Microsoft-Windows-MSDTC 2
66 events across 2 channels
Event ID 4097 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4098 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4099 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4100 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4101 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4102 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4103 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4104 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4202 —
#Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
param4 | — |
param5 | — |
param6 | — |
param7 | — |
param8 | — |
param9 | — |
param10 | — |
param11 | — |
param12 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC 2",
"guid": "{5D9E0020-3761-4f36-90C8-38CE6511BD12}",
"event_source_name": "MSDTC 2",
"event_id": 4202,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-06T06:25:51.684453+00:00",
"event_record_id": 1448,
"correlation": {},
"execution": {
"process_id": 4912,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "0",
"param2": "0",
"param3": "0",
"param4": "0",
"param5": "0",
"param6": "0",
"param7": "1",
"param8": "Mutual Authentication Required",
"param9": "NT AUTHORITY\\NetworkService",
"param10": "0",
"param11": "0",
"param12": "1"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4202 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
param10 UnicodeString | — |
param11 UnicodeString | — |
param12 UnicodeString | — |
Event ID 4350 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4872 —
Event ID 4875 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4876 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4878 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4879 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4880 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 53323 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53324 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53325 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53327 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53328 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 53329 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53330 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53331 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53332 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53333 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53334 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53335 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 53336 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53337 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53338 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 53339 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 1073745921 — Failed to clean up the default DTC cluster resource setting.
Event ID 1073745922 — Contact = param1 was deleted successfully.
Event ID 1073745923 — Failed to create DTC cluster resource.
Event ID 1073745924 — Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed.
Event ID 1073745925 — Attempting to change the DTC cluster resource's log file path to param1 has failed.
Event ID 1073745926 — Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned.
Event ID 1073745927 — Service: Service is still running.
Event ID 1073745928 — Failed trying to get the state of the cluster node: param1.
Event ID 1073746026 — MSDTC started with the following settings.
Description
MSDTC started with the following settings.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
param5 UnicodeString | — |
param6 UnicodeString | — |
param7 UnicodeString | — |
param8 UnicodeString | — |
param9 UnicodeString | — |
param10 UnicodeString | — |
param11 UnicodeString | — |
param12 UnicodeString | — |
Event ID 1073746174 — Cluster API call failed with error code: param1.
Event ID 1073746185 — Cluster API call failed with error code: {param1}.
Event ID 2147488520 — A caller has attempted to register an XA resource while XA transactions are disabled.
Description
A caller has attempted to register an XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.
Message #
Event ID 2147488523 — A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager comm...
Event ID 2147488524 — A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager commu...
Event ID 2147488526 — MSDTC encountered an error (HR=0xparam1) while attempting to authenticate an incoming connection from system 'param2'.
Event ID 2147488527 — MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system param2.
Event ID 2147488528 — MS DTC encountered an error while attempting to process a message from a connection with system 'param1'.
Event ID 2147536971 — The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager 'param1'.
Description
The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 2147536972 — The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager 'param1'.
Description
The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 2147536973 — The MSDTC XA Transaction Manager called the xa_open function for XA resource manager 'param1'.
Description
The MSDTC XA Transaction Manager called the xa_open function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 2147536975 — The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL 'param1'.
Description
The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL 'param1'. The call to the 'GetXaSwitch' function failed with error param2: File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 2147536976 — The MSDTC XA Transaction Manager attempted to perform recovery with the XA resource manager DLL 'param1'.
Event ID 2147536977 — The MSDTC XA Transaction Manager called the xa_open function in the XA resource manager DLL 'param1'.
Event ID 2147536978 — The MSDTC XA Transaction Manager called the xa_close function in the XA resource manager DLL 'param1'.
Event ID 2147536979 — The MSDTC XA Transaction Manager called the xa_recover function in the XA resource manager DLL 'param1'.
Event ID 2147536980 — The MSDTC XA Transaction Manager called the xa_commit function in the XA resource manager DLL 'param1'.
Event ID 2147536981 — The MSDTC XA Transaction Manager called the xa_rollback function in the XA resource manager DLL 'param1'.
Event ID 2147536982 — The MSDTC XA Transaction Manager called the xa_prepare function in the XA resource manager DLL 'param1'.
Event ID 2147536983 — The MSDTC XA Transaction Manager called the GetXaSwitch function in the XA resource manager DLL 'param1'.
Event ID 2147536984 — The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager 'param1'.
Description
The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |
Event ID 2147536985 — The MSDTC XA Transaction Manager called the xa_commit function with the TMONEPHASE flag set for the XA resource manager 'param1'.
Event ID 2147536986 — The MSDTC XA Transaction Manager attempted to locate the 'GetXaSwitch' function in the XA resource manager DLL.
Event ID 2147536987 — The MS DTC XA Transaction Manager called the xa_close function for XA resource manager 'param1'.
Description
The MS DTC XA Transaction Manager called the xa_close function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
param4 UnicodeString | — |