ConfigPath | — |
EffectiveLocationPath | — |
Configuration | — |
EditOperationType | — |
OldValue | — |
NewValue | — |
Event ID 33 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
Event ID 33 — Unable to locate IIS_Schema.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
Event ID 36 —
Fields
| Name | Description |
|---|---|
CallSite | — |
hSourceHandle | — |
hTargetHandle | — |
Event ID 36 — Handle '.
Message
Fields
| Name | Description |
|---|---|
CallSite | — |
hSourceHandle | — |
hTargetHandle | — |
Event ID 37 —
Fields
| Name | Description |
|---|---|
SiteName | — |
Event ID 37 — Unable to locate a site with SiteName '.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |
Event ID 38 —
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 38 — Unable to locate a site with SiteId '.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 39 —
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 39 — The SiteId '.
Message
Fields
| Name | Description |
|---|---|
Id | — |
Event ID 40 —
Fields
| Name | Description |
|---|---|
SiteName | — |
Event ID 40 — The SiteName '.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |
Event ID 41 —
Fields
| Name | Description |
|---|---|
Configuration | — |
CLSID | — |
ProgId | — |
HRESULT | — |
Event ID 41 — Failed to instantiate '.
Message
Fields
| Name | Description |
|---|---|
Configuration | — |
CLSID | — |
ProgId | — |
HRESULT | — |
Event ID 42 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 42 — Failed to initialize the '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 43 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 43 — Failed to encrypt attribute '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 44 —
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 44 — Failed to decrypt attribute '.
Message
Fields
| Name | Description |
|---|---|
PhysicalPath | — |
FileConfigPath | — |
ProviderName | — |
ProviderType | — |
Blob | — |
ErrorType | — |
HRESULT | — |
Event ID 45 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 45 — Unable to map '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 46 —
Fields
| Name | Description |
|---|---|
SiteName | — |
ApplicationPath | — |
VirtualDirectoryPath | — |
RelativeVirtualPath | — |
PhysicalPath | — |
Event ID 46 — Virtual directory mapping from '.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |
ApplicationPath | — |
VirtualDirectoryPath | — |
RelativeVirtualPath | — |
PhysicalPath | — |
Event ID 47 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Directory | — |
Filename | — |
ImpersonationToken | — |
IsCustomMapping | — |
Event ID 47 — The location of the configuration file whose config path is '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Directory | — |
Filename | — |
ImpersonationToken | — |
IsCustomMapping | — |
Event ID 49 —
Fields
| Name | Description |
|---|---|
CallSite | — |
PhysicalPath | — |
FileConfigPath | — |
EffectiveLocationPath | — |
ConfigurationElementName | — |
ConfigSourceFilePath | — |
LastModifiedTime | — |
Event ID 49 — Config/child source file for configuration '.
Message
Fields
| Name | Description |
|---|---|
CallSite | — |
PhysicalPath | — |
FileConfigPath | — |
EffectiveLocationPath | — |
ConfigurationElementName | — |
ConfigSourceFilePath | — |
LastModifiedTime | — |
Event ID 50 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 50 — Changes have successfully been committed to '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
Event ID 51 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
FileExistsInMemory | — |
FileLastModifiedTimeInMemory | — |
FileSizeInMemory | — |
FileExistsOnDisk | — |
FileLastModifiedTimeOnDisk | — |
FileSizeOnDisk | — |
IsInMemoryViewOfFileRecent | — |
Event ID 51 — Failed to commit changes to '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
FileExistsInMemory | — |
FileLastModifiedTimeInMemory | — |
FileSizeInMemory | — |
FileExistsOnDisk | — |
FileLastModifiedTimeOnDisk | — |
FileSizeOnDisk | — |
IsInMemoryViewOfFileRecent | — |
Event ID 52 —
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
FileExistsInMemory | — |
FileLastModifiedTimeInMemory | — |
FileSizeInMemory | — |
FileExistsOnDisk | — |
FileLastModifiedTimeOnDisk | — |
FileSizeOnDisk | — |
IsInMemoryViewOfFileRecent | — |
Event ID 52 — Checking whether file '.
Message
Fields
| Name | Description |
|---|---|
ConfigPath | — |
PhysicalPath | — |
FileExistsInMemory | — |
FileLastModifiedTimeInMemory | — |
FileSizeInMemory | — |
FileExistsOnDisk | — |
FileLastModifiedTimeOnDisk | — |
FileSizeOnDisk | — |
IsInMemoryViewOfFileRecent | — |
Event ID 53 —
Fields
| Name | Description |
|---|---|
SiteName | — |
ApplicationPath | — |
VirtualDirectoryPath | — |
RelativeVirtualPath | — |
PhysicalPath | — |
Event ID 53 — Unable to create a path mapping for the virtual directory, /system.
Message
Fields
| Name | Description |
|---|---|
SiteName | — |
ApplicationPath | — |
VirtualDirectoryPath | — |
RelativeVirtualPath | — |
PhysicalPath | — |
Event ID 54 —
Event ID 54 — A commit operation has been initiated.
Message
Event ID 55 —
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 55 — A commit operation has completed.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 56 —
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 56 — A kernel transaction for a commit operation has been created.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 57 —
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 57 — Failed to create a kernel transaction for the commit operation.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 58 —
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 58 — Changes have successfully been committed with a kernel transaction.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 59 —
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 59 — Failed to commit the changes with a kernel transaction.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
HRESULT | — |
Event ID 60 —
Event ID 60 — A file write operation in a commit operation has been initiated.
Message
Event ID 61 —
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
RemainingRetryCount | — |
HRESULT | — |
Event ID 61 — The contents of the file '.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
RemainingRetryCount | — |
HRESULT | — |
Event ID 62 —
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
HRESULT | — |
Event ID 62 — The contents of the file '.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
HRESULT | — |
Event ID 63 —
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
SizeInBytes | — |
HRESULT | — |
Event ID 63 — The new contents of the file '.
Message
Fields
| Name | Description |
|---|---|
Handle | — |
PhysicalPath | — |
ConfigPath | — |
SizeInBytes | — |
HRESULT | — |
Event ID 64 —
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 64 — A file write operation in a commit operation has completed.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 65 —
Fields
| Name | Description |
|---|---|
TargetAddress | — |
TargetType | — |
ConfigPath | — |
IsGranular | — |
IsApplicationSpecific | — |
IsLocationTag | — |
Event ID 65 — A change listener of type '.
Message
Fields
| Name | Description |
|---|---|
TargetAddress | — |
TargetType | — |
ConfigPath | — |
IsGranular | — |
IsApplicationSpecific | — |
IsLocationTag | — |