Microsoft-Windows-TerminalServices-Gateway
120 events across 3 channels
Event ID 100 — The RD Gateway service could not be initialized.
Message
Event ID 101 — The RD Gateway service has started.
Message
Event ID 102 — The Remote Desktop Gateway service requires a valid Secure Sockets Layer (SSL) certificate to accept connections.
Message
Event ID 103 — The Remote Desktop Gateway service does not have sufficient permissions to access the Secure Sockets Layer (SSL) certificate that is required to ac...
Message
Event ID 104 — The UDP Proxy is started.
Message
Event ID 105 — The UDP Proxy is shutting down.
Message
Event ID 106 — The UDP Proxy is not enabled.
Message
Event ID 200 —
Message
Fields
| Name | Description |
|---|---|
EventInfo.Username | — |
EventInfo.IpAddress | — |
EventInfo.AuthType | — |
EventInfo.Resource | — |
EventInfo.ConnectionProtocol | — |
EventInfo.ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-TerminalServices-Gateway
guid: 4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B
event_source_name: ''
event_id: 200
version: 0
level: 4
task: 2
opcode: 30
keywords: 4620693217698906112
time_created: '2024-11-04T13:59:32.400587+00:00'
event_record_id: 87
correlation:
ActivityID: 7CF86876-882F-0625-F153-3DEC514DA0B2
execution:
process_id: 1444
thread_id: 2256
channel: Microsoft-Windows-TerminalServices-Gateway/Operational
computer: EC2AMAZ-6C3C9U6
security:
user_id: S-1-5-20
user_data:
EventInfo:
Username: EC2AMAZ-6C3C9U6\Administrator
IpAddress: 219.100.37.243
AuthType: NTLM
Resource: ''
ConnectionProtocol: HTTP
ErrorCode: 0
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 201 — The user ".
Message
Event ID 202 — The administrator disconnected the user ".
Message
Event ID 203 — The number of simultaneous connections to the RD Gateway server has reached the maximum number that was configured by the administrator.
Message
Event ID 204 — The user ".
Message
Event ID 205 — The user ".
Message
Event ID 206 — The user ".
Message
Event ID 207 — The administrator disconnected the user ".
Message
Event ID 208 — The UDP Proxy disconnected the user ".
Message
Event ID 209 — The RD Gateway client supports HTTP proxy protocol but connected using Legacy RPC-HTTP.
Message
Event ID 210 — Http transport: IN channel could not find a corresponding OUT channel
Message
Event ID 300 —
Message
Fields
| Name | Description |
|---|---|
EventInfo.Username | — |
EventInfo.IpAddress | — |
EventInfo.AuthType | — |
EventInfo.Resource | — |
EventInfo.ConnectionProtocol | — |
EventInfo.ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-TerminalServices-Gateway
guid: 4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B
event_source_name: ''
event_id: 300
version: 0
level: 4
task: 5
opcode: 30
keywords: 4620693217698906112
time_created: '2024-11-04T13:59:32.621299+00:00'
event_record_id: 88
correlation:
ActivityID: 7CF86876-882F-0625-F153-3DEC514DA0B2
execution:
process_id: 1444
thread_id: 2556
channel: Microsoft-Windows-TerminalServices-Gateway/Operational
computer: EC2AMAZ-6C3C9U6
security:
user_id: S-1-5-20
user_data:
EventInfo:
Username: EC2AMAZ-6C3C9U6\Administrator
IpAddress: 219.100.37.243
AuthType: ''
Resource: ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com
ConnectionProtocol: ''
ErrorCode: 0
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 301 — The user ".
Message
Event ID 302 —
Message
Fields
| Name | Description |
|---|---|
EventInfo.Username | — |
EventInfo.IpAddress | — |
EventInfo.AuthType | — |
EventInfo.Resource | — |
EventInfo.ConnectionProtocol | — |
EventInfo.ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-TerminalServices-Gateway
guid: 4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B
event_source_name: ''
event_id: 302
version: 0
level: 4
task: 3
opcode: 30
keywords: 4611686018444165120
time_created: '2024-11-04T13:59:32.624374+00:00'
event_record_id: 89
correlation:
ActivityID: 7CF86876-882F-0625-F153-3DEC514DA0B2
execution:
process_id: 1444
thread_id: 2556
channel: Microsoft-Windows-TerminalServices-Gateway/Operational
computer: EC2AMAZ-6C3C9U6
security:
user_id: S-1-5-20
user_data:
EventInfo:
Username: EC2AMAZ-6C3C9U6\Administrator
IpAddress: 219.100.37.243
AuthType: ''
Resource: ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com
ConnectionProtocol: HTTP
ErrorCode: 0
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 303 —
Message
Fields
| Name | Description |
|---|---|
EventInfo.Username | — |
EventInfo.IpAddress | — |
EventInfo.AuthType | — |
EventInfo.Resource | — |
EventInfo.BytesReceived | — |
EventInfo.BytesTransfered | — |
EventInfo.SessionDuration | — |
EventInfo.ConnectionProtocol | — |
EventInfo.ErrorCode | — |
Example Event
system:
provider: Microsoft-Windows-TerminalServices-Gateway
guid: 4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B
event_source_name: ''
event_id: 303
version: 0
level: 4
task: 3
opcode: 44
keywords: 4611686018444165120
time_created: '2024-11-04T13:59:25.431624+00:00'
event_record_id: 84
correlation:
ActivityID: D993DEC4-0E8C-5014-E2B6-F10CDDA2250E
execution:
process_id: 1444
thread_id: 2256
channel: Microsoft-Windows-TerminalServices-Gateway/Operational
computer: EC2AMAZ-6C3C9U6
security:
user_id: S-1-5-20
user_data:
EventInfo:
Username: EC2AMAZ-6C3C9U6\Administrator
IpAddress: 219.100.37.243
AuthType: ''
Resource: ec2-18-179-8-103.ap-northeast-1.compute.amazonaws.com
BytesReceived: '391624'
BytesTransfered: '241242'
SessionDuration: '57'
ConnectionProtocol: HTTP
ErrorCode: 1226
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 304 — The user ".
Message
Event ID 305 — The user ".
Message
Event ID 306 — The user ".
Message
Event ID 307 — The user ".
Message
Event ID 308 — The user ".
Message
Event ID 309 — The user ".
Message
Event ID 310 — The user ".
Message
Event ID 311 — The user ".
Message
Event ID 312 —
Message
Fields
| Name | Description |
|---|---|
EventInfo.Username | — |
EventInfo.IpAddress | — |
Example Event
system:
provider: Microsoft-Windows-TerminalServices-Gateway
guid: 4D5AE6A1-C7C8-4E6D-B840-4D8080B42E1B
event_source_name: ''
event_id: 312
version: 0
level: 0
task: 3
opcode: 30
keywords: 4611686018427387904
time_created: '2024-11-04T13:59:31.379210+00:00'
event_record_id: 86
correlation:
ActivityID: 7CF86876-882F-0625-F153-3DEC514DA0B2
execution:
process_id: 1444
thread_id: 2256
channel: Microsoft-Windows-TerminalServices-Gateway/Operational
computer: EC2AMAZ-6C3C9U6
security:
user_id: S-1-5-20
user_data:
EventInfo:
Username: Administrator
IpAddress: 219.100.37.243:63920
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 313 — The user ".
Message
Event ID 400 — The RD Gateway service is shutting down.
Message
Event ID 401 — The RD Gateway service successfully registered with the Service Connection Point.
Message
Event ID 402 — The RD Gateway service failed to register with the Service Connection Point.
Message
Event ID 403 — The RD Gateway service successfully unregistered with the Service Connection Point.
Message
Event ID 404 — The RD Gateway service failed to unregister with the Service Connection Point.
Message
Event ID 504 — Logging was enabled for the following RD Gateway event: ".
Message
Event ID 505 — Logging could not be enabled for the following RD Gateway event: ".
Message
Event ID 506 — Logging was disabled for the following RD Gateway event: ".
Message
Event ID 507 — Logging could not be disabled for the following RD Gateway event: ".
Message
Event ID 508 — The value for the maximum number of connections allowed to the RD Gateway server was updated.
Message
Event ID 509 — The value for the maximum number of simultaneous connections allowed to the RD Gateway server could not be updated.
Message
Event ID 510 — The central connection authorization policy was enabled.
Message
Event ID 511 — The central connection authorization policy store could not be enabled.
Message
Event ID 512 — The central connection authorization policy was disabled.
Message
Event ID 513 — The central connection authorization policy store could not be disabled.
Message
Event ID 514 — The 'Request clients to send a statement of health' (SoH) setting is enabled on this RD Gateway server.
Message
Event ID 515 — The 'Request clients to send a statement of health' (SoH) setting could not be enabled on this RD Gateway server.
Message
Fields
| Name | Description |
|---|---|
name | — |
Event ID 516 — The 'Request clients to send a statement of health' (SoH) setting is not enabled on this RD Gateway server.
Message
Event ID 517 — The 'Request clients to send a statement of health' (SoH) setting could not be disabled on this RD Gateway server.
Message
Fields
| Name | Description |
|---|---|
name | — |