Microsoft-Windows-SMBClient
181 events across 9 channels
Event ID 101 — Create SrvCall Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 201 — Session Setup Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 301 — Tree Connect Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 401 — Create VNetRoot Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 501 — Create File Error: %1 Location: %2 Context: %3.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Location | — |
Context | — |
Event ID 2000 — Packet Fragment (%2 bytes).
Message
Fields
| Name | Description |
|---|---|
ReassembledEventID | — |
FragmentSize | — |
FragmentData | — |
Event ID 20001 — Transitioned to State: %1 Context: %2.
Message
Fields
| Name | Description |
|---|---|
CurrentOrNextState | — |
Context | — |
Event ID 30101 — SMB ISC request: SessionEntry {SessionEntry} ServerName {ServerName}.
Message
Fields
| Name | Description |
|---|---|
SessionEntry | — |
ServerName | — |
Event ID 30102 — SMB ISC completion: SessionEntry {SessionEntry} ServerName {ServerName} Status {Status}.
Message
Fields
| Name | Description |
|---|---|
SessionEntry | — |
ServerName | — |
Status | — |
Event ID 30103 — SMB exchange suspended: RxContext %1 Exchange %2 ListHead %3.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Exchange | — |
ListHead | — |
Event ID 30104 — SMB exchange resumed: RxContext %1 Exchange %2 ExchangeState %3 ExchangeStatus %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Exchange | — |
ExchangeState | — |
ExchangeStatus | — |
Event ID 30105 — SMB buffer context suspended: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7.
Message
Fields
| Name | Description |
|---|---|
BufferCtxt | — |
Exchange | — |
MidCharge | — |
Window | — |
CurrentWindowLimit | — |
ThrottlingWindowLimit | — |
CurrentWindowSize | — |
Event ID 30106 — SMB buffer context resumed: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize %7.
Message
Fields
| Name | Description |
|---|---|
BufferCtxt | — |
Exchange | — |
MidCharge | — |
Window | — |
CurrentWindowLimit | — |
ThrottlingWindowLimit | — |
CurrentWindowSize | — |
Event ID 30107 — SMB exchange expired: Exchange {Exchange} Window {Window}.
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
Window | — |
Event ID 30108 — SMB Mid window blocked: Window %1 HungSession %2.
Message
Fields
| Name | Description |
|---|---|
Window | — |
HungSession | — |
Event ID 30109 — SMB rechunk multi-credit request: BufferCtxt %1 Exchange %2 MidCharge %3 Window %4 CurrentWindowLimit %5 ThrottlingWindowLimit %6 CurrentWindowSize...
Message
Fields
| Name | Description |
|---|---|
BufferCtxt | — |
Exchange | — |
MidCharge | — |
Window | — |
CurrentWindowLimit | — |
ThrottlingWindowLimit | — |
CurrentWindowSize | — |
Event ID 30110 — SMB initialize Mid window: Server %2 Window %3.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
MidWindow | — |
Event ID 30111 — SMB Mid window state: Window %1 CurrentWindowSize %2 CurrentWindowLimit %3 ThrottlingWindowLimit %4 OldestPendingMid %5 NextAvailableMid %6 Credits...
Message
Fields
| Name | Description |
|---|---|
MidWindow | — |
CurrentWindowSize | — |
CurrentWindowLimit | — |
ThrottlingWindowLimit | — |
OldestPendingMid | — |
NextAvailableMid | — |
CreditsGranted | — |
Event ID 30112 — SMB teardown Mid window: Server %2 Window %3.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
MidWindow | — |
Event ID 30113 — SMB copy data completion: Status %1 VcEndpoint %2.
Message
Fields
| Name | Description |
|---|---|
Status | — |
VcEndpoint | — |
Event ID 30114 — SMB send completion: Status %1 VcEndpoint %2.
Message
Fields
| Name | Description |
|---|---|
Status | — |
VcEndpoint | — |
Event ID 30201 — WSK get address info request: ServerName {ServerName} Irp {Irp}.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Irp | — |
Event ID 30202 — WSK get address info completion: Irp {Irp} Status {Status}.
Message
Fields
| Name | Description |
|---|---|
Irp | — |
Status | — |
Event ID 30203 — WSK connect: SocketAddress %2 VcEndpoint %3 Socket %4.
Message
Fields
| Name | Description |
|---|---|
RemoteAddressLength | — |
RemoteAddress | — |
VcEndpoint | — |
Socket | — |
ConnectionType | — |
Event ID 30204 — WSK connect completion: VcEndpoint %1 Socket %2 Status %3.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
Status | — |
ConnectionType | — |
Event ID 30205 — WSK send: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
ConnectionType | — |
Event ID 30206 — WSK send completion: VcEndpoint %1 Socket %2 SendMdl %3 SendLength %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
Status | — |
ConnectionType | — |
Event ID 30207 — WSK receive: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
ConnectionType | — |
Event ID 30208 — WSK receive completion: VcEndpoint %1 Socket %2 ReceiveMdl %3 ReceiveLength %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
Status | — |
ConnectionType | — |
Event ID 30209 — Compression requested for file object %3: Status %4.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
Smb2Fobx | — |
Status | — |
Event ID 30210 — Decompression failed: VcEndpoint %1 Socket %2 ReceiveBuffer %3 ReceiveLength %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
Status | — |
ConnectionType | — |
Event ID 30211 — Compression failed: VcEndpoint %1 Socket %2 SendBuffer %3 SendLength %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
VcEndpoint | — |
Socket | — |
SendMdl | — |
SendLength | — |
Status | — |
ConnectionType | — |
Event ID 30401 — SMB session expired: SessionEntry %1 ServerName %3.
Message
Fields
| Name | Description |
|---|---|
SessionEntry | — |
ServerNameLength | — |
ServerName | — |
Event ID 30402 — SMB 3 part SPN reauth: SessionEntry %1 ServiceName %3.
Message
Fields
| Name | Description |
|---|---|
SessionEntry | — |
ServerNameLength | — |
ServerName | — |
Event ID 30403 — SMB reconnect durable open: Fcb %1 SrvOpen %2.
Message
Fields
| Name | Description |
|---|---|
Fcb | — |
SrvOpen | — |
Event ID 30404 — SMB defer open: Fcb %1 SrvOpen %2.
Message
Fields
| Name | Description |
|---|---|
Fcb | — |
SrvOpen | — |
Event ID 30405 — SMB undefer open: Fcb %1 SrvOpen %2.
Message
Fields
| Name | Description |
|---|---|
Fcb | — |
SrvOpen | — |
Event ID 30406 — SMB send[.
Message
Fields
| Name | Description |
|---|---|
Count | — |
Command | — |
MessageId | — |
SessionId | — |
TreeId | — |
MidCharge | — |
CreditRequested | — |
SendLength | — |
VcEndpoint | — |
Event ID 30407 — SMB receive: [.
Message
Fields
| Name | Description |
|---|---|
Command | — |
MessageId | — |
AsyncId | — |
SessionId | — |
TreeId | — |
CreditGranted | — |
Status | — |
VcEndpoint | — |
Event ID 30408 — SMB receive interim: [.
Message
Fields
| Name | Description |
|---|---|
Command | — |
MessageId | — |
AsyncId | — |
SessionId | — |
TreeId | — |
CreditGranted | — |
Status | — |
VcEndpoint | — |
Event ID 30409 — SMB receive async: [.
Message
Fields
| Name | Description |
|---|---|
Command | — |
MessageId | — |
AsyncId | — |
SessionId | — |
TreeId | — |
CreditGranted | — |
Status | — |
VcEndpoint | — |
Event ID 30410 — SMB registry key: %1 = %2.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 30501 — SMB update file info cache: RxContext %1 Fcb %2 FileName %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30502 — SMB fetch file info cache: RxContext %1 Fcb %2 FileName %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30503 — SMB invalidate file info cache: RxContext %1 Fcb %2 FileName %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30504 — SMB update file not found cache: RxContext %1 Fcb %2 FileName %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30505 — SMB fetch file not found cache: RxContext %1 Fcb %2 FileName %4 Result %5.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30506 — SMB invalidate file not found cache: RxContext %1 Fcb %2 FileName %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30507 — SMB populate dir cache: RxContext %1 Fcb %2 DirName %4.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30508 — SMB fetch dir cache: RxContext %1 Fcb %2 FileName %4 Status %5.
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
Fcb | — |
FileNameLength | — |
FileName | — |
Status | — |
Event ID 30600 — Session %1 to %6 transitioned from [%2] to [%3] with Status %4.
Message
Fields
| Name | Description |
|---|---|
Object | — |
OldState | — |
NewState | — |
Status | — |
NameLength | — |
ObjectName | — |
Event ID 30601 — Share connection %1 to %6 transitioned from [%2] to [%3] with Status %4.
Message
Fields
| Name | Description |
|---|---|
Object | — |
OldState | — |
NewState | — |
Status | — |
NameLength | — |
ObjectName | — |
Event ID 30603 — Open handle %1 to %10%12 transitioned from [%5] to [%6] with Status %7.
Message
Fields
| Name | Description |
|---|---|
Object | — |
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
OldState | — |
NewState | — |
Status | — |
Reason | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
PreviousStatus | — |
PreviousReason | — |
Event ID 30604 — The local computer didn't received an SMB1 negotiate response in the last 20 minutes.
Message
Fields
| Name | Description |
|---|---|
Days | — |
Event ID 30611 — Failed to reconnect a persistent handle.
Message
Fields
| Name | Description |
|---|---|
Object | — |
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
OldState | — |
NewState | — |
Status | — |
Reason | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
PreviousStatus | — |
PreviousReason | — |
Event ID 30612 — Failed to reconnect a resilient handle.
Message
Fields
| Name | Description |
|---|---|
Object | — |
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
OldState | — |
NewState | — |
Status | — |
Reason | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
PreviousStatus | — |
PreviousReason | — |
Event ID 30613 — Failed to open a persistent handle.
Message
Fields
| Name | Description |
|---|---|
Object | — |
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
OldState | — |
NewState | — |
Status | — |
Reason | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
PreviousStatus | — |
PreviousReason | — |
Event ID 30614 — Persistent handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 was orphaned.
Message
Fields
| Name | Description |
|---|---|
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
Object | — |
Event ID 30615 — Resilient handle {PersistentFID}:{VolatileFID} to {Object}0{Object}2 was orphaned.
Message
Fields
| Name | Description |
|---|---|
PersistentFID | — |
VolatileFID | — |
Object | — |
Event ID 30620 — Connection to server {ServerName} IP Address {RemoteAddress} was aborted.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
RemoteAddress | — |
Event ID 30621 — Session to server {ObjectName} was lost Status {Status}.
Message
Fields
| Name | Description |
|---|---|
ObjectName | — |
Status | — |
Event ID 30622 — Session to server {ObjectName} was re-established.
Message
Fields
| Name | Description |
|---|---|
ObjectName | — |
Event ID 30623 — Connection to share {ObjectName} was lost.
Message
Fields
| Name | Description |
|---|---|
ObjectName | — |
Status | — |
Event ID 30624 — Connection to share {ObjectName} was re-established.
Message
Fields
| Name | Description |
|---|---|
ObjectName | — |
Event ID 30625 — Handle {PersistentFID}:{VolatileFID} CreateGUID {CreateGUID} to {Object}0{Object}2 granted without persistence.
Message
Fields
| Name | Description |
|---|---|
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
Object | — |
Event ID 30626 — The SMB client received a request to move file server cluster {ServerName} to IP address {RemoteAddress}.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
RemoteAddress | — |
Event ID 30627 — The SMB client successfully moved file server cluster {ServerName} to IP address {RemoteAddress}.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
RemoteAddress | — |
Event ID 30628 — The SMB client failed to move file server cluster {ServerName}.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Status | — |
Event ID 30700 — The server {ServerName} does not support multichannel.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Event ID 30701 — An invalid FSCTL_QUERY_NETWORK_INTERFACE_INFO response was sent by the server %2.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30702 — The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Status | — |
Event ID 30703 — The client failed to connect to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Status | — |
Event ID 30704 — The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over TCP transport successfully.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Status | — |
Event ID 30705 — The client connected to the server %2 from the local IP address %4 to the remote IP address %6 over RDMA transport successfully.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
LocalAddressLength | — |
LocalAddress | — |
RemoteAddressLength | — |
RemoteAddress | — |
Status | — |
Event ID 30706 — The client can not connect to the server {ServerName} due to a multichannel constraint registry setting.
Message
Fields
| Name | Description |
|---|---|
ServerName | — |
Event ID 30800 — The server name cannot be resolved.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
Example Event
system:
provider: Microsoft-Windows-SMBClient
guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
event_source_name: ''
event_id: 30800
version: 0
level: 2
task: 0
opcode: 0
keywords: 288230376151711808
time_created: '2022-04-07T16:53:50.061721+00:00'
event_record_id: 19
correlation: {}
execution:
process_id: 4
thread_id: 592
channel: Microsoft-Windows-SmbClient/Connectivity
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-18
event_data:
Reason: 1
Status: 3221226021
ServerNameLength: 8
ServerName: sigma.fr
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30801 — %1.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
Event ID 30802 — %1.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
Event ID 30803 — Failed to establish a network connection.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
RemoteAddress | — |
LocalAddress | — |
InstanceNameLength | — |
InstanceName | — |
ConnectionType | — |
PortSelectionOrigin | — |
ConnectionIdSize | — |
ConnectionId | — |
ClientCertSha1HashSize | — |
ClientCertSha1Hash | — |
Event ID 30804 — A network connection was disconnected.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
InstanceNameLength | — |
InstanceName | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
Address | — |
ConnectionType | — |
InterfaceId | — |
Event ID 30805 — The client lost its session to the server.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
Address | — |
Event ID 30806 — The client re-established its session to the server.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
Address | — |
SigningUsed | — |
EncryptionUsed | — |
Event ID 30807 — The connection to the share was lost.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
Address | — |
Event ID 30808 — The connection to the share was re-established.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
Address | — |
SigningUsed | — |
EncryptionUsed | — |
Event ID 30809 — A request timed out because there was no response from the server.
Message
Fields
| Name | Description |
|---|---|
Smb2Command | — |
MessageId | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
Status | — |
InstanceNameLength | — |
InstanceName | — |
RetryCount | — |
ElapsedTimeInMs | — |
Event ID 30810 — Added a TCP/IP transport interface.
Message
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
IfIndex | — |
Example Event
system:
provider: Microsoft-Windows-SMBClient
guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
event_source_name: ''
event_id: 30810
version: 0
level: 4
task: 0
opcode: 0
keywords: 288230376151711808
time_created: '2023-11-06T06:25:42.647569+00:00'
event_record_id: 86
correlation: {}
execution:
process_id: 4
thread_id: 428
channel: Microsoft-Windows-SmbClient/Connectivity
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
NameLength: 9
Name: Ethernet1
IfIndex: 4
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30811 — Deleted a TCP/IP transport interface.
Message
Fields
| Name | Description |
|---|---|
NameLength | — |
Name | — |
IfIndex | — |
Example Event
system:
provider: Microsoft-Windows-SMBClient
guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
event_source_name: ''
event_id: 30811
version: 0
level: 4
task: 0
opcode: 0
keywords: 288230376151711808
time_created: '2023-11-06T06:25:42.599960+00:00'
event_record_id: 84
correlation: {}
execution:
process_id: 4
thread_id: 428
channel: Microsoft-Windows-SmbClient/Connectivity
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
NameLength: 9
Name: Ethernet1
IfIndex: 4
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30812 — Added a TDI transport interface.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Example Event
system:
provider: Microsoft-Windows-SMBClient
guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
event_source_name: ''
event_id: 30812
version: 0
level: 4
task: 0
opcode: 0
keywords: 288230376151711808
time_created: '2023-11-06T06:25:42.665527+00:00'
event_record_id: 88
correlation: {}
execution:
process_id: 4
thread_id: 224
channel: Microsoft-Windows-SmbClient/Connectivity
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ServerNameLength: 58
ServerName: \Device\NetBT_Tcpip_{3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30813 — Deleted a TDI transport interface.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Example Event
system:
provider: Microsoft-Windows-SMBClient
guid: 988C59C5-0A1C-45B6-A555-0C62276E327D
event_source_name: ''
event_id: 30813
version: 0
level: 4
task: 0
opcode: 0
keywords: 288230376151711808
time_created: '2023-11-06T06:25:42.600171+00:00'
event_record_id: 85
correlation: {}
execution:
process_id: 4
thread_id: 224
channel: Microsoft-Windows-SmbClient/Connectivity
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
ServerNameLength: 58
ServerName: \Device\NetBT_Tcpip_{3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30814 — Witness registration has completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ShareType | — |
NameLength | — |
Name | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 30815 — Witness deregistration has completed.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ShareType | — |
NameLength | — |
Name | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 30816 — The server failed the negotiate request.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
Event ID 30817 — Close request failed.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
Event ID 30818 — RDMA interfaces are available but the client failed to connect to the server over RDMA transport.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30819 — The SMB client received a request to move to a different node on a file server cluster.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ShareType | — |
NameLength | — |
Name | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 30820 — The SMB client successfully moved to a different node on a file server cluster.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ShareType | — |
NameLength | — |
Name | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 30821 — The SMB client failed to move to a different node on a file server cluster.
Message
Fields
| Name | Description |
|---|---|
Status | — |
ShareType | — |
NameLength | — |
Name | — |
RemoteAddressLength | — |
RemoteAddress | — |
Event ID 30822 — Failed to establish an SMB multichannel network connection.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
RemoteAddress | — |
LocalAddress | — |
InstanceNameLength | — |
InstanceName | — |
ConnectionType | — |
PortSelectionOrigin | — |
Event ID 30823 — The connection was terminated due to one or more IO request timeouts.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
RemoteAddress | — |
LocalAddress | — |
InstanceNameLength | — |
InstanceName | — |
ConnectionType | — |
Event ID 30824 — The connection was forcibly disconnected.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
AddressLength | — |
RemoteAddress | — |
LocalAddress | — |
InstanceNameLength | — |
InstanceName | — |
ConnectionType | — |
Event ID 30825 — The disconnect state on connection was cleared Name: %3 Instance name: %5 Guidance: Any persistent disconnect state on this connection is cleared.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
ServerNameLength | — |
ServerName | — |
InstanceNameLength | — |
InstanceName | — |
Event ID 30826 — The SMB negotiate response processing failed on the client to determine the selected encryption cipher for the client and server.
Message
Fields
| Name | Description |
|---|---|
ClientCipherSuiteOrderLength | — |
ClientCipherSuiteOrder | — |
ServerChosenEncryptionCipherLength | — |
ServerChosenEncryptionCipher | — |
Event ID 30827 — Could not find a certificate mapping that matches the server name.
Message
Fields
| Name | Description |
|---|---|
ConnectionType | — |
ServerNameLength | — |
ServerName | — |
Event ID 30828 — The client established its session to the server.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
ServerNameLength | — |
ServerName | — |
RemoteAddressLength | — |
RemoteAddress | — |
LocalAddressLength | — |
LocalAddress | — |
Event ID 30829 — The client failed to establish its session to the server.
Message
Fields
| Name | Description |
|---|---|
Status | — |
SessionId | — |
ServerNameLength | — |
ServerName | — |
RemoteAddressLength | — |
RemoteAddress | — |
LocalAddressLength | — |
LocalAddress | — |
Event ID 30830 — The SMB redirector selected the connection initiated with the following parameters: Server name: %2 Server socket address: %5 Client socket address...
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ConnectionType | — |
RemoteAddressLength | — |
RemoteAddress | — |
LocalAddressLength | — |
LocalAddress | — |
InstanceNameLength | — |
InstanceName | — |
PortSelectionOrigin | — |
Status | — |
ConnectionIdSize | — |
ConnectionId | — |
ClientCertSha1HashSize | — |
ClientCertSha1Hash | — |
Event ID 30831 — The SMB client was denied access to the SMB server during mutual authentication.
Message
Event ID 30832 — The SMB connection was successfully established.
Message
Event ID 30833 — The initial connection to the share was established.
Message
Event ID 30834 — The client was unable to perform revocation checks on the server certificate chain.
Message
Event ID 30835 — Server authentication failed.
Message
Event ID 30837 — The requested transport is disabled.
Message
Event ID 30900 — The handle was created without persistence.
Message
Fields
| Name | Description |
|---|---|
Object | — |
PersistentFID | — |
VolatileFID | — |
CreateGUID | — |
OldState | — |
NewState | — |
Status | — |
Reason | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
PreviousStatus | — |
PreviousReason | — |
Event ID 30904 — The server does not support multichannel.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30905 — The client cannot connect to the server due to a multichannel constraint registry setting.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30906 — A request on persistent/resilient handle failed because the handle was invalid or it exceeded the timeout.
Message
Fields
| Name | Description |
|---|---|
IrpCode | — |
RestartCount | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
Status | — |
Reason | — |
HistoryCount | — |
Event ID 30907 — The SMB Multichannel registry value is not configured with default settings.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 30908 — The SMB 3 and SMB 2 driver is not configured with the default start type.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 30909 — The client supports SMB Direct (RDMA) and SMB Signing is in use.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30910 — The client supports SMB Direct (RDMA) and SMB Encryption is in use.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 30911 — The Cipher Suite Order group policy setting is invalid.
Message
Fields
| Name | Description |
|---|---|
CipherSuiteOrder | — |
Event ID 30912 — The RequireSecureNegotiate setting has been removed.
Message
Event ID 30913 — Server %2 share %4 has requested client to use isolated connections to connection to the share.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ShareNameLength | — |
ShareName | — |
AsymmetricFlag | — |
IsolatedTransportFlag | — |
IsIsolatedTransportServerEntry | — |
Event ID 30914 — RDMA rundown is active.
Message
Fields
| Name | Description |
|---|---|
ActiveRdmaResourceCount | — |
Event ID 30915 — RDMA rundown is complete.
Message
Fields
| Name | Description |
|---|---|
NoOp | — |
Event ID 30916 — Reactivation of RDMA support has commenced.
Message
Event ID 30917 — RDMA is no longer disabled.
Message
Fields
| Name | Description |
|---|---|
NoOp | — |
Event ID 30918 — SMBDirect load attempt complete.
Message
Fields
| Name | Description |
|---|---|
IsSuccess | — |
LoadStatus | — |
ServicePathLength | — |
ServicePath | — |
DeviceNameLength | — |
DeviceName | — |
Event ID 30950 — Component capabilities: %1 Internal patch number: %2.
Message
Fields
| Name | Description |
|---|---|
ComponentCapabilities | — |
PatchNumber | — |
Event ID 30951 — The alternative port %1 is not a valid port within the range 0 to 65535 for mapping name %3:%5.
Message
Fields
| Name | Description |
|---|---|
PortNumber | — |
ServerNameLength | — |
ServerName | — |
TransportNameLength | — |
TransportName | — |
Event ID 30952 — The SMB redirector did not select the connection initiated with the following parameters: Server name: %2 IP Address: %5 Transport: %3 Instance Nam...
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ConnectionType | — |
RemoteAddressLength | — |
RemoteAddress | — |
InstanceNameLength | — |
InstanceName | — |
PortSelectionOrigin | — |
Status | — |
Event ID 30953 — SMB Dialect Change %1 was changed from %2 to %3.
Message
Fields
| Name | Description |
|---|---|
SmbDialect | — |
OldDialect | — |
NewDialect | — |
Event ID 30954 — It took %2 secs to execute %1.
Message
Fields
| Name | Description |
|---|---|
FunctionName | — |
CallDuration | — |
ThresholdDuration | — |
Event ID 30955 — It took %2 secs to execute %1 which is longer than threshold of %3 secs.
Message
Fields
| Name | Description |
|---|---|
FunctionName | — |
CallDuration | — |
ThresholdDuration | — |
Event ID 31000 — %1.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
SecurityStatus | — |
LogonId | — |
ServerNameLength | — |
ServerName | — |
PrincipalNameLength | — |
PrincipalName | — |
UserNameLength | — |
UserName | — |
Event ID 31001 — %1.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
SecurityStatus | — |
LogonId | — |
ServerNameLength | — |
ServerName | — |
PrincipalNameLength | — |
PrincipalName | — |
UserNameLength | — |
UserName | — |
Event ID 31002 — The outbound authentication failed using a network token.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ServerNameLength | — |
ServerName | — |
Event ID 31003 — The LmCompatibilityLevel value is different from the default.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 31010 — The SMB client failed to connect to the share.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
ShareNameLength | — |
ShareName | — |
ObjectNameLength | — |
ObjectName | — |
Event ID 31012 — The negotiate validation failed.
Message
Fields
| Name | Description |
|---|---|
Dialect | — |
SecurityMode | — |
Capabilities | — |
Guid | — |
Dialect2 | — |
SecurityMode2 | — |
Capabilities2 | — |
Guid2 | — |
Event ID 31013 — The signing validation failed.
Message
Fields
| Name | Description |
|---|---|
Smb2Command | — |
MessageId | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
Status | — |
MessageSize | — |
FragmentOffset | — |
FragmentSize | — |
FragmentData | — |
RemoteAddressLength | — |
RemoteAddress | — |
LocalAddressLength | — |
LocalAddress | — |
Event ID 31014 — The client received an unencrypted message when encryption was expected.
Message
Fields
| Name | Description |
|---|---|
Smb2Command | — |
MessageId | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
Status | — |
InstanceNameLength | — |
InstanceName | — |
RetryCount | — |
ElapsedTimeInMs | — |
RemoteAddressLength | — |
RemoteAddress | — |
LocalAddressLength | — |
LocalAddress | — |
Event ID 31015 — Failed to decrypt an encrypted SMB message.
Message
Fields
| Name | Description |
|---|---|
Smb2Command | — |
MessageId | — |
SessionId | — |
TreeId | — |
ServerNameLength | — |
ServerName | — |
Status | — |
InstanceNameLength | — |
InstanceName | — |
RetryCount | — |
ElapsedTimeInMs | — |
Event ID 31016 — The SMB Signing registry value is not configured with default settings.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 31017 — Rejected an insecure guest logon.
Message
Fields
| Name | Description |
|---|---|
UserNameLength | — |
UserName | — |
ServerNameLength | — |
ServerName | — |
Event ID 31018 — Guidance: An administrator has enabled AllowInsecureGuestAuth.
Message
Fields
| Name | Description |
|---|---|
RegName | — |
RegValue | — |
Event ID 31019 — Mutual authentication was unexpectedly lost after re-authenticating to %6 User %8 LogonID %4 Status %2 AuthProtocol Old %9 New %10 MutualAuthState ...
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Status | — |
SecurityStatus | — |
LogonId | — |
ServerNameLength | — |
ServerName | — |
UserNameLength | — |
UserName | — |
OldAuthProtocolId | — |
NewAuthProtocolId | — |
OldMutualAuthState | — |
NewMutualAuthState | — |
ClusteredServer | — |
Event ID 31020 — Session key for connection is weaker than required.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
SessionKeyLength | — |
RequiredSessionKeyLength | — |
SessionId | — |
UserName | — |
AuthProtocol | — |
Event ID 31021 — SMB DDP security changed from %1 to %2.
Message
Fields
| Name | Description |
|---|---|
OldValue | — |
NewValue | — |
Event ID 31022 — Allowed an insecure guest logon.
Message
Fields
| Name | Description |
|---|---|
UserNameLength | — |
UserName | — |
ServerNameLength | — |
ServerName | — |
Event ID 31023 — NTLM is prohibited for authentication on the server Server name: %2 NTLM was disabled by user or by administrator using policies.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 31997 — The SMB client was logged on as Guest account.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
Event ID 31998 — The SMB client observed that the server doesn't support signing.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ClientRequireSigning | — |
Event ID 31999 — The SMB client observed that the server doesn't support encryption.
Message
Fields
| Name | Description |
|---|---|
ServerNameLength | — |
ServerName | — |
ClientRequireEncryption | — |
Event ID 32000 — SMB1 negotiate response received from remote device when SMB1 cannot be negotiated by the local computer.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Dialect | — |
ServerNameLength | — |
ServerName | — |
Event ID 32002 — The local computer received an SMB1 negotiate response.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Dialect | — |
SecurityMode | — |
ServerNameLength | — |
ServerName | — |
Event ID 32003 — The local computer didn't received an SMB1 negotiate response in the last %1 days.
Message
Fields
| Name | Description |
|---|---|
Days | — |
Event ID 32004 — SMB2 rxcontext performance work started
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
FileNameLength | — |
FileName | — |
MajorFunction | — |
MinorFunction | — |
Event ID 32005 — SMB2 exchange performance work started
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
MajorFunction | — |
MinorFunction | — |
Event ID 32006 — SMB2 buffer context performance work started
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
MajorFunction | — |
MinorFunction | — |
Smb2Command | — |
Event ID 32007 — SMB2 performance work transition
Message
Fields
| Name | Description |
|---|---|
BlockType | — |
Event ID 32008 — SMB2 rxcontext performance work read summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
FileObject | — |
IRP | — |
ByteCount | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
ReadProcessing | — |
HitCountReadProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
AttemptTurboIORead | — |
HitCountAttemptTurboIORead | — |
AttemptTurboIOInit | — |
HitCountAttemptTurboIOInit | — |
TurboIORxCompletion | — |
HitCountTurboIORxCompletion | — |
Event ID 32009 — SMB2 rxcontext performance work write summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
FileObject | — |
IRP | — |
ByteCount | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
WriteProcessing | — |
HitCountWriteProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
AttemptTurboIOWrite | — |
HitCountAttemptTurboIOWrite | — |
AttemptTurboIOInit | — |
HitCountAttemptTurboIOInit | — |
TurboIORxCompletion | — |
HitCountTurboIORxCompletion | — |
Event ID 32010 — SMB2 rxcontext performance work create summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
IRP | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
CreateProcessing | — |
HitCountCreateProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
Event ID 32011 — SMB2 rxcontext performance work close summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
IRP | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
CloseProcessing | — |
HitCountCloseProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
Event ID 32012 — SMB2 rxcontext performance work query directory summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
IRP | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
QueryDirectoryProcessing | — |
HitCountQueryDirectoryProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
Event ID 32013 — SMB2 rxcontext performance work fsctl summary
Message
Fields
| Name | Description |
|---|---|
RxContext | — |
InstanceId | — |
IRP | — |
TotalDuration | — |
Construction | — |
HitCountConstruction | — |
DispatchProcessing | — |
HitCountDispatchProcessing | — |
FsctlProcessing | — |
HitCountFsctlProcessing | — |
CallMiniRdr_MRXSMB | — |
HitCountCallMiniRdr_MRXSMB | — |
LowIoCompletionRoutine | — |
HitCountLowIoCompletionRoutine | — |
CompleteIRP | — |
HitCountCompleteIRP | — |
PostIOCompletion | — |
HitCountPostIOCompletion | — |
PostIORetry | — |
HitCountPostIORetry | — |
Event ID 32028 — SMB2 exchange performance work read summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
RxContext | — |
ByteCount | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
ReadStart | — |
HitCountReadStart | — |
ReadBuildAndSendChunks | — |
HitCountReadBuildAndSendChunks | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
TurboIOStart | — |
HitCountTurboIOStart | — |
TurboIOComplete | — |
HitCountTurboIOComplete | — |
Event ID 32029 — SMB2 exchange performance work write summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
RxContext | — |
ByteCount | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
WriteStart | — |
HitCountWriteStart | — |
WriteBuildAndSendChunks | — |
HitCountWriteBuildAndSendChunks | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
TurboIOStart | — |
HitCountTurboIOStart | — |
TurboIOComplete | — |
HitCountTurboIOComplete | — |
Event ID 32030 — SMB2 exchange performance work create summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
CreateStart | — |
HitCountCreateStart | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
Event ID 32031 — SMB2 exchange performance work close summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
CloseStart | — |
HitCountCloseStart | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
Event ID 32032 — SMB2 exchange performance work query directory summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
QueryDirectoryStart | — |
HitCountQueryDirectoryStart | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
Event ID 32033 — SMB2 exchange performance work fsctl summary
Message
Fields
| Name | Description |
|---|---|
Exchange | — |
InstanceId | — |
TotalDuration | — |
RestartCount | — |
ResolvingConnectionObjects | — |
HitCountResolvingConnectionObjects | — |
CommandProcessing | — |
HitCountCommandProcessing | — |
FsctlStart | — |
HitCountFsctlStart | — |
CommandFinalizationCallback | — |
HitCountCommandFinalizationCallback | — |
Finalize | — |
HitCountFinalize | — |
PostFinalizeWorker | — |
HitCountPostFinalizeWorker | — |
FinalizeWorkerHitCount | — |
HitCountFinalizeWorkerHitCount | — |
Event ID 32048 — SMB2 buffer context performance work read summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
Exchange | — |
ByteCount | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
WriteRDMABufferRegistration | — |
HitCountWriteRDMABufferRegistration | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
ReadReceive | — |
HitCountReadReceive | — |
Event ID 32049 — SMB2 buffer context performance work write summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
Exchange | — |
ByteCount | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
ReadRDMABufferRegistration | — |
HitCountReadRDMABufferRegistration | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
WriteReceive | — |
HitCountWriteReceive | — |
Event ID 32050 — SMB2 buffer context performance work create summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
CreateReceive | — |
HitCountCreateReceive | — |
Event ID 32051 — SMB2 buffer context performance work close summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
CloseReceive | — |
HitCountCloseReceive | — |
Event ID 32052 — SMB2 buffer context performance work query directory summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
QueryDirectoryReceive | — |
HitCountQueryDirectoryReceive | — |
Event ID 32053 — SMB2 buffer context performance work fsctl summary
Message
Fields
| Name | Description |
|---|---|
BufferContext | — |
InstanceId | — |
TotalDuration | — |
Initialized | — |
HitCountInitialized | — |
RDMAGetDescriptors | — |
HitCountRDMAGetDescriptors | — |
AssociateMID | — |
HitCountAssociateMID | — |
Assembly | — |
HitCountAssembly | — |
BeginSmbSend | — |
HitCountBeginSmbSend | — |
BeginSmbSendAsyncPostWorkerCount | — |
HitCountBeginSmbSendAsyncPostWorkerCount | — |
SmbdPrepareSend | — |
HitCountSmbdPrepareSend | — |
ServerTimeTakenToReply | — |
HitCountServerTimeTakenToReply | — |
FsctlReceive | — |
HitCountFsctlReceive | — |
Event ID 32068 — SMB2 FCB capture summary
Message
Fields
| Name | Description |
|---|---|
InstanceId | — |
PrefixLength | — |
Prefix | — |
ServerShareLength | — |
ServerShare | — |
Event ID 40000 — Packet (%4 bytes).
Message
Fields
| Name | Description |
|---|---|
ConnectionType | — |
PeerAddressLength | — |
PeerAddress | — |
PacketSize | — |
PacketData | — |