Microsoft-Windows-SENSE

211 events across 1 channel

Event IDTitleChannel
1Service is starting (Version %1).Operational
2Service is shutting down.Operational
3Windows Defender Advanced Threat Protection service failed to start.Operational
4Contacted server %1 times, all succeeded, URI: %2.Operational
5Contacted server %1 times, all failed, URI: %2.Operational
6Windows Defender Advanced Threat Protection service is not onboarded and no …Operational
7Windows Defender Advanced Threat Protection service failed to read the …Operational
8Service failed to clean configuration settings.Operational
9Windows Defender Advanced Threat Protection service failed to change its start …Operational
10Windows Defender Advanced Threat Protection service failed to persist the …Operational
11Onboarding or re-onboarding of Windows Defender Advanced Threat Protection …Operational
12New cloud configuration failed to apply, version.Operational
13Windows Defender Advanced Threat Protection machine ID calculated.Operational
14Windows Defender Advanced Threat Protection cannot calculate machine ID.Operational
15Windows Defender Advanced Threat Protection cannot start command channel with …Operational
17Windows Defender Advanced Threat Protection service failed to change the …Operational
18OOBE (Windows Welcome) is completed.Operational
19OOBE (Windows Welcome) has not yet completed.Operational
20Cannot wait for OOBE (Windows Welcome) to complete.Operational
25Service failed to reset health status in the registry.Operational
26Windows Defender Advanced Threat Protection service failed to set the onboarding …Operational
27Failed to enable Windows Defender Advanced Threat Protection mode in Windows …Operational
28Connected User Experiences and Telemetry service registration failed with …Operational
29Failed to read the offboarding parameters.Operational
30Failed to disable Windows Defender Advanced Threat Protection mode in Windows …Operational
31Windows Defender Advanced Threat Protection Connected User Experiences and …Operational
32Windows Defender Advanced Threat Protection service failed to request to stop …Operational
33Windows Defender Advanced Threat Protection service failed to persist SENSE …Operational
34Microsoft Defender for Endpoint service failed to add itself as a dependency on …Operational
35Communication quotas are updated.Operational
36Connected User Experiences and Telemetry service registration succeeded with …Operational
37Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4.Operational
38Network connection is identified as low.Operational
39Network connection is identified as normal.Operational
40Battery state is identified as low.Operational
41Battery state is identified as normal.Operational
42Component failed to perform action.Operational
43Component failed to perform action.Operational
44Offboarding of Windows Defender Advanced Threat Protection service completed.Operational
45Failed to register and to start the event trace session [.Operational
46Failed to register and start the event trace session [.Operational
47Successfully registered and started the event trace session - recovered after …Operational
48Failed to add a provider [.Operational
49Invalid cloud configuration command received and ignored.Operational
50New cloud configuration applied successfully.Operational
51New cloud configuration failed to apply, version.Operational
52New cloud configuration failed to apply, version.Operational
53Cloud configuration loaded from persistent storage, version.Operational
54Global (per-pattern) state changed.Operational
55Failed to create the Secure ETW autologger.Operational
56Failed to remove the Secure ETW autologger.Operational
57Capturing a snapshot of the machine for troubleshooting purposes.Operational
59Starting command.Operational
60Failed to run command %1, error: %2.Operational
61Data collection command parameters are invalid: SasUri: %1, compressionLevel: …Operational
62Failed to start Connected User Experiences and Telemetry service.Operational
63Updating the start type of external service.Operational
64Starting stopped external service.Operational
65Failed to load Microsoft Security Events Component Minifilter driver.Operational
66Policy update: Latency mode - %1.Operational
67Contacted server %1 times, failed %2 times and succeeded %3 times.Operational
68The start type of the service is unexpected.Operational
69The service is stopped.Operational
70Policy update: Allow sample collection - %1.Operational
71Succeeded to run command.Operational
72Tried to send first full machine profile report.Operational
73Sense starting for platform.Operational
74Device tag in registry exceeds length limit.Operational
75Device tag name in registry exceeds length limit.Operational
76Number of customer tags in registry exceeds limit.Operational
77Successfully applied protection on Connected User Experiences and Telemetry …Operational
78Successfully removed protection from Connected User Experiences and Telemetry …Operational
79Failed to apply protection on Connected User Experiences and Telemetry service.Operational
80Failed to remove protection from Connected User Experiences and Telemetry …Operational
81Failed to create Windows Defender Advanced Threat Protection ETW autologger.Operational
82Failed to remove Windows Defender Advanced Threat Protection ETW autologger.Operational
83Cyber event may be dropped because its size [.Operational
84Set Windows Defender Antivirus running mode.Operational
85Failed to trigger Windows Defender Advanced Threat Protection Incident Response …Operational
86Starting again stopped external service that should be up.Operational
87Cannot start the external service.Operational
88Updating the start type of external service again.Operational
89Cannot update the start type of external service.Operational
90Failed to configure System Guard Runtime Monitor to connect to cloud service in …Operational
91Failed to remove System Guard Runtime Monitor geo-region information.Operational
92Stopping sending sensor cyber data quota because data quota is exceed.Operational
93Resuming sending sensor cyber data.Operational
94Windows Defender Advanced Threat Protection Classification Engine executable has …Operational
95Windows Defender Advanced Threat Protection Classification Engine executable has …Operational
96Windows Defender Advanced Threat Protection Classification Engine Init has …Operational
97There are connectivity issues to the Cloud for the DLP scenarioOperational
98The connectivity to the Cloud for the DLP scenario has been restoredOperational
99Sense has encoutered the following error while communicating with server.Operational
100Windows Defender Advanced Threat Protection Classification Engine executable …Operational
101Windows Defender Advanced Threat Protection Network Detection and Response …Operational
102Windows Defender Advanced Threat Protection Network Detection and Response …Operational
103Windows Defender Advanced Threat Protection Network Detection and Response …Operational
104Failed to queue asynchronous driver unload.Operational
105Failed to wait for driver unload.Operational
106Windows Defender Advanced Threat Protection service failed to start.Operational
107Windows Defender Advanced Threat Protection service failed to start.Operational
108Update phase:%1, new platform version: %2, message: %3.Operational
109Update phase:%1 new platform version: %2, failure message: %3, error: %4.Operational
110Failed to remove MDEContain WFP filtersOperational
111Failed to Leave SecurityManagement.Operational
112MsSecFlt.Operational
113MsSecFlt.Operational
114MsSecFlt.Operational
115MsSecWfp.Operational
116MsSecWfp.Operational
117%1: Failed to modify service object trust label.Operational
118Update phase:%1, new platform version: %2, success message: %3.Operational
119Windows Defender Advanced Threat Protection service failed to remove its failure …Operational
120EventTraker Event data:Operational
121Info message.Operational
122Update phase:%1 new platform version: %2, warning message: %3.Operational
123Update error message: %5, Additional parameters: %1: %2, %3: %4, error message: …Operational
124Windows Defender Advanced Threat Protection Trace Event Monitor executable has …Operational
125Windows Defender Advanced Threat Protection Trace Event Monitor executable has …Operational
126Windows Defender Advanced Threat Protection Trace Event Monitor executable …Operational
127Windows Defender Advanced Threat Protection Dlp Processor executable failed to …Operational
128Windows Defender Advanced Threat Protection Dlp Processor executable has startedOperational
129Windows Defender Advanced Threat Protection Dlp Processor executable has endedOperational
130Received DLP policy type.Operational
131Completed processing DLP policy type.Operational
132Failed to process DLP policy type.Operational
133Ignore DLP policy type: %1 at %2 due to Data Loss Prevention feature currently …Operational
134Offboarding blob is revoked via configuration.Operational
135Offboarding is blocked for blob with Epoch: %1 , BlobSha256: %2.Operational
300Windows Defender Advanced Threat Protection Session Recorder executable has …Operational
301Windows Defender Advanced Threat Protection Session Recorder executable has …Operational
302Windows Defender Advanced Threat Protection Session Recorder init has called …Operational
303Windows Defender Advanced Threat Protection Session Recorder executable failed …Operational
304Windows Defender Advanced Threat Protection Session Recorder user session logon …Operational
305Windows Defender Advanced Threat Protection Session Recorder user session logoff …Operational
306Windows Defender Advanced Threat Protection Session Recorder user session unlock …Operational
307Failed to update driver permissions Failure code.Operational
308Failed to ACL on Folder %1 Failure code: %2.Operational
309Windows Defender Advanced Threat Protection Network Detection and Response …Operational
310Failed to store cloud configuration.Operational
400Windows Defender Advanced Threat Protection service failed to create …Operational
401Windows Defender Advanced Threat Protection service failed to generate key.Operational
402Windows Defender Advanced Threat Protection service failed to persist …Operational
403Registration of device by Windows Defender Advanced Threat Protection service …Operational
404Windows Defender Advanced Threat Protection service successfully generated a …Operational
405Failed to communicate with authentication service.Operational
406Request for %1 rejected by authentication service.Operational
407Windows Defender Advanced Threat Protection service failed to sign message …Operational
408Windows Defender Advanced Threat Protection service failed to remove persist …Operational
409Windows Defender Advanced Threat Protection service failed to open key.Operational
410Registration is required as part of re-onboarding of Windows Defender Advanced …Operational
411Cyber telemetry upload has been suspended for Windows Defender Advanced Threat …Operational
412Cyber telemetry upload been resumed for Windows Defender Advanced Threat …Operational
413Windows Defender Advanced Threat Protection Network Detection and Response …Operational
414Key rotation of device by Windows Defender Advanced Threat Protection service …Operational
415Authentication initialization for Windows Defender Advanced Threat Protection …Operational
416EventTraker Event data:Operational
417Windows Defender Advanced Threat Protection service opened key successfully.Operational
418Windows Defender Advanced Threat Protection service certificate creation …Operational
419Windows Defender Advanced Threat Protection service authentication request …Operational
420Rename of device by Windows Defender Advanced Threat Protection service …Operational
500Windows Defender Advanced Threat Protection orchestrator failed to perform.Operational
501Windows Defender Advanced Threat Protection orchestrator performed: %1 …Operational
1800CSP: Get Node's Value.Operational
1801CSP: Failed to Get Node's Value.Operational
1802CSP: Get Node's Value complete.Operational
1803CSP: Get Last Connected value complete.Operational
1804CSP: Get Org ID value complete.Operational
1805CSP: Get Sense Is Running value complete.Operational
1806CSP: Get Onboarding State value complete.Operational
1807CSP: Get Onboarding value complete.Operational
1808CSP: Get Offboarding value complete.Operational
1809CSP: Get Sample Sharing value complete.Operational
1810CSP: Onboarding process.Operational
1811CSP: Onboarding process.Operational
1812CSP: Onboarding process.Operational
1813CSP: Onboarding process.Operational
1814CSP: Onboarding process.Operational
1815CSP: Set Sample Sharing value complete.Operational
1816CSP: Offboarding process.Operational
1817CSP: Offboarding process.Operational
1818CSP: Set Node's Value started.Operational
1819CSP: Failed to Set Node's Value.Operational
1820CSP: Set Node's Value complete.Operational
1821CSP: Set Telemetry Reporting Frequency started.Operational
1822CSP: Set Telemetry Reporting Frequency complete.Operational
1823CSP: Get Telemetry Reporting Frequency complete.Operational
1824CSP: Get Group Ids complete.Operational
1825CSP: Set Group Ids exceeded allowed limit.Operational
1826CSP: Set Group Ids complete.Operational
1827CSP: Onboarding process.Operational
1828CSP: Onboarding process.Operational
1829CSP: Failed to Set Sample Sharing Value.Operational
1830CSP: Failed to Set Telemetry Reporting Frequency Value.Operational
1831CSP: Get Sense is running.Operational
1832CSP: Get Device Tagging Group complete.Operational
1833CSP: Get Device Tagging Criticality value complete.Operational
1834CSP: Get Device Tagging Identification Method value complete.Operational
1835CSP: Set Device Tagging Group complete.Operational
1836CSP: Set Device Tagging Group exceeded allowed limit.Operational
1837CSP: Set Device Tagging Criticality value complete.Operational
1838CSP: Failed to Set Device Tagging Criticality Value.Operational
1839CSP: Set Device Tagging Identification Method value complete.Operational
1840CSP: Failed to Set Device Tagging Identification Method Value.Operational
1841CSP: Get AadDeviceId complete.Operational
1842CSP: Set AadDeviceId complete.Operational
1843CSP: Set AadDeviceId exceeded allowed limit.Operational
2001SenseCM.Operational
2002Info.Operational
2003Warning.Operational
2004Error.Operational

Event ID 1 — Service is starting (Version %1).

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during system startup, shut down, and during onboarding. Normal operating notification; no action required.

Message

Service is starting (Version %1).

Fields

NameDescription
parameter

References

Event ID 2 — Service is shutting down.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs when the device is shut down or offboarded. Normal operating notification; no action required.

Message

Service is shutting down.

References

Event ID 3 — Windows Defender Advanced Threat Protection service failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Service didn't start. Review other messages to determine possible cause and troubleshooting steps.

Message

Windows Defender Advanced Threat Protection service failed to start. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 4 — Contacted server %1 times, all succeeded, URI: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Variable = URL of the Defender for Endpoint processing servers. This URL matches that seen in the Firewall or network activity. Normal operating notification; no action required.

Message

Contacted server %1 times, all succeeded, URI: %2.

Fields

NameDescription
UInt1
Message1

References

Event ID 5 — Contacted server %1 times, all failed, URI: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Variable = URL of the Defender for Endpoint processing servers. The service couldn't contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity.

Message

Contacted server %1 times, all failed, URI: %2. Last HTTP error code: %3

Fields

NameDescription
Last_HTTP_error_code1 times, all failed, URI.
UInt1
Message1
Int1

References

Event ID 6 — Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device didn't onboard correctly and isn't reporting to the portal. Onboarding must be run before starting the service. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.

Message

Windows Defender Advanced Threat Protection service is not onboarded and no onboarding parameters were found.

References

Event ID 7 — Windows Defender Advanced Threat Protection service failed to read the onboarding parameters.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Variable = detailed error description. The device didn't onboard correctly and isn't reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.

Message

Windows Defender Advanced Threat Protection service failed to read the onboarding parameters. Failure: %1

Fields

NameDescription
parameter

References

Event ID 8 — Service failed to clean configuration settings.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

During onboarding: The service failed to clean its configuration during the onboarding. The onboarding process continues. During offboarding: The service failed to clean its configuration during the offboarding. The offboarding process finished but the service keeps running. Onboarding: No action required. Offboarding: Reboot the system. See Onboard client devices.

Message

Service failed to clean configuration settings.

References

Event ID 9 — Windows Defender Advanced Threat Protection service failed to change its start type.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

During onboarding: The device didn't onboard correctly and isn't reporting to the portal. During offboarding: Failed to change the service start type. The offboarding process continues. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices.

Message

Windows Defender Advanced Threat Protection service failed to change its start type. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 10 — Windows Defender Advanced Threat Protection service failed to persist the onboarding information.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device didn't onboard correctly and isn't reporting to the portal. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

Windows Defender Advanced Threat Protection service failed to persist the onboarding information. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 11 — Onboarding or re-onboarding of Windows Defender Advanced Threat Protection service completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device onboarded correctly. Normal operating notification; no action required. It might take several hours for the device to appear in the portal.

Message

Onboarding or re-onboarding of Windows Defender Advanced Threat Protection service completed.

References

Event ID 12 — New cloud configuration failed to apply, version.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Service was unable to apply the default configuration. This error should resolve after a short period of time.

Message

New cloud configuration failed to apply, version: %1. Also failed to apply last known good configuration, version %2. Also failed to apply the default configuration.

Fields

NameDescription
parameter1
parameter2

References

Event ID 13 — Windows Defender Advanced Threat Protection machine ID calculated.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Normal operating process. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection machine ID calculated: %1

Fields

NameDescription
parameter

References

Event ID 14 — Windows Defender Advanced Threat Protection cannot calculate machine ID.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection cannot calculate machine ID. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 15 — Windows Defender Advanced Threat Protection cannot start command channel with URL.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Variable = URL of the Defender for Endpoint processing servers. The service couldn't contact the external processing servers at that URL. Check the connection to the URL. See Configure proxy and Internet connectivity.

Message

Windows Defender Advanced Threat Protection cannot start command channel with URL: %1

Fields

NameDescription
parameter

References

Event ID 17 — Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

Windows Defender Advanced Threat Protection service failed to change the Connected User Experiences and Telemetry service location. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 18 — OOBE (Windows Welcome) is completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Service will only start after any Windows updates have finished installing. Normal operating notification; no action required.

Message

OOBE (Windows Welcome) is completed.

References

Event ID 19 — OOBE (Windows Welcome) has not yet completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Service will only start after any Windows updates finish installing. Normal operating notification; no action required. If this error persists after a system restart, ensure all Windows updates have full installed.

Message

OOBE (Windows Welcome) has not yet completed.

References

Event ID 20 — Cannot wait for OOBE (Windows Welcome) to complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Internal error. If this error persists after a system restart, ensure all Windows updates are installed.

Message

Cannot wait for OOBE (Windows Welcome) to complete. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 25 — Service failed to reset health status in the registry.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device didn't onboard correctly. It reports to the portal; however, the service might not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

Service failed to reset health status in the registry. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 26 — Windows Defender Advanced Threat Protection service failed to set the onboarding status in the registry.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device didn't onboard correctly. It reports to the portal; however the service may not appear as registered in SCCM or the registry. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

Windows Defender Advanced Threat Protection service failed to set the onboarding status in the registry. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 27 — Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Normally, Microsoft Defender Antivirus enters a special passive state if another real-time antimalware product is running properly on the device, and the device is reporting to Defender for Endpoint. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS. Ensure real-time antimalware protection is running properly.

Message

Failed to enable Windows Defender Advanced Threat Protection mode in Windows Defender. Onboarding process failed. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 28 — Connected User Experiences and Telemetry service registration failed with failure code.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

Connected User Experiences and Telemetry service registration failed with failure code: %1. Requested disk quota in MB: %2, Requested daily upload quota in MB: %3

Fields

NameDescription
HRESULT
diskSizeQuotaValue
dailyUploadQuotaValue

References

Event ID 29 — Failed to read the offboarding parameters.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

This event occurs when the system can't read the offboarding parameters. Ensure the device has Internet access, then run the entire offboarding process again. Ensure the offboarding package isn't expired.

Message

Failed to read the offboarding parameters. Error type: %1, Error code: %2, Description: %3

Fields

NameDescription
errorType
HRESULT
description

References

Event ID 30 — Failed to disable Windows Defender Advanced Threat Protection mode in Windows Defender.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Normally, Microsoft Defender Antivirus enters a special passive state if another real-time antimalware product is running properly on the device, and the device is reporting to Defender for Endpoint. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS. Ensure real-time antimalware protection is running properly.

Message

Failed to disable Windows Defender Advanced Threat Protection mode in Windows Defender. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 31 — Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred with the Windows telemetry service during onboarding. The offboarding process continues. Check for errors with the Windows telemetry service.

Message

Windows Defender Advanced Threat Protection Connected User Experiences and Telemetry service unregistration failed. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 32 — Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred during offboarding. Reboot the device.

Message

Windows Defender Advanced Threat Protection service failed to request to stop itself after offboarding process. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 33 — Windows Defender Advanced Threat Protection service failed to persist SENSE GUID.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

A unique identifier is used to represent each device that is reporting to the portal. If the identifier doesn't persist, the same device might appear twice in the portal. Check registry permissions on the device to ensure the service can update the registry.

Message

Windows Defender Advanced Threat Protection service failed to persist SENSE GUID. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 34 — Microsoft Defender for Endpoint service failed to add itself as a dependency on the Connected User Experiences and Telemetry service, causing onboarding process to fail. Failure code: variable.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

Message

An error occurred with the Windows telemetry service. Ensure the diagnostic data service is enabled. Check that the onboarding settings and scripts were deployed properly. Try to redeploy the configuration packages. See Onboard client devices running Windows or macOS.

References

Event ID 35 — Communication quotas are updated.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Variable = disk quota in MB. Normal operating notification; no action required.

Message

Communication quotas are updated. Disk quota in MB: %1, daily upload quota in MB: %2

Fields

NameDescription
diskSizeQuotaValue
dailyUploadQuotaValue

References

Event ID 36 — Connected User Experiences and Telemetry service registration succeeded with completion code.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Registering Defender for Endpoint with the Connected User Experiences and Telemetry service completed successfully. Normal operating notification; no action required.

Message

Connected User Experiences and Telemetry service registration succeeded with completion code: %1. Requested disk quota in MB: %2, requested daily upload quota in MB: %3

Fields

NameDescription
HRESULT
diskSizeQuotaValue
dailyUploadQuotaValue

References

Event ID 37 — Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device is near its allocated quota of the current 24-hour window. It's about to be throttled. Normal operating notification; no action required.

Message

Module: %1, Quota: {%2} {%3}, Percentage of quota utilization: %4.

Fields

NameDescription
Module
module
quotaValue
quotaValueUnit
percentageValue

References

Event ID 38 — Network connection is identified as low.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device is using a metered/paid network and contacts the server less frequently. Normal operating notification; no action required.

Message

Network connection is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. Metered connection: %2, internet available: %3, free network available: %4, proxy is defined by GP: %5.

Fields

NameDescription
pollingInterval
meteredConnectionState
internetAvailabilityState
freeNetworkAvailabilityState
proxyDefined

References

Event ID 39 — Network connection is identified as normal.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device isn't using a metered/paid connection and contacts the server as usual. Normal operating notification; no action required.

Message

Network connection is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. Metered connection: %2, internet available: %3, free network available: %4, proxy is defined by GP: %5.

Fields

NameDescription
pollingInterval
meteredConnectionState
internetAvailabilityState
freeNetworkAvailabilityState
proxyDefined

References

Event ID 40 — Battery state is identified as low.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device has low battery level and contacts the server less frequently. Normal operating notification; no action required.

Message

Battery state is identified as low. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. AC state: %2, battery saver mode : %3, battery low state: %4, battery critical state: %5

Fields

NameDescription
battery_saver_mode1 seconds. AC state.
battery_low_state
battery_critical_state
pollingInterval
acPowerState
batterySavingState
batteryLowState
batteryCriticalState

References

Event ID 41 — Battery state is identified as normal.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device doesn't have low battery level and contacts the server as usual. Normal operating notification; no action required.

Message

Battery state is identified as normal. Windows Defender Advanced Threat Protection will contact the server every %1 seconds. AC state: %2, battery saver mode : %3, battery low state: %4, battery critical state: %5

Fields

NameDescription
battery_saver_mode1 seconds. AC state.
battery_low_state
battery_critical_state
pollingInterval
acPowerState
batterySavingState
batteryLowState
batteryCriticalState

References

Event ID 42 — Component failed to perform action.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Internal error. The service failed to start. If this error persists, contact Support.

Message

Component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception message: %4

Fields

NameDescription
Component
Operation
ExceptionType
ExceptionMessage

References

Event ID 43 — Component failed to perform action.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Internal error. The service failed to start. If this error persists, contact Support.

Message

Component failed to perform action. Component: %1, Action: %2, Exception Type: %3, Exception Error: %4, Exception message: %5

Fields

NameDescription
Component
Operation
ExceptionType
ExceptionErrorCode
ExceptionMessage

References

Event ID 44 — Offboarding of Windows Defender Advanced Threat Protection service completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The service was offboarded. Normal operating notification; no action required.

Message

Offboarding of Windows Defender Advanced Threat Protection service completed.

References

Event ID 45 — Failed to register and to start the event trace session [.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred on service startup while creating ETW session. This caused service start-up failure. If this error persists, contact Support.

Message

Failed to register and to start the event trace session [%1]. Error code: %2

Fields

NameDescription
TraceSessionName
HRESULT

References

Event ID 46 — Failed to register and start the event trace session [.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An error occurred on service startup while creating ETW session due to lack of resources. The service is running, but doesn't report sensor events until the ETW session starts. Normal operating notification; no action required. The service tries to start the session every minute.

Message

Failed to register and start the event trace session [%1] due to lack of resources. Error code: %2. This is most likely because there are too many active event trace sessions. The service will retry in 1 minute.

Fields

NameDescription
TraceSessionName
HRESULT

References

Event ID 47 — Successfully registered and started the event trace session - recovered after previous failed attempts.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

This event follows the previous event after successfully starting of the ETW session. Normal operating notification; no action required.

Message

Successfully registered and started the event trace session - recovered after previous failed attempts.

References

Event ID 48 — Failed to add a provider [.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to add a provider to ETW session. As a result, the provider events aren't reported. Check the error code. If the error persists contact Support.

Message

Failed to add a provider [%1] to event trace session [%2]. Error code: %3. This means that events from this provider will not be reported.

Fields

NameDescription
ProviderId
TraceSessionName
ErrorCode

References

Event ID 49 — Invalid cloud configuration command received and ignored.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Received an invalid configuration file from the cloud service that was ignored. If this error persists, contact Support.

Message

Invalid cloud configuration command received and ignored. Version: %1, status: %2, error code: %3, message: %4

Fields

NameDescription
Version
Status
HRESULT
ErrorMessage

References

Event ID 50 — New cloud configuration applied successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Successfully applied a new configuration from the cloud service. Normal operating notification; no action required.

Message

New cloud configuration applied successfully. Version: %1.

Fields

NameDescription
parameter

References

Event ID 51 — New cloud configuration failed to apply, version.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Received a bad configuration file from the cloud service. Last known good configuration was applied successfully. If this error persists, contact Support.

Message

New cloud configuration failed to apply, version: %1. Successfully applied the last known good configuration, version %2.

Fields

NameDescription
parameter1
parameter2

References

Event ID 52 — New cloud configuration failed to apply, version.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Received a bad configuration file from the cloud service. Failed to apply the last known good configuration - and the default configuration was applied. The service will attempt to download a new configuration file within 5 minutes. If you don't see event #50 - contact Support.

Message

New cloud configuration failed to apply, version: %1. Also failed to apply last known good configuration, version %2. Successfully applied the default configuration.

Fields

NameDescription
parameter1
parameter2

References

Event ID 53 — Cloud configuration loaded from persistent storage, version.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The configuration was loaded from persistent storage on service startup. Normal operating notification; no action required.

Message

Cloud configuration loaded from persistent storage, version: %1.

Fields

NameDescription
parameter

References

Event ID 54 — Global (per-pattern) state changed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Global (per-pattern) state changed. State: %1, pattern: %2

Fields

NameDescription
Global_perpattern_state_changed_StateGlobal (per-pattern) state changed. State.
pattern
Value1
Value2
Value3

Event ID 55 — Failed to create the Secure ETW autologger.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to create the secure ETW logger. Reboot the device. If this error persists, contact Support.

Message

Failed to create the Secure ETW autologger. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 56 — Failed to remove the Secure ETW autologger.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to remove the secure ETW session on offboarding. Contact Support.

Message

Failed to remove the Secure ETW autologger. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 57 — Capturing a snapshot of the machine for troubleshooting purposes.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An investigation package, also known as forensics package, is being collected. Normal operating notification; no action required.

Message

Capturing a snapshot of the machine for troubleshooting purposes.

References

Event ID 59 — Starting command.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Starting response command execution. Normal operating notification; no action required.

Message

Starting command: %1

Fields

NameDescription
Starting_command
parameter

References

Event ID 60 — Failed to run command %1, error: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to execute response command. If this error persists, contact Support.

Message

Failed to run command %1, error: %2.

Fields

NameDescription
CommandName
HRESULT

References

Event ID 61 — Data collection command parameters are invalid: SasUri: %1, compressionLevel: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to read or parse the data collection command arguments (invalid arguments). If this error persists, contact Support.

Message

Data collection command parameters are invalid: SasUri: %1, compressionLevel: %2.

Fields

NameDescription
SasUri
CompressionLevel

References

Event ID 62 — Failed to start Connected User Experiences and Telemetry service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Connected User Experiences and Telemetry (diagtrack) service failed to start. Non-Microsoft Defender for Endpoint telemetry isn't sent from this machine. Look for more troubleshooting hints in the event log: Microsoft-Windows-UniversalTelemetryClient/Operational.

Message

Failed to start Connected User Experiences and Telemetry service. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 63 — Updating the start type of external service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Updated start type of the external service. Normal operating notification; no action required.

Message

Updating the start type of external service. Name: %1, actual start type: %2, expected start type: %3, exit code: %4

Fields

NameDescription
ServiceName
ActualStartType
ExpectedStartType
ErrorCode

References

Event ID 64 — Starting stopped external service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Starting an external service. Normal operating notification; no action required.

Message

Starting stopped external service. Name: %1, exit code: %2

Fields

NameDescription
Starting_stopped_external_service_NameStarting stopped external service. Name.
exit_code
ServiceName
ErrorCode

References

Event ID 65 — Failed to load Microsoft Security Events Component Minifilter driver.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to load MsSecFlt.sys filesystem minifilter. Reboot the device. If this error persists, contact Support.

Message

Failed to load Microsoft Security Events Component Minifilter driver. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 66 — Policy update: Latency mode - %1.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The C&C connection frequency policy was updated. Normal operating notification; no action required.

Message

Policy update: Latency mode - %1

Fields

NameDescription
parameter

References

Event ID 67 — Contacted server %1 times, failed %2 times and succeeded %3 times.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Contacted server %1 times, failed %2 times and succeeded %3 times. URI: %4. Last HTTP error code: %5

Fields

NameDescription
Last_HTTP_error_code
UInt1
UInt2
UInt3
Message1
Int1

Event ID 68 — The start type of the service is unexpected.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Unexpected external service start type. Fix the external service start type.

Message

The start type of the service is unexpected. Service name: %1, actual start type: %2, expected start type: %3

Fields

NameDescription
ServiceName
ActualStartType
ExpectedStartType

References

Event ID 69 — The service is stopped.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The external service is stopped. Start the external service.

Message

The service is stopped. Service name: %1

Fields

NameDescription
parameter

References

Event ID 70 — Policy update: Allow sample collection - %1.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The sample collection policy was updated. Normal operating notification; no action required.

Message

Policy update: Allow sample collection - %1

Fields

NameDescription
UInt1

References

Event ID 71 — Succeeded to run command.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The command was executed successfully. Normal operating notification; no action required.

Message

Succeeded to run command: %1

Fields

NameDescription
parameter

References

Event ID 72 — Tried to send first full machine profile report.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Informational only. Normal operating notification; no action required.

Message

Tried to send first full machine profile report. Result code: %1

Fields

NameDescription
HRESULT

References

Event ID 73 — Sense starting for platform.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Informational only. Normal operating notification; no action required.

Message

Sense starting for platform: %1

Fields

NameDescription
platformBitMask

References

Event ID 74 — Device tag in registry exceeds length limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The device tag exceeds the length limit. Use a shorter device tag.

Message

Device tag in registry exceeds length limit. Tag name: %2. Length limit: %1.

Fields

NameDescription
UInt1
Message1

References

Event ID 75 — Device tag name in registry exceeds length limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Device tag name in registry exceeds length limit. Tag name: %2. Length limit: %1.

Fields

NameDescription
UInt1
Message1

Event ID 76 — Number of customer tags in registry exceeds limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Number of customer tags in registry exceeds limit. Limit: %1 tags.

Fields

NameDescription
UInt1

Event ID 77 — Successfully applied protection on Connected User Experiences and Telemetry service

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Successfully applied protection on Connected User Experiences and Telemetry service

Event ID 78 — Successfully removed protection from Connected User Experiences and Telemetry service

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Successfully removed protection from Connected User Experiences and Telemetry service

Event ID 79 — Failed to apply protection on Connected User Experiences and Telemetry service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Failed to apply protection on Connected User Experiences and Telemetry service. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 80 — Failed to remove protection from Connected User Experiences and Telemetry service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Failed to remove protection from Connected User Experiences and Telemetry service. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 81 — Failed to create Windows Defender Advanced Threat Protection ETW autologger.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to create the ETW session. Reboot the device. If this error persists, contact Support.

Message

Failed to create Windows Defender Advanced Threat Protection ETW autologger. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 82 — Failed to remove Windows Defender Advanced Threat Protection ETW autologger.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to delete the ETW session. Contact Support.

Message

Failed to remove Windows Defender Advanced Threat Protection ETW autologger. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 83 — Cyber event may be dropped because its size [.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Cyber event may be dropped because its size [%1 bytes] exceeded max size [%2 bytes] or close to it.

Fields

NameDescription
RealValue
quotaValue

Event ID 84 — Set Windows Defender Antivirus running mode.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set defender running mode (active or passive). Normal operating notification; no action required.

Message

Set Windows Defender Antivirus running mode. Force passive mode: %1, result code: %2.

Fields

NameDescription
forcePassiveMode
HRESULT

References

Event ID 85 — Failed to trigger Windows Defender Advanced Threat Protection Incident Response executable.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Starring SenseIR executable failed. Reboot the device. If this error persists, contact Support.

Message

Failed to trigger Windows Defender Advanced Threat Protection Incident Response executable. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 86 — Starting again stopped external service that should be up.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Starting the external service again. Normal operating notification; no action required.

Message

Starting again stopped external service that should be up. Name: %1, exit code: %2

Fields

NameDescription
ServiceName
ErrorCode

References

Event ID 87 — Cannot start the external service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to start the external service. Contact Support.

Message

Cannot start the external service. Name: %1

Fields

NameDescription
ServiceName

References

Event ID 88 — Updating the start type of external service again.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Updated the start type of the external service. Normal operating notification; no action required.

Message

Updating the start type of external service again. Name: %1, actual start type: %2, expected start type: %3, exit code: %4

Fields

NameDescription
ServiceName
ActualStartType
ExpectedStartType
ErrorCode

References

Event ID 89 — Cannot update the start type of external service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Can't update the start type of the external service. Contact Support.

Message

Cannot update the start type of external service. Name: %1, actual start type: %2, expected start type: %3

Fields

NameDescription
ServiceName
ActualStartType
ExpectedStartType

References

Event ID 90 — Failed to configure System Guard Runtime Monitor to connect to cloud service in geo-region %1.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

System Guard Runtime Monitor doesn't send attestation data to the cloud service. Check the permissions on register path: "HKLM\Software\Microsoft\Windows\CurrentVersion\Sgrm". If no issues spotted, contact Support.

Message

Failed to configure System Guard Runtime Monitor to connect to cloud service in geo-region %1. Failure code: %2

Fields

NameDescription
Message1
HRESULT

References

Event ID 91 — Failed to remove System Guard Runtime Monitor geo-region information.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

System Guard Runtime Monitor doesn't send attestation data to the cloud service. Check the permissions on register path: "HKLM\Software\Microsoft\Windows\CurrentVersion\Sgrm". If no issues spotted, contact Support.

Message

Failed to remove System Guard Runtime Monitor geo-region information. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 92 — Stopping sending sensor cyber data quota because data quota is exceed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Exceed throttling limit. Normal operating notification; no action required.

Message

Stopping sending sensor cyber data quota because data quota is exceed. Will resume sending once quota period passes. State Mask: %1

Fields

NameDescription
UInt2

References

Event ID 93 — Resuming sending sensor cyber data.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Resume cyber data submission. Normal operating notification; no action required.

Message

Resuming sending sensor cyber data. State Mask: %1

Fields

NameDescription
UInt2

References

Event ID 94 — Windows Defender Advanced Threat Protection Classification Engine executable has started

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseCE executable has started. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection Classification Engine executable has started

References

Event ID 95 — Windows Defender Advanced Threat Protection Classification Engine executable has ended

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseCE executable has ended. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection Classification Engine executable has ended

References

Event ID 96 — Windows Defender Advanced Threat Protection Classification Engine Init has called.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseCE executable has called MCE initialization. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection Classification Engine Init has called. Result code: %1

Fields

NameDescription
HRESULT

References

Event ID 97 — There are connectivity issues to the Cloud for the DLP scenario

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

There are network connectivity issues that affect the DLP classification flow. Check the network connectivity.

Message

There are connectivity issues to the Cloud for the DLP scenario

References

Event ID 98 — The connectivity to the Cloud for the DLP scenario has been restored

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The connectivity to the network was restored and the DLP classification flow can continue. Normal operating notification; no action required.

Message

The connectivity to the Cloud for the DLP scenario has been restored

References

Event ID 99 — Sense has encoutered the following error while communicating with server.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

A communication error occurred. Check the following events in the event log for further details.

Message

Sense has encoutered the following error while communicating with server: (%1). Result: (%2)

Fields

NameDescription
Message1
HRESULT

References

Event ID 100 — Windows Defender Advanced Threat Protection Classification Engine executable failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseCE executable has failed to start. Reboot the device. If this error persists, contact Support.

Message

Windows Defender Advanced Threat Protection Classification Engine executable failed to start. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 101 — Windows Defender Advanced Threat Protection Network Detection and Response executable failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Network Detection and Response executable failed to start. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 102 — Windows Defender Advanced Threat Protection Network Detection and Response executable has started

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseNdr executable has started. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection Network Detection and Response executable has started

References

Event ID 103 — Windows Defender Advanced Threat Protection Network Detection and Response executable has ended

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The SenseNdr executable has ended. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection Network Detection and Response executable has ended

References

Event ID 104 — Failed to queue asynchronous driver unload.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during offboarding. Normal operating notification; no action required.

Message

Failed to queue asynchronous driver unload. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 105 — Failed to wait for driver unload.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during offboarding. Normal operating notification; no action required.

Message

Failed to wait for driver unload.

References

Event ID 106 — Windows Defender Advanced Threat Protection service failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during startup. Contact support.

Message

Windows Defender Advanced Threat Protection service failed to start. Failure code %1 ; Failed to load MsSense DLL Module

Fields

NameDescription
HRESULT

References

Event ID 107 — Windows Defender Advanced Threat Protection service failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during startup. Contact support.

Message

Windows Defender Advanced Threat Protection service failed to start. Failure code %1 ; Issue with MsSense DLL Module

Fields

NameDescription
UInt2

References

Event ID 108 — Update phase:%1, new platform version: %2, message: %3.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during update. Normal operating notification; no action required.

Message

Update phase:%1, new platform version: %2, message: %3

Fields

NameDescription
Update_phase
new_platform_version
message
phase
newVersion

References

Event ID 109 — Update phase:%1 new platform version: %2, failure message: %3, error: %4.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during update. Contact support.

Message

Update phase:%1 new platform version: %2, failure message: %3, error: %4

Fields

NameDescription
Update_phase
new_platform_version
failure_message
error
phase
newVersion
message
HRESULT

References

Event ID 110 — Failed to remove MDEContain WFP filters

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during offboarding. Contact support.

Message

Failed to remove MDEContain WFP filters

References

Event ID 111 — Failed to Leave SecurityManagement.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Failed to Leave SecurityManagement. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 112 — MsSecFlt.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

MsSecFlt.sys kernel service failed to request to stop itself after offboarding process. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 113 — MsSecFlt.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

MsSecFlt.sys kernel service has successfully started.

Event ID 114 — MsSecFlt.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

MsSecFlt.sys kernel service failed to start.

Event ID 115 — MsSecWfp.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

MsSecWfp.sys kernel service has successfully started.

Event ID 116 — MsSecWfp.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

MsSecWfp.sys kernel service failed to start.

Event ID 117 — %1: Failed to modify service object trust label.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

%1: Failed to modify service object trust label. Failure code: %2

Fields

NameDescription
Message1
HRESULT

Event ID 118 — Update phase:%1, new platform version: %2, success message: %3.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Update phase:%1, new platform version: %2, success message: %3

Fields

NameDescription
Update_phase
new_platform_version
success_message
phase
newVersion
message

Event ID 119 — Windows Defender Advanced Threat Protection service failed to remove its failure actions.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection service failed to remove its failure actions. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 120 — EventTraker Event data:

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

EventTraker Event data: (%1)

Fields

NameDescription
parameter

Event ID 121 — Info message.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Info message: %1

Fields

NameDescription
Info_message
message

Event ID 122 — Update phase:%1 new platform version: %2, warning message: %3.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Update phase:%1 new platform version: %2, warning message: %3

Fields

NameDescription
Update_phase
new_platform_version
warning_message
phase
newVersion
message
HRESULT

Event ID 123 — Update error message: %5, Additional parameters: %1: %2, %3: %4, error message: %6.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Update error message: %5, Additional parameters: %1: %2, %3: %4, error message: %6

Fields

NameDescription
valueName1
value1
valueName2
value2
message
HRESULT

Event ID 124 — Windows Defender Advanced Threat Protection Trace Event Monitor executable has started

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Trace Event Monitor executable has started

Event ID 125 — Windows Defender Advanced Threat Protection Trace Event Monitor executable has ended

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Trace Event Monitor executable has ended

Event ID 126 — Windows Defender Advanced Threat Protection Trace Event Monitor executable failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Trace Event Monitor executable failed to start. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 127 — Windows Defender Advanced Threat Protection Dlp Processor executable failed to start.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Dlp Processor executable failed to start. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 128 — Windows Defender Advanced Threat Protection Dlp Processor executable has started

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Dlp Processor executable has started

Event ID 129 — Windows Defender Advanced Threat Protection Dlp Processor executable has ended

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Dlp Processor executable has ended

Event ID 130 — Received DLP policy type.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Received DLP policy type: %1. Policy Hash: %2, Timestamp: %3

Fields

NameDescription
Received_DLP_policy_type
Policy_Hash
Timestamp
CommandType
PolicyHash
TimeStamp

Event ID 131 — Completed processing DLP policy type.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Completed processing DLP policy type: %1. Policy Hash: %2, Timestamp: %3

Fields

NameDescription
Completed_processing_DLP_policy_type
Policy_Hash
Timestamp
CommandType
PolicyHash
TimeStamp

Event ID 132 — Failed to process DLP policy type.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Failed to process DLP policy type: %1. Policy Hash: %2, Timestamp: %3. Exception: %4 [%5]

Fields

NameDescription
CommandType
PolicyHash
TimeStamp
HRESULT
ErrorMessage

Event ID 133 — Ignore DLP policy type: %1 at %2 due to Data Loss Prevention feature currently disabled.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Ignore DLP policy type: %1 at %2 due to Data Loss Prevention feature currently disabled.

Fields

NameDescription
Ignore_DLP_policy_type
CommandType
TimeStamp

Event ID 134 — Offboarding blob is revoked via configuration.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Offboarding blob is revoked via configuration. Blob Sha 256: %1.

Fields

NameDescription
BlobSha256

Event ID 135 — Offboarding is blocked for blob with Epoch: %1 , BlobSha256: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Offboarding is blocked for blob with Epoch: %1 , BlobSha256: %2.

Fields

NameDescription
BlobEpoch
BlobSha256

Event ID 300 — Windows Defender Advanced Threat Protection Session Recorder executable has started

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder executable has started

Event ID 301 — Windows Defender Advanced Threat Protection Session Recorder executable has ended

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder executable has ended

Event ID 302 — Windows Defender Advanced Threat Protection Session Recorder init has called from user session %1.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder init has called from user session %1

Fields

NameDescription
parameter

Event ID 303 — Windows Defender Advanced Threat Protection Session Recorder executable failed to start from user session %1.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder executable failed to start from user session %1. Failure code: %2

Fields

NameDescription
Message1
HRESULT

Event ID 304 — Windows Defender Advanced Threat Protection Session Recorder user session logon event for session id: %1, session name: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder user session logon event for session id: %1, session name: %2

Fields

NameDescription
UInt1
Message1

Event ID 305 — Windows Defender Advanced Threat Protection Session Recorder user session logoff event for session id.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder user session logoff event for session id: %1

Fields

NameDescription
UInt1

Event ID 306 — Windows Defender Advanced Threat Protection Session Recorder user session unlock event for session id.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Session Recorder user session unlock event for session id: %1

Fields

NameDescription
UInt1
Message1

Event ID 307 — Failed to update driver permissions Failure code.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during onboarding. Contact support.

Message

Failed to update driver permissions Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 308 — Failed to ACL on Folder %1 Failure code: %2.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during onboarding. Contact support.

Message

Failed to ACL on Folder %1 Failure code: %2

Fields

NameDescription
Message1
HRESULT

References

Event ID 309 — Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id %1 of event log channel: %2, with provid...

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id %1 of event log channel: %2, with provider: %3. Event data will not be collected until next reboot.

Fields

NameDescription
with_provider1 of event log channel.
UInt1
Message1
providerName

Event ID 310 — Failed to store cloud configuration.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Failed to store cloud configuration. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 400 — Windows Defender Advanced Threat Protection service failed to create certificate.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection service failed to create certificate. Failure code: %1

Fields

NameDescription
HRESULT

Event ID 401 — Windows Defender Advanced Threat Protection service failed to generate key.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to create crypto key. If machine isn't reporting, contact support. Otherwise, no action required.

Message

Windows Defender Advanced Threat Protection service failed to generate key. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 402 — Windows Defender Advanced Threat Protection service failed to persist authentication state.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to persist authentication state. If a device isn't reporting, contact support. Otherwise, no action required.

Message

Windows Defender Advanced Threat Protection service failed to persist authentication state. State: %1, Failure code: %2

Fields

NameDescription
Message1
HRESULT

References

Event ID 403 — Registration of device by Windows Defender Advanced Threat Protection service completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Successful registration to authentication service. Normal operating notification; no action required.

Message

Registration of device by Windows Defender Advanced Threat Protection service completed.

References

Event ID 404 — Windows Defender Advanced Threat Protection service successfully generated a key.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Successful crypto key generation. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection service successfully generated a key.

References

Event ID 405 — Failed to communicate with authentication service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to send request to authentication service. Normal operating notification; no action required.

Message

Failed to communicate with authentication service. %1 request failed, hresult: %2,  HTTP error code: %3 .

Fields

NameDescription
HTTP_error_code1 request failed, hresult.
requestType
HRESULT
errorCode

References

Event ID 406 — Request for %1 rejected by authentication service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Request returned undesired response. Normal operating notification; no action required.

Message

Request for %1 rejected by authentication service. Hresult: %2, error code: %3 .

Fields

NameDescription
error_code1 rejected by authentication service. Hresult.
requestType
HRESULT
errorCode

References

Event ID 407 — Windows Defender Advanced Threat Protection service failed to sign message (authentication).

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to sign request. Normal operating notification; no action required.

Message

Windows Defender Advanced Threat Protection service failed to sign message (authentication). Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 408 — Windows Defender Advanced Threat Protection service failed to remove persist authentication state.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to persist authentication state. If a device isn't reporting, contact support. Otherwise, no action required.

Message

Windows Defender Advanced Threat Protection service failed to remove persist authentication state. State: %1, Failure code: %2

Fields

NameDescription
Message1
HRESULT

References

Event ID 409 — Windows Defender Advanced Threat Protection service failed to open key.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to open crypto key. If a device isn't reporting, contact support. Otherwise, no action required.

Message

Windows Defender Advanced Threat Protection service failed to open key. Failure code: %1

Fields

NameDescription
HRESULT

References

Event ID 410 — Registration is required as part of re-onboarding of Windows Defender Advanced Threat Protection service.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Occurs during reonboarding. Normal operating notification; no action required.

Message

Registration is required as part of re-onboarding of Windows Defender Advanced Threat Protection service.

References

Event ID 411 — Cyber telemetry upload has been suspended for Windows Defender Advanced Threat Protection service due to invalid/expired token.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Cyber upload temporarily suspended. Normal operating notification; no action required.

Message

Cyber telemetry upload has been suspended for Windows Defender Advanced Threat Protection service due to invalid/expired token.

References

Event ID 412 — Cyber telemetry upload been resumed for Windows Defender Advanced Threat Protection service due to newly refreshed token.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Cyber upload successfully resumed. Normal operating notification; no action required.

Message

Cyber telemetry upload been resumed for Windows Defender Advanced Threat Protection service due to newly refreshed token.

References

Event ID 413 — Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id {UInt1} of event log channel: {Message1}.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection Network Detection and Response failed to subscribe to event id {UInt1} of event log channel: {Message1}. Event data will not be collected until next reboot.

Fields

NameDescription
UInt1
Message1

Event ID 414 — Key rotation of device by Windows Defender Advanced Threat Protection service completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Key rotation of device by Windows Defender Advanced Threat Protection service completed.

Event ID 415 — Authentication initialization for Windows Defender Advanced Threat Protection service completed successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Authentication initialization for Windows Defender Advanced Threat Protection service completed successfully.

Event ID 416 — EventTraker Event data:

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

EventTraker Event data: (%1)

Fields

NameDescription
parameter

Event ID 417 — Windows Defender Advanced Threat Protection service opened key successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection service opened key successfully.

Event ID 418 — Windows Defender Advanced Threat Protection service certificate creation completed successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection service certificate creation completed successfully.

Event ID 419 — Windows Defender Advanced Threat Protection service authentication request signing completed successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection service authentication request signing completed successfully.

Event ID 420 — Rename of device by Windows Defender Advanced Threat Protection service completed.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Rename of device by Windows Defender Advanced Threat Protection service completed.

Event ID 500 — Windows Defender Advanced Threat Protection orchestrator failed to perform.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection orchestrator failed to perform: %1. Identifier: %2. HRESULT: %3.

Fields

NameDescription
UInt1
Message1
HRESULT

Event ID 501 — Windows Defender Advanced Threat Protection orchestrator performed: %1 successfully.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Windows Defender Advanced Threat Protection orchestrator performed: %1 successfully. Identifier: %2.

Fields

NameDescription
UInt1
Message1

Event ID 1800 — CSP: Get Node's Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Get is about to start. Contact support.

Message

CSP: Get Node's Value. NodeId: (%1), TokenName: (%2).

Fields

NameDescription
UInt1
Message1

References

Event ID 1801 — CSP: Failed to Get Node's Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Get has failed. Contact support.

Message

CSP: Failed to Get Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3).

Fields

NameDescription
UInt1
Message1
HRESULT

References

Event ID 1802 — CSP: Get Node's Value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Get has succeeded. Contact support.

Message

CSP: Get Node's Value complete. NodeId: (%1), TokenName: (%2), Result: (%3).

Fields

NameDescription
UInt1
Message1
HRESULT

References

Event ID 1803 — CSP: Get Last Connected value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Last time the device communicated with CNC. Normal operating notification; no action required.

Message

CSP: Get Last Connected value complete. Result (%1), IsDefault: (%2).

Fields

NameDescription
Message1
Boolean1

References

Event ID 1804 — CSP: Get Org ID value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

The org ID device get during onboarding. Normal operating notification; no action required.

Message

CSP: Get Org ID value complete. Result: (%1), IsDefault: (%2).

Fields

NameDescription
Message1
Boolean1

References

Event ID 1805 — CSP: Get Sense Is Running value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Sense running message after onboarding. Normal operating notification; no action required.

Message

CSP: Get Sense Is Running value complete. Result: (%1).

Fields

NameDescription
UInt1

References

Event ID 1806 — CSP: Get Onboarding State value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get is Sense onboarded. Normal operating notification; no action required.

Message

CSP: Get Onboarding State value complete. Result: (%1), IsDefault: (%2).

Fields

NameDescription
UInt1
Boolean1

References

Event ID 1807 — CSP: Get Onboarding value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get is Sense onboarded and onboarding blob hash. Normal operating notification; no action required.

Message

CSP: Get Onboarding value complete. Onboarding Blob Hash: (%1), IsDefault: (%2), Onboarding State: (%3), Onboarding State IsDefault: (%4)

Fields

NameDescription
onboardingBlobHash
isDefaultOnboardingBlob
onboardingState
isDefaultOnboardingState

References

Event ID 1808 — CSP: Get Offboarding value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get offboarding blob hash. Normal operating notification; no action required.

Message

CSP: Get Offboarding value complete. Offboarding Blob Hash: (%1), IsDefault: (%2).

Fields

NameDescription
offboardingBlobHash
isDefaultOffboardingBlob

References

Event ID 1809 — CSP: Get Sample Sharing value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get is sample upload is allowed. Normal operating notification; no action required.

Message

CSP: Get Sample Sharing value complete. Result: (%1), IsDefault: (%2).

Fields

NameDescription
UInt1
Boolean1

References

Event ID 1810 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Started onboarding flow. Normal operating notification; no action required.

Message

CSP: Onboarding process. Started.

References

Event ID 1811 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Deleted offboarding blob as part of onboarding flow. Normal operating notification; no action required.

Message

CSP: Onboarding process. Delete Offboarding blob complete. Result: (%1).

Fields

NameDescription
HRESULT

References

Event ID 1812 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Wrote onboarding blob to registry as part of onboarding flow. Normal operating notification; no action required.

Message

CSP: Onboarding process. Write Onboarding blob complete. Result: (%1)

Fields

NameDescription
HRESULT

References

Event ID 1813 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Started Sense service as part of onboarding flow. Normal operating notification; no action required.

Message

CSP: Onboarding process. The service started successfully.

References

Event ID 1814 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Finished waiting for Sense to start as part of onboarding flow. Normal operating notification; no action required.

Message

CSP: Onboarding process. Pending service running state complete. Result: (%1).

Fields

NameDescription
HRESULT

References

Event ID 1815 — CSP: Set Sample Sharing value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set sample sharing value. Normal operating notification; no action required.

Message

CSP: Set Sample Sharing value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

Fields

NameDescription
previousSampleCollectionValue
IsDefault
newSampleSharing
HRESULT

References

Event ID 1816 — CSP: Offboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Deleted onboarding blob as part of offboarding flow. Normal operating notification; no action required.

Message

CSP: Offboarding process. Delete Onboarding blob complete. Result (%1).

Fields

NameDescription
HRESULT

References

Event ID 1817 — CSP: Offboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Wrote offboarding blob to registry as part of offboarding flow. Normal operating notification; no action required.

Message

CSP: Offboarding process. Write Offboarding blob complete. Result (%1).

Fields

NameDescription
HRESULT

References

Event ID 1818 — CSP: Set Node's Value started.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Set is about to start. Normal operating notification; no action required.

Message

CSP: Set Node's Value started. NodeId: (%1), TokenName: (%2).

Fields

NameDescription
UInt1
Message1

References

Event ID 1819 — CSP: Failed to Set Node's Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Set has failed. Contact support.

Message

CSP: Failed to Set Node's Value. NodeId: (%1), TokenName: (%2), Result: (%3).

Fields

NameDescription
UInt1
Message1
HRESULT

References

Event ID 1820 — CSP: Set Node's Value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

An operation of Set has succeeded. Normal operating notification; no action required.

Message

CSP: Set Node's Value complete. NodeId: (%1), TokenName: (%2), Result: (%3).

Fields

NameDescription
UInt1
Message1
HRESULT

References

Event ID 1821 — CSP: Set Telemetry Reporting Frequency started.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Start setting the value of TelemetryReportingFrequency. Normal operating notification; no action required.

Message

CSP: Set Telemetry Reporting Frequency started. New value: (%1).

Fields

NameDescription
UInt1

References

Event ID 1822 — CSP: Set Telemetry Reporting Frequency complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Finish setting the value of TelemetryReportingFrequency. Normal operating notification; no action required.

Message

CSP: Set Telemetry Reporting Frequency complete. Previous value: (%1), IsDefault: (%2), New value: (%3), Result: (%4).

Fields

NameDescription
previousLatencyMode
IsDefault
newLatencyMode
HRESULT

References

Event ID 1823 — CSP: Get Telemetry Reporting Frequency complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Gets the value of TelemetryReportingFrequency. Normal operating notification; no action required.

Message

CSP: Get Telemetry Reporting Frequency complete. Value: (%1), Registry Value: (%2), IsDefault: (%3).

Fields

NameDescription
UInt1
Message1
Boolean1

References

Event ID 1824 — CSP: Get Group Ids complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Got groupIds from registry. Normal operating notification; no action required.

Message

CSP: Get Group Ids complete. Value: (%1), IsDefault: (%2).

Fields

NameDescription
Message1
Boolean1

References

Event ID 1825 — CSP: Set Group Ids exceeded allowed limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Failed to set groupIds due to length. Normal operating notification; no action required.

Message

CSP: Set Group Ids exceeded allowed limit. Allowed: (%1), Actual: (%2).

Fields

NameDescription
UInt1
UInt2

References

Event ID 1826 — CSP: Set Group Ids complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set groupIds. Normal operating notification; no action required.

Message

CSP: Set Group Ids complete. Value: (%1), Result: (%2).

Fields

NameDescription
Message1
HRESULT

References

Event ID 1827 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Trace values as part of onboarding. Normal operating notification; no action required.

Message

CSP: Onboarding process. Service is running: (%1), Previous Onboarding Blob Hash: (%2), IsDefault: (%3), Onboarding State: (%4), Onboarding State IsDefault: (%5), New Onboarding Blob Hash: (%6)

Fields

NameDescription
isServiceRunningAlready
previousOnboardingBlobHash
isDefaultOnboardingBlob
onboardingState
isDefaultOnboardingState
newOnboardingBlobHash

References

Event ID 1828 — CSP: Onboarding process.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Trace values as part of offboarding. Normal operating notification; no action required.

Message

CSP: Onboarding process. Service is running: (%1), Previous Offboarding Blob Hash: (%2), IsDefault: (%3), Onboarding State: (%4), Onboarding State IsDefault: (%5), New Offboarding Blob Hash: (%6)

Fields

NameDescription
isServiceRunning
previousOffboardingBlobHash
isDefaultOffboardingBlob
onboardingState
isDefaultOnboardingState
newOffboardingBlobHash

References

Event ID 1829 — CSP: Failed to Set Sample Sharing Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Invalid value for SampleSharing operation. Contact support.

Message

CSP: Failed to Set Sample Sharing Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

Fields

NameDescription
requestedValue
minimumAllowedValue
maximumAllowedValue

References

Event ID 1830 — CSP: Failed to Set Telemetry Reporting Frequency Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Setting the value of TelemetryReportingFrequency failed. Contact support if problem persists.

Message

CSP: Failed to Set Telemetry Reporting Frequency Value. Requested Value: (%1)

Fields

NameDescription
UInt1

References

Event ID 1831 — CSP: Get Sense is running.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get SenseIsRunning result. Normal operating notification; no action required.

Message

CSP: Get Sense is running. Service is configured as delay-start, and hasn't started yet.

References

Event ID 1832 — CSP: Get Device Tagging Group complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get DeviceTagging Group from registry completed. Normal operating notification; no action required.

Message

CSP: Get Device Tagging Group complete. Value: (%1), IsDefault: (%2).

Fields

NameDescription
Message1
Boolean1

References

Event ID 1833 — CSP: Get Device Tagging Criticality value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get DeviceTagging Criticality from registry completed. Normal operating notification; no action required.

Message

CSP: Get Device Tagging Criticality value complete. In Registry: (%1), IsDefault: (%2), Conversion Succeeded: (%3), Result: (%4).

Fields

NameDescription
registryValue
IsDefault
conversionSucceeded
Result

References

Event ID 1834 — CSP: Get Device Tagging Identification Method value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Get DeviceTagging Id Method from registry completed. Normal operating notification; no action required.

Message

CSP: Get Device Tagging Identification Method value complete. In Registry: (%1), IsDefault: (%2), Conversion Succeeded: (%3), Result: (%4).

Fields

NameDescription
registryValue
IsDefault
conversionSucceeded
Result

References

Event ID 1835 — CSP: Set Device Tagging Group complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Group in registry completed. Normal operating notification; no action required.

Message

CSP: Set Device Tagging Group complete. Value: (%1), Result: (%2).

Fields

NameDescription
Message1
HRESULT

References

Event ID 1836 — CSP: Set Device Tagging Group exceeded allowed limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Group failed as maximum Length Limit exceeded. Contact support if problem persists.

Message

CSP: Set Device Tagging Group exceeded allowed limit. Allowed: (%1), Actual: (%2).

Fields

NameDescription
UInt1
UInt2

References

Event ID 1837 — CSP: Set Device Tagging Criticality value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Criticality in registry completed. Normal operating notification; no action required.

Message

CSP: Set Device Tagging Criticality value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

Fields

NameDescription
previousCriticalityValue
IsDefault
newCriticalityValue
HRESULT

References

Event ID 1838 — CSP: Failed to Set Device Tagging Criticality Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Criticality failed as value was not within expected range. Contact support if problem persists.

Message

CSP: Failed to Set Device Tagging Criticality Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

Fields

NameDescription
requestedValue
minimumAllowedValue
maximumAllowedValue

References

Event ID 1839 — CSP: Set Device Tagging Identification Method value complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Id Method in registry completed. Normal operating notification; no action required.

Message

CSP: Set Device Tagging Identification Method value complete. Previous Value: (%1), IsDefault: (%2), New Value: (%3), Result: (%4).

Fields

NameDescription
previousIdMethodValue
IsDefault
newIdMethodValue
HRESULT

References

Event ID 1840 — CSP: Failed to Set Device Tagging Identification Method Value.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Description

Set DeviceTagging Id Method failed as value was not within expected range. Contact support if problem persists.

Message

CSP: Failed to Set Device Tagging Identification Method Value. Requested Value: (%1), Allowed Values between (%2) and (%3).

Fields

NameDescription
requestedValue
minimumAllowedValue
maximumAllowedValue

References

Event ID 1841 — CSP: Get AadDeviceId complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

CSP: Get AadDeviceId complete. Value: (%1), IsDefault: (%2).

Fields

NameDescription
Message1
Boolean1

Event ID 1842 — CSP: Set AadDeviceId complete.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

CSP: Set AadDeviceId complete. Value: (%1), Result: (%2).

Fields

NameDescription
Message1
HRESULT

Event ID 1843 — CSP: Set AadDeviceId exceeded allowed limit.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

CSP: Set AadDeviceId exceeded allowed limit. Allowed: (%1), Actual: (%2).

Fields

NameDescription
UInt1
UInt2

Event ID 2001 — SenseCM.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

SenseCM: %1

Fields

NameDescription
SenseCM
parameter

Event ID 2002 — Info.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Info: %1

Fields

NameDescription
Info
parameter

Event ID 2003 — Warning.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Warning: %1

Fields

NameDescription
Warning
parameter

Event ID 2004 — Error.

Provider
Microsoft-Windows-SENSE
Channel
Operational

Message

Error: %1

Fields

NameDescription
Error
parameter