Microsoft-Windows-TCPIP
624 events across 2 channels
Event ID 1001 — TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = Status.
Description
TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
AddressFamily UInt32 | — |
Pid UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1001",
"version": "0",
"level": "4",
"task": "1001",
"opcode": "0",
"keywords": 9223372036854776832,
"time_created": "2026-03-16T00:21:40.064345500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Status": "0x0",
"Endpoint": "0xFFFF980A15F74B50",
"AddressFamily": " 23",
"Pid": " 3688"
},
"message": ""
}
Event ID 1002 — TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.
Description
TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
NewState UInt32 | — |
RexmitCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1002",
"version": "0",
"level": "4",
"task": "1002",
"opcode": "0",
"keywords": 9223372054034646144,
"time_created": "2026-03-16T00:21:40.119471500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"NewState": " 0",
"RexmitCount": " 0"
},
"message": ""
}
Event ID 1003 — TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.
Description
TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
AddressFamily UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1003",
"version": "0",
"level": "4",
"task": "1003",
"opcode": "0",
"keywords": 9223372054034646144,
"time_created": "2026-03-16T00:21:40.119557300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Status": "0x0",
"AddressFamily": " 0"
},
"message": ""
}
Event ID 1004 — TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale = RcvWndScale.
Description
TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale = RcvWndScale.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
ISN UInt32 | — |
RcvWnd UInt32 | — |
RcvWndScale UInt8 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1004",
"version": "0",
"level": "4",
"task": "1004",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-16T00:21:40.119603700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"ISN": "155000287",
"RcvWnd": " 64240",
"RcvWndScale": "8"
},
"message": ""
}
Event ID 1005 — TCP: endpoint bind failed: address LocalAddressLength cannot be resolved (LocalAddress).
Description
TCP: endpoint bind failed: address LocalAddressLength cannot be resolved (LocalAddress).
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1006 — TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status = LocalAddress.
Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1007 — TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = LocalAddress.
Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1008 — TCP: endpoint (sockaddr=LocalAddressLength) bound.
Description
TCP: endpoint (sockaddr=LocalAddressLength) bound.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1008",
"version": "1",
"level": "4",
"task": "1008",
"opcode": "0",
"keywords": 9223372036854776841,
"time_created": "2026-03-16T00:21:40.119123100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A0DA8A910",
"LocalAddressLength": " 16",
"LocalAddress": "0.0.0.0:52999",
"Status": "0x0"
},
"message": ""
}
Event ID 1009 — TCP: endpoint (sockaddr=LocalAddressLength) closed.
Description
TCP: endpoint (sockaddr=LocalAddressLength) closed.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1009",
"version": "1",
"level": "4",
"task": "1009",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.064514900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"LocalAddressLength": " 28",
"LocalAddress": "::",
"Status": "0x0"
},
"message": ""
}
Event ID 1010 — TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family not attached.
Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1011 — TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment CompartmentId not found.
Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment CompartmentId not found.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1012 — TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection status Status.
Description
TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection status Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1013 — TCP: endpoint (Family=CompartmentId PID=Status) created.
Description
TCP: endpoint (Family=CompartmentId PID=Status) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1013",
"version": "2",
"level": "4",
"task": "1013",
"opcode": "0",
"keywords": 9223372036854776833,
"time_created": "2026-03-16T00:21:40.064333400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"LocalAddressLength": " 0",
"LocalAddress": "",
"Status": "0x0",
"ProcessId": " 3688",
"CompartmentId": " 1",
"AddressFamily": " 23",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1014 — TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route lookup status = Status, TCB = Tcb.
Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route lookup status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1015 — TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: connection insertion.
Event ID 1016 — TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client rejection status = Status.
Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client rejection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1017 — TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed.
Description
TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed. TCB = Tcb. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1017",
"version": "1",
"level": "4",
"task": "1017",
"opcode": "0",
"keywords": 9223372054034646150,
"time_created": "2026-03-16T00:21:38.720229400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 4",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "2814749767106561"
},
"message": ""
}
Event ID 1018 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: address family not attached.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1019 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: compartment Compartment not found.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: compartment Compartment not found.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1020 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: inspection status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1021 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: route lookup status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: route lookup status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1022 — TCP: Bypass rate limiting since flag is set on path Path (local=LocalAddress remote=RemoteAddress).
Event ID 1023 — TCP: Charge rate limiting quota and set rate limiting flag for path Path (local=LocalAddress remote=RemoteAddress).
Event ID 1024 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1025 — TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog backlogged connections.
Description
TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog backlogged connections.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1026 — TCP: Release and set rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress).
Event ID 1027 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1028 — TCP: Clear rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress) since connection is cancelled.
Event ID 1029 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connection cancelled.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connection cancelled.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1030 — TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect failed: connection insertion status = RemoteAddress.
Description
TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect failed: connection insertion status = RemoteAddress.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
NewState UInt32 | — |
RexmitCount UInt32 | — |
Event ID 1031 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect proceeding.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect proceeding.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1031",
"version": "1",
"level": "4",
"task": "1031",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:40.119618200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A15CE6AE0",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1032 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to cancel.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to cancel.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1033 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1033",
"version": "1",
"level": "4",
"task": "1033",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:40.246461800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"Status": "0x0",
"ProcessId": " 3688",
"Compartment": " 0",
"Tcb": "0xFFFF980A15CE6AE0",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1034 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt failed with status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt failed with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1034",
"version": "1",
"level": "2",
"task": "1034",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-15T23:27:04.870761200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{009c52a0-d780-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3912",
"thread_id": "13412"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::1]:51202",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::1]:389",
"Status": "0xC0000120",
"ProcessId": " 3912",
"Compartment": " 0",
"Tcb": "0xFFFFD780009C52A0",
"ProcessStartKey": "3940649673949252"
},
"message": ""
}
Event ID 1035 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-complete inspect status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-complete inspect status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1036 — TCP: ApplySynOptions, failed to create session state with status = Status, TCB = Tcb.
Description
TCP: ApplySynOptions, failed to create session state with status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1037 — TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.
Description
TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1038 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1038",
"version": "1",
"level": "4",
"task": "1038",
"opcode": "0",
"keywords": 9223372105574253572,
"time_created": "2026-03-16T00:21:38.733239500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1039 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1039",
"version": "1",
"level": "4",
"task": "1039",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:22:37.889609500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52990",
"RemoteAddressLength": " 16",
"RemoteAddress": "52.159.108.190:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0E584560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1040 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1040",
"version": "1",
"level": "4",
"task": "1040",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:22:37.890003800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52990",
"RemoteAddressLength": " 16",
"RemoteAddress": "52.159.108.190:443",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0E584560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1041 — TCP: Injecting disconnect on a shutdown TCB failed.
Event ID 1042 — TCP: connection disconnect Injected, length=Length.
Description
TCP: connection disconnect Injected, length=Length.
Message #
Fields #
| Name | Description |
|---|---|
Length Pointer | — |
Timeout UInt64 | — |
Injected UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1042",
"version": "0",
"level": "4",
"task": "1042",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.732224500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Length": "0x0",
"Timeout": "0x0",
"Injected": "issued"
},
"message": ""
}
Event ID 1043 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect completed.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect completed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Inspect Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1043",
"version": "1",
"level": "4",
"task": "1043",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.732982900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1044 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status).
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status). PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1044",
"version": "1",
"level": "4",
"task": "1044",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-16T00:21:38.733255900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"Status": "0xC0000241",
"ProcessId": " 4",
"Compartment": " 0",
"Tcb": "0xFFFF980A0EEE7560",
"ProcessStartKey": "2814749767106561"
},
"message": ""
}
Event ID 1045 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-request timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-request timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1046 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: retransmission timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: retransmission timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1046",
"version": "1",
"level": "4",
"task": "1046",
"opcode": "0",
"keywords": 9223372105574253700,
"time_created": "2026-03-15T23:32:02.749394100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.11:51269",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.21:389",
"Status": "0x0",
"ProcessId": " 0",
"Compartment": " 0",
"Tcb": "0xFFFFD78FF9CA95F0",
"ProcessStartKey": "0"
},
"message": ""
}
Event ID 1047 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: keep-alive timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: keep-alive timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1048 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: disconnect timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: disconnect timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1049 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: extended statistics status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: extended statistics status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1050 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: port-acquisition status = Status.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: port-acquisition status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1051 — TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.
Description
TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
OldState UInt32 | — |
NewState UInt32 | — |
SndNxt UInt32 | — |
Tcb Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1051",
"version": "0",
"level": "4",
"task": "1051",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:38.719167800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"OldState": " 1",
"NewState": " 3",
"SndNxt": " 0",
"Tcb": "0xFFFF980A0EEE7560"
},
"message": ""
}
Event ID 1052 — TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at StartPort.
Description
TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at StartPort.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status UInt32 | — NTSTATUS reference |
StartPort UInt16 | — |
NumberOfPorts UInt16 | — |
ProcessStartKey UInt64 | — |
Event ID 1053 — TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting at StartPort with status = Status.
Description
TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status UInt32 | — NTSTATUS reference |
StartPort UInt16 | — |
NumberOfPorts UInt16 | — |
ProcessStartKey UInt64 | — |
Event ID 1054 — TCP: Process with PID = ProcessId completed global port reservation of NumberOfPorts ports starting at StartPort with status = Status.
Description
TCP: Process with PID = ProcessId completed global port reservation of NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status UInt32 | — NTSTATUS reference |
StartPort UInt16 | — |
NumberOfPorts UInt16 | — |
ProcessStartKey UInt64 | — |
Event ID 1055 — TCP: entering SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Description
TCP: entering SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1056 — TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since boot.
Description
TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1057 — TCP: connection rate-limiting violated ConnectionRateLimitViolations times since boot.
Description
TCP: connection rate-limiting violated ConnectionRateLimitViolations times since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1058 — TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.
Description
TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1059 — TCP: low memory state detected.
Event ID 1060 — TCP: leaving low memory state.
Event ID 1061 — TCP: address family AddressFamily added to interface InterfaceIndex.
Event ID 1062 — TCP: address family AddressFamily removed from interface InterfaceIndex.
Event ID 1063 — TCP: leaving SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Description
TCP: leaving SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.
Message #
Fields #
| Name | Description |
|---|---|
SynAttacksDetected UInt32 | — |
ReassemblyLimitViolations UInt32 | — |
ConnectionRateLimitBacklog UInt32 | — |
ConnectionRateLimitViolations UInt32 | — |
LandAttackSegmentsDropped UInt32 | — |
ConnectionRateLimitDepth UInt32 | — |
Event ID 1064 — TCP: Connection Tcb TimerType timer started.
Description
TCP: Connection Tcb TimerType timer started. Scheduled to expire in WaitTimeMilliseconds ms.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TimerType UInt32 | — |
WaitTimeMilliseconds UInt32 | — |
Processor UInt32 | — |
LastInterruptTime UInt64 | — |
LastMicroseconds UInt64 | — |
CachedKQPCValues | — |
CachedFrequencyValues | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1064",
"version": "1",
"level": "5",
"task": "1064",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.388854500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 0",
"WaitTimeMilliseconds": " 201",
"Processor": " 9",
"LastInterruptTime": "577532689097",
"LastMicroseconds": "57753289800",
"CachedKQPCValues": "577532898003",
"CachedFrequencyValues": "10000000"
},
"message": ""
}
Event ID 1065 — TCP: Connection Tcb stopping TimerType timer.
Description
TCP: Connection Tcb stopping TimerType timer.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TimerType UInt32 | — |
WaitTimeMilliseconds UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1065",
"version": "0",
"level": "5",
"task": "1065",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.388747900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 7",
"WaitTimeMilliseconds": " 0"
},
"message": ""
}
Event ID 1066 — TCP: Connection Tcb TimerType timer has expired.
Description
TCP: Connection Tcb TimerType timer has expired.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TimerType UInt32 | — |
WaitTimeMilliseconds UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1066",
"version": "0",
"level": "5",
"task": "1066",
"opcode": "0",
"keywords": 9223372036854776836,
"time_created": "2026-03-16T00:21:34.715526000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TimerType": " 2",
"WaitTimeMilliseconds": " 0"
},
"message": ""
}
Event ID 1067 — TCP: ISB changed to IsbSize.
Event ID 1068 — TCP: moving RSS indirection table index TableEntry from processor SourceProcessor to processor DestinationProcessor.
Description
TCP: moving RSS indirection table index TableEntry from processor SourceProcessor to processor DestinationProcessor.
Message #
Fields #
| Name | Description |
|---|---|
SourceProcessor UInt32 | — |
SourceActivity UInt32 | — |
DestinationProcessor UInt32 | — |
DestinationActivity UInt32 | — |
PartitionMovesRemaining UInt32 | — |
TableEntry UInt8 | — |
Event ID 1069 — TCP: connection Tcb: Timeout Event updated cwnd = Cwnd and updated ssthresh = SSThresh.
Description
TCP: connection Tcb: Timeout Event updated cwnd = Cwnd and updated ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1070 — TCP: connection Tcb: Rtt sample recorded RttSample.
Event ID 1071 — TCP: connection Tcb: Cumulative ACK updated cwnd = Cwnd.
Event ID 1072 — TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh.
Description
TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1073 — TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence number = SeqNo.
Description
TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence number = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1074 — TCP: connection Tcb: Received data with number of bytes = NumBytes.
Description
TCP: connection Tcb: Received data with number of bytes = NumBytes. ThSeq = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
NumPkt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1074",
"version": "0",
"level": "4",
"task": "1074",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.390777500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"NumBytes": " 6",
"SeqNo": "3537939053"
},
"message": ""
}
Event ID 1075 — TCP: connection Tcb: ECN Echo updated cwnd = Cwnd and updated ssthresh = SSThresh.
Event ID 1076 — TCP: connection Tcb: Spurious timeout with SndUna = SndUna.
Event ID 1077 — TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, SRTT = SRTT, RTO = RTO.
Description
TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, SRTT = SRTT, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1078 — TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Description
TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1078",
"version": "0",
"level": "4",
"task": "1078",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:40.489867400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102"
},
"message": ""
}
Event ID 1079 — TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Description
TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax = SndMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1079",
"version": "0",
"level": "4",
"task": "1079",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:40.494494300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6656"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155007102",
"SndMax": "155007102"
},
"message": ""
}
Event ID 1080 — TCP: connection Tcb entering SACK mode with SndUna = SndUna.
Event ID 1081 — TCP: connection Tcb leaving SACK mode with SndUna = SndUna.
Event ID 1082 — TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Description
TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1084 — TCP: connection Tcb entered BH, BH MSS BHMSS, original MSS OriginalMSS.
Event ID 1085 — TCP: connection Tcb Exiting BH due to TraceString, BH mss BHMSS, Original MSS OriginalMSS.
Event ID 1086 — TCP: connection Tcb not entering BH due to TraceString.
Event ID 1087 — TCP: connection Tcb spurious RTO detection initiated at SndUna.
Event ID 1088 — TCP: connection Tcb spurious RTO detection terminated at SndUna.
Event ID 1089 — TCP: active connect failed (family=Status) connect-complete inspection failed: status = AddressFamily.
Description
TCP: active connect failed (family=Status) connect-complete inspection failed: status = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
AddressFamily UInt32 | — |
Event ID 1090 — TCP: TcpReleaseIndicationList: Nbl = NBL.
Description
TCP: TcpReleaseIndicationList: Nbl = NBL.
Message #
Fields #
| Name | Description |
|---|---|
NBL Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1090",
"version": "0",
"level": "5",
"task": "1090",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.509548500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"NBL": "0xFFFF980A0EE312B0"
},
"message": ""
}
Event ID 1091 — TCP: connection Tcb posted an average of NumBytes bytes per send.
Event ID 1092 — TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive window auto-tuning.
Description
TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive window auto-tuning.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
BufferSize UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1092",
"version": "0",
"level": "5",
"task": "1092",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.316699400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52999",
"RemoteAddressLength": " 16",
"RemoteAddress": "13.89.179.13:443",
"BufferSize": " 0"
},
"message": ""
}
Event ID 1093 — TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window auto-tuning.
Description
TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window auto-tuning.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
BufferSize UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1093",
"version": "0",
"level": "5",
"task": "1093",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:22:31.341328500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e7ae010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51208",
"BufferSize": " 0"
},
"message": ""
}
Event ID 1094 — TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because fine-grained RTT estimation could not be started.
Event ID 1095 — TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because receiver bandwidth estimation could not be started.
Description
TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because receiver bandwidth estimation could not be started.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
BufferSize UInt32 | — |
Event ID 1096 — TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because of receive window tuning allocation failure.
Event ID 1097 — TCP: connection (local=LocalAddress remote=RemoteAddress) auto-tuner adjusted receive buffer size to BufferSize bytes.
Event ID 1098 — TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
Description
TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1099 — TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState.
Description
TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState. SndNxt = SndNxt, RcvNxt = RcvNxt. NdisStatus = Status.
Message #
Fields #
| Name | Description |
|---|---|
TcbState UInt32 | — |
OcbState UInt32 | — |
SndNxt UInt32 | — |
RcvNxt UInt32 | — |
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1100 — TCP: SWS avoidance began on connection Tcb.
Description
TCP: SWS avoidance began on connection Tcb. Timer set for TimerValue ms. BytesToSend = BytesToSend, SendAvailable = SendAvailable, Cwnd = Cwnd, MaxSndWnd = MaxSndWnd.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TimerValue UInt32 | — |
BytesToSend Pointer | — |
SendAvailable UInt32 | — |
Cwnd UInt32 | — |
MaxSndWnd Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1100",
"version": "0",
"level": "4",
"task": "1100",
"opcode": "0",
"keywords": 9223372041149743232,
"time_created": "2026-03-16T00:23:27.100938500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "10580"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"TimerValue": " 5000",
"BytesToSend": "0x10E0",
"SendAvailable": " 18500",
"Cwnd": " 14786",
"MaxSndWnd": "0x400000"
},
"message": ""
}
Event ID 1101 — TCP: SWS avoidance ended on connection Tcb.
Event ID 1102 — TCP: connection Tcb send: Beginning zero-window probing with SndUna = SndUna.
Event ID 1103 — TCP: connection Tcb send: Leaving zero-window probing with SndUna = SndUna.
Event ID 1104 — TCP: Option OptionType is going to be set for connection Tcb.
Description
TCP: Option OptionType is going to be set for connection Tcb.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
OptionType UInt32 | — |
SoOptionType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1104",
"version": "0",
"level": "4",
"task": "1104",
"opcode": "0",
"keywords": 9223372311732683780,
"time_created": "2026-03-16T00:23:28.314606700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "1356",
"thread_id": "4456"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"OptionType": " 1",
"SoOptionType": " 0"
},
"message": ""
}
Event ID 1105 — TCP: Socket Option SoOptionType is going to be set for connection Tcb.
Description
TCP: Socket Option SoOptionType is going to be set for connection Tcb.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
OptionType UInt32 | — |
SoOptionType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1105",
"version": "0",
"level": "4",
"task": "1105",
"opcode": "0",
"keywords": 9223372311732683780,
"time_created": "2026-03-16T00:23:28.314680700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "1356",
"thread_id": "4456"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"OptionType": " 0",
"SoOptionType": " 8"
},
"message": ""
}
Event ID 1106 — IP: Disconnecting interface InterfaceIndex, trace = TraceString.
Event ID 1107 — TCPIP: Module ModuleNameString started.
Event ID 1108 — TCPIP: Module ModuleNameString stopped.
Event ID 1109 — TCPIP: Failure allocating AllocationObjectString.
Event ID 1110 — TCP: Global parameters updated for Address Family AddressFamily: EnablePMtuDiscovery = EnablePMTUDiscovery, UseRfc1122UrgentPointer = TcpUseRFC1122UrgentPointer, DisableTaskOffload = DisableTaskOff...
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | — |
EnablePMTUDiscovery UInt8 | — |
TcpUseRFC1122UrgentPointer UInt8 | — |
DisableTaskOffload UInt8 | — |
EnablePMTUBHDetect UInt8 | — |
DisableTcpChimneyOffload UInt8 | — |
DisableRss UInt8 | — |
EcnCapability UInt8 | — |
TcpMaxDataRetransmissions UInt8 | — |
KeepAliveTime UInt32 | — |
KeepAliveInterval UInt32 | — |
TcpTimedWaitDelay UInt32 | — |
SillyWindowTimeout UInt32 | — |
TcpFinWait2Delay UInt32 | — |
CongestionAlgorithm UInt8 | — |
Tcp1323Opts UInt8 | — |
AutoTuningLevelLocal UInt32 | — |
AutoTuningLevelGroupPolicy UInt32 | — |
Event ID 1111 — TCP: Connection Tcb Large Send Offload, Bytes in segment = BytesInSegment and Bytes remaining = BytesRemaining.
Description
TCP: Connection Tcb Large Send Offload, Bytes in segment = BytesInSegment and Bytes remaining = BytesRemaining.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
BytesInSegment UInt32 | — |
BytesRemaining UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1111",
"version": "0",
"level": "5",
"task": "1111",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.415610100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6972"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"BytesInSegment": " 1492",
"BytesRemaining": " 0"
},
"message": ""
}
Event ID 1112 — TCP: Connection Tcb status changed to Status.
Description
TCP: Connection Tcb status changed to Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
Interface UInt32 | — |
PMax UInt32 | — |
Event ID 1113 — TCP: Connection Tcb status = Status, Interface = Interface, PMax = PMax.
Description
TCP: Connection Tcb status = Status, Interface = Interface, PMax = PMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
Interface UInt32 | — |
PMax UInt32 | — |
Event ID 1114 — IP: DAD successful for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Description
IP: DAD successful for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CompartmentId UInt32 | — |
Event ID 1115 — IP: DAD failed for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, DL address of packet = DLAddress.
Description
IP: DAD failed for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, DL address of packet = DLAddress.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CompartmentId UInt32 | — |
Event ID 1116 — IP: DAD started for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Description
IP: DAD started for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CompartmentId UInt32 | — |
Event ID 1117 — TCP: listener (sockaddr=SocketAddress PID=ProcessId) activation failed: address family not attached.
Description
TCP: listener (sockaddr=SocketAddress PID=ProcessId) activation failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1118 — TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found.
Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found. Status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1119 — TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: inspection status=Status.
Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: inspection status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1120 — TCP: listener Listener (sockaddr=SocketAddress) activation failed: inspection status=Status.
Description
TCP: listener Listener (sockaddr=SocketAddress) activation failed: inspection status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1121 — TCP: listener Listener (sockaddr=SocketAddress) bind failed: port-acquisition status=Status.
Description
TCP: listener Listener (sockaddr=SocketAddress) bind failed: port-acquisition status=Status.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1122 — TCP: listener Listener (family=AddressFamily PID=ProcessId) bind failed: address SocketAddress cannot be resolved (Status=Status).
Description
TCP: listener Listener (family=AddressFamily PID=ProcessId) bind failed: address SocketAddress cannot be resolved (Status=Status).
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1123 — TCP: listener Listener (sockaddr=SocketAddress) activated.
Description
TCP: listener Listener (sockaddr=SocketAddress) activated.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1124 — TCP: listener Listener (sockaddr=SocketAddress) unbound.
Description
TCP: listener Listener (sockaddr=SocketAddress) unbound.
Message #
Fields #
| Name | Description |
|---|---|
Listener Pointer | — |
AddressLength UInt32 | — |
SocketAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1127 — IP: IP address = IPv4Address IPProtocol IPv6Address added on interface = Interface, Protocol = Protocol.
Description
IP: IP address = IPv4Address IPProtocol IPv6Address added on interface = Interface, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CompartmentId UInt32 | — |
PrefixOrigin UInt32 | — |
SuffixOrigin UInt32 | — |
Event ID 1128 — IP: IP address = IPv4Address IPProtocol IPv6Address deleted on interface = Interface, Protocol = Protocol.
Description
IP: IP address = IPv4Address IPProtocol IPv6Address deleted on interface = Interface, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CompartmentId UInt32 | — |
Event ID 1130 — Framing: Interface operation status change.
Description
Framing: Interface Interface Operational Status = OperationalStatus, Operational Status Flags = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
OperationalStatus UInt32 | — |
Status UInt64 | — NTSTATUS reference |
CompartmentId UInt32 | — |
Event ID 1136 — Framing: NDIS pause event on interface InterfaceIndex.
Event ID 1137 — Framing: NDIS restart event on interface InterfaceIndex.
Event ID 1138 — IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred.
Description
IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred. Interface = Interface.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
Event ID 1139 — IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred.
Description
IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred. Interface = Interface. DadState = DadState.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
DadState UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
Event ID 1144 — IP: Interface Interface property change.
Description
IP: Interface Interface property change. Advertise= Advertise, AdvertiseDefaultRoute = AdvertiseDefaultRoute, Forward = Forward, ForwardMulticast = ForwardMulticast, UseNud = UseNud, AdvertisingEnabled = AdvertisingEnabled.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Advertise UInt32 | — |
AdvertiseDefaultRoute UInt32 | — |
Forward UInt32 | — |
ForwardMulticast UInt32 | — |
UseNud UInt32 | — |
AdvertisingEnabled UInt32 | — |
WeakHostSend UInt32 | — |
WeakHostReceive UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
StrictSourceForwarding UInt32 | — |
Event ID 1145 — IP: Route Route created on interface Interface.
Description
IP: Route Route created on interface Interface. Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
DestinationPrefixLength UInt32 | — |
ValidLifetime UInt64 | — |
PreferredLifetime UInt64 | — |
Metric UInt32 | — |
Loopback UInt32 | — |
AutoconfigureAddress UInt32 | — |
Publish UInt32 | — |
Immortal UInt32 | — |
IPUnicastroutedeletionreason UInt32 | — |
Event ID 1146 — IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 Destinatio...
Description
IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Reason = %19.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
DestinationPrefixLength UInt32 | — |
ValidLifetime UInt64 | — |
PreferredLifetime UInt64 | — |
Metric UInt32 | — |
Loopback UInt32 | — |
AutoconfigureAddress UInt32 | — |
Publish UInt32 | — |
Immortal UInt32 | — |
IPUnicastroutedeletionreason UInt32 | — |
Event ID 1147 — IP: Route Route property change.
Message #
Fields #
| Name | Description |
|---|---|
Route Pointer | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
DestinationPrefixLength UInt32 | — |
ValidLifetime UInt64 | — |
PreferredLifetime UInt64 | — |
Metric UInt32 | — |
Loopback UInt32 | — |
AutoconfigureAddress UInt32 | — |
Publish UInt32 | — |
Immortal UInt32 | — |
IPUnicastroutedeletionreason UInt32 | — |
Event ID 1148 — IP: Neighbor unreachable.
Event ID 1149 — IP: Neighbor reachable.
Event ID 1150 — TCP: CTCP DataTransferTimeout event.
Description
TCP: CTCP DataTransferTimeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1151 — TCP: CTCP Cumulative Ack event Connection Tcb, sequence = SeqNo, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt.
Description
TCP: CTCP Cumulative Ack event Connection Tcb, sequence = SeqNo, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1152 — TCP: CTCP Duplicate Ack event.
Description
TCP: CTCP Duplicate Ack event. Connection Tcb, sequence = SeqNo, SndUna = SndUna, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt, DupAckCount = DupAckCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1153 — TCP: CTCP Send event.
Event ID 1154 — TCP: CTCP ECN event.
Event ID 1155 — TCP: CTCP Spurious timeout event.
Description
TCP: CTCP Spurious timeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
RttSample UInt32 | — |
NumBytes UInt32 | — |
SeqNo UInt32 | — |
SndUna UInt32 | — |
Round UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
DWnd UInt32 | — |
BaseRtt UInt32 | — |
DupAckCount UInt32 | — |
Event ID 1156 — TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags.
Description
TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1156",
"version": "0",
"level": "4",
"task": "1156",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.389030100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0xFFFF980A15EC82E0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537939053"
},
"message": ""
}
Event ID 1157 — TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus.
Description
TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1157",
"version": "0",
"level": "4",
"task": "1157",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.418359700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "8632"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0x0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0xC000021B",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537939065"
},
"message": ""
}
Event ID 1158 — TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested.
Description
TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested. IsFullySatisfied = FullySatisfiedORDelayedPush. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1158",
"version": "0",
"level": "4",
"task": "1158",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:34.390668300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0xFFFF980A15EC82E0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x6",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 1",
"RcvNxt": "3537939053"
},
"message": ""
}
Event ID 1159 — TCP: connection Tcb send Injected NumBytes bytes at SndNxt.
Description
TCP: connection Tcb send Injected NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Injected UnicodeString | — |
NumBytes UInt32 | — |
SndNxt UInt32 | — |
SendAvailable UInt32 | — |
ActivityID Pointer | — |
SndLimBytesSnd UInt64 | — |
SndLimBytesRwin UInt64 | — |
SndLimBytesCwnd UInt64 | — |
CWnd UInt32 | — |
SRtt UInt32 | — |
LossRecoveryEpisodes UInt32 | — |
RtoEpisodes UInt32 | — |
PtoEpisodes UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1159",
"version": "0",
"level": "4",
"task": "1159",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388647300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "posted",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1160 — TCP: connection Tcb send transmitted NumBytes bytes at SndNxt.
Description
TCP: connection Tcb send transmitted NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Injected UnicodeString | — |
NumBytes UInt32 | — |
SndNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1160",
"version": "0",
"level": "5",
"task": "1160",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388761700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1161 — TCP: connection Tcb send advance NumBytes bytes at SndNxt.
Description
TCP: connection Tcb send advance NumBytes bytes at SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Injected UnicodeString | — |
NumBytes UInt32 | — |
SndNxt UInt32 | — |
SendAvailable UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1161",
"version": "0",
"level": "5",
"task": "1161",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390443300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1162 — TCP: CTcp: Connection Tcb Delay window has not kicked in.
Description
TCP: CTcp: Connection Tcb Delay window has not kicked in.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Status UInt32 | — NTSTATUS reference |
AddressFamily UInt32 | — |
Event ID 1163 — TCP: CTcp: Allocated blocks: AssignedBlocks; Assigned blocks: AllocatedBlocks.
Event ID 1164 — TCP: CTcp: Connection Tcb, DWnd = DWnd (Prev = PrevDWnd), BaseRtt = BaseRtt, AverageRtt = AvgRtt, CWnd =Cwnd, DiffWnd = DiffWnd, DWnd increment = DwndIncrement.
Description
TCP: CTcp: Connection Tcb, DWnd = DWnd (Prev = PrevDWnd), BaseRtt = BaseRtt, AverageRtt = AvgRtt, CWnd =Cwnd, DiffWnd = DiffWnd, DWnd increment = DwndIncrement.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
DWnd UInt32 | — |
PrevDWnd UInt32 | — |
BaseRtt UInt32 | — |
AvgRtt UInt32 | — |
Cwnd UInt32 | — |
DiffWnd UInt32 | — |
DwndIncrement UInt32 | — |
Event ID 1165 — TCP: CTcp: Gamma Autotuning: Connection Tcb Updated Gamma Gamma, Average backlog AverageBacklog, Average backlog across LFPs AverageBacklogAcrossLFP.
Event ID 1166 — TCP: connection Tcb SRTT measurement started (seq = SeqNum, tick = Tick).
Event ID 1167 — TCP: connection Tcb SRTT measurement complete (tick = Tick, sample = RttSample ms, new srtt = NewSrtt ms).
Description
TCP: connection Tcb SRTT measurement complete (tick = Tick, sample = RttSample ms, new srtt = NewSrtt ms).
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SeqNum UInt32 | — |
Tick UInt32 | — |
RttSample UInt32 | — |
NewSrtt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1167",
"version": "0",
"level": "4",
"task": "1167",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.268231300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7084"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"SeqNum": " 0",
"Tick": "66907815",
"RttSample": " 0",
"NewSrtt": " 0"
},
"message": ""
}
Event ID 1168 — TCP: connection Tcb: SRTT measurement cancelled.
Description
TCP: connection Tcb: SRTT measurement cancelled.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SeqNum UInt32 | — |
Tick UInt32 | — |
RttSample UInt32 | — |
NewSrtt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1168",
"version": "0",
"level": "5",
"task": "1168",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440661100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SeqNum": " 0",
"Tick": " 0",
"RttSample": " 0",
"NewSrtt": " 0"
},
"message": ""
}
Event ID 1169 — UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
Description
UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
NumMessages UInt32 | — |
NumBytes UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Pid UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1169",
"version": "0",
"level": "4",
"task": "1169",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.078234200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"NumMessages": " 1",
"NumBytes": " 63",
"LocalSockAddrLength": " 28",
"LocalSockAddr": "[::ffff:0:0]:53893",
"RemoteSockAddrLength": " 28",
"RemoteSockAddr": "[::ffff:10.2.10.11]:53",
"Pid": " 228"
},
"message": ""
}
Event ID 1170 — UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
Description
UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
NumMessages UInt32 | — |
NumBytes UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Pid UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1170",
"version": "0",
"level": "4",
"task": "1170",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.117082900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"NumMessages": " 0",
"NumBytes": " 186",
"LocalSockAddrLength": " 28",
"LocalSockAddr": "[::ffff:10.2.10.21]:53893",
"RemoteSockAddrLength": " 28",
"RemoteSockAddr": "[::ffff:10.2.10.11]:53",
"Pid": " 228"
},
"message": ""
}
Event ID 1171 — TCP: connection Tcb delivery Delivery flushing NumBytes bytes Length requested status = RequestStatus.
Description
TCP: connection Tcb delivery Delivery flushing NumBytes bytes Length requested status = RequestStatus.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1171",
"version": "0",
"level": "5",
"task": "1171",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.593480400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Delivery": "0xFFFF980A15CE6D10",
"Request": "0xFFFF980A11C13950",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x2000",
"RequestStatus": "0xC0000120",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1172 — TCP: Injecting receive on a shutdown TCB failed.
Event ID 1173 — TCP: connection Tcb delivery Delivery injecting NumBytes bytes delta Length, IsUrgentDelivery = IsUrgentDelivery.
Description
TCP: connection Tcb delivery Delivery injecting NumBytes bytes delta Length, IsUrgentDelivery = IsUrgentDelivery.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1173",
"version": "0",
"level": "5",
"task": "1173",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:28.315732300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7644"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"Delivery": "0xFFFF980A0E584790",
"Request": "0x0",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x70",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1174 — TCP: Injecting fin on a shutdown TCB failed.
Event ID 1175 — TCP: connection Tcb delivery Delivery accepting NumBytes bytes.
Description
TCP: connection Tcb delivery Delivery accepting NumBytes bytes. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1175",
"version": "0",
"level": "5",
"task": "1175",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:22:29.058226900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Delivery": "0xFFFF980A1018B790",
"Request": "0x0",
"NumBytes": "0x6",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "3537945353"
},
"message": ""
}
Event ID 1176 — TCP: connection Tcb delivery Delivery delivering FIN.
Description
TCP: connection Tcb delivery Delivery delivering FIN. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1176",
"version": "0",
"level": "4",
"task": "1176",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:38.731999900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"Delivery": "0xFFFF980A0EEE7790",
"Request": "0x0",
"NumBytes": "0x0",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": "2633618840"
},
"message": ""
}
Event ID 1178 — TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested.
Description
TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested. Delayed push = FullySatisfiedORDelayedPush.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Event ID 1180 — TCP: Injecting fin on TCB completed.
Description
TCP: Injecting fin on TCB completed. TCB = Tcb, Processor = NumBytes.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1180",
"version": "0",
"level": "5",
"task": "1180",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.852963300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "13080"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"Delivery": "0x0",
"Request": "0x0",
"NumBytes": "0xD",
"RequestFlags": " 0",
"Length": "0x0",
"RequestStatus": "0x0",
"IsUrgentDelivery": " 0",
"FullySatisfiedORDelayedPush": " 0",
"RcvNxt": " 0"
},
"message": ""
}
Event ID 1181 — TCP: connection Tcb delivery Delivery urgent boundary completing NumBytes bytes Length requested.
Description
TCP: connection Tcb delivery Delivery urgent boundary completing NumBytes bytes Length requested.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Event ID 1182 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress): initiating SYN/RST validation.
Event ID 1183 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: received RST.
Event ID 1184 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received RST.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received RST.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
NewState UInt32 | — |
RexmitCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1184",
"version": "0",
"level": "4",
"task": "1184",
"opcode": "0",
"keywords": 9223372062624579712,
"time_created": "2026-03-16T00:23:11.140010200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11ae9ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A11AE9AE0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:53002",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.11:445",
"NewState": " 0",
"RexmitCount": " 0"
},
"message": ""
}
Event ID 1185 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received SYN in state NewState.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received SYN in state NewState.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
NewState UInt32 | — |
RexmitCount UInt32 | — |
Event ID 1186 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting connect attempt, RexmitCount = RexmitCount.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting connect attempt, RexmitCount = RexmitCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
NewState UInt32 | — |
RexmitCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1186",
"version": "0",
"level": "4",
"task": "1186",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-15T23:31:42.716275300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF9CA95F0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.11:51269",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.21:389",
"NewState": " 0",
"RexmitCount": " 1"
},
"message": ""
}
Event ID 1187 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting data, RexmitCount = RexmitCount.
Event ID 1188 — TCP: connection Tcb send keep-alive at SndUna = SndUna.
Description
TCP: connection Tcb send keep-alive at SndUna = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1188",
"version": "0",
"level": "4",
"task": "1188",
"opcode": "0",
"keywords": 9223372058329612416,
"time_created": "2026-03-16T00:21:53.057881700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"SndUna": "2262383926",
"SndMax": " 0"
},
"message": ""
}
Event ID 1189 — TCP: connection Tcb, delivery Delivery: delivery state changed from OldDeliveryState to NewDeliveryState.
Event ID 1190 — TCP: connection Tcb delivery Delivery dropping data.
Description
TCP: connection Tcb delivery Delivery dropping data. TotalBytesEnqueued = NumBytes. Length = Length. RcvNxt = RcvNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Delivery Pointer | — |
Request Pointer | — |
NumBytes Pointer | — |
RequestFlags UInt32 | — |
Length Pointer | — |
RequestStatus UInt32 | — |
IsUrgentDelivery UInt32 | — |
FullySatisfiedORDelayedPush UInt32 | — |
RcvNxt UInt32 | — |
Event ID 1191 — TCP: endpoint/connection PortAcquirer acquired port number PortNumber.
Description
TCP: endpoint/connection PortAcquirer acquired port number PortNumber.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | — |
PortNumber UInt16 | — |
WeakReference UInt32 | — |
OriginalAcquirer Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1191",
"version": "0",
"level": "4",
"task": "1191",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:40.119043200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0DA8A910",
"PortNumber": "52999",
"WeakReference": " 0",
"OriginalAcquirer": "0x0"
},
"message": ""
}
Event ID 1192 — TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer.
Description
TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer. Successful = WeakReference.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | — |
PortNumber UInt16 | — |
WeakReference UInt32 | — |
OriginalAcquirer Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1192",
"version": "0",
"level": "4",
"task": "1192",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:38.719220200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0EEE7560",
"PortNumber": "5985",
"WeakReference": " 1",
"OriginalAcquirer": "0xFFFF980A0EF4B580"
},
"message": ""
}
Event ID 1193 — TCP: endpoint/connection PortAcquirer released port number PortNumber.
Description
TCP: endpoint/connection PortAcquirer released port number PortNumber. WeakReference = WeakReference.
Message #
Fields #
| Name | Description |
|---|---|
PortAcquirer Pointer | — |
PortNumber UInt16 | — |
WeakReference UInt32 | — |
OriginalAcquirer Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1193",
"version": "0",
"level": "4",
"task": "1193",
"opcode": "0",
"keywords": 9223372054034644992,
"time_created": "2026-03-16T00:21:38.733428000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PortAcquirer": "0xFFFF980A0EEE7560",
"PortNumber": "5985",
"WeakReference": " 1",
"OriginalAcquirer": "0x0"
},
"message": ""
}
Event ID 1194 — TCP: endpoint/connection PortAcquirer replaced base endpoint OriginalAcquirer and acquired reference to port number PortNumber.
Event ID 1195 — TCP: Portpool assigned port number PortNumber with weak references due to port exhaustion.
Event ID 1196 — TCP: connection Tcb BH receive ACK for full size seq.
Description
TCP: connection Tcb BH receive ACK for full size seq. Seq = SndUna. IsSack = IsSack.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Reason UnicodeString | — |
IsSack UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1196",
"version": "0",
"level": "4",
"task": "1196",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.217663000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"SndUna": "1228953133",
"SndMax": " 0",
"Reason": "NULL",
"IsSack": " 0"
},
"message": ""
}
Event ID 1197 — TCP: connection Tcb flushed SACK state at SndUna = SndUna.
Event ID 1198 — TCP: Connection Tcb entering reassembly at RcvNxt = SndUna.
Description
TCP: Connection Tcb entering reassembly at RcvNxt = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1198",
"version": "0",
"level": "5",
"task": "1198",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.839186900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"SndUna": "3358248696",
"SndMax": " 0"
},
"message": ""
}
Event ID 1199 — TCP: Connection Tcb leaving reassembly at RcvNxt = SndUna.
Description
TCP: Connection Tcb leaving reassembly at RcvNxt = SndUna.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1199",
"version": "0",
"level": "5",
"task": "1199",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:23:59.839225300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A14CDE010",
"SndUna": "3358248696",
"SndMax": " 0"
},
"message": ""
}
Event ID 1200 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: Zero window probe timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: Zero window probe timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1201 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: FIN-WAIT-2 timeout expired.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: FIN-WAIT-2 timeout expired.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1202 — IP: Interface rundown: Index = IfIndex, Linkspeed = CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType, IP Address = IPv4 Address IPProtocol IPv6 Address.
Description
IP: Interface rundown: Index = IfIndex, Linkspeed = CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType, IP Address = IPv4 Address IPProtocol IPv6 Address.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CurrLinkSpeed UInt64 | — |
IPProtocol UInt32 | — |
IPv4 Address | — |
IpAddrLength UInt32 | — |
IPv6 Address | — |
PhysicalMediumType UInt32 | — |
CompartmentId UInt32 | — |
OldLinkSpeed UInt64 | — |
NetworkCategory UInt32 | — |
Metric UInt32 | — |
Connected UInt32 | — |
InternetConnectivityStatus UInt32 | — |
Flags UInt64 | — |
IsolationId UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
NlMtu UInt32 | — |
ForwardingTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1202",
"version": "4",
"level": "4",
"task": "1202",
"opcode": "0",
"keywords": 9223372586610589840,
"time_created": "2026-03-15T23:26:13.264840100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "15176",
"thread_id": "13152"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 1",
"CurrLinkSpeed": "0",
"IPProtocol": " 4",
"IPv4 Address": "127.0.0.1",
"IpAddrLength": " 0",
"IPv6 Address": "",
"PhysicalMediumType": " 0",
"CompartmentId": " 1",
"OldLinkSpeed": "0",
"NetworkCategory": " 0",
"Metric": " 75",
"Connected": " 1",
"InternetConnectivityStatus": "4294967295",
"Flags": "0x10262102300",
"IsolationId": " 0"
},
"message": ""
}
Event ID 1203 — IP: Interface Index = IfIndex, Linkspeed changed to CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType.
Description
IP: Interface Index = IfIndex, Linkspeed changed to CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CurrLinkSpeed UInt64 | — |
IPProtocol UInt32 | — |
IPv4Address UInt32 | — |
IpAddrLength UInt32 | — |
IPv6Address Binary | — |
PhysicalMediumType UInt32 | — |
CompartmentId UInt32 | — |
OldLinkSpeed UInt64 | — |
ReceiveLinkSpeed UInt64 | — |
MediaConnectState UInt32 | — |
Event ID 1204 — TCP: Connection Tcb flushing reassembly state at RcvNxt = SndUna.
Event ID 1205 — TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason.
Description
TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | — |
IPTransportProtocol UInt32 | — |
AddressFamily UInt32 | — |
Source IPv4 Address | — |
Dest IPv4 Address | — |
IPv6SourceIpAddrLength UInt32 | — |
IPv6 Source Address | — |
IPv6DestIpAddrLength UInt32 | — |
IPv6 Dest Address | — |
Reason UInt32 | — |
NblCount UInt32 | — |
IPProtocol UInt32 | — |
SourceIPv4Address UInt32 | — |
DestIPv4Address UInt32 | — |
IPv6SourceAddress Binary | — |
IPv6DestAddress Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1205",
"version": "0",
"level": "5",
"task": "1205",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:38.718814700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A1D7C5570",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"Source IPv4 Address": "10.2.10.11",
"Dest IPv4 Address": "10.2.10.21",
"IPv6SourceIpAddrLength": " 0",
"IPv6 Source Address": "",
"IPv6DestIpAddrLength": " 0",
"IPv6 Dest Address": "",
"Reason": " 17",
"NblCount": " 1",
"IPProtocol": " 4"
},
"message": ""
}
Event ID 1206 — TCPIP: NBL Nbl fell off the send fast path, Reason: Reason.
Description
TCPIP: NBL Nbl fell off the send fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | — |
IPTransportProtocol UInt32 | — |
AddressFamily UInt32 | — |
Source IPv4 Address | — |
Dest IPv4 Address | — |
IPv6SourceIpAddrLength UInt32 | — |
IPv6 Source Address | — |
IPv6DestIpAddrLength UInt32 | — |
IPv6 Dest Address | — |
Reason UInt32 | — |
NblCount UInt32 | — |
IPProtocol UInt32 | — |
SourceIPv4Address UInt32 | — |
DestIPv4Address UInt32 | — |
IPv6SourceAddress Binary | — |
IPv6DestAddress Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1206",
"version": "0",
"level": "5",
"task": "1206",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388870500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A11CCA4F0",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"Source IPv4 Address": "10.2.10.21",
"Dest IPv4 Address": "10.2.20.41",
"IPv6SourceIpAddrLength": " 0",
"IPv6 Source Address": "",
"IPv6DestIpAddrLength": " 0",
"IPv6 Dest Address": "",
"Reason": " 11",
"NblCount": " 1",
"IPProtocol": " 4"
},
"message": ""
}
Event ID 1207 — TCP: WSD - TcpWsdEtwPoint Status: Status.
Description
TCP: WSD - TcpWsdEtwPoint Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
TcpWsdEtwPoint UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1208 — TCP: WSD - TcpWsdEtwPoint Status: Status.
Description
TCP: WSD - TcpWsdEtwPoint Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
TcpWsdEtwPoint UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1209 — TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.
Event ID 1210 — TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.
Event ID 1211 — TCP: WSD - Entry (Processor, Entry) moved from OldState to NewState due to TcpWsdEtwPoint.
Event ID 1212 — TCP: WSD - Profile: Profile State: State Qualified: Qualified EreQualified: EreQualified.
Event ID 1213 — TCP: WSD - Enabled moved from OldEnabledState to NewEnabledState.
Event ID 1214 — TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr.
Description
TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | — |
AddressFamily UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Reason UInt32 | — |
PacketCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1214",
"version": "0",
"level": "4",
"task": "1214",
"opcode": "0",
"keywords": 9223373694712152192,
"time_created": "2026-03-16T00:21:38.733034500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:5985",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "10.2.10.11:51201",
"Reason": " 20",
"PacketCount": " 1"
},
"message": ""
}
Event ID 1215 — TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s).
Description
TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s). SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | — |
AddressFamily UInt32 | — |
Source IPv4 Address | — |
Dest IPv4 Address | — |
IPv6SourceIpAddrLength UInt32 | — |
IPv6 Source Address | — |
IPv6DestIpAddrLength UInt32 | — |
IPv6 Dest Address | — |
Reason UInt32 | — |
PacketCount UInt32 | — |
IPProtocol UInt32 | — |
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
DestAddressLength UInt32 | — |
DestAddress Binary | — |
IfIndex UInt32 | — |
PathDirection UInt32 | — |
SourceIPv4Address UInt32 | — |
DestIPv4Address UInt32 | — |
IPv6SourceAddress Binary | — |
IPv6DestAddress Binary | — |
Nbl Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1215",
"version": "1",
"level": "4",
"task": "1215",
"opcode": "0",
"keywords": 9223373699007119488,
"time_created": "2026-03-15T23:27:04.761762100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "3912",
"thread_id": "13412"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 6",
"AddressFamily": " 23",
"Source IPv4 Address": "0.0.0.0",
"Dest IPv4 Address": "0.0.0.0",
"IPv6SourceIpAddrLength": " 16",
"IPv6 Source Address": "::1",
"IPv6DestIpAddrLength": " 16",
"IPv6 Dest Address": "::1",
"Reason": " 256",
"PacketCount": " 1",
"IPProtocol": " 6",
"SourceAddressLength": " 28",
"SourceAddress": "::1",
"DestAddressLength": " 28",
"DestAddress": "::1",
"IfIndex": " 1",
"PathDirection": " 1"
},
"message": ""
}
Event ID 1216 — TCP: MPP NPP Evaluation PhysicalPages = PhysicalPages NonPagedPoolPages = NonPagedPoolPages Current = CurrentWatermark Peak = PeakWatermark Low = HighWatermark High = LowWatermark.
Description
TCP: MPP NPP Evaluation PhysicalPages = PhysicalPages NonPagedPoolPages = NonPagedPoolPages Current = CurrentWatermark Peak = PeakWatermark Low = HighWatermark High = LowWatermark.
Message #
Fields #
| Name | Description |
|---|---|
PhysicalPages UInt32 | — |
NonPagedPoolPages UInt32 | — |
CurrentWatermark UInt32 | — |
PeakWatermark UInt32 | — |
HighWatermark UInt32 | — |
LowWatermark UInt32 | — |
Event ID 1217 — TCP: MPP: Episode started.
Description
TCP: MPP: Episode started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Current = CurrentWatermark Low = LowWatermark Reentry = ReentryWatermark.
Message #
Fields #
| Name | Description |
|---|---|
LowNppEventState UInt32 | — |
HighNppEventState UInt32 | — |
EpisodeStartTick UInt64 | — |
EpisodeStopTick UInt64 | — |
CurrentWatermark UInt32 | — |
LowWatermark UInt32 | — |
ReentryWatermark UInt32 | — |
Event ID 1218 — TCP: MPP: Episode ended.
Description
TCP: MPP: Episode ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Reentry = ReentryWatermark.
Message #
Fields #
| Name | Description |
|---|---|
LowNppEventState UInt32 | — |
HighNppEventState UInt32 | — |
EpisodeStartTick UInt64 | — |
EpisodeStopTick UInt64 | — |
ReentryWatermark UInt32 | — |
Event ID 1219 — TCP: MPP: Epoch Epoch started.
Description
TCP: MPP: Epoch Epoch started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = OldSynDropRate -> NewSynDropRate TcbKillRate = OldTcbKillRate -> NewTcbKillRate CurrentWatermark = CurrentWatermark.
Message #
Fields #
| Name | Description |
|---|---|
Epoch UInt32 | — |
LowNppEventState UInt32 | — |
HighNppEventState UInt32 | — |
EpochStartTick UInt64 | — |
EpochStopTick UInt64 | — |
OldSynDropRate UInt32 | — |
NewSynDropRate UInt32 | — |
OldTcbKillRate UInt32 | — |
NewTcbKillRate UInt32 | — |
CurrentWatermark UInt32 | — |
Event ID 1220 — TCP: MPP: Epoch Epoch ended.
Description
TCP: MPP: Epoch Epoch ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = SynDropRate TcbKillRate = TcbKillRate Current = CurrentWatermark.
Message #
Fields #
| Name | Description |
|---|---|
Epoch UInt32 | — |
LowNppEventState UInt32 | — |
HighNppEventState UInt32 | — |
EpochStartTick UInt64 | — |
EpochStopTick UInt64 | — |
SynDropRate UInt32 | — |
TcbKillRate UInt32 | — |
CurrentWatermark UInt32 | — |
Event ID 1221 — TCP: Connection Tcb restarting Cwnd.
Description
TCP: Connection Tcb restarting Cwnd. Old Cwnd = OldCwnd, New Cwnd = NewCwnd, Processor = Processor, CurrentTick = CurrentTick, IdleTick = IdleTick, Rto = Rto.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
OldCwnd UInt32 | — |
NewCwnd UInt32 | — |
Processor UInt32 | — |
CurrentTick UInt32 | — |
IdleTick UInt32 | — |
Rto UInt32 | — |
Event ID 1222 — TCP: Connection Tcb adjust InitalCwnd.
Event ID 1223 — TCP: Connection Tcb committed TemplateType = TemplateType.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TemplateType UInt32 | — |
MinRto UInt32 | — |
EnableCwndRestart UInt32 | — |
InitialCwnd UInt32 | — |
CongestionAlgorithm UInt32 | — |
MaxDataRetransmissions UInt32 | — |
DelayedAckTicks UInt32 | — |
DelayedAckFrequency UInt32 | — |
Rack UInt32 | — |
TailLossProbe UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1223",
"version": "0",
"level": "4",
"task": "1223",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:38.719984100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"TemplateType": " 0",
"MinRto": " 300",
"EnableCwndRestart": " 0",
"InitialCwnd": " 10",
"CongestionAlgorithm": " 5",
"MaxDataRetransmissions": " 5",
"DelayedAckTicks": " 40",
"DelayedAckFrequency": " 2",
"Rack": " 1",
"TailLossProbe": " 1"
},
"message": ""
}
Event ID 1224 — TCP: Connection Tcb template changed.
Description
TCP: Connection Tcb template changed. New template=TemplateType. Context=Context.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TemplateType UInt32 | — |
Context UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1224",
"version": "0",
"level": "5",
"task": "1224",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:38.719121800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"TemplateType": " 0",
"Context": "Initializing Template Accept TCB"
},
"message": ""
}
Event ID 1225 — TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount.
Description
TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount. Bytes marked = EcnTotalMarkedCount, ThAck = ThAck, updated EcnAlpha = EcnAlpha.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndRound UInt32 | — |
EcnTotalByteCount UInt32 | — |
EcnTotalMarkedCount UInt32 | — |
ThAck UInt32 | — |
EcnAlpha UInt32 | — |
Event ID 1226 — TCP: interface IfIndex: RSC state changed, IPV4 State = StateV4, IPV4 Failure Reason = FailureReasonV4, IPV6 State = StateV6, IPV6 Failure Reason = FailureReasonV6, Event = Event.
Description
TCP: interface IfIndex: RSC state changed, IPV4 State = StateV4, IPV4 Failure Reason = FailureReasonV4, IPV6 State = StateV6, IPV6 Failure Reason = FailureReasonV6, Event = Event.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
StateV4 UInt32 | — |
FailureReasonV4 UInt32 | — |
StateV6 UInt32 | — |
FailureReasonV6 UInt32 | — |
Event UInt32 | — |
Event ID 1227 — TCP: connection Tcb: RSC SCU received.
Description
TCP: connection Tcb: RSC SCU received. CoalescedSegCount = CoalescedSegCount, DupAckCount = DupAckCount, RscTcpTimestampDelta = RscTcpTimestampDelta, HeaderFlags = HeaderFlags, EcnCePresent = EcnCePresent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
CoalescedSegCount UInt16 | — |
DupAckCount UInt16 | — |
RscTcpTimestampDelta UInt32 | — |
HeaderFlags UInt16 | — |
EcnCePresent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1227",
"version": "0",
"level": "5",
"task": "1227",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:36.016716200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{10708010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A10708010",
"CoalescedSegCount": "2",
"DupAckCount": "0",
"RscTcpTimestampDelta": " 0",
"HeaderFlags": "24",
"EcnCePresent": " 0"
},
"message": ""
}
Event ID 1228 — TCPIP: TCB Tcb does not take fast path, Cause: Cause.
Event ID 1229 — TCP: Connection Tcb send queue is idle.
Description
TCP: Connection Tcb send queue is idle. Cwnd = OldCwnd, Processor = Processor, CurrentTick = CurrentTick, IdleTick = IdleTick.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
OldCwnd UInt32 | — |
NewCwnd UInt32 | — |
Processor UInt32 | — |
CurrentTick UInt32 | — |
IdleTick UInt32 | — |
Rto UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1229",
"version": "0",
"level": "4",
"task": "1221",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390542000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"OldCwnd": " 2110976",
"NewCwnd": " 0",
"Processor": " 8",
"CurrentTick": "57753291",
"IdleTick": "57753291",
"Rto": " 0"
},
"message": ""
}
Event ID 1230 — RSS: Bind notification for AddressFamily on interface InterfaceIndex.
Event ID 1231 — RSS: Bind notification for adapter AdapterIndex.
Event ID 1232 — RSS: ReferenceAdded reference on adapter AdapterIndex.
Event ID 1233 — RSS: adapter AdapterIndex with capabilities CapabilitiesFlags and NumberOfReceiveQueues receive queues.
Event ID 1234 — RSS: adapter AdapterIndex processor group GroupNumber maximum processors MaximumProcessors processor affinity GroupAffinity.
Description
RSS: adapter AdapterIndex processor group GroupNumber maximum processors MaximumProcessors processor affinity GroupAffinity.
Message #
Fields #
| Name | Description |
|---|---|
AdapterIndex UInt32 | — |
GroupNumber UInt16 | — |
MaximumProcessors UInt32 | — |
GroupAffinity UInt64 | — |
AvailableProcessorsSize UInt32 | — |
AvailableProcessors Binary | — |
Event ID 1235 — RSS: assigning processor ProcessorIndex from adapter PreviousAdapterIndex to NewAdapterIndex.
Event ID 1236 — RSS: unassigning processor ProcessorIndex from adapter PreviousAdapterIndex.
Event ID 1237 — RSS: adapter AdapterIndex reassigning indirection entry IndirectionIndex from processor OldProcessorIndex to NewProcessorIndex.
Event ID 1238 — RSS: adapter AdapterIndex removing processor ProcessorIndex from its indirection table.
Event ID 1239 — RSS: adapter AdapterIndex changing Setting to Value.
Event ID 1240 — RSS: Failed to FailureDescription on IfIndex InterfaceIndex: Status.
Description
RSS: Failed to FailureDescription on IfIndex InterfaceIndex: Status.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
FailureDescription UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1241 — RSS: bind completed successfully for AddressFamily on interface InterfaceIndex.
Event ID 1242 — RSS: bind completed successfully for adapter AdapterIndex.
Event ID 1243 — RSS: adapter AdapterIndex not supported.
Event ID 1244 — RSS: adapter AdapterIndex indirection table initialized on group GroupNumber with processor set ActiveAffinity.
Event ID 1245 — RSS: Rundown: interface InterfaceIndex with adapter AdapterIndex at port PortNumber.
Description
RSS: Rundown: interface InterfaceIndex with adapter AdapterIndex at port PortNumber.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
AdapterIndex UInt32 | — |
PortNumber UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1245",
"version": "0",
"level": "4",
"task": "1245",
"opcode": "0",
"keywords": 9223372586610591888,
"time_created": "2026-03-16T00:21:34.295777000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{517fdda0-f803-ffff-0600-000000000000}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"InterfaceIndex": " 6",
"AdapterIndex": " 6",
"PortNumber": " 0"
},
"message": ""
}
Event ID 1246 — RSS: Rundown: adapter AdapterIndex hash info HashInfo maximum processors MaximumProcessors group GroupNumber affinity GroupAffinity active processors ActiveAffinity active mode: ActiveMode.
Description
RSS: Rundown: adapter AdapterIndex hash info HashInfo maximum processors MaximumProcessors group GroupNumber affinity GroupAffinity active processors ActiveAffinity active mode: ActiveMode.
Message #
Fields #
| Name | Description |
|---|---|
AdapterIndex UInt32 | — |
HashInfo UInt32 | — |
MaximumProcessors UInt32 | — |
GroupNumber UInt16 | — |
GroupAffinity UInt64 | — |
ActiveAffinity UInt64 | — |
ActiveMode UInt32 | — |
IndirectionTableSize UInt32 | — |
IndirectionTable Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1246",
"version": "0",
"level": "4",
"task": "1246",
"opcode": "0",
"keywords": 9223372586610591888,
"time_created": "2026-03-15T23:26:13.264909200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0f1f9564-f803-ffff-0400-000000000000}"
},
"execution": {
"process_id": "15176",
"thread_id": "13152"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AdapterIndex": " 4",
"HashInfo": "0xD701",
"MaximumProcessors": " 14",
"GroupNumber": "0",
"GroupAffinity": "0x3FFF",
"ActiveAffinity": "0x3FFF",
"ActiveMode": " 1002",
"IndirectionTableSize": " 128",
"IndirectionTable": "0x000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D0001"
},
"message": ""
}
Event ID 1247 — RSS: interface InterfaceIndex support: Capability.
Event ID 1248 — NDKPI Create CQ: RequestContext RequestContext Adapter NdkAdapter CqDepth CqDepth CqNotificationContext CqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
Description
NDKPI Create CQ: RequestContext RequestContext Adapter NdkAdapter CqDepth CqDepth CqNotificationContext CqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
Message #
Fields #
| Name | Description |
|---|---|
NdkAdapter Pointer | — |
CqDepth UInt32 | — |
CqNotificationContext Pointer | — |
AffinityMask UInt64 | — |
AffinityGroup UInt16 | — |
RequestContext Pointer | — |
Event ID 1249 — NDKPI Create Completion: RequestContext RequestContext Status Status (CompletionType) NdkObjectType NdkObject.
Description
NDKPI Create Completion: RequestContext RequestContext Status Status (CompletionType) NdkObjectType NdkObject.
Message #
Fields #
| Name | Description |
|---|---|
RequestContext Pointer | — |
Status UInt32 | — NTSTATUS reference |
NdkObject Pointer | — |
CompletionType UInt32 | — |
NdkObjectType UInt32 | — |
Event ID 1250 — NDKPI Close NdkObjectType: RequestContext RequestContext NdkObjectType NdkObject.
Event ID 1251 — NDKPI Close Completion: RequestContext RequestContext (CompletionType).
Event ID 1252 — NDKPI Resize CQ: RequestContext RequestContext CQ NdkCq CqDepth CqDepth.
Event ID 1253 — NDKPI Request Completion: RequestContext RequestContext Status Status (CompletionType).
Description
NDKPI Request Completion: RequestContext RequestContext Status Status (CompletionType).
Message #
Fields #
| Name | Description |
|---|---|
RequestContext Pointer | — |
Status UInt32 | — NTSTATUS reference |
CompletionType UInt32 | — |
Event ID 1254 — NDKPI Arm CQ: CQ NdkCq ArmType.
Event ID 1255 — NDKPI Result ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext.
Description
NDKPI Result ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | — |
Status UInt32 | — NTSTATUS reference |
BytesTransferred UInt32 | — |
QpContext Pointer | — |
RequestContext Pointer | — |
ResultIndex Int32 | — |
ResultCount Int32 | — |
Event ID 1256 — NDKPI Create MR: RequestContext RequestContext PD NdkPd FastRegister FastRegister.
Event ID 1257 — NDKPI Flush: QP NdkQp.
Event ID 1258 — NDKPI Send (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken Flags Flags.
Description
NDKPI Send (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
Event ID 1259 — NDKPI Receive (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
Description
NDKPI Receive (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
Event ID 1260 — NDKPI Register MR: RequestContext RequestContext MR NdkMr MDL Mdl Length Length Flags Flags.
Event ID 1261 — NDKPI Deregister MR: RequestContext RequestContext MR NdkObject.
Event ID 1262 — NDKPI Initialize FastRegister MR: RequestContext RequestContext MR NdkMr AdapterPageCount AdapterPageCount RemoteAccess RemoteAccess.
Event ID 1263 — NDKPI Modify SRQ: RequestContext RequestContext SRQ NdkSrq SrqDepth SrqDepth NotifyThreshold NotifyThreshold.
Event ID 1264 — NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SrcAddress SrcSockAddr DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Description
NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SrcAddress SrcSockAddr DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
NdkQp Pointer | — |
SrcSockAddrLength UInt32 | — |
SrcSockAddr Binary | — |
DestSockAddrLength UInt32 | — |
DestSockAddr Binary | — |
IRD UInt32 | — |
ORD UInt32 | — |
RequestContext Pointer | — |
NdkSharedEndpoint Pointer | — |
PrivateDataLength UInt32 | — |
Event ID 1265 — NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SharedEndpoint NdkSharedEndpoint DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Description
NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SharedEndpoint NdkSharedEndpoint DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
NdkQp Pointer | — |
SrcSockAddrLength UInt32 | — |
SrcSockAddr Binary | — |
DestSockAddrLength UInt32 | — |
DestSockAddr Binary | — |
IRD UInt32 | — |
ORD UInt32 | — |
RequestContext Pointer | — |
NdkSharedEndpoint Pointer | — |
PrivateDataLength UInt32 | — |
Event ID 1266 — NDKPI CompleteConnect: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.
Event ID 1267 — NDKPI Accept: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Description
NDKPI Accept: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
NdkQp Pointer | — |
IRD UInt32 | — |
ORD UInt32 | — |
DisconnectEventContext Pointer | — |
RequestContext Pointer | — |
PrivateDataLength UInt32 | — |
Event ID 1268 — NDKPI Disconnect: RequestContext RequestContext Connector NdkObject.
Event ID 1269 — NDKPI Listen: RequestContext RequestContext Listener NdkListener Address SockAddr.
Event ID 1270 — NDKPI Create MW: RequestContext RequestContext PD NdkObject.
Event ID 1271 — NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext Af...
Description
NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | — |
SrqDepth UInt32 | — |
MaxReceiveRequestSge UInt32 | — |
NotifyThreshold UInt32 | — |
SrqNotificationContext Pointer | — |
AffinityMask UInt64 | — |
AffinityGroup UInt16 | — |
RequestContext Pointer | — |
Event ID 1272 — NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth M...
Description
NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth MaxReceiveRequestSge MaxReceiveRequestSge MaxInitiatorRequestSge MaxInitiatorRequestSge.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | — |
ReceiveCq Pointer | — |
InitiatorCq Pointer | — |
QPContext Pointer | — |
ReceiveQueueDepth UInt32 | — |
InitiatorQueueDepth UInt32 | — |
MaxReceiveRequestSge UInt32 | — |
MaxInitiatorRequestSge UInt32 | — |
RequestContext Pointer | — |
NdkSrq Pointer | — |
Event ID 1273 — NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge Max...
Description
NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge MaxInitiatorRequestSge.
Message #
Fields #
| Name | Description |
|---|---|
NdkPd Pointer | — |
ReceiveCq Pointer | — |
InitiatorCq Pointer | — |
QPContext Pointer | — |
ReceiveQueueDepth UInt32 | — |
InitiatorQueueDepth UInt32 | — |
MaxReceiveRequestSge UInt32 | — |
MaxInitiatorRequestSge UInt32 | — |
RequestContext Pointer | — |
NdkSrq Pointer | — |
Event ID 1274 — NDKPI Create PD: RequestContext RequestContext Adapter NdkObject.
Event ID 1275 — NDKPI Create SharedEndpoint: RequestContext RequestContext Adapter NdkListener Address SockAddr.
Event ID 1276 — NDKPI Create Connector: RequestContext RequestContext Adapter NdkObject.
Event ID 1277 — NDKPI Create Listener: RequestContext RequestContext Adapter NdkAdapter ConnectEventContext ConnectEventContext.
Event ID 1278 — NDKPI Build LAM: RequestContext RequestContext Adapter NdkAdapter MDL Mdl Length Length LAMBuffer LAMBuffer LAMBufferSize LAMBufferSize.
Event ID 1279 — NDKPI Release LAM: Adapter NdkAdapter LAMBuffer LAMBuffer.
Event ID 1280 — NDKPI CQ Notification Callback: CqNotificationContext CqNotificationContext CqStatus CqStatus.
Event ID 1281 — NDKPI SRQ Notification Callback: SrqNotificationContext SrqNotificationContext SrqStatus SrqStatus.
Event ID 1282 — NDKPI Disconnect Event Callback: DisconnectEventContext DisconnectEventContext.
Event ID 1283 — NDKPI Connect Event Callback: ConnectEventContext ConnectEventContext Connector NdkConnector.
Event ID 1284 — NDKPI Got TokenType Token Token from NdkObjectType NdkObject.
Event ID 1285 — NDKPI Got SockAddrType Address SockAddr from NdkObjectType NdkObject.
Event ID 1286 — NDKPI SockAddrType Address query failure Status on NdkObjectType NdkObject.
Description
NDKPI SockAddrType Address query failure Status on NdkObjectType NdkObject.
Message #
Fields #
| Name | Description |
|---|---|
NdkObject Pointer | — |
NdkObjectType UInt32 | — |
SockAddrType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1287 — NDKPI Reject: Connector NdkConnector PrivateDataLength PrivateDataLength Status Status.
Description
NDKPI Reject: Connector NdkConnector PrivateDataLength PrivateDataLength Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
PrivateDataLength UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1288 — NDKPI Get Connect Data: Connector NdkConnector IRD IRD ORD ORD PrivateDataLength PrivateDataLength Status Status.
Description
NDKPI Get Connect Data: Connector NdkConnector IRD IRD ORD ORD PrivateDataLength PrivateDataLength Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
IRD UInt32 | — |
ORD UInt32 | — |
PrivateDataLength UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1289 — NDKPI Work Request Inline Failure: RequestContext RequestContext QP NdkQp Status Status.
Description
NDKPI Work Request Inline Failure: RequestContext RequestContext QP NdkQp Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1290 — NDKPI Bind: RequestContext RequestContext QP NdkQp MR NdkMr MW NdkMw VirtualAddress VirtualAddress Length Length Flags Flags.
Event ID 1291 — NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress F...
Description
NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
NdkMr Pointer | — |
AdapterPageCount UInt32 | — |
AdapterPageArray Pointer | — |
FBO UInt32 | — |
Length UInt64 | — |
BaseVirtualAddress Pointer | — |
Flags UInt32 | — |
Event ID 1292 — NDKPI Invalidate: RequestContext RequestContext QP NdkQp NdkObjectType NdkObject Flags Flags.
Event ID 1293 — NDKPI Read (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Description
NDKPI Read (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
RemoteAddress UInt64 | — |
RemoteToken UInt32 | — |
Event ID 1294 — NDKPI Write (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Description
NDKPI Write (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
RemoteAddress UInt64 | — |
RemoteToken UInt32 | — |
Event ID 1295 — NDKPI SRQ Receive (SGE SgeIndex/NumSge): RequestContext RequestContext SRQ NdkSrq SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
Description
NDKPI SRQ Receive (SGE SgeIndex/NumSge): RequestContext RequestContext SRQ NdkSrq SGE SgeAddress/SgeLength/SgeMemoryRegionToken.
Message #
Fields #
| Name | Description |
|---|---|
NdkSrq Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
Event ID 1296 — NDKPI SRQ Work Request Inline Failure: RequestContext RequestContext SRQ NdkSrq Status Status.
Description
NDKPI SRQ Work Request Inline Failure: RequestContext RequestContext SRQ NdkSrq Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkSrq Pointer | — |
RequestContext Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1297 — NDKPI Open Adapter: InterfaceIndex InterfaceIndex Adapter NdkAdapter Status Status.
Description
NDKPI Open Adapter: InterfaceIndex InterfaceIndex Adapter NdkAdapter Status Status.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
NdkAdapter Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1298 — NDKPI Close Adapter (Enter): Adapter NdkAdapter.
Event ID 1299 — NDKPI Close Adapter (Exit): Adapter NdkAdapter.
Event ID 1300 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists. State = State. PID = Pid.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
State UInt32 | — |
Pid UInt32 | — |
ProcessStartKey UInt64 | — |
SendTrackerEnabled UInt32 | — |
RcvBufSet UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1300",
"version": "2",
"level": "4",
"task": "1300",
"opcode": "0",
"keywords": 9223372054034646148,
"time_created": "2026-03-16T00:21:34.294712000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1cf5fec0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1CF5FEC0",
"LocalAddressLength": " 16",
"LocalAddress": "10.2.10.21:52992",
"RemoteAddressLength": " 16",
"RemoteAddress": "10.2.10.11:49669",
"State": " 10",
"Pid": " 0",
"ProcessStartKey": "0",
"SendTrackerEnabled": " 0"
},
"message": ""
}
Event ID 1301 — NDKPI Interface Event: InterfaceIndex InterfaceIndex, NDK-Operational NDKOperational, EventDescription (StatusCode).
Event ID 1302 — Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.
Description
Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination: DestAddress : DestPort.
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | — |
PatternFriendlyName UnicodeString | — |
DlAddrLength UInt32 | — |
SrcDLAddress Binary | — |
DestDLAddress Binary | — |
SrcAddress UInt32 | — |
DestAddress UInt32 | — |
Protocol UInt32 | — Known values
|
SrcPort UInt16 | — |
DestPort UInt16 | — |
Event ID 1302 — Network adapter Luid .
Description
Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination: : .
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | — |
PatternFriendlyName UnicodeString | — |
DlAddrLength UInt32 | — |
SrcDLAddress Binary | — |
DestDLAddress Binary | — |
SrcAddress UInt32 | — |
DestAddress UInt32 | — |
Protocol UInt32 | — Known values
|
SrcPort UInt16 | — |
DestPort UInt16 | — |
Event ID 1303 — Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.
Description
Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination DestAddress : DestPort.
Message #
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | — |
PatternFriendlyName UnicodeString | — |
DlAddrLength UInt32 | — |
SrcDLAddress Binary | — |
DestDLAddress Binary | — |
IpAddrLength UInt32 | — |
SrcAddress Binary | — |
DestAddress Binary | — |
Protocol UInt32 | — Known values
|
SrcPort UInt16 | — |
DestPort UInt16 | — |
Event ID 1303 — Network adapter Luid .
Description
Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination : .
Fields #
| Name | Description |
|---|---|
AdapterLuid UInt64 | — |
PatternFriendlyName UnicodeString | — |
DlAddrLength UInt32 | — |
SrcDLAddress Binary | — |
DestDLAddress Binary | — |
IpAddrLength UInt32 | — |
SrcAddress Binary | — |
DestAddress Binary | — |
Protocol UInt32 | — Known values
|
SrcPort UInt16 | — |
DestPort UInt16 | — |
Event ID 1304 — TCP: Connection Tcb: Silent Mode SilentModeEvent Context Context.
Event ID 1305 — TCP: Connection Tcb notification channel request.
Description
TCP: Connection Tcb notification channel request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
State UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1306 — TCP: Connection Tcb query notification channel status request.
Description
TCP: Connection Tcb query notification channel status request. NcmContext = NcmContext, PID = Pid, Channel Status = ChannelStatus, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
State UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1307 — TCP: Connection Tcb notification channel request processed.
Description
TCP: Connection Tcb notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
Pid UInt32 | — |
Status UInt32 | — NTSTATUS reference |
PushNotificationGuid GUID | — |
Event ID 1308 — TCP: Connection Tcb notification channel signal event.
Description
TCP: Connection Tcb notification channel signal event. NcmContext = NcmContext, PID = Pid, RcvNxt = RcvNxt, Delivered Data = Delivered, Indicated Data = Indicated, FinalEvent = FinalEvent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
Pid UInt32 | — |
RcvNxt UInt32 | — |
Delivered UInt32 | — |
Indicated UInt32 | — |
FinalEvent UInt32 | — |
Event ID 1309 — TCP: Connection Tcb notification channel detached.
Description
TCP: Connection Tcb notification channel detached. NcmContext = NcmContext, TCB State = State. Cleanup NcmContext = IsLoopback.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
State UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1310 — TCP: Connection Tcb notification channel unlinked.
Description
TCP: Connection Tcb notification channel unlinked. TCB State = State.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
State UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1311 — TCP: Connection Tcb notification channel wake pattern plumbing.
Description
TCP: Connection Tcb notification channel wake pattern plumbing. SystemReserved = SystemReserved, Wake-on-Lan Handle = WolHandle, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SystemReserved UInt32 | — |
WolHandle UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1312 — TCP: Connection Tcb notification channel wake pattern deplumbing.
Description
TCP: Connection Tcb notification channel wake pattern deplumbing. Wake-on-Lan Handle = WolHandle, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SystemReserved UInt32 | — |
WolHandle UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1313 — TCPIP: Interface index InterfaceIndex wake pattern properties.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
AoAcCapable UInt32 | — |
BitmapPatternSupported UInt32 | — |
ARPNDOffloadSupported UInt32 | — |
IPAddressWakeReady UInt32 | — |
PatternPriority UInt32 | — |
PhysicalMediumType UInt32 | — |
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
Status UInt32 | — NTSTATUS reference |
HasBeenAoAcCapable UInt32 | — |
WolHandle UInt32 | — |
Event ID 1314 — NDKPI Control CQ Interrupt Moderation: CQ NdkCq Interval ModerationInterval Count ModerationCount Status Status.
Description
NDKPI Control CQ Interrupt Moderation: CQ NdkCq Interval ModerationInterval Count ModerationCount Status Status.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | — |
ModerationInterval UInt32 | — |
ModerationCount UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1315 — TCP: Connection Tcb notification channel request processing.
Description
TCP: Connection notification channel request processing. IsRedirected = , WfpFailure = , Status = , WaitStatus = , Local IP address = , Remote IP address = Local Port = , Remote Port = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
IsRedirected UInt32 | — |
WfpFailure UInt32 | — |
Status UInt32 | — NTSTATUS reference |
WaitStatus UInt32 | — |
IpAddrLength UInt32 | — |
LocalIPv4Address UInt32 | — |
LocalIPv6Address Binary | — |
IPProtocol UInt32 | — |
RemoteIPv4Address UInt32 | — |
RemoteIPv6Address Binary | — |
SrcPort UInt16 | — |
DestPort UInt16 | — |
Event ID 1316 — IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New Bas...
Description
IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New BaseTime = NewBaseTime New ValidTime = NewValidTime.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
CurrentTime UInt32 | — |
OldBaseTime UInt32 | — |
OldValidTime UInt32 | — |
OldPreferredTime UInt32 | — |
NewBaseTime UInt32 | — |
NewValidTime UInt32 | — |
NewPreferredTime UInt32 | — |
InterfaceGuid GUID | — |
IpAddressLifetimeChangeReason UInt32 | — |
Event ID 1317 — TCP: Repartition event Event (Type) OldPartitionCount.
Event ID 1318 — Component PowerStateTransition on processor IndicatingProcessor at Tick = CurrentTick Time = CurrentTime.
Event ID 1319 — Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration...
Description
Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration NewScheduledExpiration = New Scheduled Expiration DueTime = Due Time Aperiodic = Aperiodic.
Message #
Fields #
| Name | Description |
|---|---|
Component UInt32 | — |
Indicating Processor | — |
Target Processor | — |
Current Tick | — |
Next Expiration Tick | — |
Old Scheduled Expiration | — |
New Scheduled Expiration | — |
Due Time | — |
Aperiodic UInt32 | — |
IndicatingProcessor UInt32 | — |
TargetProcessor UInt32 | — |
CurrentTick UInt32 | — |
NextExpirationTick UInt32 | — |
DueTime Int64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1319",
"version": "0",
"level": "5",
"task": "1460",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:34.388840200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Component": " 1",
"Indicating Processor": " 9",
"Target Processor": " 10",
"Current Tick": "57753289",
"Next Expiration Tick": "57753299",
"Old Scheduled Expiration": "577539799250",
"New Scheduled Expiration": "577532789097",
"Due Time": "-100000",
"Aperiodic": " 1"
},
"message": ""
}
Event ID 1320 — Component timer fired on processor Target Processor at Tick = Current Tick, was scheduled for = Next Expiration.
Description
Component timer fired on processor Target Processor at Tick = Current Tick, was scheduled for = Next Expiration.
Message #
Fields #
| Name | Description |
|---|---|
Component UInt32 | — |
Target Processor | — |
Current Tick | — |
Next Expiration | — |
Current Interrupt Time | — |
Scheduled Expiration Time | — |
External Trigger | — |
TargetProcessor UInt32 | — |
CurrentTick UInt32 | — |
NextExpiration UInt32 | — |
ExternalTrigger UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1320",
"version": "0",
"level": "5",
"task": "1461",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:34.401656600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Component": " 1",
"Target Processor": " 10",
"Current Tick": "57753302",
"Next Expiration": "57753299",
"Current Interrupt Time": "577532821643",
"Scheduled Expiration Time": "577532789097",
"External Trigger": " 0"
},
"message": ""
}
Event ID 1321 — IP: Connecting interface InterfaceIndex, trace = TraceString.
Event ID 1322 — IP: Limited link connectivity set on interface InterfaceIndex, trace = TraceString.
Event ID 1323 — IP: Limited link connectivity reset on interface InterfaceIndex, trace = TraceString.
Event ID 1324 — IP: Neighbor with IpAddress = IP Address DlAddress = DL Address on Interface = Interface changed state from Old Neighbor State to New Neighbor State due to Event = Neighbor Event.
Description
IP: Neighbor with IpAddress = IP Address DlAddress = DL Address on Interface = Interface changed state from Old Neighbor State to New Neighbor State due to Event = Neighbor Event.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
IpAddrLength UInt32 | — |
IP Address | — |
DlAddrLength UInt32 | — |
DL Address | — |
Old Neighbor State | — |
New Neighbor State | — |
Neighbor Event | — |
CompartmentId UInt32 | — |
IPAddress Binary | — |
DLAddress Binary | — |
OldNeighborState UInt32 | — |
NewNeighborState UInt32 | — |
NeighborEvent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1324",
"version": "1",
"level": "4",
"task": "1324",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:22:30.711141200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"IpAddrLength": " 16",
"IP Address": "10.2.10.11",
"DlAddrLength": " 6",
"DL Address": "0xBC241141F258",
"Old Neighbor State": " 5",
"New Neighbor State": " 2",
"Neighbor Event": " 9",
"CompartmentId": " 1"
},
"message": ""
}
Event ID 1325 — IP: Neighbor Event on Interface = Interface from SourceIpAddress = Source IP Address for TargetIpAddress = Target IP Address.
Description
IP: Neighbor Event on Interface = Interface from SourceIpAddress = Source IP Address for TargetIpAddress = Target IP Address.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
IpAddrLength UInt32 | — |
Source IP Address | — |
Target IP Address | — |
Neighbor Event | — |
CompartmentId UInt32 | — |
SourceIPAddress Binary | — |
TargetIPAddress Binary | — |
NeighborEvent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1325",
"version": "1",
"level": "5",
"task": "1325",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:59.242716700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"IpAddrLength": " 16",
"Source IP Address": "10.2.10.254",
"Target IP Address": "10.2.10.21",
"Neighbor Event": " 12",
"CompartmentId": " 1"
},
"message": ""
}
Event ID 1326 — IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName.
Description
IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | — |
PreferredSourceIPAddress Binary | — |
NonPreferredSourceIPAddress Binary | — |
DestinationIPAddress Binary | — |
CompartmentId UInt32 | — |
Rule UInt32 | — |
RuleExtension UInt32 | — |
RuleName UInt32 | — |
Event ID 1327 — IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Opti...
Description
IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Option, Rule = Rule Type Rule Major.Rule Minor.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | — |
Preferred Source IP Address | — |
Preferred Destination IP Address | — |
Non-Preferred Source IP Address | — |
Non-Preferred Destination IP Address | — |
Sort Option | — |
Rule Type | — |
Rule Major | — |
Rule Minor | — |
RuleName UInt32 | — |
PreferredSourceIPAddress Binary | — |
PreferredDestinationIPAddress Binary | — |
NonPreferredSourceIPAddress Binary | — |
NonPreferredDestinationIPAddress Binary | — |
SortOption UInt32 | — |
RuleType AnsiString | — |
RuleMajor UInt32 | — |
RuleMinor UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1327",
"version": "1",
"level": "5",
"task": "1327",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:23:59.745142800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "1992",
"thread_id": "6452"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IpAddrLength": " 28",
"Preferred Source IP Address": "::ffff:10.2.10.21",
"Preferred Destination IP Address": "::ffff:192.228.79.201",
"Non-Preferred Source IP Address": "::",
"Non-Preferred Destination IP Address": "2001:478:65::53",
"Sort Option": " 0",
"Rule Type": "D",
"Rule Major": " 1",
"Rule Minor": " 0",
"RuleName": " 16"
},
"message": ""
}
Event ID 1328 — NDKPI ResultEx ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext Type Type TypeSpecific TypeSpecificCompletionOutput.
Description
NDKPI ResultEx ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext Type Type TypeSpecific TypeSpecificCompletionOutput.
Message #
Fields #
| Name | Description |
|---|---|
NdkCq Pointer | — |
Status UInt32 | — NTSTATUS reference |
BytesTransferred UInt32 | — |
QpContext Pointer | — |
RequestContext Pointer | — |
ResultIndex Int32 | — |
ResultCount Int32 | — |
Type UInt32 | — |
TypeSpecificCompletionOutput UInt64 | — |
ProviderErrorCode UInt32 | — |
Event ID 1329 — NDKPI SendInvalidate (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteToken RemoteToken Flags Flags.
Description
NDKPI SendInvalidate (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteToken RemoteToken Flags Flags.
Message #
Fields #
| Name | Description |
|---|---|
NdkQp Pointer | — |
RequestContext Pointer | — |
SgeAddress Pointer | — |
SgeLength UInt32 | — |
SgeMemoryRegionToken UInt32 | — |
NumSge Int32 | — |
Flags UInt32 | — |
SgeIndex Int32 | — |
RemoteToken UInt32 | — |
Event ID 1330 — TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
Description
TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SndWnd UInt32 | — |
BytesAcked UInt32 | — |
SeqNo UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1330",
"version": "0",
"level": "4",
"task": "1071",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390572700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Cwnd": " 2110976",
"SndWnd": " 2110976",
"BytesAcked": " 1303",
"SeqNo": "2307521250"
},
"message": ""
}
Event ID 1331 — TCP: connection Tcb: CTCP Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.
Event ID 1332 — TCP: connection Tcb: TCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Description
TCP: connection Tcb: TCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SndWnd UInt32 | — |
BytesSent UInt32 | — |
SeqNo UInt32 | — |
SRtt UInt32 | — |
RttVar UInt32 | — |
RTO UInt32 | — |
RcvWnd UInt32 | — |
PacingRate UInt32 | — |
TcpState UInt32 | — |
CongestionState UInt32 | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
RecoveryMax UInt32 | — |
RcvBufSet UInt32 | — |
MaxRcvBuf UInt32 | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1332",
"version": "1",
"level": "4",
"task": "1073",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.266633700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"Cwnd": " 1705088",
"SndWnd": " 1705088",
"BytesSent": " 0",
"SeqNo": "644684595",
"SRtt": " 596",
"RttVar": " 279",
"RTO": " 60",
"RcvWnd": " 261882"
},
"message": ""
}
Event ID 1333 — TCP: connection Tcb: TCP CTCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Description
TCP: connection Tcb: TCP CTCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SndWnd UInt32 | — |
BytesSent UInt32 | — |
SeqNo UInt32 | — |
SRtt UInt32 | — |
RttVar UInt32 | — |
RTO UInt32 | — |
RcvWnd UInt32 | — |
Event ID 1334 — UDP: Endpoint UdpEndpoint notification channel request.
Description
UDP: Endpoint UdpEndpoint notification channel request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, IsLoopback = IsLoopback, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
NcmContext Pointer | — |
Activated UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1335 — UDP: Endpoint UdpEndpoint query notification channel status request.
Description
UDP: Endpoint UdpEndpoint query notification channel status request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, Channel Status = ChannelStatus, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
NcmContext Pointer | — |
Activated UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1336 — UDP: Endpoint UdpEndpoint notification channel request processed.
Description
UDP: Endpoint UdpEndpoint notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
NcmContext Pointer | — |
Pid UInt32 | — |
Status UInt32 | — NTSTATUS reference |
PushNotificationGuid GUID | — |
Event ID 1337 — UDP: Endpoint UdpEndpoint notification channel signal event.
Event ID 1338 — UDP: Endpoint UdpEndpoint notification channel detached.
Description
UDP: Endpoint UdpEndpoint notification channel detached. NcmContext = NcmContext, Endpoint State = Activated.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
NcmContext Pointer | — |
Activated UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1339 — UDP: Endpoint UdpEndpoint notification channel unlinked.
Description
UDP: Endpoint UdpEndpoint notification channel unlinked. Endpoint State = Activated.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
NcmContext Pointer | — |
Activated UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
ChannelStatus UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1340 — UDP: Endpoint UdpEndpoint notification channel request processing.
Description
UDP: Endpoint UdpEndpoint notification channel request processing. Local IP address = LocalIPv4Address IPProtocol LocalIPv6Address, Local Port = SrcPort.
Message #
Fields #
| Name | Description |
|---|---|
UdpEndpoint Pointer | — |
IpAddrLength UInt32 | — |
LocalIPv4Address UInt32 | — |
LocalIPv6Address Binary | — |
IPProtocol UInt32 | — |
SrcPort UInt16 | — |
Event ID 1341 — TCP: connection Tcb: Rtt sample recorded RttSample SRTT SRTT RttVar RttVar.
Description
TCP: connection Tcb: Rtt sample recorded RttSample SRTT SRTT RttVar RttVar.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
RttSample UInt32 | — |
RttVar UInt32 | — |
SRTT UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1341",
"version": "0",
"level": "5",
"task": "1070",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390489700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"RttSample": " 1632",
"RttVar": " 544",
"SRTT": " 1626"
},
"message": ""
}
Event ID 1342 — TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.
Event ID 1343 — TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo.
Description
TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
DupAckCount UInt32 | — |
SeqNo UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1343",
"version": "0",
"level": "4",
"task": "1072",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-16T00:21:40.488225900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Cwnd": " 16734",
"SSThresh": "4294967295",
"DupAckCount": " 1",
"SeqNo": "155002622"
},
"message": ""
}
Event ID 1344 — TCP: CTCP Duplicate Ack event.
Event ID 1345 — TCP: connection Tcb: Spurious timeout at Seq = SeqNo.
Event ID 1346 — TCP: connection Tcb spurious RTO detection initiated at SeqNo.
Event ID 1347 — TCP: connection Tcb spurious RTO detection terminated at SeqNo.
Event ID 1348 — TCP: CTCP DataTransferTimeout event.
Event ID 1349 — TCP: CTCP Spurious timeout event.
Event ID 1350 — TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Description
TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1350",
"version": "0",
"level": "4",
"task": "1082",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-15T23:27:12.440659500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"Cwnd": " 15414",
"SSThresh": " 15414"
},
"message": ""
}
Event ID 1351 — TCP: connection Tcb: Send Retransmit round with SndUna = SndUna, Round = RexmitCount, SRTT = SRTT, RTO = RTO.
Description
TCP: connection Tcb: Send Retransmit round with SndUna = SndUna, Round = RexmitCount, SRTT = SRTT, RTO = RTO.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
RexmitCount UInt32 | — |
SRTT UInt32 | — |
RTO UInt32 | — |
SndMax UInt32 | — |
RecoveryMax UInt32 | — |
TcpState UInt32 | — |
CongestionState UInt32 | — |
Frto UInt32 | — |
TotalRT UInt32 | — |
MaxRT UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1351",
"version": "0",
"level": "4",
"task": "1077",
"opcode": "0",
"keywords": 9223372041149743232,
"time_created": "2026-03-15T23:31:42.716273800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF9CA95F0",
"SndUna": "2098991634",
"RexmitCount": " 1",
"SRTT": " 3000",
"RTO": " 2000"
},
"message": ""
}
Event ID 1352 — TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
DataBytesOut UInt64 | — |
DataBytesIn UInt64 | — |
DataSegmentsOut UInt64 | — |
DataSegmentsIn UInt64 | — |
SegmentsOut UInt64 | — |
SegmentsIn UInt64 | — |
NonRecovDa UInt32 | — |
NonRecovDaEpisodes UInt32 | — |
DupAcksIn UInt32 | — |
BytesRetrans UInt32 | — |
Timeouts UInt32 | — |
SpuriousRtoDetections UInt32 | — |
FastRetran UInt32 | — |
MaxSsthresh UInt32 | — |
MaxSsCwnd UInt32 | — |
MaxCaCwnd UInt32 | — |
SndLimTransRwin UInt32 | — |
SndLimTimeRwin UInt32 | — |
SndLimBytesRwin UInt64 | — |
SndLimTransCwnd UInt32 | — |
SndLimTimeCwnd UInt32 | — |
SndLimBytesCwnd UInt64 | — |
SndLimTransSnd UInt32 | — |
SndLimTimeRSnd UInt32 | — |
SndLimBytesRSnd UInt64 | — |
Event ID 1353 — TCPIP: Message AllocationObjectString Param1 Param2 Param3 Param4.
Event ID 1354 — TCP: Connection Tcb SACK updated SndUna SndUna SndMax SndMax SackCount SackCount SackBytes SackBytes SackInFlight SackInFlight SackIsLost SackIsLost.
Description
TCP: Connection Tcb SACK updated SndUna SndUna SndMax SndMax SackCount SackCount SackBytes SackBytes SackInFlight SackInFlight SackIsLost SackIsLost.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
SackCount UInt32 | — |
SackBytes UInt32 | — |
SackInFlight UInt32 | — |
SackIsLost UInt32 | — |
Event ID 1355 — TCP: TCB Tcb Requires address based pattern = RequireAddressCoalescing LocalPort = LocalPort RtcPortRange = [RtcStartPort, RtcEndPort] Status = Status.
Description
TCP: TCB Tcb Requires address based pattern = RequireAddressCoalescing LocalPort = LocalPort RtcPortRange = [RtcStartPort, RtcEndPort] Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
RequireAddressCoalescing UInt32 | — |
LocalPort UInt16 | — |
RtcStartPort UInt16 | — |
RtcEndPort UInt16 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1356 — TCP: Rtc Port Range Assignment.
Event ID 1357 — TCPIP has failed a RequestType request from LocalAddress to RemoteAddress on endpoint TcbOrEndpoint owned by process ProcessId with Status since network interface InterfaceIndex is in low-power mode.
Description
TCPIP has failed a RequestType request from LocalAddress to RemoteAddress on endpoint TcbOrEndpoint owned by process ProcessId with Status since network interface InterfaceIndex is in low-power mode.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | — |
TcbOrEndpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
InterfaceIndex UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1358 — IP: Interface configuration updated on interface InterfaceIndex property Property value Value event InterfaceUpdateEvent.
Event ID 1359 — TCP: Connection Tcb notification channel unmark request.
Description
TCP: Connection Tcb notification channel unmark request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, IsShutdown = IsShutdown, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NcmContext Pointer | — |
State UInt32 | — |
Pid UInt32 | — |
IsLoopback UInt32 | — |
IsShutdown UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1360 — TCPIP: A packet has been cloned for a raw listener.
Event ID 1361 — TCPIP: A cloned packet has been dropped.
Event ID 1362 — IP: Interface = Interface IpAddress = IPAddress processing WolEvent = WoLEvent with Status = Status.
Description
IP: Interface = Interface IpAddress = IPAddress processing WolEvent = WoLEvent with Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
IpAddrLength UInt32 | — |
IPAddress Binary | — |
WoLEvent UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1363 — IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processin...
Description
IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processing WolEvent = WoLEvent with Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
IpAddrLength UInt32 | — |
WolHandle UInt32 | — |
DestinationIPAddress Binary | — |
TargetIPAddress1 Binary | — |
TargetIPAddress2 Binary | — |
Flags UInt32 | — |
WoLEvent UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1364 — TCP connection tuple inserted- TCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.
Event ID 1365 — TCP connection tuple removed- TCB/TWTCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.
Event ID 1366 — TCP port selection deferred for outbound connect- LocalAddress: LocalAddress.
Description
TCP port selection deferred for outbound connect- LocalAddress: LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1367 — Nbl Nbl OOB info (PathDirection): TcpIpChecksumNetBufferListInfo TcpIpChecksumNetBufferListInfo, TcpLargeSendNetBufferListInfo TcpLargeSendNetBufferListInfo, Ieee8021QNetBufferListInfo Ieee8021QNet...
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | — |
PathDirection UInt32 | — |
TcpIpChecksumNetBufferListInfo Pointer | — |
TcpLargeSendNetBufferListInfo Pointer | — |
Ieee8021QNetBufferListInfo Pointer | — |
NetBufferListHashValue Pointer | — |
NetBufferListHashInfo Pointer | — |
VirtualSubnetInfo Pointer | — |
TcpRecvSegCoalesceInfo Pointer | — |
NrtNameResolutionInfo Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1367",
"version": "1",
"level": "17",
"task": "1367",
"opcode": "0",
"keywords": 9223372049739677696,
"time_created": "2026-03-16T00:21:34.388895400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A11CCA4F0",
"PathDirection": " 0",
"TcpIpChecksumNetBufferListInfo": "0x220015",
"TcpLargeSendNetBufferListInfo": "0x0",
"Ieee8021QNetBufferListInfo": "0x0",
"NetBufferListHashValue": "0xF92BBC40",
"NetBufferListHashInfo": "0x0",
"VirtualSubnetInfo": "0x0",
"TcpRecvSegCoalesceInfo": "0x0",
"NrtNameResolutionInfo": "0x0"
},
"message": ""
}
Event ID 1368 — Teredo Add -- PID: PID started listening on LocalAddress.
Description
Teredo Add -- PID: PID started listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.
Message #
Fields #
| Name | Description |
|---|---|
PID UInt64 | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
AddressType UInt32 | — |
ScopeLevel UInt32 | — |
Port UInt32 | — |
EndpointRecord Pointer | — |
Event ID 1369 — Teredo Remove -- PID: PID stopped listening on LocalAddress.
Description
Teredo Remove -- PID: PID stopped listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.
Message #
Fields #
| Name | Description |
|---|---|
PID UInt64 | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
AddressType UInt32 | — |
ScopeLevel UInt32 | — |
Port UInt32 | — |
EndpointRecord Pointer | — |
Event ID 1370 — IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained...
Description
IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained: ReturnConstrained OutgoingIfIndex: OutgoingInterfaceIndex NextHopAddr: NextHopAddress Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
API AnsiString | — |
IpAddrLength UInt32 | — |
DestinationAddress Binary | — |
ConstrainSourceAddress Binary | — |
ConstrainInterfaceIndex UInt32 | — |
ConstraintOverridden UInt32 | — |
ReturnConstrained UInt32 | — |
OutgoingInterfaceIndex UInt32 | — |
NextHopAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ConstrainForwardingTag UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1370",
"version": "0",
"level": "5",
"task": "1370",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-15T23:26:13.698249300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "1868",
"thread_id": "2740"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"API": "IppFindPath",
"IpAddrLength": " 16",
"DestinationAddress": "127.0.0.1",
"ConstrainSourceAddress": "0.0.0.0",
"ConstrainInterfaceIndex": " 0",
"ConstraintOverridden": " 0",
"ReturnConstrained": " 0",
"OutgoingInterfaceIndex": " 1",
"NextHopAddress": "127.0.0.1",
"Status": "0x0"
},
"message": ""
}
Event ID 1371 — IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: Retu...
Description
IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: ReturnConstrained SelectedSrcAddr: SelectedSourceAddress.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | — |
DestinationAddress Binary | — |
ConstrainSourceAddress Binary | — |
ConstrainInterfaceIndex UInt32 | — |
OutgoingInterfaceIndex UInt32 | — |
ReturnConstrained UInt32 | — |
SelectedSourceAddress Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1371",
"version": "0",
"level": "5",
"task": "1371",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:40.067796000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IpAddrLength": " 16",
"DestinationAddress": "0.0.0.0",
"ConstrainSourceAddress": "0.0.0.0",
"ConstrainInterfaceIndex": " 0",
"OutgoingInterfaceIndex": " 6",
"ReturnConstrained": " 0",
"SelectedSourceAddress": "10.2.10.21"
},
"message": ""
}
Event ID 1372 — WFP-ALE: Partition Count=PartitionCount Partition Mask=PartitionMask: Partition Id=%d Partition NumEntries = NumEntries.
Event ID 1373 — WFP-ALE: HotAdd/Remove: Old Partiton Count=OldPartitionCount Old Partition Mask=OldPartitionMask New Partiton Count=OldPartitionCount New Partition Mask=OldPartitionMask.
Description
WFP-ALE: HotAdd/Remove: Old Partiton Count=OldPartitionCount Old Partition Mask=OldPartitionMask New Partiton Count=OldPartitionCount New Partition Mask=OldPartitionMask.
Message #
Fields #
| Name | Description |
|---|---|
OldPartitionCount UInt64 | — |
OldPartitionMask UInt64 | — |
NewPartitionCount UInt64 | — |
NewPartitionMask UInt64 | — |
Event ID 1374 — WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEnt...
Description
WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
RemoteAddress Binary | — |
RemotePort UInt64 | — |
LocalAddress Binary | — |
LocalPort UInt16 | — |
PartitionId UInt64 | — |
NumEntries UInt64 | — |
Event ID 1375 — WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntr...
Description
WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
RemoteAddress Binary | — |
RemotePort UInt64 | — |
LocalAddress Binary | — |
LocalPort UInt16 | — |
PartitionId UInt64 | — |
NumEntries UInt64 | — |
Event ID 1376 — WFP-ALE: ALE: low memory state detected.
Event ID 1377 — WFP-ALE: leaving low memory state.
Description
WFP-ALE: leaving low memory state. HighMemoryEvent = HighMemoryEvent HighNonPagedPoolEvent = HighNonPagedPoolEvent.
Message #
Fields #
| Name | Description |
|---|---|
HighMemoryEvent UInt32 | — |
HighNonPagedPoolEvent UInt32 | — |
LowMemoryEvent UInt32 | — |
LowNonPagedPoolEvent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1377",
"version": "0",
"level": "4",
"task": "1373",
"opcode": "0",
"keywords": 9223372036854841344,
"time_created": "2026-03-15T23:26:23.462874700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"HighMemoryEvent": " 1",
"HighNonPagedPoolEvent": " 1",
"LowMemoryEvent": " 0",
"LowNonPagedPoolEvent": " 0"
},
"message": ""
}
Event ID 1378 — WFP-ALE: Dpc for cleanup initiated: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
Event ID 1379 — WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
Description
WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.
Message #
Fields #
| Name | Description |
|---|---|
HighMemoryEvent UInt32 | — |
HighNonPagedPoolEvent UInt32 | — |
LowMemoryEvent UInt32 | — |
LowNonPagedPoolEvent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1379",
"version": "0",
"level": "5",
"task": "1373",
"opcode": "0",
"keywords": 9223372036854841344,
"time_created": "2026-03-16T00:21:40.078370400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"HighMemoryEvent": " 1",
"HighNonPagedPoolEvent": " 1",
"LowMemoryEvent": " 0",
"LowNonPagedPoolEvent": " 0"
},
"message": ""
}
Event ID 1380 — TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPerc...
Description
TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPercent%, RemainingTimeMs = RemainingTimeMs.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
LedbatEvent UInt32 | — |
Cwnd UInt32 | — |
SsThresh UInt32 | — |
SndWnd UInt32 | — |
BaseDelayMs UInt16 | — |
CurrentDelayMs UInt16 | — |
RemainingTimeMs UInt32 | — |
DelayBasedCwndFactorPercent Int32 | — |
Event ID 1381 — TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %...
Description
TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %13 %15.
Message #
Fields #
| Name | Description |
|---|---|
EndpointObj Pointer | — |
IsConnectionObj UInt32 | — |
NameResContext Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1382 — TCP: InspectConnectWithNameResContext Connection: Tcb (local: LocalAddress remote: RemoteAddress) NameResolutionContext: NameResContext DnsName: DnsName Status: Status.
Description
TCP: InspectConnectWithNameResContext Connection: Tcb (local: LocalAddress remote: RemoteAddress) NameResolutionContext: NameResContext DnsName: DnsName Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Tcb Pointer | — |
NameResContext Pointer | — |
DnsName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1383 — IP: Route [DestinationPrefix: PrDestinationPrefix/PrDestinationPrefixLength NextHop: PrNextHopAddress InterfaceIndex: PrInterfaceIndex InterfaceMetric: PrInterfaceMetric RouteMetric: PrRouteMetric]...
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
DestinationAddressLength UInt32 | — |
DestinationAddress Binary | — |
PrDestinationPrefixLength UInt32 | — |
PrDestinationPrefixAddressLength UInt32 | — |
PrDestinationPrefix Binary | — |
PrNextHopAddressLength UInt32 | — |
PrNextHopAddress Binary | — |
PrInterfaceIndex UInt32 | — |
PrInterfaceMetric UInt32 | — |
PrRouteMetric UInt32 | — |
NonPrDestinationPrefixLength UInt32 | — |
NonPrDestinationPrefixAddressLength UInt32 | — |
NonPrDestinationPrefix Binary | — |
NonPrNextHopAddressLength UInt32 | — |
NonPrNextHopAddress Binary | — |
NonPrInterfaceIndex UInt32 | — |
NonPrInterfaceMetric UInt32 | — |
NonPrRouteMetric UInt32 | — |
PreferenceReason UInt32 | — |
Event ID 1384 — IP: Route [DestinationPrefix: DestinationPrefix/DestinationPrefixLength NextHop: NextHopAddress InterfaceIndex: InterfaceIndex RouteMetric: RouteMetric] is blocked for Destination: DestinationAddre...
Description
IP: Route [DestinationPrefix: / NextHop: InterfaceIndex: RouteMetric: ] is blocked for Destination: ConstrainInterfaceIndex: ConstrainScopeZone: in Compartment: , Reason: .
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
DestinationAddressLength UInt32 | — |
DestinationAddress Binary | — |
DestinationPrefixLength UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
InterfaceIndex UInt32 | — |
RouteMetric UInt32 | — |
ConstrainInterfaceIndex UInt32 | — |
ConstrainScope UInt32 | — |
BlockReason UInt32 | — |
Event ID 1385 — TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSe...
Description
TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSend, ThFlags = ThFlags.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
SendAvailable UInt32 | — |
TailProbeSeq UInt32 | — |
TailProbeLast UInt32 | — |
ControlsToSend UInt32 | — |
ThFlags UInt8 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1385",
"version": "0",
"level": "4",
"task": "1380",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.721122900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"SndUna": "2308839694",
"SndMax": "2308842691",
"SendAvailable": " 2997",
"TailProbeSeq": "2308841231",
"TailProbeLast": "2308842691",
"ControlsToSend": " 0",
"ThFlags": "16"
},
"message": ""
}
Event ID 1386 — TCP: Tail Loss Probe Event Connection = Tcb, Event = TlpEvent.
Description
TCP: Tail Loss Probe Event Connection = Tcb, Event = TlpEvent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
TlpEvent UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1386",
"version": "0",
"level": "4",
"task": "1380",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.388823900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"TlpEvent": " 1"
},
"message": ""
}
Event ID 1387 — TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample =...
Description
TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample = RttSample.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
RackEvent UInt32 | — |
RackMinRtt UInt32 | — |
RackReoWind UInt32 | — |
RackTimeSlotDeltaMin UInt32 | — |
SequenceNumber UInt32 | — |
Timestamp UInt32 | — |
RttSample UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1387",
"version": "0",
"level": "4",
"task": "1381",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:14.411027300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f6654220-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "10828",
"thread_id": "9684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FF6654220",
"RackEvent": " 1",
"RackMinRtt": " 751",
"RackReoWind": " 0",
"RackTimeSlotDeltaMin": " 0",
"SequenceNumber": "2723729970",
"Timestamp": "4090263552",
"RttSample": " 751"
},
"message": ""
}
Event ID 1388 — TCP: Fastopen state changed for connection = Tcb from OldState = OldState to NewState = NewState.
Event ID 1389 — UDP: endpoint (family=AddressFamily pid=ProcessId) create failed: address family not attached.
Description
UDP: endpoint (family=AddressFamily pid=ProcessId) create failed: address family not attached.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1390 — UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: compartment CompartmentId not found.
Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: compartment CompartmentId not found.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1391 — UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) created.
Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1391",
"version": "1",
"level": "4",
"task": "1385",
"opcode": "0",
"keywords": 9223372036854776833,
"time_created": "2026-03-16T00:21:40.077667700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"Status": "0x0",
"ProcessId": " 228",
"CompartmentId": " 1",
"AddressFamily": " 23",
"ProcessStartKey": "2814749767106594"
},
"message": ""
}
Event ID 1392 — UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: inspection status = Status.
Description
UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1393 — UDP: endpoint Endpoint bind failed: address LocalAddress cannot be resolved, status = Status.
Description
UDP: endpoint Endpoint bind failed: address LocalAddress cannot be resolved, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Event ID 1394 — UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: port-acquisition status = Status.
Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: port-acquisition status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Event ID 1395 — UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: inspection status = Status.
Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: inspection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Event ID 1396 — UDP: endpoint Endpoint (sockaddr=LocalAddress) bound.
Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bound.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Pid UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1396",
"version": "0",
"level": "4",
"task": "1390",
"opcode": "0",
"keywords": 9223372036854776841,
"time_created": "2026-03-16T00:21:40.078017600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::]:53893",
"Status": "0x0",
"Endpoint": "0xFFFF980A11735E80"
},
"message": ""
}
Event ID 1397 — UDP: endpoint Endpoint (sockaddr=LocalAddress) closed.
Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) closed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1397",
"version": "0",
"level": "4",
"task": "1391",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.117474200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "2612"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 28",
"LocalAddress": "[::]:53893",
"Status": "0x0",
"Endpoint": "0xFFFF980A11735E80"
},
"message": ""
}
Event ID 1398 — UDP: endpoint Endpoint closed.
Description
UDP: endpoint Endpoint closed.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1398",
"version": "0",
"level": "4",
"task": "1392",
"opcode": "0",
"keywords": 9223372105574253569,
"time_created": "2026-03-16T00:21:40.118277500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11737aa0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "10580"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"LocalAddressLength": " 0",
"LocalAddress": "",
"Status": "0x0",
"Endpoint": "0xFFFF980A11737AA0"
},
"message": ""
}
Event ID 1399 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address resolution status = Status.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address resolution status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1400 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address validation failed.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address validation failed.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1401 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: source-address selection status = Status.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: source-address selection status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1402 — UDP: endpoint {Endpoint} too many packets queued for the pending join path.
Event ID 1403 — UDP: address family AddressFamilyadded to interface InterfaceIndex.
Event ID 1404 — UDP: address family AddressFamilyremoved from interface InterfaceIndex.
Event ID 1405 — UDP: Failure initializing transport protocol, status = Status.
Description
UDP: Failure initializing transport protocol, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1406 — UDP: Failure starting NLNPI client, status = Status.
Description
UDP: Failure starting NLNPI client, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1407 — UDP: Failure initializing NSI support, status = Status.
Description
UDP: Failure initializing NSI support, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1408 — UDP: Failure starting TLNPI provider, status = Status.
Description
UDP: Failure starting TLNPI provider, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1409 — UDP: Failure initializing QoS support, status = Status.
Description
UDP: Failure initializing QoS support, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1410 — UDP: Failure starting FailedQueueString, status = Status.
Description
UDP: Failure starting FailedQueueString, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
FailedQueueString UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1411 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: could not allocate send context.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: could not allocate send context.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1412 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path af failure, status = Status.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path af failure, status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1413 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path missing next hop failure.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path missing next hop failure.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1414 — UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path next hop address failure.
Description
UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path next hop address failure.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1415 — TCP: Early Retransmission, FACK or RACK, Connection = Tcb, SndUna = SndUna, SackIsLostSeq = SackIsLostSeq, DupAckCount = DupAckCount.
Description
TCP: Early Retransmission, FACK or RACK, Connection = Tcb, SndUna = SndUna, SackIsLostSeq = SackIsLostSeq, DupAckCount = DupAckCount.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SackIsLostSeq UInt32 | — |
DupAckCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1415",
"version": "0",
"level": "4",
"task": "1409",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440656500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SndUna": "4068749001",
"SackIsLostSeq": " 0",
"DupAckCount": " 1"
},
"message": ""
}
Event ID 1416 — TCP: Ignoring fastopen SYN option due to limit on concurrent SYN_RCVD fastopen connections, Connection = Tcb, SynRcvdLimit = SynRcvdLimit.
Event ID 1417 — TCP: Failed to update fastopen key state, Location = Location, Status = Status.
Description
TCP: Failed to update fastopen key state, Location = Location, Status = Status. Server-side fastopen will be disabled.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1418 — TCP: Fast Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Description
TCP: Fast Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
BytesToSend UInt32 | — |
SndNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1418",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.489901200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"BytesToSend": " 1440",
"SndNxt": "155002622"
},
"message": ""
}
Event ID 1419 — TCP: SACK Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Description
TCP: SACK Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
BytesToSend UInt32 | — |
SndNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1419",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.490433800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"BytesToSend": " 38",
"SndNxt": "155004100"
},
"message": ""
}
Event ID 1420 — TCP: Limited Transmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Description
TCP: Limited Transmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
BytesToSend UInt32 | — |
SndNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1420",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.162052500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"BytesToSend": " 1440",
"SndNxt": "1228953133"
},
"message": ""
}
Event ID 1421 — TCP: SACK Retransmit Additional Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Description
TCP: SACK Retransmit Additional Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
BytesToSend UInt32 | — |
SndNxt UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1421",
"version": "0",
"level": "4",
"task": "1412",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:23:27.167320000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A170D1290",
"BytesToSend": " 1440",
"SndNxt": "1228956013"
},
"message": ""
}
Event ID 1422 — IPTransportProtocol: PathDirectionmessage.
Description
IPTransportProtocol: PathDirectionmessage. Type = IcmpType, Code = IcmpCode, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | — |
PathDirection UInt32 | — |
IcmpType UInt32 | — |
IcmpCode UInt32 | — |
CompartmentId UInt32 | — |
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
DestAddressLength UInt32 | — |
DestAddress Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1422",
"version": "0",
"level": "4",
"task": "1413",
"opcode": "0",
"keywords": 9223372586610589696,
"time_created": "2026-03-16T00:21:40.180500700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 1",
"PathDirection": " 0",
"IcmpType": " 3",
"IcmpCode": " 3",
"CompartmentId": " 1",
"SourceAddressLength": " 16",
"SourceAddress": "10.2.10.21",
"DestAddressLength": " 16",
"DestAddress": "8.8.8.8"
},
"message": ""
}
Event ID 1423 — IPTransportProtocol: PathDirectionpath drop.
Description
IPTransportProtocol: PathDirectionpath drop. Type = IcmpType, Code = IcmpCode, Reason = DropReason, Status = Status, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | — |
PathDirection UInt32 | — |
IcmpType UInt32 | — |
IcmpCode UInt32 | — |
DropReason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
CompartmentId UInt32 | — |
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
DestAddressLength UInt32 | — |
DestAddress Binary | — |
IfIndex UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1423",
"version": "1",
"level": "4",
"task": "1414",
"opcode": "0",
"keywords": 9223373136366403712,
"time_created": "2026-03-15T23:30:50.067428800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "10828",
"thread_id": "12980"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IPTransportProtocol": " 1",
"PathDirection": " 0",
"IcmpType": " 3",
"IcmpCode": " 3",
"DropReason": " 12",
"Status": "0xC000021B",
"CompartmentId": " 1",
"SourceAddressLength": " 16",
"SourceAddress": "10.2.10.11",
"DestAddressLength": " 16",
"DestAddress": "10.2.10.21",
"IfIndex": " 4"
},
"message": ""
}
Event ID 1424 — IPTransportProtocol: Echo timeout.
Description
IPTransportProtocol: Echo timeout. Status = IcmpCode.
Message #
Fields #
| Name | Description |
|---|---|
IPTransportProtocol UInt32 | — |
PathDirection UInt32 | — |
IcmpType UInt32 | — |
IcmpCode UInt32 | — |
DropReason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
CompartmentId UInt32 | — |
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
DestAddressLength UInt32 | — |
DestAddress Binary | — |
Event ID 1425 — Component Timer state changed to CurrentState by Processor Processor Usage = ProcessorUsage at Tick = CurrentTick.
Event ID 1426 — TCP: connection Tcb send complete NumBytes bytes at SndNxt (Injected).
Description
TCP: connection Tcb send complete NumBytes bytes at SndNxt (Injected).
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Injected UnicodeString | — |
NumBytes UInt32 | — |
SndNxt UInt32 | — |
ActivityID Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1426",
"version": "0",
"level": "5",
"task": "1417",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:34.390792600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4248",
"thread_id": "4684"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A1018B560",
"Injected": "normal",
"NumBytes": " 1303",
"SndNxt": "2307521250"
},
"message": ""
}
Event ID 1427 — IP: Compartment creation.
Description
IP: Compartment creation. Compartment = CompartmentId, Protocol = AddressFamily, Private = Private, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Private UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1428 — IP: Compartment deletion.
Description
IP: Compartment deletion. Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Private UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1429 — TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd = SndWnd, InRecovery = InRecovery, TimeSinceLastLossMS = TimeSinceLastLossMS, CubicCwnd...
Description
TCP: connection : Cumulative Ack event, SeqNo = , BytesAcked = , CWnd = , SndWnd = , InRecovery = , TimeSinceLastLossMS = , CubicCwnd = , AimdCwnd = , K = , Wmax = , LastWmax = , MaxSndWnd = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SndWnd UInt32 | — |
BytesAcked UInt32 | — |
SeqNo UInt32 | — |
InRecovery UInt8 | — |
TimeSinceLastLossMS UInt64 | — |
CubicCwnd UInt64 | — |
AimdCwnd UInt32 | — |
K UInt64 | — |
Wmax UInt32 | — |
LastWmax UInt32 | — |
MaxSndWnd UInt32 | — |
IsLimitedSlowStart UInt8 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1429",
"version": "1",
"level": "4",
"task": "1420",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:36.015001500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{10708010-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A10708010",
"Cwnd": " 27376",
"SndWnd": " 262656",
"BytesAcked": " 0",
"SeqNo": "3807647817",
"InRecovery": "0",
"TimeSinceLastLossMS": "0",
"CubicCwnd": "0",
"AimdCwnd": " 0",
"K": "0",
"Wmax": " 0",
"LastWmax": " 0",
"MaxSndWnd": " 262656",
"IsLimitedSlowStart": "0"
},
"message": ""
}
Event ID 1430 — TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo CwrMax = CwrMax.
Description
TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo CwrMax = CwrMax.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
DupAckCount UInt32 | — |
SeqNo UInt32 | — |
CwrMax UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1430",
"version": "0",
"level": "4",
"task": "1421",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-15T23:27:12.440654900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"Cwnd": " 22020",
"SSThresh": " 16760",
"DupAckCount": " 1",
"SeqNo": "4068749001",
"CwrMax": "4068749000"
},
"message": ""
}
Event ID 1431 — IP: Compartment cleanup.
Description
IP: Compartment cleanup. Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Private UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1432 — IP: Interface network category state change.
Description
IP: Interface network category state change. Interface = IfIndex, Compartment = CompartmentId , Protocol = AddressFamily, NetworkCategory = NetworkCategory, DomainNetworkLocation = DomainNetworkLocation, DomainType = DomainType, Signature = NetworkSignature.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
NetworkCategory UInt32 | — |
DomainNetworkLocation UInt32 | — |
DomainType UInt32 | — |
NetworkSignature GUID | — |
Event ID 1433 — IP: Interface creation.
Description
IP: Interface creation. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, PhysicalMediumType = PhysicalMediumType, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
PhysicalMediumType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1434 — IP: Interface deletion.
Description
IP: Interface deletion. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
PhysicalMediumType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1435 — IP: Interface cleanup.
Description
IP: Interface cleanup. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
PhysicalMediumType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1436 — IP: SubInterface creation.
Description
IP: SubInterface creation. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1437 — IP: SubInterface deletion.
Description
IP: SubInterface deletion. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1438 — IP: SubInterface cleanup.
Description
IP: SubInterface cleanup. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.
Message #
Fields #
| Name | Description |
|---|---|
SubIfIndex UInt32 | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1439 — IP: Interface change Notification.
Event ID 1440 — IP: Interface internet connectivity status change.
Description
IP: Interface internet connectivity status change. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, OldConnectivityStatus = OldConnectivityStatus, NewConnectivityStatus = NewConnectivityStatus.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
OldConnectivityStatus UInt32 | — |
NewConnectivityStatus UInt32 | — |
Event ID 1441 — IP: Address change notification.
Description
IP: Address change notification. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, Protocol = Protocol, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
Protocol AnsiString | — Known values
|
Reason UInt32 | — |
State UInt32 | — |
NotificationType UInt32 | — |
DadState UInt32 | — |
Event ID 1442 — IP: Route change notification.
Description
IP: Route change notification. DestinationPrefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Interface = IfIndex, Compartment = CompartmentId, NotifyFlags = NotifyFlags.
Message #
Fields #
| Name | Description |
|---|---|
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
DestinationPrefixLength UInt32 | — |
CompartmentId UInt32 | — |
IfIndex UInt32 | — |
NotifyFlags UInt64 | — |
State UInt32 | — |
NotificationType UInt32 | — |
Event ID 1443 — IP: Neighbor change notification.
Description
IP: Neighbor change notification. IpAddress = IPAddress, DlAddress = DLAddress, Interface = IfIndex, Compartment = CompartmentId, State = NeighborState, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | — |
IPAddress Binary | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
NeighborState UInt32 | — |
Reason UInt32 | — |
NotificationState UInt32 | — |
NotificationType UInt32 | — |
Event ID 1444 — IP: Address DAD state change.
Description
IP: Address DAD state change. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, OldState = OldDadState, NewState = NewDadState, Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddressLength UInt32 | — |
SourceAddress Binary | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
OldDadState UInt32 | — |
NewDadState UInt32 | — |
Reason UInt32 | — |
Event ID 1445 — IP: Route Dead Gateway Detection state change.
Message #
Fields #
| Name | Description |
|---|---|
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
DestinationPrefixLength UInt32 | — |
CompartmentId UInt32 | — |
IfIndex UInt32 | — |
OldState UInt32 | — |
NewState UInt32 | — |
OldProbeCount UInt32 | — |
NewProbeCount UInt32 | — |
OldUnreachablePaths UInt32 | — |
NewUnreachablePaths UInt32 | — |
OldMovedPaths UInt32 | — |
NewMovedPaths UInt32 | — |
TotalPaths UInt32 | — |
OldStateChangeTick UInt32 | — |
NewStateChangeTick UInt32 | — |
DgdNeedsReset UInt32 | — |
Reason UInt32 | — |
Event ID 1446 — IP: Disconnecting TCP connections with Address = Address, Interface = IfIndex, Compartment = CompartmentId, SkipLocal = SkipLocal, SkipOnLink = SkipOnLink.
Description
IP: Disconnecting TCP connections with Address = Address, Interface = IfIndex, Compartment = CompartmentId, SkipLocal = SkipLocal, SkipOnLink = SkipOnLink.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
Address Binary | — |
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
SkipLocal UInt32 | — |
SkipOnLink UInt32 | — |
Event ID 1447 — TCP: connection Tcb: Sending paced chunk of QuantizedAllowance bytes with CWnd = Cwnd, SndWnd = SndWnd, BytesAvailable = BytesAvailable, BytesOutstanding = BytesOutstanding.
Description
TCP: connection Tcb: Sending paced chunk of QuantizedAllowance bytes with CWnd = Cwnd, SndWnd = SndWnd, BytesAvailable = BytesAvailable, BytesOutstanding = BytesOutstanding.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Cwnd UInt32 | — |
SndWnd UInt32 | — |
BytesAvailable UInt32 | — |
BytesOutstanding UInt32 | — |
QuantizedAllowance UInt32 | — |
Allowance UInt32 | — |
OriginalBytesToSend UInt32 | — |
Event ID 1448 — Fallback: Context = Fallback, Feature = Feature, TraceReason = Reason, Confidence = Confidence, Successes = Successes, Failures = Failures.
Event ID 1449 — TCPIP: TCB Tcb using fast loopback.
Event ID 1450 — IP: Router information change notification.
Event ID 1451 — IP: Event.
Description
IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, DNS Server/Suffix: DNSServerAddress DNSSuffix, Lifetime = Lifetime.
Message #
Fields #
| Name | Description |
|---|---|
Event UInt32 | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
RouterAddrLength UInt32 | — |
RouterAddress Binary | — |
DnsAddrLength UInt32 | — |
DNSServerAddress Binary | — |
DNSSuffix AnsiString | — |
Lifetime UInt32 | — |
Event ID 1452 — IP: Route rundown.
Description
IP: Route rundown. Interface = Interface, Compartment = Compartment, Prefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Metric = Metric, State = State, Origin = Origin, Age = Age, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Flags = Flags.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Compartment UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
DestinationPrefixLength UInt32 | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
Metric UInt32 | — |
State UInt32 | — |
Origin UInt32 | — |
Age UInt64 | — |
ValidLifetime UInt64 | — |
PreferredLifetime UInt64 | — |
Flags UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1452",
"version": "0",
"level": "4",
"task": "1443",
"opcode": "0",
"keywords": 9223372586610589856,
"time_created": "2026-03-16T00:21:34.295267700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Interface": " 6",
"Compartment": " 1",
"DestinationPrefixAddressLength": " 16",
"DestinationPrefix": "0.0.0.0",
"DestinationPrefixLength": " 0",
"NextHopAddressLength": " 16",
"NextHopAddress": "10.2.10.254",
"Metric": " 256",
"State": " 0",
"Origin": " 0",
"Age": "0x1A11",
"ValidLifetime": "0xFFFFFFFF",
"PreferredLifetime": "0xFFFFFFFF",
"Flags": "0x388"
},
"message": ""
}
Event ID 1453 — TCP: CUBIC ECN event.
Event ID 1454 — INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectAction, Status = Status.
Description
INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectAction, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Owner Pointer | — |
InspectHandle Pointer | — |
InspectType UInt32 | — |
InspectAction UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1454",
"version": "0",
"level": "4",
"task": "1445",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:34.388718700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4168",
"thread_id": "6880"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Owner": "0xFFFF980A1018B560",
"InspectHandle": "0xFFFF980A17030CE0",
"InspectType": " 0",
"InspectAction": " 1",
"Status": "0x0"
},
"message": ""
}
Event ID 1455 — INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectPort, Status = Status.
Description
INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectPort, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Owner Pointer | — |
InspectHandle Pointer | — |
InspectType UInt32 | — |
InspectPort UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1455",
"version": "0",
"level": "4",
"task": "1445",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:40.077855500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0b1c4090-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Owner": "0xFFFF980A0B1C4090",
"InspectHandle": "0xFFFF980A13FE6CC0",
"InspectType": " 17",
"InspectPort": " 0",
"Status": "0x0"
},
"message": ""
}
Event ID 1456 — FallbackCheck: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Description
FallbackCheck: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | — |
Feature UInt32 | — |
Failed UInt32 | — |
Succeeded UInt32 | — |
InProbe UInt32 | — |
PathsProbed UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1457 — FallbackUpdate: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Description
FallbackUpdate: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | — |
Feature UInt32 | — |
Failed UInt32 | — |
Succeeded UInt32 | — |
InProbe UInt32 | — |
PathsProbed UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1458 — Fallback: Permanently disabling feature, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Description
Fallback: Permanently disabling feature, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | — |
Feature UInt32 | — |
Failed UInt32 | — |
Succeeded UInt32 | — |
InProbe UInt32 | — |
PathsProbed UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1459 — Fallback: Enabling feature for this boot session, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Description
Fallback: Enabling feature for this boot session, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | — |
Feature UInt32 | — |
Failed UInt32 | — |
Succeeded UInt32 | — |
InProbe UInt32 | — |
PathsProbed UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1460 — Fallback: Feature previously disabled, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Description
Fallback: Feature previously disabled, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.
Message #
Fields #
| Name | Description |
|---|---|
Fallback Pointer | — |
Feature UInt32 | — |
Failed UInt32 | — |
Succeeded UInt32 | — |
InProbe UInt32 | — |
PathsProbed UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1461 — TCP Fastopen fallback update: Tcb = Tcb, FastopenState = FastopenState, DataBytesIn = DataBytesIn, ShutdownStatus = ShutdownStatus, ProbeStatus = ProbeStatus.
Event ID 1462 — Disabling feature until connectivity is established: CompartmentId =CompartmentId, IfIndex = IfIndex, Feature = Feature, ConnectivityStatus = ConnectivityStatus.
Event ID 1463 — Disabling Feature for loopback connection.
Event ID 1464 — Disabling TCP Fastopen for BaseEndpoint = BaseEndpoint because an incompatible WFP callout is installed.
Event ID 1465 — IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFl...
Description
IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFlags: ConstraintFlags.
Message #
Fields #
| Name | Description |
|---|---|
Compartment UInt32 | — |
DestinationAddrLength UInt32 | — |
DestinationAddress Binary | — |
ConstrainSourceAddrLength UInt32 | — |
ConstrainSourceAddress Binary | — |
ConstrainInterfaceIndex UInt32 | — |
ConstraintFlags UInt32 | — |
TransportProtocol UInt32 | — |
IcmpType UInt8 | — |
IcmpCode UInt8 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1465",
"version": "0",
"level": "5",
"task": "1450",
"opcode": "0",
"keywords": 9223372036854775840,
"time_created": "2026-03-16T00:21:38.719138100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Compartment": " 1",
"DestinationAddrLength": " 16",
"DestinationAddress": "10.2.10.11",
"ConstrainSourceAddrLength": " 16",
"ConstrainSourceAddress": "10.2.10.21",
"ConstrainInterfaceIndex": " 6",
"ConstraintFlags": "0x1"
},
"message": ""
}
Event ID 1466 — WFP-ALE: RemoteEndPoint Insertion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Description
WFP-ALE: RemoteEndPoint Insertion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddress Binary | — |
PartitionId UInt64 | — |
NumEntries UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1466",
"version": "0",
"level": "4",
"task": "1372",
"opcode": "0",
"keywords": 9223372036854808576,
"time_created": "2026-03-16T00:21:40.078425500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressLength": " 16",
"LocalAddress": "10.2.10.21:53893",
"RemoteAddress": "10.2.10.11:53",
"PartitionId": "4",
"NumEntries": "4"
},
"message": ""
}
Event ID 1467 — WFP-ALE: RemoteEndPoint Deletion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Description
WFP-ALE: RemoteEndPoint Deletion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddress Binary | — |
PartitionId UInt64 | — |
NumEntries UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1467",
"version": "0",
"level": "4",
"task": "1372",
"opcode": "0",
"keywords": 9223372036854808576,
"time_created": "2026-03-16T00:21:40.078776800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressLength": " 16",
"LocalAddress": "10.2.10.21",
"RemoteAddress": "8.8.8.8:1",
"PartitionId": "4",
"NumEntries": "3"
},
"message": ""
}
Event ID 1468 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort. PID = ProcessId.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Reason UInt32 | — |
Event ID 1469 — Disabling Feature due to no next hop.
Event ID 1470 — TCP: endpoint (sockaddr=LocalAddressLength) bind failed: wake status = LocalAddress.
Description
TCP: endpoint (sockaddr=LocalAddressLength) bind failed: wake status = LocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1471 — UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: wake status = Status.
Description
UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: wake status = Status.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
Endpoint Pointer | — |
Event ID 1472 — Acquire wake port Port, type=AcquireType, family=AddressFamily, IF=Interface, compartment=Compartment.
Event ID 1473 — TCP: Connection Tcb reached max SACK queue length.
Event ID 1474 — TCP: Connection Tcb requested fast open.
Event ID 1475 — TCP: CUBIC Hystart state change event.
Description
TCP: CUBIC Hystart state change event. Connection Tcb, State State, CWnd Cwnd, SSThresh = SSThresh.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
State UInt16 | — |
Cwnd UInt32 | — |
SSThresh UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1475",
"version": "0",
"level": "4",
"task": "1463",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.489856100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"State": "2",
"Cwnd": " 16734",
"SSThresh": "4294967295"
},
"message": ""
}
Event ID 1476 — IP: Transmitting loopback Nbl Nbl.
Description
IP: Transmitting loopback Nbl Nbl. Interface=Interface, Compartment=Compartment, Src=SourceAddress, Dst=DestinationAddress, Proto=IPTransportProtocol.
Message #
Fields #
| Name | Description |
|---|---|
Nbl Pointer | — |
Interface UInt32 | — |
Compartment UInt32 | — |
AddressLength UInt32 | — |
DestinationAddress Binary | — |
SourceAddress Binary | — |
IPTransportProtocol UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1476",
"version": "0",
"level": "17",
"task": "1464",
"opcode": "0",
"keywords": 9223372036858970112,
"time_created": "2026-03-16T00:23:11.240868900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "11564"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Nbl": "0xFFFF980A1A0CE070",
"Interface": " 6",
"Compartment": " 1",
"AddressLength": " 16",
"DestinationAddress": "224.0.0.251:5353",
"SourceAddress": "10.2.10.21:5353",
"IPTransportProtocol": " 17"
},
"message": ""
}
Event ID 1477 — TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
DataBytesOut UInt64 | — |
DataBytesIn UInt64 | — |
DataSegmentsOut UInt64 | — |
DataSegmentsIn UInt64 | — |
SegmentsOut UInt64 | — |
SegmentsIn UInt64 | — |
NonRecovDa UInt32 | — |
NonRecovDaEpisodes UInt32 | — |
DupAcksIn UInt32 | — |
BytesRetrans UInt32 | — |
Timeouts UInt32 | — |
SpuriousRtoDetections UInt32 | — |
FastRetran UInt32 | — |
MaxSsthresh UInt32 | — |
MaxSsCwnd UInt32 | — |
MaxCaCwnd UInt32 | — |
SndLimTransRwin UInt32 | — |
SndLimTimeRwin UInt32 | — |
SndLimBytesRwin UInt64 | — |
SndLimTransCwnd UInt32 | — |
SndLimTimeCwnd UInt32 | — |
SndLimBytesCwnd UInt64 | — |
SndLimTransSnd UInt32 | — |
SndLimTimeRSnd UInt32 | — |
SndLimBytesRSnd UInt64 | — |
ConnectionTimeMs UInt64 | — |
TimestampsEnabled UInt32 | — |
RttUs UInt32 | — |
MinRttUs UInt32 | — |
MaxRttUs UInt32 | — |
SynRetrans UInt32 | — |
CongestionAlgorithm UInt32 | — |
State UInt32 | — |
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
CWnd UInt32 | — |
SsThresh UInt32 | — |
RcvWnd UInt32 | — |
RcvBuf UInt32 | — |
SndWnd UInt32 | — |
InterfaceIndex UInt32 | — |
LocalPort UInt32 | — |
IsLoopback Boolean | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1477",
"version": "1",
"level": "16",
"task": "1341",
"opcode": "0",
"keywords": 9223407221226864640,
"time_created": "2026-03-16T00:21:38.733329900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4",
"thread_id": "7444"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0EEE7560",
"DataBytesOut": "426",
"DataBytesIn": "5091",
"DataSegmentsOut": "2",
"DataSegmentsIn": "5",
"SegmentsOut": "6",
"SegmentsIn": "8",
"NonRecovDa": " 0",
"NonRecovDaEpisodes": " 0",
"DupAcksIn": " 0",
"BytesRetrans": " 0",
"Timeouts": " 0",
"SpuriousRtoDetections": " 0",
"FastRetran": " 0",
"MaxSsthresh": "4294967295",
"MaxSsCwnd": " 15027",
"MaxCaCwnd": " 0",
"SndLimTransRwin": " 0",
"SndLimTimeRwin": " 0",
"SndLimBytesRwin": "0",
"SndLimTransCwnd": " 0",
"SndLimTimeCwnd": " 0",
"SndLimBytesCwnd": "0",
"SndLimTransSnd": " 1",
"SndLimTimeRSnd": " 0",
"SndLimBytesRSnd": "430",
"ConnectionTimeMs": "14",
"TimestampsEnabled": " 0",
"RttUs": " 1146",
"MinRttUs": " 982",
"MaxRttUs": " 1717",
"SynRetrans": " 0",
"CongestionAlgorithm": " 5",
"State": " 0",
"LocalAddressLength": " 28",
"LocalAddress": "[::ffff:10.2.10.21]:5985",
"RemoteAddressLength": " 28",
"RemoteAddress": "[::ffff:10.2.10.11]:51201",
"CWnd": " 15027",
"SsThresh": "4294967295",
"RcvWnd": " 2098020",
"RcvBuf": " 2098020",
"SndWnd": " 262144",
"InterfaceIndex": " 6",
"LocalPort": " 24855",
"IsLoopback": "false"
},
"message": ""
}
Event ID 1478 — TCPIP: Framing layer PathDirection (AddressFamily=AddressFamily) dropped PacketCount packet(s) on interface=Interface, Reason=Reason, Data=Data.
Event ID 1479 — TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr.
Description
TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
IPTransportProtocol UInt32 | — |
AddressFamily UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Reason UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1479",
"version": "0",
"level": "4",
"task": "1466",
"opcode": "0",
"keywords": 9223372586610589824,
"time_created": "2026-03-16T00:22:37.889812500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A0E584560",
"IPTransportProtocol": " 6",
"AddressFamily": " 2",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:52990",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "52.159.108.190:443",
"Reason": " 10"
},
"message": ""
}
Event ID 1480 — TCP connection failed with Status = Status, Local = LocalSockAddr, Remote = RemoteSockAddr, ProcessId = TcpState, TcpState = ProcessId at Hour:Minute:Second Reason = Reason.
Description
TCP connection failed with Status = Status, Local = LocalSockAddr, Remote = RemoteSockAddr, ProcessId = TcpState, TcpState = ProcessId at Hour:Minute:Second Reason = Reason.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
TcpState UInt32 | — |
ProcessId UInt32 | — |
Hour UInt16 | — |
Minute UInt16 | — |
Second UInt16 | — |
Reason UInt32 | — |
ProcessStartKey UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1480",
"version": "1",
"level": "16",
"task": "1467",
"opcode": "0",
"keywords": 9223407221226864640,
"time_created": "2026-03-16T00:21:34.294926800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Status": "0xC0000241",
"LocalSockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:50542",
"RemoteSockAddrLength": " 16",
"RemoteSockAddr": "20.42.65.85:443",
"TcpState": " 6",
"ProcessId": " 3688",
"Hour": "0",
"Minute": "17",
"Second": "1",
"Reason": " 14",
"ProcessStartKey": "2814749767106643"
},
"message": ""
}
Event ID 1481 — TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight B...
Description
TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight BytesInFlight BytesToSend BytesToSend PrrDelivered PrrDelivered PrrOut PrrOut.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SackIsLostSeq UInt32 | — |
SackInFlight UInt32 | — |
SackBytes UInt32 | — |
SackIsLost UInt32 | — |
SsThresh UInt32 | — |
HeadSeq UInt32 | — |
AckedData UInt32 | — |
BytesInFlight UInt32 | — |
BytesToSend Int64 | — |
PrrDelivered UInt32 | — |
PrrOut UInt32 | — |
Event ID 1482 — UDP: Endpoint Endpoint segment message.
Description
UDP: Endpoint Endpoint segment message. SegmentSize = SegmentSize (0 == No Segmentation) MessageLength = MessageLength HwDatagrams = HwDatagrams HwSegments = HwSegments SwSegments = SwSegments Status = SubMssSegments.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
SegmentSize UInt32 | — |
MessageLength UInt64 | — |
HwDatagrams UInt32 | — |
HwSegments UInt32 | — |
SwSegments UInt32 | — |
SubMssSegments UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1482",
"version": "1",
"level": "5",
"task": "1469",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.078220100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "228",
"thread_id": "8220"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A11735E80",
"SegmentSize": " 0",
"MessageLength": "63",
"HwDatagrams": " 0",
"HwSegments": " 0",
"SwSegments": " 0",
"SubMssSegments": " 0",
"Status": "0x0"
},
"message": ""
}
Event ID 1483 — UDP: Endpoint Endpoint segmentation offload unavailable.
Description
UDP: Endpoint Endpoint segmentation offload unavailable. Reason = FailureReason SegmentSize = SegmentSize LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
FailureReason UInt32 | — Known values
|
SegmentSize UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Event ID 1484 — TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider.
Description
TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider. Code = FailureCode. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
AddressFamily UInt32 | — |
FailureCode UInt32 | — NTSTATUS reference |
Status UInt32 | — NTSTATUS reference |
Event ID 1485 — TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed.
Description
TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed. OID = OID. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
AddressFamily UInt32 | — |
OID UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1486 — TCPIP received a status indication on interface IfIndex.
Event ID 1487 — IP: Failed to set socket option.
Description
IP: Failed to set socket option. Level = SocketOptionLevel. Option = SocketOptionValue. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SocketOptionLevel UInt32 | — |
SocketOptionValue UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1487",
"version": "0",
"level": "2",
"task": "1474",
"opcode": "0",
"keywords": 9223372036854775952,
"time_created": "2026-03-16T00:23:11.242873300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "228",
"thread_id": "2612"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketOptionLevel": " 41",
"SocketOptionValue": " 9",
"Status": "0xC0000225"
},
"message": ""
}
Event ID 1488 — IP: Failed to set socket IOCTL.
Description
IP: Failed to set socket IOCTL. IOCTL = SocketIoctl. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
SocketIoctl UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1489 — Failed to process multicast RequestType request.
Description
Failed to process multicast RequestType request. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress. Reason = FailureReason. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | — |
IPv4Address UInt32 | — |
IPv4SourceAddress UInt32 | — |
IpAddrLength UInt32 | — |
IpSourceAddrLength UInt32 | — |
IPv6Address Binary | — |
IPv6SourceAddress Binary | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
Event ID 1490 — Processed multicast RequestType request successfully.
Description
Processed multicast RequestType request successfully. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress.
Message #
Fields #
| Name | Description |
|---|---|
RequestType UInt32 | — |
IPv4Address UInt32 | — |
IPv4SourceAddress UInt32 | — |
IpAddrLength UInt32 | — |
IpSourceAddrLength UInt32 | — |
IPv6Address Binary | — |
IPv6SourceAddress Binary | — |
Event ID 1491 — MessageType.
Event ID 1492 — MessageType.
Description
MessageType. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
MessageType UInt32 | — |
IfIndex UInt32 | — |
IPv4Address UInt32 | — |
IpAddrLength UInt32 | — |
IPv6Address Binary | — |
Data UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1493 — Invalid ECN codepoints in reassembly.
Event ID 1494 — Reassembly failure: packets do not add up correctly.
Event ID 1495 — Reassembly failure: failed to restore IPSec packet history.
Description
Reassembly failure: failed to restore IPSec packet history. Interface = IfIndex. Address family = AddressFamily. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
AddressFamily UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1496 — Could not transfer FragmentContextDirection.
Event ID 1497 — Attempting to GroupChangeType the multicast group at FL.
Description
Attempting to GroupChangeType the multicast group at FL. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
GroupChangeType UInt32 | — |
IfIndex UInt32 | — |
IPv4Address UInt32 | — |
IpAddrLength UInt32 | — |
IPv6Address Binary | — |
Data UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1498 — Failed to update address list at FL.
Description
Failed to update address list at FL. Interface = IfIndex. Address Family = AddressFamily. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
AddressFamily UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1499 — Too many DAD failures, so will not create temporary address.
Event ID 1500 — Failed to address interface; deleting it.
Description
Failed to address interface; deleting it. Interface = IfIndex. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1501 — Failed to reach default gateway after reconnect; cleaning settings.
Event ID 1502 — Failed to sync interface with registry.
Description
Failed to sync interface with registry. Interface = IfIndex. Field = Field. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
Field UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1503 — Failed to Release an active reference on the interface.
Description
Failed to Release an active reference on the interface. Interface = IfIndex. Reference Reason = Subtask. Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Release UInt32 | — |
IfIndex UInt32 | — |
Subtask UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1504 — Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop.
Description
Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop. Interface = IfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
IPv4DestinationAddress UInt32 | — |
IPv4NextHop UInt32 | — |
IpAddrLength UInt32 | — |
IPv6DestinationAddress Binary | — |
IPv6NextHop Binary | — |
Event ID 1505 — Redirect path rate limit for IPv6 source address IPv6Address.
Event ID 1506 — Dropped AddressFamily fragment.
Event ID 1507 — Reassembly timeout.
Description
Reassembly timeout. Interface = IfIndex. Id = ReassemblyId. Source Address = IPv4SourceAddress IPv6SourceAddress. Destination Address = IPv4DestinationAddress IPv6DestinationAddress.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
ReassemblyId UInt32 | — |
IPv4SourceAddress UInt32 | — |
IPv4DestinationAddress UInt32 | — |
IpAddrLength UInt32 | — |
IPv6SourceAddress Binary | — |
IPv6DestinationAddress Binary | — |
Event ID 1508 — Invalid IP option.
Event ID 1509 — Invalid IP hop-by-hop option.
Event ID 1510 — Invalid IP hop-by-hop option.
Event ID 1511 — Invalid IP routing header option.
Event ID 1512 — Invalid IP routing header option.
Event ID 1513 — This option cannot be specified by the user
Event ID 1514 — TCP: interface IfIndex: received potential RSC status indication.
Description
TCP: interface IfIndex: received potential RSC status indication. Current IPv4 State = TcpRscEnabledIpv4, Offload IPv4 State = OffloadRscEnabledIpv4, Current IPv6 State = TcpRscEnabledIpv6, Offload IPv6 State = OffloadRscEnabledIpv6.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
TcpRscEnabledIpv4 UInt32 | — |
OffloadRscEnabledIpv4 UInt32 | — |
TcpRscEnabledIpv6 UInt32 | — |
OffloadRscEnabledIpv6 UInt32 | — |
Event ID 1515 — UDP: endpoint Endpoint: URO SCU received.
Event ID 1516 — TCP software RSC global disabled mask = TcpRscDisabledMask, UDP software URO global disabled mask = UdpUroDisabledMask.
Description
TCP software RSC global disabled mask = TcpRscDisabledMask, UDP software URO global disabled mask = UdpUroDisabledMask.
Message #
Fields #
| Name | Description |
|---|---|
TcpRscDisabledMask Int32 | — |
UdpUroDisabledMask Int32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1516",
"version": "0",
"level": "4",
"task": "1486",
"opcode": "0",
"keywords": 9223372586610589824,
"time_created": "2026-03-16T00:21:34.295804400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"TcpRscDisabledMask": "0",
"UdpUroDisabledMask": "48"
},
"message": ""
}
Event ID 1517 — UDP: Global parameters updated for Address Family AddressFamily: DisableUro = DisableUro.
Event ID 1518 — IP: IPSNPI client rundown.
Event ID 1519 — TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at St...
Description
TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at StartPort with status = Status.
Message #
Fields #
| Name | Description |
|---|---|
ProcessId UInt32 | — |
Status UInt32 | — NTSTATUS reference |
ReservationType UInt32 | — |
IPTransportProtocol UInt32 | — |
StartPort UInt16 | — |
NumberOfPorts UInt16 | — |
ProcessSequenceNumber UInt64 | — |
Event ID 1520 — Illegal tunnel.
Event ID 1521 — Framing: Interface change in progress.
Event ID 1522 — Framing: Isolation is not supported on this network adapter.
Event ID 1523 — Framing: Failed to set pattern.
Event ID 1524 — Framing: Interface management request.
Description
Framing: Interface management request. Interface: IfIndex. Address Family: AddressFamily. Request code: FlicCode. Status: NtStatus.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
AddressFamily UInt32 | — |
FlicCode UInt32 | — |
NtStatus UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1524",
"version": "0",
"level": "4",
"task": "1491",
"opcode": "0",
"keywords": 9223372586610589712,
"time_created": "2026-03-15T23:27:10.979455500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "7392",
"thread_id": "7388"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 4",
"AddressFamily": " 2",
"FlicCode": "0x7",
"NtStatus": "0x0"
},
"message": ""
}
Event ID 1525 — Framing: WOL capabilities update in progress.
Event ID 1526 — Framing: A PNP event has been indicated.
Event ID 1527 — Framing: interface rundown: Interface = IfIndex, Luid = IfLuid, Address family = AddressFamily, Compartment = Compartment, Isolation mode = IsolationMode, Isolation ID = IsolalationId, DL address =...
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
IfLuid UInt64 | — |
AddressFamily UInt32 | — |
Compartment UInt32 | — |
IsolationMode UInt32 | — |
IsolalationId UInt32 | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
InterfaceType UInt32 | — |
PhysicalMediumType UInt32 | — |
SwRscUroApplicable UInt32 | — |
SwRscEnabled UInt32 | — |
IfAlias UnicodeString | — |
SwUroEnabled UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1527",
"version": "0",
"level": "4",
"task": "1202",
"opcode": "0",
"keywords": 9223372586610589712,
"time_created": "2026-03-16T00:21:34.295249100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 6",
"IfLuid": "0x6008001000000",
"AddressFamily": " 2",
"Compartment": " 1",
"IsolationMode": " 0",
"IsolalationId": " 0",
"DlAddrLength": " 6",
"DLAddress": "0xBC24119A4DC2",
"InterfaceType": " 6",
"PhysicalMediumType": " 0",
"SwRscUroApplicable": " 1",
"SwRscEnabled": " 0",
"IfAlias": "Ethernet"
},
"message": ""
}
Event ID 1528 — RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
IPTransportProtocol UInt32 | — |
NumMessages UInt32 | — |
NumBytes UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Event ID 1529 — RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
IPTransportProtocol UInt32 | — |
NumMessages UInt32 | — |
NumBytes UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddrLength UInt32 | — |
RemoteSockAddr Binary | — |
Event ID 1530 — RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = EndpointAddress, RemoteAddress = SendAddress) send failed with reason = Reason status = Status.
Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = EndpointAddress, RemoteAddress = SendAddress) send failed with reason = Reason status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
IPTransportProtocol UInt32 | — |
EndpointAddressLength UInt32 | — |
EndpointAddress Binary | — |
SendAddressLength UInt32 | — |
SendAddress Binary | — |
Reason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1531 — RAW: endpoint Endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) created.
Description
RAW: endpoint Endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) created.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
AddressFamily UInt32 | — |
IPTransportProtocol UInt32 | — |
Compartment UInt32 | — |
ProcessId UInt32 | — |
ProcessSequenceNumber UInt64 | — |
Reason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1532 — RAW: endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) create failed with reason Reason status Status.
Description
RAW: endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) create failed with reason Reason status Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
AddressFamily UInt32 | — |
IPTransportProtocol UInt32 | — |
Compartment UInt32 | — |
ProcessId UInt32 | — |
ProcessSequenceNumber UInt64 | — |
Reason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1533 — RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bound.
Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bound.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
IPTransportProtocol UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
Reason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1534 — RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bind failed with reason Reason status Status.
Description
RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bind failed with reason Reason status Status.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
IPTransportProtocol UInt32 | — |
LocalSockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
Reason UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1535 — RAW: endpoint Endpoint closed.
Event ID 1536 — TCPIP: Error processing router advertisement on interface index IfIndex - Preferred lifetime of PreferredLifetime should not be greater than the valid lifetime of ValidLifetime.
Event ID 1537 — TCPIP: Error processing router advertisement on interface index IfIndex - Prefix length of PrefixLength and identifier of IdentifierLength must add up to the size of an IPv6 ad...
Event ID 1538 — TCPIP: An ARP request was dropped on interface IfIndex.
Description
TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
DlAddrLength UInt32 | — |
DlSourceAddress Binary | — |
IpSourceAddress UInt32 | — |
IpTargetAddress UInt32 | — |
DropReason UInt32 | — |
Event ID 1539 — TCPIP: An ARP reply was dropped on interface IfIndex.
Description
TCPIP: An ARP reply was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, Directed to this interface = Directed, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
DlAddrLength UInt32 | — |
DlSourceAddress Binary | — |
IpSourceAddress UInt32 | — |
Directed UInt32 | — |
DropReason UInt32 | — |
Event ID 1540 — TCPIP: No handler found for an AddressFamily packet with upper layer protocol IPTransportProtocol.
Event ID 1541 — TCPIP: Handler for upper layer protocol IPTransportProtocol for an AddressFamily packet returned with error Status.
Description
TCPIP: Handler for upper layer protocol IPTransportProtocol for an AddressFamily packet returned with error Status.
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | — |
IPTransportProtocol UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1541",
"version": "0",
"level": "5",
"task": "1496",
"opcode": "0",
"keywords": 9223372045444710400,
"time_created": "2026-03-15T23:27:12.462571400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AddressFamily": " 2",
"IPTransportProtocol": " 6",
"Status": "0x40000026"
},
"message": ""
}
Event ID 1542 — IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = I...
Description
IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = IsUnreachable, Flags = Flags.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
CompartmentId UInt32 | — |
IpAddrLength UInt32 | — |
IPAddress Binary | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
Neighbor State | — |
LastReachableInMs UInt32 | — |
IsUnreachable UInt32 | — |
Flags UInt32 | — |
NeighborState UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1542",
"version": "0",
"level": "4",
"task": "1497",
"opcode": "0",
"keywords": 9223372586610589728,
"time_created": "2026-03-16T00:21:34.295470700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
},
"execution": {
"process_id": "9132",
"thread_id": "4236"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"IfIndex": " 1",
"CompartmentId": " 1",
"IpAddrLength": " 16",
"IPAddress": "224.0.0.22",
"DlAddrLength": " 0",
"DLAddress": "",
"Neighbor State": " 6",
"LastReachableInMs": "57839000",
"IsUnreachable": " 0",
"Flags": "0xAC"
},
"message": ""
}
Event ID 1543 — TCPIP: An ARP request was dropped on interface IfIndex.
Description
TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | — |
DlAddrLength UInt32 | — |
DlSourceAddress Binary | — |
IpSourceAddress UInt32 | — |
IpTargetAddress UInt32 | — |
DropReason UInt32 | — |
Event ID 1544 — Endpoint Endpoint socket option set with level Level, name Name, value Value.
Description
Endpoint Endpoint socket option set with level Level, name Name, value Value.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Level UInt32 | — |
Name UInt32 | — |
Length UInt32 | — |
Value Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1544",
"version": "0",
"level": "4",
"task": "1498",
"opcode": "0",
"keywords": 9223372036854775936,
"time_created": "2026-03-16T00:21:40.064415100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "7552"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Endpoint": "0xFFFF980A15F74B50",
"Level": " 41",
"Name": " 27",
"Length": " 4",
"Value": "0x00000000"
},
"message": ""
}
Event ID 1545 — TCP: connection = Tcb RACK timeout expired.
Event ID 1546 — TCP: connection = Tcb armed RACK timer.
Description
TCP: connection = Tcb armed RACK timer. SndUna = SndUna, SndMax = SndMax, SackedBytes = SackedBytes, LossDetected = LossDetected, InRecovery = InRecovery, DeltaTicks = DeltaTicks.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
SackedBytes UInt32 | — |
LossDetected UInt32 | — |
InRecovery UInt32 | — |
DeltaTicks UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1546",
"version": "0",
"level": "4",
"task": "1501",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.488186800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102",
"SackedBytes": " 1440",
"LossDetected": " 0",
"InRecovery": " 0",
"DeltaTicks": " 18"
},
"message": ""
}
Event ID 1547 — TCP: connection = Tcb received a SACK block.
Description
TCP: connection = Tcb received a SACK block. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Ack UInt32 | — |
SLE UInt32 | — |
SRE UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1547",
"version": "0",
"level": "5",
"task": "1502",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.488113200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"SndUna": "155002622",
"SndMax": "155007102",
"Ack": "155002622",
"SLE": "155004100",
"SRE": "155005540"
},
"message": ""
}
Event ID 1548 — TCP: connection = Tcb received a SACK.
Description
TCP: connection = received a SACK. SndUna = , SndMax = , Ack = , SackedBytes = , LossDetected = , InRecovery = , NumSackBlocks = , DSackCount = , NewSackInfo = , RecoveryMax = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Ack UInt32 | — |
SackedBytes UInt32 | — |
LossDetected UInt32 | — |
InRecovery UInt32 | — |
NumSackBlocks UInt32 | — |
DSackCount UInt32 | — |
NewSackInfo UInt32 | — |
RecoveryMax UInt32 | — |
NewSackedBytes UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1548",
"version": "0",
"level": "4",
"task": "1503",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:27:12.440654000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFD182260",
"SndUna": "4068749001",
"SndMax": "4068767248",
"Ack": "4068749001",
"SackedBytes": " 1460",
"LossDetected": " 1",
"InRecovery": " 0",
"NumSackBlocks": " 1",
"DSackCount": " 0",
"NewSackInfo": " 1",
"RecoveryMax": "4068565828"
},
"message": ""
}
Event ID 1549 — TCP: connection = Tcb enabled send tracker.
Description
TCP: connection = Tcb enabled send tracker.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1549",
"version": "0",
"level": "4",
"task": "1504",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.119290700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "3688",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0"
},
"message": ""
}
Event ID 1550 — TCP: connection = Tcb send tracker acked a transmit.
Description
TCP: connection = Tcb send tracker acked a transmit. AckNo = AckNo, Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
AckNo UInt32 | — |
Start UInt32 | — |
End UInt32 | — |
Timestamps UInt32 | — |
EverRetransmitted UInt32 | — |
SackedBytes UInt32 | — |
BytesInFlight UInt32 | — |
State UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1550",
"version": "0",
"level": "5",
"task": "1505",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.268229900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7084"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"AckNo": "644687492",
"Start": "644684595",
"End": "644687492",
"Timestamps": "2483305555",
"EverRetransmitted": " 0",
"SackedBytes": " 0",
"BytesInFlight": " 0"
},
"message": ""
}
Event ID 1551 — TCP: connection = Tcb send tracker enqueued a transmit.
Description
TCP: connection = Tcb send tracker enqueued a transmit. Start = Start, End = End, Timestamp = Timestamps, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Start UInt32 | — |
End UInt32 | — |
Timestamps UInt32 | — |
SackedBytes UInt32 | — |
BytesInFlight UInt32 | — |
NoNewTransmitCreated UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1551",
"version": "0",
"level": "5",
"task": "1506",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-15T23:26:13.267679100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
},
"execution": {
"process_id": "4200",
"thread_id": "7948"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFFD78FFF7AF7E0",
"Start": "644684595",
"End": "644687492",
"Timestamps": "2483305555",
"SackedBytes": " 0",
"BytesInFlight": " 2897"
},
"message": ""
}
Event ID 1552 — TCP: connection = Tcb send tracker marked a transmit as lost.
Description
TCP: connection = Tcb send tracker marked a transmit as lost. Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Start UInt32 | — |
End UInt32 | — |
Timestamps UInt32 | — |
EverRetransmitted UInt32 | — |
InFlightCount UInt32 | — |
SackedBytes UInt32 | — |
BytesInFlight UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1552",
"version": "0",
"level": "5",
"task": "1507",
"opcode": "0",
"keywords": 9223372041149743104,
"time_created": "2026-03-16T00:21:40.490313500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{15ce6eb8-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Tcb": "0xFFFF980A15CE6AE0",
"Start": "155004062",
"End": "155004100",
"Timestamps": "1924745937",
"EverRetransmitted": " 0",
"InFlightCount": " 0",
"SackedBytes": " 3002",
"BytesInFlight": " 2804"
},
"message": ""
}
Event ID 1553 — TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAdd...
Description
TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAddrLength, remote address = LocalSockAddr, redirected address = RemoteSockAddr.
Message #
Fields #
| Name | Description |
|---|---|
OriginalListener Pointer | — |
RedirectedListener Pointer | — |
Succeeded UInt32 | — |
Redirected UInt32 | — |
CodePath UInt32 | — |
SockAddrLength UInt32 | — |
LocalSockAddr Binary | — |
RemoteSockAddr Binary | — |
RedirectSockAddr Binary | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-TCPIP",
"guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
"event_source_name": "",
"event_id": "1553",
"version": "0",
"level": "5",
"task": "1508",
"opcode": "0",
"keywords": 9223372045444710528,
"time_created": "2026-03-16T00:21:38.718862500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
},
"execution": {
"process_id": "0",
"thread_id": "0"
},
"channel": "Microsoft-Windows-TCPIP/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"OriginalListener": "0xFFFF980A0EF4B580",
"RedirectedListener": "0x0",
"Succeeded": " 1",
"Redirected": " 0",
"CodePath": " 2",
"SockAddrLength": " 16",
"LocalSockAddr": "10.2.10.21:5985",
"RemoteSockAddr": "10.2.10.11:51201",
"RedirectSockAddr": "0x00000000000000000000000000000000"
},
"message": ""
}
Event ID 1554 — TCP: connection = Tcb dropped a SACK block due to SACK limit reached.
Description
TCP: connection = Tcb dropped a SACK block due to SACK limit reached. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE, NumSackedTransmits = NumSackTransmits, limit = Limit.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
Ack UInt32 | — |
SLE UInt32 | — |
SRE UInt32 | — |
NumSackTransmits UInt32 | — |
Limit UInt32 | — |
Event ID 1555 — TCP: connection Tcb terminated by NSI.
Event ID 1556 — TCP: connection = Tcb rate-based pacing timeout expired.
Event ID 1557 — TCP RLedbat connection = Tcb.
Description
TCP RLedbat connection = . Type = , SSThresh = , Wnd = , WndWs = , DrainedBytes = , ReceiveHigh = , TsHigh = , LastRollOverTimeMs = , EndReductionTimeMs = , MinDelaySampleMs = , MinBaseDelayMs =.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
EventType UInt32 | — |
SsThresh UInt32 | — |
Wnd UInt32 | — |
WndWs UInt32 | — |
DrainedBytes UInt32 | — |
ReceiveHigh UInt32 | — |
TsHigh UInt32 | — |
LastRollOverTimeMs UInt32 | — |
EndReductionTimeMs UInt32 | — |
MinDelaySampleMs UInt32 | — |
MinBaseDelayMs UInt32 | — |
Event ID 1558 — UDP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Description
UDP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | — |
CurrentLocalAddress Binary | — |
ModifiedLocalAddressLength UInt32 | — |
ModifiedLocalAddress Binary | — |
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
EndpointRestored Boolean | — |
Event ID 1559 — UDP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Description
UDP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | — |
CurrentLocalAddress Binary | — |
ModifiedLocalAddressLength UInt32 | — |
ModifiedLocalAddress Binary | — |
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
EndpointRestored Boolean | — |
Event ID 1560 — TCP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Description
TCP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | — |
CurrentLocalAddress Binary | — |
ModifiedLocalAddressLength UInt32 | — |
ModifiedLocalAddress Binary | — |
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
EndpointRestored Boolean | — |
Event ID 1561 — TCP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Description
TCP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.
Message #
Fields #
| Name | Description |
|---|---|
CurrentLocalAddressLength UInt32 | — |
CurrentLocalAddress Binary | — |
ModifiedLocalAddressLength UInt32 | — |
ModifiedLocalAddress Binary | — |
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
EndpointRestored Boolean | — |
Event ID 1562 — TCP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Description
TCP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1563 — UDP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Description
UDP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
Endpoint Pointer | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
ProcessStartKey UInt64 | — |
Event ID 1564 — TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId ProcessSeqNum=ProcessStartKey) connect failed: access denied.
Description
TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId ProcessSeqNum=ProcessStartKey) connect failed: access denied.
Message #
Fields #
| Name | Description |
|---|---|
LocalAddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddressLength UInt32 | — |
RemoteAddress Binary | — |
Status UInt32 | — NTSTATUS reference |
ProcessId UInt32 | — |
Compartment UInt32 | — |
Tcb Pointer | — |
ProcessStartKey UInt64 | — |
Event ID 1565 — TCP: Congestion state changed for connection = Tcb from OldState = OldState to NewState = NewState.
Event ID 1566 — TCP: connection = Tcb detected reordering.
Event ID 1577 — TCP: connection = Tcb updated reownd.
Description
TCP: connection = updated reownd. Multiplier = , Persist = , Reownd = , ReorderingSeen = , DSackSeenOnLatestAck = , InLossRecovery = , DupAckCountReached = , DSackRound = , DSackRoundValid = .
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Multiplier UInt32 | — |
Persist UInt32 | — |
Reownd UInt32 | — |
ReorderingSeen UInt32 | — |
DSackSeenOnLatestAck UInt32 | — |
InLossRecovery UInt32 | — |
DupAckCountReached UInt32 | — |
DSackRound UInt32 | — |
DSackRoundValid UInt32 | — |
Event ID 1578 — IP: Injecting NBL Nbl on send path.
Event ID 1579 — IP: Injecting NBL Nbl on raw send path.
Event ID 1580 — IP: Injecting NBL Nbl on receive path.
Event ID 1581 — IP: Injecting NBL Nbl on forward path.
Event ID 1582 — IP: Indication filtered because destination interface IfIndex is not contained in IF list.
Event ID 1583 — BBR2: TCB Tcb bbr_bw bbr_bw min_rtt_us min_rtt_us mode mode cycle_idx cycle_idx CWnd CWnd PacingRate PacingRate BytesSent BytesSent SRtt SRtt.
Description
BBR2: TCB Tcb bbr_bw bbr_bw min_rtt_us min_rtt_us mode mode cycle_idx cycle_idx CWnd CWnd PacingRate PacingRate BytesSent BytesSent SRtt SRtt.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
bbr_bw UInt32 | — |
min_rtt_us UInt32 | — |
mode UInt32 | — |
cycle_idx UInt32 | — |
CWnd UInt32 | — |
PacingRate UInt32 | — |
BytesSent UInt32 | — |
SRtt UInt32 | — |
Event ID 1584 — TCP: connection = Tcb send tracker marked a transmit as rexmit.
Description
TCP: connection = Tcb send tracker marked a transmit as rexmit. Start = Start, End = End, Timestamp = Timestamps, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Start UInt32 | — |
End UInt32 | — |
Timestamps UInt32 | — |
InFlightCount UInt32 | — |
SackedBytes UInt32 | — |
BytesInFlight UInt32 | — |
Event ID 1585 — TCP: connection = Tcb send tracker update RACK info.
Description
TCP: connection = Tcb send tracker update RACK info. RackXmitTimeStampValid = RackXmitTimeStampValid, RackXmitTimeStampInUs = RackXmitTimeStampInUs, RackEndSeq = RackEndSeq, RackRttInUs = RackRttInUs, NowInUs = NowInUs, TimeStampInUs = TimeStampInUs.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
RackXmitTimeStampValid UInt32 | — |
RackXmitTimeStampInUs UInt32 | — |
RackEndSeq UInt32 | — |
RackRttInUs UInt32 | — |
NowInUs UInt32 | — |
TimeStampInUs UInt32 | — |
Event ID 1586 — IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily.
Description
IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily. Updating shared prefixes and resetting autoconfigured state, such as addresses and routes.
Message #
Fields #
| Name | Description |
|---|---|
AddressFamily UInt32 | — |
CompartmentId UInt32 | — |
Interface UInt32 | — |
PrefixSharing UInt32 | — |
Event ID 1587 — TCP: connection Tcb received a careful ACK.
Description
TCP: connection Tcb received a careful ACK. ThAck = ThAck, SndUna = SndUna, SndMax = SndMax, RecoveryMax = RecoveryMax, SndWnd = SndWnd, SndWndChanged = SndWndChanged, SackUpdated = SackUpdated, State = TcpState, CongestionState = CongestionState, F-RTO = Frto.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
ThAck UInt32 | — |
SndUna UInt32 | — |
SndMax UInt32 | — |
RecoveryMax UInt32 | — |
SndWnd UInt32 | — |
SndWndChanged UInt32 | — |
SackUpdated UInt32 | — |
TcpState UInt32 | — |
CongestionState UInt32 | — |
Frto UInt32 | — |
Event ID 1588 — IP: Forwarding tag on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily changed from OldForwardingTag to NewForwardingTag.
Event ID 1589 — TCP: AF AddressFamily, RssEnabled = RssEnabled .
Event ID 1590 — TCP: connection = Tcb send completion failed.
Description
TCP: connection = Tcb send completion failed. NBL = Nbl, Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
Nbl Pointer | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1591 — TCPIP: Alloc hooks setup: Status = Status.
Description
TCPIP: Alloc hooks setup: Status = Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1592 — IP: Neighbor with IpAddress = IPAddress DlAddress = DLAddress on Interface = Interface was reset while in state OldNeighborState due to Reason = ResetReason.
Description
IP: Neighbor with IpAddress = IPAddress DlAddress = DLAddress on Interface = Interface was reset while in state OldNeighborState due to Reason = ResetReason.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
IpAddrLength UInt32 | — |
IPAddress Binary | — |
DlAddrLength UInt32 | — |
DLAddress Binary | — |
OldNeighborState UInt32 | — |
ResetReason UInt32 | — |
CompartmentId UInt32 | — |
Event ID 1593 — TCP: Global timer fired, Processor = Processor, Tick = Tick.
Event ID 1594 — TCP: Global timer armed, NextToExpire = NextToExpire, Period = Period.
Event ID 1595 — TCP: Global timer cancelled
Description
TCP: Global timer cancelled.
Message #
Event ID 1596 — TCP: Updating Fastopen Key
Description
TCP: Updating Fastopen Key.
Message #
Event ID 1597 — TCP: paused receive buffer growth for high memory usage, AF = AddressFamily, TCB = Tcb, TotalBytesBuffered = TotalBytesBuffered, UpperLimit = UpperLimit.
Event ID 1598 — IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = IPv4Address IPProtocol IPv6Address, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
Description
IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = IPv4Address IPProtocol IPv6Address, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
CompartmentId UInt32 | — |
Protocol AnsiString | — Known values
|
IpAddrLength UInt32 | — |
IPv4Address UInt32 | — |
IPv6Address Binary | — |
IPProtocol UInt32 | — |
Event ID 1599 — IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddres...
Description
IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddress IPProtocol NextHopAddress, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
CompartmentId UInt32 | — |
Protocol AnsiString | — Known values
|
DestinationPrefixAddressLength UInt32 | — |
NextHopAddressLength UInt32 | — |
DestinationPrefixLength UInt32 | — |
DestinationPrefix Binary | — |
NextHopAddress Binary | — |
IPv4DestinationPrefix UInt32 | — |
IPv4NextHopAddress UInt32 | — |
IPProtocol UInt32 | — |
Event ID 1600 — IP: Policy based routing failed - Compartment: Compartment DstAddr: DestinationAddress SrcAddr: SourceAddress TransProto: TransportProtocol IcmpType: IcmpType IcmpCode: IcmpCode PolicySrcAddr: Poli...
Description
IP: Policy based routing failed - Compartment: DstAddr: SrcAddr: TransProto: IcmpType: IcmpCode: PolicySrcAddr: PolicyNextHopAddr: PolicyIfIndex: FailureReason: Status.
Message #
Fields #
| Name | Description |
|---|---|
Compartment UInt32 | — |
DestinationAddrLength UInt32 | — |
DestinationAddress Binary | — |
SourceAddrLength UInt32 | — |
SourceAddress Binary | — |
TransportProtocol UInt32 | — |
IcmpType UInt8 | — |
IcmpCode UInt8 | — |
PolicySourceAddrLength UInt32 | — |
PolicySourceAddress Binary | — |
PolicyNextHopAddrLength UInt32 | — |
PolicyNextHopAddress Binary | — |
PolicyInterfaceLuid UInt64 | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
Event ID 1601 — TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestam...
Description
TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestampDelta EcnCePresent = EcnCePresent.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NewState UInt32 | — |
FastPath UInt32 | — |
NBL Pointer | — |
ThSeq UInt32 | — |
ThAck UInt32 | — |
ThFlags UInt8 | — |
RSC UInt32 | — |
CoalescedSegCount UInt16 | — |
RscTcpTimestampDelta UInt32 | — |
EcnCePresent UInt32 | — |
Event ID 1602 — TCP: connection Tcb process fast RX batch SegmentCount = SegmentCount NumBytes = NumBytes NblHead = NblHead NblTail = NblTail Inspect = Inspect.
Event ID 1603 — TCP: connection Tcb in State Injected disconnect DataLength=DataLength.
Event ID 1604 — NDKPI Disconnect Event CallbackEx: DisconnectEventContext DisconnectEventContext ProviderDisconnectReason ProviderDisconnectReason.
Event ID 1605 — NDKPI AcceptEx: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Description
NDKPI AcceptEx: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.
Message #
Fields #
| Name | Description |
|---|---|
NdkConnector Pointer | — |
NdkQp Pointer | — |
IRD UInt32 | — |
ORD UInt32 | — |
DisconnectEventContext Pointer | — |
RequestContext Pointer | — |
PrivateDataLength UInt32 | — |
Event ID 1606 — NDKPI CompleteConnectEx: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.
Event ID 1607 — NDKPI Open Adapter Version Override: IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.
Description
NDKPI Open Adapter Version Override: IF_INDEX ProviderSupportedNDKVersion {.} FlConfiguredNdkpiVersion {.} ActualSupportedVersion {.}.
Message #
Fields #
| Name | Description |
|---|---|
ProviderSupportedNDKVersionMajor UInt16 | — |
ProviderSupportedNDKVersionMinor UInt16 | — |
FlConfiguredNdkpiVersionMajor UInt16 | — |
FlConfiguredNdkpiVersionMinor UInt16 | — |
ActualSupportedNDKVersionMajor UInt16 | — |
ActualSupportedNDKVersionMinor UInt16 | — |
IF_INDEX UInt32 | — |
Event ID 1608 — Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.
Description
Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.OldFlVersionMinor} NewFlConfiguredVersion {NewFlVersionMajor.NewFlVersionMinor}.
Message #
Fields #
| Name | Description |
|---|---|
OldFlVersionMajor UInt16 | — |
OldFlVersionMinor UInt16 | — |
NewFlVersionMajor UInt16 | — |
NewFlVersionMinor UInt16 | — |
OverrideStatus UnicodeString | — |
Event ID 1609 — NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.
Description
NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.ProviderSupportedNDKVersionMinor} ConsumerSpecifiedVersion {ConsumerSpecifiedNdkpiVersionMajor.ConsumerSpecifiedNdkpiVersionMinor}.
Message #
Fields #
| Name | Description |
|---|---|
ProviderSupportedNDKVersionMajor UInt16 | — |
ProviderSupportedNDKVersionMinor UInt16 | — |
ConsumerSpecifiedNdkpiVersionMajor UInt16 | — |
ConsumerSpecifiedNdkpiVersionMinor UInt16 | — |
IF_INDEX UInt32 | — |
Event ID 1610 — TCPIP: Disconnected Standby traffic.
Event ID 1611 — TCPIP: Disconnected Standby (DS) transition detected.
Event ID 1612 — ResetResolve API call: ProcessName API.
Event ID 1613 — USO global disabled mask = UdpUsoDisabledMask.
Event ID 1614 — Framing: SW URO SwUroEnabled, HW URO HwUroEnabled.
Event ID 1615 — Tcpip Power Policy set to: PowerPolicy.
Event ID 1616 — Router Solicitation sent.
Event ID 1617 — Router Solicitation requested on dormant interface.
Event ID 1618 — IP: Route lifetime refresh.
Message #
Fields #
| Name | Description |
|---|---|
Interface UInt32 | — |
Protocol AnsiString | — Known values
|
Compartment UInt32 | — |
DestinationPrefixAddressLength UInt32 | — |
DestinationPrefix Binary | — |
DestinationPrefixLength UInt32 | — |
NextHopAddressLength UInt32 | — |
NextHopAddress Binary | — |
Metric UInt32 | — |
Origin UInt32 | — |
CurrentTime UInt32 | — |
OldBasetime UInt32 | — |
OldValidTime UInt32 | — |
OldPreferredTime UInt32 | — |
NewBasetime UInt32 | — |
NewValidTime UInt32 | — |
NewPreferredTime UInt32 | — |
Event ID 1619 — IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason...
Description
IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).
Message #
Fields #
| Name | Description |
|---|---|
IpAddrLength UInt32 | — |
PreferredSourceIPAddress Binary | — |
NonPreferredSourceIPAddress Binary | — |
DestinationIPAddress Binary | — |
CompartmentId UInt32 | — |
Rule UInt32 | — |
RuleExtension UInt32 | — |
RuleName UInt32 | — |
Event ID 1620 — WFP-ALE: RemoteEndPoint Cleanup: (local=LocalAddress remote=RemoteAddress) currentTick=CurrentTick lastTick=LastTick lifeTime=LifeTime LifetimeFactor=LifetimeFactor.
Description
WFP-ALE: RemoteEndPoint Cleanup: (local=LocalAddress remote=RemoteAddress) currentTick=CurrentTick lastTick=LastTick lifeTime=LifeTime LifetimeFactor=LifetimeFactor.
Message #
Fields #
| Name | Description |
|---|---|
AddressLength UInt32 | — |
LocalAddress Binary | — |
RemoteAddress Binary | — |
CurrentTick UInt64 | — |
LastTick UInt64 | — |
LifeTime UInt32 | — |
LifetimeFactor UInt16 | — |
Event ID 1621 — FL: Virtual interface creation.
Description
FL: Virtual interface creation. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
AddressFamily UInt32 | — |
CompartmentGuid GUID | — |
CompartmentId UInt32 | — |
IsolationMode UInt32 | — |
IsolalationId UInt32 | — |
Origin UInt32 | — |
VirtualIfLuid UInt64 | — |
VirtualIfIndex UInt32 | — |
Event ID 1622 — FL: Virtual interface deletion.
Description
FL: Virtual interface deletion. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
AddressFamily UInt32 | — |
CompartmentGuid GUID | — |
CompartmentId UInt32 | — |
IsolationMode UInt32 | — |
IsolalationId UInt32 | — |
Origin UInt32 | — |
VirtualIfLuid UInt64 | — |
VirtualIfIndex UInt32 | — |
Event ID 1623 — Tcpip Power Policy Standby-to-Full-Power transition detected.
Event ID 1624 — TCP: connection Tcb: flow label refreshed, old = OldFlowLabel new = NewFlowLabel.
Event ID 1625 — TCP: Connection Tcb send idle triggered.
Event ID 1626 — TCP: connection Tcb: bytes limited by sender = SenderLimitedBytes receiver = ReceiverLimitedBytes congestion = CongestionLimitedBytes.
Event ID 1627 — UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid.
Description
UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid. CurrentState:CurrentUroState. Last scheduled state: LastScheduledState.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
ChangeReason UInt32 | — |
NewUroState UInt32 | — |
CurrentUroState UInt32 | — |
LastScheduledState UInt32 | — |
FailureReasonFlags UInt32 | — |
Event ID 1628 — UDP: ChangeReason NewUroState HW URO on interface IfLuid.
Description
UDP: ChangeReason NewUroState HW URO on interface IfLuid. Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
IfLuid UInt64 | — |
ChangeReason UInt32 | — |
NewUroState UInt32 | — |
Status UInt32 | — NTSTATUS reference |
FailureReasonFlags UInt32 | — |
Event ID 1629 — FL: FLSNPI client attach.
Description
FL: FLSNPI client attach. Client: ClientName, AddressFamily: AddressFamily, NpiVersion: ClientNpiVersion, NblContextSize: NblContextSize, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | — |
AddressFamily UInt32 | — |
ClientNpiVersion UInt32 | — |
NblContextSize UInt32 | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
Event ID 1630 — FL: FLSNPI client detach.
Event ID 1631 — FL: FLSNPI client interface attach.
Description
FL: FLSNPI client interface attach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | — |
AddressFamily UInt32 | — |
CompartmentId UInt32 | — |
IfIndex UInt32 | — |
VirtualIfId UInt32 | — |
Flags UInt32 | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
Event ID 1632 — FL: FLSNPI client interface detach.
Description
FL: FLSNPI client interface detach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | — |
AddressFamily UInt32 | — |
CompartmentId UInt32 | — |
IfIndex UInt32 | — |
VirtualIfId UInt32 | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
Flags UInt32 | — |
Event ID 1633 — FL: FLSNPI datapath failure.
Description
FL: FLSNPI datapath failure. Operation: Operation, AddressFamily: AddressFamily, Direction: PathDirection, Client:ClientName, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, InjectIfIndex: InjectionIfIndex, FailureReason: FailureReason, Status: Status.
Message #
Fields #
| Name | Description |
|---|---|
Operation UInt32 | — Known values
|
AddressFamily UInt32 | — |
PathDirection UInt32 | — |
ClientName UnicodeString | — |
CompartmentId UInt32 | — |
IfIndex UInt32 | — |
VirtualIfId UInt32 | — |
Flags UInt32 | — |
FailureReason UInt32 | — Known values
|
Status UInt32 | — NTSTATUS reference |
InjectionIfIndex UInt32 | — |
Event ID 1634 — FL: FLSNPI client silent drop.
Description
FL: FLSNPI client silent drop. Direction: PathDirection, AddressFamily:AddressFamily, Client: ClientName, CompartmentId: CompartmentId, IfIndex: InterfaceIndex, VirtualIfId: VirtualIfId, PacketCount: PacketCount.
Message #
Fields #
| Name | Description |
|---|---|
PathDirection UInt32 | — |
AddressFamily UInt32 | — |
ClientName UnicodeString | — |
CompartmentId UInt32 | — |
InterfaceIndex UInt32 | — |
VirtualIfId UInt32 | — |
PacketCount UInt32 | — |
Event ID 1635 — FL: FLSNPI indication stats.
Message #
Fields #
| Name | Description |
|---|---|
Direction UInt32 | — Known values
|
AddressFamily UInt32 | — |
CompartmentId UInt32 | — |
InterfaceIndex UInt32 | — |
VirtualIfId UInt32 | — |
PacketsIndicated UInt32 | — |
PacketsReturned UInt32 | — |
PacketsInjected UInt32 | — |
PacketsCloned UInt32 | — |
PacketsClonedWithNBSplit UInt32 | — |
PacketsDropped UInt32 | — |
PacketsSilentlyDropped UInt32 | — |
Event ID 1636 — TCPIP: Current Power Policy : PowerPolicy.
Event ID 1637 — TCP: connection Tcb send acked NumBytes bytes starting from SndNxt ActivityID = ActivityID.
Description
TCP: connection Tcb send acked NumBytes bytes starting from SndNxt ActivityID = ActivityID.
Message #
Fields #
| Name | Description |
|---|---|
Tcb Pointer | — |
NumBytes UInt32 | — |
SndNxt UInt32 | — |
ActivityID Pointer | — |
SndLimBytesSnd UInt64 | — |
SndLimBytesRwin UInt64 | — |
SndLimBytesCwnd UInt64 | — |
CWnd UInt32 | — |
SRtt UInt32 | — |
LossRecoveryEpisodes UInt32 | — |
RtoEpisodes UInt32 | — |
PtoEpisodes UInt32 | — |
Event ID 1638 — IP: Event.
Description
IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, Prefix = Prefix/PrefixLength, Lifetime = Lifetime.
Message #
Fields #
| Name | Description |
|---|---|
Event UInt32 | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
RouterAddrLength UInt32 | — |
RouterAddress Binary | — |
PrefixAddrLength UInt32 | — |
Prefix Binary | — |
PrefixLength UInt32 | — |
Lifetime UInt32 | — |
Event ID 1638 —
Description
IP: . Interface = , Compartment = , RouterAddress = , Prefix = /, Lifetime = .
Fields #
| Name | Description |
|---|---|
Event UInt32 | — |
Interface UInt32 | — |
CompartmentId UInt32 | — |
RouterAddrLength UInt32 | — |
RouterAddress Binary | — |
PrefixAddrLength UInt32 | — |
Prefix Binary | — |
PrefixLength UInt32 | — |
Lifetime UInt32 | — |
Event ID 1639 — IP: Destination cache invalidated.
Event ID 1639 —
Description
IP: Destination cache invalidated. Compartment = , Family = , RoutingEpoch = .
Fields #
| Name | Description |
|---|---|
CompartmentId UInt32 | — |
AddressFamily UInt32 | — |
RoutingEpoch Int32 | — |
Event ID 1640 — FL: Virtual interface set failed.
Description
FL: Virtual interface set failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.
Message #
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | — |
AddressFamily UInt32 | — |
IfLuid UInt64 | — |
CompartmentGuid GUID | — |
VirtualIfId UInt32 | — |
IsolationMode UInt32 | — |
Status UInt32 | — NTSTATUS reference |
FailureReason UInt32 | — Known values
|
Event ID 1640 —
Description
FL: Virtual interface set failed. NsiAction = , Family , IfLuid = , CompartmentGuid = , VirtualIfId = , IsolationMode = , Status = , Reason =.
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | — |
AddressFamily UInt32 | — |
IfLuid UInt64 | — |
CompartmentGuid GUID | — |
VirtualIfId UInt32 | — |
IsolationMode UInt32 | — |
Status UInt32 | — NTSTATUS reference |
FailureReason UInt32 | — Known values
|
Event ID 1641 — FL: Virtual interface get failed.
Description
FL: Virtual interface get failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.
Message #
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | — |
AddressFamily UInt32 | — |
IfLuid UInt64 | — |
CompartmentGuid GUID | — |
VirtualIfId UInt32 | — |
IsolationMode UInt32 | — |
Status UInt32 | — NTSTATUS reference |
FailureReason UInt32 | — Known values
|
Event ID 1641 —
Description
FL: Virtual interface get failed. NsiAction = , Family , IfLuid = , CompartmentGuid = , VirtualIfId = , IsolationMode = , Status = , Reason =.
Fields #
| Name | Description |
|---|---|
NsiAction UInt32 | — |
AddressFamily UInt32 | — |
IfLuid UInt64 | — |
CompartmentGuid GUID | — |
VirtualIfId UInt32 | — |
IsolationMode UInt32 | — |
Status UInt32 | — NTSTATUS reference |
FailureReason UInt32 | — Known values
|
Event ID 1642 — IP: Received Prefix Option in Router Advertisement.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
InterfaceGuid GUID | — |
CompartmentId UInt32 | — |
AddressLength UInt32 | — |
SourceIpAddress Binary | — |
PrefixValue Binary | — |
PrefixLength UInt32 | — |
ValidLifetime UInt32 | — |
PreferredLifetime UInt32 | — |
FlagsValue UInt8 | — |
IsRoute Boolean | — |
IsSitePrefix Boolean | — |
IsRouterAddress Boolean | — |
IsAutonomous Boolean | — |
IsOnLink Boolean | — |
Event ID 1642 —
Fields #
| Name | Description |
|---|---|
InterfaceIndex UInt32 | — |
InterfaceGuid GUID | — |
CompartmentId UInt32 | — |
AddressLength UInt32 | — |
SourceIpAddress Binary | — |
PrefixValue Binary | — |
PrefixLength UInt32 | — |
ValidLifetime UInt32 | — |
PreferredLifetime UInt32 | — |
FlagsValue UInt8 | — |
IsRoute Boolean | — |
IsSitePrefix Boolean | — |
IsRouterAddress Boolean | — |
IsAutonomous Boolean | — |
IsOnLink Boolean | — |