Microsoft-Windows-PowerShell

189 events across 3 channels

Event IDTitleChannel
4097Computer Name $null or.Operational
4098Resolving to default scheme httpOperational
4099Remote shell name resolved to default Microsoft.Operational
4100%3 Context: %1 User Data: %2.Operational
4101%3 Context: %1 User Data: %2.Operational
4102%3 Context: %1 User Data: %2.Operational
4103%3 Context: %1 User Data: %2.Operational
4104Creating Scriptblock text (%1 of %2): %3 ScriptBlock ID: %4 Path: %5.Operational
4105Started invocation of ScriptBlock ID: %1 Runspace ID: %2.Operational
4106Completed invocation of ScriptBlock ID: %1 Runspace ID: %2.Operational
7937%3 Context: %1 User Data: %2.Analytic
7938%3 Context: %1 User Data: %2.Analytic
7939%3 Context: %1 User Data: %2.Analytic
7940%3 Context: %1 User Data: %2.Analytic
7941Correlating activity id's.Analytic
7942Class Name = %1 Method Name = %2 Workflow GUID = %3 Message = %4 %5 Activity …Analytic
8193Creating Runspace object Instance Id.Operational
8194Creating RunspacePool object InstanceId %1 MinRunspaces %2 MaxRunspaces %3.Operational
8195Opening RunspacePoolOperational
8196Modifying activity Id and correlatingOperational
8197Runspace state changed to %1.Operational
8198Attempting session creation retry %1 for error code %2 on session Id %3.Operational
12033Port resolved to %1.Analytic
12034AppName resolved to %1.Analytic
12035ComputerName resolved to %1.Analytic
12036Scheme is %1.Analytic
12037Test analytic messageAnalytic
12038Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 …Analytic
12039Modifying activity Id and correlatingOperational
16385AmsiUtil state.Analytic
24577Windows PowerShell ISE has started to run script file %1.Operational
24578Windows PowerShell ISE has started to run a user-selected script from file %1.Operational
24579Windows PowerShell ISE is stopping the current command.Operational
24580Windows PowerShell ISE is resuming the debugger.Operational
24581Windows PowerShell ISE is stopping the debugger.Operational
24582Windows PowerShell ISE is stepping into debugging.Operational
24583Windows PowerShell ISE is stepping over debugging.Operational
24584Windows PowerShell ISE is stepping out of debugging.Operational
24592Windows PowerShell ISE is enabling all breakpoints.Operational
24593Windows PowerShell ISE is disabling all breakpoints.Operational
24594Windows PowerShell ISE is removing all breakpoints.Operational
24595Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.Operational
24596Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.Operational
24597Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.Operational
24598Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.Operational
24599Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.Operational
28673Successfully rehydrated an object.Analytic
28674Failed to rehydrated an object.Analytic
28675Serialization depth has been overriden.Analytic
28676Serialization mode has been overriden.Analytic
28677Serialization of a script property has been skipped, because there is no …Analytic
28678Serialization of a property has been skipped, because property getter failed.Analytic
28679Serialization of an enumerable object might not be complete, because object …Analytic
28680Serialization called object's ToString method which failed.Analytic
28682Maximum depth below top level has been reached, forcing object to be serialized …Analytic
28683XmlException has been thrown by the deserializer (most likely indicating …Analytic
28684Serialization of specified properties failed, because one of the specified …Analytic
32769Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 …Analytic
32775An unhandled exception occurred in the appdomain.Analytic
32776Runspace Id: %1 Pipeline Id: %2.Analytic
32777An unhandled exception occurred in the appdomain.Operational
32784Runspace Id: %1 Pipeline Id: %2.Operational
32785Runspace Id %1.Analytic
32786Runspace Id %1.Analytic
32787Runspace Id.Analytic
32788Runspace Id.Analytic
32789Runspace Id: %1 Pipeline Id: %2.Analytic
32790Runspace Id: %1 Pipeline Id: %2.Analytic
32791Runspace Id: %1 Pipeline Id: %2.Analytic
32792Runspace Id: %1 Pipeline Id: %2.Analytic
32793Runspace Id %1 Pipeline Id %2.Analytic
32800Runspace Id %1 Pipeline Id %2.Analytic
32801Runspace Id: %1 Pipeline Id %2.Analytic
32802Runspace Id: %1 Pipeline Id %2.Analytic
32803Runspace Id: %1 Pipeline Id %2.Analytic
32804Runspace Id: %1 Pipeline Id %2.Analytic
32805Runspace Id.Analytic
32849Runspace Id: %1 Pipeline Id: %2.Analytic
32850Request %1.Analytic
32851Reporting context for request: %1 Context Reported: %1.Analytic
32852Reporting operation complete for request: %1 Error Code: %2 Error Message: %3 …Analytic
32853Shell Context %1.Analytic
32854Shell Context %1 Command Context %2 Request Id %3.Analytic
32855Shell Context %1 Command Context %2 Request Id %3.Analytic
32856Shell Context %1 Command Context %2 Request Id %3.Analytic
32857Shell Context %1 Command Context %2 IsReceiveOperation %3.Analytic
32865Loading assembly %1 for custom shell with shell Id %2.Analytic
32866Loading type %1 for custom shell with shell Id %2.Analytic
32867Received remoting fragment.Analytic
32868Sent remoting fragment.Analytic
32869Shutting down winrm service.Analytic
40961PowerShell console is starting upOperational
40962PowerShell console is ready for user inputOperational
45057Tracing ErrorRecord: Message: %1 CategoryInfo.Debug
45058Exception: Message: %1 StackTrace: %2 InnerException : %3.Debug
45059Tracing PSObjectDebug
45060Tracing Job: Id: %1 InstanceId: %2 Name: %3 Location: %4 State: %5 Command: %6.Debug
45061Trace Information.Debug
45062Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 …Debug
45063Workflow plugin loaded.Analytic
45064Workflow execution started.Analytic
45065Workflow state changed.Analytic
45072Workflow plugin has been requested for a shutdown.Analytic
45073Workflow plugin restarted.Analytic
45074Workflow is resuming.Analytic
45075A quota limit that was set for the endpoint was exceeded.Analytic
45076Workflow has resumed.Analytic
45078Workflow runspace pool was created.Analytic
45079Activity was queued for execution.Analytic
45080Activity execution started.Analytic
45081Workflow is being imported from a XAML file.Analytic
45082Workflow has been imported from a XAML file.Analytic
45083Workflow could not be imported from a XAML file because of an error.Analytic
45084Workflow validation started.Analytic
45085Workflow validation succeeded.Analytic
45086Workflow validation failed with error.Analytic
45087Workflow activity validated.Analytic
45088Workflow activity could not be validated.Analytic
45089Activity execution failed.Analytic
45090Runspace availability changed.Analytic
45091Runspace state changed.Analytic
45092Workflow loaded for execution.Analytic
45093Workflow unloaded.Analytic
45094Workflow execution cancelled.Analytic
45095Workflow execution aborted.Analytic
45096Workflow cleanup operation executed.Analytic
45097Persisted workflow loaded from disk.Analytic
45098Workflow data was deleted from disk.Analytic
45100Starting remove job.Analytic
45101Job state changed.Analytic
45102Job error.Analytic
45104Job created for workflow (child job).Analytic
45105Parent job created for workflow.Analytic
45106All required jobs were created for workflow execution.Analytic
45107Child job removed for workflow.Analytic
45108An error occurred while removing job.Analytic
45109Loading workflow for execution.Analytic
45110Workflow execution finished.Analytic
45111Cancelling workflow execution.Analytic
45112Aborting workflow execution.Analytic
45113Unloading workflow.Analytic
45114Forced workflow shutdown started.Analytic
45115Forced workflow shutdown finished.Analytic
45116An error occurred while forcefully shutting down a workflow.Analytic
45117Persisting workflow to disk.Analytic
45118Workflow persisted to disk.Analytic
45119Activity execution finished.Analytic
45120Workflow execution error.Analytic
45121A new PowerShell endpoint was registered.Analytic
45122Endpoint configuration modified.Analytic
45123Endpoint configuration unregistered.Analytic
45124Endpoint configuration disabled.Analytic
45125Endpoint configuration enabled.Analytic
45126Out of process runspace started.Analytic
45127Parameter splatting was performed during workflow execution.Analytic
45128Workflow engine started.Analytic
45129Workflow manager instantiated with CheckpointPath: %1 ConfigProviderId: %2 …Debug
46337BEGIN ImportWorkflowCommand::StartWorkflowApplication.Debug
46338END ImportWorkflowCommand::StartWorkflowApplication.Debug
46339BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication.Debug
46340END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.Debug
46341END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.Debug
46342BEGIN JobLogic ContainerParentJob Guid %1.Debug
46343END JobLogic ContainerParentJob Guid %1.Debug
46344BEGIN WorkflowExecution ContainerParentJob Guid %1.Debug
46345END WorkflowExecution ContainerParentJob Guid %1.Debug
46346WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2.Debug
46347ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2.Debug
46348BEGIN Execution of ContainerParentJob with Guid %1.Debug
46349END Execution of ContainerParentJob with Guid %1.Debug
46350BEGIN Execution of Proxy Job with Guid %1.Debug
46351END Execution of Proxy Job with Guid %1.Debug
46352BEGIN StateChanged event handler for Proxy Job with Guid %1.Debug
46353END StateChanged event handler for Proxy Job with Guid %1.Debug
46354BEGIN StateChanged event handler for Proxy Child Job with Guid %1.Debug
46355END StateChanged event handler for Proxy Child Job with Guid %1.Debug
46356BEGIN Running garbage collectionDebug
46357END Running garbage collectionDebug
46358Persistence store has reached its maximum specified sizeOperational
49152Debug
49153Trace Information: %1 %2.Debug
53249Scheduled Job %1 started at %2.Operational
53250Scheduled Job %1 completed at %2 with state %3.Operational
53251Scheduled Job Exception %1: Message: %2 StackTrace: %3 InnerException: %4.Operational
53504Windows PowerShell has started an IPC listening thread on process: %1 in …Operational
53505Windows PowerShell has ended an IPC listening thread on process: %1 in …Operational
53506An error has occurred in Windows PowerShell IPC listening thread on process: %1 …Operational
53507Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.Operational
53508Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.Operational

Event ID 4097 — Computer Name $null or.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Computer Name $null or . resolve to LocalHost

Event ID 4098 — Resolving to default scheme http

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Resolving to default scheme http

Event ID 4099 — Remote shell name resolved to default Microsoft.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Remote shell name resolved to default Microsoft.PowerShell

Event ID 4100 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
3
Samples
1

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
ContextInfoContext
UserData
Payload

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4100
  version: 1
  level: 3
  task: 106
  opcode: 19
  keywords: 0
  time_created: '2022-04-07T17:04:47.579256+00:00'
  event_record_id: 144
  correlation:
    ActivityID: E0AAB88C-4A9F-0000-0BCA-AAE09F4AD801
  execution:
    process_id: 380
    thread_id: 3624
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  ContextInfo: "        Severity = Warning\r\n        Host Name = ADMUX\r\n        Host
    Version = 1.0.0.0\r\n        Host ID = 2e800f71-2f5c-4821-bd98-9e3b61b6b054\r\n
    \       Host Application = C:\\Windows\\system32\\dsac.exe\r\n        Engine Version
    = 5.1.20348.617\r\n        Runspace ID = 4e800c4b-dc8b-408d-8e82-38150ba7d4fe\r\n
    \       Pipeline ID = 31\r\n        Command Name = Set-ADAccountPassword\r\n        Command
    Type = Cmdlet\r\n        Script Name = \r\n        Command Path = \r\n        Sequence
    Number = 23\r\n        User = SIGMA\\Administrator\r\n        Connected User =
    \r\n        Shell ID = Microsoft.PowerShell\r\n"
  UserData: ''
  Payload: "Error Message = The password does not meet the length, complexity, or
    history requirement of the domain.\r\nFully Qualified Error ID = ActiveDirectoryServer:1325,Microsoft.ActiveDirectory.Management.Commands.SetADAccountPassword\r\n"
message: ''

References

Event ID 4101 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
Context
User_Data
ContextInfo
UserData
Payload

Event ID 4102 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
3
Samples
1

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
ContextInfoContext
UserData
Payload

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4102
  version: 1
  level: 3
  task: 106
  opcode: 19
  keywords: 0
  time_created: '2023-10-25T21:34:05.630892+00:00'
  event_record_id: 11
  correlation:
    ActivityID: DE03B784-07C3-0001-BC98-04DEC307DA01
  execution:
    process_id: 1796
    thread_id: 2088
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDevEval
  security:
    user_id: S-1-5-21-2533829718-189860685-2477588761-500
event_data:
  ContextInfo: "        Severity = Warning\r\n        Host Name = ConsoleHost\r\n
    \       Host Version = 5.1.22621.2428\r\n        Host ID = d4db7522-7ab1-46f8-add0-ee6f22c6c812\r\n
    \       Host Application = C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe
    -ExecutionPolicy Bypass a:\\FixPublicNetworkType.ps1\r\n        Engine Version
    = 5.1.22621.2428\r\n        Runspace ID = c5b2be04-de37-4a47-bfdd-d75d2d714efd\r\n
    \       Pipeline ID = 1\r\n        Command Name = \r\n        Command Type = \r\n
    \       Script Name = \r\n        Command Path = \r\n        Sequence Number =
    16\r\n        User = WINDEVEVAL\\Administrator\r\n        Connected User = \r\n
    \       Shell ID = Microsoft.PowerShell\r\n"
  UserData: ''
  Payload: "Error Message = Could not find the drive 'a:\\'. The drive might not be
    ready or might not be mapped.\r\n\r\nProvider name = Microsoft.PowerShell.Core\\FileSystem\r\n"
message: ''

References

Event ID 4103 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
ContextInfoContext
UserData
Payload

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4103
  version: 1
  level: 4
  task: 106
  opcode: 20
  keywords: 0
  time_created: '2023-11-06T01:35:06.007359+00:00'
  event_record_id: 907
  correlation:
    ActivityID: E4DB489E-1037-0000-CD79-E9E43710DA01
  execution:
    process_id: 15468
    thread_id: 15184
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  ContextInfo: "        Severity = Informational\r\n        Host Name = ConsoleHost\r\n
    \       Host Version = 5.1.22621.2428\r\n        Host ID = 9500ad9e-7709-413f-b91b-8945cbb52940\r\n
    \       Host Application = powershell.exe -NoExit -Command &{Import-Module \"C:\\Program
    Files\\Microsoft Visual Studio\\2022\\Community\\Common7\\Tools\\Microsoft.VisualStudio.DevShell.dll\";
    Enter-VsDevShell d5dcd421 -SkipAutomaticLocation -DevCmdArguments \"-arch=x64
    -host_arch=x64\"}\r\n        Engine Version = 5.1.22621.2428\r\n        Runspace
    ID = 6fa4bb48-d600-4d4b-b445-e1fa0a41db53\r\n        Pipeline ID = 23\r\n        Command
    Name = Set-StrictMode\r\n        Command Type = Cmdlet\r\n        Script Name
    = C:\\Program Files\\WindowsPowerShell\\Modules\\PSReadLine\\2.0.0\\PSReadLine.psm1\r\n
    \       Command Path = \r\n        Sequence Number = 58\r\n        User = WINDEV2310EVAL\\User\r\n
    \       Connected User = \r\n        Shell ID = Microsoft.PowerShell\r\n"
  UserData: ''
  Payload: "CommandInvocation(Set-StrictMode): \"Set-StrictMode\"\r\nParameterBinding(Set-StrictMode):
    name=\"Off\"; value=\"True\"\r\n"
message: ''

Sigma Rules

Showing 5 of 33 matching Sigma rules.

References

Event ID 4104 — Creating Scriptblock text (%1 of %2): %3 ScriptBlock ID: %4 Path: %5.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Creating Scriptblock text (%1 of %2):
%3

ScriptBlock ID: %4
Path: %5

Fields

NameDescription
MessageNumber
MessageTotal
ScriptBlockText
ScriptBlockIdScriptBlock ID.
Path

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4104
  version: 1
  level: 5
  task: 2
  opcode: 15
  keywords: 0
  time_created: '2023-11-06T01:35:05.990326+00:00'
  event_record_id: 901
  correlation:
    ActivityID: E4DB489E-1037-0002-FA44-ECE43710DA01
  execution:
    process_id: 15468
    thread_id: 15184
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  MessageNumber: 1
  MessageTotal: 1
  ScriptBlockText: prompt
  ScriptBlockId: 6baf0dc7-a83f-43e1-bb6a-d7ab8d05eeb0
  Path: ''
message: ''

Sigma Rules

  • AADInternals PowerShell Cmdlets Execution - PsScript
    Detects ADDInternals Cmdlet execution. A tool for administering Azure AD and Office 365. Which can be abused by threat actors to attack Azure AD or Office 365.
  • Access to Browser Login Data
    Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials such as website usernames and passwords so that they do not need to be entered manually in the future. Web browsers typically store the credentials in an encrypted format within a credential store.
  • Potential Active Directory Enumeration Using AD Module - PsScript
    Detects usage of the "Import-Module" cmdlet to load the "Microsoft.ActiveDirectory.Management.dl" DLL. Which is often used by attackers to perform AD enumeration.
  • Powershell Add Name Resolution Policy Table Rule
    Detects powershell scripts that adds a Name Resolution Policy Table (NRPT) rule for the specified namespace. This will bypass the default DNS server and uses a specified server for answering the query.
  • Add Windows Capability Via PowerShell Script
    Detects usage of the "Add-WindowsCapability" cmdlet to add Windows capabilities. Notable capabilities could be "OpenSSH" and others.

Showing 5 of 160 matching Sigma rules.

References

Event ID 4105 — Started invocation of ScriptBlock ID: %1 Runspace ID: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Started invocation of ScriptBlock ID: %1
Runspace ID: %2

Fields

NameDescription
ScriptBlockIdStarted invocation of ScriptBlock ID.
RunspaceId

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4105
  version: 1
  level: 5
  task: 102
  opcode: 15
  keywords: 0
  time_created: '2023-11-06T01:35:05.999333+00:00'
  event_record_id: 906
  correlation:
    ActivityID: E4DB489E-1037-0000-CC79-E9E43710DA01
  execution:
    process_id: 15468
    thread_id: 15184
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  ScriptBlockId: 4b7eebd5-d6e3-46f7-b795-a7d9736e5810
  RunspaceId: 6fa4bb48-d600-4d4b-b445-e1fa0a41db53
message: ''

References

Event ID 4106 — Completed invocation of ScriptBlock ID: %1 Runspace ID: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Completed invocation of ScriptBlock ID: %1
Runspace ID: %2

Fields

NameDescription
ScriptBlockIdCompleted invocation of ScriptBlock ID.
RunspaceId

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 4106
  version: 1
  level: 5
  task: 103
  opcode: 15
  keywords: 0
  time_created: '2023-11-06T01:35:05.993908+00:00'
  event_record_id: 905
  correlation:
    ActivityID: E4DB489E-1037-0002-FB44-ECE43710DA01
  execution:
    process_id: 15468
    thread_id: 15184
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  ScriptBlockId: 6baf0dc7-a83f-43e1-bb6a-d7ab8d05eeb0
  RunspaceId: 6fa4bb48-d600-4d4b-b445-e1fa0a41db53
message: ''

References

Event ID 7937 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
Context
User_Data
ContextInfo
UserData
Payload

Event ID 7938 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
Context
User_Data
ContextInfo
UserData
Payload

Event ID 7939 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
Context
User_Data
ContextInfo
UserData
Payload

Event ID 7940 — %3 Context: %1 User Data: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

%3

Context:
%1

User Data:
%2

Fields

NameDescription
Context
User_Data
ContextInfo
UserData
Payload

Event ID 7941 — Correlating activity id's.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Correlating activity id's. 
 	 CurrentActivityId: %1 
 	 ParentActivityId: %2

Fields

NameDescription
CurrentActivityId
ParentActivityId
currentActivityId
parentActivityId

Event ID 7942 — Class Name = %1 Method Name = %2 Workflow GUID = %3 Message = %4 %5 Activity Name = %6 Activity GUID = %7 Parameters = %8.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Class Name = %1
Method Name = %2
Workflow GUID = %3
Message = %4
%5
Activity Name = %6
Activity GUID = %7
Parameters = %8

Fields

NameDescription
ClassName
MethodName
WorkflowGuid
Message
JobData
ActivityName
ActivityGuid
Parameters

Event ID 8193 — Creating Runspace object Instance Id.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Creating Runspace object 
 	 Instance Id: %1

Fields

NameDescription
InstanceId

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 8193
  version: 1
  level: 5
  task: 1
  opcode: 16
  keywords: 0
  time_created: '2022-04-07T17:06:32.284732+00:00'
  event_record_id: 9
  correlation:
    ActivityID: C88130F4-85B6-4F22-BDD1-6F6F4B29582D
  execution:
    process_id: 5272
    thread_id: 5572
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  param1: c88130f4-85b6-4f22-bdd1-6f6f4b29582d
message: ''

References

Event ID 8194 — Creating RunspacePool object InstanceId %1 MinRunspaces %2 MaxRunspaces %3.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Creating RunspacePool object 
 	 InstanceId %1 
 	 MinRunspaces %2 
 	 MaxRunspaces %3

Fields

NameDescription
InstanceId
MaxRunspaces
MinRunspaces

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 8194
  version: 1
  level: 5
  task: 1
  opcode: 16
  keywords: 0
  time_created: '2022-04-07T17:21:29.409715+00:00'
  event_record_id: 146
  correlation:
    ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
  execution:
    process_id: 4444
    thread_id: 4780
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
  InstanceId: 1480b89f-e871-42e4-bfb4-c8f88b053137
  MaxRunspaces: '2'
  MinRunspaces: '10'
message: ''

References

Event ID 8195 — Opening RunspacePool

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
5
Samples
1

Message

Opening RunspacePool

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 8195
  version: 1
  level: 5
  task: 1
  opcode: 10
  keywords: 0
  time_created: '2022-04-07T17:21:29.483155+00:00'
  event_record_id: 147
  correlation:
    ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
  execution:
    process_id: 4444
    thread_id: 4780
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 8196 — Modifying activity Id and correlating

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

Modifying activity Id and correlating

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 8196
  version: 1
  level: 4
  task: 0
  opcode: 20
  keywords: 0
  time_created: '2022-04-07T17:21:43.024925+00:00'
  event_record_id: 191
  correlation:
    ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
  execution:
    process_id: 4444
    thread_id: 940
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 8197 — Runspace state changed to %1.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Runspace state changed to %1

Fields

NameDescription
param1

Event ID 8198 — Attempting session creation retry %1 for error code %2 on session Id %3.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Attempting session creation retry %1 for error code %2 on session Id %3

Fields

NameDescription
param1
param2
param3

Event ID 12033 — Port resolved to %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Port resolved to %1

Fields

NameDescription
param1

Event ID 12034 — AppName resolved to %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

AppName resolved to %1

Fields

NameDescription
param1

Event ID 12035 — ComputerName resolved to %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

ComputerName resolved to %1

Fields

NameDescription
param1

Event ID 12036 — Scheme is %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Scheme is %1

Fields

NameDescription
param1

Event ID 12037 — Test analytic message

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Test analytic message

Event ID 12038 — Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 OpenTimeout: %4 IdleTimeout: %5 CancelTimeout: %6 AuthenticationMechanism: %7...

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Connection Paramters are 
 Connection URI: %1 
 Resource URI: %2 
 User: %3 
 OpenTimeout: %4 
 IdleTimeout: %5 
 CancelTimeout: %6 
 AuthenticationMechanism: %7 
 Thumb Print: %8 
 MaxUriRedirectionCount: %9 
 MaxReceivedDataSizePerCommand: %10 
 MaxReceivedObjectSize: %11

Fields

NameDescription
Connection_URI
Resource_URI
User
OpenTimeout
IdleTimeout
CancelTimeout
AuthenticationMechanism
Thumb_Print
MaxUriRedirectionCount
MaxReceivedDataSizePerCommand
MaxReceivedObjectSize
uri
shell
userName
opentimeout
idletimeout
canceltimeout
auth
thumbPrint
redircount
recvdDataSize
recvdObjSize

Event ID 12039 — Modifying activity Id and correlating

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

Modifying activity Id and correlating

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 12039
  version: 1
  level: 4
  task: 0
  opcode: 20
  keywords: 0
  time_created: '2022-04-07T17:21:43.024926+00:00'
  event_record_id: 192
  correlation:
    ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
  execution:
    process_id: 4444
    thread_id: 940
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''

References

Event ID 16385 — AmsiUtil state.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

AmsiUtil state. 
 	 state: %1 
 	 Context: %2

Fields

NameDescription
state
Context
Action
AmsiContext

Event ID 24577 — Windows PowerShell ISE has started to run script file %1.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE has started to run script file %1.

Fields

NameDescription
FileName

Event ID 24578 — Windows PowerShell ISE has started to run a user-selected script from file %1.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE has started to run a user-selected script from file %1.

Fields

NameDescription
FileName

Event ID 24579 — Windows PowerShell ISE is stopping the current command.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is stopping the current command.

Event ID 24580 — Windows PowerShell ISE is resuming the debugger.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is resuming the debugger.

Event ID 24581 — Windows PowerShell ISE is stopping the debugger.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is stopping the debugger.

Event ID 24582 — Windows PowerShell ISE is stepping into debugging.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is stepping into debugging.

Event ID 24583 — Windows PowerShell ISE is stepping over debugging.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is stepping over debugging.

Event ID 24584 — Windows PowerShell ISE is stepping out of debugging.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is stepping out of debugging.

Event ID 24592 — Windows PowerShell ISE is enabling all breakpoints.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is enabling all breakpoints.

Event ID 24593 — Windows PowerShell ISE is disabling all breakpoints.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is disabling all breakpoints.

Event ID 24594 — Windows PowerShell ISE is removing all breakpoints.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is removing all breakpoints.

Event ID 24595 — Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is setting the breakpoint at line #: %1 of file %2.

Fields

NameDescription
CurrentLine
FileName

Event ID 24596 — Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is removing the breakpoint on line #: %1 of file %2.

Fields

NameDescription
CurrentLine
FileName

Event ID 24597 — Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is enabling the breakpoint on line #: %1 of file %2.

Fields

NameDescription
CurrentLine
FileName

Event ID 24598 — Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE is disabling the breakpoint on line #: %1 of file %2.

Fields

NameDescription
CurrentLine
FileName

Event ID 24599 — Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell ISE has hit a breakpoint on line #: %1 of file %2.

Fields

NameDescription
CurrentLine
FileName

Event ID 28673 — Successfully rehydrated an object.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Successfully rehydrated an object. 
 	 Deserialized type name: %1 
 	 Rehydrated by casting to type: %2 
 	 Rehydrated object is of type: %3

Fields

NameDescription
DeserializedType
CastedToType
RehydratedType

Event ID 28674 — Failed to rehydrated an object.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Failed to rehydrated an object. 
 	 Deserialized type name: %1 
 	 Rehydrated by casting to type: %2 
 	 Type cast exception: %3 
 	 Type cast inner exception: %4

Fields

NameDescription
DeserializedType
CastedToType
TypeCastException
TypeCastInnerException

Event ID 28675 — Serialization depth has been overriden.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization depth has been overriden. 
 	 Serialized type name: %1 
 	 Original depth: %2 
 	 Overriden depth: %3 
 	 Current depth below top level: %4

Fields

NameDescription
Serialized_type_name
Original_depth
Overriden_depth
Current_depth_below_top_level
SerializedType
OriginalDepth
OverridenDepth
CurrentDepthBelowTopLevel

Event ID 28676 — Serialization mode has been overriden.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization mode has been overriden. 
 	 Serialized type name: %1 
 	 Overriden mode: %2

Fields

NameDescription
Serialized_type_name
Overriden_mode
SerializedType
OverridenMode

Event ID 28677 — Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization of a script property has been skipped, because there is no runspace to use for evaluation of the property. 
 	 Property name: %1 
 	 Property owner's type name: %2 
 	 Getter script: %3

Fields

NameDescription
Property_name
Property_owners_type_nameProperty owner's type name.
Getter_script
PropertyName
PropertyOwnerType
GetterScript

Event ID 28678 — Serialization of a property has been skipped, because property getter failed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization of a property has been skipped, because property getter failed. 
 	 Property name: %1 
 	 Property owner's type name: %2 
 	 Exception from property getter: %3 
 	 Inner exception from property getter: %4

Fields

NameDescription
PropertyName
PropertyOwnerType
Exception
InnerException

Event ID 28679 — Serialization of an enumerable object might not be complete, because object being enumerated threw an exception.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization of an enumerable object might not be complete, because object being enumerated threw an exception. 
 	 Type of object being enumerated: %1 
 	 Exception: %2

Fields

NameDescription
TypeBeingEnumerated
Exception

Event ID 28680 — Serialization called object's ToString method which failed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization called object's ToString method which failed. 
 	 Type of object: %1 
 	 Exception: %2

Fields

NameDescription
Type
Exception

Event ID 28682 — Maximum depth below top level has been reached, forcing object to be serialized as strings.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Maximum depth below top level has been reached, forcing object to be serialized as strings. 
 	 Object type at max depth: %1 
 	 Property name at max depth: %2 
 	 Depth: %3

Fields

NameDescription
Object_type_at_max_depth
Property_name_at_max_depth
Depth
TypeOfObjectAtMaxDepth
PropertyNameAtMaxDepth

Event ID 28683 — XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format).

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

XmlException has been thrown by the deserializer (most likely indicating incorrect clixml format). 
 	 Line number: %1 Line position: %2 
 	 Exception: %3

Fields

NameDescription
Line_number
Line_position
Exception
LineNumber
LinePosition

Event ID 28684 — Serialization of specified properties failed, because one of the specified properties was missing.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Serialization of specified properties failed, because one of the specified properties was missing. 
 	 Type of object: %1 
 	 Property name: %2

Fields

NameDescription
TypeOfObjectWithMissingProperty
PropertyName

Event ID 32769 — Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 TargetInterface: %5.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Received object with Runspace Id: %1 Command Id: %2 Destination: %3 DataType: %4 TargetInterface: %5

Fields

NameDescription
Runspace_InstanceId
PowerShell_InstanceId
Destination
DataType
TargetInterface

Event ID 32775 — An unhandled exception occurred in the appdomain.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

An unhandled exception occurred in the appdomain. 
Exception Type: %1 
Exception Message: %2 
Exception StackTrace: %3

Fields

NameDescription
param1
param2
param3

Event ID 32776 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. 
 Error message: %4 
 StackTrace: %5

Fields

NameDescription
SessionId
PipelineId
ErrorCode
ErrorMessage
StackTrace

Event ID 32777 — An unhandled exception occurred in the appdomain.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

An unhandled exception occurred in the appdomain. 
Exception Type: %1 
Exception Message: %2 
Exception StackTrace: %3

Fields

NameDescription
param1
param2
param3

Event ID 32784 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Runspace Id: %1 Pipeline Id: %2. WSMan reported an error with error code: %3. 
 Error message: %4 
 StackTrace: %5

Fields

NameDescription
SessionId
PipelineId
ErrorCode
ErrorMessage
StackTrace

Event ID 32785 — Runspace Id %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id %1. Establishing a connection using WSMan Create Shell

Fields

NameDescription
param1

Event ID 32786 — Runspace Id %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id %1. Callback received for WSMan Create Shell

Fields

NameDescription
param1

Event ID 32787 — Runspace Id.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1. Closing shell using WSManCloseShell

Fields

NameDescription
param1

Event ID 32788 — Runspace Id.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1. Callback received for WSManCloseShell

Fields

NameDescription
param1

Event ID 32789 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. Sending data of size %3

Fields

NameDescription
Runspace_Id
Pipeline_Id
SessionId
PipelineId
DataSize

Event ID 32790 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. Callback received for WSManSendShellInputEx

Fields

NameDescription
Runspace_Id
Pipeline_Id
SessionId
PipelineId

Event ID 32791 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. Placing Receive request using WSManReceiveShellOutputEx

Fields

NameDescription
Runspace_Id
Pipeline_Id
SessionId
PipelineId

Event ID 32792 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. Received Data of size %3.

Fields

NameDescription
Runspace_Id
Pipeline_Id
SessionId
PipelineId
DataSize

Event ID 32793 — Runspace Id %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id %1 Pipeline Id %2. Establishing a command connection using WSManRunShellCommandEx

Fields

NameDescription
SessionId
PipelineId

Event ID 32800 — Runspace Id %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id %1 Pipeline Id %2. Callback received for command connection

Fields

NameDescription
SessionId
PipelineId

Event ID 32801 — Runspace Id: %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id %2. Closing transport for command

Fields

NameDescription
Runspace_Id
SessionId
PipelineId

Event ID 32802 — Runspace Id: %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id %2. Callback received for command close

Fields

NameDescription
Runspace_Id
SessionId
PipelineId

Event ID 32803 — Runspace Id: %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id %2. Sending signal with code %3 using WSManSignalShellEx

Fields

NameDescription
Runspace_Id
SessionId
PipelineId
SignalCode

Event ID 32804 — Runspace Id: %1 Pipeline Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id %2. Callback received for WSManSignalShellEx

Fields

NameDescription
Runspace_Id
SessionId
PipelineId

Event ID 32805 — Runspace Id.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1. Connection is getting redirected to Uri: %2

Fields

NameDescription
SessionId
Uri

Event ID 32849 — Runspace Id: %1 Pipeline Id: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace Id: %1 Pipeline Id: %2. Server is sending data of size %3 to client. DataType: %4 TargetInterface: %5

Fields

NameDescription
Runspace_Id
Pipeline_Id
TargetInterface3 to client. DataType.
Runspace_InstanceId
PowerShell_InstanceId
DataSize
DataType

Event ID 32850 — Request %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Request %1. Creating a server remote session. UserName: %2 Custome Shell Id: %3

Fields

NameDescription
param1
param2
param3

Event ID 32851 — Reporting context for request: %1 Context Reported: %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Reporting context for request: %1 Context Reported: %1

Fields

NameDescription
param1
param2

Event ID 32852 — Reporting operation complete for request: %1 Error Code: %2 Error Message: %3 StackTrace: %4.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Reporting operation complete for request: %1 
 Error Code: %2 
 Error Message: %3 
 StackTrace: %4

Fields

NameDescription
param1
param2
param3
param4

Event ID 32853 — Shell Context %1.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shell Context %1. Request Id %2. Creating a commonad session for running a command.

Fields

NameDescription
param1
param2

Event ID 32854 — Shell Context %1 Command Context %2 Request Id %3.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shell Context %1 Command Context %2 Request Id %3. Stopping command.

Fields

NameDescription
param1
param2
param3

Event ID 32855 — Shell Context %1 Command Context %2 Request Id %3.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shell Context %1 Command Context %2 Request Id %3. Received data from client.

Fields

NameDescription
param1
param2
param3

Event ID 32856 — Shell Context %1 Command Context %2 Request Id %3.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shell Context %1 Command Context %2 Request Id %3. Client sent a receive request so that server can send data.

Fields

NameDescription
param1
param2
param3

Event ID 32857 — Shell Context %1 Command Context %2 IsReceiveOperation %3.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shell Context %1 Command Context %2 IsReceiveOperation %3. Got close operation request.

Fields

NameDescription
param1
param2
param3

Event ID 32865 — Loading assembly %1 for custom shell with shell Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Loading assembly %1 for custom shell with shell Id %2

Fields

NameDescription
param1
param2

Event ID 32866 — Loading type %1 for custom shell with shell Id %2.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Loading type %1 for custom shell with shell Id %2

Fields

NameDescription
param1
param2

Event ID 32867 — Received remoting fragment.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Received remoting fragment. 
 	 Object Id: %1 
 	 Fragment Id: %2 
 	 Start Flag: %3 
 	 End Flag: %4 
 	 Payload Length: %5 
 	 Payload Data: %6

Fields

NameDescription
Object_Id
Fragment_Id
Start_Flag
End_Flag
Payload_Length
Payload_Data
ObjectId
FragmentId
sFlag
eFlag
FragmentLength
FragmentPayload

Event ID 32868 — Sent remoting fragment.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Sent remoting fragment. 
 	 Object Id: %1 
 	 Fragment Id: %2 
 	 Start Flag: %3 
 	 End Flag: %4 
 	 Payload Length: %5 
 	 Payload Data: %6

Fields

NameDescription
Object_Id
Fragment_Id
Start_Flag
End_Flag
Payload_Length
Payload_Data
ObjectId
FragmentId
sFlag
eFlag
FragmentLength
FragmentPayload

Event ID 32869 — Shutting down winrm service.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Shutting down winrm service.

Event ID 40961 — PowerShell console is starting up

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

PowerShell console is starting up

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 40961
  version: 1
  level: 4
  task: 4
  opcode: 1
  keywords: 0
  time_created: '2023-11-06T01:18:27.730646+00:00'
  event_record_id: 772
  correlation:
    ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
  execution:
    process_id: 12192
    thread_id: 16872
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''

References

Event ID 40962 — PowerShell console is ready for user input

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

PowerShell console is ready for user input

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 40962
  version: 1
  level: 4
  task: 4
  opcode: 2
  keywords: 0
  time_created: '2023-11-06T01:18:31.505927+00:00'
  event_record_id: 788
  correlation:
    ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
  execution:
    process_id: 12192
    thread_id: 16872
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''

References

Event ID 45057 — Tracing ErrorRecord: Message: %1 CategoryInfo.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Tracing ErrorRecord: 
 Message: %1 
 CategoryInfo.Category: %2 
 CategoryInfo.Reason : %3 
 CategoryInfo.TargetName : %4 
 FullyQualifiedErrorId: %5 
 Exception Details: 
 Message : %6 
 Stack Trace: %7 
 InnerException %8

Fields

NameDescription
Message[Tracing ErrorRecord] Message.
CategoryInfoCategory[Tracing ErrorRecord] CategoryInfo.Category.
CategoryInfoReason[Tracing ErrorRecord] CategoryInfo.Reason.
CategoryInfoTargetName[Tracing ErrorRecord] CategoryInfo.TargetName.
FullyQualifiedErrorId[Tracing ErrorRecord] FullyQualifiedErrorId.
Message[Exception Details] Message.
Stack_Trace[Exception Details] Stack Trace.
Category
Reason
TargetName
ExceptionMessage
ExceptionStackTrace
ExceptionInnerException

Event ID 45058 — Exception: Message: %1 StackTrace: %2 InnerException : %3.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Exception: 
 Message: %1 
 StackTrace: %2 
 InnerException : %3

Fields

NameDescription
param1
param2
param3

Event ID 45059 — Tracing PSObject

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Tracing PSObject

Event ID 45060 — Tracing Job: Id: %1 InstanceId: %2 Name: %3 Location: %4 State: %5 Command: %6.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Tracing Job: 
 Id: %1 
 InstanceId: %2 
 Name: %3 
 Location: %4 
 State: %5 
 Command: %6

Fields

NameDescription
Id[Tracing Job] Id.
InstanceId[Tracing Job] InstanceId.
Name[Tracing Job] Name.
Location[Tracing Job] Location.
State[Tracing Job] State.
Command[Tracing Job] Command.

Event ID 45061 — Trace Information.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Trace Information: 
 %1

Fields

NameDescription
param1

Event ID 45062 — Connection Paramters are Connection URI: %1 Resource URI: %2 User: %3 OpenTimeout: %4 IdleTimeout: %5 CancelTimeout: %6 AuthenticationMechanism: %7...

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Connection Paramters are 
 Connection URI: %1 
 Resource URI: %2 
 User: %3 
 OpenTimeout: %4 
 IdleTimeout: %5 
 CancelTimeout: %6 
 AuthenticationMechanism: %7 
 Thumb Print: %8 
 MaxUriRedirectionCount: %9 
 MaxReceivedDataSizePerCommand: %10 
 MaxReceivedObjectSize: %11

Fields

NameDescription
Connection_URI
Resource_URI
User
OpenTimeout
IdleTimeout
CancelTimeout
AuthenticationMechanism
Thumb_Print
MaxUriRedirectionCount
MaxReceivedDataSizePerCommand
MaxReceivedObjectSize
uri
shell
userName
opentimeout
idletimeout
canceltimeout
auth
thumbPrint
redircount
recvdDataSize
recvdObjSize

Event ID 45063 — Workflow plugin loaded.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow plugin loaded. 
 	 EndpointName: %1 
 	 User: %2 
 	 HostingMode: %3 
 	 Protocol: %4 
 	 Configuration: 
 %5

Fields

NameDescription
EndpointName
User
HostingMode
Protocol
Configuration
endpointName
user
hostingMode
protocol
configuration

Event ID 45064 — Workflow execution started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow execution started. 
 	 WorkflowId: %1 
 	 ManagedNodes: %2

Fields

NameDescription
WorkflowId
ManagedNodes
workflowId
managedNodes

Event ID 45065 — Workflow state changed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow state changed. 
 	 WorkflowId: %1 
 	 NewState: %2 
 	 OldState: %3

Fields

NameDescription
WorkflowId
NewState
OldState
workflowId
newState
oldState

Event ID 45072 — Workflow plugin has been requested for a shutdown.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow plugin has been requested for a shutdown. 
 	 EndpointName: %1

Fields

NameDescription
EndpointName
endpointName

Event ID 45073 — Workflow plugin restarted.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow plugin restarted. 
 	 EndpointName: %1

Fields

NameDescription
EndpointName
endpointName

Event ID 45074 — Workflow is resuming.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow is resuming. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45075 — A quota limit that was set for the endpoint was exceeded.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

A quota limit that was set for the endpoint was exceeded. 
 	 EndpointName: %1 
 	 ConfigName: %2 
 	 AllowedValue: %3 
 	 ValueInQuestion: %4

Fields

NameDescription
EndpointName
ConfigName
AllowedValue
ValueInQuestion
endpointName
configName
allowedValue
valueInQuestion

Event ID 45076 — Workflow has resumed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow has resumed. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45078 — Workflow runspace pool was created.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow runspace pool was created. 
 	 WorkflowId: %1 
 	 ManagedNode: %2

Fields

NameDescription
WorkflowId
ManagedNode
workflowId
managedNode

Event ID 45079 — Activity was queued for execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Activity was queued for execution. 
 	 WorkflowId: %1 
 	 ActivityName: %2

Fields

NameDescription
WorkflowId
ActivityName
workflowId
activityName

Event ID 45080 — Activity execution started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Activity execution started. 
 	 ActivityName: %1 
 	 ActivityTypeName: %2

Fields

NameDescription
ActivityName
ActivityTypeName
activityName
activityTypeName

Event ID 45081 — Workflow is being imported from a XAML file.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow is being imported from a XAML file. 
 	 WorkflowId: %1 
 	 XamlFile: %2

Fields

NameDescription
WorkflowId
XamlFile
workflowId
xamlFile

Event ID 45082 — Workflow has been imported from a XAML file.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow has been imported from a XAML file. 
 	 WorkflowId: %1 
 	 XamlFile: %2

Fields

NameDescription
WorkflowId
XamlFile
workflowId
xamlFile

Event ID 45083 — Workflow could not be imported from a XAML file because of an error.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow could not be imported from a XAML file because of an error. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields

NameDescription
WorkflowId
ErrorDescription
workflowId
errorDescription

Event ID 45084 — Workflow validation started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow validation started. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45085 — Workflow validation succeeded.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow validation succeeded. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45086 — Workflow validation failed with error.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow validation failed with error. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45087 — Workflow activity validated.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow activity validated. 
 	 WorkflowId: %1 
 	 ActivityDisplayName: %2 
 	 ActivityTypeName: %3

Fields

NameDescription
WorkflowId
ActivityDisplayName
ActivityTypeName
workflowId
activityDisplayName
activityType

Event ID 45088 — Workflow activity could not be validated.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow activity could not be validated. 
 	 WorkflowId: %1 
 	 ActivityDisplayName: %2 
 	 ActivityTypeName: %3

Fields

NameDescription
WorkflowId
ActivityDisplayName
ActivityTypeName
workflowId
activityDisplayName
activityType

Event ID 45089 — Activity execution failed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Activity execution failed. 
 	 WorkflowId: %1 
 	 ActivityName: %2 
 	 FailureDescription: %3

Fields

NameDescription
WorkflowId
ActivityName
FailureDescription
workflowId
activityName
failureDescription

Event ID 45090 — Runspace availability changed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace availability changed. 
 	 RunspaceId: %1 
 	 Availability: %2

Fields

NameDescription
RunspaceId
Availability
runspaceId
availability

Event ID 45091 — Runspace state changed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Runspace state changed. 
 	 RunspaceId: %1 
 	 NewState: %2 
 	 OldState: %3

Fields

NameDescription
RunspaceId
NewState
OldState
runspaceId
newState
oldState

Event ID 45092 — Workflow loaded for execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow loaded for execution. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45093 — Workflow unloaded.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow unloaded. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45094 — Workflow execution cancelled.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow execution cancelled. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45095 — Workflow execution aborted.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow execution aborted. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45096 — Workflow cleanup operation executed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow cleanup operation executed. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45097 — Persisted workflow loaded from disk.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Persisted workflow loaded from disk. 
 	 WorkflowId: %1 
 	 Path: %2

Fields

NameDescription
WorkflowId
Path
workflowId
path

Event ID 45098 — Workflow data was deleted from disk.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow data was deleted from disk. 
 	 WorkflowId: %1 
 	 Path: %2

Fields

NameDescription
WorkflowId
Path
workflowId
path

Event ID 45100 — Starting remove job.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Starting remove job. 
 	 JobId: %1

Fields

NameDescription
JobId
jobId

Event ID 45101 — Job state changed.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Job state changed. 
 	 JobId: %1 
 	 WorkflowId: %2 
 	 NewState: %3 
 	 OldState: %4

Fields

NameDescription
JobId
WorkflowId
NewState
OldState
jobId
workflowId
newState
oldState

Event ID 45102 — Job error.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Job error. 
 	 JobId: %1 
 	 WorkflowId: %2 
 	 ErrorDescription: %3

Fields

NameDescription
JobId
WorkflowId
ErrorDescription
jobId
workflowId
errorDescription

Event ID 45104 — Job created for workflow (child job).

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Job created for workflow (child job). 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 ChildWorkflowId: %3

Fields

NameDescription
ParentJobId
ChildJobId
ChildWorkflowId
parentJobId
childJobId
childWorkflowId

Event ID 45105 — Parent job created for workflow.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Parent job created for workflow. 
 	 JobId: %1

Fields

NameDescription
JobId
jobId

Event ID 45106 — All required jobs were created for workflow execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

All required jobs were created for workflow execution. 
 	 JobId: %1 
 	 WorkflowId: %2

Fields

NameDescription
JobId
WorkflowId
jobId
workflowId

Event ID 45107 — Child job removed for workflow.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Child job removed for workflow. 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 WorkflowId: %3

Fields

NameDescription
ParentJobId
ChildJobId
WorkflowId
parentJobId
childJobId
workflowId

Event ID 45108 — An error occurred while removing job.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

An error occurred while removing job. 
 	 ParentJobId: %1 
 	 ChildJobId: %2 
 	 WorkflowId: %3 
 	 Error: %4

Fields

NameDescription
ParentJobId
ChildJobId
WorkflowId
Error
parentJobId
childJobId
workflowId
error

Event ID 45109 — Loading workflow for execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Loading workflow for execution. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45110 — Workflow execution finished.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow execution finished. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45111 — Cancelling workflow execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Cancelling workflow execution. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45112 — Aborting workflow execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Aborting workflow execution. 
 	 WorkflowId: %1 
 	 Reason: %2

Fields

NameDescription
WorkflowId
Reason
workflowId
reason

Event ID 45113 — Unloading workflow.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Unloading workflow. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45114 — Forced workflow shutdown started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Forced workflow shutdown started. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45115 — Forced workflow shutdown finished.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Forced workflow shutdown finished. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45116 — An error occurred while forcefully shutting down a workflow.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

An error occurred while forcefully shutting down a workflow. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields

NameDescription
WorkflowId
ErrorDescription
workflowId
errorDescription

Event ID 45117 — Persisting workflow to disk.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Persisting workflow to disk. 
 	 WorkflowId: %1 
 	 PersistPath: %2

Fields

NameDescription
WorkflowId
PersistPath
workflowId
persistPath

Event ID 45118 — Workflow persisted to disk.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow persisted to disk. 
 	 WorkflowId: %1

Fields

NameDescription
WorkflowId
workflowId

Event ID 45119 — Activity execution finished.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Activity execution finished. 
 	 ActivityName: %1

Fields

NameDescription
ActivityName
activityName

Event ID 45120 — Workflow execution error.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow execution error. 
 	 WorkflowId: %1 
 	 ErrorDescription: %2

Fields

NameDescription
WorkflowId
ErrorDescription
workflowId
errorDescription

Event ID 45121 — A new PowerShell endpoint was registered.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

A new PowerShell endpoint was registered. 
 	 EndpointName: %1 
 	 EndpointType: %2 
 	 RegisteredBy: %3

Fields

NameDescription
EndpointName
EndpointType
RegisteredBy
endpointName
endpointType
registeredBy

Event ID 45122 — Endpoint configuration modified.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Endpoint configuration modified. 
 	 EndpointName: %1 
 	 ModifiedBy: %2

Fields

NameDescription
EndpointName
ModifiedBy
endpointName
modifiedBy

Event ID 45123 — Endpoint configuration unregistered.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Endpoint configuration unregistered. 
 	 EndpointName: %1 
 	 UnregisteredBy: %2

Fields

NameDescription
EndpointName
UnregisteredBy
endpointName
unregisteredBy

Event ID 45124 — Endpoint configuration disabled.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Endpoint configuration disabled. 
 	 EndpointName: %1 
 	 DisabledBy: %2

Fields

NameDescription
EndpointName
DisabledBy
endpointName
disabledBy

Event ID 45125 — Endpoint configuration enabled.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Endpoint configuration enabled. 
 	 EndpointName: %1 
 	 EnabledBy: %2

Fields

NameDescription
EndpointName
EnabledBy
endpointName
enabledBy

Event ID 45126 — Out of process runspace started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Out of process runspace started. 
 	 Command: %1

Fields

NameDescription
Command
command

Event ID 45127 — Parameter splatting was performed during workflow execution.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Parameter splatting was performed during workflow execution. 
 	 Parameters: %1 
 	 Computers: %2

Fields

NameDescription
Parameters
Computers
parameters
computers

Event ID 45128 — Workflow engine started.

Provider
Microsoft-Windows-PowerShell
Channel
Analytic

Message

Workflow engine started. 
 	 EndpointName: %1

Fields

NameDescription
EndpointName
endpointName

Event ID 45129 — Workflow manager instantiated with CheckpointPath: %1 ConfigProviderId: %2 UserName: %3 Path: %4.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Workflow manager instantiated with 
 	 CheckpointPath: %1 
 	 ConfigProviderId: %2 
 	 UserName: %3 
 	 Path: %4

Fields

NameDescription
CheckpointPath
ConfigProviderId
UserName
Path
checkpointPath
configProviderId
userName
path

Event ID 46337 — BEGIN ImportWorkflowCommand::StartWorkflowApplication.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN ImportWorkflowCommand::StartWorkflowApplication. Starting invocation of workflow function. Tracking Guid %1

Fields

NameDescription
TrackingId

Event ID 46338 — END ImportWorkflowCommand::StartWorkflowApplication.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END ImportWorkflowCommand::StartWorkflowApplication. Ending invocation of workflow function. Tracking Guid %1

Fields

NameDescription
TrackingId

Event ID 46339 — BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields

NameDescription
TrackingId

Event ID 46340 — END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1

Fields

NameDescription
TrackingId

Event ID 46341 — END Creating new job in ImportWorkflowCommand::StartWorkflowApplication.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END Creating new job in ImportWorkflowCommand::StartWorkflowApplication. Tracking Guid %1 : ContainerParentJob Guid %2

Fields

NameDescription
TrackingId
ContainerParentJobInstanceId

Event ID 46342 — BEGIN JobLogic ContainerParentJob Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN JobLogic ContainerParentJob Guid %1

Fields

NameDescription
WorkflowJobJobInstanceId

Event ID 46343 — END JobLogic ContainerParentJob Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END JobLogic ContainerParentJob Guid %1

Fields

NameDescription
WorkflowJobJobInstanceId

Event ID 46344 — BEGIN WorkflowExecution ContainerParentJob Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN WorkflowExecution ContainerParentJob Guid %1

Fields

NameDescription
WorkflowJobJobInstanceId

Event ID 46345 — END WorkflowExecution ContainerParentJob Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END WorkflowExecution ContainerParentJob Guid %1

Fields

NameDescription
WorkflowJobJobInstanceId

Event ID 46346 — WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

WorkflowJob with Guid %1 added to ContainerParentJob with Guid %2

Fields

NameDescription
WorkflowJobInstanceId
ContainerParentJobInstanceId

Event ID 46347 — ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

ProxyJob with Guid %1 associated with remote ContainerParentJob with Guid %2

Fields

NameDescription
ProxyJobInstanceId
ContainerParentJobInstanceId

Event ID 46348 — BEGIN Execution of ContainerParentJob with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN Execution of ContainerParentJob with Guid %1

Fields

NameDescription
ContainerParentJobInstanceId

Event ID 46349 — END Execution of ContainerParentJob with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END Execution of ContainerParentJob with Guid %1

Fields

NameDescription
ContainerParentJobInstanceId

Event ID 46350 — BEGIN Execution of Proxy Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN Execution of Proxy Job with Guid %1

Fields

NameDescription
ProxyJobInstanceId

Event ID 46351 — END Execution of Proxy Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END Execution of Proxy Job with Guid %1

Fields

NameDescription
ProxyJobInstanceId

Event ID 46352 — BEGIN StateChanged event handler for Proxy Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN StateChanged event handler for Proxy Job with Guid %1

Fields

NameDescription
ProxyJobInstanceId

Event ID 46353 — END StateChanged event handler for Proxy Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END StateChanged event handler for Proxy Job with Guid %1

Fields

NameDescription
ProxyJobInstanceId

Event ID 46354 — BEGIN StateChanged event handler for Proxy Child Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN StateChanged event handler for Proxy Child Job with Guid %1

Fields

NameDescription
ProxyChildJobInstanceId

Event ID 46355 — END StateChanged event handler for Proxy Child Job with Guid %1.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END StateChanged event handler for Proxy Child Job with Guid %1

Fields

NameDescription
ProxyChildJobInstanceId

Event ID 46356 — BEGIN Running garbage collection

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

BEGIN Running garbage collection

Event ID 46357 — END Running garbage collection

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

END Running garbage collection

Event ID 46358 — Persistence store has reached its maximum specified size

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Persistence store has reached its maximum specified size

Event ID 49152 —

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

%1

Fields

NameDescription
message

Event ID 49153 — Trace Information: %1 %2.

Provider
Microsoft-Windows-PowerShell
Channel
Debug

Message

Trace Information: 
 %1 %2

Fields

NameDescription
param1
param2

Event ID 53249 — Scheduled Job %1 started at %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Scheduled Job %1 started at %2

Fields

NameDescription
ScheduledJobDefName
StartTime

Event ID 53250 — Scheduled Job %1 completed at %2 with state %3.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Scheduled Job %1 completed at %2 with state %3

Fields

NameDescription
ScheduledJobDefName
StopTime
State

Event ID 53251 — Scheduled Job Exception %1: Message: %2 StackTrace: %3 InnerException: %4.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Scheduled Job Exception %1: 
 Message: %2 
 StackTrace: %3 
 InnerException: %4

Fields

NameDescription
Message
StackTrace
InnerException
Name

Event ID 53504 — Windows PowerShell has started an IPC listening thread on process: %1 in AppDomain: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational
Level
4
Samples
1

Message

Windows PowerShell has started an IPC listening thread on process: %1 in AppDomain: %2.

Fields

NameDescription
param1Windows PowerShell has started an IPC listening thread on process.
param2in AppDomain.

Example Event

system:
  provider: Microsoft-Windows-PowerShell
  guid: A0C1853B-5C40-4B15-8766-3CF1C58F985A
  event_source_name: ''
  event_id: 53504
  version: 1
  level: 4
  task: 111
  opcode: 10
  keywords: 0
  time_created: '2023-11-06T01:18:29.006927+00:00'
  event_record_id: 774
  correlation:
    ActivityID: E4DB489E-1037-0002-CA26-E6E43710DA01
  execution:
    process_id: 12192
    thread_id: 10468
  channel: Microsoft-Windows-PowerShell/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
  param1: '12192'
  param2: DefaultAppDomain
message: ''

References

Event ID 53505 — Windows PowerShell has ended an IPC listening thread on process: %1 in AppDomain: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell has ended an IPC listening thread on process: %1 in AppDomain: %2.

Fields

NameDescription
param1
param2

Event ID 53506 — An error has occurred in Windows PowerShell IPC listening thread on process: %1 in AppDomain: %2.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

An error has occurred in Windows PowerShell IPC listening thread on process: %1 in AppDomain: %2.  Error Message: %3.

Fields

NameDescription
param1
param2
param3

Event ID 53507 — Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell IPC connect on process: %1 in AppDomain: %2 for User: %3.

Fields

NameDescription
param1
param2
param3

Event ID 53508 — Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.

Provider
Microsoft-Windows-PowerShell
Channel
Operational

Message

Windows PowerShell IPC disconnect on process: %1 in AppDomain: %2 for User: %3.

Fields

NameDescription
param1
param2
param3