Microsoft-Windows-TerminalServices-ClientActiveXCore

75 events across 3 channels

Event IDTitleChannel
225StateTransitionName: Transitioned successfully from PreviousStateName to …Debug
226StateTransitionName: An error was encountered when transitioning from …Operational
227StateTransitionName: MCS Channel Join Confirmation received: ChannelID = …Debug
1000Debug
1001RDP ClientActiveX is trying to connect to the server (Value).Analytic
1002RDP ClientActiveX has connected to the serverAnalytic
1003RDP ClientActiveX has been disconnected (Reason= Value).Analytic
1004Client has logged on to the server (SessionId = Value).Analytic
1005Client failed to logon on to the server (Error = ErrorCode).Analytic
1006Client machine has lost network connectivity (Reason= ErrorCode).Analytic
1007DNS failed to resolve the server name (Error= ErrorCode).Operational
1008The credentials provided are authenticated by the serverAnalytic
1009The credentials provided were failed to be authenticated by the serverOperational
1010RDP ClientActiveX is connecting to a gateway server (Name=Value).Analytic
1011RDP ClientActiveX succeeded in connecting to the gateway serverAnalytic
1012RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).Analytic
1013RDP ClientActiveX is trying to automatically reconnect to the server (Value).Analytic
1014RDP ClientActiveX succeeded in automatically connecting to the serverAnalytic
1015RDP ClientActiveX failed to automatically connect to the server (Reason= …Operational
1016Client has a license to connect to the serverAnalytic
1017Client does not have a license to connect to the server (Error= ErrorCode).Operational
1018RDP ClientActiveX failed to connect to the server (Error = ErrorCode).Analytic
1019TraceMessage.Analytic
1020RDP ClientActiveX has recorded the following error - ErrorCode.Analytic
1021RDP ClientActiveX's gateway transport has recorded the following error - Value.Analytic
1022TraceMessage.Analytic
1023RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder …Analytic
1024RDP ClientActiveX is trying to connect to the server (Value).Operational
1025RDP ClientActiveX has connected to the serverOperational
1026RDP ClientActiveX has been disconnected (Reason= Value).Operational
1027Connected to domain (DomainName) with session SessionId.Operational
1028Server supports SSL = TraceMessage.Operational
1029Base64(SHA256(UserName)) is = TraceMessage.Operational
1030RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.Analytic
1031Invalid format error occured when decoding packet of type TraceMessage.Operational
1032Component name:ErrorCode, :: ErrorDescription.Debug
1033Component name:Name, :: CustomLevel, Error code:Value.Operational
1034Component name:ErrorCode, :: ErrorDescription.Operational
1100The client detected the link latency is Value milliseconds.Operational
1101The client detected the bandwidth is Value kbps/second.Operational
1102The client has initiated a multi-transport connection to the server Value.Operational
1103The client has established a multi-transport connection to the server.Operational
1104The client failed to establish the multi-transport connection.Operational
1105The multi-transport connection has been disconnected.Operational
1106Close event, code = Code.Operational
1107Disconnect trace:ComponentName "Message", Error code:ErrorCode.Operational
1201The RdClient has been forced exit since cancelling existing workspace job took …Operational
1202The user has clicked sign out on the OOB Client ribbon.Operational
1203The user has clicked Refresh on the OOB client ribbon.Operational
1204The user tried to login into ADAL with a different user name than the one he/she …Operational
1205Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = …Operational
1206Event: Workspace Event failed for Tenant = TenantId.Operational
1207RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.Analytic
1208Feed discovery succeeded.Operational
1209Feed discovery failed.Operational
1210Feed cache corruption encountered.Operational
1211Consent status updated successfully.Operational
1212Consent status update failed.Operational
1213The user has clicked view invitations on the OOB client ribbon.Operational
1214Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone …Operational
1215Refresh Time = refreshTime, Number of feeds = numberOfFeeds.Operational
1216ADAL error code = ErrorCode, description = ErrorDescription.Operational
1217ADAL token collected successfullyOperational
1218ADAL cancelledOperational
1227RadcClientType entering stage RadcClientStage.Operational
1228RadcClientStage with http event type RadcHttpEvent.Operational
1229RadcClientStage with http event type RadcHttpEvent and http status code Code.Operational
1230RadcClientStage with http event type RadcHttpEvent failed with xresult Code.Operational
1401The server is using version Version of the RDP graphics protocol (client mode: …Operational
1402The client is using hardware memory for the frame buffer.Operational
1403The client is using software memory for the frame buffer.Operational
1404The client encountered an issue while decoding and displaying RDP graphics …Operational
1501TraceMessage.Analytic
1502TraceMessage.Analytic
1503TraceMessage.Analytic

Event ID 225 — StateTransitionName: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Message #

%1: Transitioned successfully from %3 to %5 in response to %7.

Fields #

NameDescription
StateTransitionName UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString

Event ID 226 — StateTransitionName: An error was encountered when transitioning from PreviousStateName to NewStateName in response to EventName (error code Error Code).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Warning
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: An error was encountered when transitioning from PreviousStateName to NewStateName in response to EventName (error code Error Code).

Message #

%1: An error was encountered when transitioning from %3 to %5 in response to %7 (error code %8).

Fields #

NameDescription
StateTransitionName UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString
Error Code
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 226,
    "version": 0,
    "level": 3,
    "task": 104,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T18:26:54.989202+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "DB2461B3-3531-4655-AE9C-36EB94410000"
    },
    "execution": {
      "process_id": 12488,
      "thread_id": 13944
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "StateTransitionName": "RDPClient_SSL",
    "PreviousState": 2,
    "PreviousStateName": "TsSslStateHandshakeStart",
    "NewState": 10,
    "NewStateName": "TsSslStateDisconnecting",
    "Event": 7,
    "EventName": "TsSslEventStartHandshakeFailed",
    "Error Code": 2147500037
  },
  "message": ""
}

Event ID 227 — StateTransitionName: MCS Channel Join Confirmation received: ChannelID = ChannelID, ChannelName = ChannelName.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
RDPStateTransition
Opcode
Thiseventisraisedduringastatetransition.

Description

StateTransitionName: MCS Channel Join Confirmation received: ChannelID = ChannelID, ChannelName = ChannelName.

Message #

%1: MCS Channel Join Confirmation received: ChannelID = %2, ChannelName = %3.

Fields #

NameDescription
StateTransitionName UnicodeString
ChannelID UInt32
ChannelName UnicodeString

Event ID 1000 —

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Opcode
Info

Fields #

NameDescription
Function UnicodeString
Line UnicodeString
DebugMessage UnicodeString

Event ID 1001 — RDP ClientActiveX is trying to connect to the server (Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX is trying to connect to the server (Value).

Message #

RDP ClientActiveX is trying to connect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1002 — RDP ClientActiveX has connected to the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX has connected to the server.

Message #

RDP ClientActiveX has connected to the server

Event ID 1003 — RDP ClientActiveX has been disconnected (Reason= Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

RDP ClientActiveX has been disconnected (Reason= Value).

Message #

RDP ClientActiveX has been disconnected (Reason= %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1004 — Client has logged on to the server (SessionId = Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Client has logged on to the server (SessionId = Value).

Message #

Client has logged on to the server (SessionId = %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1005 — Client failed to logon on to the server (Error = ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Client failed to logon on to the server (Error = ErrorCode).

Message #

Client failed to logon on to the server (Error = %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1006 — Client machine has lost network connectivity (Reason= ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

Client machine has lost network connectivity (Reason= ErrorCode).

Message #

Client machine has lost network connectivity (Reason= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1007 — DNS failed to resolve the server name (Error= ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringresolvingtheservername

Description

DNS failed to resolve the server name (Error= ErrorCode).

Message #

DNS failed to resolve the server name (Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1008 — The credentials provided are authenticated by the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheauthenticationprocess

Description

The credentials provided are authenticated by the server.

Message #

The credentials provided are authenticated by the server

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1009 — The credentials provided were failed to be authenticated by the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheauthenticationprocess

Description

The credentials provided were failed to be authenticated by the server.

Message #

The credentials provided were failed to be authenticated by the server

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1010 — RDP ClientActiveX is connecting to a gateway server (Name=Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX is connecting to a gateway server (Name=Value).

Message #

RDP ClientActiveX is connecting to a gateway server (%1=%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1011 — RDP ClientActiveX succeeded in connecting to the gateway server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX succeeded in connecting to the gateway server.

Message #

RDP ClientActiveX succeeded in connecting to the gateway server

Event ID 1012 — RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX failed to connect to the gateway server(Error= ErrorCode).

Message #

RDP ClientActiveX failed to connect to the gateway server(Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1013 — RDP ClientActiveX is trying to automatically reconnect to the server (Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX is trying to automatically reconnect to the server (Value).

Message #

RDP ClientActiveX is trying to automatically reconnect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1014 — RDP ClientActiveX succeeded in automatically connecting to the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX succeeded in automatically connecting to the server.

Message #

RDP ClientActiveX succeeded in automatically connecting to the server

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1015 — RDP ClientActiveX failed to automatically connect to the server (Reason= TraceMessage).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
AutomaticReconnectionSequence
Opcode
Thiseventisraisedwhiletryingtoautomaticallyreconnecttotheserver

Description

RDP ClientActiveX failed to automatically connect to the server (Reason= TraceMessage).

Message #

RDP ClientActiveX failed to automatically connect to the server (Reason= %1)

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1016 — Client has a license to connect to the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtogetavalidlicense

Description

Client has a license to connect to the server.

Message #

Client has a license to connect to the server

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1017 — Client does not have a license to connect to the server (Error= ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedwhiletryingtogetavalidlicense

Description

Client does not have a license to connect to the server (Error= ErrorCode).

Message #

Client does not have a license to connect to the server (Error= %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1018 — RDP ClientActiveX failed to connect to the server (Error = ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX failed to connect to the server (Error = ErrorCode).

Message #

RDP ClientActiveX failed to connect to the server (Error = %2)

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1019 — TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1020 — RDP ClientActiveX has recorded the following error - ErrorCode.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Description

RDP ClientActiveX has recorded the following error - ErrorCode. Check Details.

Message #

RDP ClientActiveX has recorded the following error - %2. Check Details.

Fields #

NameDescription
TraceMessage UnicodeString
ErrorCode UInt32

Event ID 1021 — RDP ClientActiveX's gateway transport has recorded the following error - Value.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Description

RDP ClientActiveX's gateway transport has recorded the following error - Value. Check Details.

Message #

RDP ClientActiveX's gateway transport has recorded the following error - %2. Check Details.

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1022 — TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
GatewayConnectionSequence
Opcode
Thiseventisraisedinthegatewaytransport

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1023 — RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence

Description

RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = Value).

Message #

RDP Client ActiveX has started using RemoteFX for graphics decoding (decoder type = %2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1024 — RDP ClientActiveX is trying to connect to the server (Value).

#
Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Collection Priority
Recommended (Microsoft-WEF, others)
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX is trying to connect to the server (Value).

Message #

RDP ClientActiveX is trying to connect to the server (%2)

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1024,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.580526+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 11240
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Name": "Server Name",
    "Value": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
    "CustomLevel": "Info"
  },
  "message": ""
}

Detection Rules #

View all rules referencing this event →

Splunk # view in reference

  • Windows RDPClient Connection Sequence Events source: This analytic monitors Windows RDP client connection sequence events (EventCode 1024) from the Microsoft-Windows-TerminalServices-RDPClient/Operational log. These events track when RDP ClientActiveX initiates connection attempts to remote servers. The connection sequence is a critical phase of RDP where the client and server exchange settings and establish common parameters for the session. Monitoring these events can help identify unusual RDP connection patterns, potential lateral movement attempts, unauthorized remote access activity, and RDP connection chains that may indicate compromised systems. NOTE the analytic was written for Multi-Line as XML was not properly parsed out.

References #

Event ID 1025 — RDP ClientActiveX has connected to the server

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Collection Priority
Recommended (ANSSI)
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

RDP ClientActiveX has connected to the server.

Message #

RDP ClientActiveX has connected to the server

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.058263+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 5172
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1026 — RDP ClientActiveX has been disconnected (Reason= Value).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

RDP ClientActiveX has been disconnected (Reason= Value).

Message #

RDP ClientActiveX has been disconnected (Reason= %2)

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1027 — Connected to domain (DomainName) with session SessionId.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Connected to domain (DomainName) with session SessionId.

Message #

Connected to domain (%1) with session %2.

Fields #

NameDescription
DomainName UnicodeString
SessionId UInt32

Event ID 1028 — Server supports SSL = TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Server supports SSL = TraceMessage.

Message #

Server supports SSL = %1

Fields #

NameDescription
TraceMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1028,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.991587+00:00",
    "event_record_id": 2,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 5172
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "TraceMessage": "not supported"
  },
  "message": ""
}

Event ID 1029 — Base64(SHA256(UserName)) is = TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

Base64(SHA256(UserName)) is = TraceMessage.

Message #

Base64(SHA256(UserName)) is = %1

Fields #

NameDescription
TraceMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1029,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:36.992493+00:00",
    "event_record_id": 3,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 11240
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "TraceMessage": "-"
  },
  "message": ""
}

Event ID 1030 — RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
ConnectionSequence

Description

RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Message #

RDP Client build %1 %2 %3 %4 %5

Fields #

NameDescription
BuildBranch UnicodeString
BuildDate UnicodeString
BuildTime UnicodeString
BuildVersion UnicodeString
ArchAndFlavour UnicodeString

Event ID 1031 — Invalid format error occured when decoding packet of type TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

Invalid format error occured when decoding packet of type TraceMessage.

Message #

Invalid format error occured when decoding packet of type %1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1032 — Component name:ErrorCode, :: ErrorDescription.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Debug
Task
General
Opcode
Thisisagenericeventthatmayberaisedbytheclient.

Description

Component name:ErrorCode, :: ErrorDescription.

Message #

Component name:%1, :: %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1033 — Component name:Name, :: CustomLevel, Error code:Value.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thisisagenericerrorthatmaybesignaledbytheclient.

Description

Component name:Name, :: CustomLevel, Error code:Value.

Message #

Component name:%1, :: %2, Error code:%3

Fields #

NameDescription
Name UnicodeString
CustomLevel UnicodeString
Value HexInt32

Event ID 1034 — Component name:ErrorCode, :: ErrorDescription.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thisisagenericeventthatmayberaisedbytheclient.

Description

Component name:ErrorCode, :: ErrorDescription.

Message #

Component name:%1, :: %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1100 — The client detected the link latency is Value milliseconds.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client detected the link latency is Value milliseconds.

Message #

The client detected the link latency is %2 milliseconds.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1101 — The client detected the bandwidth is Value kbps/second.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client detected the bandwidth is Value kbps/second.

Message #

The client detected the bandwidth is %2 kbps/second.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1102 — The client has initiated a multi-transport connection to the server Value.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client has initiated a multi-transport connection to the server Value.

Message #

The client has initiated a multi-transport connection to the server %2.

Fields #

NameDescription
Name UnicodeString
Value UnicodeString
CustomLevel UnicodeString

Event ID 1103 — The client has established a multi-transport connection to the server.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client has established a multi-transport connection to the server.

Message #

The client has established a multi-transport connection to the server.

Event ID 1104 — The client failed to establish the multi-transport connection.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The client failed to establish the multi-transport connection.

Message #

The client failed to establish the multi-transport connection.

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Event ID 1105 — The multi-transport connection has been disconnected.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
ConnectionSequence
Opcode
Thiseventisraisedduringtheconnectionprocess

Description

The multi-transport connection has been disconnected.

Message #

The multi-transport connection has been disconnected.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1105,
    "version": 0,
    "level": 4,
    "task": 101,
    "opcode": 10,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-13T18:26:54.989606+00:00",
    "event_record_id": 5,
    "correlation": {
      "ActivityID": "DB2461B3-3531-4655-AE9C-36EB94410000"
    },
    "execution": {
      "process_id": 12488,
      "thread_id": 13944
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1106 — Close event, code = Code.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
ConnectionSequence
Opcode
Thiseventisraisedwhenthereisacloseoperationwhichwillteardowntheconnection.

Description

Close event, code = Code.

Message #

Close event, code = %1.

Fields #

NameDescription
Code UInt32

Event ID 1107 — Disconnect trace:ComponentName "Message", Error code:ErrorCode.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
General
Opcode
Thiseventisraisedduringthedisconnectionprocess

Description

Disconnect trace:ComponentName "Message", Error code:ErrorCode.

Message #

Disconnect trace:%1 "%2", Error code:%3

Fields #

NameDescription
ComponentName UnicodeString
Message UnicodeString
ErrorCode UInt32

Event ID 1201 — The RdClient has been forced exit since cancelling existing workspace job took too long.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheclienthasnotbeenshutdowncleanly.

Description

The RdClient has been forced exit since cancelling existing workspace job took too long.

Message #

The RdClient has been forced exit since cancelling existing workspace job took too long.

Event ID 1202 — The user has clicked sign out on the OOB Client ribbon.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhentheusertriestosignoutfromtheOOBclient.

Description

The user has clicked sign out on the OOB Client ribbon.

Message #

The user has clicked sign out on the OOB Client ribbon.

Event ID 1203 — The user has clicked Refresh on the OOB client ribbon.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheusermanuallytriestodofeedrefresh.

Description

The user has clicked Refresh on the OOB client ribbon.

Message #

The user has clicked Refresh on the OOB client ribbon.

Event ID 1204 — The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhentheusertriestologininADALpageusingdifferentusername.

Description

The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

Message #

The user tried to login into ADAL with a different user name than the one he/she subscribed to initially.

Event ID 1205 — Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenaworkspaceeventlikesubscribe/updatesucceeded.

Description

Event: Workspace Event succeeded for Tenant = TenantId , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. NumberOfResources = ErrorCode.

Message #

%1: Workspace Event succeeded for Tenant = %2 , TotalTimeWithoutAdal = %3 ms, AdalTime = %4 ms. NumberOfResources = %5

Fields #

NameDescription
Event UnicodeString
TenantId UnicodeString
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1206 — Event: Workspace Event failed for Tenant = TenantId.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenaworkspaceeventlikesubscribe/updatefailed!

Description

Event: Workspace Event failed for Tenant = TenantId. , TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. (Error code ErrorCode).

Message #

%1: Workspace Event failed for Tenant = %2. , TotalTimeWithoutAdal = %3 ms, AdalTime = %4 ms. (Error code %5)

Fields #

NameDescription
Event UnicodeString
TenantId UnicodeString
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1207 — RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
RdClientRADCworkspace

Description

RDP Client build BuildBranch BuildDate BuildTime BuildVersion ArchAndFlavour.

Message #

RDP Client build %1 %2 %3 %4 %5

Fields #

NameDescription
BuildBranch UnicodeString
BuildDate UnicodeString
BuildTime UnicodeString
BuildVersion UnicodeString
ArchAndFlavour UnicodeString

Event ID 1208 — Feed discovery succeeded.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenfeeddiscoverysucceeds

Description

Feed discovery succeeded. TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms, NumberOfFeeds = NumberOfFeeds.

Message #

Feed discovery succeeded. TotalTimeWithoutAdal = %1 ms, AdalTime = %2 ms, NumberOfFeeds = %3

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
NumberOfFeeds UInt32

Event ID 1209 — Feed discovery failed.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenfeeddiscoveryfailed!

Description

Feed discovery failed. TotalTimeWithoutAdal = TotalTimeWithoutAdal ms, AdalTime = AdalTime ms. (Error code = ErrorCode).

Message #

Feed discovery failed. TotalTimeWithoutAdal = %1 ms, AdalTime = %2 ms. (Error code = %3)

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1210 — Feed cache corruption encountered.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenthefeedcacheontheclientlocalmachineismissingiconsorRdpfilesduetocachecorruption!

Description

Feed cache corruption encountered. Tenant = TenantId, ResourceId = ResourceIndex, ResourceType = ResourceType, (Error code ErrorCode).

Message #

Feed cache corruption encountered. Tenant = %1, ResourceId = %2, ResourceType = %3, (Error code %4).

Fields #

NameDescription
TenantId UnicodeString
ResourceIndex UInt32
ResourceType UnicodeString
ErrorCode UInt32

Event ID 1211 — Consent status updated successfully.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenuserhassuccessfullyupdatedtheconsentstatusonserverside

Description

Consent status updated successfully. TotalTimeWithoutAdal = TotalTimeWithoutAdal, AdalTime = AdalTime.

Message #

Consent status updated successfully. TotalTimeWithoutAdal =  %1, AdalTime = %2.

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32

Event ID 1212 — Consent status update failed.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenuserisunabletoupdatetheconsentstatusonserver!

Description

Consent status update failed. TotalTimeWithoutAdal = TotalTimeWithoutAdal, AdalTime = AdalTime. (Error code ErrorCode).

Message #

Consent status update failed. TotalTimeWithoutAdal =  %1, AdalTime = %2. (Error code %3)

Fields #

NameDescription
TotalTimeWithoutAdal UInt32
AdalTime UInt32
ErrorCode UInt32

Event ID 1213 — The user has clicked view invitations on the OOB client ribbon.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheusermanuallyclickstheviewinvitationsbutton.

Description

The user has clicked view invitations on the OOB client ribbon.

Message #

The user has clicked view invitations on the OOB client ribbon.

Event ID 1214 — Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone Name = TimeZoneName.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhentheuserstartsanewcycleoffeeddiscovery.WelogthehashedUPNandtimezoneinformationhere

Description

Base64(SHA256(UserName)) = UserNameHash, TimeZone Bias = TimeZoneBias, TimeZone Name = TimeZoneName.

Message #

Base64(SHA256(UserName)) = %1, TimeZone Bias = %2, TimeZone Name = %3.

Fields #

NameDescription
UserNameHash UnicodeString
TimeZoneBias Int32
TimeZoneName UnicodeString

Event ID 1215 — Refresh Time = refreshTime, Number of feeds = numberOfFeeds.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedwhenallthefeedsoftheuserhavebeensubscribedorupdatedcompletely.Welogtheoveralltimeittooktodownloadallfeedsinparallel.

Description

Refresh Time = refreshTime, Number of feeds = numberOfFeeds.

Message #

Refresh Time = %1, Number of feeds = %2.

Fields #

NameDescription
refreshTime UInt32
numberOfFeeds UInt32

Event ID 1216 — ADAL error code = ErrorCode, description = ErrorDescription.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenthereiserrorinacquiringADALtoken.

Description

ADAL error code = ErrorCode, description = ErrorDescription.

Message #

ADAL error code = %1, description = %2

Fields #

NameDescription
ErrorCode UnicodeString
ErrorDescription UnicodeString

Event ID 1217 — ADAL token collected successfully

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenADALauthenticationtokenissuccessfullycreated.

Description

ADAL token collected successfully.

Message #

ADAL token collected successfully

Event ID 1218 — ADAL cancelled

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
ThiseventisraisedwhenADALauthenticationiscancelled.

Description

ADAL cancelled.

Message #

ADAL cancelled

Event ID 1227 — RadcClientType entering stage RadcClientStage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientType entering stage RadcClientStage.

Message #

%1 entering stage %2

Fields #

NameDescription
RadcClientType UnicodeString
RadcClientStage UnicodeString

Event ID 1228 — RadcClientStage with http event type RadcHttpEvent.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent.

Message #

%1 with http event type %2

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString

Event ID 1229 — RadcClientStage with http event type RadcHttpEvent and http status code Code.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent and http status code Code.

Message #

%1 with http event type %2 and http status code %3

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString
Code UInt32

Event ID 1230 — RadcClientStage with http event type RadcHttpEvent failed with xresult Code.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientRADCworkspace
Opcode
Thiseventisraisedduringastatetransition.

Description

RadcClientStage with http event type RadcHttpEvent failed with xresult Code.

Message #

%1 with http event type %2 failed with xresult %3

Fields #

NameDescription
RadcClientStage UnicodeString
RadcHttpEvent UnicodeString
Code UInt32

Event ID 1401 — The server is using version Version of the RDP graphics protocol (client mode: ClientMode, AVC available: AvcEnabled).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogtheversionselected,andtheclientmodeandAVCcapability.

Description

The server is using version Version of the RDP graphics protocol (client mode: ClientMode, AVC available: AvcEnabled).

Message #

The server is using version %1 of the RDP graphics protocol (client mode: %2, AVC available: %3).

Fields #

NameDescription
Version HexInt32
ClientMode UInt32
AvcEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1401,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 36,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.635292+00:00",
    "event_record_id": 6,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Version": "0x80004",
    "ClientMode": 0,
    "AvcEnabled": 0
  },
  "message": ""
}

Event ID 1402 — The client is using hardware memory for the frame buffer.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogthathardwareresourcesarebeingused.

Description

The client is using hardware memory for the frame buffer.

Message #

The client is using hardware memory for the frame buffer.

Event ID 1403 — The client is using software memory for the frame buffer.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Level
Informational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedwhenprotocolcapsarereceivedfromtheserver.Welogthathardwareresourcesarenotbeingused.

Description

The client is using software memory for the frame buffer.

Message #

The client is using software memory for the frame buffer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TerminalServices-ClientActiveXCore",
    "guid": "28AA95BB-D444-4719-A36F-40462168127E",
    "event_source_name": "",
    "event_id": 1403,
    "version": 0,
    "level": 4,
    "task": 106,
    "opcode": 38,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T06:32:37.464424+00:00",
    "event_record_id": 5,
    "correlation": {
      "ActivityID": "2C2C9D66-5F3D-4BCB-872E-D1B715C30000"
    },
    "execution": {
      "process_id": 11236,
      "thread_id": 3796
    },
    "channel": "Microsoft-Windows-TerminalServices-RDPClient/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1404 — The client encountered an issue while decoding and displaying RDP graphics (component: Component, function: Function, error code: ErrorCode).

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Operational
Task
RdClientPipelineworkspace
Opcode
Thiseventisraisedifapipelineerrorisencounteredduringexecution.Welogthefaultingcomponent,function,anderrorcode.

Description

The client encountered an issue while decoding and displaying RDP graphics (component: Component, function: Function, error code: ErrorCode).

Message #

The client encountered an issue while decoding and displaying RDP graphics (component: %1, function: %2, error code: %3)

Fields #

NameDescription
Component UnicodeString
Function UInt32
ErrorCode UInt32

Event ID 1501 — TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1502 — TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString

Event ID 1503 — TraceMessage.

Provider
Microsoft-Windows-TerminalServices-ClientActiveXCore
Channel
Analytic
Task
General

Message #

%1

Fields #

NameDescription
TraceMessage UnicodeString