Microsoft-Windows-ShellCommon-StartLayoutPopulation
126 events across 2 channels
Event ID 1 — Initialization of collection: %1 has started.
Message
Fields
| Name | Description |
|---|---|
collectionName | — |
initializationReason | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1
version: 0
level: 4
task: 1
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:31.478231+00:00'
event_record_id: 60
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
collectionName: Start.TileGrid
initializationReason: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2 — The collection named %1 is being reset.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 3 — The following selection data was used to choose an initial collection.
Message
Fields
| Name | Description |
|---|---|
layoutSelectionSerializedString | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 3
version: 0
level: 4
task: 3
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:31.705908+00:00'
event_record_id: 61
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
layoutSelectionSerializedString: "\nRegion Codes:US \nSKUs:3 \nOffice SKUs: <not
set>\nGroup Cell Width: <not set>\nPreInstalledAppsEnabled: 0\nTargetedContentTilesEnabled:
1\nEducationModeEnabled: 0\nCommercialDevice: 1\n"
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4 — Initialization of the Start collection has started in the logon tasks
Message
Event ID 5 — Initialization of the Start collection has finished in the logon tasks with the following result.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 6 — The collection initialization pipeline is attempting to find an initial collection.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 6
version: 0
level: 4
task: 5
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:32.529937+00:00'
event_record_id: 62
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 7 — The collection initialization pipeline got an initial collection from the specified collection provider named.
Message
Fields
| Name | Description |
|---|---|
layoutProviderName | — |
Event ID 8 — The collection initialization pipeline got an initial collection from the following provider.
Message
Fields
| Name | Description |
|---|---|
layoutProviderName | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 8
version: 0
level: 4
task: 5
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.128457+00:00'
event_record_id: 63
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
layoutProviderName: LocalXmlStartCollectionProvider
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 9 — The collection initialization pipeline failed to find an initial collection that matched the selection criteria
Message
Event ID 10 — Starting post processing of the selected initial collection.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 10
version: 0
level: 4
task: 6
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.128460+00:00'
event_record_id: 64
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 11 — The %1 post processor has succesfully completed its post processing of the initial collection.
Message
Fields
| Name | Description |
|---|---|
layoutProviderName | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 11
version: 0
level: 4
task: 6
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.234252+00:00'
event_record_id: 69
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
layoutProviderName: MfuModificationPostProcessor
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 12 — The %1 post processor encountered the following error when post processing the initial collection: %2.
Message
Fields
| Name | Description |
|---|---|
layoutProviderName | — |
HResultValue | — |
Event ID 13 — Post processing of the selection initial collection complete.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 13
version: 0
level: 4
task: 6
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.234254+00:00'
event_record_id: 70
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 14 — The collection initialization pipeline is starting to write the collection data to permanent storage.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 14
version: 0
level: 4
task: 8
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.234705+00:00'
event_record_id: 71
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 15 — The collection is being written to the %1 data store.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 15
version: 0
level: 4
task: 8
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.513863+00:00'
event_record_id: 73
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
value: CDS
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 16 — The %1 tile was successfully written to storage.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 16
version: 0
level: 4
task: 8
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.522947+00:00'
event_record_id: 81
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
tileIdentifier: P~Microsoft.WindowsStore_8wekyb3d8bbwe!App
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 17 — Attempting to write the %1 tile to storage encountered the following error: %2.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
failureDetails | — |
Event ID 18 — The collection initialization pipeline has finished writing the collection data to permanent storage.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 18
version: 0
level: 4
task: 8
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.523473+00:00'
event_record_id: 83
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
TaskHResultValue: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 19 — A secondary tile in the chosen layout with the following information is being initialized.
Message
Fields
| Name | Description |
|---|---|
tileData | — |
Event ID 20 — Secondary tile initialization complete.
Message
Event ID 21 — The following error occurred while initializing a secondary tile.
Message
Fields
| Name | Description |
|---|---|
failureDetails | — |
Event ID 22 — The following error occurred while initializing parsing an xml file.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 23 — The installation of the app for the placeholder tile %1 has been initiated due to tile activation.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
Event ID 24 — Placeholder tile app installation has completed.
Message
Event ID 25 — The lifecycle event indicating a placeholder tile installation has succeeded was seen.
Message
Event ID 26 — The automatic installation of placeholder tiles has started.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 26
version: 0
level: 4
task: 11
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:59.904561+00:00'
event_record_id: 85
correlation:
ActivityID: 59A0D65F-1037-0001-8800-A1593710DA01
execution:
process_id: 7864
thread_id: 3512
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 27 — The automatic installation of placeholder tiles is complete.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 27
version: 0
level: 4
task: 11
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:59.911786+00:00'
event_record_id: 87
correlation:
ActivityID: 59A0D65F-1037-0001-8800-A1593710DA01
execution:
process_id: 7864
thread_id: 3512
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 28 — The following placeholder tile's automatic installation was filtered out as the application is already installed.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
Event ID 29 — The following placeholder tile's automatic installation was skipped due to the application's size: %1 Application size: %2.
Message
Fields
| Name | Description |
|---|---|
tileAumid | — |
appSize | — |
Event ID 30 — The installation of the app for placeholder tile %1 has been successfully queued with the Store.
Message
Fields
| Name | Description |
|---|---|
tileAumid | — |
appSize | — |
Event ID 31 — %1 apps have been queued for auto-install.
Message
Fields
| Name | Description |
|---|---|
appSize | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 31
version: 0
level: 4
task: 11
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:59.904580+00:00'
event_record_id: 86
correlation:
ActivityID: 59A0D65F-1037-0001-8800-A1593710DA01
execution:
process_id: 7864
thread_id: 3512
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
appSize: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 32 — The installation of the app for placeholder tile %1 encountered an error.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
Event ID 33 — Starting to retrieve Store metadata for the following applications.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 34 — Store app metadata retrieval successful.
Message
Event ID 35 — An error occurred while retrieving Store metadata.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 36 — The CDSLayoutInitializationPolicy is determining whether is should provide the initial collection.
Message
Event ID 37 — The CDSLayoutInitializationPolicy has completed determining whether is should provide the initial collection.
Message
Event ID 38 — The following tile was detected in the cloud CDS collection but did not appear in the final local CDS collection.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 39 — Starting to retrieve Store assets for the following applications.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 40 — Finished retrieving Store assets for the applications.
Message
Event ID 41 — The following asset was downloaded.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 42 — The UnattendLayoutParser encountered an error processing the following tile.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 43 — Registry keys indicate an OS upgrade needs to be processed.
Message
Event ID 44 — There was a data inconsistency in the upgrade registry keys.
Message
Event ID 45 — The following folder was successfully writen to the collection: %1 X:%2 Y:%3.
Message
Fields
| Name | Description |
|---|---|
containerName | — |
containerXPosition | — |
containerYPosition | — |
Event ID 46 — An error occurred writing the following folder to the collection: %1 X:%2 Y:%3 Error:%4.
Message
Fields
| Name | Description |
|---|---|
containerName | — |
containerXPosition | — |
containerYPosition | — |
failureDetails | — |
Event ID 47 — The collection initialization background task has started processing.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 47
version: 0
level: 4
task: 17
opcode: 1
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:59.766792+00:00'
event_record_id: 84
correlation:
ActivityID: 59A0D65F-1037-0001-8800-A1593710DA01
execution:
process_id: 7864
thread_id: 3512
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 48 — The collection initialization background task has completed processing.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 48
version: 0
level: 4
task: 17
opcode: 2
keywords: 4611686018427387904
time_created: '2023-11-05T22:30:59.917069+00:00'
event_record_id: 88
correlation:
ActivityID: 59A0D65F-1037-0001-8800-A1593710DA01
execution:
process_id: 7864
thread_id: 3512
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 49 — The following tile was registered for background processing.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 50 — The TDLMigrationInitialCollectionProvider is attempting to create an initial collection from the TDL data.
Message
Event ID 51 — The TDLMigrationInitialCollectionProvider is has successfully created an initial collection from the TDL data.
Message
Event ID 52 — A tile with the following data was migrated from TDL.
Message
Fields
| Name | Description |
|---|---|
tileData | — |
Event ID 53 — A tile with the following identifier failed to migrate due to invalid properties.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
Event ID 54 — A group with the following data was migrated from TDL.
Message
Fields
| Name | Description |
|---|---|
groupData | — |
Event ID 55 — A group with the following data failed to migrate.
Message
Fields
| Name | Description |
|---|---|
groupData | — |
Event ID 56 — The following group was successfully writen to the collection: %1 X:%2 Y:%3.
Message
Fields
| Name | Description |
|---|---|
containerName | — |
containerXPosition | — |
containerYPosition | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 56
version: 0
level: 4
task: 8
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.522967+00:00'
event_record_id: 82
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
containerName: Productivity
containerXPosition: 4294967295
containerYPosition: 4294967295
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 57 — An error occurred writing the following group to the collection: %1 X:%2 Y:%3 Error:%4.
Message
Fields
| Name | Description |
|---|---|
containerName | — |
containerXPosition | — |
containerYPosition | — |
failureDetails | — |
Event ID 58 — StartNonLayoutProperties migration failed with HRESULT.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 59 — TryMigrateTDLData was called even though the migration is already complete.
Message
Event ID 60 — The following error occurred trying to parse the local default layout file.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 61 — No layouts were found in the local default layout file.
Message
Event ID 62 — None of the layouts in the local default layout file matched the selection criteria.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 63 — GetCollection was called for collection %1 which does not exist and will be initialized.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 63
version: 0
level: 4
task: 20
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:30.653201+00:00'
event_record_id: 59
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
value: Start.TileGrid
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 64 — The following error occurred while parsing a layout xml file.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 65 — The collection '.
Message
Fields
| Name | Description |
|---|---|
value1 | — |
value2 | — |
Event ID 66 — The Start tile layout was reset to recover from reliability issues.
Message
Event ID 1000 — CuratedTileCollectionTransformer is creating a container for collection it hasn't seen before.
Message
Event ID 1001 — CuratedTileCollectionTransformer has created a container for collection it hasn't seen before.
Message
Event ID 1002 — A CuratedTile has been initialized for the identifier:%1 with GUID :%2.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1004 — A CuratedGroup has been initialized for the identifier:%1 with Name :%2, contained group count:%3, contained tile count: %4.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
itemName | — |
groupCount | — |
tileCount | — |
Event ID 1005 — A CuratedRoot has been initialized for the identifier:%1 with Name :%2, contained group count:%3, contained tile count: %4.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
itemName | — |
groupCount | — |
tileCount | — |
Event ID 1100 — Created group with guid:%1 under parent %2 in collection: %3.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
containerId | — |
collectionName | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1100
version: 0
level: 4
task: 1001
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.520502+00:00'
event_record_id: 75
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
itemId: 063A7277-5D2A-47C9-BE79-DBED598C456E
containerId: 00000000-0000-0000-0000-000000000000
collectionName: Start.TileGrid
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1101 — Removed group named:%1 with guid:%2 from parent: %3 in collection: %4.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
containerId | — |
collectionName | — |
Event ID 1102 — Created tile identifier:%1 and guid:%2 and added it to parent: %3 in collection: %4.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
containerId | — |
collectionName | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1102
version: 0
level: 4
task: 1001
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:05.507941+00:00'
event_record_id: 90
correlation: {}
execution:
process_id: 5484
thread_id: 3168
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
itemName: W~MSEdge
itemId: FCBDF7B6-1920-469A-BA30-56E0FBFE67DB
containerId: 063A7277-5D2A-47C9-BE79-DBED598C456E
collectionName: Start.TileGrid
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1103 — Added tile identifier:%1 and guid:%2 to parent: %3 in collection: %4.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
containerId | — |
collectionName | — |
Event ID 1104 — Removed tile identifier:%1 and guid:%2 from parent: %3 in collection: %4.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
containerId | — |
collectionName | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1104
version: 0
level: 4
task: 1001
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:05.500051+00:00'
event_record_id: 89
correlation: {}
execution:
process_id: 5484
thread_id: 3168
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
itemName: P~Microsoft.MicrosoftEdge_8wekyb3d8bbwe!MicrosoftEdge
itemId: EF66609D-0926-4126-A9BD-C551B16F89A6
containerId: 063A7277-5D2A-47C9-BE79-DBED598C456E
collectionName: Start.TileGrid
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1105 — Added group named:%1 with guid:%2 to parent: %3 in collection: %4.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
containerId | — |
collectionName | — |
Event ID 1106 — Item added to root named.
Message
Fields
| Name | Description |
|---|---|
value | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1106
version: 0
level: 4
task: 1002
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.513521+00:00'
event_record_id: 72
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8072
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
value: Start.TileGrid
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1107 — Item removed from root named.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1200 — An update to the tile with identifier:%1 and guid:%2 was saved locally and communicated to listeners.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1202 — An update to the group with identifier:%1 and guid:%2 was saved locally and communicated to listeners.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1203 — An update to the root with identifier:%1 and guid:%2 was saved locally and communicated to listeners.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1204 — The container %2 could not find the group with GUID:%1 in collection: %3.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
containerId | — |
collectionName | — |
Event ID 1205 — A container %2 could not find the tile with GUID:%1 in collection: %3.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
containerId | — |
collectionName | — |
Event ID 1206 — A missing item with GUID:%1 was created.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
Event ID 1207 — A container %2 was able to resolve the missing group with GUID:%1 in collection: %3.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
containerId | — |
collectionName | — |
Event ID 1208 — A container %2 was able to resolve the missing tile with GUID:%1 in collection: %3.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
containerId | — |
collectionName | — |
Event ID 1209 — A container %1 was waiting to fire a change notification, but was destroyed.
Message
Fields
| Name | Description |
|---|---|
itemId | — |
Event ID 1250 — An update to the tile with identifier:%1 and guid:%2 was saved to CDS.
Message
Fields
| Name | Description |
|---|---|
savedVersion | — |
itemId | — |
Event ID 1252 — An update to the group with identifier:%1 and guid:%2 was saved to CDS.
Message
Fields
| Name | Description |
|---|---|
savedVersion | — |
itemId | — |
Event ID 1253 — An update to the root with identifier:%1 and guid:%2 was saved to CDS.
Message
Fields
| Name | Description |
|---|---|
savedVersion | — |
itemId | — |
Event ID 1254 — An update to the root container was saved to CDS.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1254
version: 0
level: 4
task: 1002
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:29:35.516075+00:00'
event_record_id: 74
correlation:
ActivityID: 59A0D65F-1037-0003-58E5-A0593710DA01
execution:
process_id: 8016
thread_id: 8060
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1300 — An update to the root with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1301 — An update to the group with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1303 — An update to the tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1400 — Removed %1 due to data source reconciliation.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
collectionName | — |
Event ID 1401 — Tile %1 was resurrected into collection %2.
Message
Fields
| Name | Description |
|---|---|
tileIdentifier | — |
collectionName | — |
Event ID 1402 — Data Store Cache secondary data reconciliation start.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1402
version: 0
level: 4
task: 1002
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:34:27.699126+00:00'
event_record_id: 67
correlation: {}
execution:
process_id: 4636
thread_id: 4164
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1403 — Data Store Cache secondary data reconciliation end.
Message
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 1403
version: 0
level: 4
task: 1002
opcode: 0
keywords: 4611686018427387904
time_created: '2022-04-07T17:34:27.739083+00:00'
event_record_id: 68
correlation: {}
execution:
process_id: 4636
thread_id: 4164
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-21-2121334350-1110938707-2888912545-500
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1404 — Unified Tile %1 appeared in the UTM.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1405 — Unified Tile %1 removed from the UTM.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1900 — A failed update to the tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1901 — The Start Layout Root is pinned, but is missing from its collection container.
Message
Event ID 1902 — A failed update to the tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1903 — A failed update to the tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 1904 — A tile with the following data ID is supposed to exist, but has no data.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1905 — A group with the following data ID is supposed to exist, but has no data.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 1906 — A tile with the following data ID exists, but has default data.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 2052 — The CloudInitialCollectionProvider encountered a retrieval error: {failureDetails}.
Message
Fields
| Name | Description |
|---|---|
failureDetails | — |
Event ID 2053 — An error occurred trying to parse the content from the subscription: {TaskHResultValue}.
Message
Fields
| Name | Description |
|---|---|
TaskHResultValue | — |
Event ID 2101 — An update to the placeholder tile with identifier:%1 and guid:%2 was saved locally and communicated to listeners.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 2102 — An update to the placeholder tile with identifier:%1 and guid:%2 was saved to CDS with version %3.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
savedVersion | — |
Event ID 2103 — An update to the placeholder tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 2110 — The data for the logo of placeholder tile with identifier:%1 was loaded.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
size | — |
Event ID 2111 — The logo of placeholder tile with identifier:%1 and size:%2 was saved locally and communicated to listeners.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
size | — |
Event ID 2112 — The logo of placeholder tile with identifier:%1 and size:%2 was saved to CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
size | — |
savedVersion | — |
Event ID 2150 — A failed update to the placeholder tile with identifier:%1 and guid:%2 was received from CDS.
Message
Fields
| Name | Description |
|---|---|
itemName | — |
itemId | — |
Event ID 2151 — An image asset was successfully download to the following location.
Message
Fields
| Name | Description |
|---|---|
value | — |
Event ID 2152 — Install progress state changed for package:%1 to state:%2.
Message
Fields
| Name | Description |
|---|---|
packageFamilyName | — |
InstallState | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 2152
version: 0
level: 4
task: 3002
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T01:39:00.181570+00:00'
event_record_id: 98
correlation: {}
execution:
process_id: 6356
thread_id: 14020
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
packageFamilyName: SpotifyAB.SpotifyMusic_zpdnekdrzrea0
InstallState: 0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2153 — Install completed for package:%1 with state: %2.
Message
Fields
| Name | Description |
|---|---|
packageFamilyName | — |
InstallState | — |
Example Event
system:
provider: Microsoft-Windows-ShellCommon-StartLayoutPopulation
guid: 97CA8142-10B1-4BAA-9FBB-70A7D11231C3
event_source_name: ''
event_id: 2153
version: 0
level: 4
task: 3002
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T01:42:46.303623+00:00'
event_record_id: 99
correlation:
ActivityID: E4DB489E-1037-0000-5148-EDE43710DA01
execution:
process_id: 6356
thread_id: 20696
channel: Microsoft-Windows-ShellCommon-StartLayoutPopulation/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
packageFamilyName: SpotifyAB.SpotifyMusic_zpdnekdrzrea0
InstallState: 4
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2154 — Pacakge:%1 is already installed, installation cancelled.
Message
Fields
| Name | Description |
|---|---|
value | — |