Microsoft-Windows-MSDTC 2
66 events across 2 channels
Event ID 4097 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4098 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4099 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4100 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4101 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4102 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4103 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4104 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4202 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
param12 | — |
Event ID 4202 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
param12 | — |
Example Event
system:
provider: Microsoft-Windows-MSDTC 2
guid: '{5D9E0020-3761-4f36-90C8-38CE6511BD12}'
event_source_name: MSDTC 2
event_id: 4202
version: 0
level: 4
task: 2
opcode: 0
keywords: 36028797018963968
time_created: '2023-11-06T06:25:51.684453+00:00'
event_record_id: 1448
correlation: {}
execution:
process_id: 4912
thread_id: 0
channel: Application
computer: WinDev2310Eval
security:
user_id: ''
event_data:
param1: '0'
param2: '0'
param3: '0'
param4: '0'
param5: '0'
param6: '0'
param7: '1'
param8: Mutual Authentication Required
param9: NT AUTHORITY\NetworkService
param10: '0'
param11: '0'
param12: '1'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4350 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4872 —
Event ID 4875 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4876 —
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 4878 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 4879 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 4880 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 53323 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53324 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53325 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53327 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53328 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 53329 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53330 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53331 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53332 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53333 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53334 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53335 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 53336 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53337 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53338 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 53339 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 1073745921 — Failed to clean up the default DTC cluster resource setting.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745922 — Contact = %1 was deleted successfully.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073745923 — Failed to create DTC cluster resource.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073745924 — Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745925 — Attempting to change the DTC cluster resource's log file path to %1 has failed.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073745926 — Application specified a cluster resource ID: %1, but no DTC cluster resource could be returned.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745927 — Service: %1 is still running.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 1073745928 — Failed trying to get the state of the cluster node.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 1073746026 — MSDTC started with the following settings: Security Configuration (OFF = 0 and ON = 1): Allow Remote Administrator = %1, Network Clients = %2, Tran...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
param12 | — |
Event ID 1073746174 — Cluster API call failed with error code.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 1073746185 — Cluster API call failed with error code: {param1}.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488520 — A caller has attempted to register an XA resource while XA transactions are disabled.
Message
Event ID 2147488523 — A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager comm...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488524 — A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager commu...
Message
Fields
| Name | Description |
|---|---|
param1 | — |
Event ID 2147488526 — MSDTC encountered an error (HR=0x%1) while attempting to authenticate an incoming connection from system '%2'.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147488527 — MSDTC encountered an error (HR=0x%1) while attempting to establish a secure connection with system %2.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147488528 — MS DTC encountered an error while attempting to process a message from a connection with system '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147536971 — The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536972 — The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536973 — The MSDTC XA Transaction Manager called the xa_open function for XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536975 — The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536976 — The MSDTC XA Transaction Manager attempted to perform recovery with the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Event ID 2147536977 — The MSDTC XA Transaction Manager called the xa_open function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536978 — The MSDTC XA Transaction Manager called the xa_close function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536979 — The MSDTC XA Transaction Manager called the xa_recover function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536980 — The MSDTC XA Transaction Manager called the xa_commit function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536981 — The MSDTC XA Transaction Manager called the xa_rollback function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536982 — The MSDTC XA Transaction Manager called the xa_prepare function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536983 — The MSDTC XA Transaction Manager called the GetXaSwitch function in the XA resource manager DLL '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Event ID 2147536984 — The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536985 — The MSDTC XA Transaction Manager called the xa_commit function with the TMONEPHASE flag set for the XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536986 — The MSDTC XA Transaction Manager attempted to locate the 'GetXaSwitch' function in the XA resource manager DLL.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
Event ID 2147536987 — The MS DTC XA Transaction Manager called the xa_close function for XA resource manager '.
Message
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |