Microsoft-Windows-SMBClient

181 events across 9 channels

Event IDTitleChannel
101Create SrvCall Error: %1 Location: %2 Context: %3.HelperClassDiagnostic
201Session Setup Error: %1 Location: %2 Context: %3.HelperClassDiagnostic
301Tree Connect Error: %1 Location: %2 Context: %3.HelperClassDiagnostic
401Create VNetRoot Error: %1 Location: %2 Context: %3.HelperClassDiagnostic
501Create File Error: %1 Location: %2 Context: %3.HelperClassDiagnostic
2000Packet Fragment (%2 bytes).Diagnostic
20001Transitioned to State: %1 Context: %2.HelperClassDiagnostic
30101SMB ISC request: SessionEntry {SessionEntry} ServerName {ServerName}.XPerfAnalytic
30102SMB ISC completion: SessionEntry {SessionEntry} ServerName {ServerName} Status …XPerfAnalytic
30103SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3.Analytic
30104SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus …Analytic
30105SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 …Analytic
30106SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 …Analytic
30107SMB exchange expired: Exchange {Exchange} Window {Window}.XPerfAnalytic
30108SMB Mid window blocked: Window %1 HungSession %2.Analytic
30109SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window …Analytic
30110SMB initialize Mid window: Server %2 Window %3.Analytic
30111SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 …Analytic
30112SMB teardown Mid window: Server %2 Window %3.Analytic
30113SMB copy data completion: Status %1 VcEndpoint %2.Analytic
30114SMB send completion: Status %1 VcEndpoint %2.Analytic
30201WSK get address info request: ServerName {ServerName} Irp {Irp}.XPerfAnalytic
30202WSK get address info completion: Irp {Irp} Status {Status}.XPerfAnalytic
30203WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4.Analytic
30204WSK connect completion: VcEndpoint %1 Socket %2 Status %3.Analytic
30205WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4.Analytic
30206WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5.Analytic
30207WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4.Analytic
30208WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 …Analytic
30209Compression requested for file object %3: Status %4.Analytic
30210Decompression failed: VcEndpoint %1 Socket %2 ReceiveBuffer %3 ReceiveLength %4 …Analytic
30211Compression failed: VcEndpoint %1 Socket %2 SendBuffer %3 SendLength %4 Status …Analytic
30401SMB session expired: SessionEntry %1 ServerName %3.Analytic
30402SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3.Analytic
30403SMB reconnect durable open: Fcb %1 SrvOpen %2.Analytic
30404SMB defer open: Fcb %1 SrvOpen %2.Analytic
30405SMB undefer open: Fcb %1 SrvOpen %2.Analytic
30406SMB send[.Analytic
30407SMB receive: [.Analytic
30408SMB receive interim: [.Analytic
30409SMB receive async: [.Analytic
30410SMB registry key: %1 = %2.Analytic
30501SMB update file info cache: RxContext %1 Fcb %2 FileName %4.Analytic
30502SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5.Analytic
30503SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4.Analytic
30504SMB update file not found cache: RxContext %1 Fcb %2 FileName %4.Analytic
30505SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5.Analytic
30506SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4.Analytic
30507SMB populate dir cache: RxContext %1 Fcb %2 DirName %4.Analytic
30508SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5.Analytic
30600Session %1 to %6 transitioned from [%2] to [%3] with Status %4.ObjectStateDiagnostic
30601Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4.ObjectStateDiagnostic
30603Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7.ObjectStateDiagnostic
30604The local computer didn't received an SMB1 negotiate response in the last 20 …ObjectStateDiagnostic
30611Failed to reconnect a persistent handle.Operational
30612Failed to reconnect a resilient handle.Operational
30613Failed to open a persistent handle.Operational
30614Persistent handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to …Operational
30615Resilient handle {PersistentFID}:{VolatileFID} to {Object}0{Object}2 was …Operational
30620Connection to server {ServerName} IP Address {RemoteAddress} was aborted.Operational
30621Session to server {ObjectName} was lost Status {Status}.Operational
30622Session to server {ObjectName} was re-established.Operational
30623Connection to share {ObjectName} was lost.Operational
30624Connection to share {ObjectName} was re-established.Operational
30625Handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to …Operational
30626The SMB client received a request to move file server cluster {ServerName} to IP …Operational
30627The SMB client successfully moved file server cluster {ServerName} to IP address …Operational
30628The SMB client failed to move file server cluster {ServerName}.Operational
30700The server {ServerName} does not support multichannel.Operational
30701An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server …ObjectStateDiagnostic
30702The client failed to connect to the server %2 from the local IP address %4 to …ObjectStateDiagnostic
30703The client failed to connect to the server %2 from the local IP address %4 to …ObjectStateDiagnostic
30704The client connected to the server %2 from the local IP address %4 to the remote …ObjectStateDiagnostic
30705The client connected to the server %2 from the local IP address %4 to the remote …ObjectStateDiagnostic
30706The client can not connect to the server {ServerName} due to a multichannel …Operational
30800The server name cannot be resolved.Connectivity
30801%1.Connectivity
30802%1.Connectivity
30803Failed to establish a network connection.Connectivity
30804A network connection was disconnected.Connectivity
30805The client lost its session to the server.Connectivity
30806The client re-established its session to the server.Connectivity
30807The connection to the share was lost.Connectivity
30808The connection to the share was re-established.Connectivity
30809A request timed out because there was no response from the server.Connectivity
30810Added a TCP/IP transport interface.Connectivity
30811Deleted a TCP/IP transport interface.Connectivity
30812Added a TDI transport interface.Connectivity
30813Deleted a TDI transport interface.Connectivity
30814Witness registration has completed.Connectivity
30815Witness deregistration has completed.Connectivity
30816The server failed the negotiate request.Connectivity
30817Close request failed.Connectivity
30818RDMA interfaces are available but the client failed to connect to the server …Connectivity
30819The SMB client received a request to move to a different node on a file server …Connectivity
30820The SMB client successfully moved to a different node on a file server cluster.Connectivity
30821The SMB client failed to move to a different node on a file server cluster.Connectivity
30822Failed to establish an SMB multichannel network connection.Connectivity
30823The connection was terminated due to one or more IO request timeouts.Connectivity
30824The connection was forcibly disconnected.Connectivity
30825The disconnect state on connection was cleared Name: %3 Instance name: %5 …Connectivity
30826The SMB negotiate response processing failed on the client to determine the …Connectivity
30827Could not find a certificate mapping that matches the server name.Connectivity
30828The client established its session to the server.Connectivity
30829The client failed to establish its session to the server.Connectivity
30830The SMB redirector selected the connection initiated with the following …Connectivity
30831The SMB client was denied access to the SMB server during mutual authentication.Connectivity
30832The SMB connection was successfully established.Connectivity
30833The initial connection to the share was established.Connectivity
30834The client was unable to perform revocation checks on the server certificate …Connectivity
30835Server authentication failed.Connectivity
30837The requested transport is disabled.Connectivity
30900The handle was created without persistence.Operational
30904The server does not support multichannel.Operational
30905The client cannot connect to the server due to a multichannel constraint …Operational
30906A request on persistent/resilient handle failed because the handle was invalid …Operational
30907The SMB Multichannel registry value is not configured with default settings.Operational
30908The SMB 3 and SMB 2 driver is not configured with the default start type.Operational
30909The client supports SMB Direct (RDMA) and SMB Signing is in use.Operational
30910The client supports SMB Direct (RDMA) and SMB Encryption is in use.Operational
30911The Cipher Suite Order group policy setting is invalid.Operational
30912The RequireSecureNegotiate setting has been removed.Operational
30913Server %2 share %4 has requested client to use isolated connections to …Operational
30914RDMA rundown is active.Operational
30915RDMA rundown is complete.Operational
30916Reactivation of RDMA support has commenced.Operational
30917RDMA is no longer disabled.Operational
30918SMBDirect load attempt complete.Operational
30950Component capabilities: %1 Internal patch number: %2.Operational
30951The alternative port %1 is not a valid port within the range 0 to 65535 for …Operational
30952The SMB redirector did not select the connection initiated with the following …Operational
30953SMB Dialect Change %1 was changed from %2 to %3.Operational
30954It took %2 secs to execute %1.HelperClassDiagnostic
30955It took %2 secs to execute %1 which is longer than threshold of %3 secs.Operational
31000%1.Security
31001%1.Security
31002The outbound authentication failed using a network token.Security
31003The LmCompatibilityLevel value is different from the default.Security
31010The SMB client failed to connect to the share.Security
31012The negotiate validation failed.Security
31013The signing validation failed.Security
31014The client received an unencrypted message when encryption was expected.Security
31015Failed to decrypt an encrypted SMB message.Security
31016The SMB Signing registry value is not configured with default settings.Security
31017Rejected an insecure guest logon.Security
31018Guidance: An administrator has enabled AllowInsecureGuestAuth.Security
31019Mutual authentication was unexpectedly lost after re-authenticating to %6 User …Security
31020Session key for connection is weaker than required.Security
31021SMB DDP security changed from %1 to %2.Security
31022Allowed an insecure guest logon.Security
31023NTLM is prohibited for authentication on the server Server name: %2 NTLM was …Security
31997The SMB client was logged on as Guest account.Audit
31998The SMB client observed that the server doesn't support signing.Audit
31999The SMB client observed that the server doesn't support encryption.Audit
32000SMB1 negotiate response received from remote device when SMB1 cannot be …Audit
32002The local computer received an SMB1 negotiate response.Audit
32003The local computer didn't received an SMB1 negotiate response in the last %1 …Audit
32004SMB2 rxcontext performance work startedAnalytic
32005SMB2 exchange performance work startedAnalytic
32006SMB2 buffer context performance work startedAnalytic
32007SMB2 performance work transitionAnalytic
32008SMB2 rxcontext performance work read summaryAnalytic
32009SMB2 rxcontext performance work write summaryAnalytic
32010SMB2 rxcontext performance work create summaryAnalytic
32011SMB2 rxcontext performance work close summaryAnalytic
32012SMB2 rxcontext performance work query directory summaryAnalytic
32013SMB2 rxcontext performance work fsctl summaryAnalytic
32028SMB2 exchange performance work read summaryAnalytic
32029SMB2 exchange performance work write summaryAnalytic
32030SMB2 exchange performance work create summaryAnalytic
32031SMB2 exchange performance work close summaryAnalytic
32032SMB2 exchange performance work query directory summaryAnalytic
32033SMB2 exchange performance work fsctl summaryAnalytic
32048SMB2 buffer context performance work read summaryAnalytic
32049SMB2 buffer context performance work write summaryAnalytic
32050SMB2 buffer context performance work create summaryAnalytic
32051SMB2 buffer context performance work close summaryAnalytic
32052SMB2 buffer context performance work query directory summaryAnalytic
32053SMB2 buffer context performance work fsctl summaryAnalytic
32068SMB2 FCB capture summaryAnalytic
40000Packet (%4 bytes).Diagnostic

Event ID 101 — Create SrvCall Error: %1 Location: %2 Context: %3.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Create SrvCall Error: %1 Location: %2 Context: %3

Fields

NameDescription
ErrorCode
Location
Context

Event ID 201 — Session Setup Error: %1 Location: %2 Context: %3.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Session Setup Error: %1 Location: %2 Context: %3

Fields

NameDescription
ErrorCode
Location
Context

Event ID 301 — Tree Connect Error: %1 Location: %2 Context: %3.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Tree Connect Error: %1 Location: %2 Context: %3

Fields

NameDescription
ErrorCode
Location
Context

Event ID 401 — Create VNetRoot Error: %1 Location: %2 Context: %3.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Create VNetRoot Error: %1 Location: %2 Context: %3

Fields

NameDescription
ErrorCode
Location
Context

Event ID 501 — Create File Error: %1 Location: %2 Context: %3.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Create File Error: %1 Location: %2 Context: %3

Fields

NameDescription
ErrorCode
Location
Context

Event ID 2000 — Packet Fragment (%2 bytes).

Provider
Microsoft-Windows-SMBClient
Channel
Diagnostic

Message

Packet Fragment (%2 bytes)

Fields

NameDescription
ReassembledEventID
FragmentSize
FragmentData

Event ID 20001 — Transitioned to State: %1 Context: %2.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

Transitioned to State: %1 Context: %2

Fields

NameDescription
CurrentOrNextState
Context

Event ID 30101 — SMB ISC request: SessionEntry {SessionEntry} ServerName {ServerName}.

Provider
Microsoft-Windows-SMBClient
Channel
XPerfAnalytic

Message

SMB ISC request: SessionEntry {SessionEntry} ServerName {ServerName}

Fields

NameDescription
SessionEntry
ServerName

Event ID 30102 — SMB ISC completion: SessionEntry {SessionEntry} ServerName {ServerName} Status {Status}.

Provider
Microsoft-Windows-SMBClient
Channel
XPerfAnalytic

Message

SMB ISC completion: SessionEntry {SessionEntry} ServerName {ServerName} Status {Status}

Fields

NameDescription
SessionEntry
ServerName
Status

Event ID 30103 — SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3

Fields

NameDescription
RxContext
Exchange
ListHead

Event ID 30104 — SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus %4

Fields

NameDescription
RxContext
Exchange
ExchangeState
ExchangeStatus

Event ID 30105 — SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7

Fields

NameDescription
BufferCtxt
Exchange
MidCharge
Window
CurrentWindowLimit
ThrottlingWindowLimit
CurrentWindowSize

Event ID 30106 — SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7

Fields

NameDescription
BufferCtxt
Exchange
MidCharge
Window
CurrentWindowLimit
ThrottlingWindowLimit
CurrentWindowSize

Event ID 30107 — SMB exchange expired: Exchange {Exchange} Window {Window}.

Provider
Microsoft-Windows-SMBClient
Channel
XPerfAnalytic

Message

SMB exchange expired: Exchange {Exchange} Window {Window}

Fields

NameDescription
Exchange
Window

Event ID 30108 — SMB Mid window blocked: Window %1 HungSession %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB Mid window blocked: Window %1 HungSession %2

Fields

NameDescription
Window
HungSession

Event ID 30109 — SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize...

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7

Fields

NameDescription
BufferCtxt
Exchange
MidCharge
Window
CurrentWindowLimit
ThrottlingWindowLimit
CurrentWindowSize

Event ID 30110 — SMB initialize Mid window: Server %2 Window %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB initialize Mid window: Server %2 Window %3

Fields

NameDescription
ServerNameLength
ServerName
MidWindow

Event ID 30111 — SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 ThrottlingWindowLimit %4 OldestPendingMid %5 NextAvailableMid %6 Credits...

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 ThrottlingWindowLimit %4 OldestPendingMid %5 NextAvailableMid %6 CreditsGranted %7

Fields

NameDescription
MidWindow
CurrentWindowSize
CurrentWindowLimit
ThrottlingWindowLimit
OldestPendingMid
NextAvailableMid
CreditsGranted

Event ID 30112 — SMB teardown Mid window: Server %2 Window %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB teardown Mid window: Server %2 Window %3

Fields

NameDescription
ServerNameLength
ServerName
MidWindow

Event ID 30113 — SMB copy data completion: Status %1 VcEndpoint %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB copy data completion: Status %1 VcEndpoint %2

Fields

NameDescription
Status
VcEndpoint

Event ID 30114 — SMB send completion: Status %1 VcEndpoint %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB send completion: Status %1 VcEndpoint %2

Fields

NameDescription
Status
VcEndpoint

Event ID 30201 — WSK get address info request: ServerName {ServerName} Irp {Irp}.

Provider
Microsoft-Windows-SMBClient
Channel
XPerfAnalytic

Message

WSK get address info request: ServerName {ServerName} Irp {Irp}

Fields

NameDescription
ServerName
Irp

Event ID 30202 — WSK get address info completion: Irp {Irp} Status {Status}.

Provider
Microsoft-Windows-SMBClient
Channel
XPerfAnalytic

Message

WSK get address info completion: Irp {Irp} Status {Status}

Fields

NameDescription
Irp
Status

Event ID 30203 — WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4

Fields

NameDescription
RemoteAddressLength
RemoteAddress
VcEndpoint
Socket
ConnectionType

Event ID 30204 — WSK connect completion: VcEndpoint %1 Socket %2 Status %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK connect completion: VcEndpoint %1 Socket %2 Status %3

Fields

NameDescription
VcEndpoint
Socket
Status
ConnectionType

Event ID 30205 — WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
ConnectionType

Event ID 30206 — WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
Status
ConnectionType

Event ID 30207 — WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
ConnectionType

Event ID 30208 — WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
Status
ConnectionType

Event ID 30209 — Compression requested for file object %3: Status %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

Compression requested for file object %3: Status %4

Fields

NameDescription
VcEndpoint
Socket
Smb2Fobx
Status

Event ID 30210 — Decompression failed: VcEndpoint %1 Socket %2 ReceiveBuffer %3 ReceiveLength %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

Decompression failed: VcEndpoint %1 Socket %2 ReceiveBuffer %3 ReceiveLength %4 Status %5

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
Status
ConnectionType

Event ID 30211 — Compression failed: VcEndpoint %1 Socket %2 SendBuffer %3 SendLength %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

Compression failed: VcEndpoint %1 Socket %2 SendBuffer %3 SendLength %4 Status %5

Fields

NameDescription
VcEndpoint
Socket
SendMdl
SendLength
Status
ConnectionType

Event ID 30401 — SMB session expired: SessionEntry %1 ServerName %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB session expired: SessionEntry %1 ServerName %3

Fields

NameDescription
SessionEntry
ServerNameLength
ServerName

Event ID 30402 — SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3

Fields

NameDescription
SessionEntry
ServerNameLength
ServerName

Event ID 30403 — SMB reconnect durable open: Fcb %1 SrvOpen %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB reconnect durable open: Fcb %1 SrvOpen %2

Fields

NameDescription
Fcb
SrvOpen

Event ID 30404 — SMB defer open: Fcb %1 SrvOpen %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB defer open: Fcb %1 SrvOpen %2

Fields

NameDescription
Fcb
SrvOpen

Event ID 30405 — SMB undefer open: Fcb %1 SrvOpen %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB undefer open: Fcb %1 SrvOpen %2

Fields

NameDescription
Fcb
SrvOpen

Event ID 30406 — SMB send[.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB send[%1]: [%2] (Mid/Sid/Tid) (%3/%4/%5) MidCharge %6 Creds %7 SendLengh %8 VcEndpoint %9

Fields

NameDescription
Count
Command
MessageId
SessionId
TreeId
MidCharge
CreditRequested
SendLength
VcEndpoint

Event ID 30407 — SMB receive: [.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB receive: [%1] (Mid/Sid/Tid) (%2/%4/%5) Creds %6 Status %7 VcEndpoint %8

Fields

NameDescription
Command
MessageId
AsyncId
SessionId
TreeId
CreditGranted
Status
VcEndpoint

Event ID 30408 — SMB receive interim: [.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB receive interim: [%1] (Mid/AsyncId/Sid/Tid) (%2/%3/%4/%5) Creds %6 Status %7 VcEndpoint %8

Fields

NameDescription
Command
MessageId
AsyncId
SessionId
TreeId
CreditGranted
Status
VcEndpoint

Event ID 30409 — SMB receive async: [.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB receive async: [%1] (AsyncId/Sid/Tid) (%3/%4/%5) Creds %6 Status %7 VcEndpoint %8

Fields

NameDescription
Command
MessageId
AsyncId
SessionId
TreeId
CreditGranted
Status
VcEndpoint

Event ID 30410 — SMB registry key: %1 = %2.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB registry key: %1 = %2

Fields

NameDescription
RegName
RegValue

Event ID 30501 — SMB update file info cache: RxContext %1 Fcb %2 FileName %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB update file info cache: RxContext %1 Fcb %2 FileName %4

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30502 — SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30503 — SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30504 — SMB update file not found cache: RxContext %1 Fcb %2 FileName %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB update file not found cache: RxContext %1 Fcb %2 FileName %4

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30505 — SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30506 — SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30507 — SMB populate dir cache: RxContext %1 Fcb %2 DirName %4.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB populate dir cache: RxContext %1 Fcb %2 DirName %4

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30508 — SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5.

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5

Fields

NameDescription
RxContext
Fcb
FileNameLength
FileName
Status

Event ID 30600 — Session %1 to %6 transitioned from [%2] to [%3] with Status %4.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

Session %1 to %6 transitioned from [%2] to [%3] with Status %4

Fields

NameDescription
Object
OldState
NewState
Status
NameLength
ObjectName

Event ID 30601 — Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4

Fields

NameDescription
Object
OldState
NewState
Status
NameLength
ObjectName

Event ID 30603 — Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7

Fields

NameDescription
Object
PersistentFID
VolatileFID
CreateGUID
OldState
NewState
Status
Reason
ShareNameLength
ShareName
ObjectNameLength
ObjectName
PreviousStatus
PreviousReason

Event ID 30604 — The local computer didn't received an SMB1 negotiate response in the last 20 minutes.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

The local computer didn't received an SMB1 negotiate response in the last 20 minutes.n
Guidance:

This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Client service will automatically uninstall.

Fields

NameDescription
Days

Event ID 30611 — Failed to reconnect a persistent handle.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Failed to reconnect a persistent handle.

Error: %7

FileId: %2:%3
CreateGUID: %4
Path: %10%12

Reason: %8

Previous reconnect error: %13
Previous reconnect reason: %14

Guidance:
A persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information.

Fields

NameDescription
Object
PersistentFID
VolatileFID
CreateGUID
OldState
NewState
Status
Reason
ShareNameLength
ShareName
ObjectNameLength
ObjectName
PreviousStatus
PreviousReason

Event ID 30612 — Failed to reconnect a resilient handle.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Failed to reconnect a resilient handle.

Error: %7

FileId: %2:%3
Path: %10%12

Reason: %8.

Previous reconnect error: %13
Previous reconnect reason: %14

Guidance:
A resilient handle provides guarantees to applications requesting it. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information.

Fields

NameDescription
Object
PersistentFID
VolatileFID
CreateGUID
OldState
NewState
Status
Reason
ShareNameLength
ShareName
ObjectNameLength
ObjectName
PreviousStatus
PreviousReason

Event ID 30613 — Failed to open a persistent handle.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Failed to open a persistent handle.

Error: %7

FileId: %2:%3
CreateGUID: %4
Path: %10%12

Reason: %8

Guidance:
A persistent handle allows transparent failover on Windows File Server clusters. This event has many causes and does not always indicate an issue with SMB. Review online documentation for troubleshooting information.

Fields

NameDescription
Object
PersistentFID
VolatileFID
CreateGUID
OldState
NewState
Status
Reason
ShareNameLength
ShareName
ObjectNameLength
ObjectName
PreviousStatus
PreviousReason

Event ID 30614 — Persistent handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 was orphaned.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Persistent handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 was orphaned.

Fields

NameDescription
PersistentFID
VolatileFID
CreateGUID
Object

Event ID 30615 — Resilient handle {PersistentFID}:{VolatileFID} to {Object}0{Object}2 was orphaned.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Resilient handle {PersistentFID}:{VolatileFID} to {Object}0{Object}2 was orphaned.

Fields

NameDescription
PersistentFID
VolatileFID
Object

Event ID 30620 — Connection to server {ServerName} IP Address {RemoteAddress} was aborted.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Connection to server {ServerName} IP Address {RemoteAddress} was aborted.

Fields

NameDescription
ServerName
RemoteAddress

Event ID 30621 — Session to server {ObjectName} was lost Status {Status}.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Session to server {ObjectName} was lost Status {Status}

Fields

NameDescription
ObjectName
Status

Event ID 30622 — Session to server {ObjectName} was re-established.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Session to server {ObjectName} was re-established.

Fields

NameDescription
ObjectName

Event ID 30623 — Connection to share {ObjectName} was lost.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Connection to share {ObjectName} was lost. Status {Status}

Fields

NameDescription
ObjectName
Status

Event ID 30624 — Connection to share {ObjectName} was re-established.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Connection to share {ObjectName} was re-established.

Fields

NameDescription
ObjectName

Event ID 30625 — Handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 granted without persistence.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 granted without persistence.

Fields

NameDescription
PersistentFID
VolatileFID
CreateGUID
Object

Event ID 30626 — The SMB client received a request to move file server cluster {ServerName} to IP address {RemoteAddress}.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB client received a request to move file server cluster {ServerName} to IP address {RemoteAddress}

Fields

NameDescription
ServerName
RemoteAddress

Event ID 30627 — The SMB client successfully moved file server cluster {ServerName} to IP address {RemoteAddress}.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB client successfully moved file server cluster {ServerName} to IP address {RemoteAddress}

Fields

NameDescription
ServerName
RemoteAddress

Event ID 30628 — The SMB client failed to move file server cluster {ServerName}.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB client failed to move file server cluster {ServerName}. Error: {Status}

Fields

NameDescription
ServerName
Status

Event ID 30700 — The server {ServerName} does not support multichannel.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The server {ServerName} does not support multichannel

Fields

NameDescription
ServerName

Event ID 30701 — An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server %2.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server %2

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30702 — The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport. Error: %7

Fields

NameDescription
ServerNameLength
ServerName
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress
Status

Event ID 30703 — The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport. Error: %7

Fields

NameDescription
ServerNameLength
ServerName
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress
Status

Event ID 30704 — The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport successfully.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport successfully

Fields

NameDescription
ServerNameLength
ServerName
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress
Status

Event ID 30705 — The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport successfully.

Provider
Microsoft-Windows-SMBClient
Channel
ObjectStateDiagnostic

Message

The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport successfully

Fields

NameDescription
ServerNameLength
ServerName
LocalAddressLength
LocalAddress
RemoteAddressLength
RemoteAddress
Status

Event ID 30706 — The client can not connect to the server {ServerName} due to a multichannel constraint registry setting.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The client can not connect to the server {ServerName} due to a multichannel constraint registry setting

Fields

NameDescription
ServerName

Event ID 30800 — The server name cannot be resolved.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity
Level
2
Samples
1

Message

The server name cannot be resolved.

Error: %2

Server name: %4

Guidance:
The client cannot resolve the server address in DNS or WINS. This issue often manifests immediately after joining a computer to the domain, when the client's DNS registration may not yet have propagated to all DNS servers. You should also expect this event at system startup on a DNS server (such as a domain controller) that points to itself for the primary DNS. You should validate the DNS client settings on this computer using IPCONFIG /ALL and NSLOOKUP.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName

Example Event

system:
  provider: Microsoft-Windows-SMBClient
  guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
  event_source_name: ''
  event_id: 30800
  version: 0
  level: 2
  task: 0
  opcode: 0
  keywords: 288230376151711808
  time_created: '2022-04-07T16:53:50.061721+00:00'
  event_record_id: 19
  correlation: {}
  execution:
    process_id: 4
    thread_id: 592
  channel: Microsoft-Windows-SmbClient/Connectivity
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
event_data:
  Reason: 1
  Status: 3221226021
  ServerNameLength: 8
  ServerName: sigma.fr
message: ''

References

Event ID 30801 — %1.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

%1.

Error: %2

Server name: %4

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName

Event ID 30802 — %1.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

%1.

Error: %2

Server name: %4

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName

Event ID 30803 — Failed to establish a network connection.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Failed to establish a network connection.

Error: %2

Server name: %4
Server address: %6!S!
Connection type: %7

Guidance:
This indicates a problem with the underlying network or transport, such as with TCP/IP, and not with SMB. A firewall that blocks TCP port 445, or TCP port 5445 when using an iWARP RDMA adapter, can also cause this issue.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName
AddressLength
RemoteAddress
LocalAddress
InstanceNameLength
InstanceName
ConnectionType
PortSelectionOrigin
ConnectionIdSize
ConnectionId
ClientCertSha1HashSize
ClientCertSha1Hash

Event ID 30804 — A network connection was disconnected.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

A network connection was disconnected.

Server name: %4
Server address: %6!S!
Connection type: %7

Guidance:
This indicates that the client's connection to the server was disconnected.

Frequent, unexpected disconnects when using an RDMA over Converged Ethernet (RoCE) adapter may indicate a network misconfiguration. RoCE requires Priority Flow Control (PFC) to be configured for every host, switch and router on the RoCE network. Failure to properly configure PFC will cause packet loss, frequent disconnects and poor performance.

Fields

NameDescription
Reason
Status
InstanceNameLength
InstanceName
ServerNameLength
ServerName
AddressLength
Address
ConnectionType
InterfaceId

Event ID 30805 — The client lost its session to the server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The client lost its session to the server.

Error: %1

Server name: %5
Session ID: %2

Guidance:
If the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30806 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network.

Fields

NameDescription
Status
SessionId
TreeId
ServerNameLength
ServerName
AddressLength
Address

Event ID 30806 — The client re-established its session to the server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The client re-established its session to the server.

Server name: %5
Server address: %7!S!
Session ID: %2

Guidance:
You should expect this event if there was a previous event 30805, but the client successfully resumed the cached connection before the timeout expired.

Fields

NameDescription
Status
SessionId
TreeId
ServerNameLength
ServerName
AddressLength
Address
SigningUsed
EncryptionUsed

Event ID 30807 — The connection to the share was lost.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The connection to the share was lost.

Error: %1

Share name: %5
Session ID: %2
Tree ID: %3

Guidance:
If the server is a Windows Failover Cluster file server, then this message occurs when the file share moves between cluster nodes. There should also be an anti-event 30808 indicating the session to the server was re-established. If the server is not a failover cluster, it is likely that the server was previously online, but it is now inaccessible over the network.

Fields

NameDescription
Status
SessionId
TreeId
ServerNameLength
ServerName
AddressLength
Address

Event ID 30808 — The connection to the share was re-established.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The connection to the share was re-established.

Share name: %5
Server address: %7!S!
Session ID: %2
Tree ID: %3

Guidance:
You should expect this event if there was a previous event 30807, but the client successfully resumed the cached connection before the timeout expired.

Fields

NameDescription
Status
SessionId
TreeId
ServerNameLength
ServerName
AddressLength
Address
SigningUsed
EncryptionUsed

Event ID 30809 — A request timed out because there was no response from the server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

A request timed out because there was no response from the server.

Server name: %6
Session ID:%3
Tree ID:%4
Message ID:%2
Command: %1
Instance Name: %9
RetryCount: %10
ElapsedTime(ms): %11

Guidance:
The server is responding over TCP but not over SMB. Ensure the Server service is running and responsive, and the disks do not have high per-IO latency, which makes the disks appear unresponsive to SMB. Also, ensure the server is responsive overall and not paused; for instance, make sure you can log on to it.

Fields

NameDescription
Smb2Command
MessageId
SessionId
TreeId
ServerNameLength
ServerName
Status
InstanceNameLength
InstanceName
RetryCount
ElapsedTimeInMs

Event ID 30810 — Added a TCP/IP transport interface.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity
Level
4
Samples
1

Message

Added a TCP/IP transport interface.

Name: %2
InterfaceIndex: %3

Guidance:
A TCP/IP binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TCP/IP. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required.

Fields

NameDescription
NameLength
Name
IfIndex

Example Event

system:
  provider: Microsoft-Windows-SMBClient
  guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
  event_source_name: ''
  event_id: 30810
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 288230376151711808
  time_created: '2023-11-06T06:25:42.647569+00:00'
  event_record_id: 86
  correlation: {}
  execution:
    process_id: 4
    thread_id: 428
  channel: Microsoft-Windows-SmbClient/Connectivity
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  NameLength: 9
  Name: Ethernet1
  IfIndex: 4
message: ''

References

Event ID 30811 — Deleted a TCP/IP transport interface.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity
Level
4
Samples
1

Message

Deleted a TCP/IP transport interface.

Name: %2
InterfaceIndex: %3

Guidance:
A TCP/IP binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required.

Fields

NameDescription
NameLength
Name
IfIndex

Example Event

system:
  provider: Microsoft-Windows-SMBClient
  guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
  event_source_name: ''
  event_id: 30811
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 288230376151711808
  time_created: '2023-11-06T06:25:42.599960+00:00'
  event_record_id: 84
  correlation: {}
  execution:
    process_id: 4
    thread_id: 428
  channel: Microsoft-Windows-SmbClient/Connectivity
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  NameLength: 9
  Name: Ethernet1
  IfIndex: 4
message: ''

References

Event ID 30812 — Added a TDI transport interface.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity
Level
4
Samples
1

Message

Added a TDI transport interface.

Name: %2

Guidance:
A TDI (NetBIOS) binding was added to the specified network adapter for the SMB client. The SMB client can now send and receive SMB traffic on this network adapter using TDI. You should expect this event when a computer restarts or when a previously disabled network adaptor is re-enabled. No user action is required.

Fields

NameDescription
ServerNameLength
ServerName

Example Event

system:
  provider: Microsoft-Windows-SMBClient
  guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
  event_source_name: ''
  event_id: 30812
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 288230376151711808
  time_created: '2023-11-06T06:25:42.665527+00:00'
  event_record_id: 88
  correlation: {}
  execution:
    process_id: 4
    thread_id: 224
  channel: Microsoft-Windows-SmbClient/Connectivity
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  ServerNameLength: 58
  ServerName: \Device\NetBT_Tcpip_{3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}
message: ''

References

Event ID 30813 — Deleted a TDI transport interface.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity
Level
4
Samples
1

Message

Deleted a TDI transport interface.

Name: %2

Guidance:
A TDI (NetBIOS) binding was removed from the specified network adapter for the SMB client. You should expect this event when a computer shuts down or when a previously enabled network adaptor is disabled. No user action is required.

Fields

NameDescription
ServerNameLength
ServerName

Example Event

system:
  provider: Microsoft-Windows-SMBClient
  guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
  event_source_name: ''
  event_id: 30813
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 288230376151711808
  time_created: '2023-11-06T06:25:42.600171+00:00'
  event_record_id: 85
  correlation: {}
  execution:
    process_id: 4
    thread_id: 224
  channel: Microsoft-Windows-SmbClient/Connectivity
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  ServerNameLength: 58
  ServerName: \Device\NetBT_Tcpip_{3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}
message: ''

References

Event ID 30814 — Witness registration has completed.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Witness registration has completed.

Status: %1

Cluster share name: %4
Cluster share type: %2
File server cluster address: %6!S!

Guidance:
The client successfully registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required.

Fields

NameDescription
Status
ShareType
NameLength
Name
RemoteAddressLength
RemoteAddress

Event ID 30815 — Witness deregistration has completed.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Witness deregistration has completed.

Status: %1

Cluster share name: %4
Cluster share type: %2

Guidance:
The client successfully de-registered with the SMB Witness through RPC using TCP (port 135, then an endpoint port above 1023). No action is required.

Fields

NameDescription
Status
ShareType
NameLength
Name
RemoteAddressLength
RemoteAddress

Event ID 30816 — The server failed the negotiate request.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The server failed the negotiate request.

Error: %2

Server name: %4

Guidance:
The server does not support any dialect that the client is trying to negotiate, such as the client has SMB2/SMB3 disabled and the server has SMB1 disabled.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName

Event ID 30817 — Close request failed.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Close request failed.

Error: %2

Path: %4%6

Guidance:
A persistent handle (Continuous Availability) or a resilient handle failed to close.

Fields

NameDescription
Reason
Status
ShareNameLength
ShareName
ObjectNameLength
ObjectName

Event ID 30818 — RDMA interfaces are available but the client failed to connect to the server over RDMA transport.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

RDMA interfaces are available but the client failed to connect to the server over RDMA transport.

Server name: %2

Guidance:
Both client and server have RDMA (SMB Direct) adaptors but there was a problem with the connection and the client had to fall back to using TCP/IP SMB (non-RDMA).

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30819 — The SMB client received a request to move to a different node on a file server cluster.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB client received a request to move to a different node on a file server cluster.

File server cluster name: %4
New file server cluster address: %6!S!

Guidance:
Continuous Availability (Transparent Failover) is in use and the client computer is going to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required.

Fields

NameDescription
Status
ShareType
NameLength
Name
RemoteAddressLength
RemoteAddress

Event ID 30820 — The SMB client successfully moved to a different node on a file server cluster.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB client successfully moved to a different node on a file server cluster.

File server cluster name: %4
 New file server cluster address: %6!S!

Guidance:
Continuous Availability (Transparent Failover) is in use and the client computer successfully moved to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). No user action is required.

Fields

NameDescription
Status
ShareType
NameLength
Name
RemoteAddressLength
RemoteAddress

Event ID 30821 — The SMB client failed to move to a different node on a file server cluster.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB client failed to move to a different node on a file server cluster.

Error: %1

File server cluster name: %4

Guidance:
Continuous Availability (Transparent Failover) is in use and the client computer failed to move to a different node after an SMB witness request over RPC using TCP (first contacting port 135, then contacting an endpoint port above 1023). The attempt to connect to the destination server failed, which is typically due to a network configuration issue. For example, this issue may occur if the destination node's IP address cannot be resolved, if the destination node is behind a firewall, or if there is no network route from the client to the node.

Fields

NameDescription
Status
ShareType
NameLength
Name
RemoteAddressLength
RemoteAddress

Event ID 30822 — Failed to establish an SMB multichannel network connection.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Failed to establish an SMB multichannel network connection.

Error: %2

Server name: %4
Server address: %6!S!
Client address: %7!S!
Instance name: %9
Connection type: %10

Guidance:
This indicates a problem with the underlying network or transport, such as with TCP/IP or QUIC/UDP, and not with SMB. A firewall that blocks TCP port 445 or UDP port 443 or TCP port 5445 when using an iWARP RDMA adapter can also cause this issue. Since the error occurred while trying to connect extra channels, it will not result in an application error. This event is for diagnostics only.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName
AddressLength
RemoteAddress
LocalAddress
InstanceNameLength
InstanceName
ConnectionType
PortSelectionOrigin

Event ID 30823 — The connection was terminated due to one or more IO request timeouts.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The connection was terminated due to one or more IO request timeouts.

Error: %2

Name: %4
Server address: %6!S!
Client address: %7!S!
Instance name: %9
Connection type: %10

Guidance:
This indicates a problem with the underlying network or the storage stack on the remote server. IO operations were not completed within the allotted time. The application may not see this failure because IOs are usually retried on a different connection. This event is for diagnostics only.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName
AddressLength
RemoteAddress
LocalAddress
InstanceNameLength
InstanceName
ConnectionType

Event ID 30824 — The connection was forcibly disconnected.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The connection was forcibly disconnected. 

Error: %2

Name: %4

Server address: %6!S!
Client address: %7!S!
Instance name: %9
Connection type: %10

Guidance:
This connection is disconnected to force existing requests to fail back as soon as possible. This is a fast-fail mechanism to allow upper layers to apply their recovery policies as soon as possible. This event is for diagnostics only.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName
AddressLength
RemoteAddress
LocalAddress
InstanceNameLength
InstanceName
ConnectionType

Event ID 30825 — The disconnect state on connection was cleared Name: %3 Instance name: %5 Guidance: Any persistent disconnect state on this connection is cleared.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The disconnect state on connection was cleared 

Name: %3
Instance name: %5

Guidance:
Any persistent disconnect state on this connection is cleared. Any new IO will be sent to the server as usual. This event is for diagnostics only.

Fields

NameDescription
Reason
ServerNameLength
ServerName
InstanceNameLength
InstanceName

Event ID 30826 — The SMB negotiate response processing failed on the client to determine the selected encryption cipher for the client and server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB negotiate response processing failed on the client to determine the selected encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Client encryption cipher suite order (most to least preferred): %2
Server replied back with its selected encryption cipher ID: %4

Fields

NameDescription
ClientCipherSuiteOrderLength
ClientCipherSuiteOrder
ServerChosenEncryptionCipherLength
ServerChosenEncryptionCipher

Event ID 30827 — Could not find a certificate mapping that matches the server name.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Could not find a certificate mapping that matches the server name. 

Connection type: %1
Server name: %3.

Fields

NameDescription
ConnectionType
ServerNameLength
ServerName

Event ID 30828 — The client established its session to the server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The client established its session to the server.

Server name: %4
Server address: %6!S!
Client address: %8!S!
Session ID: %2

Fields

NameDescription
Status
SessionId
ServerNameLength
ServerName
RemoteAddressLength
RemoteAddress
LocalAddressLength
LocalAddress

Event ID 30829 — The client failed to establish its session to the server.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The client failed to establish its session to the server.

Error: %1

Server name: %4
Server address: %6!S!
Client address: %8!S!
Session ID: %2

Fields

NameDescription
Status
SessionId
ServerNameLength
ServerName
RemoteAddressLength
RemoteAddress
LocalAddressLength
LocalAddress

Event ID 30830 — The SMB redirector selected the connection initiated with the following parameters: Server name: %2 Server socket address: %5 Client socket address...

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB redirector selected the connection initiated with the following parameters:

Server name: %2
Server socket address: %5
Client socket address: %7
Client certificate thumbprint: %12
Transport: %3
Instance Name: %9

Fields

NameDescription
ServerNameLength
ServerName
ConnectionType
RemoteAddressLength
RemoteAddress
LocalAddressLength
LocalAddress
InstanceNameLength
InstanceName
PortSelectionOrigin
Status
ConnectionIdSize
ConnectionId
ClientCertSha1HashSize
ClientCertSha1Hash

Event ID 30831 — The SMB client was denied access to the SMB server during mutual authentication.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB client was denied access to the SMB server during mutual authentication.

Server name: %2
Server socket address: %5
Client socket address: %7
Client certificate thumbprint: %11
Transport: %3
Instance Name: %9

Event ID 30832 — The SMB connection was successfully established.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The SMB connection was successfully established.

Server name: %2
Server socket address: %5
Client socket address: %7
Connection ID: %12
Client certificate thumbprint: %14
Transport: %3
Instance Name: %9
Port Origin: %10

Guidance:

The event occurs when server authentication succeeds. The connection may later be closed if client authentication fails or if the client is denied access to the server.

Event ID 30833 — The initial connection to the share was established.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The initial connection to the share was established.

Share name: %5
Server address: %7!S!
Session ID: %2
Tree ID: %3
Transport type: %8
Signing used: %9
Encryption used: %10
Compression requested: %11
NTLM blocked: %12

Event ID 30834 — The client was unable to perform revocation checks on the server certificate chain.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The client was unable to perform revocation checks on the server certificate chain. The connection will proceed.

Verification Status: %1

Server name: %3
Server socket address: %6
Client socket address: %8
Connection ID: %13
Client certificate thumbprint: %15
Transport: %4
Instance Name: %10
Port Origin: %11

Event ID 30835 — Server authentication failed.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

Server authentication failed.

Error: %1

Server name: %3
Server socket address: %6
Client socket address: %8
Connection ID: %13
Client certificate thumbprint: %15
Transport: %4
Instance Name: %10
Port Origin: %11

Event ID 30837 — The requested transport is disabled.

Provider
Microsoft-Windows-SMBClient
Channel
Connectivity

Message

The requested transport is disabled.

Server name: %2
Server socket address: %5
Transport: %3

Event ID 30900 — The handle was created without persistence.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The handle was created without persistence.

File ID: %2:%3
CreateGUID: %4
Path: %10%12

Guidance:
The server supports Continuous Availability (persistent handles) and the request to create the handle succeeded. However, the server did not grant persistence. You should verify that the Resume Key Filter is running on the server and is attached to the target volume.

Fields

NameDescription
Object
PersistentFID
VolatileFID
CreateGUID
OldState
NewState
Status
Reason
ShareNameLength
ShareName
ObjectNameLength
ObjectName
PreviousStatus
PreviousReason

Event ID 30904 — The server does not support multichannel.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The server does not support multichannel.

Server name: %2

Guidance:
The client attempted to use SMB Multichannel, but an administrator has disabled multichannel support on the server. This may also be a non-Microsoft file server that does not support multichannel or has multichannel disabled. You can enable SMB Multichannel on the server using this Windows PowerShell cmdlet: Set-SmbServerConfiguration -EnableMultiChannel:$true. This event does not apply to the multichannel settings of SMB client, which are controlled by the Set-SmbClientConfiguration Windows PowerShell cmdlet. Enabling or disabling client multichannel support does not affect server multichannel support.

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30905 — The client cannot connect to the server due to a multichannel constraint registry setting.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The client cannot connect to the server due to a multichannel constraint registry setting.

Server name: %2

Guidance:
The client attempted to use SMB Multichannel, but an administrator has configured multichannel support to prevent multichannel on the client. You can configure SMB Multichannel on the client using the Windows PowerShell cmdlets: New-SmbMultichannelConstraint and Remove-SmbMultichannelConstraint.

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30906 — A request on persistent/resilient handle failed because the handle was invalid or it exceeded the timeout.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

A request on persistent/resilient handle failed because the handle was invalid or it exceeded the timeout.

Status: %7

Type: %1
Path: %4%6
Restart count: %2

Guidance:
After retrying a request on a Continuously Available (Persistent) handle or a Resilient handle, the client was unable to reconnect the handle. This event is the result of a handle recovery failure. Review other events for more details.

Fields

NameDescription
IrpCode
RestartCount
ShareNameLength
ShareName
ObjectNameLength
ObjectName
Status
Reason
HistoryCount

Event ID 30907 — The SMB Multichannel registry value is not configured with default settings.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB Multichannel registry value is not configured with default settings.

Default Registry Value:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"DisableMultiChannel"=dword:0
Configured Registry Value:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"DisableMultiChannel"=dword:%2

Guidance:
You can configure SMB Multichannel on the client using the Windows PowerShell cmdlet Set-SmbClientConfiguration. Disabling SMB client multichannel support is not a recommended configuration, as it can lead to degraded performance and decreased reliability if one channel or network path fails.

Fields

NameDescription
RegName
RegValue

Event ID 30908 — The SMB 3 and SMB 2 driver is not configured with the default start type.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB 3 and SMB 2 driver is not configured with the default start type.

Default Start Type: DEMAND_START
Configured Start Type: DISABLED

Guidance:
You should expect this event when disabling SMB2/SMB3 for the client using SC.EXE or editing the Windows registry. Microsoft does not recommend disabling SMB2/SMB3. Disabling SMB2/SMB3 prevents use of features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. SMB provides alternative troubleshooting workarounds to disabling SMB2/SMB3 in most cases.

Fields

NameDescription
RegName
RegValue

Event ID 30909 — The client supports SMB Direct (RDMA) and SMB Signing is in use.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The client supports SMB Direct (RDMA) and SMB Signing is in use.

Share name: %2

Guidance:
For optimal SMB Direct performance, you can disable SMB Signing. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control.

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30910 — The client supports SMB Direct (RDMA) and SMB Encryption is in use.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The client supports SMB Direct (RDMA) and SMB Encryption is in use.

Share name: %2

Guidance:
For optimal SMB Direct performance, you can disable SMB Encryption on the server for shares accessed by this client. This configuration is less secure and you should only consider this configuration on trustworthy private networks with strict access control.

Fields

NameDescription
ServerNameLength
ServerName

Event ID 30911 — The Cipher Suite Order group policy setting is invalid.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The Cipher Suite Order group policy setting is invalid.

Guidance:

This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Workstation\Cipher Suite Order" group policy setting. The client will use the default cipher suite order "%1" until this error is resolved.

Fields

NameDescription
CipherSuiteOrder

Event ID 30912 — The RequireSecureNegotiate setting has been removed.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The RequireSecureNegotiate setting has been removed.

Registry Key: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters
Registry Value: RequireSecureNegotiate

Guidance:

You should expect this event when an administrator configures the RequireSecureNegotiate setting. Secure negotiate prevents man-in-the-middle attacks against SMB connection establishment. Previous versions of Windows allowed secure negotiate to be disabled. Disabling secure negotiate is no longer allowed. The client removed the setting from the registry. No user action is required.

Event ID 30913 — Server %2 share %4 has requested client to use isolated connections to connection to the share.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Server %2 share %4 has requested client to use isolated connections to connection to the share. Asymmetric flag %5. Isolated transport flag %6. NetRoot already use isolated connections %7.

Fields

NameDescription
ServerNameLength
ServerName
ShareNameLength
ShareName
AsymmetricFlag
IsolatedTransportFlag
IsIsolatedTransportServerEntry

Event ID 30914 — RDMA rundown is active.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources.

Fields

NameDescription
ActiveRdmaResourceCount

Event ID 30915 — RDMA rundown is complete.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1.

Fields

NameDescription
NoOp

Event ID 30916 — Reactivation of RDMA support has commenced.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Reactivation of RDMA support has commenced.

Event ID 30917 — RDMA is no longer disabled.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1.

Fields

NameDescription
NoOp

Event ID 30918 — SMBDirect load attempt complete.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

SMBDirect load attempt complete.

Success: %1
Status code: %2
Service path: %4

Fields

NameDescription
IsSuccess
LoadStatus
ServicePathLength
ServicePath
DeviceNameLength
DeviceName

Event ID 30950 — Component capabilities: %1 Internal patch number: %2.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

Component capabilities: %1
Internal patch number: %2

Fields

NameDescription
ComponentCapabilities
PatchNumber

Event ID 30951 — The alternative port %1 is not a valid port within the range 0 to 65535 for mapping name %3:%5.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The alternative port %1 is not a valid port within the range 0 to 65535 for mapping name %3:%5.

Fields

NameDescription
PortNumber
ServerNameLength
ServerName
TransportNameLength
TransportName

Event ID 30952 — The SMB redirector did not select the connection initiated with the following parameters: Server name: %2 IP Address: %5 Transport: %3 Instance Nam...

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

The SMB redirector did not select the connection initiated with the following parameters:

Server name: %2
IP Address: %5
Transport: %3
Instance Name:%7
Port Origin: %8

The failure status associated with this decision: %9

Fields

NameDescription
ServerNameLength
ServerName
ConnectionType
RemoteAddressLength
RemoteAddress
InstanceNameLength
InstanceName
PortSelectionOrigin
Status

Event ID 30953 — SMB Dialect Change %1 was changed from %2 to %3.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

SMB Dialect Change

%1 was changed from %2 to %3.

Fields

NameDescription
SmbDialect
OldDialect
NewDialect

Event ID 30954 — It took %2 secs to execute %1.

Provider
Microsoft-Windows-SMBClient
Channel
HelperClassDiagnostic

Message

It took %2 secs to execute %1.

Fields

NameDescription
FunctionName
CallDuration
ThresholdDuration

Event ID 30955 — It took %2 secs to execute %1 which is longer than threshold of %3 secs.

Provider
Microsoft-Windows-SMBClient
Channel
Operational

Message

It took %2 secs to execute %1 which is longer than threshold of %3 secs. This warning is because %1 is taking longer than expected.

Fields

NameDescription
FunctionName
CallDuration
ThresholdDuration

Event ID 31000 — %1.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

%1.

Error: %2

Security status: %3
User name: %10
Logon ID: %4
Serrver name: %6

Fields

NameDescription
Reason
Status
SecurityStatus
LogonId
ServerNameLength
ServerName
PrincipalNameLength
PrincipalName
UserNameLength
UserName

Event ID 31001 — %1.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

%1.

Error: %2

Security status: %3
User name: %10
Logon ID: %4
Server name: %6
Principal name: %8

Fields

NameDescription
Reason
Status
SecurityStatus
LogonId
ServerNameLength
ServerName
PrincipalNameLength
PrincipalName
UserNameLength
UserName

Event ID 31002 — The outbound authentication failed using a network token.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The outbound authentication failed using a network token.

Error: %2

Server name: %4

Guidance:
This typically indicates that delegation must be configured for a Kerberos double-hop scenario. If delegation is configured, confirm that the services are configured correctly on the middle-tier server.

Fields

NameDescription
Reason
Status
ServerNameLength
ServerName

Event ID 31003 — The LmCompatibilityLevel value is different from the default.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The LmCompatibilityLevel value is different from the default.

Configured LM Compatibility Level: %2
Default LM Compatibility Level: 3

Guidance:
LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers.

Value (Setting) - Description

0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication.

5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication.

Incompatibly configured  LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings.

Fields

NameDescription
RegName
RegValue

Event ID 31010 — The SMB client failed to connect to the share.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The SMB client failed to connect to the share.

Error: %2

Path: %4%6

Fields

NameDescription
Reason
Status
ShareNameLength
ShareName
ObjectNameLength
ObjectName

Event ID 31012 — The negotiate validation failed.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The negotiate validation failed.

From negotiate response:
Dialect: %1
SecurityMode: %2
Capabilities: %3
ServerGuid: %4

From FSCTL_VALIDATE_NEGOTIATE_INFO response:
Dialect: %5
SecurityMode: %6
Capabilities: %7
ServerGuid: %8

Guidance:
The client successfully negotiated SMB dialect, security mode, capabilities and server GUID with the server, but the validation of these values then failed after connecting to a share. This may be due to a "adversary-in-the-middle" compromise attempt.

Fields

NameDescription
Dialect
SecurityMode
Capabilities
Guid
Dialect2
SecurityMode2
Capabilities2
Guid2

Event ID 31013 — The signing validation failed.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The signing validation failed.

Error:%7

Server name: %6
Session ID:%3
Tree ID:%4
Message ID:%2
Command: %1

Guidance:
This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt.

PacketFragment:%9

Fields

NameDescription
Smb2Command
MessageId
SessionId
TreeId
ServerNameLength
ServerName
Status
MessageSize
FragmentOffset
FragmentSize
FragmentData
RemoteAddressLength
RemoteAddress
LocalAddressLength
LocalAddress

Event ID 31014 — The client received an unencrypted message when encryption was expected.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The client received an unencrypted message when encryption was expected.

Server name: %6
Session ID:%3
Tree ID:%4
Message ID:%2
Command: %1
Instance Name: %9

Guidance:
This error indicates that SMB messages are being modified in transit across the network from the server to the client. This may be due to the session ending on the server, a problem with the network, a problem with a third-party SMB server, or a "adversary-in-the-middle" compromise attempt.

Fields

NameDescription
Smb2Command
MessageId
SessionId
TreeId
ServerNameLength
ServerName
Status
InstanceNameLength
InstanceName
RetryCount
ElapsedTimeInMs
RemoteAddressLength
RemoteAddress
LocalAddressLength
LocalAddress

Event ID 31015 — Failed to decrypt an encrypted SMB message.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Failed to decrypt an encrypted SMB message.

Error:%7

Server name: %6
Session ID:%3
Instance Name: %9

Guidance:
The client received an encrypted SMB message but cannot decrypt the data. This typically means that the communication came from a previous session that no longer exists. The encryption header may also have been damaged or tampered with on the network between the client and server.

Fields

NameDescription
Smb2Command
MessageId
SessionId
TreeId
ServerNameLength
ServerName
Status
InstanceNameLength
InstanceName
RetryCount
ElapsedTimeInMs

Event ID 31016 — The SMB Signing registry value is not configured with default settings.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

The SMB Signing registry value is not configured with default settings.

Default Registry Value:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"EnableSecuritySignature"=dword:1
Configured Registry Value:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"EnableSecuritySignature"=dword:0

Guidance:
Even though you can disable, enable, or require SMB Signing, the negotiation rules changed starting with SMB2 and not all combinations operate like SMB1.

The effective behavior for SMB2/SMB3 is:
Client Required and Server Required = Signed
Client Not Required and Server Required = Signed
Server Required and Client Not Required = Signed
Server Not Required and Client Not Required = Not Signed

When requiring SMB Encryption, SMB Signing is not used, regardless of settings. SMB Encryption implicitly provides the same integrity guarantees as SMB Signing.

Fields

NameDescription
RegName
RegValue

Event ID 31017 — Rejected an insecure guest logon.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Rejected an insecure guest logon.

User name: %2
Server name: %4

Guidance:
This event indicates that the server attempted to log the user on as an unauthenticated guest and was denied by the client. Guest logons do not support standard security features such as signing and encryption. As a result, guest logons are vulnerable to man-in-the-middle attacks that can expose sensitive data on the network. Windows disables insecure guest logons by default. Microsoft does not recommend enabling insecure guest logons.

Fields

NameDescription
UserNameLength
UserName
ServerNameLength
ServerName

Event ID 31018 — Guidance: An administrator has enabled AllowInsecureGuestAuth.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Guidance: An administrator has enabled AllowInsecureGuestAuth. Clients using insecure guest logons are more vulnerable to attackers-in-the-middle, phishing, and malware.

Fields

NameDescription
RegName
RegValue

Event ID 31019 — Mutual authentication was unexpectedly lost after re-authenticating to %6 User %8 LogonID %4 Status %2 AuthProtocol Old %9 New %10 MutualAuthState ...

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Mutual authentication was unexpectedly lost after re-authenticating to %6
User %8
LogonID %4
Status %2
 AuthProtocol Old %9  New %10
MutualAuthState Old %11 New %12
Clustered %13

Fields

NameDescription
Reason
Status
SecurityStatus
LogonId
ServerNameLength
ServerName
UserNameLength
UserName
OldAuthProtocolId
NewAuthProtocolId
OldMutualAuthState
NewMutualAuthState
ClusteredServer

Event ID 31020 — Session key for connection is weaker than required.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Session key for connection is weaker than required. Connection will be closed as a result.

Server: %2
User: %6
Session key length: %3
Required Session key length: %4

Guidance:
To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanWorkstation\Parameters]
"MinimumSessionKeyLength"

Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM.

Fields

NameDescription
ServerNameLength
ServerName
SessionKeyLength
RequiredSessionKeyLength
SessionId
UserName
AuthProtocol

Event ID 31021 — SMB DDP security changed from %1 to %2.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

SMB DDP security changed from %1 to %2.

Fields

NameDescription
OldValue
NewValue

Event ID 31022 — Allowed an insecure guest logon.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

Allowed an insecure guest logon.

User name: %2
Server name: %4

Guidance:
This event indicates that the server attempted to log the user on as an unauthenticated guest and was allowed by the client.

Fields

NameDescription
UserNameLength
UserName
ServerNameLength
ServerName

Event ID 31023 — NTLM is prohibited for authentication on the server Server name: %2 NTLM was disabled by user or by administrator using policies.

Provider
Microsoft-Windows-SMBClient
Channel
Security

Message

NTLM is prohibited for authentication on the server 

Server name: %2

 NTLM was disabled by user or by administrator using policies. For more information: https://go.microsoft.com/fwlink/?linkid=2267451.

Fields

NameDescription
ServerNameLength
ServerName

Event ID 31997 — The SMB client was logged on as Guest account.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

The SMB client was logged on as Guest account.

Server name: %2

Fields

NameDescription
ServerNameLength
ServerName

Event ID 31998 — The SMB client observed that the server doesn't support signing.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

The SMB client observed that the server doesn't support signing.

Server name: %2
Client requires signing: %3

Fields

NameDescription
ServerNameLength
ServerName
ClientRequireSigning

Event ID 31999 — The SMB client observed that the server doesn't support encryption.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

The SMB client observed that the server doesn't support encryption.

Server name: %2
Client requires encyption: %3

Fields

NameDescription
ServerNameLength
ServerName
ClientRequireEncryption

Event ID 32000 — SMB1 negotiate response received from remote device when SMB1 cannot be negotiated by the local computer.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

SMB1 negotiate response received from remote device when SMB1 cannot be negotiated by the local computer. 

Dialect: %1

 Server name: %3

 Guidance:
The client has SMB1 disabled or uninstalled. For more information: https://go.microsoft.com/fwlink/?linkid=852747.

Fields

NameDescription
Reason
Dialect
ServerNameLength
ServerName

Event ID 32002 — The local computer received an SMB1 negotiate response.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

The local computer received an SMB1 negotiate response.

Dialect: %2

 SecurityMode %3

 Server name: %5

 Guidance:
 SMB1 is deprecated and should not be installed nor enabled. For more information, see https://go.microsoft.com/fwlink/?linkid=852747.

Fields

NameDescription
Reason
Dialect
SecurityMode
ServerNameLength
ServerName

Event ID 32003 — The local computer didn't received an SMB1 negotiate response in the last %1 days.

Provider
Microsoft-Windows-SMBClient
Channel
Audit

Message

The local computer didn't received an SMB1 negotiate response in the last %1 days.n
Guidance:

This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Client service was automatically uninstalled. The computer must be restarted for SMB1 removal to take effect.

Fields

NameDescription
Days

Event ID 32004 — SMB2 rxcontext performance work started

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work started

Fields

NameDescription
RxContext
FileNameLength
FileName
MajorFunction
MinorFunction

Event ID 32005 — SMB2 exchange performance work started

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work started

Fields

NameDescription
Exchange
MajorFunction
MinorFunction

Event ID 32006 — SMB2 buffer context performance work started

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work started

Fields

NameDescription
BufferContext
MajorFunction
MinorFunction
Smb2Command

Event ID 32007 — SMB2 performance work transition

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 performance work transition

Fields

NameDescription
BlockType

Event ID 32008 — SMB2 rxcontext performance work read summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work read summary

Fields

NameDescription
RxContext
InstanceId
FileObject
IRP
ByteCount
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
ReadProcessing
HitCountReadProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry
AttemptTurboIORead
HitCountAttemptTurboIORead
AttemptTurboIOInit
HitCountAttemptTurboIOInit
TurboIORxCompletion
HitCountTurboIORxCompletion

Event ID 32009 — SMB2 rxcontext performance work write summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work write summary

Fields

NameDescription
RxContext
InstanceId
FileObject
IRP
ByteCount
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
WriteProcessing
HitCountWriteProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry
AttemptTurboIOWrite
HitCountAttemptTurboIOWrite
AttemptTurboIOInit
HitCountAttemptTurboIOInit
TurboIORxCompletion
HitCountTurboIORxCompletion

Event ID 32010 — SMB2 rxcontext performance work create summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work create summary

Fields

NameDescription
RxContext
InstanceId
IRP
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
CreateProcessing
HitCountCreateProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry

Event ID 32011 — SMB2 rxcontext performance work close summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work close summary

Fields

NameDescription
RxContext
InstanceId
IRP
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
CloseProcessing
HitCountCloseProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry

Event ID 32012 — SMB2 rxcontext performance work query directory summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work query directory summary

Fields

NameDescription
RxContext
InstanceId
IRP
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
QueryDirectoryProcessing
HitCountQueryDirectoryProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry

Event ID 32013 — SMB2 rxcontext performance work fsctl summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 rxcontext performance work fsctl summary

Fields

NameDescription
RxContext
InstanceId
IRP
TotalDuration
Construction
HitCountConstruction
DispatchProcessing
HitCountDispatchProcessing
FsctlProcessing
HitCountFsctlProcessing
CallMiniRdr_MRXSMB
HitCountCallMiniRdr_MRXSMB
LowIoCompletionRoutine
HitCountLowIoCompletionRoutine
CompleteIRP
HitCountCompleteIRP
PostIOCompletion
HitCountPostIOCompletion
PostIORetry
HitCountPostIORetry

Event ID 32028 — SMB2 exchange performance work read summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work read summary

Fields

NameDescription
Exchange
RxContext
ByteCount
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
ReadStart
HitCountReadStart
ReadBuildAndSendChunks
HitCountReadBuildAndSendChunks
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount
TurboIOStart
HitCountTurboIOStart
TurboIOComplete
HitCountTurboIOComplete

Event ID 32029 — SMB2 exchange performance work write summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work write summary

Fields

NameDescription
Exchange
RxContext
ByteCount
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
WriteStart
HitCountWriteStart
WriteBuildAndSendChunks
HitCountWriteBuildAndSendChunks
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount
TurboIOStart
HitCountTurboIOStart
TurboIOComplete
HitCountTurboIOComplete

Event ID 32030 — SMB2 exchange performance work create summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work create summary

Fields

NameDescription
Exchange
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
CreateStart
HitCountCreateStart
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount

Event ID 32031 — SMB2 exchange performance work close summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work close summary

Fields

NameDescription
Exchange
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
CloseStart
HitCountCloseStart
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount

Event ID 32032 — SMB2 exchange performance work query directory summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work query directory summary

Fields

NameDescription
Exchange
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
QueryDirectoryStart
HitCountQueryDirectoryStart
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount

Event ID 32033 — SMB2 exchange performance work fsctl summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 exchange performance work fsctl summary

Fields

NameDescription
Exchange
InstanceId
TotalDuration
RestartCount
ResolvingConnectionObjects
HitCountResolvingConnectionObjects
CommandProcessing
HitCountCommandProcessing
FsctlStart
HitCountFsctlStart
CommandFinalizationCallback
HitCountCommandFinalizationCallback
Finalize
HitCountFinalize
PostFinalizeWorker
HitCountPostFinalizeWorker
FinalizeWorkerHitCount
HitCountFinalizeWorkerHitCount

Event ID 32048 — SMB2 buffer context performance work read summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work read summary

Fields

NameDescription
BufferContext
Exchange
ByteCount
InstanceId
TotalDuration
Initialized
HitCountInitialized
WriteRDMABufferRegistration
HitCountWriteRDMABufferRegistration
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
ReadReceive
HitCountReadReceive

Event ID 32049 — SMB2 buffer context performance work write summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work write summary

Fields

NameDescription
BufferContext
Exchange
ByteCount
InstanceId
TotalDuration
Initialized
HitCountInitialized
ReadRDMABufferRegistration
HitCountReadRDMABufferRegistration
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
WriteReceive
HitCountWriteReceive

Event ID 32050 — SMB2 buffer context performance work create summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work create summary

Fields

NameDescription
BufferContext
InstanceId
TotalDuration
Initialized
HitCountInitialized
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
CreateReceive
HitCountCreateReceive

Event ID 32051 — SMB2 buffer context performance work close summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work close summary

Fields

NameDescription
BufferContext
InstanceId
TotalDuration
Initialized
HitCountInitialized
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
CloseReceive
HitCountCloseReceive

Event ID 32052 — SMB2 buffer context performance work query directory summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work query directory summary

Fields

NameDescription
BufferContext
InstanceId
TotalDuration
Initialized
HitCountInitialized
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
QueryDirectoryReceive
HitCountQueryDirectoryReceive

Event ID 32053 — SMB2 buffer context performance work fsctl summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 buffer context performance work fsctl summary

Fields

NameDescription
BufferContext
InstanceId
TotalDuration
Initialized
HitCountInitialized
RDMAGetDescriptors
HitCountRDMAGetDescriptors
AssociateMID
HitCountAssociateMID
Assembly
HitCountAssembly
BeginSmbSend
HitCountBeginSmbSend
BeginSmbSendAsyncPostWorkerCount
HitCountBeginSmbSendAsyncPostWorkerCount
SmbdPrepareSend
HitCountSmbdPrepareSend
ServerTimeTakenToReply
HitCountServerTimeTakenToReply
FsctlReceive
HitCountFsctlReceive

Event ID 32068 — SMB2 FCB capture summary

Provider
Microsoft-Windows-SMBClient
Channel
Analytic

Message

SMB2 FCB capture summary

Fields

NameDescription
InstanceId
PrefixLength
Prefix
ServerShareLength
ServerShare

Event ID 40000 — Packet (%4 bytes).

Provider
Microsoft-Windows-SMBClient
Channel
Diagnostic

Message

Packet (%4 bytes)

Fields

NameDescription
ConnectionType
PeerAddressLength
PeerAddress
PacketSize
PacketData