Microsoft-Windows-ServerManager-MultiMachine
333 events across 2 channels
Event ID 0 — Refresh scheduler started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 0
version: 0
level: 0
task: 0
opcode: 0
keywords: 0
time_created: '2022-04-07T17:06:29.351679+00:00'
event_record_id: 174
correlation:
ActivityID: DD7B0B6A-4A9E-0000-F886-7BDD9E4AD801
RelatedActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1 — Refresh scheduler stopped.
Message
Event ID 2 — Start of filtering out in-progress refresh.
Message
Fields
| Name | Description |
|---|---|
Category | — |
Machines | — |
Event ID 3 — End of filtering out in-progress refresh.
Message
Fields
| Name | Description |
|---|---|
Category | — |
Machines | — |
Event ID 4 — Short circuit refresh.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 4
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T08:14:07.080861+00:00'
event_record_id: 370
correlation:
ActivityID: DD7B0B6A-4A9E-0001-47B6-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5 — Start of triggering refresh job.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
JobName | — |
Event ID 6 — End of triggering refresh job.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
JobName | — |
Event ID 7 — Error received from refresh job.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 8 — Child job completed.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Command | — |
Target | — |
State | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 8
version: 0
level: 4
task: 12
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:43.025255+00:00'
event_record_id: 687
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 940
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ID: E829D96F-C50A-47DE-A1F2-3823DF71237B
Command: ServerManagerShell\Invoke-_InternalServiceMethod
Target: localhost
State: Completed
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 9 — Parent job completed.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Command | — |
Target | — |
State | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 9
version: 0
level: 4
task: 12
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:43.028446+00:00'
event_record_id: 688
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 4924
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ID: 97DEB445-282E-4B54-9C43-57E30F4270F5
Command: ServerManagerShell\Invoke-_InternalServiceMethod
Target: localhost
State: Completed
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10 — Start of request for refresh.
Message
Fields
| Name | Description |
|---|---|
RefreshTriggerSource | — |
Category | — |
Machines | — |
ID | — |
Event ID 11 — End of request for refresh.
Message
Fields
| Name | Description |
|---|---|
RefreshTriggerSource | — |
Category | — |
Machines | — |
ID | — |
Event ID 12 — Task '.
Message
Fields
| Name | Description |
|---|---|
TaskName | — |
Event ID 13 — Task '.
Message
Fields
| Name | Description |
|---|---|
TaskName | — |
Event ID 14 — Error during processing data.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 15 — Start of decoding BPA results.
Message
Event ID 16 — End of decoding BPA results.
Message
Event ID 17 — Error during decoding of BPA results.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 18 — Start of updating Bpa result records.
Message
Event ID 19 — End of updating Bpa result records.
Message
Event ID 20 — Short circuting of updating of Bpa result records.
Message
Event ID 21 — Error during updating of Bpa result records.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 22 — Triggered Bpa results updated event.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 23 — Start of decoding service statuses.
Message
Event ID 24 — End of decoding service statuses.
Message
Event ID 25 — Error during decoding of service statuses.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 26 — Start of updating services records.
Message
Event ID 27 — End of updating services records.
Message
Event ID 28 — Short circuting of updating of services records.
Message
Event ID 29 — Error during updating of services records.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 30 — Triggered services updated event.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 31 — Plugin load started for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 31
version: 0
level: 4
task: 1
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:20.940593+00:00'
event_record_id: 221
correlation:
ActivityID: DF7F44FB-F3E3-46FF-9AD1-438899980538
execution:
process_id: 1460
thread_id: 3544
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
roleId: 10
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 32 — Plugin load stopped for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 32
version: 0
level: 4
task: 1
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:20.944256+00:00'
event_record_id: 226
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 1260
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
roleId: 10
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 33 — Plugin load failed for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Message | — |
Event ID 34 — Plugin unload started for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 34
version: 0
level: 4
task: 2
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T08:38:13.298689+00:00'
event_record_id: 514
correlation: {}
execution:
process_id: 5300
thread_id: 5256
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
roleId: 481
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 35 — Plugin unload stopped for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Event ID 36 — Plugin unload failed for Role Id %1.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Message | — |
Event ID 37 — Plugin registration information is loaded.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 37
version: 0
level: 4
task: 3
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:22.364248+00:00'
event_record_id: 99
correlation:
ActivityID: DD7B0B6A-4A9E-0000-AC85-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 38 — Plugin registration information failed to load.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 39 — ARW launch command started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 39
version: 0
level: 4
task: 4
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:14.456573+00:00'
event_record_id: 78
correlation:
ActivityID: DD7B0B6A-4A9E-0001-737B-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 40 — ARW launch command completed.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 40
version: 0
level: 4
task: 4
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:14.691796+00:00'
event_record_id: 86
correlation:
ActivityID: DD7B0B6A-4A9E-0001-737B-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 41 — Add server command started.
Message
Event ID 42 — Add server command completed.
Message
Event ID 43 — The requested server %1 is already added.
Message
Fields
| Name | Description |
|---|---|
machineName | — |
errorMessage | — |
Event ID 44 — Add server command failed while adding server %1, failure: %2.
Message
Fields
| Name | Description |
|---|---|
machineName | — |
errorMessage | — |
Event ID 45 — Full refresh command started.
Message
Event ID 46 — Full refresh command completed.
Message
Event ID 47 — Started initializing service provider.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 47
version: 0
level: 4
task: 5
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T16:58:09.017503+00:00'
event_record_id: 517
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 48 — Completed initializing service provider.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 48
version: 0
level: 4
task: 5
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T16:58:09.029982+00:00'
event_record_id: 518
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 49 — Boot loader started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 49
version: 0
level: 4
task: 5
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T16:58:09.083883+00:00'
event_record_id: 519
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 50 — Boot loader completed.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 50
version: 0
level: 4
task: 5
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T16:58:23.552622+00:00'
event_record_id: 527
correlation: {}
execution:
process_id: 4444
thread_id: 4124
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 51 — Boot loader can't find the service provider list, Error.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 52 — Failed to load user settings, Error.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 53 — Main window initialized.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 53
version: 0
level: 4
task: 6
opcode: 0
keywords: 2306124484190404608
time_created: '2022-04-07T16:58:20.988934+00:00'
event_record_id: 522
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 54 — Main window initialization failed, Error.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 55 — Failed to change the navigation item %1 of type %2, attached descriptor: %3.
Message
Fields
| Name | Description |
|---|---|
navigationItemName | — |
navigationItemType | — |
associatedViewDescriptorType | — |
Event ID 56 — Navigation service selection changed.
Message
Fields
| Name | Description |
|---|---|
newNavigationItem | — |
Event ID 57 — Server manager started
Message
Event ID 58 — Server manager shutdown started
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 58
version: 0
level: 4
task: 9
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T08:38:13.257143+00:00'
event_record_id: 509
correlation: {}
execution:
process_id: 5300
thread_id: 5388
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 59 — Server manager shutdown failure.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 60 — Saving server list failure.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 61 — Server manager automation shutdown failure.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 62 — Server manager plugin manager shutdown failure.
Message
Fields
| Name | Description |
|---|---|
errorMessage | — |
Event ID 63 — Server manager exception.
Message
Fields
| Name | Description |
|---|---|
source | — |
exception | — |
Event ID 64 — Start of decoding performance counter threshold alerts results.
Message
Event ID 65 — Stop of decoding performance counter threshold alerts results.
Message
Event ID 66 — Error during decoding performance counter threshold alerts results.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 67 — Start of data update to performance counter threshold alert data.
Message
Event ID 68 — Stop of data update to performance counter threshold alert data.
Message
Event ID 69 — Error during data update to performance counter threshold alert data.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 70 — Triggered performance counter threshold alert data results updated event.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 71 — Start of decoding performance counter samples results.
Message
Event ID 72 — Stop of decoding performance counter samples results.
Message
Event ID 73 — Error during decoding performance counter samples results.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 74 — Start of data update to performance counter sample data.
Message
Event ID 75 — Stop of data update to performance counter sample data.
Message
Event ID 76 — Error during data update to performance counter sample data.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 77 — Triggered performance counter sample data results updated event.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 78 — Start job of diagnostics data collect (process snapshots).
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 79 — Stop job of diagnostics data collect (process snapshots).
Message
Event ID 80 — Error in a job of diagnostics data collect (process snapshots).
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 81 — Start of data update to diagnostics data (process snapshots).
Message
Event ID 82 — Stop of data update to diagnostics data (process snapshots).
Message
Event ID 83 — Error during data update to diagnostics data (process snapshots).
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 84 — Start of time change filter.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 85 — Stop of time change filter.
Message
Event ID 86 — Error during time change filter.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 87 — Start job of time change filter.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 88 — Stop job of time change filter.
Message
Event ID 89 — Error in a job of time change filter.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 90 — Start of data update for time change filter.
Message
Event ID 91 — Stop of data update for time change filter.
Message
Event ID 92 — Error during data update for time change filter.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 93 — Job refresh error.
Message
Fields
| Name | Description |
|---|---|
server | — |
job | — |
exception | — |
Event ID 94 — Splash screen started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 94
version: 0
level: 4
task: 6
opcode: 1
keywords: 2306124484190404608
time_created: '2022-04-07T16:58:06.733119+00:00'
event_record_id: 516
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 95 — Splash screen stopped.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 95
version: 0
level: 4
task: 6
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T16:58:15.307676+00:00'
event_record_id: 521
correlation: {}
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 96 — Server list loading failed.
Message
Event ID 97 — Server manager shutdown stopped.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 97
version: 0
level: 4
task: 9
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T08:38:13.358492+00:00'
event_record_id: 515
correlation: {}
execution:
process_id: 5300
thread_id: 5388
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 98 — User settings save started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 98
version: 0
level: 4
task: 7
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T08:38:13.280535+00:00'
event_record_id: 510
correlation: {}
execution:
process_id: 5300
thread_id: 5256
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 99 — User settings save stopped.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 99
version: 0
level: 4
task: 7
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T08:38:13.293162+00:00'
event_record_id: 511
correlation: {}
execution:
process_id: 5300
thread_id: 5256
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 100 — Automation job history.
Message
Fields
| Name | Description |
|---|---|
Target | — |
JobID | — |
JobName | — |
TimeElapsed | — |
History | — |
Event ID 101 — Automation job history.
Message
Fields
| Name | Description |
|---|---|
Target | — |
JobID | — |
JobName | — |
TimeElapsed | — |
History | — |
Exception | — |
Event ID 102 — Group of inventory refresh jobs has finished.
Message
Fields
| Name | Description |
|---|---|
RefreshTriggerSource | — |
Category | — |
Machines | — |
ID | — |
Event ID 103 — Error encountered while attempting to load an advanced tool.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 104 — DataStore persistence: starting load
Message
Event ID 105 — DataStore persistence: load error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 106 — DataStore persistence: load finished
Message
Event ID 107 — DataStore persistence: starting save
Message
Event ID 108 — DataStore persistence: save error.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 109 — DataStore persistence: save finished
Message
Event ID 110 — Inventory data update failed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 111 — Launched BPA scan on machine %1, BPA Model Ids %2.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
JobName | — |
Event ID 112 — Bpa Scan launch failed for server %1, error: %2.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 113 — Start of enable job of performance counter collector.
Message
Event ID 114 — Stop of enable job of performance counter collector.
Message
Event ID 115 — Failed enabling of performance counter collector.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 116 — Bpa include or exclude launch failed for server %1, error: %2.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 117 — Error while launching command '.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 118 — Failed to close the post deployment configuration task.
Message
Fields
| Name | Description |
|---|---|
Task | — |
Error | — |
Event ID 119 — Created the post deployment task.
Message
Fields
| Name | Description |
|---|---|
Description | — |
Source | — |
Event ID 120 — Completed the post deployment task.
Message
Fields
| Name | Description |
|---|---|
Description | — |
Source | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 120
version: 0
level: 4
task: 13
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:17.045456+00:00'
event_record_id: 181
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
Description: Additional steps are required to make this machine a domain controller.
Source: Wizard
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 121 — Failed to create the post deployment configuration task.
Message
Fields
| Name | Description |
|---|---|
RoleId | — |
Server | — |
Source | — |
Message | — |
Event ID 122 — Unknown type of failure to refresh data.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
MessageId | — |
Message | — |
Event ID 123 — Roles and features discovered on %1: %2.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Features | — |
Event ID 124 — Roles and features requiring configuration on %1: %2.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Features | — |
Event ID 125 — Skipping Server Manager auto refresh.
Message
Event ID 126 — Skipping loading the navigation item for a plugin that is not initialized.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Status | — |
Event ID 127 — Shell plugin icon not found.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Icon | — |
Event ID 128 — Parent role not found.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
currentRoleId | — |
parentRoleId | — |
Event ID 129 — String pool has been scanned.
Message
Fields
| Name | Description |
|---|---|
totalCount | — |
removedCount | — |
elapsedTime | — |
Event ID 130 — Automation job query started.
Message
Fields
| Name | Description |
|---|---|
Owner | — |
Event ID 131 — Automation job query result.
Message
Fields
| Name | Description |
|---|---|
Owner | — |
Count | — |
Event ID 132 — Automation job query completed.
Message
Fields
| Name | Description |
|---|---|
Owner | — |
Error | — |
Event ID 133 — Automation job created.
Message
Fields
| Name | Description |
|---|---|
Owner | — |
Command | — |
Target | — |
Tracked | — |
Rehydrated | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 133
version: 0
level: 4
task: 12
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:40.297165+00:00'
event_record_id: 685
correlation:
ActivityID: E0AAB88C-4A9F-0000-ADEC-AAE09F4AD801
execution:
process_id: 4444
thread_id: 4100
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
Owner: ServerManager
Command: ServerManagerShell\Invoke-_InternalServiceMethod
Target: ''
Tracked: true
Rehydrated: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 134 — Automation job creation failed with error.
Message
Fields
| Name | Description |
|---|---|
ErrorMessage | — |
Event ID 135 — Exception reported to refresh data.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
MessageId | — |
Message | — |
Event ID 136 — Exception reported to data collection.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
MessageId | — |
Message | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 136
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-04T11:01:44.968878+00:00'
event_record_id: 1087
correlation:
ActivityID: 748EA6BB-2722-4FDA-B8B7-DA861FFC7DC8
execution:
process_id: 3156
thread_id: 5064
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
MachineName: WIN-TKC15D7KHUR
OperationName: GetServerEventDetail
MessageId: (None)
Message: "Events from 'WebServer.Events.xml' could not be enumerated.\r\n"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 150 — Automation job started.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Command | — |
Target | — |
Event ID 151 — Automation job state changed.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Command | — |
Target | — |
State | — |
Event ID 152 — Automation job error data added.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
ErrorId | — |
Message | — |
Action | — |
Exception | — |
Event ID 153 — Automation job output data added.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
Event ID 154 — Automation job progress data added.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
PercentComplete | — |
Event ID 155 — Automation job error data added.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
Message | — |
Event ID 156 — Data processing time.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
Milliseconds | — |
Event ID 157 — Lengthy data processing time.
Message
Fields
| Name | Description |
|---|---|
ID | — |
ParentID | — |
Command | — |
Target | — |
Milliseconds | — |
Event ID 160 — Error setting main window focus with the handle.
Message
Fields
| Name | Description |
|---|---|
exception | — |
Event ID 161 — Error writing the window handle.
Message
Fields
| Name | Description |
|---|---|
exception | — |
Event ID 162 — File mapping initialization failed.
Message
Fields
| Name | Description |
|---|---|
errorCode | — |
Event ID 163 — Error shutting down the kernel service.
Message
Fields
| Name | Description |
|---|---|
exception | — |
Event ID 164 — CEIP/WER launch command started.
Message
Event ID 165 — CEIP/WER launch command completed.
Message
Event ID 166 — CEIP/WER plugin load started.
Message
Event ID 167 — CEIP/WER plugin load completed.
Message
Event ID 168 — Connection to M3P starting.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 168
version: 0
level: 4
task: 5
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:29.048530+00:00'
event_record_id: 676
correlation:
ActivityID: E0AAB88C-4A9F-0000-77EB-AAE09F4AD801
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 169 — Connection to M3P completed.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 169
version: 0
level: 4
task: 5
opcode: 2
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:31.700287+00:00'
event_record_id: 679
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 170 — Credentials set for connections to machines.
Message
Fields
| Name | Description |
|---|---|
Targets | — |
UserName | — |
Event ID 171 — Refresh session started.
Message
Fields
| Name | Description |
|---|---|
RefreshTriggerSource | — |
Category | — |
Machines | — |
ID | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 171
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:23.580114+00:00'
event_record_id: 722
correlation: {}
execution:
process_id: 4444
thread_id: 2880
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
RefreshTriggerSource: Scheduler (None, None)
Category: Inventory
Machines: WIN-FPV0DSIC9O6.sigma.fr
ID: 670EEE8B-2C25-447D-AAD4-2FDBE19E5196
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 172 — Refresh session completed.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 172
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.540457+00:00'
event_record_id: 753
correlation:
ActivityID: C9DB0EBB-AD74-4A6D-A36D-C691522795E3
execution:
process_id: 4444
thread_id: 4868
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ID: 670EEE8B-2C25-447D-AAD4-2FDBE19E5196
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 173 — Credentials loaded from the cred store: User name = %1.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Event ID 174 — Error loading credentials from the cred store.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Error | — |
Event ID 175 — Credentials saved to the cred store: User name = %1.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Event ID 176 — Error saving credentials to the cred store.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Error | — |
Event ID 177 — Credentials deleted from the cred store: User name = %1.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Event ID 178 — Error deleting credentials from the cred store.
Message
Fields
| Name | Description |
|---|---|
UserName | — |
Error | — |
Event ID 179 — Local server properties refresh started.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 179
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:11:32.549096+00:00'
event_record_id: 613
correlation: {}
execution:
process_id: 4444
thread_id: 2492
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 180 — Local server properties refresh completed.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 180
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:11:34.976833+00:00'
event_record_id: 615
correlation: {}
execution:
process_id: 4444
thread_id: 2492
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 181 — Error accessing local server properties.
Message
Fields
| Name | Description |
|---|---|
exception | — |
Event ID 182 — Completed services modification job
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 182
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:43.028714+00:00'
event_record_id: 689
correlation:
ActivityID: E0AAB88C-4A9F-0000-E7EC-AAE09F4AD801
execution:
process_id: 4444
thread_id: 4448
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 183 — Launching wizard from automation job started.
Message
Fields
| Name | Description |
|---|---|
Command | — |
Event ID 184 — Launching wizard from automation job completed.
Message
Fields
| Name | Description |
|---|---|
Command | — |
Event ID 190 — Starting WinRM service status check.
Message
Fields
| Name | Description |
|---|---|
serviceStatus | — |
exception | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 190
version: 0
level: 4
task: 12
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:29.061107+00:00'
event_record_id: 677
correlation:
ActivityID: E0AAB88C-4A9F-0000-77EB-AAE09F4AD801
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serviceStatus: Running
exception: None
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 191 — Completed WinRM service status check.
Message
Fields
| Name | Description |
|---|---|
serviceStatus | — |
exception | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 191
version: 0
level: 4
task: 12
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:29.061322+00:00'
event_record_id: 678
correlation:
ActivityID: E0AAB88C-4A9F-0000-77EB-AAE09F4AD801
execution:
process_id: 4444
thread_id: 4780
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serviceStatus: Running
exception: None
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 192 — Refresh item completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Count | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 192
version: 0
level: 4
task: 10
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.540265+00:00'
event_record_id: 752
correlation:
ActivityID: C9DB0EBB-AD74-4A6D-A36D-C691522795E3
execution:
process_id: 4444
thread_id: 4868
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
MachineName: WIN-FPV0DSIC9O6.sigma.fr
Count: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 193 — Error cleaning up credentials from the cred store.
Message
Fields
| Name | Description |
|---|---|
errorCode | — |
Event ID 194 — Cluster query item added.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
ClusterName | — |
Event ID 195 — Cluster query item data received.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 196 — New cluster nodes added to session.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 197 — Cluster query item completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Count | — |
Event ID 200 — Refresh item session create started.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 201 — Refresh item session create completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 202 — Refresh item session close started.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 203 — Refresh item session close completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Error | — |
Event ID 204 — Refresh item invocation started.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
Event ID 205 — Refresh item enumeration started.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
Event ID 206 — Refresh item data received.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
Event ID 207 — Refresh item operation completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
Event ID 208 — Refresh item operation error.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
OperationName | — |
Error | — |
Event ID 209 — Creating new session.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
protocol | — |
userName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 209
version: 0
level: 4
task: 17
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.506487+00:00'
event_record_id: 746
correlation:
ActivityID: 4ACAA8DE-FAC8-4188-A6B0-EFCD7D7B46CA
execution:
process_id: 4444
thread_id: 2632
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: localhost
protocol: DCOM
userName: 'null'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 210 — Enumerate instances started.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
protocol | — |
Event ID 211 — Enumerate instances completed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
protocol | — |
Event ID 212 — Enumerate instances error.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
protocol | — |
error | — |
Event ID 213 — Enumerate instances data received.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
protocol | — |
Event ID 214 — Invoke method started.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 214
version: 0
level: 4
task: 17
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.506485+00:00'
event_record_id: 745
correlation:
ActivityID: 4ACAA8DE-FAC8-4188-A6B0-EFCD7D7B46CA
execution:
process_id: 4444
thread_id: 2632
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: localhost
namespaceName: root\microsoft\windows\servermanager
wmiClassName: MSFT_ServerManagerTasks
methodName: GetServerBpaResult
protocol: DCOM
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 215 — Invoke method completed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 215
version: 0
level: 4
task: 17
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.540206+00:00'
event_record_id: 751
correlation:
ActivityID: C9DB0EBB-AD74-4A6D-A36D-C691522795E3
execution:
process_id: 4444
thread_id: 4868
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: localhost
namespaceName: root\microsoft\windows\servermanager
wmiClassName: MSFT_ServerManagerTasks
methodName: GetServerEventDetail
protocol: DCOM
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 216 — Invoke method error.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
error | — |
Event ID 217 — Invoke method data received.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 217
version: 0
level: 4
task: 17
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:38:27.540179+00:00'
event_record_id: 750
correlation:
ActivityID: C9DB0EBB-AD74-4A6D-A36D-C691522795E3
execution:
process_id: 4444
thread_id: 4868
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: localhost
namespaceName: root\microsoft\windows\servermanager
wmiClassName: MSFT_ServerManagerTasks
methodName: GetServerEventDetail
protocol: DCOM
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 218 — Invoke method non-terminating error received.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
errorCode | — |
errorMessage | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 218
version: 0
level: 3
task: 17
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-04T11:01:44.968700+00:00'
event_record_id: 1086
correlation:
ActivityID: 748EA6BB-2722-4FDA-B8B7-DA861FFC7DC8
execution:
process_id: 3156
thread_id: 5064
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
serverName: localhost
namespaceName: root\microsoft\windows\servermanager
wmiClassName: MSFT_ServerManagerTasks
methodName: GetServerEventDetail
protocol: DCOM
errorCode: 2
errorMessage: "Events from 'WebServer.Events.xml' could not be enumerated.\r\n"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 219 — Invoke method message received.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
namespaceName | — |
wmiClassName | — |
methodName | — |
protocol | — |
channel | — |
message | — |
Event ID 220 — Disconnect from M3P starting.
Message
Event ID 221 — Disconnect from M3P completed.
Message
Event ID 300 — Server data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 301 — Server data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 302 — Server data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 303 — Server data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
categories | — |
Event ID 304 — Server data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
categories | — |
Event ID 305 — Feature data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 306 — Feature data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 307 — Feature data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 308 — Feature data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 309 — Feature data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 310 — BPA data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 311 — BPA data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 312 — BPA data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 313 — BPA data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 314 — BPA data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 315 — Events data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 316 — Events data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 317 — Events data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 318 — Events data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 319 — Events data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 320 — Performance counter data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 321 — Performance counter data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 322 — Performance counter data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 323 — Performance counter data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 324 — Performance counter data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 325 — Services data processer start.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 326 — Services data processer stop.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
Event ID 327 — Services data processor failed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 328 — Services data processor on next start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 329 — Services data processor on next stop.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
parameterName | — |
Event ID 330 — Servers tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 331 — Servers tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 332 — Features tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 333 — Features tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 334 — BPA tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 335 — BPA tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 336 — Events tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 337 — Events tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 338 — Performance tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 339 — Performance tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 340 — Services tile view update start.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 341 — Services tile view update stop.
Message
Fields
| Name | Description |
|---|---|
tileName | — |
categories | — |
Event ID 342 — Servers thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 343 — Servers thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 344 — Timestamp thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
timestamp | — |
Event ID 345 — Timestamp thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
timestamp | — |
Event ID 346 — BPA thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 347 — BPA thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 348 — Events thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 349 — Events thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 350 — Performance thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 351 — Performance thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 352 — Services thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 353 — Services thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 354 — Manageability thumbnail view update start.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 355 — Manageability thumbnail view update stop.
Message
Fields
| Name | Description |
|---|---|
thumbnailName | — |
categories | — |
Event ID 356 — Async job creation started.
Message
Fields
| Name | Description |
|---|---|
ID | — |
Command | — |
Target | — |
State | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 356
version: 0
level: 4
task: 12
opcode: 1
keywords: 2305843009213693952
time_created: '2022-04-07T17:21:41.337170+00:00'
event_record_id: 686
correlation:
ActivityID: 1480B89F-E871-42E4-BFB4-C8F88B053137
execution:
process_id: 4444
thread_id: 4380
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
ID: 97DEB445-282E-4B54-9C43-57E30F4270F5
Command: ServerManagerShell\Invoke-_InternalServiceMethod
Target: localhost
State: Running
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2000 — Deployment Wizard is launched.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2000
version: 0
level: 4
task: 5
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:14.611551+00:00'
event_record_id: 85
correlation:
ActivityID: DD7B0B6A-4A9E-0001-737B-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: WIN-FPV0DSIC9O6
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2001 — Deployment Wizard is closed.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2001
version: 0
level: 4
task: 9
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:18.961762+00:00'
event_record_id: 203
correlation:
ActivityID: DD7B0B6A-4A9E-0000-FD97-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: WIN-FPV0DSIC9O6
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2002 — Deployment Wizard repository loading start.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2002
version: 0
level: 4
task: 6
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:14.562299+00:00'
event_record_id: 81
correlation:
ActivityID: DD7B0B6A-4A9E-0000-5585-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 1360
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
serverName: WIN-FPV0DSIC9O6
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2003 — Deployment Wizard repository loading completed.
Message
Fields
| Name | Description |
|---|---|
targetServer | — |
Message | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2003
version: 0
level: 4
task: 6
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:15.267300+00:00'
event_record_id: 89
correlation:
ActivityID: DD7B0B6A-4A9E-0000-5585-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 1360
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
targetServer: WIN-FPV0DSIC9O6
Message: Success
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2004 — Deployment Wizard repository loading completed and repository is empty.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
Event ID 2005 — Deployment Wizard installation type changed.
Message
Fields
| Name | Description |
|---|---|
Category | — |
Event ID 2006 — Deployment Wizard component selected.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
displayName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2006
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:53.457840+00:00'
event_record_id: 102
correlation:
ActivityID: DD7B0B6A-4A9E-0000-3986-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 3188
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
componentId: 10
displayName: Active Directory Domain Services
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2007 — Deployment Wizard component unselected.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
displayName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2007
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-04T10:56:42.409230+00:00'
event_record_id: 859
correlation:
ActivityID: 066FA786-2FC0-0000-A7F8-7006C02FD801
execution:
process_id: 3156
thread_id: 4644
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
componentId: 468
displayName: Remote Access
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2008 — Deployment Wizard component selection cancelled through dependency dialog.
Message
Event ID 2009 — Deployment Wizard target server collection has changed.
Message
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2009
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:19.729055+00:00'
event_record_id: 96
correlation:
ActivityID: DD7B0B6A-4A9E-0001-BC7B-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2010 — Deployment Wizard page enter.
Message
Fields
| Name | Description |
|---|---|
pageTitle | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2010
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:06:24.456060+00:00'
event_record_id: 163
correlation:
ActivityID: DD7B0B6A-4A9E-0000-9086-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
pageTitle: InstallationCompletionPage
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2011 — Deployment Wizard page exit.
Message
Fields
| Name | Description |
|---|---|
pageTitle | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2011
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:06:24.453440+00:00'
event_record_id: 162
correlation:
ActivityID: DD7B0B6A-4A9E-0000-9086-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
pageTitle: InstallationConfirmationPage
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2012 — Deployment Wizard cancel requested.
Message
Fields
| Name | Description |
|---|---|
serverName | — |
Event ID 2013 — Deployment Wizard commit action started.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
JobName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2013
version: 0
level: 4
task: 12
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:06:32.648209+00:00'
event_record_id: 177
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 5200
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
MachineName: WIN-FPV0DSIC9O6
JobName: ID:66eda40e-d1c4-4391-9a10-1a9a078f1add;Feature installation
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2014 — Deployment Wizard commit action completed.
Message
Fields
| Name | Description |
|---|---|
MachineName | — |
JobName | — |
Status | — |
Reason | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2014
version: 0
level: 4
task: 5
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:17.055539+00:00'
event_record_id: 198
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 5236
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
MachineName: localhost
JobName: ID:66eda40e-d1c4-4391-9a10-1a9a078f1add;Feature installation
Status: Succeeded
Reason: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2015 — Deployment Wizard component selection step completed.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
displayName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2015
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:56.402968+00:00'
event_record_id: 140
correlation:
ActivityID: DD7B0B6A-4A9E-0001-777C-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
componentId: 10
displayName: Active Directory Domain Services
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2016 — Deployment Wizard component unselection completed.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
displayName | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2016
version: 0
level: 4
task: 15
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-04T10:56:42.427037+00:00'
event_record_id: 861
correlation:
ActivityID: 066FA786-2FC0-0000-A8F8-7006C02FD801
execution:
process_id: 3156
thread_id: 3160
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
componentId: 468
displayName: Remote Access
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2100 — Deployment plugin loading started.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2100
version: 0
level: 4
task: 1
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:17.045905+00:00'
event_record_id: 196
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
roleId: 299
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2101 — Deployment plugin loading completed.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Status | — |
Message | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2101
version: 0
level: 4
task: 1
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:17.045906+00:00'
event_record_id: 197
correlation:
ActivityID: AA4DB9AF-DA1D-455F-908A-502ABDF549C8
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
roleId: 299
Status: Not required
Message: The feature add-in is not required.
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2102 — Deployment component pages added.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2102
version: 0
level: 4
task: 7
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:05:56.444994+00:00'
event_record_id: 141
correlation:
ActivityID: DD7B0B6A-4A9E-0001-777C-7BDD9E4AD801
execution:
process_id: 1460
thread_id: 4948
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
componentId: 10
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2103 — Deployment component pages removed.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 2103
version: 0
level: 4
task: 7
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-04T10:56:42.433764+00:00'
event_record_id: 862
correlation:
ActivityID: 066FA786-2FC0-0000-A8F8-7006C02FD801
execution:
process_id: 3156
thread_id: 3160
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-21-1958040314-2592322477-2606035944-500
event_data:
componentId: 468
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2105 — Deployment configuration data export started.
Message
Fields
| Name | Description |
|---|---|
fileLocation | — |
Event ID 2106 — Deployment configuration data export completed.
Message
Fields
| Name | Description |
|---|---|
fileLocation | — |
Event ID 2107 — Pre-requisite check started for component with ComponentId.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
Event ID 2108 — Pre-requisite check completed for component with ComponentId: %1, Status: %2.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Status | — |
Event ID 2109 — Pre-uninstall step started for component with ComponentId.
Message
Fields
| Name | Description |
|---|---|
componentId | — |
Event ID 2110 — Pre-uninstall step completed for component with ComponentId: %1, Status: %2.
Message
Fields
| Name | Description |
|---|---|
roleId | — |
Status | — |
Event ID 4000 — Add-_InternalWindowsRole workflow entered.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
serverComponentNames | — |
remove | — |
pathToVhdFile | — |
permitReboot | — |
source | — |
deleteComponents | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 4000
version: 0
level: 4
task: 4001
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:06:32.576262+00:00'
event_record_id: 175
correlation:
ActivityID: DD7B0B6A-4A9E-0001-E27C-7BDD9E4AD801
execution:
process_id: 5272
thread_id: 2168
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
targetComputer: ''
serverComponentNames: ServerComponent_AD_Domain_Services ServerComponent_GPMC ServerComponent_RSAT
ServerComponent_RSAT_AD_AdminCenter ServerComponent_RSAT_AD_PowerShell ServerComponent_RSAT_AD_Tools
ServerComponent_RSAT_ADDS ServerComponent_RSAT_ADDS_Tools ServerComponent_RSAT_Role_Tools
remove: false
pathToVhdFile: ''
permitReboot: true
source: ''
deleteComponents: false
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4001 — Add-_InternalWindowsRole workflow ended, TargetComputer:%1, RequestState:%2, RebootRequired: %3, ErrorMessage: %4, ErrorId: %5, ErrorCategory: %6, ...
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestState | — |
restartRequired | — |
errorMessage | — |
errorId | — |
errorCategory | — |
warnings | — |
Example Event
system:
provider: Microsoft-Windows-ServerManager-MultiMachine
guid: D8D37081-10BD-4A89-A971-1CDA6899BDB3
event_source_name: ''
event_id: 4001
version: 0
level: 4
task: 4001
opcode: 0
keywords: 2305843009213693952
time_created: '2022-04-07T17:07:16.570811+00:00'
event_record_id: 178
correlation:
ActivityID: DD7B0B6A-4A9E-0001-1F85-7BDD9E4AD801
execution:
process_id: 5272
thread_id: 4992
channel: Microsoft-Windows-ServerManager-MultiMachine/Operational
computer: WIN-FPV0DSIC9O6
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data:
targetComputer: ''
requestState: 1
restartRequired: false
errorMessage: ''
errorId: ''
errorCategory: 0
warnings: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4002 — Add-_InternalWindowsRole workflow reported an error installing or removing the requested component(s), TargetComputer:%1, RequestState:%2, RebootRe...
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestState | — |
restartRequired | — |
errorMessage | — |
errorId | — |
errorCategory | — |
warnings | — |
Event ID 4010 — Add-_InternalWindowsRole workflow launching install/remove operation.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestGuid | — |
Event ID 4011 — Add-_InternalWindowsRole workflow launched install/remove operation, TargetComputer:%1, RequestGuid: %2, RequestState:%3, RebootRequired: %4, Progr...
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestGuid | — |
requestState | — |
restartRequired | — |
progressTicks | — |
totalTicks | — |
errorMessage | — |
errorId | — |
errorCategory | — |
warnings | — |
Event ID 4012 — Add-_InternalWindowsRole workflow polling for completion.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestGuid | — |
Event ID 4013 — Add-_InternalWindowsRole workflow polled for completion, TargetComputer:%1, RequestGuid: %2, RequestState:%3, RebootRequired: %4, ProgressTicks: %5...
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
requestGuid | — |
requestState | — |
restartRequired | — |
progressTicks | — |
totalTicks | — |
errorMessage | — |
errorId | — |
errorCategory | — |
warnings | — |
Event ID 4020 — Add-_InternalWindowsRole workflow has determined that the target computer should be restarted, and is checking whether it has already been restarted.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
initialLastBootTime | — |
Event ID 4021 — Add-_InternalWindowsRole workflow has determined that the target computer should be restarted, and finished checking whether it has already been re...
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
initialLastBootTime | — |
currentLastBootTime | — |
alreadyRebooted | — |
Event ID 4022 — Add-_InternalWindowsRole workflow is requesting restart of the target computer.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
Event ID 4023 — Add-_InternalWindowsRole workflow has requested restart of the target computer.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
Event ID 4024 — Add-_InternalWindowsRole workflow failed to restart the target computer within the timeout period and will exit.
Message
Fields
| Name | Description |
|---|---|
targetComputer | — |
Event ID 9000 — Get-WindowsFeature cmdlet started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9001 — Get-WindowsFeature cmdlet ended, Guid: %1, Components: %2.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9002 — GetServerComponent method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9003 — GetServerComponent method ended with Success.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9004 — GetServerComponent method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9005 — GetServerComponent method returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9006 — GetEnumerationState method started.
Message
Event ID 9007 — GetEnumerationState method ended with Success.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9008 — GetEnumerationState method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9009 — GetEnumerationState method returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9010 — Get Windows feature failed with Error.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 9011 — Component %1 has invalid state %2.
Message
Fields
| Name | Description |
|---|---|
message1 | — |
currentRoleId | — |
Event ID 9012 — Component %1 has state %2.
Message
Fields
| Name | Description |
|---|---|
message1 | — |
currentRoleId | — |
Event ID 9100 — Add-WindowsFeature cmdlet started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9101 — Add-WindowsFeature cmdlet ended.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9102 — AddServerComponent method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9103 — AddServerComponent method ended with Success.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9104 — AddServerComponent method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9105 — AddServerComponent method returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9106 — GetAlterationState method for Add-WindowsFeature started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 9107 — GetAlterationState method for Add-WindowsFeature ended.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9108 — GetAlterationState method for Add-WindowsFeature returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9109 — GetAlterationState method for Add-WindowsFeature returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9110 — Mutual Exclusion conflict detected during add.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9200 — Remove-WindowsFeature cmdlet started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9201 — Remove-WindowsFeature cmdlet ended.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9202 — RemoveServerComponent method started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
serverComponentNames | — |
Event ID 9203 — RemoveServerComponent method ended with Success.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9204 — RemoveServerComponent method returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9205 — RemoveServerComponent method returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9206 — GetAlterationState method for Remove-WindowsFeature started.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
Event ID 9207 — GetAlterationState method for Remove-WindowsFeature ended.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
restartRequired | — |
Event ID 9208 — GetAlterationState method for Remove-WindowsFeature returned InProgress.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
ticks | — |
totalTicks | — |
Event ID 9209 — GetAlterationState method for Remove-WindowsFeature returned Failed.
Message
Fields
| Name | Description |
|---|---|
requestGuid | — |
message | — |
Event ID 9210 — Remove Windows feature failed with Error.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 9211 — Add Windows feature failed with Error.
Message
Fields
| Name | Description |
|---|---|
message | — |
Event ID 9301 —
Message
Fields
| Name | Description |
|---|---|
message | — |