Microsoft-Windows-RemoteAssistance

50 events across 4 channels

Event IDTitleChannel
1Entering function FuncName.Tracing
2Leaving function FuncName.Tracing
3Application will terminate, a critical error was detected in file Line line …Application
4Hit exception block of code at file Line line in function function.Tracing
5Branching on Line:line File:file with the string Condition.Tracing
6Switching on Line:line File:file with the value Condition.Tracing
7Entering conditional block at Line:Entering_conditional_block_at_Line File:File.Tracing
8Exiting conditional block at Line:Exiting_conditional_block_at_Line File:File.Tracing
9There was a problem interacting with COM object FuncName.Admin
10A user tried to use Remote Assistance and send an invitation for help through …Admin
11A user opened a Remote Assistance invitation, but the invitation was closed due …Admin
12A user tried to use Remote Assistance, group policy requires a session log to be …Admin
13Remote Assistance started with: FuncName as the command line parameters.Operational
14A Remote Assistance Invitation was successfully opened.Operational
15An RDP connection was successfully made.Operational
16The Remote Assistance password was verified.Operational
17The Remote Assistance password provided was incorrect.Operational
18The Remote Assistance session was disconnected remotely.Operational
19The Remote Assistance session was disconnected locally.Operational
20The Remote Assistance invitation was closed, any information concerning it given …Operational
21The helper is sharing control.Operational
22The helper can now view the screen.Operational
23Remote Assistance detected that it didn't restore the background and screen …Operational
24The time limit of offered invitations has been reached.Operational
25User setting value currently applied is Code.Operational
26The system or GP settings do not allow an Remote Assistance invitation to be …Operational
27The system or GP settings do not allow a helper to share control.Operational
28The Windows firewall has been checked and it appears that it is configured so …Operational
29The error message: FuncName has been shown to the user.Operational
30Remote Assistance has ended.Operational
31Remote Assistance COM server has started.Operational
32Remote Assistance COM server has ended.Operational
33The Remote Assistance ticket contained the following IP addresses: FuncName.Operational
34A PNRP Node was created at the following address: FuncName.Operational
35The following PNRP clouds were detected: FuncName.Operational
36A PNRP Node was released at the following address: FuncName.Operational
37Started looking for PNRP node with the following address: FuncName.Operational
38Stopped looking for PNRP node, address: FuncName.Operational
39There was a problem interacting with the PNRP service.Admin
40Diagnosis Repro Attempt resulted in a success.Operational
41Diagnosis Repro Attempt resulted in a failure.Operational
42Current time on NTP Server: FuncName.Tracing
43Remote Assistance troubleshooting rejected problem Code.Tracing
44Remote Assistance troubleshooting has confirmed the problem: FuncName.Operational
45Remote Assistance troubleshooting is starting to repair the identified problem: …Operational
46Remote Assistance troubleshooting successfully repaired the problem: FuncName.Operational
47Remote Assistance troubleshooting failed to repair the problem: FuncName.Operational
100Remote OS Type : Remote_OS_Type.Tracing
101Remote Assistance connection attempt failed with error code: Code.Tracing
102Remote Assistance reproduced the problem and created following ticket to verify …Tracing

Event ID 1 — Entering function FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Entering function FuncName.

Message #

Entering function %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 2 — Leaving function FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Leaving function FuncName.

Message #

Leaving function %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 3 — Application will terminate, a critical error was detected in file Line line Function function.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Application
Opcode
Stop

Description

Application will terminate, a critical error was detected in file Line line Function function.

Message #

Application will terminate, a critical error was detected in %1 Line %2 Function %3

Fields #

NameDescription
file UnicodeString
line UInt32
function UnicodeString
error UInt32

Event ID 4 — Hit exception block of code at file Line line in function function.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Hit exception block of code at file Line line in function function.

Message #

Hit exception block of code at %1 Line %2 in function %3

Fields #

NameDescription
file UnicodeString
line UInt32
function UnicodeString
error UInt32

Event ID 5 — Branching on Line:line File:file with the string Condition.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Branching on Line:line File:file with the string Condition.

Message #

Branching on Line:%2 File:%1 with the string %3

Fields #

NameDescription
file UnicodeString
line UInt32
Condition UnicodeString

Event ID 6 — Switching on Line:line File:file with the value Condition.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Switching on Line:line File:file with the value Condition.

Message #

Switching on Line:%2 File:%1 with the value %3

Fields #

NameDescription
file UnicodeString
line UInt32
Condition UInt32

Event ID 7 — Entering conditional block at Line:Entering_conditional_block_at_Line File:File.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Entering conditional block at Line:Entering_conditional_block_at_Line File:File.

Message #

Entering conditional block at Line:%1 File:%2

Fields #

NameDescription
Entering_conditional_block_at_Line UInt32
File UnicodeString
line UInt32

Event ID 8 — Exiting conditional block at Line:Exiting_conditional_block_at_Line File:File.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Exiting conditional block at Line:Exiting_conditional_block_at_Line File:File.

Message #

Exiting conditional block at Line:%1 File:%2

Fields #

NameDescription
Exiting_conditional_block_at_Line UInt32
File UnicodeString
line UInt32

Event ID 9 — There was a problem interacting with COM object FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin
Opcode
Info

Description

There was a problem interacting with COM object FuncName. An outdated version might be installed, or the component might not be installed at all.

Message #

There was a problem interacting with COM object %1.  An outdated version might be installed, or the component might not be installed at all.

Fields #

NameDescription
FuncName UnicodeString

Event ID 10 — A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfu...

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin
Opcode
Info

Message #

A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfully send the invitation.  It is possible the email client configured as the default client does not support SMAPI calls, or that the email client is improperly configured.  It is also possible that the user closed the email client without sending the message.

Event ID 11 — A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin
Opcode
Info

Description

A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

Message #

A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

Event ID 12 — A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin
Opcode
Info

Message #

A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.  Remote Assistance was terminated.  Check the disk to see if there are problems with the disk or if it is full.

Event ID 13 — Remote Assistance started with: FuncName as the command line parameters.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance started with: FuncName as the command line parameters.

Message #

Remote Assistance started with: %1    as the command line parameters.

Fields #

NameDescription
FuncName UnicodeString

Event ID 14 — A Remote Assistance Invitation was successfully opened.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

A Remote Assistance Invitation was successfully opened.

Message #

A Remote Assistance Invitation was successfully opened.

Event ID 15 — An RDP connection was successfully made.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

An RDP connection was successfully made.

Message #

An RDP connection was successfully made.

Event ID 16 — The Remote Assistance password was verified.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance password was verified. The Remote Assistance session has begun.

Message #

The Remote Assistance password was verified.  The Remote Assistance session has begun.

Event ID 17 — The Remote Assistance password provided was incorrect.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance password provided was incorrect. The RDP session was terminated, IP address of the connecting machine is FuncName.

Message #

The Remote Assistance password provided was incorrect.  The RDP session was terminated, IP address of the connecting machine is %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 18 — The Remote Assistance session was disconnected remotely.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance session was disconnected remotely.

Message #

The Remote Assistance session was disconnected remotely.

Event ID 19 — The Remote Assistance session was disconnected locally.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance session was disconnected locally.

Message #

The Remote Assistance session was disconnected locally.

Event ID 20 — The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

Message #

The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

Event ID 21 — The helper is sharing control.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The helper is sharing control.

Message #

The helper is sharing control.

Event ID 22 — The helper can now view the screen.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The helper can now view the screen.

Message #

The helper can now view the screen.

Event ID 23 — Remote Assistance detected that it didn't restore the background and screen settings before shutting down.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance detected that it didn't restore the background and screen settings before shutting down. An attempt was made to restore these settings.

Message #

Remote Assistance detected that it didn't restore the background and screen settings before shutting down.  An attempt was made to restore these settings.

Event ID 24 — The time limit of offered invitations has been reached.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The time limit of offered invitations has been reached.

Message #

The time limit of offered invitations has been reached.

Event ID 25 — User setting value currently applied is Code.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

User setting value currently applied is Code.

Message #

User setting value currently applied is %1

Fields #

NameDescription
Code UInt32

Event ID 26 — The system or GP settings do not allow an Remote Assistance invitation to be created.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The system or GP settings do not allow an Remote Assistance invitation to be created. This action has been blocked by the application.

Message #

The system or GP settings do not allow an Remote Assistance invitation to be created.  This action has been blocked by the application.

Event ID 27 — The system or GP settings do not allow a helper to share control.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The system or GP settings do not allow a helper to share control. This action has been blocked by the application.

Message #

The system or GP settings do not allow a helper to share control.  This action has been blocked by the application.

Event ID 28 — The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

Message #

The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

Event ID 29 — The error message: FuncName has been shown to the user.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The error message: FuncName has been shown to the user.

Message #

The error message: %1    has been shown to the user.

Fields #

NameDescription
FuncName UnicodeString

Event ID 30 — Remote Assistance has ended.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance has ended.

Message #

Remote Assistance has ended.

Event ID 31 — Remote Assistance COM server has started.

#
Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Level
Verbose
Opcode
Info

Description

Remote Assistance COM server has started.

Message #

Remote Assistance COM server has started.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteAssistance",
    "guid": "5B0A651A-8807-45CC-9656-7579815B6AF0",
    "event_source_name": "",
    "event_id": 31,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:50:13.780543+00:00",
    "event_record_id": 41,
    "correlation": {},
    "execution": {
      "process_id": 11236,
      "thread_id": 9452
    },
    "channel": "Microsoft-Windows-RemoteAssistance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 32 — Remote Assistance COM server has ended.

#
Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Level
Verbose
Opcode
Info

Description

Remote Assistance COM server has ended.

Message #

Remote Assistance COM server has ended.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteAssistance",
    "guid": "5B0A651A-8807-45CC-9656-7579815B6AF0",
    "event_source_name": "",
    "event_id": 32,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:50:13.791029+00:00",
    "event_record_id": 42,
    "correlation": {},
    "execution": {
      "process_id": 11236,
      "thread_id": 9452
    },
    "channel": "Microsoft-Windows-RemoteAssistance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 33 — The Remote Assistance ticket contained the following IP addresses: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The Remote Assistance ticket contained the following IP addresses: FuncName.

Message #

The Remote Assistance ticket contained the following IP addresses: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 34 — A PNRP Node was created at the following address: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

A PNRP Node was created at the following address: FuncName.

Message #

A PNRP Node was created at the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 35 — The following PNRP clouds were detected: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

The following PNRP clouds were detected: FuncName.

Message #

The following PNRP clouds were detected: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 36 — A PNRP Node was released at the following address: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

A PNRP Node was released at the following address: FuncName.

Message #

A PNRP Node was released at the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 37 — Started looking for PNRP node with the following address: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Started looking for PNRP node with the following address: FuncName.

Message #

Started looking for PNRP node with the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 38 — Stopped looking for PNRP node, address: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Stopped looking for PNRP node, address: FuncName.

Message #

Stopped looking for PNRP node, address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 39 — There was a problem interacting with the PNRP service.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Admin
Opcode
Info

Description

There was a problem interacting with the PNRP service. This component might not be installed correctly. The error code received was: FuncName.

Message #

There was a problem interacting with the PNRP service.  This component might not be installed correctly. The error code received was: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 40 — Diagnosis Repro Attempt resulted in a success.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Diagnosis Repro Attempt resulted in a success.

Message #

Diagnosis Repro Attempt resulted in a success.

Event ID 41 — Diagnosis Repro Attempt resulted in a failure.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Diagnosis Repro Attempt resulted in a failure.

Message #

Diagnosis Repro Attempt resulted in a failure.

Event ID 42 — Current time on NTP Server: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Current time on NTP Server: FuncName.

Message #

Current time on NTP Server: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 43 — Remote Assistance troubleshooting rejected problem Code.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Remote Assistance troubleshooting rejected problem Code.

Message #

Remote Assistance troubleshooting rejected problem %1.

Fields #

NameDescription
Code UInt32

Event ID 44 — Remote Assistance troubleshooting has confirmed the problem: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance troubleshooting has confirmed the problem: FuncName.

Message #

Remote Assistance troubleshooting has confirmed the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 45 — Remote Assistance troubleshooting is starting to repair the identified problem: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance troubleshooting is starting to repair the identified problem: FuncName.

Message #

Remote Assistance troubleshooting is starting to repair the identified problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 46 — Remote Assistance troubleshooting successfully repaired the problem: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance troubleshooting successfully repaired the problem: FuncName.

Message #

Remote Assistance troubleshooting successfully repaired the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 47 — Remote Assistance troubleshooting failed to repair the problem: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Operational
Opcode
Info

Description

Remote Assistance troubleshooting failed to repair the problem: FuncName.

Message #

Remote Assistance troubleshooting failed to repair the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 100 — Remote OS Type : Remote_OS_Type.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Remote OS Type : Remote_OS_Type.

Message #

Remote OS Type : %1.

Fields #

NameDescription
Remote_OS_Type UInt32
Code UInt32

Event ID 101 — Remote Assistance connection attempt failed with error code: Code.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Remote Assistance connection attempt failed with error code: Code.

Message #

Remote Assistance connection attempt failed with error code: %1.

Fields #

NameDescription
Code UInt32

Event ID 102 — Remote Assistance reproduced the problem and created following ticket to verify the problem: FuncName.

Provider
Microsoft-Windows-RemoteAssistance
Channel
Tracing
Opcode
Info

Description

Remote Assistance reproduced the problem and created following ticket to verify the problem: FuncName.

Message #

Remote Assistance reproduced the problem and created following ticket to verify the problem: %1.

Fields #

NameDescription
FuncName UnicodeString