Microsoft-Windows-SMBServer

207 events across 7 channels

Event IDTitleChannel
1Smb2 Request NegotiatePerformance
2Smb2 Request Session SetupPerformance
3Smb2 Request LogoffPerformance
4Smb2 Request Tree ConnectPerformance
5Smb2 Request Tree DisconnectPerformance
6Smb2 Request EchoPerformance
7Smb2 Request CancelPerformance
8Smb2 Request CreatePerformance
9Smb2 Request ClosePerformance
10Smb2 Request FlushPerformance
11Smb2 Request ReadPerformance
12Smb2 Request WritePerformance
13Smb2 Request Break OplockPerformance
14Smb2 Request Notify Break LeasePerformance
15Smb2 Request Acknowledge Break LeasePerformance
16Smb2 Request LockPerformance
17Smb2 Request IoctlPerformance
18Smb2 Request Query DirectoryPerformance
19Smb2 Request Change NotifyPerformance
20Smb2 Request Query InfoPerformance
21Smb2 Request Set InfoPerformance
101Smb2 Response NegotiatePerformance
102Smb2 Response Session SetupPerformance
103Smb2 Response LogoffPerformance
104Smb2 Response Tree ConnectPerformance
105Smb2 Response Tree DisconnectPerformance
106Smb2 Response EchoPerformance
108Smb2 Response CreatePerformance
109Smb2 Response ClosePerformance
110Smb2 Response FlushPerformance
111Smb2 Response ReadPerformance
112Smb2 Response WritePerformance
113Smb2 Response Break OplockPerformance
115Smb2 Response Acknowledge Break LeasePerformance
116Smb2 Response LockPerformance
117Smb2 Response IoctlPerformance
118Smb2 Response Query DirectoryPerformance
119Smb2 Response Change NotifyPerformance
120Smb2 Response Query InfoPerformance
121Smb2 Response Set InfoPerformance
122Smb2 Response ErrorPerformance
200Smb2 Work Item Component TransitionPerformance
201Smb2 Work Item allocatedPerformance
202Smb2 Work Item releasedPerformance
203SMB2 Work Item activity id transferPerformance
204SMB2 Work Item external activity id stopPerformance
500Smb2 Connection acceptedAnalytic
501Smb2 Connection Disconnected by PeerAnalytic
502Smb2 Connection TerminatedAnalytic
550Smb2 Session AllocatedAnalytic
551Smb2 Session Authentication FailureAnalytic
551SMB Session Authentication Failure Client Name: %11 Client Address: %6 User …Security
552Smb2 Session Authentication SuccessAnalytic
553Smb2 Session Bound to ConnectionAnalytic
554Smb2 Session TerminatedAnalytic
555SMB2 Session Closed.Analytic
600Smb2 TreeConnect AllocatedAnalytic
601Smb2 TreeConnect DisconnectedAnalytic
602Smb2 TreeConnect TerminatedAnalytic
603Smb2 TreeConnect Failed due to Cluster Endpoint InitializingAnalytic
604A client connection to a continuously available share has been marked so that …Operational
605A client request on a continuously available share has been failed so that the …Operational
650Smb2 Open establishedAnalytic
651Smb2 Open Disconnected - PreservedAnalytic
652Smb2 Open ReconnectedAnalytic
653Smb2 Open Suspended - PreservedAnalytic
654Smb2 Open ClosedAnalytic
655Smb2 Open Timed OutAnalytic
656Smb2 Open TerminatedAnalytic
657Smb2 Open Clustered Client Failover ClosedAnalytic
658File handle for file {ShareName}\{FileName} was invalidated by user {UserName} …Operational
700Smb2 Share AddedAnalytic
701Smb2 Share ModifiedAnalytic
702Smb2 Share DeletedAnalytic
1000S4U2Self authentication failure - The client could not be reauthenticated with …Operational
1001SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.Operational
1002RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for …Operational
1003The server received an unencrypted message from client {ClientName}.Operational
1004The server received a incorrectly signed message from client {ClientName}.Operational
1005The server failed to validate negotiation from client {ClientName}.Operational
1006The share denied access to the client.Security
1007The share denied anonymous access to the client.Security
1009The server denied anonymous access to the client.Security
1010Endpoint added.Operational
1011Endpoint removed.Operational
1012The network name information changed.Operational
1013Endpoint coming online.Operational
1014Endpoint going offline.Operational
1015Decrypt call failed.Security
1016Reopen failed.Operational
1017Handle scavenged.Operational
1018Backchannel invalidation of session completed.Operational
1019Backchannel invalidation of file completed.Operational
1020File system operation has taken longer than expected.Operational
1021LmCompatibilityLevel value is different from the default.Security
1022File and printer sharing firewall rule enabled.Connectivity
1023One or more shares present on this server have access based enumeration enabled.Operational
1024SMB2 and SMB3 have been disabled on this server.Operational
1025One or more named pipes or shares have been marked for access by anonymous …Operational
1026File leasing has been disabled for the SMB2 and SMB3 protocols.Operational
1027The file and printer sharing firewall ports are currently closed.Operational
1028The maximum cluster-supported SMB dialect has changed.Operational
1029The Cipher Suite Order group policy setting is invalid.Operational
1030An MDL read or write completion request failed.Operational
1031The server detected a problem and has captured a live kernel dump to collect …Operational
1032The server detected a problem but was unable to capture a live kernel dump to …Operational
1033Sent RDMA .Analytic
1033Sent RDMA %1 event to LanmanServer for interface %3.Operational
1034Send RDMA Endpoint notification failure - .Analytic
1034Send RDMA Endpoint notification failure - %1.Operational
1035RDMA Endpoint %4 for interface %2 was %1.Operational
1035RDMA Endpoint .Analytic
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface .Analytic
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1.Operational
1037RDMA listener creation failure - .Analytic
1037RDMA listener creation failure - %1.Operational
1038RDMA Send endpoint notification RPC failure for device .Analytic
1038RDMA Send endpoint notification RPC failure for device %3 - %1.Operational
1039Received Nsi notification type .Analytic
1039Received Nsi notification type %1 for interface %2 with NdkOperationalState %3.Operational
1040Received Mib notification type .Analytic
1040Received Mib notification type %1 for interface %2.Operational
1041Error reading FSCTL properties information from the registry.Operational
1042The certificate for the server is about to expire.Operational
1043RDMA connection disconnected.Operational
1044Quic connection shutdown.Operational
1045The server failed to update server certificate mapping.Analytic
1045The server failed to update server certificate mapping.Operational
1046The server received a request and the server requires encryption, but the server …Operational
1047The server received a %2 request but is taking an abnormal amount of time to …Operational
1048The server processed a %1 request.Operational
1049The certificate for the server has expired.Operational
1050Found %1 endpoint(s) related to interface ID %2, closed %3 of which.Operational
1051The SMB negotiate request processing failed on the server to select the …Operational
1052Failed to restore a server certificate mapping from persistent storage.Operational
1053Restored %2 of %1 server certificate mappings from persistent storage.Operational
1054Network operation has taken longer than expected.Operational
1055RDMA rundown is active.Operational
1056RDMA rundown is complete.Operational
1057Reactivation of RDMA support has commenced.Operational
1058RDMA is no longer disabled.Operational
1059SMBDirect load attempt complete.Operational
1060SMB DDP security changed from %1 to %2.Operational
1061SMB2 Request Negotiate Dialect Failure Session ID: %1 Client Address: %18 Client …Operational
1062SMB Dialect Change %1 was changed from %2 to %3.Operational
1080Component capabilities: %1 Internal patch number: %2.Operational
1800CA failure - Failed to set continuously available property on a new or existing …Operational
1801CA failure - Failed to set continuously available property on a new or existing …Operational
1802The server failed to reserve the next ID region in the cluster registry.Operational
1803The security descriptor differs from the default value.Operational
1804No SMB1 usage detected in the last 20 minutes.Analytic
1900TDI mode enabled: .Analytic
1900TDI mode enabled.Operational
1901Failed to allocate an NSI table for network interface enumeration: .Analytic
1901Failed to allocate an NSI table for network interface enumeration.Operational
1902Received notification of a newly-started network interface with Luid .Analytic
1902Received notification of a newly-started network interface with Luid %2 on …Operational
1903Received notification of a stopped network interface with Luid .Analytic
1903Received notification of a stopped network interface with Luid %2 on address …Operational
1904Failed to open network interface with Luid .Analytic
1904Failed to open network interface with Luid %1: error %2.Operational
1905The server closed the session as part of periodic system cleanup.Operational
1906Session key for connection is weaker than required.Security
1907Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.Analytic
1908Custom FSCTL allow list was not successfully loaded after several retries.Analytic
1909Send QUIC Endpoint notification failure - .Analytic
1909Send QUIC Endpoint notification failure - %1.Operational
1910RDMA listen socket disable override is %1.Operational
1911Server Certificate failure - %1.Operational
1912Warning to set the QoS policy on file %6.Operational
1913The SMB connection was successfully established.Operational
1914The server was unable to perform revocation checks on the client certificate …Operational
2000Packet Fragment ({FragmentSize} bytes).Diagnostic
3000SMB1 access Client Address: %1 Guidance: This event indicates that a client …Audit
3002A remote device attempted SMB1 connection to this computer.Audit
3003SMB1 server service has been automatically uninstalled.Audit
3004SMB server admin file rundownOperational
3005SMB server admin session rundownOperational
3006SMB server admin share rundownOperational
3007Access Denied Server certificate mapping name: %2 Client socket address: %4 …Audit
3008Access Allowed Server certificate mapping name: %2 Client socket address: %4 …Audit
3009An error occurred while checking client certificate chain access during mutual …Audit
3010An administrator attempted to assign an alternative SMB server listener port %1, …Operational
3011The SMB server service created an endpoint with the following listener rule …Operational
3012The SMB server service failed to create an endpoint with the following listener …Operational
3013An administrator created an alternative SMB server listener port rule entry: …Operational
3014An administrator updated an existing alterative SMB server listener port rule …Operational
3015An administrator removed an existing alternative SMB server listener port rule …Operational
3016The SMB server service failed to enable an implicit loopback interface for …Operational
3017The SMB server service failed to disable an implicit loopback interface for …Operational
3018The inbound %2 firewall rule already exists for port %1.Operational
3019The inbound %2 firewall rule failed to be created for port %1.Operational
3020The inbound %2 firewall rule was successfully created for port %1.Operational
3021The SMB server observed that the client doesn't support signing.Audit
3022The SMB server observed that the client doesn't support encryption.Audit
3023The SMB client was logged on as Guest account.Operational
3024Operational
3024The SMB server observed that the client did not send an SPN during …Audit
3025Operational
3025The SMB server observed that the client sent an unrecognized SPN during …Audit
3026Operational
3026The SMB server observed that the client sent an empty SPN during authentication, …Audit
3027Operational
3027The SMBv1 server observed that the SMBv1 client does not have signing enabled.Audit
4000Operational
4000The SMB client connection to the share was established.Connectivity
40000Packet ({PacketSize} bytes).Diagnostic

Event ID 1 — Smb2 Request Negotiate

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Negotiate

Event ID 2 — Smb2 Request Session Setup

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Session Setup

Event ID 3 — Smb2 Request Logoff

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Logoff

Event ID 4 — Smb2 Request Tree Connect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Tree Connect

Event ID 5 — Smb2 Request Tree Disconnect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Tree Disconnect

Event ID 6 — Smb2 Request Echo

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Echo

Event ID 7 — Smb2 Request Cancel

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Cancel

Event ID 8 — Smb2 Request Create

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Create

Event ID 9 — Smb2 Request Close

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Close

Event ID 10 — Smb2 Request Flush

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Flush

Event ID 11 — Smb2 Request Read

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Read

Event ID 12 — Smb2 Request Write

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Write

Event ID 13 — Smb2 Request Break Oplock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Break Oplock

Event ID 14 — Smb2 Request Notify Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Notify Break Lease

Event ID 15 — Smb2 Request Acknowledge Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Acknowledge Break Lease

Event ID 16 — Smb2 Request Lock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Lock

Event ID 17 — Smb2 Request Ioctl

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Ioctl

Event ID 18 — Smb2 Request Query Directory

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Query Directory

Event ID 19 — Smb2 Request Change Notify

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Change Notify

Event ID 20 — Smb2 Request Query Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Query Info

Event ID 21 — Smb2 Request Set Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Request Set Info

Event ID 101 — Smb2 Response Negotiate

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Negotiate

Event ID 102 — Smb2 Response Session Setup

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Session Setup

Event ID 103 — Smb2 Response Logoff

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Logoff

Event ID 104 — Smb2 Response Tree Connect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Tree Connect

Event ID 105 — Smb2 Response Tree Disconnect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Tree Disconnect

Event ID 106 — Smb2 Response Echo

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Echo

Event ID 108 — Smb2 Response Create

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Create

Event ID 109 — Smb2 Response Close

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Close

Event ID 110 — Smb2 Response Flush

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Flush

Event ID 111 — Smb2 Response Read

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Read

Event ID 112 — Smb2 Response Write

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Write

Event ID 113 — Smb2 Response Break Oplock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Break Oplock

Event ID 115 — Smb2 Response Acknowledge Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Acknowledge Break Lease

Event ID 116 — Smb2 Response Lock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Lock

Event ID 117 — Smb2 Response Ioctl

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Ioctl

Event ID 118 — Smb2 Response Query Directory

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Query Directory

Event ID 119 — Smb2 Response Change Notify

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Change Notify

Event ID 120 — Smb2 Response Query Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Query Info

Event ID 121 — Smb2 Response Set Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Set Info

Event ID 122 — Smb2 Response Error

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Response Error

Event ID 200 — Smb2 Work Item Component Transition

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Work Item Component Transition

Event ID 201 — Smb2 Work Item allocated

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Work Item allocated

Event ID 202 — Smb2 Work Item released

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Message

Smb2 Work Item released

Event ID 203 — SMB2 Work Item activity id transfer

Provider
Microsoft-Windows-SMBServer
Channel
Performance

Message

SMB2 Work Item activity id transfer

Event ID 204 — SMB2 Work Item external activity id stop

Provider
Microsoft-Windows-SMBServer
Channel
Performance

Message

SMB2 Work Item external activity id stop

Event ID 500 — Smb2 Connection accepted

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Connection accepted

Event ID 501 — Smb2 Connection Disconnected by Peer

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Connection Disconnected by Peer

Event ID 502 — Smb2 Connection Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Connection Terminated

Event ID 550 — Smb2 Session Allocated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Session Allocated

Event ID 551 — Smb2 Session Authentication Failure

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Session Authentication Failure

Event ID 551 — SMB Session Authentication Failure Client Name: %11 Client Address: %6 User Name: %9 Session ID: %7 Status: %4 (%3) SPN: %12 SPN Validation Policy:...

Provider
Microsoft-Windows-SMBServer
Channel
Security
Level
2
Samples
1

Message

SMB Session Authentication Failure



Client Name: %11

Client Address: %6

User Name: %9

Session ID: %7

Status: %4 (%3)

SPN: %12

SPN Validation Policy: %13



Guidance:



You should expect this error when attempting to connect to shares using incorrect credentials.



This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.



This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, an incorrect service principal name, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled

Fields

NameDescription
EventData.SessionGUID
EventData.ConnectionGUID
EventData.Status
EventData.TranslatedStatus
EventData.ClientAddressLength
EventData.ClientAddress
EventData.SessionId
EventData.UserNameLength
EventData.UserName
EventData.ClientNameLength
EventData.ClientName
EventData.SPN
EventData.SPNValidationPolicy
EventData.ReasonCode

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 551
  version: 3
  level: 2
  task: 551
  opcode: 0
  keywords: 580964351930793992
  time_created: '2022-04-07T17:25:55.271679+00:00'
  event_record_id: 10
  correlation: {}
  execution:
    process_id: 4
    thread_id: 4460
  channel: Microsoft-Windows-SMBServer/Security
  computer: WIN-FPV0DSIC9O6.sigma.fr
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    SessionGUID: E0AAB88C-4A9F-0000-B5F0-AAE09F4AD801
    ConnectionGUID: E0AAB88C-4A9F-0000-A5F0-AAE09F4AD801
    Status: '0xc000006d'
    TranslatedStatus: '0xc000006d'
    ClientAddressLength: 16
    ClientAddress: 0200C33B0A0002860000000000000000
    SessionId: '0x100000000061'
    UserNameLength: 0
    UserName: null
    ClientNameLength: 12
    ClientName: \\10.0.2.134
    SPN: session setup failed before the SPN could be queried
    SPNValidationPolicy: 0
    ReasonCode: 3
message: ''

References

Event ID 552 — Smb2 Session Authentication Success

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Session Authentication Success

Event ID 553 — Smb2 Session Bound to Connection

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Session Bound to Connection

Event ID 554 — Smb2 Session Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Session Terminated

Event ID 555 — SMB2 Session Closed.

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Message

SMB2 Session Closed.

Fields

NameDescription
SessionGUID
InvalidateSession
Reason

Event ID 600 — Smb2 TreeConnect Allocated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 TreeConnect Allocated

Event ID 601 — Smb2 TreeConnect Disconnected

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 TreeConnect Disconnected

Event ID 602 — Smb2 TreeConnect Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 TreeConnect Terminated

Event ID 603 — Smb2 TreeConnect Failed due to Cluster Endpoint Initializing

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 TreeConnect Failed due to Cluster Endpoint Initializing

Event ID 604 — A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best p...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields

NameDescription
SessionGUID
TreeConnectGUID
ShareNameLength
ShareName

Event ID 605 — A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best poss...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields

NameDescription
SessionGUID
TreeConnectGUID
ShareNameLength
ShareName

Event ID 650 — Smb2 Open established

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open established

Event ID 651 — Smb2 Open Disconnected - Preserved

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Disconnected - Preserved

Event ID 652 — Smb2 Open Reconnected

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Reconnected

Event ID 653 — Smb2 Open Suspended - Preserved

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Suspended - Preserved

Event ID 654 — Smb2 Open Closed

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Closed

Event ID 655 — Smb2 Open Timed Out

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Timed Out

Event ID 656 — Smb2 Open Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Terminated

Event ID 657 — Smb2 Open Clustered Client Failover Closed

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Open Clustered Client Failover Closed

Event ID 658 — File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}

Fields

NameDescription
ShareName
FileName
UserName
ComputerName

Event ID 700 — Smb2 Share Added

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Share Added

Event ID 701 — Smb2 Share Modified

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Share Modified

Event ID 702 — Smb2 Share Deleted

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Message

Smb2 Share Deleted

Event ID 1000 — S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.  This may be expected if the account is not a domain account.

Event ID 1001 — SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Event ID 1002 — RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Event ID 1003 — The server received an unencrypted message from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

The server received an unencrypted message from client {ClientName}. Messsage was rejected.

Fields

NameDescription
ClientName

Event ID 1004 — The server received a incorrectly signed message from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

The server received a incorrectly signed message from client {ClientName}. Message was rejected.

Fields

NameDescription
ClientName

Event ID 1005 — The server failed to validate negotiation from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

The server failed to validate negotiation from client {ClientName}. Connection was terminated.

Fields

NameDescription
ClientName

Event ID 1006 — The share denied access to the client.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

The share denied access to the client.

Client Name: %10
Client Address: %6
User Name: %8
Session ID: %17
Share Name: %2
Share Path: %4
Status: %16 (%15)
Mapped Access: %11
Granted Access: %12
Security Descriptor: %14

Guidance:

You should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue.

Applications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required.

If access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions.

This error does not indicate a problem with authentication, only authorization.

Fields

NameDescription
ShareNameLength
ShareName
SharePathLength
SharePath
ClientAddressLength
ClientAddress
UserNameLength
UserName
ClientNameLength
ClientName
MappedAccess
GrantedAccess
ShareSecurityDescriptorLength
ShareSecurityDescriptor
Status
TranslatedStatus
SessionID

Event ID 1007 — The share denied anonymous access to the client.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

The share denied anonymous access to the client.

Client Name: %8
Client Address: %6
Share Name: %2
Share Path: %4

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields

NameDescription
ShareNameLength
ShareName
SharePathLength
SharePath
ClientAddressLength
ClientAddress
ClientNameLength
ClientName

Event ID 1009 — The server denied anonymous access to the client.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

The server denied anonymous access to the client.

Client Name: %4
 Client Address: %2
Session ID: %5

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, Windows Server denies anonymous access to shares.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields

NameDescription
ClientAddressLength
ClientAddress
ClientNameLength
ClientName
SessionId
SessionGUID
ConnectionGUID

Event ID 1010 — Endpoint added.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

Endpoint added.

Name: %2
Domain Name: %4
Transport Name: %6
Transport Flags: %7

Guidance:

You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required.

Fields

NameDescription
EventData.NameLength
EventData.Name
EventData.DomainNameLength
EventData.DomainName
EventData.TransportNameLength
EventData.TransportName
EventData.TransportFlags

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1010
  version: 0
  level: 4
  task: 1010
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-06T06:25:52.476934+00:00'
  event_record_id: 99
  correlation: {}
  execution:
    process_id: 4
    thread_id: 124
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    NameLength: 16
    Name: 'WINDEV2310EVAL  '
    DomainNameLength: 9
    DomainName: WORKGROUP
    TransportNameLength: 58
    TransportName: \Device\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}
    TransportFlags: '0x1'
message: ''

References

Event ID 1011 — Endpoint removed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

Endpoint removed.

Name: %2
Domain Name: %4
Transport Name: %6

Guidance:

You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. No user action is required.

Fields

NameDescription
EventData.NameLength
EventData.Name
EventData.DomainNameLength
EventData.DomainName
EventData.TransportNameLength
EventData.TransportName

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1011
  version: 0
  level: 4
  task: 1011
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2022-04-04T12:00:04.359257+00:00'
  event_record_id: 18
  correlation: {}
  execution:
    process_id: 4
    thread_id: 196
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WIN-TKC15D7KHUR
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    NameLength: 0
    Name: null
    DomainNameLength: 0
    DomainName: null
    TransportNameLength: 58
    TransportName: \Device\NetBT_Tcpip_{64AAD862-869C-436D-A905-CCB55AA6A79F}
message: ''

References

Event ID 1012 — The network name information changed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The network name information changed.

Change Type: %1
Net Name: %3
IP Address: %9
Flags: %4
Interface Index: %5
Capability: %6
Link Speed: %7

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network configuration. No user action is required.

Fields

NameDescription
ChangeType
NetNameLength
NetName
Flags
InterfaceIndex
Capability
LinkSpeed
ClientAddressLength
ClientAddress

Event ID 1013 — Endpoint coming online.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Endpoint coming online.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields

NameDescription
EndpointNameLength
EndpointName
TransportNameLength
TransportName

Event ID 1014 — Endpoint going offline.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Endpoint going offline.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields

NameDescription
EndpointNameLength
EndpointName
TransportNameLength
TransportName

Event ID 1015 — Decrypt call failed.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

Decrypt call failed.

Client Name: %2
Client Address: %4
Session ID: %7
Status: %6 (%5)

Guidance:

This event commonly occurs because a previous SMB session no longer exists. It may also be caused by packets that are altered on the network between the computers due to either errors or a "man-in-the-middle" attack.

Fields

NameDescription
ClientNameLength
ClientName
ClientAddressLength
ClientAddress
Status
TranslatedStatus
SessionID

Event ID 1016 — Reopen failed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Reopen failed.

Client Name: %7
Client Address: %9
User Name: %13
Session ID: %14
Share Name: %11
File Name: %16
Resume Key: %20
Status: %2 (%1)
RKF Status: %4 (%3)
Durable: %17
Resilient: %18
Persistent: %19
Reason: %21

Guidance:

The client attempted to reopen a continuously available handle, but the attempt failed. This typically indicates a problem with the network or underlying file being re-opened.

Fields

NameDescription
Status
TranslatedStatus
RKFStatus
TranslatedRKFStatus
ConnectionGUID
ClientNameLength
ClientName
ClientAddressLength
ClientAddress
ShareNameLength
ShareName
UserNameLength
UserName
SessionId
FileNameLength
FileName
DurableHandle
ResilientHandle
PersistentHandle
ResumeKey
Reason

Event ID 1017 — Handle scavenged.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Handle scavenged.

Share Name: %7
File Name: %9
Resume Key: %5
Persistent File ID: %3
Volatile File ID: %4
Durable: %1
Resilient or Persistent: %2

Guidance:

The server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted.

Fields

NameDescription
DurableHandle
ResilientHandle
PersistentFID
VolatileFID
ResumeKey
ShareNameLength
ShareName
FileNameLength
FileName

Event ID 1018 — Backchannel invalidation of session completed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Backchannel invalidation of session completed.

Session ID: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields

NameDescription
SessionId
Status
TranslatedStatus
TaskStatus
TranslatedTaskStatus

Event ID 1019 — Backchannel invalidation of file completed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Backchannel invalidation of file completed.

Resume Key: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields

NameDescription
ResumeKey
Status
TranslatedStatus
TaskStatus
TranslatedTaskStatus

Event ID 1020 — File system operation has taken longer than expected.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

File system operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields

NameDescription
Command
SessionGuid
SessionId
ConnectionGuid
UserNameLength
UserName
ClientNameLength
ClientName
ClientAddressLength
ClientAddress
ShareNameLength
ShareName
FileNameLength
FileName
DurationInMilliseconds
ThresholdInMilliseconds
CtlCode
SubCode
TunneledControl

Event ID 1021 — LmCompatibilityLevel value is different from the default.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

LmCompatibilityLevel value is different from the default.

Configured LM Compatibility Level: %1
Default LM Compatibility Level: %2

Guidance:

LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers.

Value (Setting) - Description

0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication.

5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication.

Incompatibly configured  LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings.

Fields

NameDescription
ConfiguredLmCompatibilityLevel
DefaultLmCompatibilityLevel

Event ID 1022 — File and printer sharing firewall rule enabled.

Provider
Microsoft-Windows-SMBServer
Channel
Connectivity

Message

File and printer sharing firewall rule enabled.

Guidance:

You should expect this event when Windows Firewall is configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that has custom shares configured.

Event ID 1023 — One or more shares present on this server have access based enumeration enabled.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

One or more shares present on this server have access based enumeration enabled.

Guidance:

You should expect this event when enabling access-based enumeration on one or more shares by using either Server Manager or the Set-SmbShare Windows PowerShell cmdlet. Access-based enumeration can raise CPU utilization when clients connect to shares with folders containing many peer-level resources to which a user does not have access. You can control the CPU utilization by configuring the ABELevel value in the Windows registry:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters\ABELevel [DWORD]

You can set the value for ABELevel to greater depths to minimize CPU overhead, but doing so diminishes the effectiveness of access-based enumeration:

Value = 0: access-based enumeration is enabled for all levels

Value = 1: access-based enumeration is enabled for a depth of 1 (example: \server\share)

Value = 2: access-based enumeration is enabled for a depth of 2 (example: \server\share\folder)

You can continue setting values for multiple depth levels.

Event ID 1024 — SMB2 and SMB3 have been disabled on this server.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB2 and SMB3 have been disabled on this server.  This results in reduced functionality and performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: Smb2
Default Value: 1 (or not present)
Current Value: 0

Guidance:

You should expect this event when disabling SMB2/SMB3. Microsoft does not recommend disabling SMB2/SMB3. When SMB3 is disabled, you cannot use features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. In most scenarios, SMB provides a troubleshooting workaround as an alternative to disabling SMB2/SMB3. Use the Set-SmbServerConfiguration Windows PowerShell cmdlet to enable SMB2/SMB3.

Event ID 1025 — One or more named pipes or shares have been marked for access by anonymous users.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
3
Samples
1

Message

One or more named pipes or shares have been marked for access by anonymous users.  This increases the security risk of the computer by allowing unauthenticated users to connect to this server.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Values: NullSessionPipes, NullSessionShares
Default Value: Empty (or not present)
Current Value: Non-empty

Guidance:

You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods.

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1025
  version: 0
  level: 3
  task: 1025
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-06T06:25:44.207725+00:00'
  event_record_id: 96
  correlation: {}
  execution:
    process_id: 3912
    thread_id: 3512
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
user_data:
  EventData: {}
message: ''

References

Event ID 1026 — File leasing has been disabled for the SMB2 and SMB3 protocols.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

File leasing has been disabled for the SMB2 and SMB3 protocols.  This reduces functionality and can decrease performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: DisableLeasing
Default Value: 0 (or not present)
Current Value: non-zero

Guidance:

You should expect this event when disabling SMB 3 Leasing. Microsoft does not recommend disabling SMB Leasing. Once disabled, traffic from client to server may increase since metadata and data may no longer be retrieved from a local cache.

Event ID 1027 — The file and printer sharing firewall ports are currently closed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

The file and printer sharing firewall ports are currently closed.  This is the default configuration for a system that is not sharing content or is on a Public network.

Guidance:

You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer until SMB traffic is allowed through the firewall.

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1027
  version: 0
  level: 4
  task: 1027
  opcode: 0
  keywords: 2305843009213693960
  time_created: '2023-11-05T22:32:38.630794+00:00'
  event_record_id: 124
  correlation: {}
  execution:
    process_id: 3368
    thread_id: 3592
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
user_data:
  EventData: {}
message: ''

References

Event ID 1028 — The maximum cluster-supported SMB dialect has changed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The maximum cluster-supported SMB dialect has changed.

NewMaxDialect: %1
OldMaxDialect: %2

Guidance:

You should expect this event during a Windows Failover Cluster upgrade. No user action is required.

Fields

NameDescription
NewDialect
OldDialect

Event ID 1029 — The Cipher Suite Order group policy setting is invalid.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The Cipher Suite Order group policy setting is invalid.

Guidance:

This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher Suite Order" group policy setting. The server will use the default cipher suite order "%1" until this error is resolved.

Fields

NameDescription
CipherSuiteOrder

Event ID 1030 — An MDL read or write completion request failed.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

An MDL read or write completion request failed.

Server Name: %2
Share Name: %4
File Name: %6
IsRead: %7
Status: %8

Guidance:

The SMB server sends MDL completion requests to a file system upon completion of a buffered I/O to release system resources. The file system and its filter drivers must not fail MDL completion requests. Failures may result in memory leaks and degraded system performance and stability. Non-Microsoft file system filter drivers are the most common cause of failed MDL completion requests.

Fields

NameDescription
ServerNameLength
ServerName
ShareNameLength
ShareName
FileNameLength
FileName
IsRead
Status

Event ID 1031 — The server detected a problem and has captured a live kernel dump to collect debug information.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server detected a problem and has captured a live kernel dump to collect debug information.

Reason: %1
Dump Location: %SystemRoot%\LiveKernelReports

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields

NameDescription
Reason

Event ID 1032 — The server detected a problem but was unable to capture a live kernel dump to collect debug information.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server detected a problem but was unable to capture a live kernel dump to collect debug information.

Reason: %1

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. In this case, the server's request to create a live kernel dump was rejected. This is usually due to the live kernel dump throttle, which prevents frequent dumps from consuming too much disk space. Either wait for the throttle limit to expire (by default, 7 days), or contact Microsoft Support for steps to override the throttle. This event is written to the log no more than once per day. The problem that caused the server to the request a live kernel dump may be occuring more frequently.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields

NameDescription
Reason

Event ID 1033 — Sent RDMA .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
NotificationType
InterfaceNameLength
InterfaceName

Event ID 1033 — Sent RDMA %1 event to LanmanServer for interface %3.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

Sent RDMA %1 event to LanmanServer for interface %3.

Fields

NameDescription
EventData.NotificationType
EventData.InterfaceNameLength
EventData.InterfaceName

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1033
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213694464
  time_created: '2023-10-26T04:17:52.198363+00:00'
  event_record_id: 18
  correlation: {}
  execution:
    process_id: 4
    thread_id: 436
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WIN-OQ6R0RVA4NF
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    NotificationType: 0
    InterfaceNameLength: 34
    InterfaceName: \Device\RdmaSmbIpv4_169.254.253.61
message: ''

References

Event ID 1034 — Send RDMA Endpoint notification failure - .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
FailureType
InterfaceIndex
Error
DeviceNameLength
DeviceName
ExtraInformation

Event ID 1034 — Send RDMA Endpoint notification failure - %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

Send RDMA Endpoint notification failure - %1

Fields

NameDescription
EventData.FailureType
EventData.InterfaceIndex
EventData.Error
EventData.DeviceNameLength
EventData.DeviceName
EventData.ExtraInformation

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1034
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213694464
  time_created: '2023-10-26T04:17:52.198365+00:00'
  event_record_id: 19
  correlation: {}
  execution:
    process_id: 4
    thread_id: 436
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WIN-OQ6R0RVA4NF
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    FailureType: 6
    InterfaceIndex: 0
    Error: '0xc0000034'
    DeviceNameLength: 34
    DeviceName: \Device\RdmaSmbIpv4_169.254.253.61
    ExtraInformation: 0
message: ''

References

Event ID 1035 — RDMA Endpoint %4 for interface %2 was %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA Endpoint %4 for interface %2 was %1.

Fields

NameDescription
EndpointState
InterfaceIndex
TransportNameLength
TransportName

Event ID 1035 — RDMA Endpoint .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
EndpointState
InterfaceIndex
TransportNameLength
TransportName

Event ID 1036 — RDMA Endpoint allocation failure - Endpoint allocation failed for interface .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
InterfaceIndex
Error

Event ID 1036 — RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2

Fields

NameDescription
InterfaceIndex
Error

Event ID 1037 — RDMA listener creation failure - .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
FailureType
InterfaceIndex
Error

Event ID 1037 — RDMA listener creation failure - %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA listener creation failure - %1

Fields

NameDescription
FailureType
InterfaceIndex
Error

Event ID 1038 — RDMA Send endpoint notification RPC failure for device .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
FailureType
DeviceNameLength
DeviceName
Error

Event ID 1038 — RDMA Send endpoint notification RPC failure for device %3 - %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

RDMA Send endpoint notification RPC failure for device %3 - %1

Fields

NameDescription
EventData.FailureType
EventData.DeviceNameLength
EventData.DeviceName
EventData.Error

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1038
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213694464
  time_created: '2023-11-06T06:25:49.867686+00:00'
  event_record_id: 98
  correlation: {}
  execution:
    process_id: 4
    thread_id: 428
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    FailureType: 3
    DeviceNameLength: 58
    DeviceName: \Device\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}
    Error: '0x102'
message: ''

References

Event ID 1039 — Received Nsi notification type .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
NotificationType
InterfaceIndex
NdkOperationalState

Event ID 1039 — Received Nsi notification type %1 for interface %2 with NdkOperationalState %3.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Received Nsi notification type %1 for interface %2 with NdkOperationalState %3

Fields

NameDescription
NotificationType
InterfaceIndex
NdkOperationalState

Event ID 1040 — Received Mib notification type .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
NotificationType
InterfaceIndex

Event ID 1040 — Received Mib notification type %1 for interface %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

Received Mib notification type %1 for interface %2

Fields

NameDescription
EventData.NotificationType
EventData.InterfaceIndex

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1040
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213694464
  time_created: '2023-11-05T22:32:37.991590+00:00'
  event_record_id: 123
  correlation: {}
  execution:
    process_id: 4
    thread_id: 136
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
user_data:
  EventData:
    NotificationType: 3
    InterfaceIndex: 0
message: ''

References

Event ID 1041 — Error reading FSCTL properties information from the registry.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Error reading FSCTL properties information from the registry. Registry value entry %3 will be ignored. Error: %1

Fields

NameDescription
FailureType
RegistryValueNameLength
RegistryValueName

Event ID 1042 — The certificate for the server is about to expire.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The certificate for the server is about to expire. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate is about to expire. 

Renew or issue new certificates to avoid service interruption.

Fields

NameDescription
CertSubjectNameLength
CertSubjectName
CertThumbprintLength
CertThumbprint
Expiring

Event ID 1043 — RDMA connection disconnected.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA connection disconnected.

Transport name: %3
Milliseconds spent closing the connection: %1

Guidance:

Closing an RDMA connection should not take longer than 2 minutes. An RDMA IO that takes an abnormally long time to complete indicates a problem with the RDMA network adapters on this computer or its remote host. Contact your RDMA vendor for an updated driver and further troubleshooting.

Fields

NameDescription
CloseOperationDurationInMillieconds
TransportNameLength
TransportName
EndpointShutdown
EndpointRemoved

Event ID 1044 — Quic connection shutdown.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Quic connection shutdown.

Error: %1
Reason: %2
Endpoint Name: %4
Transport Name: %6

Guidance:

This event indicates that the winquic connection is shutting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections.

Fields

NameDescription
ErrorCode
Reason
EndpointNameLength
EndpointName
TransportNameLength
TransportName

Event ID 1045 — The server failed to update server certificate mapping.

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
ServerNameLength
ServerName
SubjectLength
Subject
ThumbPrintLength
ThumbPrint
Status
RemovedLength
Removed

Event ID 1045 — The server failed to update server certificate mapping.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server failed to update server certificate mapping.

Name: %2
Subject: %4
Thumbprint: %6

The certificate can't be used for the server due to error %7

The server certificate mapping %9 removed.

Fields

NameDescription
ServerNameLength
ServerName
SubjectLength
Subject
ThumbPrintLength
ThumbPrint
Status
RemovedLength
Removed

Event ID 1046 — The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access.

Request: %10
Client Name: %4
Client Address: %8
User Name: %6
Session ID: %9
Share Name: %2

Guidance:

This event indicates that client is trying to access a server that requires encryption, but no cipher was negotiated, and server does not allow unencrypted access. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\RejectUnencryptedAccess to see if the value has been changed.

Fields

NameDescription
ShareNameLength
ShareName
ClientNameLength
ClientName
UserNameLength
UserName
ClientAddressLength
ClientAddress
SessionID
Smb2Command

Event ID 1047 — The server received a %2 request but is taking an abnormal amount of time to process it.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server received a %2 request but is taking an abnormal amount of time to process it.

Instance Id: %1
Command: %2
PerfBlock: %3
Duration(s): %4
Threshold(s): %5

Fields

NameDescription
InstanceId
Smb2Command
Smb2PerfBlock
Duration
Threshold

Event ID 1048 — The server processed a %1 request.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server processed a %1 request. Times taken to complete each stage below.

Command: %1
AcquireLockTime(s): %2
IoTime(s): %3
TotalTime(s): %4
Threshold(s): %5

Fields

NameDescription
Smb2Command
AcquireLockTime
IoTime
TotalTime
Threshold

Event ID 1049 — The certificate for the server has expired.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The certificate for the server has expired. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate has expired. 

Renew or issue new certificates to avoid service interruption.

Fields

NameDescription
CertSubjectNameLength
CertSubjectName
CertThumbprintLength
CertThumbprint
Expiring

Event ID 1050 — Found %1 endpoint(s) related to interface ID %2, closed %3 of which.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Found %1 endpoint(s) related to interface ID %2, closed %3 of which.

Fields

NameDescription
InterfaceID
NumberOfEndpointsFound
NumberOfEndpointsClosed

Event ID 1051 — The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Client encryption cipher suite order (most to least preferred): %2
Server encryption cipher suite order (most to least preferred): %4

Fields

NameDescription
ClientCipherSuiteOrderLength
ClientCipherSuiteOrder
ServerCipherSuiteOrderLength
ServerCipherSuiteOrder
ClientCipherCount
LoggedClientCipherCount
ClientCipherOrder

Event ID 1052 — Failed to restore a server certificate mapping from persistent storage.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Failed to restore a server certificate mapping from persistent storage.

Subject: %2
Thumbprint: %4

Error code: %5.

Fields

NameDescription
SubjectLength
Subject
ThumbprintLength
Thumbprint
Status

Event ID 1053 — Restored %2 of %1 server certificate mappings from persistent storage.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Restored %2 of %1 server certificate mappings from persistent storage. Last error code: %3.

Fields

NameDescription
CountOfCertsTotal
CountOfCertsRestored
Status

Event ID 1054 — Network operation has taken longer than expected.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Network operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields

NameDescription
Command
SessionGuid
SessionId
ConnectionGuid
UserNameLength
UserName
ClientNameLength
ClientName
ClientAddressLength
ClientAddress
ShareNameLength
ShareName
FileNameLength
FileName
DurationInMilliseconds
ThresholdInMilliseconds
CtlCode
SubCode
TunneledControl

Event ID 1055 — RDMA rundown is active.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources.

Fields

NameDescription
ActiveRdmaResourceCount

Event ID 1056 — RDMA rundown is complete.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1.

Fields

NameDescription
NoOp

Event ID 1057 — Reactivation of RDMA support has commenced.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Reactivation of RDMA support has commenced.

Event ID 1058 — RDMA is no longer disabled.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1.

Fields

NameDescription
NoOp

Event ID 1059 — SMBDirect load attempt complete.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMBDirect load attempt complete.

Success: %1
Status code: %2
Service path: %4

Fields

NameDescription
IsSuccess
LoadStatus
ServicePathLength
ServicePath
DeviceNameLength
DeviceName

Event ID 1060 — SMB DDP security changed from %1 to %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB DDP security changed from %1 to %2.

Fields

NameDescription
OldValue
NewValue

Event ID 1061 — SMB2 Request Negotiate Dialect Failure Session ID: %1 Client Address: %18 Client Name:%20 Client Dialects: %12 Minimum dialect required by server: ...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB2 Request Negotiate Dialect Failure

Session ID: %1
Client Address: %18
Client Name:%20
Client Dialects: %12
Minimum dialect required by server: %15
Maximum dialect required by server: %16

Guidance:

You should expect this error when servers don't meet the dialects requested by client. Please check the minimum and maximum dialects set by the client and ensure the server supports the dialects.

Fields

NameDescription
SessionId
ProcessId
TreeId
MessageId
MasterMessageId
Command
CreditsRequested
Flags
SecurityMode
Capabilities
DialectCount
Dialects
ClientGuid
ConnectionGUID
MinSmb2Dialect
MaxSmb2Dialect
ClientAddressLength
ClientAddress
ClientNameLength
ClientName

Event ID 1062 — SMB Dialect Change %1 was changed from %2 to %3.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB Dialect Change 

%1 was changed from %2 to %3.

Fields

NameDescription
SmbDialect
OldDialect
NewDialect

Event ID 1080 — Component capabilities: %1 Internal patch number: %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Component capabilities: %1
Internal patch number: %2

Fields

NameDescription
SrvNetComponentCapabilities
PatchNumber

Event ID 1800 — CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Event ID 1801 — CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.

Event ID 1802 — The server failed to reserve the next ID region in the cluster registry.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Message

The server failed to reserve the next ID region in the cluster registry.

Event ID 1803 — The security descriptor differs from the default value.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The security descriptor differs from the default value.

 Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity\%1

 Guidance:

 This is typically caused by an administrator or a third party changing the security on the object manually. To reset the security back to the default value, delete the path shown above.
 Microsoft does not recommend changing the default security of %1 as it may cause application incompatibilities or security concerns.

Fields

NameDescription
DescriptorName

Event ID 1804 — No SMB1 usage detected in the last 20 minutes.

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Message

No SMB1 usage detected in the last 20 minutes.

Guidance:

This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Server service will automatically uninstall.

Fields

NameDescription
Days

Event ID 1900 — TDI mode enabled: .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
IsTdiEnabled

Event ID 1900 — TDI mode enabled.

Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Samples
1

Message

TDI mode enabled: %1

Fields

NameDescription
IsTdiEnabled

Example Event

system:
  provider: Microsoft-Windows-SMBServer
  guid: D48CE617-33A2-4BC3-A5C7-11AA4F29619E
  event_source_name: ''
  event_id: 1900
  version: 0
  level: 4
  task: 0
  opcode: 0
  keywords: 2305843009213694464
  time_created: '2023-11-06T06:25:43.357313+00:00'
  event_record_id: 95
  correlation: {}
  execution:
    process_id: 4
    thread_id: 224
  channel: Microsoft-Windows-SMBServer/Operational
  computer: WinDev2310Eval
  security:
    user_id: S-1-5-18
event_data:
  IsTdiEnabled: true
message: ''

References

Event ID 1901 — Failed to allocate an NSI table for network interface enumeration: .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
Status

Event ID 1901 — Failed to allocate an NSI table for network interface enumeration.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Failed to allocate an NSI table for network interface enumeration: %1

Fields

NameDescription
Status

Event ID 1902 — Received notification of a newly-started network interface with Luid .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
AddressFamily
NetLuid

Event ID 1902 — Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23).

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields

NameDescription
AddressFamily
NetLuid

Event ID 1903 — Received notification of a stopped network interface with Luid .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
AddressFamily
NetLuid

Event ID 1903 — Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23).

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields

NameDescription
AddressFamily
NetLuid

Event ID 1904 — Failed to open network interface with Luid .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
NetLuid
Status

Event ID 1904 — Failed to open network interface with Luid %1: error %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Failed to open network interface with Luid %1: error %2

Fields

NameDescription
NetLuid
Status

Event ID 1905 — The server closed the session as part of periodic system cleanup.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server closed the session as part of periodic system cleanup.

Session Id: %1
Instance Id: %2
Reason: %3

Fields

NameDescription
SessionId
InstanceId
Reason

Event ID 1906 — Session key for connection is weaker than required.

Provider
Microsoft-Windows-SMBServer
Channel
Security

Message

Session key for connection is weaker than required. Connection will be closed as a result.

Client: %2
User: %6
Session key length: %3
Required Session key length: %4

Guidance:
To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters]
"MinimumSessionKeyLength"

Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM.

Fields

NameDescription
ClientNameLength
ClientName
SessionKeyLength
RequiredSessionKeyLength
SessionId
UserName
AuthProtocol

Event ID 1907 — Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Message

Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

Event ID 1908 — Custom FSCTL allow list was not successfully loaded after several retries.

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Message

Custom FSCTL allow list was not successfully loaded after several retries.

Event ID 1909 — Send QUIC Endpoint notification failure - .

Provider
Microsoft-Windows-SMBServer
Channel
Analytic

Fields

NameDescription
FailureType
InterfaceIndex
Error
DeviceNameLength
DeviceName
ExtraInformation

Event ID 1909 — Send QUIC Endpoint notification failure - %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Send QUIC Endpoint notification failure - %1

Fields

NameDescription
FailureType
InterfaceIndex
Error
DeviceNameLength
DeviceName
ExtraInformation

Event ID 1910 — RDMA listen socket disable override is %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

RDMA listen socket disable override is %1. New value is %2. SrvNetIsRDMASupportEnabled is %3. Action taken %4.

Fields

NameDescription
CurrentDisableOverrideState
NewState
SrvNetEnableRdmaSupport
SrvNetEvaluateRdmaEnabledPolicy
SrvNetIsSMBDirectSupported
ActionTaken

Event ID 1911 — Server Certificate failure - %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Server Certificate failure - %1

Fields

NameDescription
FailureType
Error
MappingNameLength
MappingName
ThumprintLength
Thumbprint

Event ID 1912 — Warning to set the QoS policy on file %6.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

Warning to set the QoS policy on file %6.
Status=%1

Fields

NameDescription
Status
ServerNameLength
ServerName
ShareNameLength
ShareName
FileNameLength
FileName

Event ID 1913 — The SMB connection was successfully established.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB connection was successfully established.

Endpoint Name: %2
Transport: %3
Server socket address: %5
Client socket address: %7
Connection ID: %9
Mutual authentication: %10
Access control: %11

Fields

NameDescription
EndpointNameLength
EndpointName
ConnectionType
ServerSocketAddressLength
ServerSocketAddress
ClientSocketAddressLength
ClientSocketAddress
ConnectionIdSize
ConnectionId
MutualAuthentication
AccessControlCheck

Event ID 1914 — The server was unable to perform revocation checks on the client certificate chain.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. 

Verification Status: %1

Endpoint Name: %3
Transport: %4
Server socket address: %6
Client socket address: %8
Connection ID: %10

Fields

NameDescription
Status
EndpointNameLength
EndpointName
ConnectionType
TransportNameLength
TransportName
ClientSocketAddressLength
ClientSocketAddress

Event ID 2000 — Packet Fragment ({FragmentSize} bytes).

Provider
Microsoft-Windows-SmbServer
Channel
Diagnostic

Message

Packet Fragment ({FragmentSize} bytes)

Fields

NameDescription
FragmentSize

Event ID 3000 — SMB1 access Client Address: %1 Guidance: This event indicates that a client attempted to access the server using SMB1.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

SMB1 access

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields

NameDescription
ClientName

Event ID 3002 — A remote device attempted SMB1 connection to this computer.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

A remote device attempted SMB1 connection to this computer.

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields

NameDescription
ClientName

Event ID 3003 — SMB1 server service has been automatically uninstalled.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

SMB1 server service has been automatically uninstalled.n
Guidance:

This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Server service was automatically uninstalled.

Fields

NameDescription
Days

Event ID 3004 — SMB server admin file rundown

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB server admin file rundown

Fields

NameDescription
FileId
FileNameLength
FileName
SessionId
ShareId

Event ID 3005 — SMB server admin session rundown

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB server admin session rundown

Fields

NameDescription
SessionId
ComputerNameLength
ComputerName
UserNameLength
UserName
DomainNameLength
DomainName
DomainAndUserNameLength
DomainAndUserName
ClientOsLength
ClientOs
TransportNameLength
TransportName
ServerNameLength
ServerName
StartTime
LastActiveTime

Event ID 3006 — SMB server admin share rundown

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

SMB server admin share rundown

Fields

NameDescription
ShareId
ShareNameLength
ShareName

Event ID 3007 — Access Denied Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny en...

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

Access Denied

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808

Fields

NameDescription
ServerNameLength
ServerName
ClientSocketAddressLength
ClientSocketAddress
SupportedHashAlgsStrLength
SupportedHashAlgsStr
CertChainPropertiesStrLength
CertChainPropertiesStr
DenySidsStrLength
DenySidsStr
AllowSidsStrLength
AllowSidsStr
ConnectionIdSize
ConnectionId

Event ID 3008 — Access Allowed Server certificate mapping name: %2 Client socket address: %4 Client certificate chain: Subject, Issuer, Serial Number, %6 %8 Deny e...

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

Access Allowed

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809

Fields

NameDescription
ServerNameLength
ServerName
ClientSocketAddressLength
ClientSocketAddress
SupportedHashAlgsStrLength
SupportedHashAlgsStr
CertChainPropertiesStrLength
CertChainPropertiesStr
DenySidsStrLength
DenySidsStr
AllowSidsStrLength
AllowSidsStr
ConnectionIdSize
ConnectionId

Event ID 3009 — An error occurred while checking client certificate chain access during mutual authentication.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1

Server certificate mapping name: %3
Client socket address: %5

Guidance:

For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709

Fields

NameDescription
Error
ServerNameLength
ServerName
ClientSocketAddressLength
ClientSocketAddress
ConnectionIdSize
ConnectionId

Event ID 3010 — An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0?

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0?1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields

NameDescription
Port

Event ID 3011 — The SMB server service created an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvInstances: ...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB server service created an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5

Guidance:

You should expect this event when assigning alternative SMB server listener ports and on any subsequent restarts of the SMB server service.

Fields

NameDescription
TransportNameLength
TransportName
Port
TransportType
SrvInstances
Status

Event ID 3012 — The SMB server service failed to create an endpoint with the following listener rule entry settings: Transport: %2 Port: %3 TransportType: %4 SrvIn...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB server service failed to create an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5
Error: %6

Guidance:

This error is usually caused by another process already listening on the same IP address and port. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields

NameDescription
TransportNameLength
TransportName
Port
TransportType
SrvInstances
Status

Event ID 3013 — An administrator created an alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clients can ...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

An administrator created an alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this alternative SMB server listener port.

Fields

NameDescription
Port
TransportType
SrvInstances

Event ID 3014 — An administrator updated an existing alterative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: SMB clie...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

An administrator updated an existing alterative SMB server listener port rule entry:

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this updated alternative SMB server listener port.

Fields

NameDescription
Port
TransportType
SrvInstances

Event ID 3015 — An administrator removed an existing alternative SMB server listener port rule entry: Port: %1 TransportType: %2 SrvInstances: %3 Guidance: This wi...

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

An administrator removed an existing alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

This will close the specified listening sockets for the transport type on the specified port number. SMB clients cannot connect to this SMB server on that alternative port anymore.

Fields

NameDescription
Port
TransportType
SrvInstances

Event ID 3016 — The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields

NameDescription
Interface
Status

Event ID 3017 — The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields

NameDescription
Interface
Status

Event ID 3018 — The inbound %2 firewall rule already exists for port %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The inbound %2 firewall rule already exists for port %1.

Fields

NameDescription
Port
ProtocolType

Event ID 3019 — The inbound %2 firewall rule failed to be created for port %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The inbound %2 firewall rule failed to be created for port %1.

Fields

NameDescription
Port
ProtocolType

Event ID 3020 — The inbound %2 firewall rule was successfully created for port %1.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The inbound %2 firewall rule was successfully created for port %1.

Fields

NameDescription
Port
ProtocolType

Event ID 3021 — The SMB server observed that the client doesn't support signing.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMB server observed that the client doesn't support signing.

Client name: %2
Server requires signing: %3

Fields

NameDescription
ClientNameLength
ClientName
UserNameLength
UserName
ServerRequiresSigning

Event ID 3022 — The SMB server observed that the client doesn't support encryption.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMB server observed that the client doesn't support encryption.

Client name: %2
Server requires encryption: %3

Fields

NameDescription
ClientNameLength
ClientName
ServerRequiresEncryption
SmbClientDoesNotSupportEncryptionType

Event ID 3023 — The SMB client was logged on as Guest account.

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Message

The SMB client was logged on as Guest account.

Client name: %2

Fields

NameDescription
ClientNameLength
ClientName

Event ID 3024 —

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Fields

NameDescription
ClientNameLength
ClientName
Status
SPNValidationPolicy

Event ID 3024 — The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection ...

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled.

Client name: %2
SPN Query Status: %3
SPN Validation Policy: %4

Fields

NameDescription
ClientNameLength
ClientName
Status
SPNValidationPolicy

Event ID 3025 —

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Fields

NameDescription
ClientNameLength
ClientName
SPN
ServiceClassIsValid
PrincipalNameIsValid
SPNValidationPolicy

Event ID 3025 — The SMB server observed that the client sent an unrecognized SPN during authentication.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMB server observed that the client sent an unrecognized SPN during authentication.

Client name: %2
SPN: %3
SPN Validation Policy: %6

Fields

NameDescription
ClientNameLength
ClientName
SPN
ServiceClassIsValid
PrincipalNameIsValid
SPNValidationPolicy

Event ID 3026 —

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Fields

NameDescription
ClientNameLength
ClientName
SPNValidationPolicy

Event ID 3026 — The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but electe...

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Client name: %2
SPN Validation Policy: %3

Fields

NameDescription
ClientNameLength
ClientName
SPNValidationPolicy

Event ID 3027 —

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Fields

NameDescription
ClientNameLength
ClientName
ServerRequiresSigning

Event ID 3027 — The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Provider
Microsoft-Windows-SMBServer
Channel
Audit

Message

The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Client name: %2
Server requires signing: %3

Guidance:

This event indicates that the SMBv1 client may not support SMB signing, but due to protocol limitations, this cannot be determined with certainty. Further evaluation is recommended to verify the client's signing capabilities.

Prior to Windows Vista, SMBv1 clients that did not have signing explicitly enabled could not perform SMB signing.
This behavior was changed with the release of Windows Vista and was also backported to Windows XP and Windows Server 2003 through updates. With these changes, SMB clients may support signing even if it is not explicitly enabled, provided the server requires it.

Fields

NameDescription
ClientNameLength
ClientName
ServerRequiresSigning

Event ID 4000 —

Provider
Microsoft-Windows-SMBServer
Channel
Operational

Fields

NameDescription
ShareNameLength
ShareName
ClientAddressLength
ClientAddress
ClientNameLength
ClientName
SessionId
TreeId
ConnectionType
SigningUsed
EncyptionUsed
CompressionUsed

Sigma Rules

Event ID 4000 — The SMB client connection to the share was established.

Provider
Microsoft-Windows-SMBServer
Channel
Connectivity

Message

The SMB client connection to the share was established.

Share name: %2
Client name: %6
Client address: %4
Session ID: %7
Tree ID: %8
Transport type: %9
Signing used: %10
Encryption used: %11
Compression activated: %12

Fields

NameDescription
ShareNameLength
ShareName
ClientAddressLength
ClientAddress
ClientNameLength
ClientName
SessionId
TreeId
ConnectionType
SigningUsed
EncyptionUsed
CompressionUsed

Event ID 40000 — Packet ({PacketSize} bytes).

Provider
Microsoft-Windows-SmbServer
Channel
Diagnostic

Message

Packet ({PacketSize} bytes)

Fields

NameDescription
PacketSize