Microsoft-Windows-RemoteDesktopServices-RdpCoreTS

89 events across 3 channels

Event IDTitleChannel
1The RDP Graphics module failed to initialize.Admin
2Remote Desktop Protocol will use the RDP Graphics module to connect to the …Admin
3The RemoteFX module failed to initialize.Admin
4The RemoteFX module failed to initialize.Admin
5The client computer does not support RemoteFX.Admin
6The resolution requested by the remote client is not supported by RemoteFX.Admin
7The resolution requested by the remote client could not be set.Admin
8Module terminated.Admin
33Remote Desktop Protocol will use the RemoteFX guest mode module to connect to …Operational
34Remote Desktop Protocol will use the RemoteFX host mode module to connect to the …Operational
35Unable to initialize the RemoteFX host mode module.Admin
36Unable to initialize the RemoteFX host mode module.Admin
37The display resolution requested by the remote client is not supported by …Operational
38The display resolution requested by the remote client could not be enabled.Operational
65Connection ConnectionName created.Operational
66The connection ConnectionName was assigned to session SessionID.Operational
67The RemoteFX protocol connection ConnectionName encountered an error …Operational
68TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, …Operational
69Listener ModuleName is loaded.Operational
70The listener listens with display driver DisplayDriverName available.Operational
71The connection ConnectionName uses display driver DisplayDriverName.Operational
72Interface method called: Interface_method_called.Operational
73Inner encryption disabled?Operational
97The RDP protocol component ComponentName detected an error (ErrorCode) in the …Operational
98A TCP connection has been successfully established.Operational
99The TCP connection has failed with the error code ResultCode.Operational
100The server has confirmed that the client's multi-transport capability.Operational
101The network characteristics detection function has been disabled because of …Operational
102The server has terminated main RDP connection with the client.Operational
103The disconnect reason is ReasonCode.Operational
104Client timezone is TimezoneBiasHour hour from UTC.Operational
105The server's security layer setting allows it to use native RDP encryption, …Admin
106Disconnect initiated by server; forcing an AutoReconnect since listener is …Operational
107Received Disconnect Provider Indication from the client.Operational
129The server is using TransportProtocolName to bind to port Port.Operational
130The server has initiated a multi-transport request to the client, for tunnel: …Operational
131The server accepted a new ConnType connection from client ClientIP.Operational
132A channel ChannelName has been connected between the server and the client using …Operational
133The following network characteristics have been detected for tunnel TunnelID; …Operational
134Link latency and bandwidth could not be detected for tunnel TunnelID.Operational
135The multi-transport connection finished for tunnel: …Operational
136Unable to establish a multi-transport connection; the connection will use TCP.Operational
137The following network characteristics have been detected for tunnel TunnelID; …Operational
138The DTLS initialization failed with the error code ResultCode, TLS will be used …Admin
139The server security layer detected an error (ResultCode) in the protocol stream …Operational
140A connection from the client computer with an IP address of IPString failed …Operational
141PerfCounter session started with instance ID InstanceID.Operational
142TCP socket READ operation failed, error error.Operational
143TCP socket WRITE operation failed, error error.Operational
144TCP socket was gracefully terminatedOperational
145During this connection, server has not sent data or graphics update for Idle2 …Operational
146AutoReconnect failed with error Error.Operational
147LogonUserExEx failed with error Error.Operational
148Channel ChannelName has been closed between the server and the client on …Operational
149Logon certificate sent by client did not pass validation.Operational
150Long delay experienced while flushing data to the network.Debug
151In the past ms_all_packets_throughout_connection ms, HistoryMs heartbeats were …Debug
152Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last …Debug
153Session negotiated TLS version TLSVersion.Debug
154Message.Operational
155RDP Diagnostic HeartbeatDebug
161The RemoteFX encoding engine encountered an error (ErrorCode).Operational
162The client supports version AVC_available of the RDP graphics protocol, client …Operational
163The client supports RDP 7.Operational
164The client advertised protocol configurations which are not supported by the …Operational
165RDP RemoteFX graphics encoding is enabled.Operational
166The RemoteFX Adaptive Graphics internal configuration changed to optimize for …Operational
167The RemoteFX Adaptive Graphics internal configuration changed to optimize for …Operational
168The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, …Operational
169The client operating system type is (MajorType, MinorType).Operational
170AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is …Operational
171The client is uncapable to support screen capture protection feature.Operational
172The client is uncapable to support watermarking feature.Operational
193The RemoteFX Media Remoting is not supported by the client.Operational
194The RemoteFX Media Remoting is not supported by the current server …Operational
195The RemoteFX Media Remoting module encountered an error.Operational
225StateTransition: Transitioned successfully from PreviousStateName to …Debug
226StateTransition: An error was encountered when transitioning from …Operational
227CustomLevel.Operational
228Disconnect trace:Disconnect_trace %2, Error code:%3.Operational
229CustomLevel.Operational
257The connection is using advanced RemoteFX RemoteApp graphics.Operational
258The connection is not using advanced RemoteFX RemoteApp graphicsOperational
289Got UDP reverse connect request to URL port Port connection id ConnectionID.Operational
290UDP reverse connect successful.Operational
291UDP reverse connect failed with error Error.Operational
292Multi transport listener NOT initialized.Operational
293Multi transport listener initialized.Operational
294Reverse UDP connect is disabled by SxS registry settings.Operational

Event ID 1 — The RDP Graphics module failed to initialize.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RDPStack
Opcode
Initialize

Description

The RDP Graphics module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status error code was HresultCode.

Message #

The RDP Graphics module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status error code was %1.

Fields #

NameDescription
HresultCode HexInt32

Event ID 2 — Remote Desktop Protocol will use the RDP Graphics module to connect to the client computer.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RDPStack
Opcode
Initialize

Message #

Remote Desktop Protocol will use the RDP Graphics module to connect to the client computer. The RDP Graphics module is being used based on the server configuration, client configuration, and network connection.

Event ID 3 — The RemoteFX module failed to initialize.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was ErrorCode.

Message #

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 4 — The RemoteFX module failed to initialize.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was ErrorCode.

Message #

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 5 — The client computer does not support RemoteFX.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The client computer does not support RemoteFX. The connection will be made with the RDP Graphics. The relevant status code was StatusCode.

Message #

The client computer does not support RemoteFX. The connection will be made with the RDP Graphics. The relevant status code was %1.

Fields #

NameDescription
StatusCode HexInt32

Event ID 6 — The resolution requested by the remote client is not supported by RemoteFX.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Message #

The resolution requested by the remote client is not supported by RemoteFX. The connection will be made with RemoteFX using a supported resolution. Resolution requested by the client: Monitors %1: %2. Resolution applied: %3.

Fields #

NameDescription
NumMonitors UInt32
RequestedMode UnicodeString
AppliedMode UnicodeString

Event ID 7 — The resolution requested by the remote client could not be set.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The resolution requested by the remote client could not be set. The default resolution will be set for the RemoteFX session. The server may be experiencing high load or require a restart.

Message #

The resolution requested by the remote client could not be set. The default resolution will be set for the RemoteFX session. The server may be experiencing high load or require a restart.

Event ID 8 — Module terminated.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Terminate

Description

Module terminated.

Message #

Module terminated.

Event ID 33 — Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

Message #

Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 33,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.553439Z",
    "event_record_id": 898,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 34 — Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

Message #

Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

Event ID 35 — Unable to initialize the RemoteFX host mode module.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is HresultCode.

Message #

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is %1.

Fields #

NameDescription
HresultCode HexInt32

Event ID 36 — Unable to initialize the RemoteFX host mode module.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is ErrorCode.

Message #

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 37 — The display resolution requested by the remote client is not supported by RemoteFX host mode module.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The display resolution requested by the remote client is not supported by RemoteFX host mode module. The resolution requested by the client: Monitors NumMonitors: RequestedMode. Resolution applied: AppliedMode.

Message #

The display resolution requested by the remote client is not supported by RemoteFX host mode module. The resolution requested by the client: Monitors %1: %2. Resolution applied: %3.

Fields #

NameDescription
NumMonitors UInt32
RequestedMode UnicodeString
AppliedMode UnicodeString

Event ID 38 — The display resolution requested by the remote client could not be enabled.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The display resolution requested by the remote client could not be enabled. The default resolution will be enabled for the RemoteFX session. The server may be experiencing high load.

Message #

The display resolution requested by the remote client could not be enabled. The default resolution will be enabled for the RemoteFX session. The server may be experiencing high load

Event ID 65 — Connection ConnectionName created.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Connection ConnectionName created.

Message #

Connection %1 created

Fields #

NameDescription
ConnectionName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 65,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.546169Z",
    "event_record_id": 846,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1660
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#5"
  }
}

References #

Event ID 66 — The connection ConnectionName was assigned to session SessionID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The connection ConnectionName was assigned to session SessionID.

Message #

The connection %1 was assigned to session %2

Fields #

NameDescription
ConnectionName UnicodeString
SessionID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 66,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.547380Z",
    "event_record_id": 897,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#7",
    "SessionID": 1
  }
}

References #

Event ID 67 — The RemoteFX protocol connection ConnectionName encountered an error (ErrorCode).

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The RemoteFX protocol connection ConnectionName encountered an error (ErrorCode).

Message #

The RemoteFX protocol connection %1 encountered an error (%2)

Fields #

NameDescription
ConnectionName UnicodeString
ErrorCode HexInt32

Event ID 68 — TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, PromptForCredentialsDone=PromptForCredentialsDone, GfxChannelOpened=GfxChannelOpened, FirstGraphicsReceived=FirstGraph...

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, PromptForCredentialsDone=PromptForCredentialsDone, GfxChannelOpened=GfxChannelOpened, FirstGraphicsReceived=FirstGraphicsReceived [ms].

Message #

TMT: ConnectionName=%1, PromptForCredentials=%2, PromptForCredentialsDone=%3, GfxChannelOpened=%4, FirstGraphicsReceived=%5 [ms]

Fields #

NameDescription
ConnectionName UnicodeString
PromptForCredentials UInt32
PromptForCredentialsDone UInt32
GfxChannelOpened UInt32
FirstGraphicsReceived UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 68,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:15.885301Z",
    "event_record_id": 12592,
    "correlation": {
      "#attributes": {
        "ActivityID": "AF159B2D-D587-4709-AB35-F167130B0000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 8512
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#0",
    "PromptForCredentials": 0,
    "PromptForCredentialsDone": 0,
    "GfxChannelOpened": 8266,
    "FirstGraphicsReceived": 10672
  }
}

References #

Event ID 69 — Listener ModuleName is loaded.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Listener ModuleName is loaded.

Message #

Listener %1 is loaded

Fields #

NameDescription
ModuleName UnicodeString

Event ID 70 — The listener listens with display driver DisplayDriverName available.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The listener listens with display driver DisplayDriverName available.

Message #

The listener listens with display driver %1 available.

Fields #

NameDescription
DisplayDriverName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 70,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T03:36:49.826774Z",
    "event_record_id": 979,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4624E4C-DF38-4BB3-A4DB-3782C9880000"
      }
    },
    "execution": {
      "process_id": 480,
      "thread_id": 1196
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "DisplayDriverName": "rdpudd.dll"
  }
}

References #

Event ID 71 — The connection ConnectionName uses display driver DisplayDriverName.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The connection ConnectionName uses display driver DisplayDriverName.

Message #

The connection %1 uses display driver %2.

Fields #

NameDescription
ConnectionName UnicodeString
DisplayDriverName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 71,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.622046Z",
    "event_record_id": 886,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7136
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#7",
    "DisplayDriverName": "RDPUDD"
  }
}

References #

Event ID 72 — Interface method called: Interface_method_called.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Interface method called: Interface_method_called.

Message #

Interface method called: %1

Fields #

NameDescription
Interface_method_called

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 72,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.548440Z",
    "event_record_id": 847,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MethodName": "PrepareForAccept"
  }
}

References #

Event ID 73 — Inner encryption disabled?

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Inner encryption disabled? Disabled.

Message #

Inner encryption disabled? %1

Fields #

NameDescription
Disabled UInt32

Event ID 97 — The RDP protocol component ComponentName detected an error (ErrorCode) in the protocol stream and the client was disconnected.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

The RDP protocol component ComponentName detected an error (ErrorCode) in the protocol stream and the client was disconnected.

Message #

The RDP protocol component %1 detected an error (%2) in the protocol stream and the client was disconnected.

Fields #

NameDescription
ComponentName UnicodeString
ErrorCode UInt32

Event ID 98 — A TCP connection has been successfully established.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

A TCP connection has been successfully established.

Message #

A TCP connection has been successfully established.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 98,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624254Z",
    "event_record_id": 891,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 99 — The TCP connection has failed with the error code ResultCode.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The TCP connection has failed with the error code ResultCode.

Message #

The TCP connection has failed with the error code %1.

Fields #

NameDescription
ResultCode HexInt32

Event ID 100 — The server has confirmed that the client's multi-transport capability.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server has confirmed that the client's multi-transport capability.

Message #

The server has confirmed that the client's multi-transport capability.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624261Z",
    "event_record_id": 892,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 101 — The network characteristics detection function has been disabled because of ReasonString.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The network characteristics detection function has been disabled because of ReasonString.

Message #

The network characteristics detection function has been disabled because of %1.

Fields #

NameDescription
ReasonString UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 101,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 16,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.621408Z",
    "event_record_id": 880,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ReasonString": "Reason Code: 2(Server Configuration)."
  }
}

References #

Event ID 102 — The server has terminated main RDP connection with the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

The server has terminated main RDP connection with the client.

Message #

The server has terminated main RDP connection with the client.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852452Z",
    "event_record_id": 854,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 103 — The disconnect reason is ReasonCode.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

The disconnect reason is ReasonCode.

Message #

The disconnect reason is %1

Fields #

NameDescription
ReasonCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852505Z",
    "event_record_id": 857,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ReasonCode": 14
  }
}

References #

Event ID 104 — Client timezone is TimezoneBiasHour hour from UTC.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

Client timezone is TimezoneBiasHour hour from UTC.

Message #

Client timezone is %1 hour from UTC;

Fields #

NameDescription
TimezoneBiasHour UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2020-07-09T19:47:00.719124Z",
    "event_record_id": 1129,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420CA7A-0E56-4135-8A7C-CE2182D30000"
      }
    },
    "execution": {
      "process_id": 476,
      "thread_id": 4152
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TimezoneBiasHour": "[1]"
  }
}

References #

Event ID 105 — The server's security layer setting allows it to use native RDP encryption, which is no longer recommended.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Message #

The server's security layer setting allows it to use native RDP encryption, which is no longer recommended. Consider changing the server security layer to require SSL. You can change this setting in Group Policy.

Event ID 106 — Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

Message #

Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

Event ID 107 — Received Disconnect Provider Indication from the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Received Disconnect Provider Indication from the client.

Message #

Received Disconnect Provider Indication from the client.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 107,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T10:07:43.924049Z",
    "event_record_id": 1066,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4202795-713F-468C-BA0B-6C1C2F0C0000"
      }
    },
    "execution": {
      "process_id": 396,
      "thread_id": 1064
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 129 — The server is using TransportProtocolName to bind to port Port.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
NetworkBinding

Description

The server is using TransportProtocolName to bind to port Port.

Message #

The server is using %1 to bind to port %2.

Fields #

NameDescription
TransportProtocolName UnicodeString
Port UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 129,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 18,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T03:36:49.907396Z",
    "event_record_id": 980,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4624E4C-DF38-4BB3-A4DB-3782C9880000"
      }
    },
    "execution": {
      "process_id": 480,
      "thread_id": 1196
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TransportProtocolName": "TCP",
    "Port": 3389
  }
}

References #

Event ID 130 — The server has initiated a multi-transport request to the client, for tunnel: The_server_has_initiated_a_multitransport_request_to_the_client_for_tunnel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server has initiated a multi-transport request to the client, for tunnel: The_server_has_initiated_a_multitransport_request_to_the_client_for_tunnel.

Message #

The server has initiated a multi-transport request to the client, for tunnel: %1.

Fields #

NameDescription
The_server_has_initiated_a_multitransport_request_to_the_client_for_tunnelThe server has initiated a multi-transport request to the client, for tunnel.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 130,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.625322Z",
    "event_record_id": 894,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TunnelID": 1
  }
}

References #

Event ID 131 — The server accepted a new ConnType connection from client ClientIP.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server accepted a new ConnType connection from client ClientIP.

Message #

The server accepted a new %1 connection from client %2.

Fields #

NameDescription
ConnType UnicodeString
ClientIP UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 131,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:07.084053Z",
    "event_record_id": 12551,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4207C37-D7A8-4A5E-9A35-4E79CAA60000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 1292
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnType": "TCP",
    "ClientIP": "10.0.2.16:52202"
  }
}

References #

Event ID 132 — A channel ChannelName has been connected between the server and the client using transport tunnel: TunnelID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

A channel ChannelName has been connected between the server and the client using transport tunnel: TunnelID.

Message #

A channel %1 has been connected between the server and the client using transport tunnel: %2.

Fields #

NameDescription
ChannelName UnicodeString
TunnelID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 132,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.621433Z",
    "event_record_id": 881,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ChannelName": "rdplic",
    "TunnelID": 0
  }
}

References #

Event ID 133 — The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

Message #

The following network characteristics have been detected for tunnel %1; Link latency : %2 milliseconds and Bandwidth: %3 kbps.

Fields #

NameDescription
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 134 — Link latency and bandwidth could not be detected for tunnel TunnelID.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

Link latency and bandwidth could not be detected for tunnel TunnelID. The error code is ResultCode. The following default network characteristics will be used; Link latency: RTT milliseconds and Bandwidth:Bandwidth kbps.

Message #

Link latency and bandwidth could not be detected for tunnel %2.  The error code is %1. The following default network characteristics will be used;  Link latency: %3 milliseconds and Bandwidth:%4 kbps.

Fields #

NameDescription
ResultCode HexInt32
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 135 — The multi-transport connection finished for tunnel: The_multitransport_connection_finished_for_tunnel, its transport type set to %2.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The multi-transport connection finished for tunnel: The_multitransport_connection_finished_for_tunnel, its transport type set to %2.

Message #

The multi-transport connection finished for tunnel: %1, its transport type set to %2.

Fields #

NameDescription
The_multitransport_connection_finished_for_tunnelThe multi-transport connection finished for tunnel.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 135,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624288Z",
    "event_record_id": 893,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TunnelID": 3,
    "TransportType": "TCP: Reason Code: 2 (Forced by Server Configuration)"
  }
}

References #

Event ID 136 — Unable to establish a multi-transport connection; the connection will use TCP.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

Unable to establish a multi-transport connection; the connection will use TCP. Consult the product documentation to enable UDP Connections.

Message #

Unable to establish a multi-transport connection; the connection will use TCP. Consult the product documentation to enable UDP Connections.

Event ID 137 — The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The following network characteristics have been detected for tunnel ; Link latency : milliseconds and Bandwidth: kbps. Connections with these network characteristics may impact user experience.

Message #

The following network characteristics have been detected for tunnel %1; Link latency : %2 milliseconds and Bandwidth: %3 kbps. Connections with these network characteristics may impact user experience.

Fields #

NameDescription
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 138 — The DTLS initialization failed with the error code ResultCode, TLS will be used instead.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The DTLS initialization failed with the error code ResultCode, TLS will be used instead. Audio/Video experience may be impacted.

Message #

The DTLS initialization failed with the error code %1, TLS will be used instead. Audio/Video experience may be impacted.

Fields #

NameDescription
ResultCode HexInt32

Event ID 139 — The server security layer detected an error (ResultCode) in the protocol stream and the client (Client IP:IPString) has been disconnected.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

The server security layer detected an error (ResultCode) in the protocol stream and the client (Client IP:IPString) has been disconnected.

Message #

The server security layer detected an error (%1) in the protocol stream and the client (Client IP:%2) has been disconnected.

Fields #

NameDescription
ResultCode HexInt32
IPString UnicodeString

Event ID 140 — A connection from the client computer with an IP address of IPString failed because the user name or password is not correct.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

A connection from the client computer with an IP address of IPString failed because the user name or password is not correct.

Message #

A connection from the client computer with an IP address of %1 failed because the user name or password is not correct.

Fields #

NameDescription
IPString UnicodeString

Event ID 141 — PerfCounter session started with instance ID InstanceID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

PerfCounter session started with instance ID InstanceID.

Message #

PerfCounter session started with instance ID %1

Fields #

NameDescription
InstanceID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 141,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.549456Z",
    "event_record_id": 849,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "InstanceID": 5
  }
}

References #

Event ID 142 — TCP socket READ operation failed, error error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket READ operation failed, error error.

Message #

TCP socket READ operation failed, error %1

Fields #

NameDescription
error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 142,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851987Z",
    "event_record_id": 852,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "error": 64
  }
}

References #

Event ID 143 — TCP socket WRITE operation failed, error error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket WRITE operation failed, error error.

Message #

TCP socket WRITE operation failed, error %1

Fields #

NameDescription
error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 143,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851924Z",
    "event_record_id": 850,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 4988
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "error": 64
  }
}

References #

Event ID 144 — TCP socket was gracefully terminated

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket was gracefully terminated.

Message #

TCP socket was gracefully terminated

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 144,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T10:16:51.112394+00:00",
    "event_record_id": 4129,
    "correlation": {
      "ActivityID": "F420FF93-1637-4090-92CE-51A628CA0000"
    },
    "execution": {
      "process_id": 1536,
      "thread_id": 9036
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 145 — During this connection, server has not sent data or graphics update for Idle2 seconds (Idle1: %2, Idle2: %3).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

During this connection, server has not sent data or graphics update for Idle2 seconds (Idle1: %2, Idle2: %3).

Message #

During this connection, server has not sent data or graphics update for %1 seconds (Idle1: %2, Idle2: %3).

Fields #

NameDescription
Idle21 seconds (Idle1.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 145,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852455Z",
    "event_record_id": 855,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "IdleSeconds": 0,
    "IdleSeconds1": 0,
    "IdleSeconds2": 0
  }
}

References #

Event ID 146 — AutoReconnect failed with error Error.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

AutoReconnect failed with error Error.

Message #

AutoReconnect failed with error %1

Fields #

NameDescription
Error UnicodeString

Event ID 147 — LogonUserExEx failed with error Error.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

LogonUserExEx failed with error Error.

Message #

LogonUserExEx failed with error %1

Fields #

NameDescription
Error HexInt32

Event ID 148 — Channel ChannelName has been closed between the server and the client on transport tunnel: TunnelID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Channel ChannelName has been closed between the server and the client on transport tunnel: TunnelID.

Message #

Channel %1 has been closed between the server and the client on transport tunnel: %2.

Fields #

NameDescription
ChannelName UnicodeString
TunnelID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 148,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852505Z",
    "event_record_id": 856,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ChannelName": "rdpinpt",
    "TunnelID": 0
  }
}

References #

Event ID 149 — Logon certificate sent by client did not pass validation.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Logon certificate sent by client did not pass validation. Error: ErrorCode.

Message #

Logon certificate sent by client did not pass validation. Error: %1

Fields #

NameDescription
ErrorCode HexInt32

Event ID 150 — Long delay experienced while flushing data to the network.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Long delay experienced while flushing data to the network. Flush time: FlushTimeMs ms, flush interval: FlushIntervalMs ms.

Message #

Long delay experienced while flushing data to the network. Flush time: %1 ms, flush interval: %2 ms.

Fields #

NameDescription
FlushTimeMs UInt32
FlushIntervalMs UInt32

Event ID 151 — In the past ms_all_packets_throughout_connection ms, HistoryMs heartbeats were sent to the client.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Message #

In the past %1 ms, %2 heartbeats were sent to the client. Max time without sending packets in recent history: %3 ms (all packets); throughout connection: %4 ms (data), %5 ms (heartbeats), %6 ms (all packets). Time between disconnect and last packet sent: %7 ms

Fields #

NameDescription
ms_all_packets_throughout_connection
HistoryMs UInt32
NumHeartbeats UInt32
MaxRecentTimeNoPacketMs UInt32
MaxTotalTimeNoDataMs UInt32
MaxTotalTimeNoHeartbeatMs UInt32
MaxTotalTimeNoPacketMs UInt32
TimeNoLastPacketMs UInt32

Event ID 152 — Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last sent: data_packet_last_sent ms, heartbeat last sent: ms_heartbeat_last_sent ms.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last sent: data_packet_last_sent ms, heartbeat last sent: ms_heartbeat_last_sent ms.

Message #

Timestamp: %1 ms, heartbeats sent: %2, data packet last sent: %3 ms, heartbeat last sent: %4 ms.

Fields #

NameDescription
Timestamp UInt32
ms_heartbeats_sent UInt32ms, heartbeats sent.
data_packet_last_sent UInt32
ms_heartbeat_last_sent UInt32ms, heartbeat last sent.
TimestampMs UInt32
NumHeartbeats UInt32
LastDataPacketMs UInt32
LastHeartbeatMs UInt32

Event ID 153 — Session negotiated TLS version TLSVersion.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Session negotiated TLS version TLSVersion.

Message #

Session negotiated TLS version %1

Fields #

NameDescription
TLSVersion UnicodeString

Event ID 154 — Message.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Message #

%1. Error %2

Fields #

NameDescription
Message UnicodeString
Error HexInt32

Event ID 155 — RDP Diagnostic Heartbeat

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

RDP Diagnostic Heartbeat.

Message #

RDP Diagnostic Heartbeat

Event ID 161 — The RemoteFX encoding engine encountered an error (ErrorCode).

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX encoding engine encountered an error (ErrorCode). Server: ServerName.

Message #

The RemoteFX encoding engine encountered an error (%1). Server: %2

Fields #

NameDescription
ErrorCode HexInt32
ServerName UnicodeString

Event ID 162 — The client supports version AVC_available of the RDP graphics protocol, client mode: Initial_profile, AVC available: Server, Initial profile: %4.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client supports version AVC_available of the RDP graphics protocol, client mode: Initial_profile, AVC available: Server, Initial profile: %4. Server: %5.

Message #

The client supports version %1 of the RDP graphics protocol, client mode: %2, AVC available: %3, Initial profile: %4. Server: %5

Fields #

NameDescription
AVC_available1 of the RDP graphics protocol, client mode.
Initial_profile
Server

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.742779Z",
    "event_record_id": 908,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 8020
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Version": "0xa0301",
    "ClientMode": 2,
    "AvcEnabled": 1,
    "ProfileIdNum": 2,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 163 — The client supports RDP 7.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client supports RDP 7.1 or lower protocol. Server: Server.

Message #

The client supports RDP 7.1 or lower protocol. Server: %1

Fields #

NameDescription
Server

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 163,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T14:22:27.573268Z",
    "event_record_id": 1356,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4201740-D459-489E-A55C-BFE842340000"
      }
    },
    "execution": {
      "process_id": 396,
      "thread_id": 1336
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 164 — The client advertised protocol configurations which are not supported by the server.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client advertised protocol configurations which are not supported by the server. Server: ServerName.

Message #

The client advertised protocol configurations which are not supported by the server. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 165 — RDP RemoteFX graphics encoding is enabled.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

RDP RemoteFX graphics encoding is enabled. Server: ServerName.

Message #

RDP RemoteFX graphics encoding is enabled. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 166 — The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth. Server: ServerName.

Message #

The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 167 — The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience. Server: ServerName.

Message #

The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 168 — The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, MonitorHeight), origin: (MonitorX, MonitorY).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, MonitorHeight), origin: (MonitorX, MonitorY). Server: ServerName.

Message #

The resolution requested by the client: Monitor %1: (%2, %3), origin: (%4, %5). Server: %6

Fields #

NameDescription
MonitorNum UInt32
MonitorWidth UInt32
MonitorHeight UInt32
MonitorX UInt32
MonitorY UInt32
ServerName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 168,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:15.564770Z",
    "event_record_id": 12591,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4207C37-D7A8-4A5E-9A35-4E79CAA60000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MonitorNum": 0,
    "MonitorWidth": 200,
    "MonitorHeight": 200,
    "MonitorX": 0,
    "MonitorY": 0,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 169 — The client operating system type is (MajorType, MinorType).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client operating system type is (MajorType, MinorType). Server: ServerName.

Message #

The client operating system type is (%1, %2).  Server: %3

Fields #

NameDescription
MajorType UInt32
MinorType UInt32
ServerName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 169,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.567652Z",
    "event_record_id": 902,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MajorType": 1,
    "MinorType": 3,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 170 — AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is IsHardwareEncode.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is IsHardwareEncode. Server: EncoderMFTName.

Message #

AVC hardware encoder enabled: %1, encoder name is %2. Server: %3

Fields #

NameDescription
AVC_hardware_encoder_enabled
IsHardwareEncode UInt32
EncoderMFTName UnicodeString
ServerName UnicodeString

Event ID 171 — The client is uncapable to support screen capture protection feature.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client is uncapable to support screen capture protection feature. Server: ServerName.

Message #

The client is uncapable to support screen capture protection feature. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 172 — The client is uncapable to support watermarking feature.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client is uncapable to support watermarking feature. Server: ServerName.

Message #

The client is uncapable to support watermarking feature. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 193 — The RemoteFX Media Remoting is not supported by the client.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting is not supported by the client.

Message #

The RemoteFX Media Remoting is not supported by the client.

Event ID 194 — The RemoteFX Media Remoting is not supported by the current server configuration.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting is not supported by the current server configuration.

Message #

The RemoteFX Media Remoting is not supported by the current server configuration.

Event ID 195 — The RemoteFX Media Remoting module encountered an error.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting module encountered an error. The error code is ErrorCode.

Message #

The RemoteFX Media Remoting module encountered an error. The error code is %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 225 — StateTransition: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

StateTransition: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Message #

%1: Transitioned successfully from %3 to %5 in response to %7.

Fields #

NameDescription
StateTransition UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString

Event ID 226 — StateTransition: An error was encountered when transitioning from PreviousStateName in response to EventName (error code ErrorCode).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
Runtime

Description

StateTransition: An error was encountered when transitioning from PreviousStateName in response to EventName (error code ErrorCode).

Message #

%1: An error was encountered when transitioning from %3 in response to %7 (error code %8).

Fields #

NameDescription
StateTransition UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString
ErrorCode HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 226,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851971Z",
    "event_record_id": 851,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 4988
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "StateTransition": "RDP_TCP",
    "PreviousState": 23,
    "PreviousStateName": "StateUnknown",
    "NewState": 21,
    "NewStateName": "StateDisconnected",
    "Event": 43,
    "EventName": "Event_Disconnect",
    "ErrorCode": "0x80070040"
  }
}

References #

Event ID 227 — CustomLevel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Error
Task
RemoteFXmodule_4
Opcode
Runtime

Message #

%3

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 227,
    "version": 0,
    "level": 2,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.622336Z",
    "event_record_id": 887,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7136
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Name": "CUMRDPConnection",
    "Value": 2147500033,
    "CustomLevel": "'Failed GetConnectionProperty' in CUMRDPConnection::QueryProperty at 2884 err=[0x80004001]"
  }
}

References #

Event ID 228 — Disconnect trace:Disconnect_trace %2, Error code:%3.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Disconnect trace:Disconnect_trace %2, Error code:%3.

Message #

Disconnect trace:%1 %2, Error code:%3

Fields #

NameDescription
Disconnect_trace

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 228,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:26:41.767599Z",
    "event_record_id": 938,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7572
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ComponentName": "CUMRDPConnection",
    "Message": "Disconnect trace:'calling spGfxPlugin->PreDisconnect()' in CUMRDPConnection::PreDisconnect at 4595 err=[0x5]",
    "ErrorCode": 5
  }
}

References #

Event ID 229 — CustomLevel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Message #

%2

Fields #

NameDescription
Name UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 229,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T03:36:49.647283Z",
    "event_record_id": 975,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4624E4C-DF38-4BB3-A4DB-3782C9880000"
      }
    },
    "execution": {
      "process_id": 480,
      "thread_id": 1196
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Name": "CUMRDPProtocolManager",
    "CustomLevel": "'CUMRDPProtocolManager::CreateListener(RDP-Tcp) DEBUG/VM/ReverseTCP/ReverseUDP/INET' in CUMRDPProtocolManager::CreateListener at 4134 err=[0x0]"
  }
}

References #

Event ID 257 — The connection is using advanced RemoteFX RemoteApp graphics.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
AdvancedRemoteAppEnabled

Description

The connection is using advanced RemoteFX RemoteApp graphics.

Message #

The connection is using advanced RemoteFX RemoteApp graphics.

Event ID 258 — The connection is not using advanced RemoteFX RemoteApp graphics

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
AdvancedRemoteAppNotEnabled

Description

The connection is not using advanced RemoteFX RemoteApp graphics.

Message #

The connection is not using advanced RemoteFX RemoteApp graphics

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 258,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 21,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:47.617830Z",
    "event_record_id": 915,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7572
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 289 — Got UDP reverse connect request to URL port Port connection id ConnectionID.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Got UDP reverse connect request to URL port Port connection id ConnectionID.

Message #

Got UDP reverse connect request to %1 port %2 connection id %3.

Fields #

NameDescription
URL UnicodeString
Port UInt32
ConnectionID UnicodeString

Event ID 290 — UDP reverse connect successful.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

UDP reverse connect successful.

Message #

UDP reverse connect successful.

Event ID 291 — UDP reverse connect failed with error Error.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

UDP reverse connect failed with error Error.

Message #

UDP reverse connect failed with error %1.

Fields #

NameDescription
Error HexInt32

Event ID 292 — Multi transport listener NOT initialized.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Multi transport listener NOT initialized. UDP reverse connect NOT supported.

Message #

Multi transport listener NOT initialized. UDP reverse connect NOT supported.

Event ID 293 — Multi transport listener initialized.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Multi transport listener initialized. UDP reverse connect supported.

Message #

Multi transport listener initialized. UDP reverse connect supported.

Event ID 294 — Reverse UDP connect is disabled by SxS registry settings.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Reverse UDP connect is disabled by SxS registry settings.

Message #

Reverse UDP connect is disabled by SxS registry settings.