Microsoft-Windows-NlaSvc
52 events across 2 channels
Event ID 4001 — Entered State: Entered_State Interface Guid: Interface_Guid.
Event ID 4002 — Transitioning to State: CurrentOrNextState Interface Guid: InterfaceGuid.
Event ID 4101 — Received WMI Media Connect Notification for 'AdapterName' InterfaceGuid.
Event ID 4102 — Received WMI Media Disconnect Notification for 'AdapterName' InterfaceGuid.
Event ID 4103 — Route change has occurred for interface InterfaceGuid (MibNotificationType).
Event ID 4104 — Address change has occurred for interface InterfaceGuid (MibNotificationType).
Event ID 4105 — Quarantine state has changed
Description
Quarantine state has changed.
Message #
Event ID 4106 — Received DHCP notification
Description
Received DHCP notification.
Message #
Event ID 4201 — Start link resolver
Description
Start link resolver.
Message #
Event ID 4202 — Stop link resolver
Description
Stop link resolver.
Message #
Event ID 4203 — Start gateway resolution on interface InterfaceGuid for GatewayIpAddress.
Event ID 4204 — Stop gateway resolution on interface NlnsState for MAC.
Event ID 4205 — Gateway resolution failed on interface InterfaceGuid for GatewayIpAddress with error: ErrorCode.
Description
Gateway resolution failed on interface InterfaceGuid for GatewayIpAddress with error: ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
GatewayIpAddress UnicodeString | — |
ErrorCode UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-NlaSvc",
"guid": "63B530F8-29C9-4880-A5B4-B8179096E7B8",
"event_source_name": "",
"event_id": 4205,
"version": 0,
"level": 2,
"task": 3,
"opcode": 21,
"keywords": 4611686018427387938,
"time_created": "2026-03-15T05:30:49.223016+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "6FDE36A2-B353-0009-B736-DE6F53B3DC01"
},
"execution": {
"process_id": 1992,
"thread_id": 12780
},
"channel": "Microsoft-Windows-NlaSvc/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"InterfaceGuid": "8A1760B6-DC99-4B90-9C4A-029698E5AE27",
"GatewayIpAddress": "10.2.10.1",
"ErrorCode": 67
},
"message": ""
}
Event ID 4251 — Plug-in data indicated from PluginName for entity EntityName (IndicatedRowCount rows).
Event ID 4261 — DHCP has stabilized for InterfaceGuid (NlaState).
Event ID 4301 — Start Intranet resolver
Description
Start Intranet resolver.
Message #
Event ID 4311 — Start DsGetDcName(DnsSuffix,Flags) for DnsSuffix.
Event ID 4312 — Stop DsGetDcName(DnsSuffix,Flags) for DnsSuffix returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
Event ID 4313 — DsGetDcName(DnsSuffix,Flags) for DnsSuffix failed with error ErrorCode.
Event ID 4321 — Start DsGetDcName(Flags) for DS info.
Event ID 4322 — Stop DsGetDcName(Flags) for DS info returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
Event ID 4323 — DsGetDcName(Flags) for DS info failed with error ErrorCode.
Event ID 4331 — Start DsGetDcName(Flags) for root domain GUID.
Event ID 4332 — Stop DsGetDcName(Flags) for root domain GUID returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
Event ID 4333 — DsGetDcName(Flags) for root domain GUID failed with error ErrorCode.
Event ID 4341 — Start LDAP authentication on interface Interface Name (Addresses) (Try Count tries).
Event ID 4342 — Stop LDAP authentication on interface Interface Name (Addresses).
Event ID 4343 — LDAP authentication on interface Interface Name (Addresses) failed with error ErrorCode.
Event ID 4351 — Start ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries).
Event ID 4352 — Stop ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries).
Event ID 4353 — ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries) failed with ErrorCode.
Event ID 4354 — Start ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries).
Event ID 4355 — Stop ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries).
Event ID 4356 — ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries) failed with ErrorCode.
Event ID 4401 — Inserting identifying signature for interface InterfaceGuid.
Event ID 4402 — Inserting identified signature for interface InterfaceGuid.
Event ID 4403 — Removing identified signature for interface InterfaceGuid.
Event ID 4404 — Inserting identified signature for interface InterfaceGuid.
Event ID 4405 — Inserting identified signature for interface InterfaceGuid.
Event ID 4407 — Adding interface 'AdapterName' InterfaceGuid.
Event ID 4408 — Removing interface 'AdapterName' InterfaceGuid.
Event ID 4409 — Adding interface 'AdapterName' InterfaceGuid.
Event ID 4410 — Inserting identified signature for interface InterfaceGuid.
Event ID 4411 — Inserting identified signature for interface InterfaceGuid.
Event ID 4451 — Network on Reason is unlikely to be authentication-capable; authentication will continue in the background.
Event ID 5001 —
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
NlaState UInt32 | — |