Microsoft-Windows-SenseIR

14 events across 1 channel

Event ID 1 — Starting action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Starting action %1. Action ID: %2

Fields

NameDescription
ActionType
ActionId

Event ID 2 — Failed to run action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Failed to run action %1. Action ID: %2, error code: %3

Fields

NameDescription
error_code1. Action ID.
ActionType
ActionId
HRESULT

Event ID 3 — Succeeded to run action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Succeeded to run action %1. Action ID: %2

Fields

NameDescription
ActionType
ActionId

Event ID 4 — Windows Defender Advanced Threat Protection Incident Response executable started.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Windows Defender Advanced Threat Protection Incident Response executable started.

Event ID 5 — Windows Defender Advanced Threat Protection Incident Response executable terminated.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Windows Defender Advanced Threat Protection Incident Response executable terminated. Exit code: %1

Fields

NameDescription
HRESULT

Event ID 7 — Windows Defender Advanced Threat Protection Incident Response requested registration as an AIRS client.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Windows Defender Advanced Threat Protection Incident Response requested registration as an AIRS client. Result code: %1

Fields

NameDescription
HRESULT

Event ID 8 — Encountered unexpected error while getting actions from AIRS server.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Encountered unexpected error while getting actions from AIRS server. Error code: %1

Fields

NameDescription
HRESULT

Event ID 9 — Found the caller of Windows Defender Advanced Threat Protection Incident Response executable to be invalid.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Found the caller of Windows Defender Advanced Threat Protection Incident Response executable to be invalid. Terminating executable. Error code: %1

Fields

NameDescription
HRESULT

Event ID 10 — Failed to deserialize Windows Defender Advanced Threat Protection Incident Response parameters.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Failed to deserialize Windows Defender Advanced Threat Protection Incident Response parameters. Error code: %1

Fields

NameDescription
HRESULT

Event ID 11 — Finished uploading results of action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Finished uploading results of action %1. Action ID: %2, upload result code: %3

Fields

NameDescription
upload_result_code1. Action ID.
ActionType
ActionId
HRESULT

Event ID 12 — Failed to deserialize actions, received invalid actions from AIRS server.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Failed to deserialize actions, received invalid actions from AIRS server. Error code: %1

Fields

NameDescription
HRESULT

Event ID 13 — Failed to execute AIRS request.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Failed to execute AIRS request. Error code: %1

Fields

NameDescription
HRESULT

Event ID 14 — Starting to upload results of action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Starting to upload results of action %1. Action ID: %2

Fields

NameDescription
ActionType
ActionId

Event ID 15 — Failure during action %1.

Provider
Microsoft-Windows-SenseIR
Channel
Operational

Message

Failure during action %1. Action ID: %2, Action phase: %3, error code: %4

Fields

NameDescription
Action_phase1. Action ID.
error_code
ActionType
ActionId
ActionPhase
HRESULT