Microsoft-Windows-ServerManager-DeploymentProvider
158 events across 2 channels
Event ID 100 — GetServerComponentAsync method started.
Event ID 101 — GetServerComponentAsync method returned Completed.
Event ID 102 — GetServerComponentAsync method returned InProgress.
Event ID 103 — GetServerComponentAsync method returned Failed.
Event ID 104 — GetEnumerationState method started.
Event ID 105 — GetEnumerationState method returned Completed.
Event ID 106 — GetEnumerationState method returned InProgress.
Event ID 107 — GetEnumerationState method returned Failed.
Event ID 108 — GetServerComponent request started on a separate thread.
Event ID 109 — GetServerComponent request ended on a separate thread.
Event ID 110 — Generic Deployment Error: message.
Event ID 111 — Starting a GetServerComponent request.
#Description
Starting a GetServerComponent request.
Message #
Fields #
| Name | Description |
|---|---|
requestGuid GUID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 111,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:38:27.108245+00:00",
"event_record_id": 97,
"correlation": {
"ActivityID": "49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F"
},
"execution": {
"process_id": 3364,
"thread_id": 3920
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"requestGuid": "5F4BA7DD-8723-42A4-9016-E0DD80603263"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 112 — Completed processing the GetServerComponent request.
#Description
Completed processing the GetServerComponent request. Restart required: restartRequired.
Message #
Fields #
| Name | Description |
|---|---|
restartRequired Boolean | — |
requestGuid GUID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 112,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:38:27.423429+00:00",
"event_record_id": 99,
"correlation": {
"ActivityID": "49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F"
},
"execution": {
"process_id": 3364,
"thread_id": 3920
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"restartRequired": false,
"requestGuid": "5F4BA7DD-8723-42A4-9016-E0DD80603263"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 113 — An error occured while processing the GetServerComponent.
Event ID 114 — An error occured while creating Wbem CIM entry: message ClassName: message2 Error: ErrorCode.
Event ID 115 — Component ptzMessage has invalid DISM state value.
Event ID 200 — AddServerComponentAsync method started.
Event ID 201 — AddServerComponentAsync method returned InProgress.
Event ID 202 — AddServerComponentAsync method returned Failed.
Event ID 203 — Processing request to add Server Components: serverComponentNames.
#Description
Processing request to add Server Components: serverComponentNames.
Message #
Fields #
| Name | Description |
|---|---|
serverComponentNames UnicodeString | — |
requestGuid GUID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 203,
"version": 0,
"level": 4,
"task": 4,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:06:34.072695+00:00",
"event_record_id": 22,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"serverComponentNames": "AD-Domain-Services,GPMC,RSAT,RSAT-AD-AdminCenter,RSAT-AD-PowerShell,RSAT-AD-Tools,RSAT-ADDS,RSAT-ADDS-Tools,RSAT-Role-Tools",
"requestGuid": "1DD4A88D-89D0-3C62-07DD-A16DAD2C3B49"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 204 — Add request complete.
#Description
Add request complete. Server Components added: serverComponentNames.
Message #
Fields #
| Name | Description |
|---|---|
serverComponentNames UnicodeString | — |
requestGuid GUID | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 204,
"version": 0,
"level": 4,
"task": 4,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.593098+00:00",
"event_record_id": 32,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"serverComponentNames": "AD-Domain-Services;GPMC;RSAT;RSAT-AD-AdminCenter;RSAT-AD-PowerShell;RSAT-AD-Tools;RSAT-ADDS;RSAT-ADDS-Tools;RSAT-Role-Tools;",
"requestGuid": "1DD4A88D-89D0-3C62-07DD-A16DAD2C3B49"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 300 — RemoveServerComponentAsync method started.
Event ID 301 — RemoveServerComponentAsync method returned InProgress.
Event ID 302 — RemoveServerComponentAsync method returned Failed.
Event ID 303 — Processing request to remove Server Components: serverComponentNames.
Event ID 304 — Remove request complete.
Event ID 400 — GetAlterationState method started.
Event ID 401 — GetAlterationState method ended.
Event ID 402 — GetAlterationState method returned InProgress.
Event ID 403 — GetAlterationState method returned Failed.
Event ID 450 — Calling MI_RefuseUnload method.
Event ID 451 — Calling MI_RequestUnload method.
Event ID 452 — CreateEvent method call failed.
Event ID 453 — CreateMutex method call failed.
Event ID 454 — MI_PostResult method call failed.
Event ID 455 — MI_Application_Initialize method call failed.
Event ID 456 — MI_Application_Close method call failed.
Event ID 457 — MI_RefuseUnload method call failed.
Event ID 458 — MI_RequestUnload method call failed.
Event ID 459 — The KeepAlive Callback method threw an exception.
Event ID 460 — Starting the KeepAlive Mechanism.
Event ID 461 — The KeepAlive Mechanism started on another thread.
Event ID 462 — The KeepAlive Mutex is in Abandoned state.
Description
The KeepAlive Mutex is in Abandoned state.
Message #
Event ID 463 — Loading Deployment provider.
Description
Loading Deployment provider.
Message #
Event ID 464 — Unloading Deployment provider.
Description
Unloading Deployment provider.
Message #
Event ID 465 — Invalid Request GUID: ptzMessage.
Event ID 466 — A WMI operation failed.
Event ID 467 — Exception detected while reporting a failure.
Event ID 500 — ExecuteEnumerationCommand serverComponentNames Guid requestGuid.
Event ID 501 — ExecuteEnumerationCommand ReadFromCache serverComponentNames Guid requestGuid.
Event ID 502 — ExecuteEnumerationCommand SpawnThread serverComponentNames Guid requestGuid.
Event ID 503 — Enumerate Function Call serverComponentNames Guid requestGuid.
Event ID 504 — Component Repository LoadFromCache serverComponentNames.
Event ID 505 — Component Repository BuildRelationshipModel serverComponentNames.
Event ID 506 — Component Repository ScanSystem serverComponentNames.
Event ID 507 — Create DismSessionManager serverComponentNames.
Event ID 508 — LoadRepository delete existing components serverComponentNames.
Event ID 509 — LoadRepository DismGetFeaturesEx API serverComponentNames.
Event ID 510 — LoadRepository add updates serverComponentNames.
Event ID 511 — LoadRepository add components serverComponentNames.
Event ID 512 — LoadRepository validate components serverComponentNames.
Event ID 513 — Original Server components, Update WMI CLass definitions serverComponentNames Guid requestGuid.
Event ID 514 — Write component results to registry serverComponentNames Guid requestGuid.
Event ID 515 — Write ServiceReport to registry serverComponentNames Guid requestGuid.
Event ID 516 — Consequtive Get Status requests serverComponentNames Guid requestGuid.
Event ID 517 — Consequtive Get requests read from registry StartStop Guid requestGUID.
Event ID 518 — Consequtive Get requests build sorted component tree StartStop Guid requestGUID.
Event ID 519 — Consequtive Get request select based on component names StartStop Guid requestGUID.
Event ID 520 — Consequtive Get request returning InProgress StartStop Guid requestGUID.
Event ID 521 — Add server component serverComponentNames Guid requestGuid.
Event ID 522 — Add server component on vhd serverComponentNames Guid requestGuid.
Event ID 523 — Reset component repository before Add serverComponentNames.
Event ID 524 — Prepare components for Add serverComponentNames.
Event ID 525 — Validate Mutual exclusion groups before add serverComponentNames.
Event ID 526 — Open Dism session for adding components serverComponentNames.
Event ID 527 — Get updates to deploy serverComponentNames.
Event ID 528 — DismEnableFeatures API serverComponentNames.
Event ID 529 — DismCommitImage API called after EnableFeatures serverComponentNames.
Event ID 530 — Refresh state fo modified components serverComponentNames.
Event ID 531 — Remove server component serverComponentNames Guid requestGuid.
Event ID 532 — Remove server component on vhd serverComponentNames Guid requestGuid.
Event ID 533 — Reset repository before removing components serverComponentNames.
Event ID 534 — Prepare components for remove serverComponentNames.
Event ID 535 — Create a list of components that are left installed after remove serverComponentNames.
Event ID 536 — Refresh the state of the modified components after refresh serverComponentNames.
Event ID 537 — Get the list of updates to remove serverComponentNames.
Event ID 538 — Update the children of Dism updates for removal serverComponentNames.
Event ID 539 — Add unused dism updates to the list for removal serverComponentNames.
Event ID 540 — DismDisableFeatures API serverComponentNames.
Event ID 541 — DismCommitImage API for remove serverComponentNames.
Event ID 542 — Refresh the state of the modified components after refresh serverComponentNames.
Event ID 543 — Submit Alteration request serverComponentNames Guid requestGuid.
Event ID 544 — Convert Ids to unique names and save config data serverComponentNames Guid requestGuid.
Event ID 545 — Validate component identities serverComponentNames Guid requestGuid.
Event ID 546 — Mount Image ptzMessage1 Image ptzMessage2.
Event ID 547 — Renmount Image ptzMessage1 Image ptzMessage2.
Event ID 548 — Unmount Image ptzMessage1 Image ptzMessage2.
Event ID 549 — UpdateImageInfo ptzMessage1 Image ptzMessage2.
Event ID 550 — CBS Restart Check ptzMessage.
Event ID 1281 — Unknown MUM2 element detected.
Event ID 1282 — Unknown MUM2 attribute detected.
Event ID 1283 — Server components require the Id property.
#Description
Server components require the Id property. Container Update: ptzMessage.
Message #
Fields #
| Name | Description |
|---|---|
ptzMessage UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1283,
"version": 0,
"level": 3,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.226234+00:00",
"event_record_id": 28,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ptzMessage": "NULL"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1284 — Server components require the UniqueName property.
Event ID 1285 — Server components require the DisplayName property.
#Description
Server components require the DisplayName property. Container Update: ptzMessage.
Message #
Fields #
| Name | Description |
|---|---|
ptzMessage UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1285,
"version": 0,
"level": 3,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.226233+00:00",
"event_record_id": 27,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ptzMessage": "Containers-SDN"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1286 — Server components require the Description property.
#Description
Server components require the Description property. Feature: ptzMessage.
Message #
Fields #
| Name | Description |
|---|---|
ptzMessage UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1286,
"version": 0,
"level": 3,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.226235+00:00",
"event_record_id": 29,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ptzMessage": "NULL"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1287 — Server component's parent not found.
Event ID 1288 — Server components require the Version property.
Event ID 1289 — Server component's deploys section contains an update that was not found.
Event ID 1290 — Mutual Exclusion conflict detected.
Event ID 1291 — Failed to parse MUM2 Xml blob for update message hResult: ErrorCode.
Event ID 1292 — Invalid MUM2 configuration status detected.
Event ID 1293 — Internal fatal error while parsing MUM2 data.
Event ID 1294 — Internal fatal error.
Event ID 1295 — CBS Session message status.
#Description
CBS Session message status. IsComplete: message2 hResult: ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
message UnicodeString | — |
message2 UnicodeString | — |
ErrorCode Int32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1295,
"version": 0,
"level": 4,
"task": 8,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-04T10:59:33.046918+00:00",
"event_record_id": 127,
"correlation": {
"ActivityID": "850A3DF4-2180-4E89-9B18-809650BA5F7E"
},
"execution": {
"process_id": 3636,
"thread_id": 4928
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-TKC15D7KHUR",
"security": {
"user_id": "S-1-5-21-1958040314-2592322477-2606035944-500"
}
},
"event_data": {
"message": "30951442_3983739500",
"message2": "FALSE",
"ErrorCode": 0
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1296 — Task Start: ptzMessage.
Event ID 1297 — Task Stop: ptzMessage.
Event ID 1298 — Failed to read ConfigurationStatus from registry.
Event ID 1299 — Using existing component cache from memory.
#Description
Using existing component cache from memory. Count: value.
Message #
Fields #
| Name | Description |
|---|---|
value UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1299,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:08:41.298079+00:00",
"event_record_id": 37,
"correlation": {
"ActivityID": "E77D047E-EFCB-4760-A9F1-F6ABB4D0D268"
},
"execution": {
"process_id": 3948,
"thread_id": 2712
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"value": 263
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1300 — Component cache read from registry.
#Description
Component cache read from registry. Count: value.
Message #
Fields #
| Name | Description |
|---|---|
value UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1300,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:38:27.159108+00:00",
"event_record_id": 98,
"correlation": {
"ActivityID": "49C8BFAA-E4DA-4AEB-9E40-EA3CAAEDBA1F"
},
"execution": {
"process_id": 3364,
"thread_id": 3920
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"value": 263
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1301 — Component cache loaded from Dism.
#Description
Component cache loaded from Dism. Count: value.
Message #
Fields #
| Name | Description |
|---|---|
value UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1301,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.229769+00:00",
"event_record_id": 31,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"value": 263
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1302 — Unknown MUM2 value detected.
Event ID 1303 — Failed to parse MUM2 for feature ptzMessage.
Event ID 1304 — Found unknown update.
Event ID 1305 — Unable to find component ptzMessage1 referenced by component ptzMessage2.
Event ID 1306 — Component message has invalid ServerComponentType value.
Event ID 1307 — Failed to unmount image - ptzMessage.
Event ID 1308 — Internal fatal error.
Event ID 1309 — Partial install detected.
#Description
Partial install detected. Component ptzMessage1 depends on uninstalled component ptzMessage2.
Message #
Fields #
| Name | Description |
|---|---|
ptzMessage1 UnicodeString | — |
ptzMessage2 UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-ServerManager-DeploymentProvider",
"guid": "66AF9A38-2D94-11E0-A076-8534E0D72085",
"event_source_name": "",
"event_id": 1309,
"version": 0,
"level": 3,
"task": 2,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-07T17:07:12.229250+00:00",
"event_record_id": 30,
"correlation": {
"ActivityID": "B118776B-5149-4D4B-8531-A47C40BCC8BA"
},
"execution": {
"process_id": 3948,
"thread_id": 4900
},
"channel": "Microsoft-Windows-ServerManager-DeploymentProvider/Operational",
"computer": "WIN-FPV0DSIC9O6",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ptzMessage1": "PowerShell-V2",
"ptzMessage2": "NET-Framework-Core"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1310 — Invalid Mum2 detected for component ptzMessage.
Event ID 1311 — Invalid OptionalCompanionFor detected in registry.
Description
Invalid OptionalCompanionFor detected in registry.