Microsoft-Windows-RPC-Audit

2 events across 1 channel

Event IDTitleChannel
1Operational
2Operational

Event ID 1 —

Provider
Microsoft-Windows-RPC-Audit
Channel
Operational

Fields

NameDescription
InterfaceUuid
OpNum
SubjectUserSid
SubjectLogonId
LocalIpAddressLength
LocalIpAddress
RemoteIpAddressLength
RemoteIpAddress
ProtocolSequence
AuthenticationService
AuthenticationLevel
Endpoint
RemoteHost
BufferSize
Buffer

Event ID 2 —

Provider
Microsoft-Windows-RPC-Audit
Channel
Operational

Fields

NameDescription
InterfaceUuid
OpNum
SubjectUserSid
SubjectLogonId
LocalIpAddressLength
LocalIpAddress
RemoteIpAddressLength
RemoteIpAddress
ProtocolSequence
AuthenticationService
AuthenticationLevel
Endpoint
RemoteHost
ErrorCode
IsBlockedByWFP