Microsoft-Windows-MSDTC Client 2
38 events across 2 channels
Event ID 4097 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4098 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4099 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4100 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4101 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4102 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4103 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4104 —
#Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4104,
"version": 0,
"level": 2,
"task": 14,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-05T22:27:41.546510+00:00",
"event_record_id": 1466,
"correlation": {},
"execution": {
"process_id": 4608,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "",
"param2": "0x8007045B"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4104 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4350 —
Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
param3 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4350,
"version": 0,
"level": 3,
"task": 14,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T20:23:52.178949+00:00",
"event_record_id": 3710,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "0x800706D9",
"param2": "OpenClusterEx",
"param3": "lpszClusterName: (null)"
},
"message": ""
}
Event ID 4350 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4872 —
Event ID 4873 —
Event ID 4874 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4875 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4876 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 4878 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
param3 UnicodeString | — |
Event ID 4879 —
#Fields #
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4879,
"version": 0,
"level": 3,
"task": 3,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-10-25T22:53:19.706720+00:00",
"event_record_id": 1415,
"correlation": {},
"execution": {
"process_id": 932,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDevEval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "80000171",
"param2": "WINDEVEVAL"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4879 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
param2 UnicodeString | — |
Event ID 4881 —
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | — |
Event ID 1073745921 — Failed to clean up the default DTC cluster resource setting.
Event ID 1073745922 — Contact = param1 was deleted successfully.
Event ID 1073745923 — Failed to create DTC cluster resource.
Event ID 1073745924 — Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed.
Event ID 1073745925 — Attempting to change the DTC cluster resource's log file path to param1 has failed.
Event ID 1073745926 — Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned.
Event ID 1073745927 — Service: Service is still running.
Event ID 1073745928 — Failed trying to get the state of the cluster node: param1.
Event ID 1073746174 — Cluster API call failed with error code: param1.
Event ID 1073746185 — Cluster API call failed with error code: {param1}.
Event ID 2147488520 — A caller has attempted to register an XA resource while XA transactions are disabled.
Description
A caller has attempted to register an XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.
Message #
Event ID 2147488521 — An XA transaction manager has attempted to open the MSDTC XA resource while XA transactions are disabled.
Description
An XA transaction manager has attempted to open the MSDTC XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.