Microsoft-Windows-ServerManager-DeploymentProvider
158 events across 2 channels
Event ID 100 — GetServerComponentAsync method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 101 — GetServerComponentAsync method returned Completed.
Message
Fields
| Name | Description |
|---|---|
restartRequired | — |
requestGuid | — |
Event ID 102 — GetServerComponentAsync method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
ticks | — |
totalTicks | — |
requestGuid | — |
Event ID 103 — GetServerComponentAsync method returned Failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 104 — GetEnumerationState method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 105 — GetEnumerationState method returned Completed.
Message
Fields
| Name | Description |
|---|---|
restartRequired | — |
requestGuid | — |
Event ID 106 — GetEnumerationState method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
ticks | — |
totalTicks | — |
requestGuid | — |
Event ID 107 — GetEnumerationState method returned Failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 108 — GetServerComponent request started on a separate thread.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 109 — GetServerComponent request ended on a separate thread.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 110 — Generic Deployment Error.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 111 — Starting a GetServerComponent request.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 111
version: 0
level: 4
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:38:27.108245+00:00'
event_record_id: 97
correlation:
ActivityID: 49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F
execution:
process_id: 3364
thread_id: 3920
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
requestGuid: 5F4BA7DD-8723-42A4-9016-E0DD80603263
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 112 — Completed processing the GetServerComponent request.
Message
Fields
| Name | Description |
|---|---|
restartRequired | — |
requestGuid | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 112
version: 0
level: 4
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:38:27.423429+00:00'
event_record_id: 99
correlation:
ActivityID: 49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F
execution:
process_id: 3364
thread_id: 3920
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
restartRequired: false
requestGuid: 5F4BA7DD-8723-42A4-9016-E0DD80603263
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 113 — An error occured while processing the GetServerComponent.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 114 — An error occured while creating Wbem CIM entry: %1 ClassName: %2 Error: %3.
Message
Fields
| Name | Description |
|---|---|
message | — |
message2 | — |
ErrorCode | — |
Event ID 115 — Component %1 has invalid DISM state %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
value | — |
Event ID 200 — AddServerComponentAsync method started.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 201 — AddServerComponentAsync method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
ticks | — |
totalTicks | — |
requestGuid | — |
Event ID 202 — AddServerComponentAsync method returned Failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 203 — Processing request to add Server Components.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 203
version: 0
level: 4
task: 4
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:06:34.072695+00:00'
event_record_id: 22
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
serverComponentNames: AD-Domain-Services,GPMC,RSAT,RSAT-AD-AdminCenter,RSAT-AD-PowerShell,RSAT-AD-Tools,RSAT-ADDS,RSAT-ADDS-Tools,RSAT-Role-Tools
requestGuid: 1DD4A88D-89D0-3C62-07DD-A16DAD2C3B49
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 204 — Add request complete.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 204
version: 0
level: 4
task: 4
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.593098+00:00'
event_record_id: 32
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
serverComponentNames: AD-Domain-Services;GPMC;RSAT;RSAT-AD-AdminCenter;RSAT-AD-PowerShell;RSAT-AD-Tools;RSAT-ADDS;RSAT-ADDS-Tools;RSAT-Role-Tools;
requestGuid: 1DD4A88D-89D0-3C62-07DD-A16DAD2C3B49
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — RemoveServerComponentAsync method started.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 301 — RemoveServerComponentAsync method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
ticks | — |
totalTicks | — |
requestGuid | — |
Event ID 302 — RemoveServerComponentAsync method returned Failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 303 — Processing request to remove Server Components.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 304 — Remove request complete.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 400 — GetAlterationState method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 401 — GetAlterationState method ended.
Message
Fields
| Name | Description |
|---|---|
restartRequired | — |
requestGuid | — |
Event ID 402 — GetAlterationState method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
ticks | — |
totalTicks | — |
requestGuid | — |
Event ID 403 — GetAlterationState method returned Failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
requestGuid | — |
Event ID 450 — Calling MI_RefuseUnload method.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
Event ID 451 — Calling MI_RequestUnload method.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
Event ID 452 — CreateEvent method call failed.
Message
Fields
| Name | Description |
|---|---|
win32ErrorCode | — |
errorMessage | — |
Event ID 453 — CreateMutex method call failed.
Message
Fields
| Name | Description |
|---|---|
win32ErrorCode | — |
errorMessage | — |
Event ID 454 — MI_PostResult method call failed.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
errorMessage | — |
Event ID 455 — MI_Application_Initialize method call failed.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
errorMessage | — |
Event ID 456 — MI_Application_Close method call failed.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
errorMessage | — |
Event ID 457 — MI_RefuseUnload method call failed.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
errorMessage | — |
Event ID 458 — MI_RequestUnload method call failed.
Message
Fields
| Name | Description |
|---|---|
MI_ResultCode | — |
errorMessage | — |
Event ID 459 — The KeepAlive Callback method threw an exception.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 460 — Starting the KeepAlive Mechanism.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 461 — The KeepAlive Mechanism started on another thread.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 462 — The KeepAlive Mutex is in Abandoned state.
Message
Event ID 463 — Loading Deployment provider.
Message
Event ID 464 — Unloading Deployment provider.
Message
Event ID 465 — Invalid Request GUID.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 466 — A WMI operation failed.
Message
Fields
| Name | Description |
|---|---|
message | — |
value | — |
Event ID 467 — Exception detected while reporting a failure.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 500 — ExecuteEnumerationCommand %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 501 — ExecuteEnumerationCommand ReadFromCache %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 502 — ExecuteEnumerationCommand SpawnThread %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 503 — Enumerate Function Call %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 504 — Component Repository LoadFromCache %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 505 — Component Repository BuildRelationshipModel %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 506 — Component Repository ScanSystem %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 507 — Create DismSessionManager %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 508 — LoadRepository delete existing components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 509 — LoadRepository DismGetFeaturesEx API %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 510 — LoadRepository add updates %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 511 — LoadRepository add components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 512 — LoadRepository validate components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 513 — Original Server components, Update WMI CLass definitions %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 514 — Write component results to registry %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 515 — Write ServiceReport to registry %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 516 — Consequtive Get Status requests %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 517 — Consequtive Get requests read from registry %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
StartStop | — |
requestGUID | — |
Event ID 518 — Consequtive Get requests build sorted component tree %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
StartStop | — |
requestGUID | — |
Event ID 519 — Consequtive Get request select based on component names %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
StartStop | — |
requestGUID | — |
Event ID 520 — Consequtive Get request returning InProgress %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
StartStop | — |
requestGUID | — |
Event ID 521 — Add server component %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 522 — Add server component on vhd %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 523 — Reset component repository before Add %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 524 — Prepare components for Add %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 525 — Validate Mutual exclusion groups before add %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 526 — Open Dism session for adding components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 527 — Get updates to deploy %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 528 — DismEnableFeatures API %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 529 — DismCommitImage API called after EnableFeatures %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 530 — Refresh state fo modified components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 531 — Remove server component %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 532 — Remove server component on vhd %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 533 — Reset repository before removing components %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 534 — Prepare components for remove %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 535 — Create a list of components that are left installed after remove %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 536 — Refresh the state of the modified components after refresh %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 537 — Get the list of updates to remove %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 538 — Update the children of Dism updates for removal %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 539 — Add unused dism updates to the list for removal %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 540 — DismDisableFeatures API %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 541 — DismCommitImage API for remove %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 542 — Refresh the state of the modified components after refresh %1.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
Event ID 543 — Submit Alteration request %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 544 — Convert Ids to unique names and save config data %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 545 — Validate component identities %1 Guid %2.
Message
Fields
| Name | Description |
|---|---|
serverComponentNames | — |
requestGuid | — |
Event ID 546 — Mount Image %1 Image %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 547 — Renmount Image %1 Image %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 548 — Unmount Image %1 Image %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 549 — UpdateImageInfo %1 Image %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 550 — CBS Restart Check %1.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1281 — Unknown MUM2 element detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1282 — Unknown MUM2 attribute detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
ptzMessage3 | — |
Event ID 1283 — Server components require the Id property.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1283
version: 0
level: 3
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.226234+00:00'
event_record_id: 28
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ptzMessage: 'NULL'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1284 — Server components require the UniqueName property.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1285 — Server components require the DisplayName property.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1285
version: 0
level: 3
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.226233+00:00'
event_record_id: 27
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ptzMessage: Containers-SDN
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1286 — Server components require the Description property.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1286
version: 0
level: 3
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.226235+00:00'
event_record_id: 29
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ptzMessage: 'NULL'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1287 — Server component's parent not found.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1288 — Server components require the Version property.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1289 — Server component's deploys section contains an update that was not found.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1290 — Mutual Exclusion conflict detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1291 — Failed to parse MUM2 Xml blob for update %1 hResult: %2.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1292 — Invalid MUM2 configuration status detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1293 — Internal fatal error while parsing MUM2 data.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1294 — Internal fatal error.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1295 — CBS Session %1 status.
Message
Fields
| Name | Description |
|---|---|
message | — |
message2 | — |
ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1295
version: 0
level: 4
task: 8
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-04T10:59:33.046918+00:00'
event_record_id: 127
correlation:
ActivityID: 850A3DF4-2180-4E89-9B18-809650BA5F7E
execution:
process_id: 3636
thread_id: 4928
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
message: '30951442_3983739500'
message2: 'FALSE'
ErrorCode: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1296 — Task Start.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1297 — Task Stop.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1298 — Failed to read ConfigurationStatus from registry.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
ptzMessage3 | — |
Event ID 1299 — Using existing component cache from memory.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1299
version: 0
level: 4
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:08:41.298079+00:00'
event_record_id: 37
correlation:
ActivityID: E77D047E-EFCB-4760-A9F1-F6ABB4D0D268
execution:
process_id: 3948
thread_id: 2712
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
value: 263
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1300 — Component cache read from registry.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1300
version: 0
level: 4
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:38:27.159108+00:00'
event_record_id: 98
correlation:
ActivityID: 49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F
execution:
process_id: 3364
thread_id: 3920
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
value: 263
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1301 — Component cache loaded from Dism.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1301
version: 0
level: 4
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.229769+00:00'
event_record_id: 31
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
value: 263
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1302 — Unknown MUM2 value detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
ptzMessage3 | — |
Event ID 1303 — Failed to parse MUM2 for feature %1.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1304 — Found unknown update.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1305 — Unable to find component %1 referenced by component %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1306 — Component %1 has invalid ServerComponentType %2.
Message
Fields
| Name | Description |
|---|---|
message | — |
value | — |
Event ID 1307 — Failed to unmount image - %1.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1308 — Internal fatal error.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1309 — Partial install detected.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-DeploymentProvider
guid: 66AF9A38-2D94-11E0-A076-8534E0D72085
event_source_name: ''
event_id: 1309
version: 0
level: 3
task: 2
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-07T17:07:12.229250+00:00'
event_record_id: 30
correlation:
ActivityID: B118776B-5149-4D4B-8531-A47C40BCC8BA
execution:
process_id: 3948
thread_id: 4900
channel: Microsoft-Windows-ServerManager-DeploymentProvider/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-18
event_data:
ptzMessage1: PowerShell-V2
ptzMessage2: NET-Framework-Core
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1310 — Invalid Mum2 detected for component %1.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1311 — Invalid OptionalCompanionFor detected in registry.
Message
Event ID 1312 — Failure loading OptionalCompanionFor from registry.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1313 — Failed to load cache from registry.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1314 — Update %1 is not present.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1315 — Exception Detected: %1 ErrorID: %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1316 — Unknown Parent %1 required by %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1317 — Unknown dependency %1 required by %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1318 — Unknown optional tool %1 for feature %2.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1319 — Component: %1 removed from Repository (Index: %2).
Message
Fields
| Name | Description |
|---|---|
message | — |
value | — |
Event ID 1537 — Unable to open installer session.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1538 — Unable to initialize installer.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1539 — Failed to obtain status information from mounted images.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1540 — Failed to mount image.
Message
Fields
| Name | Description |
|---|---|
message | — |
message2 | — |
ErrorCode | — |
Event ID 1541 — Failed read features from system.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1542 — Failed read feature info.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1543 — Failed get the last CBS session ID.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 1544 — Failed get the state from CBS session ID %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1545 — Failed to unmount image.
Message
Fields
| Name | Description |
|---|---|
message | — |
message2 | — |
ErrorCode | — |
Event ID 1546 — Failed to remount image.
Message
Fields
| Name | Description |
|---|---|
message | — |
message2 | — |
ErrorCode | — |
Event ID 1547 — Unable to install updates %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1548 — Unable to uninstall updates %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1549 — Dism session busy.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1550 — Attempting to enable updates via Dism.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1551 — Attempting to disable updates via Dism.
Message
Fields
| Name | Description |
|---|---|
ptzMessage | — |
Event ID 1552 — CBS session busy.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1553 — Internal fatal error.
Message
Fields
| Name | Description |
|---|---|
ptzMessage1 | — |
ptzMessage2 | — |
Event ID 1554 — Error reading configuration status for %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1555 — Failed to load module %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
ErrorCode | — |
Event ID 1556 — Failed to resource ID %2 from module %1.
Message
Fields
| Name | Description |
|---|---|
message | — |
value | — |