Microsoft-Windows-SenseIR
14 events across 1 channel
Event ID 1 — Starting action %1.
Message
Fields
| Name | Description |
|---|---|
ActionType | — |
ActionId | — |
Event ID 2 — Failed to run action %1.
Message
Fields
| Name | Description |
|---|---|
error_code | 1. Action ID. |
ActionType | — |
ActionId | — |
HRESULT | — |
Event ID 3 — Succeeded to run action %1.
Message
Fields
| Name | Description |
|---|---|
ActionType | — |
ActionId | — |
Event ID 4 — Windows Defender Advanced Threat Protection Incident Response executable started.
Message
Event ID 5 — Windows Defender Advanced Threat Protection Incident Response executable terminated.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 7 — Windows Defender Advanced Threat Protection Incident Response requested registration as an AIRS client.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 8 — Encountered unexpected error while getting actions from AIRS server.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 9 — Found the caller of Windows Defender Advanced Threat Protection Incident Response executable to be invalid.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 10 — Failed to deserialize Windows Defender Advanced Threat Protection Incident Response parameters.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 11 — Finished uploading results of action %1.
Message
Fields
| Name | Description |
|---|---|
upload_result_code | 1. Action ID. |
ActionType | — |
ActionId | — |
HRESULT | — |
Event ID 12 — Failed to deserialize actions, received invalid actions from AIRS server.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 13 — Failed to execute AIRS request.
Message
Fields
| Name | Description |
|---|---|
HRESULT | — |
Event ID 14 — Starting to upload results of action %1.
Message
Fields
| Name | Description |
|---|---|
ActionType | — |
ActionId | — |
Event ID 15 — Failure during action %1.
Message
Fields
| Name | Description |
|---|---|
Action_phase | 1. Action ID. |
error_code | — |
ActionType | — |
ActionId | — |
ActionPhase | — |
HRESULT | — |