Microsoft-Windows-SMBWitnessService
72 events across 2 channels
Event ID 1: Witness Service initialization failed with ErrorCode.
#Event ID 1:
#Description
Witness Service initialization failed with.
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 |
Event ID 2: Witness Service protocol security callback failure (Error = ErrorCode, Authentication Level = AuthenticationLevel, Authentication Service = AuthenticationService).
#Event ID 2:
#Description
Witness Service protocol security callback failure (Error = , Authentication Level = , Authentication Service = ).
Fields #
| Name | Description |
|---|---|
AuthenticationLevel UInt32 | |
AuthenticationService UInt32 | |
ErrorCode UInt32 |
Event ID 3: Witness Service received a registration request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 3:
#Description
Witness Service received a registration request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 4: Witness Service successfully registered request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 4:
#Description
Witness Service successfully registered request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 5: Witness Service registration request from Witness Client (ClientName) for NetName \\NetName failed with error (ErrorCode).
#Event ID 5:
#Description
Witness Service registration request from Witness Client () for NetName \\ failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ErrorCode Int32 |
Event ID 6: Witness Service is queuing notifications for Clients clients.
#Event ID 6:
#Description
Witness Service is queuing notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 7: Witness Service completed queuing notifications for Clients clients.
#Event ID 7:
#Description
Witness Service completed queuing notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 8: Witness Service resource notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 8:
#Description
Witness Service resource notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 9: Witness Service sent NumResources resource events to Witness Client (ClientName).
#Event ID 9:
#Description
Witness Service sent resource events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 10: Witness Service received a move client request for client (ClientName).
#Event ID 10:
#Description
Witness Service received a move client request for client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 11: Witness Service successfully sent a move request to client (ClientName).
#Event ID 11:
#Description
Witness Service successfully sent a move request to client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 12: Witness Service ignored the move client request for client (ClientName).
#Event ID 12:
#Description
Witness Service ignored the move client request for client (). Client is not registered with current Witness Service.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 13: Witness Service ignored the move client request for client (ClientName).
#Event ID 13:
#Description
Witness Service ignored the move client request for client (). Destination server () is unavailable.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ServerName UnicodeString |
Event ID 14: Witness Service reported a failure (ErrorCode) to move client (ClientName).
#Event ID 14:
#Description
Witness Service reported a failure () to move client ().
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 | |
ClientName UnicodeString |
Event ID 15: Witness Service received witness unregister request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 15:
#Description
Witness Service received witness unregister request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 16: Witness Service removed registration for Witness Client (ClientName).
#Event ID 16:
#Description
Witness Service removed registration for Witness Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 17: Witness Service shutdown failed with error (ErrorCode).
#Event ID 17:
#Description
Witness Service shutdown failed with error ().
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 |
Event ID 18: Witness Service successfully sent the list of Witness Servers to Client (ClientName).
#Event ID 18:
#Description
Witness Service successfully sent the list of Witness Servers to Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 19: Witness Service is retrying to process the list of Witness Servers to Client (ClientName).
#Event ID 19:
#Description
Witness Service is retrying to process the list of Witness Servers to Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 20: Witness Service failed to process the list of Witness Servers for Client (ClientName) with error (ErrorCode).
#Event ID 20:
#Description
Witness Service failed to process the list of Witness Servers for Client () with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 21: Witness Service failed to move client (ClientName).
#Event ID 21:
#Description
Witness Service failed to move client (). Client name is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 22: Witness Service failed to move client (ClientName).
#Event ID 22:
#Description
Witness Service failed to move client (). Destination node () is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
DestinationNode UnicodeString |
Event ID 23: Witness Service failed to move client (ClientName) to destination node (DestinationNode).
#Event ID 23:
#Description
Witness Service failed to move client () to destination node (). NetName () is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
DestinationNode UnicodeString | |
NetName UnicodeString |
Event ID 24: Witness Service received a registration request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 24:
#Description
Witness Service received a registration request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 25: Witness Service successfully registered request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 25:
#Description
Witness Service successfully registered request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 26: Witness Service registration request from Witness Client (ClientName) for \\NetName\ShareName failed with error (ErrorCode).
#Event ID 26:
#Description
Witness Service registration request from Witness Client () for \\\ failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString | |
ErrorCode Int32 |
Event ID 27: Witness Service received witness unregister request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 27:
#Description
Witness Service received witness unregister request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 28: Witness Service is queuing share move notifications for Clients clients.
#Event ID 28:
#Description
Witness Service is queuing share move notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 29: Witness Service completed queuing share move notifications for Clients clients.
#Event ID 29:
#Description
Witness Service completed queuing share move notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 30: Witness Service share move notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 30:
#Description
Witness Service share move notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 31: Witness Service sent NumResources share move events to Witness Client (ClientName).
#Event ID 31:
#Description
Witness Service sent share move events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 32: Witness Service is queuing IP notifications for Clients clients.
#Event ID 32:
#Description
Witness Service is queuing IP notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 33: Witness Service completed queuing IP notifications for Clients clients.
#Event ID 33:
#Description
Witness Service completed queuing IP notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 34: Witness Service IP notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 34:
#Description
Witness Service IP notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 35: Witness Service sent NumResources IP events to Witness Client (ClientName).
#Event ID 35:
#Description
Witness Service sent IP events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 36: Witness Service is requesting to move an SMB client that is optimized to connect to a specific SMB server for one or more file shares.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ce704b50-b105-4bc8-a24f-1792c0401c2a
Defined in Witness.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893 · schema read from the registered manifest · binary version 10.0.20348.1 · captured 2026-06-02