Microsoft-Windows-PrintService

219 events across 3 channels

Event IDTitleChannel
1The print spooler failed to import the printer driver that was downloaded from …Operational
22Failed to upgrade printer settings for printer <PrinterName> driver …Operational
23Printer <PrinterName> failed to initialize because a suitable <DriverName> …Operational
99The print spooler encountered a fatal error while executing a critical operation …Admin
100Printer PrinterName successfully added.Debug
101Failed to add printer PrinterName, error code ErrorCode.Debug
104Deleting printer PrinterName succeeded.Debug
105Deleting printer PrinterName failed, error code ErrorCode.Debug
106Starting document job JobID for printer PrinterName succeeded.Debug
107Starting document job JobID for printer PrinterName failed, error code …Debug
110Ending document job JobID for printer PrinterName succeeded.Debug
111Ending document job JobID for printer PrinterName failed, error code ErrorCode.Debug
114Adding printer driver ObjectName succeeded.Debug
115Adding printer driver ObjectName failed, error code ErrorCode.Debug
118Opening printer ObjectName succeeded.Debug
119Opening printer ObjectName failed, error code ErrorCode.Debug
122Starting page job JobID at printer PrinterName succeeded.Debug
123Starting page failed at printer JobID, error code ErrorCode.Debug
124Ending page job JobID at printer PrinterName succeeded.Debug
125Ending page job JobID at printer PrinterName failed, error code ErrorCode.Debug
131Setting printer PrinterName failed, error code ErrorCode.Debug
200Adding CSR printer connection ObjectName succeeded.Debug
201Adding CSR printer connection ObjectName failed, error code ErrorCode.Debug
204Deleting CSR printer connection ObjectName succeeded.Debug
205Deleting CSR printer connection ObjectName failed, error code ErrorCode.Debug
207Opening CSR printer ObjectName failed, error code ErrorCode.Debug
210Closing CSR printer ObjectName succeeded.Debug
211Closing CSR printer ObjectName failed, error code ErrorCode.Debug
212Parsing inf (InfPath) for printer driver DriverName succeeded (processor …Debug
213Parsing inf (InfPath) for printer driver DriverName failed (processor …Operational
214Installing printer driver DriverName succeeded.Debug
215Installing printer driver DriverName failed, error code LastError, HRESULT …Admin
216A printer setup operation succeeded during the installation process.Debug
217A printer setup operation failed during the installation process, error code …Operational
218Copying printer driver package InfPath succeeded.Operational
219Copying printer driver package InfPath failed, error code LastError, HRESULT …Operational
220Retrieving CSR cache information for printer ObjectName succeeded.Operational
221Retrieving CSR cache information for printer ObjectName failed, error code …Operational
222Message.Debug
223Message.Debug
224A remote print driver package operation Function failed with error code Error, …Operational
225An error occurred while installing printer driver 'DriverName'.Admin
226An error occurred while installing printer driver 'DriverName'.Admin
227An error occurred while installing printer driver 'DriverName'.Admin
228An error occurred while installing printer driver 'DriverName'.Admin
229An error occurred while installing printer driver 'DriverName'.Operational
230A problem was encountered while installing printer driver 'DriverName'.Admin
231An attempt was made to upgrade installed class driver 'DriverName' to a …Operational
232An attempt was made to upgrade installed printer driver 'DriverName' to an older …Admin
233An attempt was made to upgrade installed printer driver 'DriverName' to a …Admin
234A problem was encountered while deleting printer driver 'DriverName'.Operational
235An error occurred while installing printer driver 'DriverName'.Operational
236An error occurred while installing printer driver 'DriverName'.Operational
237An error occurred while installing printer driver 'DriverName'.Operational
238An error occurred while installing printer driver 'DriverName'.Operational
239An error occurred while installing printer driver 'DriverName'.Operational
240An error occurred while installing printer driver 'DriverName'.Operational
241An attempt was made to upgrade installed printer driver 'DriverName' to a driver …Admin
242An error occurred while configuring print queue 'PrinterName'.Admin
300Printer param1 was created.Operational
301Printer param1 was deleted, and users will no longer be able to print to this …Operational
302Printer param1 will be deleted.Operational
303Printer param1 was paused.Operational
304Printer param1 was resumed.Operational
305The jobs in the print queue for printer param1 were deleted.Operational
306Settings for printer param1 were changed.Operational
307Document param1, param2 owned by param3 on param4 was printed on param5 through …Operational
308Document param1, param2 owned by param3 was paused on param4.Operational
309Document param1, param2 owned by param3 was resumed on param4.Operational
310Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by …Operational
311An administrator moved document param1, param2 owned by param3 to position …Operational
312Form param1 was added.Operational
313Form param1 was removed.Operational
314Document param1, param2 owned by param3 timed out while printing on param4.Admin
315The print spooler failed to share printer param2 with shared resource name …Admin
316Printer driver param1 for param2 param3 was added or updated.Operational
317Printer driver param1 was deleted.Operational
318Failed to upgrade printer settings for printer param1 driver param2.Admin
319Printer param1 failed to initialize because a suitable param2 driver could not …Admin
320Printer param1 failed to initialize because none of its ports (param2) could be …Admin
321File(s) param1 associated with printer param2 were added or updated.Operational
322While attempting to publish the printer to the Active Directory directory …Admin
323While attempting to publish the printer to the Active Directory directory …Admin
325While attempting to remove the printer from the Active Directory directory …Admin
326While attempting to publish the printer to the Active Directory directory …Admin
327While attempting to publish the printer to the Active Directory directory …Admin
328While attempting to publish the printer to the Active Directory directory …Admin
329While attempting to publish the printer to the Active Directory directory …Admin
331While attempting to publish the printer to the Active Directory directory …Admin
332The printer was successfully published to the Active Directory directory …Operational
333While attempting to publish the printer to the Active Directory directory …Admin
334The printer was successfully removed from the Active Directory directory …Operational
335While attempting to remove the printer from the Active Directory directory …Admin
336Print queue param1 was successfully updated in the Active Directory directory …Operational
337The print queue could not be found on domain param1.Admin
338Printer param1 was successfully removed from the Active Directory directory …Operational
342The print spooler removed print queue param1 from the Active Directory directory …Operational
343The print spooler was unable to connect to print queue param1 based on the …Operational
344The print spooler removed print queue param1 from the Active Directory directory …Operational
345The print spooler removed print queue param1 from the Active Directory directory …Operational
346The print spooler removed print queue param1 from the Active Directory directory …Operational
347Print queue param1 could not be deleted (pruned) from the Active Directory …Admin
348This version of param1 is incompatible with this version of Windows.Admin
349The print spooler failed to create a symbolic link between …Admin
350Document param1 failed to print and was deleted because of corruption in the …Admin
351The attempt for param1 to use a Windows NT 4.Admin
352The priority of document param1, param2 owned by param3 was changed to param4 on …Operational
353The document failed to print because the user did not have the necessary …Admin
354param1 initialization failed at param2.Admin
356Failed to install or update driver param1 on cluster spooler resource param2.Admin
359The attempt to install printer param1 into an offline operating system image …Admin
360Updating the color profile failed for printer param1 with Win32 error code …Admin
361Printer param1 failed to initialize its ports.Admin
362The print spooler could not initialize because resolving the local machine name …Admin
363The print spooler param1 failed to start.Admin
364Windows could not load print processor param1 because EnumDatatypes did not …Admin
365Windows could not load print processor param1 because EnumDatatypes failed.Admin
366The print server security descriptor for param1 is invalid.Admin
367Windows could not initialize printer param1 because the print processor param2 …Admin
368The print spooler failed to verify printer driver package param1 for environment …Operational
369The print spooler failed to verify printer driver package for environment …Admin
370The print spooler failed to regenerate the printer driver information for driver …Admin
371The print spooler failed to unshare printer param2 which is shared as param3.Admin
372The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, …Admin
373The spooler has detected that a component has an unusually large number of open …Admin
502The print spooler failed to get the computer name.Admin
503The system failed to initialize the local print provider: Error Error.Admin
504Failed to initialize the router work crew: Error Error.Admin
505Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error.Admin
507The system failed to initialize the name cache: Error Error.Admin
508Failed to initialize the router cache: Error Error.Admin
509The print spooler cannot start because the PrinterBusEnumerator could not start.Admin
510InitializeProvider cannot allocate memory for Name.Admin
511The print spooler failed to load print provider Name.Admin
512InitializePrintProvider failed for provider Name.Admin
513Group Policy was unable to add per computer connection Name.Admin
514Group Policy was unable to delete per computer connection Name.Admin
515Group Policy was unable to delete per computer printer connection Name.Admin
516Group Policy was unable to deploy per computer printer connection Name.Admin
517Group Policy was unable to update per computer printer connection Name.Admin
518Group Policy was unable to delete the per user printer connection Name.Admin
519Group Policy was unable to deploy per user printer connection Name.Admin
520Group Policy was unable to update per user printer connection Name.Admin
600The print spooler failed to import the printer driver that was downloaded from …Admin
601The print spooler failed to download and import the printer driver from …Admin
602The print spooler failed to reopen an existing printer connection because it …Admin
603The print spooler failed to reopen an existing printer connection because it …Operational
604The print spooler encountered an unknown driver type while saving Name cache …Admin
701The print filter pipeline host cannot initialize with the Component Object Model …Operational
702The print filter pipeline host is shutting down due to the following error: …Operational
703The print filter pipeline host is shutting down due to an error in signaling the …Operational
704The print filter pipeline host is shutting down because the query interface for …Operational
800Spooling job JobDiag.JobId.Operational
801Printing job JobDiag.JobId.Operational
802Deleting job DeleteJobDiag.JobId.Operational
805Rendering job RenderJobDiag.JobId.Operational
806Pausing job JobId.Debug
807Resuming job JobId.Debug
808The print spooler failed to load a plug-in module PluginDllName, error code …Admin
809The print spooler failed to recursively delete the directory DirectoryName, …Operational
810The print spooler failed to delete the directory DirectoryName and the contained …Operational
811The print spooler failed to move the file Source to Destination, error code …Operational
812The print spooler failed to delete the file Source, error code ErrorCode.Operational
813The print spooler failed to copy the file Source to Destination, error code …Operational
814The print spooler failed to install the print processor Processor Environment …Operational
815The print spooler service failed to register the RPC server protocol sequence …Operational
816The print spooler service detected an invalid RPC protocol sequence …Operational
817The RPC end-point policy for the print spooler service is disabled.Operational
818The print spooler RPC server failed to start, error code ErrorCode.Operational
819Client Side Rendering is currently disabled by policy (Policy).Operational
820Client side rendering to PrintProcessor failed, error code ErrorCode.Operational
821The print spooler Client Side Rendering is attempting to render the job JobId on …Operational
822Unknown print processor (LocalPrintProcessor) or invalid data type …Operational
823The default printer was changed to NewDefaultPrinter.Admin
824A fatal error occurred while printing job DocumentName, id JobId on the print …Operational
825Client side rendering to PrintProcessor failed, error code ErrorCode.Operational
826Force Client Side Rendering policy was successfully set on printer PrinterName, …Operational
827The specified print queue QueueName is invalid.Operational
828The print job JobId failed with error code ErrorCode.Operational
829XPS API call Name (Context) started.Debug
830XPS API call Name (Context) ended, status StatusCode.Debug
831XPS API dependency Name (Context) started.Debug
832XPS API dependency Name (Context) ended, status StatusCode.Debug
833Print spooler operation Name (Context) started.Debug
834Print spooler operation Name (Context) ended, status StatusCode.Debug
842The print job PrintDriverSandboxJobPrintProc.JobId was sent through the print …Operational
843The print spooler service recorded SucceededRpcCalls successful and …Debug
844The print spooler selected the isolation mode IsolationMode (0 - loaded in the …Debug
845Attempted to load module Module for printer Printer, printer driver Driver.Debug
846Cached printer PrinterName has been scavenged and deleted.Operational
847Cached printer PrinterName has been scheduled for deletion due to a logon …Operational
848Printer PrinterName was shared by the print spooler as ShareName.Operational
849Printer PrinterName shared as ShareName was unshared by the print spooler.Operational
850The print spooler called the function Function in print driver module Driver.Operational
851Point and Print not allowed by policy for queue PrintQueue.Operational
852Driver OriginalDriver could not be installed for printer connection PrinterName.Admin
853Print Client Side Rendering synchronization for print job cache completed with …Debug
854Print Client Side Rendering synchronization for printer information cache …Debug
855OpenPrinter cache entry added for printer PrinterName with access code …Debug
856Connection 'ConnectionName' has been reconfigured for normal operation because …Operational
857Connection 'ConnectionName' has been reconfigured for normal operation because …Operational
858Connection 'ConnectionName' has been reconfigured for normal operation because …Admin
859Connection 'ConnectionName' has been reconfigured for normal operation because …Operational
860Connection 'ConnectionName' has been reconfigured for normal operation because …Operational
861Connection 'ConnectionName' has been reconfigured for normal operation because …Operational
862Connection 'ConnectionName' has been reconfigured for normal operation because …Admin
863Connection 'ConnectionName' has been reconfigured for normal operation due to an …Operational
864The Windows Fax and Scan servicing operation failed, HRESULT HResult.Operational
865There were Failures print job failures out of Jobs jobs sent to printer …Admin
866The print spooler failed to create a Plug and Play printer device object for the …Admin
867The WS-Print Port Monitor failed to initialize correctly.Admin
868The Offline EventLog on machine 'MachineName' exceeded the allow maximum size.Admin
869In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code …Admin
870The print spooler failed to download package for driver Driver.Admin
871The current print job was rejected due to Device Control Print Restrictions.Admin
1111Driver <DriverName> required for printer <PrinterName> is unknown.Operational
4098The computer <ComputerName or IP> preference item in the '{GUID}' Group Policy …Operational
4909Print Service event 4909 (manifest stub).Operational
8192The user <UserName> preference item in the '{GUID}' Group Policy object did not …Operational

Event ID 1 — The print spooler failed to import the printer driver that was downloaded from <ServerName> into the driver store for driver <DriverName>.

Provider
Microsoft-Windows-PrintService
Channel
Operational

Event ID 22 — Failed to upgrade printer settings for printer <PrinterName> driver <DriverName>.

Provider
Microsoft-Windows-PrintService
Channel
Operational

Event ID 23 — Printer <PrinterName> failed to initialize because a suitable <DriverName> driver could not be found.

Provider
Microsoft-Windows-PrintService
Channel
Operational

Event ID 99 — The print spooler encountered a fatal error while executing a critical operation (OperationCode, error Error) and must immediately terminate.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Processterminationduetocriticalfailure
Opcode
Unexpectedprocesstermination

Message #

The print spooler encountered a fatal error while executing a critical operation (%1, error %2) and must immediately terminate. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Fields #

NameDescription
OperationCode UInt32
Error HexInt32

Event ID 100 — Printer PrinterName successfully added.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer PrinterName successfully added. See the event user data for context information.

Message #

Printer %3 successfully added. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 101 — Failed to add printer PrinterName, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

Failed to add printer PrinterName, error code ErrorCode. See the event user data for context information.

Message #

Failed to add printer %3, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 104 — Deleting printer PrinterName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Deletingaprinter
Opcode
SpoolerOperationSucceeded

Description

Deleting printer PrinterName succeeded. See the event user data for context information.

Message #

Deleting printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 105 — Deleting printer PrinterName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Deletingaprinter
Opcode
SpoolerOperationFailed

Description

Deleting printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Deleting printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 106 — Starting document job JobID for printer PrinterName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Startingadocumentprintjob
Opcode
SpoolerOperationSucceeded

Description

Starting document job JobID for printer PrinterName succeeded. See the event user data for context information.

Message #

Starting document job %3 for printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 107 — Starting document job JobID for printer PrinterName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Startingadocumentprintjob
Opcode
SpoolerOperationFailed

Description

Starting document job JobID for printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Starting document job %3 for printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 110 — Ending document job JobID for printer PrinterName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Endingadocumentprintjob
Opcode
SpoolerOperationSucceeded

Description

Ending document job JobID for printer PrinterName succeeded. See the event user data for context information.

Message #

Ending document job %3 for printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 111 — Ending document job JobID for printer PrinterName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Endingadocumentprintjob
Opcode
SpoolerOperationFailed

Description

Ending document job JobID for printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Ending document job %3 for printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 114 — Adding printer driver ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Adding printer driver ObjectName succeeded. See the event user data for context information.

Message #

Adding printer driver %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 115 — Adding printer driver ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Adding printer driver ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Adding printer driver %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 118 — Opening printer ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationSucceeded

Description

Opening printer ObjectName succeeded. See the event user data for context information.

Message #

Opening printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 119 — Opening printer ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Opening printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Opening printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 122 — Starting page job JobID at printer PrinterName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Startinganewdocumentpage
Opcode
SpoolerOperationSucceeded

Description

Starting page job JobID at printer PrinterName succeeded. See the event user data for context information.

Message #

Starting page job %3 at printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 123 — Starting page failed at printer JobID, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Startinganewdocumentpage
Opcode
SpoolerOperationFailed

Description

Starting page failed at printer JobID, error code ErrorCode. See the event user data for context information.

Message #

Starting page failed at printer %3, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 124 — Ending page job JobID at printer PrinterName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Endingadocumentpage
Opcode
SpoolerOperationSucceeded

Description

Ending page job JobID at printer PrinterName succeeded. See the event user data for context information.

Message #

Ending page job %3 at printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 125 — Ending page job JobID at printer PrinterName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Endingadocumentpage
Opcode
SpoolerOperationFailed

Description

Ending page job JobID at printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Ending page job %3 at printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 131 — Setting printer PrinterName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Settingprinterconfiguration
Opcode
SpoolerOperationFailed

Description

Setting printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Setting printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 200 — Adding CSR printer connection ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinterconnection
Opcode
SpoolerOperationSucceeded

Description

Adding CSR printer connection ObjectName succeeded. See the event user data for context information.

Message #

Adding CSR printer connection %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 201 — Adding CSR printer connection ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Addingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Adding CSR printer connection ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Adding CSR printer connection %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 204 — Deleting CSR printer connection ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Deletingaprinterconnection
Opcode
SpoolerOperationSucceeded

Description

Deleting CSR printer connection ObjectName succeeded. See the event user data for context information.

Message #

Deleting CSR printer connection %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 205 — Deleting CSR printer connection ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Deletingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Deleting CSR printer connection ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Deleting CSR printer connection %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 207 — Opening CSR printer ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Opening CSR printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Opening CSR printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 210 — Closing CSR printer ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Closingaprinterhandle
Opcode
SpoolerOperationSucceeded

Description

Closing CSR printer ObjectName succeeded. See the event user data for context information.

Message #

Closing CSR printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 211 — Closing CSR printer ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Closingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Closing CSR printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Closing CSR printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 212 — Parsing inf (InfPath) for printer driver DriverName succeeded (processor architecture ProcessorArchitecture).

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Parsingaprinterdriverinf
Opcode
SpoolerOperationSucceeded

Description

Parsing inf (InfPath) for printer driver DriverName succeeded (processor architecture ProcessorArchitecture). See the event user data for context information.

Message #

Parsing inf (%4) for printer driver %5 succeeded (processor architecture %7). See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 213 — Parsing inf (InfPath) for printer driver DriverName failed (processor architecture ProcessorArchitecture), error code LastError, HRESULT HResult.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Parsingaprinterdriverinf
Opcode
SpoolerOperationFailed

Description

Parsing inf (InfPath) for printer driver DriverName failed (processor architecture ProcessorArchitecture), error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Parsing inf (%4) for printer driver %5 failed (processor architecture %7), error code %8, HRESULT %9. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 214 — Installing printer driver DriverName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Installingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Installing printer driver DriverName succeeded. See the event user data for context information.

Message #

Installing printer driver %5 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
PackageAware UnicodeString
CoreDriverDependencies UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 215 — Installing printer driver DriverName failed, error code LastError, HRESULT HResult.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Installing printer driver DriverName failed, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Installing printer driver %5 failed, error code %10, HRESULT %11. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
PackageAware UnicodeString
CoreDriverDependencies UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 216 — A printer setup operation succeeded during the installation process.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Installingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

A printer setup operation succeeded during the installation process. See the event user data for context information.

Message #

A printer setup operation succeeded during the installation process. See the event user data for context information.

Fields #

NameDescription
Context UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 217 — A printer setup operation failed during the installation process, error code LastError, HRESULT HResult.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

A printer setup operation failed during the installation process, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

A printer setup operation failed during the installation process, error code %5, HRESULT %6. See the event user data for context information.

Fields #

NameDescription
Context UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 218 — Copying printer driver package InfPath succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Copyingaprinterdriverpackage
Opcode
SpoolerOperationSucceeded

Description

Copying printer driver package InfPath succeeded. See the event user data for context information.

Message #

Copying printer driver package %5 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
Server UnicodeString
InfPath UnicodeString
DestInfPath UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 219 — Copying printer driver package InfPath failed, error code LastError, HRESULT HResult.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Copyingaprinterdriverpackage
Opcode
SpoolerOperationFailed

Description

Copying printer driver package InfPath failed, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Copying printer driver package %5 failed, error code %8, HRESULT %9. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
Server UnicodeString
InfPath UnicodeString
DestInfPath UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 220 — Retrieving CSR cache information for printer ObjectName succeeded.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Enumeratingprinters
Opcode
SpoolerOperationSucceeded

Description

Retrieving CSR cache information for printer ObjectName succeeded. See the event user data for context information.

Message #

Retrieving CSR cache information for printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 221 — Retrieving CSR cache information for printer ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Enumeratingprinters
Opcode
SpoolerOperationFailed

Description

Retrieving CSR cache information for printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Retrieving CSR cache information for printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 222 — Message.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Tracingaspoolermessage
Opcode
SpoolerTrace

Message #

%1

Fields #

NameDescription
Message UnicodeString
LastError HexInt32

Event ID 223 — Message.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Tracingaspoolermessage
Opcode
SpoolerOperationFailed

Message #

%1

Fields #

NameDescription
Message UnicodeString
LastError HexInt32

Event ID 224 — A remote print driver package operation Function failed with error code Error, server name Server.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

A remote print driver package operation failed with error code , server name . This was most likely caused by an unexpected error in the protocol communication between the client and the print server.

Message #

A remote print driver package operation %1 failed with error code %2, server name %3. This was most likely caused by an unexpected error in the protocol communication between the client and the print server.

Fields #

NameDescription
Function UnicodeString
Error HexInt32
Server UnicodeString

Event ID 225 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

An error occurred while installing printer driver '%1'. Error code: %4. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 226 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

An error occurred while installing printer driver '%1'. The driver being installed is incompatible with this version of Windows. Please obtain and install a compatible version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
DriverModelVersion UInt32

Event ID 227 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

An error occurred while installing printer driver '%1'. Error code: %4. The driver being installed relies on class driver '%3', which is not present on this computer. The class driver may be available on Windows Update. Please ensure that Windows Update is enabled in Device Installation Settings and that a connection can be established, and try again, or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 228 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

An error occurred while installing printer driver '%1'. The driver being installed relies on class driver '%3', which failed to install. Error code: %4. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 229 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The driver must contain a pipelineconfig.xml file.

Message #

An error occurred while installing printer driver '%1'. The driver must contain a pipelineconfig.xml file.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 230 — A problem was encountered while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Message #

A problem was encountered while installing printer driver '%1'. A printer extension bundled with the driver failed to register, and will be unavailable. Error code: %4. The driver will still be functional. Please obtain and install a new version of the printer extension or printer driver from the manufacturer (if available).

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 231 — An attempt was made to upgrade installed class driver 'DriverName' to a non-class driver.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Message #

An attempt was made to upgrade installed class driver '%1' to a non-class driver. Doing so will prevent any driver that relies on the class driver to stop functioning. The class driver will remain installed.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 232 — An attempt was made to upgrade installed printer driver 'DriverName' to an older version of the driver, which is unsupported.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Message #

An attempt was made to upgrade installed printer driver '%1' to an older version of the driver, which is unsupported. If the older version of the driver is required, please delete the current version (via Print Management or Print Server Properties) and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 233 — An attempt was made to upgrade installed printer driver 'DriverName' to a version that does not support printer sharing, or may cause compatibility problem...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Message #

An attempt was made to upgrade installed printer driver '%1' to a version that does not support printer sharing, or may cause compatibility problems when sharing to some computers. In order to use the new driver, please disable sharing for all print queues that are using this driver (via Print Management or the Sharing tab in Printer Properties) and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 234 — A problem was encountered while deleting printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Deletingaprinterdriver
Opcode
SpoolerWarning

Description

A problem was encountered while deleting printer driver 'DriverName'. A printer extension bundled with the driver failed to unregister. Error code: HResult. The driver will still be deleted.

Message #

A problem was encountered while deleting printer driver '%1'. A printer extension bundled with the driver failed to unregister. Error code: %4. The driver will still be deleted.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 235 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The file 'Value' referenced by the Directive directive could not be found.

Message #

An error occurred while installing printer driver '%1'. The file '%5' referenced by the %4 directive could not be found.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 236 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive directive is not allowed for this type of driver. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. The %4 directive is not allowed for this type of driver. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
ClassDriverOnly Boolean
NonClassDriverOnly Boolean

Event ID 237 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver ''. The directive is malformed, by having either an empty token or an incorrect number of tokens. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. The %4 directive is malformed, by having either an empty token or an incorrect number of tokens. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
EmptyToken Boolean
IncorrectNumberOfTokens Boolean

Event ID 238 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive must be a GUID, but 'Value' was provided.

Message #

An error occurred while installing printer driver '%1'. The %4 must be a GUID, but '%5' was provided.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 239 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive directive must be present in the manifest.

Message #

An error occurred while installing printer driver '%1'. The %4 directive must be present in the manifest.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 240 — An error occurred while installing printer driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

An error occurred while installing printer driver '%1'. There must be only one manifest per driver. Either no manifest was found, or too many manifests were found. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
MissingManifest Boolean
MultipleManifests Boolean

Event ID 241 — An attempt was made to upgrade installed printer driver 'DriverName' to a driver that does not support non-inbox port monitors.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Message #

An attempt was made to upgrade installed printer driver '%1' to a driver that does not support non-inbox port monitors. In order to use the new driver, please remove or reconfigure all print queues that are using this driver and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 242 — An error occurred while configuring print queue 'PrinterName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

An error occurred while configuring print queue 'PrinterName'. Printer driver 'DriverName' may not be used in conjunction with a non-inbox port monitor.

Message #

An error occurred while configuring print queue '%1'. Printer driver '%2' may not be used in conjunction with a non-inbox port monitor.

Fields #

NameDescription
PrinterName UnicodeString
DriverName UnicodeString

Event ID 300 — Printer param1 was created.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Addingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was created. No user action is required.

Message #

Printer %1 was created. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:14:27.559950Z",
    "event_record_id": 155,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "PrinterCreated": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 301 — Printer param1 was deleted, and users will no longer be able to print to this printer.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Deletingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was deleted, and users will no longer be able to print to this printer. No user action is required.

Message #

Printer %1 was deleted, and users will no longer be able to print to this printer. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 301,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:14:21.369976Z",
    "event_record_id": 152,
    "correlation": {
      "#attributes": {
        "ActivityID": "C43202E9-CB0F-0000-D030-32C40FCBD701"
      }
    },
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterDeleted": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 302 — Printer param1 will be deleted.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Deletingaprinter
Opcode
SpoolerOperationStarted

Description

Printer param1 will be deleted. No user action is required.

Message #

Printer %1 will be deleted. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 10,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:14:21.369976Z",
    "event_record_id": 150,
    "correlation": {
      "#attributes": {
        "ActivityID": "C43202E9-CB0F-0000-D030-32C40FCBD701"
      }
    },
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterDeletionPending": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 303 — Printer param1 was paused.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pausingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was paused. No user action is required.

Message #

Printer %1 was paused. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 304 — Printer param1 was resumed.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Resumingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was resumed. No user action is required.

Message #

Printer %1 was resumed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 304,
    "version": 0,
    "level": 4,
    "task": 24,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:28:26.229212Z",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3836
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "PrinterUnPaused": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "{BABBC1A0-F75A-44B0-92BC-57E20CEDA1D8}"
    }
  }
}

References #

Event ID 305 — The jobs in the print queue for printer param1 were deleted.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Purgingjobsfromprinterqueue
Opcode
SpoolerOperationSucceeded

Description

The jobs in the print queue for printer param1 were deleted. No user action is required.

Message #

The jobs in the print queue for printer %1 were deleted. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 306 — Settings for printer param1 were changed.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Settingprinterconfiguration
Opcode
SpoolerOperationSucceeded

Description

Settings for printer param1 were changed. No user action is required.

Message #

Settings for printer %1 were changed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 306,
    "version": 0,
    "level": 4,
    "task": 17,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:28:26.229212Z",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3836
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "PrinterSet": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "{BABBC1A0-F75A-44B0-92BC-57E20CEDA1D8}"
    }
  }
}

References #

Event ID 307 — Document param1, param2 owned by param3 on param4 was printed on param5 through port param6.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Collection Priority
Recommended (NSA)
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 on param4 was printed on param5 through port param6. Size in bytes: SizeInBytes. Pages printed: PagesPrinted. No user action is required.

Message #

Document %1, %2 owned by %3 on %4 was printed on %5 through port %6.  Size in bytes: %7. Pages printed: %8. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString

References #

Event ID 308 — Document param1, param2 owned by param3 was paused on param4.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 was paused on param4. This document will not print until the document owner resumes the print job. No user action is required.

Message #

Document %1, %2 owned by %3 was paused on %4. This document will not print until the document owner resumes the print job. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 309 — Document param1, param2 owned by param3 was resumed on param4.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 was resumed on param4. No user action is required.

Message #

Document %1, %2 owned by %3 was resumed on %4. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 310 — Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by DocumentDeleted.Param3 was deleted on DocumentDeleted.Param4.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Deletingadocument
Opcode
SpoolerOperationSucceeded

Description

Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by DocumentDeleted.Param3 was deleted on DocumentDeleted.Param4. No user action is required.

Message #

Document %1, %2 owned by %3 was deleted on %4. No user action is required.

Fields #

NameDescription
DocumentDeleted.Param1
DocumentDeleted.Param2
DocumentDeleted.Param3
DocumentDeleted.Param4
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 310,
    "version": 0,
    "level": 4,
    "task": 27,
    "opcode": 11,
    "keywords": 4611686018427390016,
    "time_created": "2026-03-13T20:25:33.325281+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DocumentDeleted": {
      "Param1": "2",
      "Param2": "Print Document",
      "Param3": "domainadmin",
      "Param4": "TestPrinter_EventGen"
    }
  },
  "message": ""
}

Event ID 311 — An administrator moved document param1, param2 owned by param3 to position param4 on param5.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

An administrator moved document param1, param2 owned by param3 to position param4 on param5. This changes when the document will print. No user action is required.

Message #

An administrator moved document %1, %2 owned by %3 to position %4 on %5. This changes when the document will print. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 312 — Form param1 was added.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Addingaprintform
Opcode
SpoolerOperationSucceeded

Description

Form param1 was added. No user action is required.

Message #

Form %1 was added. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 313 — Form param1 was removed.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Deletingaprintform
Opcode
SpoolerOperationSucceeded

Description

Form param1 was removed. No user action is required.

Message #

Form %1 was removed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 314 — Document param1, param2 owned by param3 timed out while printing on param4.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

Document param1, param2 owned by param3 timed out while printing on param4. The spooler waited for param5 milliseconds and no data was received.

Message #

Document %1, %2 owned by %3 timed out while printing on %4. The spooler waited for %5 milliseconds and no data was received.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 315 — The print spooler failed to share printer param2 with shared resource name param3.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Sharingaprinter
Opcode
SpoolerOperationFailed

Description

The print spooler failed to share printer param2 with shared resource name param3. Error param1. The printer cannot be used by others on the network.

Message #

The print spooler failed to share printer %2 with shared resource name %3. Error %1. The printer cannot be used by others on the network.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 316 — Printer driver param1 for param2 param3 was added or updated.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Printer driver param1 for param2 param3 was added or updated. Files:- param4. No user action is required.

Message #

Printer driver %1 for %2 %3 was added or updated. Files:- %4. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 316,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 11,
    "keywords": 4611686018427390208,
    "time_created": "2021-10-27T10:14:27.309949Z",
    "event_record_id": 153,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DriverAdded": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Generic / Text Only",
      "Param2": "Windows x64",
      "Param3": "Version-3",
      "Param4": "UNIDRV.DLL, UNIDRVUI.DLL, TTY.GPD, UNIDRV.HLP, TTYRES.DLL, TTY.INI, TTY.DLL, TTYUI.DLL, TTYUI.HLP, UNIRES.DLL, STDNAMES.GPD, STDDTYPE.GDL, STDSCHEM.GDL, STDSCHMX.GDL"
    }
  }
}

Detection Rules #

View all rules referencing this event →

Splunk # view in reference

  • Print Spooler Adding A Printer Driver source: The following analytic detects the addition of new printer drivers by monitoring Windows PrintService operational logs, specifically EventCode 316. This detection leverages log data to identify messages indicating the addition or update of printer drivers, such as "kernelbase.dll" and "UNIDRV.DLL." This activity is significant as it may indicate exploitation attempts related to vulnerabilities like CVE-2021-34527 (PrintNightmare). If confirmed malicious, attackers could gain code execution or escalate privileges, potentially compromising the affected system. Immediate isolation and investigation of the endpoint are recommended.

References #

Event ID 317 — Printer driver param1 was deleted.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Deletingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Printer driver param1 was deleted. No user action is required.

Message #

Printer driver %1 was deleted. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 317,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 11,
    "keywords": 4611686018427390208,
    "time_created": "2021-10-27T10:28:26.494838Z",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3768
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "DriverDeleted": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Generic / Text Only"
    }
  }
}

References #

Event ID 318 — Failed to upgrade printer settings for printer param1 driver param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Failed to upgrade printer settings for printer param1 driver param2. Error: Error. The device settings for the printer are set to those configured by the manufacturer.

Message #

Failed to upgrade printer settings for printer %1 driver %2. Error: %3. The device settings for the printer are set to those configured by the manufacturer.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 319 — Printer param1 failed to initialize because a suitable param2 driver could not be found.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

Printer %1 failed to initialize because a suitable %2 driver could not be found. The new printer settings that you specified have not taken effect. Install or reinstall the printer driver. You might need to contact the vendor for an updated driver.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 320 — Printer param1 failed to initialize because none of its ports (param2) could be found.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

Printer param1 failed to initialize because none of its ports (param2) could be found. This can occur if the ports were deleted or the port information is invalid.

Message #

Printer %1 failed to initialize because none of its ports (%2) could be found. This can occur if the ports were deleted or the port information is invalid.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 321 — File(s) param1 associated with printer param2 were added or updated.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

File(s) param1 associated with printer param2 were added or updated. No user action is required.

Message #

File(s) %1 associated with printer %2 were added or updated. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 322 — While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property param1 at param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property param1 at param2. Error: Error.

Message #

While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property %1 at %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 323 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue bec...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue because Windows failed to bind to container: %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 325 — While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue param1 at param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue param1 at param2. Error: Error.

Message #

While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue %1 at %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 326 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue und...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue under container %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 327 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not create print queue param1 under containe...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create print queue %1 under container %2 because Mandatory properties could not be set.  Error: %3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 328 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the primary domain query failed. Error: %1. This can occur if Domain Name System (DNS) cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString

Event ID 329 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the Domain Name System (DNS) domain name could not be retrieved. Error: %1. This can occur if DNS cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString

Event ID 331 — While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container on domain %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 332 — The printer was successfully published to the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

The printer was successfully published to the Active Directory directory service. The print queue param1 was successfully created in container param2. No user action is required.

Message #

The printer was successfully published to the Active Directory directory service. The print queue %1 was successfully created in container %2. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 333 — While attempting to publish the printer to the Active Directory directory service, the print spooler failed to create or update print queue param1 in c...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler failed to create or update print queue %1 in container %2.  Error: %3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 334 — The printer was successfully removed from the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Message #

The printer was successfully removed from the Active Directory directory service. Print queue %1 was successfully deleted from container %2. The printer can no longer be located by searching Active Directory. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 335 — While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue param1 from containe...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue param1 from container param2. Error: Error.

Message #

While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue %1 from container %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 336 — Print queue param1 was successfully updated in the Active Directory directory service container param2.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

Print queue param1 was successfully updated in the Active Directory directory service container param2. No user action is required.

Message #

Print queue %1 was successfully updated in the Active Directory directory service container %2. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 337 — The print queue could not be found on domain param1.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

The print queue could not be found on domain param1. It may have been deleted from the Active Directory directory service. Windows will attempt to republish the print queue. Error: Error.

Message #

The print queue could not be found on domain %1.  It may have been deleted from the Active Directory directory service. Windows will attempt to republish the print queue.  Error: %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 338 — Printer param1 was successfully removed from the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was successfully removed from the Active Directory directory service. The printer can no longer be located by searching Active Directory. No user action is required.

Message #

Printer %1 was successfully removed from the Active Directory directory service. The printer can no longer be located by searching Active Directory. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 342 — The print spooler removed print queue param1 from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) n...

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) name or server name listed. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) name or server name listed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 343 — The print spooler was unable to connect to print queue param1 based on the information published in the Active Directory.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Message #

The print spooler was unable to connect to print queue %1 based on the information published in the Active Directory. Error %2. No user action is required. If this print queue continues to be unreachable it may be removed from Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 344 — The print spooler removed print queue param1 from the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 345 — The print spooler removed print queue param1 from the Active Directory directory service because it is a duplicate of another print queue.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service because it is a duplicate of another print queue. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service because it is a duplicate of another print queue. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 346 — The print spooler removed print queue param1 from the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 347 — Print queue param1 could not be deleted (pruned) from the Active Directory directory service.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Pruningaprinter
Opcode
SpoolerOperationFailed

Message #

Print queue %1 could not be deleted (pruned) from the Active Directory directory service.  Error: %2. The spooler will periodically try to remove the entry until it is successful. Continued failures may indicate an Active Directory problem, a basic network problem, or a communication problem between the domain controller and the print server.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 348 — This version of param1 is incompatible with this version of Windows.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerWarning

Message #

This version of %1 is incompatible with this version of Windows. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString

Event ID 349 — The print spooler failed to create a symbolic link between HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Print\\Printers and HKEY_LOCAL_M...

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to create a symbolic link between HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Print\\Printers and HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers. Error %1. This only affects older applications, but is probably a sign that the system itself is in a poor condition or that the print spooler does not have the proper registry permissions.

Fields #

NameDescription
param1 UnicodeString

Event ID 350 — Document param1 failed to print and was deleted because of corruption in the spooled file.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

Document param1 failed to print and was deleted because of corruption in the spooled file. The associated driver is: param2. Try printing the document again.

Message #

Document %1 failed to print and was deleted because of corruption in the spooled file. The associated driver is: %2. Try printing the document again.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 351 — The attempt for param1 to use a Windows NT 4.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Message #

The attempt for %1 to use a Windows NT 4.0 (kernel mode) driver failed because this version of Windows does not support Windows NT 4.0 printer drivers. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString

Event ID 352 — The priority of document param1, param2 owned by param3 was changed to param4 on param5.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Message #

The priority of document %1, %2 owned by %3 was changed to %4 on %5. Windows prints the document with the highest priority number before other print jobs with lower priority numbers. Documents that are currently printing are unaffected by changes in priority. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 353 — The document failed to print because the user did not have the necessary privileges.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

The document failed to print because the user did not have the necessary privileges.

Message #

The document failed to print because the user did not have the necessary privileges.

Event ID 354 — param1 initialization failed at param2.

#
Provider
Microsoft-Windows-PrintService
Channel
Admin
Level
Error
Task
Initializing
Opcode
SpoolerOperationFailed

Description

param1 initialization failed at param2. Error: Error. This can occur because of system instability or a lack of system resources.

Message #

%1 initialization failed at %2. Error: %3. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
Error UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 354,
    "version": 0,
    "level": 2,
    "task": 36,
    "opcode": 12,
    "keywords": 9223372036854777856,
    "time_created": "2021-10-27T10:28:26.260460Z",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3836
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "InitFailed": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "\\\\fs03vuln\\Kiwi Legit Printer",
      "Param2": "\\\\fs03vuln\\print$\\W32X86\\3\\mimispool.dll",
      "Param3": "2. The system cannot find the file specified.\r\n"
    }
  }
}

References #

Event ID 356 — Failed to install or update driver param1 on cluster spooler resource param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Message #

Failed to install or update driver %1 on cluster spooler resource %2. Win32 error: %3. The printer driver is different from the driver in use on other computers (nodes) in the cluster. This can occur because of a transient failure in replication between nodes.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 359 — The attempt to install printer param1 into an offline operating system image failed with Win32 error code param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Message #

The attempt to install printer %1 into an offline operating system image failed with Win32 error code %2. This can occur if the printer driver requires user input or displays a user interface (UI) during installation.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 360 — Updating the color profile failed for printer param1 with Win32 error code param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Settingprinterconfiguration
Opcode
SpoolerOperationFailed

Description

Updating the color profile failed for printer param1 with Win32 error code param2. The colors printed may not be correctly matched to the colors in the document being printed.

Message #

Updating the color profile failed for printer %1 with Win32 error code %2. The colors printed may not be correctly matched to the colors in the document being printed.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 361 — Printer param1 failed to initialize its ports.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Message #

Printer %1 failed to initialize its ports. Win32 error: %2. This error usually occurs because of a problem with the port monitor. Try recreating the port using a standard TCP/IP printer port, if possible. This problem does not affect other printers.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 362 — The print spooler could not initialize because resolving the local machine name to IP addresses failed with error code param1.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Message #

The print spooler could not initialize because resolving the local machine name to IP addresses failed with error code %1. This may be a transient error. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Fields #

NameDescription
param1 UnicodeString

Event ID 363 — The print spooler param1 failed to start.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print spooler param1 failed to start. To determine the cause of this error, examine the preceding events in the Event Log.

Message #

The print spooler %1 failed to start. To determine the cause of this error, examine the preceding events in the Event Log.

Fields #

NameDescription
param1 UnicodeString

Event ID 364 — Windows could not load print processor param1 because EnumDatatypes did not return any data.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Message #

Windows could not load print processor %1 because EnumDatatypes did not return any data. Module: %2. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 365 — Windows could not load print processor param1 because EnumDatatypes failed.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Message #

Windows could not load print processor %1 because EnumDatatypes failed. Error code %2. Module: %3. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 366 — The print server security descriptor for param1 is invalid.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print server security descriptor for param1 is invalid. The default print server security descriptor will be used.

Message #

The print server security descriptor for %1 is invalid. The default print server security descriptor will be used.

Fields #

NameDescription
param1 UnicodeString

Event ID 367 — Windows could not initialize printer param1 because the print processor param2 could not be found.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Message #

Windows could not initialize printer %1 because the print processor %2 could not be found. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 368 — The print spooler failed to verify printer driver package param1 for environment param2.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to verify printer driver package %1 for environment %2. Win32 system error code %3. This can occur after an operating system upgrade or because of data loss on the hard drive. The print spooler will try to regenerate the driver information from the driver store, which is where drivers are saved before they are installed. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 369 — The print spooler failed to verify printer driver package for environment param1.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to verify printer driver package for environment %1. Win32 system error code %2. This can occur because of insufficient memory or other system failures. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 370 — The print spooler failed to regenerate the printer driver information for driver param1 for environment param2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to regenerate the printer driver information for driver %1 for environment %2. Win32 system error code %3. This can occur after an operating system upgrade or because of data loss on the hard drive.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 371 — The print spooler failed to unshare printer param2 which is shared as param3.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Unsharingaprinter
Opcode
SpoolerOperationFailed

Description

The print spooler failed to unshare printer param2 which is shared as param3. Error param1.

Message #

The print spooler failed to unshare printer %2 which is shared as %3. Error %1.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 372 — The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, failed to print on printer PrintOnProcFailedEd.Param3.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Level
Error
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, failed to print on printer PrintOnProcFailedEd.Param3. Try to print the document again, or restart the print spooler.

Message #

The document %1, owned by %2, failed to print on printer %3. Try to print the document again, or restart the print spooler. 
Data type: %4. Size of the spool file in bytes: %5. Number of bytes printed: %6. Total number of pages in the document: %7. Number of pages printed: %8. Client computer: %9. Win32 error code returned by the print processor: %10. %11

Fields #

NameDescription
PrintOnProcFailedEd.Param1
PrintOnProcFailedEd.Param2
PrintOnProcFailedEd.Param3
PrintOnProcFailedEd.Param4
PrintOnProcFailedEd.Param5
PrintOnProcFailedEd.Param6
PrintOnProcFailedEd.Param7
PrintOnProcFailedEd.Param8
PrintOnProcFailedEd.Param9
PrintOnProcFailedEd.Param10
PrintOnProcFailedEd.Param11
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString
param11 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 372,
    "version": 0,
    "level": 2,
    "task": 26,
    "opcode": 12,
    "keywords": 9223372036854777920,
    "time_created": "2026-03-13T18:26:33.122143+00:00",
    "event_record_id": 24,
    "correlation": {},
    "execution": {
      "process_id": 3664,
      "thread_id": 14104
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrintOnProcFailedEd": {
      "Param1": "Print Document",
      "Param2": "domainadmin",
      "Param3": "HP LaserJet Pro M148f-M149f 2 (redirected 1)",
      "Param4": "RAW",
      "Param5": "0",
      "Param6": "0",
      "Param7": "0",
      "Param8": "0",
      "Param9": "\\\\LAB-DC01",
      "Param10": "2152796161",
      "Param11": null
    }
  },
  "message": ""
}

Event ID 373 — The spooler has detected that a component has an unusually large number of open Graphical Device Interface (GDI) objects.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Message #

The spooler has detected that a component has an unusually large number of open Graphical Device Interface (GDI) objects. As a result, some enhanced metafile (EMF) print jobs might not print until the spooler is restarted.

Event ID 502 — The print spooler failed to get the computer name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The print spooler failed to get the computer name. Error Error. This can occur due to system instability or a lack of system resources.

Message #

The print spooler failed to get the computer name. Error %2. This can occur due to system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 503 — The system failed to initialize the local print provider: Error Error.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The system failed to initialize the local print provider: Error Error. This can occur because of system instability or a lack of system resources.

Message #

The system failed to initialize the local print provider: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 504 — Failed to initialize the router work crew: Error Error.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to initialize the router work crew: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to initialize the router work crew: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 505 — Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to create Phase2Init event in WaitForSpoolerInitialization: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 507 — The system failed to initialize the name cache: Error Error.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The system failed to initialize the name cache: Error Error. This can occur because of system instability or a lack of system resources.

Message #

The system failed to initialize the name cache: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 508 — Failed to initialize the router cache: Error Error.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to initialize the router cache: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to initialize the router cache: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 509 — The print spooler cannot start because the PrinterBusEnumerator could not start.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The print spooler cannot start because the PrinterBusEnumerator could not start. Error code Error. This can occur because of system instability or a lack of system resources.

Message #

The print spooler cannot start because the PrinterBusEnumerator could not start. Error code %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 510 — InitializeProvider cannot allocate memory for Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

InitializeProvider cannot allocate memory for Name. This can occur because of system instability or a lack of system resources.

Message #

InitializeProvider cannot allocate memory for %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 511 — The print spooler failed to load print provider Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

The print spooler failed to load print provider Name. This can occur because of system instability or a lack of system resources.

Message #

The print spooler failed to load print provider %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 512 — InitializePrintProvider failed for provider Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

InitializePrintProvider failed for provider Name. This can occur because of system instability or a lack of system resources.

Message #

InitializePrintProvider failed for provider %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 513 — Group Policy was unable to add per computer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to add per computer connection Name. Error code Error. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Message #

Group Policy was unable to add per computer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 514 — Group Policy was unable to delete per computer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to delete per computer connection Name. Error Error. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Message #

Group Policy was unable to delete per computer connection %1. Error %2. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 515 — Group Policy was unable to delete per computer printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to delete per computer printer connection %1. Error %2. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 516 — Group Policy was unable to deploy per computer printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to deploy per computer printer connection %1. Error %2. The printer connection is not available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 517 — Group Policy was unable to update per computer printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to update per computer printer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 518 — Group Policy was unable to delete the per user printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to delete the per user printer connection %1. Error code %2. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 519 — Group Policy was unable to deploy per user printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to deploy per user printer connection %1. Error code %2. The printer connection is not available to the users on this computer to which the Group Policy object applies. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 520 — Group Policy was unable to update per user printer connection Name.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Message #

Group Policy was unable to update per user printer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 600 — The print spooler failed to import the printer driver that was downloaded from DriverSource into the driver store for driver Driver.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to import the printer driver that was downloaded from %1 into the driver store for driver %2. Error code= %3. This can occur if there is a problem with the driver or the digital signature of the driver.

Fields #

NameDescription
DriverSource UnicodeString
Driver UnicodeString
Error UnicodeString

Event ID 601 — The print spooler failed to download and import the printer driver from DriverSource into the driver store for driver Driver.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to download and import the printer driver from DriverSource into the driver store for driver Driver. Error code= Error.

Message #

The print spooler failed to download and import the printer driver from %1 into the driver store for driver %2. Error code= %3.

Fields #

NameDescription
DriverSource UnicodeString
Driver UnicodeString
Error UnicodeString

Event ID 602 — The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey1\RegistryKey2.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key %1\%2. This can occur if the key name or values are malformed or missing.

Fields #

NameDescription
RegistryKey1 UnicodeString
RegistryKey2 UnicodeString

Event ID 603 — The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key %1. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Fields #

NameDescription
RegistryKey UnicodeString

Event ID 604 — The print spooler encountered an unknown driver type while saving Name cache information.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler encountered an unknown driver type while saving Name cache information. This can occur because of a protocol or network error.

Message #

The print spooler encountered an unknown driver type while saving %1 cache information. This can occur because of a protocol or network error.

Fields #

NameDescription
Name UnicodeString

Event ID 701 — The print filter pipeline host cannot initialize with the Component Object Model (COM) system.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host cannot initialize with the Component Object Model (COM) system. Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host cannot initialize with the Component Object Model (COM) system. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 702 — The print filter pipeline host is shutting down due to the following error: Error HResult.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host is shutting down due to the following error: Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host is shutting down due to the following error: Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 703 — The print filter pipeline host is shutting down due to an error in signaling the Component Object Model (COM) proxy in the spooler.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Message #

The print filter pipeline host is shutting down due to an error in signaling the Component Object Model (COM) proxy in the spooler. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 704 — The print filter pipeline host is shutting down because the query interface for ISignal in the Component Object Model (COM) proxy in the spooler fa...

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Message #

The print filter pipeline host is shutting down because the query interface for ISignal in the Component Object Model (COM) proxy in the spooler failed. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 800 — Spooling job JobDiag.JobId.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Printjobdiagnostics
Opcode
Start

Description

Spooling job JobDiag.JobId.

Message #

Spooling job %1.

Fields #

NameDescription
JobDiag.JobId UInt32
JobId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 800,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 1,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:11.317144+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 10520
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "JobDiag": {
      "JobId": 2
    }
  },
  "message": ""
}

Event ID 801 — Printing job JobDiag.JobId.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Printjobdiagnostics

Description

Printing job JobDiag.JobId.

Message #

Printing job %1.

Fields #

NameDescription
JobDiag.JobId UInt32
JobId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 801,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 0,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:11.789801+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "JobDiag": {
      "JobId": 2
    }
  },
  "message": ""
}

Event ID 802 — Deleting job DeleteJobDiag.JobId.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Printjobdiagnostics
Opcode
Stop

Description

Deleting job DeleteJobDiag.JobId.

Message #

Deleting job %1.

Fields #

NameDescription
DeleteJobDiag.JobId UInt32
DeleteJobDiag.JobSize UInt32
DeleteJobDiag.DataType UInt32
DeleteJobDiag.Pages UInt32
DeleteJobDiag.PagesPerSide UInt32
DeleteJobDiag.FilesOpened Int16
DeleteJobDiag.JobSizeHigh UInt32
JobId UInt32
JobSize UInt32
DataType UInt32
Pages UInt32
PagesPerSide UInt32
FilesOpened Int16
JobSizeHigh UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 802,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 2,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:33.325147+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DeleteJobDiag": {
      "JobId": 2,
      "JobSize": 53408,
      "DataType": 1,
      "Pages": 1,
      "PagesPerSide": 0,
      "FilesOpened": 3,
      "JobSizeHigh": 0
    }
  },
  "message": ""
}

Event ID 805 — Rendering job RenderJobDiag.JobId.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Printjobdiagnostics

Description

Rendering job RenderJobDiag.JobId.

Message #

Rendering job %1.

Fields #

NameDescription
RenderJobDiag.JobId UInt32
RenderJobDiag.GdiJobSize UInt32
RenderJobDiag.ICMMethod UInt32
RenderJobDiag.Color Int16
RenderJobDiag.XRes Int16
RenderJobDiag.YRes Int16
RenderJobDiag.Quality Int16
RenderJobDiag.Copies Int16
RenderJobDiag.TTOption Int16
JobId UInt32
GdiJobSize UInt32
ICMMethod UInt32
Color Int16
XRes Int16
YRes Int16
Quality Int16
Copies Int16
TTOption Int16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 805,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 0,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:33.323370+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "RenderJobDiag": {
      "JobId": 2,
      "GdiJobSize": 53408,
      "ICMMethod": 0,
      "Color": 2,
      "XRes": 600,
      "YRes": 600,
      "Quality": 600,
      "Copies": 1,
      "TTOption": 0
    }
  },
  "message": ""
}

References #

Event ID 806 — Pausing job JobId.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Printjobdiagnostics

Description

Pausing job JobId.

Message #

Pausing job %1.

Fields #

NameDescription
JobId UInt32

Event ID 807 — Resuming job JobId.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Printjobdiagnostics

Description

Resuming job JobId.

Message #

Resuming job %1.

Fields #

NameDescription
JobId UInt32

Event ID 808 — The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode.

#
Provider
Microsoft-Windows-PrintService
Channel
Admin
Level
Error
Task
Initializing
Opcode
SpoolerOperationFailed

Description

The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to load a plug-in module %1, error code %2. See the event user data for context information.

Fields #

NameDescription
PluginDllName UnicodeString
ErrorCode HexInt32
Context Int16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 808,
    "version": 0,
    "level": 2,
    "task": 36,
    "opcode": 12,
    "keywords": 9223372036854906880,
    "time_created": "2021-10-27T10:28:26.322960Z",
    "event_record_id": 12,
    "correlation": {
      "#attributes": {
        "ActivityID": "8811EC75-6F9C-4103-BB8A-EEED31FA139D"
      }
    },
    "execution": {
      "process_id": 1656,
      "thread_id": 1572
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "LoadPluginFailed": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PluginDllName": "C:\\Windows\\system32\\spool\\DRIVERS\\x64\\3mimispool.dll",
      "ErrorCode": "0x7e",
      "Context": 110
    }
  }
}

Detection Patterns #

References #

Event ID 809 — The print spooler failed to recursively delete the directory DirectoryName, error code WaitForReboot.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Deletingadirectory
Opcode
SpoolerOperationFailed

Description

The print spooler failed to recursively delete the directory DirectoryName, error code WaitForReboot. See the event user data for context information.

Message #

The print spooler failed to recursively delete the directory %1, error code %2. See the event user data for context information.

Fields #

NameDescription
DirectoryName UnicodeString
WaitForReboot HexInt32
ErrorCode HexInt32
Context Int16

Event ID 810 — The print spooler failed to delete the directory DirectoryName and the contained files, error code WaitForReboot.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Deletingadirectory
Opcode
SpoolerOperationFailed

Description

The print spooler failed to delete the directory DirectoryName and the contained files, error code WaitForReboot. See the event user data for context information.

Message #

The print spooler failed to delete the directory %1 and the contained files, error code %2. See the event user data for context information.

Fields #

NameDescription
DirectoryName UnicodeString
WaitForReboot HexInt32
ErrorCode HexInt32
Context Int16

Event ID 811 — The print spooler failed to move the file Source to Destination, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to move the file Source to Destination, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to move the file %1 to %2, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

Event ID 812 — The print spooler failed to delete the file Source, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to delete the file Source, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to delete the file %1, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

References #

Event ID 813 — The print spooler failed to copy the file Source to Destination, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to copy the file Source to Destination, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to copy the file %1 to %2, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

Event ID 814 — The print spooler failed to install the print processor Processor Environment Path, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Description

The print spooler failed to install the print processor Processor Environment Path, error code ErrorCode.

Message #

The print spooler failed to install the print processor %1 %2 %3, error code %4.

Fields #

NameDescription
Processor UnicodeString
Environment UnicodeString
Path UnicodeString
ErrorCode HexInt32

Event ID 815 — The print spooler service failed to register the RPC server protocol sequence ProtocolSequence, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The print spooler service failed to register the RPC server protocol sequence ProtocolSequence, error code ErrorCode. See the event user data for context information.

Message #

The print spooler service failed to register the RPC server protocol sequence %1, error code %3. See the event user data for context information.

Fields #

NameDescription
ProtocolSequence UnicodeString
EndPoint UnicodeString
ErrorCode HexInt32
Context Int16

Event ID 816 — The print spooler service detected an invalid RPC protocol sequence ValidatedProtocolSequence, expecting ExpectedProtocolSequence, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The print spooler service detected an invalid RPC protocol sequence ValidatedProtocolSequence, expecting ExpectedProtocolSequence, error code ErrorCode.

Message #

The print spooler service detected an invalid RPC protocol sequence %1, expecting %2, error code %3.

Fields #

NameDescription
ValidatedProtocolSequence UnicodeString
ExpectedProtocolSequence UnicodeString
ErrorCode HexInt32

Event ID 817 — The RPC end-point policy for the print spooler service is disabled.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The RPC end-point policy for the print spooler service is disabled. See the event user data for context information.

Message #

The RPC end-point policy for the print spooler service is disabled. See the event user data for context information.

Fields #

NameDescription
WindowsStarterEdition HexInt32
SuiteStorageServer HexInt32
SystemPrintingDisabled HexInt32
SuiteBlade HexInt32
SuiteEmbeddedRestricted HexInt32
SuiteComputerServer HexInt32

Event ID 818 — The print spooler RPC server failed to start, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The print spooler RPC server failed to start, error code ErrorCode. See the event user data for context information.

Message #

The print spooler RPC server failed to start, error code %1. See the event user data for context information.

Fields #

NameDescription
ErrorCode HexInt32
Context Int16

Event ID 819 — Client Side Rendering is currently disabled by policy (Policy).

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerTrace

Description

Client Side Rendering is currently disabled by policy (Policy).

Message #

Client Side Rendering is currently disabled by policy (%1).

Fields #

NameDescription
Policy UnicodeString

Event ID 820 — Client side rendering to PrintProcessor failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Client side rendering to PrintProcessor failed, error code ErrorCode. The print spooler service will retry server side rendering. See the event user data for more context information.

Message #

Client side rendering to %1 failed, error code %4. The print spooler service will retry server side rendering. See the event user data for more context information.

Fields #

NameDescription
PrintProcessor UnicodeString
Connection UnicodeString
IsXpsPrinter HexInt32
ErrorCode HexInt32

Event ID 821 — The print spooler Client Side Rendering is attempting to render the job JobId on the server (Server Side Rendering), status Status.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerTrace

Description

The print spooler Client Side Rendering is attempting to render the job JobId on the server (Server Side Rendering), status Status. See the event user data for context information.

Message #

The print spooler Client Side Rendering is attempting to render the job %1 on the server (Server Side Rendering), status %3. See the event user data for context information.

Fields #

NameDescription
JobId UInt32
Level HexInt32
Status HexInt32NTSTATUS reference

Event ID 822 — Unknown print processor (LocalPrintProcessor) or invalid data type (LocalDataType), error ErrorCode, Client Side Rendering is disabled.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Unknown print processor (LocalPrintProcessor) or invalid data type (LocalDataType), error ErrorCode, Client Side Rendering is disabled. See the event user data for more context information.

Message #

Unknown print processor (%1) or invalid data type (%4), error %7, Client Side Rendering is disabled. See the event user data for more context information.

Fields #

NameDescription
LocalPrintProcessor UnicodeString
RemotePrintProcessor UnicodeString
DefaultPrintProcessor UnicodeString
LocalDataType UnicodeString
RemoteDataType UnicodeString
DefaultDataType UnicodeString
ErrorCode HexInt32

Event ID 823 — The default printer was changed to NewDefaultPrinter.

#
Provider
Microsoft-Windows-PrintService
Channel
Admin
Level
Informational
Task
Changingthedefaultprinter
Opcode
SpoolerOperationSucceeded

Description

The default printer was changed to NewDefaultPrinter. See the event user data for context information.

Message #

The default printer was changed to %3. See the event user data for context information.

Fields #

NameDescription
DefaultPrinterSelectedBySpooler UInt32
OldDefaultPrinter UnicodeString
NewDefaultPrinter UnicodeString
Status HexInt32NTSTATUS reference
Module UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 823,
    "version": 0,
    "level": 4,
    "task": 49,
    "opcode": 11,
    "keywords": 9223372036854906880,
    "time_created": "2021-10-27T10:09:16.280929Z",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4012
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "ChangingDefaultPrinter": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "DefaultPrinterSelectedBySpooler": 1,
      "OldDefaultPrinter": "-",
      "NewDefaultPrinter": "Kiwi Legit Printer",
      "Status": "0x0",
      "Module": "spoolsv.exe"
    }
  }
}

References #

Event ID 824 — A fatal error occurred while printing job DocumentName, id JobId on the print queue PrintQueue.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

A fatal error occurred while printing job DocumentName, id JobId on the print queue PrintQueue. The print filter pipeline process was terminated. Error information: ErrorInfo.

Message #

A fatal error occurred while printing job %1, id %2 on the print queue %3. The print filter pipeline process was terminated. Error information: %4.

Fields #

NameDescription
DocumentName UnicodeString
JobId UInt32
PrintQueue UnicodeString
ErrorInfo UnicodeString

Event ID 825 — Client side rendering to PrintProcessor failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Client side rendering to PrintProcessor failed, error code ErrorCode. The print spooler service will not retry server side rendering. See the event user data for more context information.

Message #

Client side rendering to %1 failed, error code %4. The print spooler service will not retry server side rendering. See the event user data for more context information.

Fields #

NameDescription
PrintProcessor UnicodeString
Connection UnicodeString
IsXpsPrinter HexInt32
ErrorCode HexInt32

Event ID 826 — Force Client Side Rendering policy was successfully set on printer PrinterName, path PrinterPath, port PortName.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationSucceeded

Description

Force Client Side Rendering policy was successfully set on printer PrinterName, path PrinterPath, port PortName.

Message #

Force Client Side Rendering policy was successfully set on printer %1, path %2, port %3.

Fields #

NameDescription
PrinterName UnicodeString
PrinterPath UnicodeString
PortName UnicodeString

Event ID 827 — The specified print queue QueueName is invalid.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ExecutingXPSPrintAPIcalls
Opcode
XPSPrintAPIfailure

Description

The specified print queue QueueName is invalid.

Message #

The specified print queue %1 is invalid.

Fields #

NameDescription
QueueName UnicodeString

Event ID 828 — The print job JobId failed with error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ExecutingXPSPrintAPIcalls
Opcode
XPSPrintAPIfailure

Description

The print job JobId failed with error code ErrorCode.

Message #

The print job %1 failed with error code %2.

Fields #

NameDescription
JobId UInt32
ErrorCode HexInt32

Event ID 829 — XPS API call Name (Context) started.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Start

Description

XPS API call Name (Context) started.

Message #

XPS API call %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 830 — XPS API call Name (Context) ended, status StatusCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Stop

Description

XPS API call Name (Context) ended, status StatusCode.

Message #

XPS API call %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 831 — XPS API dependency Name (Context) started.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Start

Description

XPS API dependency Name (Context) started.

Message #

XPS API dependency %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 832 — XPS API dependency Name (Context) ended, status StatusCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Stop

Description

XPS API dependency Name (Context) ended, status StatusCode.

Message #

XPS API dependency %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 833 — Print spooler operation Name (Context) started.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Generalprintspoolerperformancetracking
Opcode
Start

Description

Print spooler operation Name (Context) started.

Message #

Print spooler operation %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 834 — Print spooler operation Name (Context) ended, status StatusCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Generalprintspoolerperformancetracking
Opcode
Stop

Description

Print spooler operation Name (Context) ended, status StatusCode.

Message #

Print spooler operation %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32

Event ID 842 — The print job PrintDriverSandboxJobPrintProc.JobId was sent through the print processor PrintDriverSandboxJobPrintProc.Processor on printer PrintDriverSandboxJobPrintProc.Printer, driver PrintDrive...

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Message #

The print job %1 was sent through the print processor %2 on printer %3, driver %4, in the isolation mode %5 (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox). Win32 error code returned by the print processor: %6.

Fields #

NameDescription
PrintDriverSandboxJobPrintProc.JobId UInt32
PrintDriverSandboxJobPrintProc.Processor UnicodeString
PrintDriverSandboxJobPrintProc.Printer UnicodeString
PrintDriverSandboxJobPrintProc.Driver UnicodeString
PrintDriverSandboxJobPrintProc.IsolationMode UInt32
PrintDriverSandboxJobPrintProc.ErrorCode
JobId UInt32
Processor UnicodeString
Printer UnicodeString
Driver UnicodeString
IsolationMode UInt32
Error HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 842,
    "version": 0,
    "level": 4,
    "task": 50,
    "opcode": 11,
    "keywords": 4611686018427650048,
    "time_created": "2026-03-13T20:25:33.321078+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrintDriverSandboxJobPrintProc": {
      "JobId": 2,
      "Processor": "MS_XPS_PROC",
      "Printer": "TestPrinter_EventGen",
      "Driver": "Microsoft Print To PDF",
      "IsolationMode": 0,
      "ErrorCode": "0x0"
    }
  },
  "message": ""
}

References #

Event ID 843 — The print spooler service recorded SucceededRpcCalls successful and FailedRpcCalls failed RPC requests for all active print driver sandbox hosts.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

The print spooler service recorded SucceededRpcCalls successful and FailedRpcCalls failed RPC requests for all active print driver sandbox hosts.

Message #

The print spooler service recorded %1 successful and %2 failed RPC requests for all active print driver sandbox hosts.

Fields #

NameDescription
SucceededRpcCalls UInt32
FailedRpcCalls UInt32

Event ID 844 — The print spooler selected the isolation mode IsolationMode (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for prin...

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

The print spooler selected the isolation mode IsolationMode (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for printer Printer, printer driver Driver.

Message #

The print spooler selected the isolation mode %1 (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for printer %2, printer driver %3.

Fields #

NameDescription
IsolationMode UInt32
Printer UnicodeString
Driver UnicodeString

Event ID 845 — Attempted to load module Module for printer Printer, printer driver Driver.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

Attempted to load module Module for printer Printer, printer driver Driver. Win32 error code Error.

Message #

Attempted to load module %1 for printer %2, printer driver %3. Win32 error code %4.

Fields #

NameDescription
Module UnicodeString
Printer UnicodeString
Driver UnicodeString
Error HexInt32

Event ID 846 — Cached printer PrinterName has been scavenged and deleted.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationSucceeded

Description

Cached printer PrinterName has been scavenged and deleted. This printer's age (PrinterAge seconds) has surpassed the expiry age of ExpiryAge seconds.

Message #

Cached printer %1 has been scavenged and deleted. This printer's age (%2 seconds) has surpassed the expiry age of %3 seconds.

Fields #

NameDescription
PrinterName UnicodeString
PrinterAge UInt32
ExpiryAge UInt32

Event ID 847 — Cached printer PrinterName has been scheduled for deletion due to a logon scavenging operation.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationSucceeded

Description

Cached printer PrinterName has been scheduled for deletion due to a logon scavenging operation. This printer is no longer referenced in the registry.

Message #

Cached printer %1 has been scheduled for deletion due to a logon scavenging operation. This printer is no longer referenced in the registry.

Fields #

NameDescription
PrinterName UnicodeString

Event ID 848 — Printer PrinterName was shared by the print spooler as ShareName.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Sharingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer PrinterName was shared by the print spooler as ShareName.

Message #

Printer %1 was shared by the print spooler as %2.

Fields #

NameDescription
PrinterName UnicodeString
ShareName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 848,
    "version": 0,
    "level": 4,
    "task": 30,
    "opcode": 11,
    "keywords": 4611686018427387936,
    "time_created": "2021-10-27T10:14:27.466200Z",
    "event_record_id": 154,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterSharing": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PrinterName": "Kiwi Legit Printer",
      "ShareName": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 849 — Printer PrinterName shared as ShareName was unshared by the print spooler.

#
Provider
Microsoft-Windows-PrintService
Channel
Operational
Level
Informational
Task
Unsharingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer PrinterName shared as ShareName was unshared by the print spooler.

Message #

Printer %1 shared as %2 was unshared by the print spooler.

Fields #

NameDescription
PrinterName UnicodeString
ShareName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 849,
    "version": 0,
    "level": 4,
    "task": 31,
    "opcode": 11,
    "keywords": 4611686018427387936,
    "time_created": "2021-10-27T10:14:21.369976Z",
    "event_record_id": 151,
    "correlation": {
      "#attributes": {
        "ActivityID": "C43202E9-CB0F-0000-D030-32C40FCBD701"
      }
    },
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterSharing": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PrinterName": "Kiwi Legit Printer",
      "ShareName": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 850 — The print spooler called the function Function in print driver module Driver.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Printdriveroperation
Opcode
SpoolerOperationFailed

Description

The print spooler called the function Function in print driver module Driver. This call initialized the Component Object Model (COM) system without properly un-initializing it.

Message #

The print spooler called the function %2 in print driver module %1. This call initialized the Component Object Model (COM) system without properly un-initializing it.

Fields #

NameDescription
Driver UnicodeString
Function UnicodeString

Event ID 851 — Point and Print not allowed by policy for queue PrintQueue.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Addingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Point and Print not allowed by policy for queue PrintQueue. Cannot make a Point and Print connection to this queue. Error Error.

Message #

Point and Print not allowed by policy for queue %1. Cannot make a Point and Print connection to this queue. Error %2.

Fields #

NameDescription
PrintQueue UnicodeString
Error HexInt32

Event ID 852 — Driver OriginalDriver could not be installed for printer connection PrinterName.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Driver OriginalDriver could not be installed for printer connection PrinterName. The print system selected the replacement driver NewDriver for the printer connection. No user action is required.

Message #

Driver %1 could not be installed for printer connection %3. The print system selected the replacement driver %2 for the printer connection. No user action is required.

Fields #

NameDescription
OriginalDriver UnicodeString
NewDriver UnicodeString
PrinterName UnicodeString

Event ID 853 — Print Client Side Rendering synchronization for print job cache completed with code Error for printer PrinterName.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

Print Client Side Rendering synchronization for print job cache completed with code Error for printer PrinterName.

Message #

Print Client Side Rendering synchronization for print job cache completed with code %1 for printer %2.

Fields #

NameDescription
Error HexInt32
PrinterName UnicodeString

Event ID 854 — Print Client Side Rendering synchronization for printer information cache completed with code Error for printer PrinterName.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

Print Client Side Rendering synchronization for printer information cache completed with code Error for printer PrinterName.

Message #

Print Client Side Rendering synchronization for printer information cache completed with code %1 for printer %2.

Fields #

NameDescription
Error HexInt32
PrinterName UnicodeString

Event ID 855 — OpenPrinter cache entry added for printer PrinterName with access code AccessCode.

Provider
Microsoft-Windows-PrintService
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

OpenPrinter cache entry added for printer PrinterName with access code AccessCode.

Message #

OpenPrinter cache entry added for printer %1 with access code %2.

Fields #

NameDescription
PrinterName UnicodeString
AccessCode UInt32

Event ID 856 — Connection 'ConnectionName' has been reconfigured for normal operation because branch office printing has been disabled.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because branch office printing has been disabled.

Message #

Connection '%1' has been reconfigured for normal operation because branch office printing has been disabled.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 857 — Connection 'ConnectionName' has been reconfigured for normal operation because the queue is incompatible with branch office printing.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the queue is incompatible with branch office printing.

Message #

Connection '%1' has been reconfigured for normal operation because the queue is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 858 — Connection 'ConnectionName' has been reconfigured for normal operation because the queue has been configured for Server Side Rendering.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the queue has been configured for Server Side Rendering. To re-enable Branch Office Printing, enable the 'Render Jobs On Client' setting on the server queue.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 859 — Connection 'ConnectionName' has been reconfigured for normal operation because the client is incompatible with branch office printing.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the client is incompatible with branch office printing.

Message #

Connection '%1' has been reconfigured for normal operation because the client is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 860 — Connection 'ConnectionName' has been reconfigured for normal operation because the server is incompatible with branch office printing.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the server is incompatible with branch office printing.

Message #

Connection '%1' has been reconfigured for normal operation because the server is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 861 — Connection 'ConnectionName' has been reconfigured for normal operation because the remote port is incompatible with branch office printing.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the remote port is incompatible with branch office printing.

Message #

Connection '%1' has been reconfigured for normal operation because the remote port is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 862 — Connection 'ConnectionName' has been reconfigured for normal operation because the 'Keep Printed Jobs' setting is enabled on the queue.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the 'Keep Printed Jobs' setting is enabled on the queue. To re-enable Branch Office Printing, disable the 'Keep Printed Jobs' setting on the server queue.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 863 — Connection 'ConnectionName' has been reconfigured for normal operation due to an internal error, Error.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation due to an internal error, Error.

Message #

Connection '%1' has been reconfigured for normal operation due to an internal error, %2.

Fields #

NameDescription
ConnectionName UnicodeString
Error HexInt32

Event ID 864 — The Windows Fax and Scan servicing operation failed, HRESULT HResult.

Provider
Microsoft-Windows-PrintService
Channel
Operational
Task
ServicingWindowsFaxandScan
Opcode
SpoolerOperationFailed

Description

The Windows Fax and Scan servicing operation failed, HRESULT HResult.

Message #

The Windows Fax and Scan servicing operation failed, HRESULT %1.

Fields #

NameDescription
HResult HexInt32

Event ID 865 — There were Failures print job failures out of Jobs jobs sent to printer 'PrinterName' using driver 'DriverName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Message #

There were %1 print job failures out of %2 jobs sent to printer '%3' using driver '%4'. The printer driver isolation setting was updated to load the printer driver inside the print spooler process. No user action is required.

Fields #

NameDescription
Failures UInt32
Jobs UInt32
PrinterName UnicodeString
DriverName UnicodeString

Event ID 866 — The print spooler failed to create a Plug and Play printer device object for the printer 'PrinterName'.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
CreatingaPlugandPlaydeviceobjectinstanceforaprinter
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to create a Plug and Play printer device object for the printer '%1'. Print object instance identifier '%2'. Error code %3. This printer will not be fully functional until the print spooler service is restarted and the Plug and Play printer device object is successfully created.

Fields #

NameDescription
PrinterName UnicodeString
DeviceObjectInstanceIdentifier UnicodeString
HResultErrorCode HexInt32

Event ID 867 — The WS-Print Port Monitor failed to initialize correctly.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
InitializingtheWS_PrintPortMonitor
Opcode
SpoolerOperationFailed

Description

The WS-Print Port Monitor failed to initialize correctly. Creating the Device Association listener failed with the following error code: HResultErrorCode.

Message #

The WS-Print Port Monitor failed to initialize correctly. Creating the Device Association listener failed with the following error code: %1.

Fields #

NameDescription
HResultErrorCode HexInt32

Event ID 868 — The Offline EventLog on machine 'MachineName' exceeded the allow maximum size.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
BOPEventOfflineArchiveFull
Opcode
SpoolerTrace

Description

The Offline EventLog on machine 'MachineName' exceeded the allow maximum size. Some job events may have been lost.

Message #

The Offline EventLog on machine '%1' exceeded the allow maximum size. Some job events may have been lost.

Fields #

NameDescription
MachineName UnicodeString

Event ID 869 — In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code ErrorCode.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Description

In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code ErrorCode. See the event user data for context information. Driver has no valid catalog.

Message #

In VALIDATINGDRVINFO, Adding printer driver %3 failed, error code %2. See the event user data for context information. Driver has no valid catalog

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 870 — The print spooler failed to download package for driver Driver.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to download package for driver Driver. Error code= Error. Blocking driver as there could be a possibility of potential tampering.

Message #

The print spooler failed to download package for driver %1. Error code= %2. Blocking driver as there could be a possibility of potential tampering.

Fields #

NameDescription
Driver UnicodeString
Error UnicodeString

Event ID 871 — The current print job was rejected due to Device Control Print Restrictions.

Provider
Microsoft-Windows-PrintService
Channel
Admin
Task
DeviceControlPrinting
Opcode
SpoolerOperationFailed

Description

The current print job was rejected due to Device Control Print Restrictions. Rejection Reason: RestrictionReason, Printer: PrinterName, Job or Document Name: JobOrDocumentName, User Name: UserName, Port Name: PortName.

Message #

The current print job was rejected due to Device Control Print Restrictions. Rejection Reason: %1, Printer: %2, Job or Document Name: %3, User Name: %4, Port Name: %5

Fields #

NameDescription
RestrictionReason UnicodeString
PrinterName UnicodeString
JobOrDocumentName UnicodeString
UserName UnicodeString
PortName UnicodeString

Event ID 1111 — Driver <DriverName> required for printer <PrinterName> is unknown.

Provider
Microsoft-Windows-PrintService
Channel
Operational

Event ID 4098 — The computer <ComputerName or IP> preference item in the '{GUID}' Group Policy object did not apply because it failed with error code '0x80070bcb The specified printer driver was not found on the s...

Provider
Microsoft-Windows-PrintService
Channel
Operational

Event ID 4909 — Print Service event 4909 (manifest stub).

Provider
Microsoft-Windows-PrintService
Channel
Operational

Detection Patterns #

Event ID 8192 — The user <UserName> preference item in the '{GUID}' Group Policy object did not apply because it failed with error code '0x80070bcb The specified printer driver was not found on the system and need...

Provider
Microsoft-Windows-PrintService
Channel
Operational