Microsoft-Windows-RemoteAssistance
50 events across 4 channels
Event ID 1 — Entering function %1.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 2 — Leaving function %1.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 3 — Application will terminate, a critical error was detected in %1 Line %2 Function %3.
Message
Fields
| Name | Description |
|---|---|
file | — |
line | — |
function | — |
error | — |
Event ID 4 — Hit exception block of code at %1 Line %2 in function %3.
Message
Fields
| Name | Description |
|---|---|
file | — |
line | — |
function | — |
error | — |
Event ID 5 — Branching on Line:%2 File:%1 with the string %3.
Message
Fields
| Name | Description |
|---|---|
file | — |
line | — |
Condition | — |
Event ID 6 — Switching on Line:%2 File:%1 with the value %3.
Message
Fields
| Name | Description |
|---|---|
file | — |
line | — |
Condition | — |
Event ID 7 — Entering conditional block at Line:%1 File:%2.
Message
Fields
| Name | Description |
|---|---|
Entering_conditional_block_at_Line | — |
File | — |
line | — |
Event ID 8 — Exiting conditional block at Line:%1 File:%2.
Message
Fields
| Name | Description |
|---|---|
Exiting_conditional_block_at_Line | — |
File | — |
line | — |
Event ID 9 — There was a problem interacting with COM object %1.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 10 — A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfu...
Message
Event ID 11 — A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.
Message
Event ID 12 — A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.
Message
Event ID 13 — Remote Assistance started with: %1 as the command line parameters.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 14 — A Remote Assistance Invitation was successfully opened.
Message
Event ID 15 — An RDP connection was successfully made.
Message
Event ID 16 — The Remote Assistance password was verified.
Message
Event ID 17 — The Remote Assistance password provided was incorrect.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 18 — The Remote Assistance session was disconnected remotely.
Message
Event ID 19 — The Remote Assistance session was disconnected locally.
Message
Event ID 20 — The Remote Assistance invitation was closed, any information concerning it given out is now invalid.
Message
Event ID 21 — The helper is sharing control.
Message
Event ID 22 — The helper can now view the screen.
Message
Event ID 23 — Remote Assistance detected that it didn't restore the background and screen settings before shutting down.
Message
Event ID 24 — The time limit of offered invitations has been reached.
Message
Event ID 25 — User setting value currently applied is %1.
Message
Fields
| Name | Description |
|---|---|
Code | — |
Event ID 26 — The system or GP settings do not allow an Remote Assistance invitation to be created.
Message
Event ID 27 — The system or GP settings do not allow a helper to share control.
Message
Event ID 28 — The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.
Message
Event ID 29 — The error message: %1 has been shown to the user.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 30 — Remote Assistance has ended.
Message
Event ID 31 — Remote Assistance COM server has started.
Message
Example Event
system:
provider: Microsoft-Windows-RemoteAssistance
guid: 5B0A651A-8807-45CC-9656-7579815B6AF0
event_source_name: ''
event_id: 31
version: 0
level: 5
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T23:50:13.780543+00:00'
event_record_id: 41
correlation: {}
execution:
process_id: 11236
thread_id: 9452
channel: Microsoft-Windows-RemoteAssistance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 32 — Remote Assistance COM server has ended.
Message
Example Event
system:
provider: Microsoft-Windows-RemoteAssistance
guid: 5B0A651A-8807-45CC-9656-7579815B6AF0
event_source_name: ''
event_id: 32
version: 0
level: 5
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T23:50:13.791029+00:00'
event_record_id: 42
correlation: {}
execution:
process_id: 11236
thread_id: 9452
channel: Microsoft-Windows-RemoteAssistance/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 33 — The Remote Assistance ticket contained the following IP addresses.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 34 — A PNRP Node was created at the following address.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 35 — The following PNRP clouds were detected.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 36 — A PNRP Node was released at the following address.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 37 — Started looking for PNRP node with the following address.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 38 — Stopped looking for PNRP node, address.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 39 — There was a problem interacting with the PNRP service.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 40 — Diagnosis Repro Attempt resulted in a success.
Message
Event ID 41 — Diagnosis Repro Attempt resulted in a failure.
Message
Event ID 42 — Current time on NTP Server.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 43 — Remote Assistance troubleshooting rejected problem %1.
Message
Fields
| Name | Description |
|---|---|
Code | — |
Event ID 44 — Remote Assistance troubleshooting has confirmed the problem.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 45 — Remote Assistance troubleshooting is starting to repair the identified problem.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 46 — Remote Assistance troubleshooting successfully repaired the problem.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 47 — Remote Assistance troubleshooting failed to repair the problem.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |
Event ID 100 — Remote OS Type.
Message
Fields
| Name | Description |
|---|---|
Remote_OS_Type | — |
Code | — |
Event ID 101 — Remote Assistance connection attempt failed with error code.
Message
Fields
| Name | Description |
|---|---|
Code | — |
Event ID 102 — Remote Assistance reproduced the problem and created following ticket to verify the problem.
Message
Fields
| Name | Description |
|---|---|
FuncName | — |