Microsoft-Windows-LUA

45 events across 2 channels

Event IDTitleChannel
15001Diagnostic
15002Diagnostic
15003Diagnostic
15004Diagnostic
15005Diagnostic
15006Diagnostic
15007Diagnostic
15008Diagnostic
15009Diagnostic
15010Diagnostic
15011Diagnostic
15012Diagnostic
15013Diagnostic
15014Diagnostic
15015Diagnostic
15016Diagnostic
15017Diagnostic
15018Diagnostic
15019Diagnostic
15020Diagnostic
15021Diagnostic
15022Diagnostic
15023Diagnostic
15024Diagnostic
15025Diagnostic
15026Diagnostic
15027Diagnostic
15028Diagnostic
15029Diagnostic
15030Diagnostic
15031Diagnostic
15031Success: Elevation prompt for executable %3 (%1 published by %2) answered by %4, …Elevation
15032Diagnostic
15032Elevation prompt for executable %3 (%1 published by %2) answered by %4.Elevation
16001Diagnostic
16002Diagnostic
16003Diagnostic
16004Diagnostic
16005Diagnostic
16006Diagnostic
16007Diagnostic
16008Diagnostic
16009Diagnostic
16010Diagnostic
16011Diagnostic

Event ID 15001 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15002 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15003 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15004 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15005 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15006 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15007 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15008 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15009 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15010 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15011 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15012 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15013 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15014 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15015 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15016 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15017 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15018 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15019 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15020 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15021 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15022 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15023 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15024 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15025 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15026 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15027 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15028 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
Parameters

Event ID 15029 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15030 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Event ID 15031 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
ProgramName
Publisher
FullCommandLine
UserName
ShadowAdmin
ShadowAdminSID
ReturnCode
ReturnMessage

Event ID 15031 — Success: Elevation prompt for executable %3 (%1 published by %2) answered by %4, will elevate as %5.

Provider
Microsoft-Windows-LUA
Channel
Elevation

Message

Success: Elevation prompt for executable %3 (%1 published by %2) answered by %4, will elevate as %5.

Fields

NameDescription
ProgramName
Publisher
FullCommandLine
UserName
ShadowAdmin
ShadowAdminSID
ReturnCode
ReturnMessage

Event ID 15032 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
ProgramName
Publisher
FullCommandLine
UserName
ShadowAdmin
ShadowAdminSID
ReturnCode
ReturnMessage

Event ID 15032 — Elevation prompt for executable %3 (%1 published by %2) answered by %4.

Provider
Microsoft-Windows-LUA
Channel
Elevation

Message

Elevation prompt for executable %3 (%1 published by %2) answered by %4. Error %7: %8.

Fields

NameDescription
ProgramName
Publisher
FullCommandLine
UserName
ShadowAdmin
ShadowAdminSID
ReturnCode
ReturnMessage

Event ID 16001 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16002 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16003 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16004 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16005 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16006 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16007 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16008 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16009 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16010 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID

Event ID 16011 —

Provider
Microsoft-Windows-LUA
Channel
Diagnostic

Fields

NameDescription
EventId
UACElevateFileID