Microsoft-Windows-RemoteAssistance

50 events across 4 channels

Event IDTitleChannel
1Entering function %1.Tracing
2Leaving function %1.Tracing
3Application will terminate, a critical error was detected in %1 Line %2 Function …Application
4Hit exception block of code at %1 Line %2 in function %3.Tracing
5Branching on Line:%2 File:%1 with the string %3.Tracing
6Switching on Line:%2 File:%1 with the value %3.Tracing
7Entering conditional block at Line:%1 File:%2.Tracing
8Exiting conditional block at Line:%1 File:%2.Tracing
9There was a problem interacting with COM object %1.Admin
10A user tried to use Remote Assistance and send an invitation for help through …Admin
11A user opened a Remote Assistance invitation, but the invitation was closed due …Admin
12A user tried to use Remote Assistance, group policy requires a session log to be …Admin
13Remote Assistance started with: %1 as the command line parameters.Operational
14A Remote Assistance Invitation was successfully opened.Operational
15An RDP connection was successfully made.Operational
16The Remote Assistance password was verified.Operational
17The Remote Assistance password provided was incorrect.Operational
18The Remote Assistance session was disconnected remotely.Operational
19The Remote Assistance session was disconnected locally.Operational
20The Remote Assistance invitation was closed, any information concerning it given …Operational
21The helper is sharing control.Operational
22The helper can now view the screen.Operational
23Remote Assistance detected that it didn't restore the background and screen …Operational
24The time limit of offered invitations has been reached.Operational
25User setting value currently applied is %1.Operational
26The system or GP settings do not allow an Remote Assistance invitation to be …Operational
27The system or GP settings do not allow a helper to share control.Operational
28The Windows firewall has been checked and it appears that it is configured so …Operational
29The error message: %1 has been shown to the user.Operational
30Remote Assistance has ended.Operational
31Remote Assistance COM server has started.Operational
32Remote Assistance COM server has ended.Operational
33The Remote Assistance ticket contained the following IP addresses.Operational
34A PNRP Node was created at the following address.Operational
35The following PNRP clouds were detected.Operational
36A PNRP Node was released at the following address.Operational
37Started looking for PNRP node with the following address.Operational
38Stopped looking for PNRP node, address.Operational
39There was a problem interacting with the PNRP service.Admin
40Diagnosis Repro Attempt resulted in a success.Operational
41Diagnosis Repro Attempt resulted in a failure.Operational
42Current time on NTP Server.Tracing
43Remote Assistance troubleshooting rejected problem %1.Tracing
44Remote Assistance troubleshooting has confirmed the problem.Operational
45Remote Assistance troubleshooting is starting to repair the identified problem.Operational
46Remote Assistance troubleshooting successfully repaired the problem.Operational
47Remote Assistance troubleshooting failed to repair the problem.Operational
100Remote OS Type.Tracing
101Remote Assistance connection attempt failed with error code.Tracing
102Remote Assistance reproduced the problem and created following ticket to verify …Tracing

Event ID 1 — Entering function %1.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Entering function %1

Fields

NameDescription
FuncName

Event ID 2 — Leaving function %1.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Leaving function %1

Fields

NameDescription
FuncName

Event ID 3 — Application will terminate, a critical error was detected in %1 Line %2 Function %3.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Application

Message

Application will terminate, a critical error was detected in %1 Line %2 Function %3

Fields

NameDescription
file
line
function
error

Event ID 4 — Hit exception block of code at %1 Line %2 in function %3.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Hit exception block of code at %1 Line %2 in function %3

Fields

NameDescription
file
line
function
error

Event ID 5 — Branching on Line:%2 File:%1 with the string %3.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Branching on Line:%2 File:%1 with the string %3

Fields

NameDescription
file
line
Condition

Event ID 6 — Switching on Line:%2 File:%1 with the value %3.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Switching on Line:%2 File:%1 with the value %3

Fields

NameDescription
file
line
Condition

Event ID 7 — Entering conditional block at Line:%1 File:%2.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Entering conditional block at Line:%1 File:%2

Fields

NameDescription
Entering_conditional_block_at_Line
File
line

Event ID 8 — Exiting conditional block at Line:%1 File:%2.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Exiting conditional block at Line:%1 File:%2

Fields

NameDescription
Exiting_conditional_block_at_Line
File
line

Event ID 9 — There was a problem interacting with COM object %1.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin

Message

There was a problem interacting with COM object %1.  An outdated version might be installed, or the component might not be installed at all.

Fields

NameDescription
FuncName

Event ID 10 — A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfu...

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin

Message

A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfully send the invitation.  It is possible the email client configured as the default client does not support SMAPI calls, or that the email client is improperly configured.  It is also possible that the user closed the email client without sending the message.

Event ID 11 — A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin

Message

A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

Event ID 12 — A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin

Message

A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.  Remote Assistance was terminated.  Check the disk to see if there are problems with the disk or if it is full.

Event ID 13 — Remote Assistance started with: %1 as the command line parameters.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance started with:    %1    as the command line parameters.

Fields

NameDescription
FuncName

Event ID 14 — A Remote Assistance Invitation was successfully opened.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

A Remote Assistance Invitation was successfully opened.

Event ID 15 — An RDP connection was successfully made.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

An RDP connection was successfully made.

Event ID 16 — The Remote Assistance password was verified.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance password was verified.  The Remote Assistance session has begun.

Event ID 17 — The Remote Assistance password provided was incorrect.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance password provided was incorrect.  The RDP session was terminated, IP address of the connecting machine is %1

Fields

NameDescription
FuncName

Event ID 18 — The Remote Assistance session was disconnected remotely.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance session was disconnected remotely.

Event ID 19 — The Remote Assistance session was disconnected locally.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance session was disconnected locally.

Event ID 20 — The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

Event ID 21 — The helper is sharing control.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The helper is sharing control.

Event ID 22 — The helper can now view the screen.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The helper can now view the screen.

Event ID 23 — Remote Assistance detected that it didn't restore the background and screen settings before shutting down.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance detected that it didn't restore the background and screen settings before shutting down.  An attempt was made to restore these settings.

Event ID 24 — The time limit of offered invitations has been reached.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The time limit of offered invitations has been reached.

Event ID 25 — User setting value currently applied is %1.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

User setting value currently applied is %1

Fields

NameDescription
Code

Event ID 26 — The system or GP settings do not allow an Remote Assistance invitation to be created.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The system or GP settings do not allow an Remote Assistance invitation to be created.  This action has been blocked by the application.

Event ID 27 — The system or GP settings do not allow a helper to share control.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The system or GP settings do not allow a helper to share control.  This action has been blocked by the application.

Event ID 28 — The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

Event ID 29 — The error message: %1 has been shown to the user.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The error message:    %1    has been shown to the user.

Fields

NameDescription
FuncName

Event ID 30 — Remote Assistance has ended.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance has ended.

Event ID 31 — Remote Assistance COM server has started.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Level
5
Samples
1

Message

Remote Assistance COM server has started.

Example Event

system:
  provider: Microsoft-Windows-RemoteAssistance
  guid: 5B0A651A-8807-45CC-9656-7579815B6AF0
  event_source_name: ''
  event_id: 31
  version: 0
  level: 5
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2023-11-05T23:50:13.780543+00:00'
  event_record_id: 41
  correlation: {}
  execution:
    process_id: 11236
    thread_id: 9452
  channel: Microsoft-Windows-RemoteAssistance/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 32 — Remote Assistance COM server has ended.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Level
5
Samples
1

Message

Remote Assistance COM server has ended.

Example Event

system:
  provider: Microsoft-Windows-RemoteAssistance
  guid: 5B0A651A-8807-45CC-9656-7579815B6AF0
  event_source_name: ''
  event_id: 32
  version: 0
  level: 5
  task: 0
  opcode: 0
  keywords: 9223372036854775808
  time_created: '2023-11-05T23:50:13.791029+00:00'
  event_record_id: 42
  correlation: {}
  execution:
    process_id: 11236
    thread_id: 9452
  channel: Microsoft-Windows-RemoteAssistance/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data: {}
message: ''

References

Event ID 33 — The Remote Assistance ticket contained the following IP addresses.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The Remote Assistance ticket contained the following IP addresses: %1

Fields

NameDescription
FuncName

Event ID 34 — A PNRP Node was created at the following address.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

A PNRP Node was created at the following address: %1

Fields

NameDescription
FuncName

Event ID 35 — The following PNRP clouds were detected.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

The following PNRP clouds were detected: %1

Fields

NameDescription
FuncName

Event ID 36 — A PNRP Node was released at the following address.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

A PNRP Node was released at the following address: %1

Fields

NameDescription
FuncName

Event ID 37 — Started looking for PNRP node with the following address.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Started looking for PNRP node with the following address: %1

Fields

NameDescription
FuncName

Event ID 38 — Stopped looking for PNRP node, address.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Stopped looking for PNRP node, address: %1

Fields

NameDescription
FuncName

Event ID 39 — There was a problem interacting with the PNRP service.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin

Message

There was a problem interacting with the PNRP service.  This component might not be installed correctly. The error code received was: %1

Fields

NameDescription
FuncName

Event ID 40 — Diagnosis Repro Attempt resulted in a success.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Diagnosis Repro Attempt resulted in a success.

Event ID 41 — Diagnosis Repro Attempt resulted in a failure.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Diagnosis Repro Attempt resulted in a failure.

Event ID 42 — Current time on NTP Server.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Current time on NTP Server: %1

Fields

NameDescription
FuncName

Event ID 43 — Remote Assistance troubleshooting rejected problem %1.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Remote Assistance troubleshooting rejected problem %1.

Fields

NameDescription
Code

Event ID 44 — Remote Assistance troubleshooting has confirmed the problem.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance troubleshooting has confirmed the problem: %1.

Fields

NameDescription
FuncName

Event ID 45 — Remote Assistance troubleshooting is starting to repair the identified problem.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance troubleshooting is starting to repair the identified problem: %1.

Fields

NameDescription
FuncName

Event ID 46 — Remote Assistance troubleshooting successfully repaired the problem.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance troubleshooting successfully repaired the problem: %1.

Fields

NameDescription
FuncName

Event ID 47 — Remote Assistance troubleshooting failed to repair the problem.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational

Message

Remote Assistance troubleshooting failed to repair the problem: %1.

Fields

NameDescription
FuncName

Event ID 100 — Remote OS Type.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Remote OS Type : %1.

Fields

NameDescription
Remote_OS_Type
Code

Event ID 101 — Remote Assistance connection attempt failed with error code.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Remote Assistance connection attempt failed with error code: %1.

Fields

NameDescription
Code

Event ID 102 — Remote Assistance reproduced the problem and created following ticket to verify the problem.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing

Message

Remote Assistance reproduced the problem and created following ticket to verify the problem: %1.

Fields

NameDescription
FuncName