Microsoft-Windows-RemoteDesktopServices-RdpCoreTS › Event 229

Event ID 229 — CustomLevel.

Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Message #

%2

Fields #

NameDescription
Name UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 229,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T03:36:49.647283Z",
    "event_record_id": 975,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4624E4C-DF38-4BB3-A4DB-3782C9880000"
      }
    },
    "execution": {
      "process_id": 480,
      "thread_id": 1196
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Name": "CUMRDPProtocolManager",
    "CustomLevel": "'CUMRDPProtocolManager::CreateListener(RDP-Tcp) DEBUG/VM/ReverseTCP/ReverseUDP/INET' in CUMRDPProtocolManager::CreateListener at 4134 err=[0x0]"
  }
}

References #