Microsoft-Windows-User Profiles Service
123 events across 4 channels
Event ID 1 — Recieved user logon notification on session %1.
Message
Fields
| Name | Description |
|---|---|
Session | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 1
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:20.533133+00:00'
event_record_id: 64
correlation: {}
execution:
process_id: 1428
thread_id: 1544
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Session: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 2 — Finished processing user logon notification on session %1.
Message
Fields
| Name | Description |
|---|---|
Session | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 2
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:20.859547+00:00'
event_record_id: 68
correlation: {}
execution:
process_id: 1428
thread_id: 1544
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Session: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 3 — Recieved user logoff notification on session %1.
Message
Fields
| Name | Description |
|---|---|
Session | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 3
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:34.014942+00:00'
event_record_id: 62
correlation: {}
execution:
process_id: 1852
thread_id: 2012
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Session: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4 — Finished processing user logoff notification on session %1.
Message
Fields
| Name | Description |
|---|---|
Session | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 4
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:31:34.250458+00:00'
event_record_id: 63
correlation: {}
execution:
process_id: 1852
thread_id: 2012
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-21-1992711665-1655669231-58201500-1000
event_data:
Session: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5 — Registry file %1 is loaded at HKU\%2.
Message
Fields
| Name | Description |
|---|---|
File | — |
Key | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 5
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:20.716085+00:00'
event_record_id: 66
correlation: {}
execution:
process_id: 1428
thread_id: 1540
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
File: C:\Users\User\AppData\Local\Microsoft\Windows\\UsrClass.dat
Key: S-1-5-21-1992711665-1655669231-58201500-1000_Classes
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 6 — Starting synchronize profile from %1 to %2.
Message
Fields
| Name | Description |
|---|---|
Source | — |
Target | — |
Event ID 7 — Finished synchronize profile from %1 to %2.
Message
Fields
| Name | Description |
|---|---|
Source | — |
Target | — |
Result | — |
Event ID 50 — Background hive upload for user %1 started.
Message
Fields
| Name | Description |
|---|---|
UserSid | — |
Event ID 51 — Background hive upload for user %1 succeeded.
Message
Fields
| Name | Description |
|---|---|
UserSid | — |
Event ID 52 — Background hive upload for user %1 failed.
Message
Fields
| Name | Description |
|---|---|
UserSid | — |
Error | — |
Event ID 53 — Cannot delete file %1.
Message
Fields
| Name | Description |
|---|---|
File | — |
Error | — |
Event ID 54 — Open user regisry root key for %1 failed.
Message
Fields
| Name | Description |
|---|---|
UserSid | — |
Error | — |
Event ID 55 — Save user hive to file %1 failed.
Message
Fields
| Name | Description |
|---|---|
File | — |
Error | — |
Event ID 56 — Save user hive to file %1 succeeded.
Message
Fields
| Name | Description |
|---|---|
File | — |
Event ID 57 — Enable background user hive upload task succeeded.
Message
Event ID 58 — Failed to enable background user hive upload task.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 59 — Disable background user hive upload task succeeded.
Message
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 59
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T23:50:00.752497+00:00'
event_record_id: 89
correlation: {}
execution:
process_id: 1428
thread_id: 1496
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 60 — Failed to disable background user hive upload task.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 61 — Slow network connection detected, abort background user hive upload task.
Message
Event ID 62 — Windows was unable to successfully evaluate whether this computer is a primary computer for this user.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 63 — This computer %1 a primary computer for this user.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 64 — The primary computer relationship for this computer and this user was not evaluated due to %1.
Message
Fields
| Name | Description |
|---|---|
EnvIssue | — |
Event ID 65 — The attempt to create or open the profile key for the user failed with error %1.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 66 — Creating the local profile for the user failed with error %1.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 67 — Logon type: %1 Local profile location: %2 Profile type: %3.
Message
Fields
| Name | Description |
|---|---|
LogonType | — |
LocalPath | — |
ProfileType | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 67
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-05T22:32:20.729159+00:00'
event_record_id: 67
correlation: {}
execution:
process_id: 1428
thread_id: 1540
channel: Microsoft-Windows-User Profile Service/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data:
LogonType: Regular
LocalPath: C:\Users\User
ProfileType: Regular
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 68 — LastDownloadTime: %1 LastUploadTime: %2.
Message
Fields
| Name | Description |
|---|---|
DownloadTime | — |
UploadTime | — |
Event ID 70 — Waiting on network arrivals.
Message
Fields
| Name | Description |
|---|---|
Timeout | — |
Event ID 71 — After waiting %1 ms, a network with the necessary capabilities was not ready for use.
Message
Fields
| Name | Description |
|---|---|
Timeout | — |
Event ID 72 — Terminating wait due to unexpected failure %1.
Message
Fields
| Name | Description |
|---|---|
Result | — |
Event ID 73 — Wait complete due to connectivity event but network not ready.
Message
Event ID 74 — Wait completed due to network connectivity or determination that no viable network connection is likely to become available.
Message
Event ID 75 — Roaming Profiles configuration is being controlled by Group Policy.
Message
Event ID 76 — Roaming Profiles configuration is being controlled by WMI configuration classes Win32_RoamingProfileUserConfiguration and Win32_RoamingProfileMachi...
Message
Event ID 1001 — Begin new user profile creation.
Message
Event ID 1002 — New user profile creation complete.
Message
Event ID 1003 — A network latency of %1 milliseconds has been detected.
Message
Fields
| Name | Description |
|---|---|
MeasuredLatency | — |
LatencyThreshold | — |
Event ID 1004 — A network bandwidth of %1 kilobits per second has been detected.
Message
Fields
| Name | Description |
|---|---|
MeasuredBandwidth | — |
BandwidthThreshold | — |
Event ID 1005 — Delete cached profile %1 since it is older than %2 days.
Message
Fields
| Name | Description |
|---|---|
ProfilePath | — |
AgeLimitInDays | — |
Event ID 1500 — Windows cannot log you on because your profile cannot be loaded.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1501 — Windows cannot create a temporary profile directory.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1502 — Windows cannot load the locally stored profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1503 — Windows cannot set security on your registry.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1504 — Windows cannot update your roaming profile completely.
Message
Event ID 1505 — Windows cannot load the user's profile but has logged you on with the default profile for the system.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1506 — Your roaming profile is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1508 — Windows was unable to load the registry.
Message
Fields
| Name | Description |
|---|---|
Error | — |
File | — |
Event ID 1509 — Windows was unable to load %1.
Message
Fields
| Name | Description |
|---|---|
File | — |
Status | — |
MachineKeys | — |
UserKeys | — |
Event ID 1510 — Windows cannot load your profile because it appears to be corrupted.
Message
Event ID 1511 — Windows cannot find the local profile and is logging you on with a temporary profile.
Message
Event ID 1512 — Windows cannot unload your registry file.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1513 — Windows cannot copy your profile because it contains encrypted files or directories.
Message
Event ID 1514 — The roaming profile path %1 is too long.
Message
Fields
| Name | Description |
|---|---|
File | — |
Event ID 1515 — Windows has backed up this user profile.
Message
Event ID 1517 — Windows saved user %1 registry while an application or service was still using the registry when the user logged off.
Message
Fields
| Name | Description |
|---|---|
UserSid | — |
Event ID 1518 — Windows cannot create a local profile and is logging you on with a temporary profile.
Message
Event ID 1519 — Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1520 — Windows cannot log you on because your roaming mandatory profile is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1521 — Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1522 — Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1523 — Your roaming profile (read only) is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1524 — Windows cannot unload your classes registry file - it is still in use by other applications or services.
Message
Event ID 1525 — Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption, Offline Cachin...
Message
Event ID 1526 — Windows could not load your roaming profile and is attempting to log you on with your local profile.
Message
Event ID 1527 — Windows failed to initialize user profiles.
Message
Event ID 1529 — Roaming user profiles across forests are disabled.
Message
Event ID 1530 — Windows detected your registry file is still in use by other applications or services.
Message
Fields
| Name | Description |
|---|---|
Name | — |
Data | — |
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 1530
version: 0
level: 3
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2013-10-23T17:27:30.004750+00:00'
event_record_id: 170
correlation: {}
execution:
process_id: 916
thread_id: 928
channel: Application
computer: IE8Win7
security:
user_id: S-1-5-18
event_data:
Name: EVENT_HIVE_LEAK
Data:
Name: Detail
Value: '1 user registry handles leaked from \Registry\User\S-1-5-21-3463664321-2923530833-3546627382-1000:
Process 432 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened
key \REGISTRY\USER\S-1-5-21-3463664321-2923530833-3546627382-1000
'
message: "Windows detected your registry file is still in use by other applications
or services. The file will be unloaded now. The applications or services that hold
your registry file may not function properly afterwards. No user action is required.
\ \n\n DETAIL - \n EVENT_HIVE_LEAK"
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 1531 — The User Profile Service has started successfully.
Message
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 1531
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:39.296302+00:00'
event_record_id: 1437
correlation: {}
execution:
process_id: 1900
thread_id: 2016
channel: Application
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: The User Profile Service has started successfully. %n%n
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 1532 — The User Profile Service has stopped.
Message
Example Event
system:
provider: Microsoft-Windows-User Profiles Service
guid: 89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845
event_source_name: ''
event_id: 1532
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:23:40.274053+00:00'
event_record_id: 1436
correlation: {}
execution:
process_id: 1716
thread_id: 1736
channel: Application
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: The User Profile Service has stopped. %n%n
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 1533 — Windows cannot delete the profile directory %1.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 1534 — Profile notification of event %1 for component %2 failed, error code is %3.
Message
Fields
| Name | Description |
|---|---|
Event | — |
Component | — |
Error | — |
Event ID 1535 — Successfully suspended folder ".
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Event ID 1536 — Successfully unsuspended folder ".
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Event ID 1537 — Failed to suspend folder ".
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 1538 — Failed to unsuspend folder ".
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 1539 — Failed to sync folder ".
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 1540 — Your roaming profile is not synchronized correctly with the server.
Message
Event ID 1541 — Failed to apply CSC suspend policy.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1542 — Windows cannot load classes registry file.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 1543 — A slow network connection is detected for the roaming profile %1.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Event ID 1544 — Windows cannot back up a ProfileList entry because one already exists for this user.
Message
Event ID 1545 — User hive is loaded by another process (File Lock).
Message
Fields
| Name | Description |
|---|---|
InterferingImageName | — |
InterferingPID | — |
ProfsvcPID | — |
Event ID 1552 — User hive is loaded by another process (Registry Lock) Process name: %1, PID: %2, ProfSvc PID: %3.
Message
Fields
| Name | Description |
|---|---|
InterferingImageName | — |
InterferingPID | — |
ProfsvcPID | — |
Event ID 1073743340 — Windows unloaded user {User} registry when it received a notification that no other applications or services were using the profile.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 1073743341 — Windows saved user {User} registry while an application or service was still using the registry when the user logged off.
Message
Fields
| Name | Description |
|---|---|
User | — |
Event ID 1073743355 — The User Profile Service has started successfully.
Message
Event ID 1073743356 — The User Profile Service has stopped.
Message
Event ID 1073743359 — Successfully suspended folder '.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Event ID 1073743360 — Successfully unsuspended folder '.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Event ID 2147485172 — Windows cannot unload your classes registry file - it is still in use by other applications or services.
Message
Event ID 2147485173 — Windows has detected that Automatic Offline Caching is enabled on the Roaming Profile share - to avoid potential profile corruption; Offline Cachin...
Message
Event ID 2147485178 — Windows detected your registry file is still in use by other applications or services.
Message
Fields
| Name | Description |
|---|---|
Detail | — |
Event ID 2147485182 — Profile notification of event {Event} for component {Component} failed; error code is {Error}.
Message
Fields
| Name | Description |
|---|---|
Event | — |
Component | — |
Error | — |
Event ID 2147485188 — Your roaming profile is not synchronized correctly with the server.
Message
Event ID 3221226972 — Windows cannot log you on because your profile cannot be loaded.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226973 — Windows cannot create a temporary profile directory.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226974 — Windows cannot load the locally stored profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226975 — Windows cannot set security on your registry.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226976 — Windows Windows cannot update your roaming profile completely.
Message
Event ID 3221226977 — Windows cannot load the user's profile but has logged you on with the default profile for the system.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226978 — Your roaming profile is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226980 — Windows was unable to load the registry.
Message
Fields
| Name | Description |
|---|---|
Error | — |
File | — |
Event ID 3221226982 — Windows cannot load your profile because it appears to be corrupted.
Message
Event ID 3221226983 — Windows cannot find the local profile and is logging you on with a temporary profile.
Message
Event ID 3221226984 — Windows cannot unload your registry file.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226985 — Windows cannot copy your profile because it contains encrypted files or directories.
Message
Event ID 3221226986 — The roaming profile path {File} is too long.
Message
Fields
| Name | Description |
|---|---|
File | — |
Event ID 3221226987 — Windows has backed up this user profile.
Message
Event ID 3221226990 — Windows cannot create a local profile and is logging you on with a temporary profile.
Message
Event ID 3221226991 — Windows cannot locate your roaming mandatory profile and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226992 — Windows cannot log you on because your roaming mandatory profile is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226993 — Windows cannot locate the server copy of your roaming profile and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226994 — Windows cannot locate your roaming profile (read only) and is attempting to log you on with your local profile.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226995 — Your roaming profile (read only) is not available.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221226998 — Windows could not load your roaming profile and is attempting to log you on with your local profile.
Message
Event ID 3221226999 — Windows failed to initialize user profiles.
Message
Event ID 3221227001 — Roaming user profiles across forests are disabled.
Message
Event ID 3221227005 — Windows cannot delete the profile directory {Directory}.
Message
Fields
| Name | Description |
|---|---|
Directory | — |
Error | — |
Event ID 3221227009 — Failed to suspend folder '.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 3221227010 — Failed to unsuspend folder '.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 3221227011 — Failed to sync folder '.
Message
Fields
| Name | Description |
|---|---|
Folder | — |
Error | — |
Event ID 3221227013 — Failed to apply CSC suspend policy.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221227014 — Windows cannot load classes registry file.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 3221227015 — A slow network connection is detected for the roaming profile {Path}.
Message
Fields
| Name | Description |
|---|---|
Path | — |