Microsoft-Windows-SmbServer

79 events across 4 channels

Event IDTitleChannel
1Smb2 Request NegotiatePerformance
2Smb2 Request Session SetupPerformance
3Smb2 Request LogoffPerformance
4Smb2 Request Tree ConnectPerformance
5Smb2 Request Tree DisconnectPerformance
6Smb2 Request EchoPerformance
7Smb2 Request CancelPerformance
8Smb2 Request CreatePerformance
9Smb2 Request ClosePerformance
10Smb2 Request FlushPerformance
11Smb2 Request ReadPerformance
12Smb2 Request WritePerformance
13Smb2 Request Break OplockPerformance
14Smb2 Request Notify Break LeasePerformance
15Smb2 Request Acknowledge Break LeasePerformance
16Smb2 Request LockPerformance
17Smb2 Request IoctlPerformance
18Smb2 Request Query DirectoryPerformance
19Smb2 Request Change NotifyPerformance
20Smb2 Request Query InfoPerformance
21Smb2 Request Set InfoPerformance
101Smb2 Response NegotiatePerformance
102Smb2 Response Session SetupPerformance
103Smb2 Response LogoffPerformance
104Smb2 Response Tree ConnectPerformance
105Smb2 Response Tree DisconnectPerformance
106Smb2 Response EchoPerformance
108Smb2 Response CreatePerformance
109Smb2 Response ClosePerformance
110Smb2 Response FlushPerformance
111Smb2 Response ReadPerformance
112Smb2 Response WritePerformance
113Smb2 Response Break OplockPerformance
115Smb2 Response Acknowledge Break LeasePerformance
116Smb2 Response LockPerformance
117Smb2 Response IoctlPerformance
118Smb2 Response Query DirectoryPerformance
119Smb2 Response Change NotifyPerformance
120Smb2 Response Query InfoPerformance
121Smb2 Response Set InfoPerformance
122Smb2 Response ErrorPerformance
200Smb2 Work Item Component TransitionPerformance
201Smb2 Work Item allocatedPerformance
202Smb2 Work Item releasedPerformance
500Smb2 Connection acceptedAnalytic
501Smb2 Connection Disconnected by PeerAnalytic
502Smb2 Connection TerminatedAnalytic
550Smb2 Session AllocatedAnalytic
551Smb2 Session Authentication FailureAnalytic
552Smb2 Session Authentication SuccessAnalytic
553Smb2 Session Bound to ConnectionAnalytic
554Smb2 Session TerminatedAnalytic
600Smb2 TreeConnect AllocatedAnalytic
601Smb2 TreeConnect DisconnectedAnalytic
602Smb2 TreeConnect TerminatedAnalytic
603Smb2 TreeConnect Failed due to Cluster Endpoint InitializingAnalytic
650Smb2 Open establishedAnalytic
651Smb2 Open Disconnected - PreservedAnalytic
652Smb2 Open ReconnectedAnalytic
653Smb2 Open Suspended - PreservedAnalytic
654Smb2 Open ClosedAnalytic
655Smb2 Open Timed OutAnalytic
656Smb2 Open TerminatedAnalytic
657Smb2 Open Clustered Client Failover ClosedAnalytic
658File handle for file {ShareName}\{FileName} was invalidated by user {UserName} …Operational
700Smb2 Share AddedAnalytic
701Smb2 Share ModifiedAnalytic
702Smb2 Share DeletedAnalytic
1000S4U2Self authentication failure - The client could not be reauthenticated with …Operational
1001SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.Operational
1002RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for …Operational
1003The server received an unencrypted message from client {ClientName}.Operational
1004The server received a incorrectly signed message from client {ClientName}.Operational
1005The server failed to validate negotiation from client {ClientName}.Operational
1800CA failure - Failed to set continuously available property on a new or existing …Operational
1801CA failure - Failed to set continuously available property on a new or existing …Operational
1802The server failed to reserve the next ID region in the cluster registry.Operational
2000Packet Fragment ({FragmentSize} bytes).Diagnostic
40000Packet ({PacketSize} bytes).Diagnostic

Event ID 1 — Smb2 Request Negotiate

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Negotiate.

Message #

Smb2 Request Negotiate

Event ID 2 — Smb2 Request Session Setup

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Session Setup.

Message #

Smb2 Request Session Setup

Event ID 3 — Smb2 Request Logoff

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Logoff.

Message #

Smb2 Request Logoff

Event ID 4 — Smb2 Request Tree Connect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Tree Connect.

Message #

Smb2 Request Tree Connect

Event ID 5 — Smb2 Request Tree Disconnect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Tree Disconnect.

Message #

Smb2 Request Tree Disconnect

Event ID 6 — Smb2 Request Echo

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Echo.

Message #

Smb2 Request Echo

Event ID 7 — Smb2 Request Cancel

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Cancel.

Message #

Smb2 Request Cancel

Event ID 8 — Smb2 Request Create

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Create.

Message #

Smb2 Request Create

Event ID 9 — Smb2 Request Close

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Close.

Message #

Smb2 Request Close

Event ID 10 — Smb2 Request Flush

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Flush.

Message #

Smb2 Request Flush

Event ID 11 — Smb2 Request Read

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Read.

Message #

Smb2 Request Read

Event ID 12 — Smb2 Request Write

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Write.

Message #

Smb2 Request Write

Event ID 13 — Smb2 Request Break Oplock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Break Oplock.

Message #

Smb2 Request Break Oplock

Event ID 14 — Smb2 Request Notify Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Notify Break Lease.

Message #

Smb2 Request Notify Break Lease

Event ID 15 — Smb2 Request Acknowledge Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Acknowledge Break Lease.

Message #

Smb2 Request Acknowledge Break Lease

Event ID 16 — Smb2 Request Lock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Lock.

Message #

Smb2 Request Lock

Event ID 17 — Smb2 Request Ioctl

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Ioctl.

Message #

Smb2 Request Ioctl

Event ID 18 — Smb2 Request Query Directory

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Query Directory.

Message #

Smb2 Request Query Directory

Event ID 19 — Smb2 Request Change Notify

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Change Notify.

Message #

Smb2 Request Change Notify

Event ID 20 — Smb2 Request Query Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Query Info.

Message #

Smb2 Request Query Info

Event ID 21 — Smb2 Request Set Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Request Set Info.

Message #

Smb2 Request Set Info

Event ID 101 — Smb2 Response Negotiate

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Negotiate.

Message #

Smb2 Response Negotiate

Event ID 102 — Smb2 Response Session Setup

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Session Setup.

Message #

Smb2 Response Session Setup

Event ID 103 — Smb2 Response Logoff

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Logoff.

Message #

Smb2 Response Logoff

Event ID 104 — Smb2 Response Tree Connect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Tree Connect.

Message #

Smb2 Response Tree Connect

Event ID 105 — Smb2 Response Tree Disconnect

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Tree Disconnect.

Message #

Smb2 Response Tree Disconnect

Event ID 106 — Smb2 Response Echo

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Echo.

Message #

Smb2 Response Echo

Event ID 108 — Smb2 Response Create

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Create.

Message #

Smb2 Response Create

Event ID 109 — Smb2 Response Close

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Close.

Message #

Smb2 Response Close

Event ID 110 — Smb2 Response Flush

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Flush.

Message #

Smb2 Response Flush

Event ID 111 — Smb2 Response Read

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Read.

Message #

Smb2 Response Read

Event ID 112 — Smb2 Response Write

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Write.

Message #

Smb2 Response Write

Event ID 113 — Smb2 Response Break Oplock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Break Oplock.

Message #

Smb2 Response Break Oplock

Event ID 115 — Smb2 Response Acknowledge Break Lease

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Acknowledge Break Lease.

Message #

Smb2 Response Acknowledge Break Lease

Event ID 116 — Smb2 Response Lock

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Lock.

Message #

Smb2 Response Lock

Event ID 117 — Smb2 Response Ioctl

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Ioctl.

Message #

Smb2 Response Ioctl

Event ID 118 — Smb2 Response Query Directory

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Query Directory.

Message #

Smb2 Response Query Directory

Event ID 119 — Smb2 Response Change Notify

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Change Notify.

Message #

Smb2 Response Change Notify

Event ID 120 — Smb2 Response Query Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Query Info.

Message #

Smb2 Response Query Info

Event ID 121 — Smb2 Response Set Info

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Set Info.

Message #

Smb2 Response Set Info

Event ID 122 — Smb2 Response Error

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Response Error.

Message #

Smb2 Response Error

Event ID 200 — Smb2 Work Item Component Transition

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Work Item Component Transition.

Message #

Smb2 Work Item Component Transition

Event ID 201 — Smb2 Work Item allocated

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Work Item allocated.

Message #

Smb2 Work Item allocated

Event ID 202 — Smb2 Work Item released

Provider
Microsoft-Windows-SmbServer
Channel
Performance

Description

Smb2 Work Item released.

Message #

Smb2 Work Item released

Event ID 500 — Smb2 Connection accepted

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Connection accepted.

Message #

Smb2 Connection accepted

Event ID 501 — Smb2 Connection Disconnected by Peer

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Connection Disconnected by Peer.

Message #

Smb2 Connection Disconnected by Peer

Event ID 502 — Smb2 Connection Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Connection Terminated.

Message #

Smb2 Connection Terminated

Event ID 550 — Smb2 Session Allocated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Session Allocated.

Message #

Smb2 Session Allocated

Event ID 551 — Smb2 Session Authentication Failure

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Session Authentication Failure.

Message #

Smb2 Session Authentication Failure

Event ID 552 — Smb2 Session Authentication Success

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Session Authentication Success.

Message #

Smb2 Session Authentication Success

Event ID 553 — Smb2 Session Bound to Connection

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Session Bound to Connection.

Message #

Smb2 Session Bound to Connection

Event ID 554 — Smb2 Session Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Session Terminated.

Message #

Smb2 Session Terminated

Event ID 600 — Smb2 TreeConnect Allocated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 TreeConnect Allocated.

Message #

Smb2 TreeConnect Allocated

Event ID 601 — Smb2 TreeConnect Disconnected

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 TreeConnect Disconnected.

Message #

Smb2 TreeConnect Disconnected

Event ID 602 — Smb2 TreeConnect Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 TreeConnect Terminated.

Message #

Smb2 TreeConnect Terminated

Event ID 603 — Smb2 TreeConnect Failed due to Cluster Endpoint Initializing

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 TreeConnect Failed due to Cluster Endpoint Initializing.

Message #

Smb2 TreeConnect Failed due to Cluster Endpoint Initializing

Event ID 650 — Smb2 Open established

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open established.

Message #

Smb2 Open established

Event ID 651 — Smb2 Open Disconnected - Preserved

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Disconnected - Preserved.

Message #

Smb2 Open Disconnected - Preserved

Event ID 652 — Smb2 Open Reconnected

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Reconnected.

Message #

Smb2 Open Reconnected

Event ID 653 — Smb2 Open Suspended - Preserved

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Suspended - Preserved.

Message #

Smb2 Open Suspended - Preserved

Event ID 654 — Smb2 Open Closed

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Closed.

Message #

Smb2 Open Closed

Event ID 655 — Smb2 Open Timed Out

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Timed Out.

Message #

Smb2 Open Timed Out

Event ID 656 — Smb2 Open Terminated

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Terminated.

Message #

Smb2 Open Terminated

Event ID 657 — Smb2 Open Clustered Client Failover Closed

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Open Clustered Client Failover Closed.

Message #

Smb2 Open Clustered Client Failover Closed

Event ID 658 — File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}.

Message #

File handle for file {ShareName}\{FileName} was invalidated by user {UserName} from computer {ComputerName}

Fields #

NameDescription
ShareName
FileName
UserName
ComputerName

Event ID 700 — Smb2 Share Added

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Share Added.

Message #

Smb2 Share Added

Event ID 701 — Smb2 Share Modified

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Share Modified.

Message #

Smb2 Share Modified

Event ID 702 — Smb2 Share Deleted

Provider
Microsoft-Windows-SmbServer
Channel
Analytic

Description

Smb2 Share Deleted.

Message #

Smb2 Share Deleted

Event ID 1000 — S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims. This may be expected if the account is not a domain account.

Message #

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.  This may be expected if the account is not a domain account.

Event ID 1001 — SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Message #

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Event ID 1002 — RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Message #

RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Event ID 1003 — The server received an unencrypted message from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

The server received an unencrypted message from client {ClientName}. Messsage was rejected.

Message #

The server received an unencrypted message from client {ClientName}. Messsage was rejected.

Fields #

NameDescription
ClientName

Event ID 1004 — The server received a incorrectly signed message from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

The server received a incorrectly signed message from client {ClientName}. Message was rejected.

Message #

The server received a incorrectly signed message from client {ClientName}. Message was rejected.

Fields #

NameDescription
ClientName

Event ID 1005 — The server failed to validate negotiation from client {ClientName}.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

The server failed to validate negotiation from client {ClientName}. Connection was terminated.

Message #

The server failed to validate negotiation from client {ClientName}. Connection was terminated.

Fields #

NameDescription
ClientName

Event ID 1800 — CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Message #

CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Event ID 1801 — CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.

Message #

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started.

Event ID 1802 — The server failed to reserve the next ID region in the cluster registry.

Provider
Microsoft-Windows-SmbServer
Channel
Operational

Description

The server failed to reserve the next ID region in the cluster registry.

Message #

The server failed to reserve the next ID region in the cluster registry.

Event ID 2000 — Packet Fragment ({FragmentSize} bytes).

Provider
Microsoft-Windows-SmbServer
Channel
Diagnostic

Description

Packet Fragment ({FragmentSize} bytes).

Message #

Packet Fragment ({FragmentSize} bytes)

Fields #

NameDescription
FragmentSize

Event ID 40000 — Packet ({PacketSize} bytes).

Provider
Microsoft-Windows-SmbServer
Channel
Diagnostic

Description

Packet ({PacketSize} bytes).

Message #

Packet ({PacketSize} bytes)

Fields #

NameDescription
PacketSize