Microsoft-Windows-UserPnp
88 events across 8 channels
Event ID 7550 — New device queued up for install.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 7551 — Plug and Play install scheduler has started.
Message
Fields
| Name | Description |
|---|---|
ThreadId | — |
Event ID 7552 — Plug and Play install scheduler has exited.
Message
Fields
| Name | Description |
|---|---|
ThreadId | — |
Event ID 7553 — Plug and Play install worker thread has started.
Message
Fields
| Name | Description |
|---|---|
ThreadId | — |
DeviceId | — |
Event ID 7554 — Plug and Play install worker thread has exited.
Message
Fields
| Name | Description |
|---|---|
ThreadId | — |
Event ID 7555 — Parent of current device is already ahead in the install queue.
Message
Fields
| Name | Description |
|---|---|
ChildDevice | — |
ParentDevice | — |
Event ID 7556 — Current device is a volume snapshot device.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 7600 — Client {ClientName} successfully registered for device notifications.
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 7601 — Error sending device event notification window message to client {WindowName} (hWnd={hWnd}; Session={SessionId}; Err={ErrorCode}).
Message
Fields
| Name | Description |
|---|---|
WindowName | — |
hWnd | — |
SessionId | — |
ErrorCode | — |
Event ID 7602 — Error sending service control for device event notification to client {ClientName} (Session={SessionId}; Err={ErrorCode}).
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
SessionId | — |
ErrorCode | — |
Event ID 7603 — Error broadcasting system message for device event notification (Err={ErrorCode}).
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 7604 — Sending notification for event {EventType} for device: {DeviceID}.
Message
Fields
| Name | Description |
|---|---|
EventType | — |
DeviceID | — |
Event ID 7650 — Received device event from Kernel PnP (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).
Message
Fields
| Name | Description |
|---|---|
EventGuid | — |
EventCategory | — |
IsEventAsync | — |
Event ID 7651 — User PnP completed handling of the device event (GUID={EventGuid}; EventCategory={EventCategory}; Async={IsEventAsync}).
Message
Fields
| Name | Description |
|---|---|
EventGuid | — |
EventCategory | — |
IsEventAsync | — |
Event ID 7700 — Start processing '.
Message
Fields
| Name | Description |
|---|---|
DIF_CODE | — |
ErrorCode | — |
Event ID 7701 — Finished processing '.
Message
Fields
| Name | Description |
|---|---|
DIF_CODE | — |
ErrorCode | — |
Event ID 7702 — START: Core device install operations.
Message
Event ID 7703 — END: Core device install operations.
Message
Event ID 7704 — ENTER: Synchronization wait for core device install.
Message
Event ID 7705 — EXIT: Synchronization wait for core device install.
Message
Event ID 7708 — ENTER: Stage driver package
Message
Event ID 7709 — EXIT: Stage driver package
Message
Event ID 7714 — ENTER: Sending event notification to service ({ClientName}).
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 7715 — EXIT: Sending event notification to service ({ClientName}).
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 7716 — ENTER: Sending event notification to window ({ClientName}).
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 7717 — EXIT: Sending event notification to window ({ClientName}).
Message
Fields
| Name | Description |
|---|---|
ClientName | — |
Event ID 7718 — ENTER: Device installation restrictions policy check.
Message
Event ID 7719 — EXIT: Device installation restrictions policy check.
Message
Event ID 7720 — ENTER: Build driver info list.
Message
Event ID 7721 — EXIT: Build driver info list.
Message
Event ID 7722 — ENTER: Build driver info list - search published INFs.
Message
Event ID 7723 — EXIT: Build driver info list - search published INFs.
Message
Event ID 7724 — ENTER: Build driver info list - search Device Path.
Message
Event ID 7725 — EXIT: Build driver info list - search Device Path.
Message
Event ID 7728 — ENTER: Build driver info list - search caller specified folder.
Message
Event ID 7729 — EXIT: Build driver info list - search caller specified folder.
Message
Event ID 7730 — ENTER: PnpInstallDevice - install device instance.
Message
Event ID 7731 — EXIT: PnpInstallDevice - install device instance.
Message
Event ID 7800 — START: Searching WMIS for metadata package
Message
Event ID 7801 — STOP: Searching WMIS for metadata package
Message
Event ID 7802 — START: Downloading metadata package from WMIS
Message
Event ID 7803 — STOP: Downloading metadata package from WMIS
Message
Event ID 7804 — START: Searching local index for metadata package
Message
Event ID 7805 — STOP: Searching local index for metadata package
Message
Event ID 7806 — START: Unpacking metadata package into cache
Message
Event ID 7807 — STOP: Unpacking metadata package into cache
Message
Event ID 7808 — START: Parsing packageinfo.
Message
Event ID 7809 — STOP: Parsing packageinfo.
Message
Event ID 7810 — START: Scanning local store for new metadata packages
Message
Event ID 7811 — STOP: Scanning local store for new metadata packages
Message
Event ID 7812 — START: Initializing DMRC
Message
Event ID 7813 — STOP: Initializing DMRC
Message
Event ID 7814 — START: Uninitialize DMRC
Message
Event ID 7815 — STOP: Uninitializing DMRC
Message
Event ID 7900 — %1 (Package: %2 Error Code = %3, Win32 Error Code = %4).
Message
Fields
| Name | Description |
|---|---|
Message | — |
Package | — |
ErrorCode | — |
Win32ErrorCode | — |
Event ID 7901 — A new device metadata package was downloaded from WMIS.
Message
Fields
| Name | Description |
|---|---|
PackagePath | — |
Event ID 7902 — %1 (Package: %2 Error Code = %3, Win32 Error Code = %4).
Message
Fields
| Name | Description |
|---|---|
Message | — |
Package | — |
ErrorCode | — |
Win32ErrorCode | — |
Event ID 7903 — Successfully parsed device metadata file.
Message
Fields
| Name | Description |
|---|---|
File | — |
Language | — |
Event ID 7950 — A new device metadata package was discovered.
Message
Fields
| Name | Description |
|---|---|
PackageName | — |
PackagePath | — |
Event ID 7951 — DMRC was queried for type '.
Message
Fields
| Name | Description |
|---|---|
QueryType | — |
LookupKey | — |
Event ID 7952 — %1 (Error Code = %2, Last Http Status Code = %3).
Message
Fields
| Name | Description |
|---|---|
Message | — |
NetworkErrorCode | — |
HttpStatusCode | — |
Event ID 8000 — A reboot is required to complete device installation of device '.
Message
Fields
| Name | Description |
|---|---|
ERR_DEVICE_ID.DeviceId | — |
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8000
version: 0
level: 3
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-10-25T22:50:39.873740+00:00'
event_record_id: 21
correlation: {}
execution:
process_id: 3600
thread_id: 1060
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDevEval
security:
user_id: S-1-5-18
user_data:
ERR_DEVICE_ID:
DeviceId: ACPI\VMW0003\4&1BD7F811&0
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8001 — The DeviceInstall service has started.
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8001
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T06:25:29.349729+00:00'
event_record_id: 30
correlation: {}
execution:
process_id: 1080
thread_id: 1096
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8002 — The DeviceInstall service is stopping (idle).
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8002
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T01:04:11.781477+00:00'
event_record_id: 44
correlation: {}
execution:
process_id: 16172
thread_id: 12452
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8003 — The DeviceInstall service is stopping (stop control).
Message
Event ID 8004 — The DeviceInstall service is stopping (shutdown).
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8004
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T06:23:40.089953+00:00'
event_record_id: 27
correlation: {}
execution:
process_id: 1068
thread_id: 1072
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8005 — The DeviceInstall service has stopped.
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8005
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T06:23:40.106579+00:00'
event_record_id: 28
correlation: {}
execution:
process_id: 1068
thread_id: 1092
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8006 — There are pending driver updates to install.
Message
Event ID 8007 — A timeout was detected during the installation of device '.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 8008 — The DeviceInstall service is starting.
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8008
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T06:25:29.340577+00:00'
event_record_id: 29
correlation: {}
execution:
process_id: 1080
thread_id: 1096
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8009 — The DeviceInstall service failed to start with error %1.
Message
Fields
| Name | Description |
|---|---|
ErrorCode | — |
Event ID 8010 — Finish install operation state changed to %1.
Message
Fields
| Name | Description |
|---|---|
hc_stateid | — |
Event ID 8020 — Device installation is currently disabled.
Message
Event ID 8021 — Device installation has been disabled.
Message
Event ID 8022 — Device installation has been enabled.
Message
Event ID 8030 — The DeviceInstall service will not idle stop.
Message
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 8030
version: 0
level: 4
task: 0
opcode: 0
keywords: 576460752303423490
time_created: '2023-11-06T06:25:29.352092+00:00'
event_record_id: 31
correlation: {}
execution:
process_id: 1080
thread_id: 1096
channel: Microsoft-Windows-UserPnp/DeviceInstall
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 8040 —
Fields
| Name | Description |
|---|---|
DeviceInstanceId | — |
HardwareIds | — |
CompatibleIds | — |
MatchingDeviceId | — |
OriginalInfName | — |
DriverDate | — |
DriverVersion | — |
SubmissionId | — |
FlightIds | — |
Event ID 20001 — Driver Management concluded the process to install driver http://schemas.
Message
Fields
| Name | Description |
|---|---|
InstallDeviceID.xmlns:auto-ns2 | — |
InstallDeviceID.DriverName | — |
InstallDeviceID.DriverVersion | — |
InstallDeviceID.DriverProvider | — |
InstallDeviceID.DeviceInstanceID | — |
InstallDeviceID.SetupClass | — |
InstallDeviceID.RebootOption | — |
InstallDeviceID.UpgradeDevice | — |
InstallDeviceID.IsDriverOEM | — |
InstallDeviceID.InstallStatus | — |
InstallDeviceID.DriverDescription | — |
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 20001
version: 0
level: 4
task: 7005
opcode: 0
keywords: 9223372036854775808
time_created: '2013-10-23T16:17:53.968750+00:00'
event_record_id: 250
correlation: {}
execution:
process_id: 1536
thread_id: 1900
channel: System
computer: 37L4247D28-05
security:
user_id: S-1-5-18
user_data:
InstallDeviceID:
xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events
DriverName: FileRepository\rdpbus.inf_x86_neutral_27637529205407be\rdpbus.inf
DriverVersion: 6.1.7600.16385
DriverProvider: Microsoft
DeviceInstanceID: ROOT\RDPBUS\0000
SetupClass: 4D36E97D-E325-11CE-BFC1-08002BE10318
RebootOption: false
UpgradeDevice: false
IsDriverOEM: false
InstallStatus: 0
DriverDescription: Remote Desktop Device Redirector Bus
message: 'Driver Management concluded the process to install driver http://schemas.microsoft.com/win/2004/08/events
for Device Instance ID Microsoft with the following status: false.'
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 20002 — Driver Management concluded the process to remove driver %1 from Device Instance ID %4 with the following status: %9.
Message
Fields
| Name | Description |
|---|---|
DriverName | — |
DriverVersion | — |
DriverProvider | — |
DeviceInstanceID | — |
SetupClass | — |
RebootOption | — |
UpgradeDevice | — |
IsDriverOEM | — |
InstallStatus | — |
DriverDescription | — |
Event ID 20003 — Driver Management has concluded the process to add Service http://schemas.microsoft.com/win/2004/08/events for Device Instance ID system32\DRIVERS\mssmbios.sys with the following status: true.
Message
Fields
| Name | Description |
|---|---|
AddServiceID.ServiceName | — |
AddServiceID.DriverFileName | — |
AddServiceID.DeviceInstanceID | — |
AddServiceID.PrimaryService | — |
AddServiceID.UpdateService | — |
AddServiceID.AddServiceStatus | — |
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 20003
version: 0
level: 4
task: 7005
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:30:40.551666+00:00'
event_record_id: 1844
correlation: {}
execution:
process_id: 7864
thread_id: 8460
channel: System
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
AddServiceID:
ServiceName: VM3DService
DriverFileName: '%SystemRoot%\system32\vm3dservice.exe'
DeviceInstanceID: PCI\VEN_15AD&DEV_0405&SUBSYS_040515AD&REV_00\3&61AAA01&0&78
PrimaryService: false
UpdateService: false
AddServiceStatus: 0
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 20004 — Driver Management has concluded the process to remove Service %1 for Device Instance ID %3 with the following status: %6.
Message
Fields
| Name | Description |
|---|---|
ServiceName | — |
DriverFileName | — |
DeviceInstanceID | — |
PrimaryService | — |
UpdateService | — |
AddServiceStatus | — |
Event ID 20005 — Driver Management has restricted the installation of Device Instance ID %1 because of a Device Installation Restriction policy setting.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 20006 — Driver Management has deferred the process to install Device Instance ID %1 until a driver has been selected because of a Device Installation Restr...
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 20007 — Driver Management has removed Device Instance ID %1 because of a Device Installation Restriction policy setting.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 20008 — Driver Management has not removed Device Instance ID %1 with matching policy restriction because it is a required system device.
Message
Fields
| Name | Description |
|---|---|
DeviceId | — |
Event ID 20009 — Driver Management will reboot the system in %1 seconds to enforce a Device Installation Restriction policy setting.
Message
Fields
| Name | Description |
|---|---|
RebootTime | — |
Event ID 20010 —
Fields
| Name | Description |
|---|---|
INFO_PNP_STATE.xmlns:auto-ns2 | — |
INFO_PNP_STATE.InstallSubsystemState | — |
INFO_PNP_STATE.CachingSubsystemState | — |
Example Event
system:
provider: Microsoft-Windows-UserPnp
guid: 96F4A050-7E31-453C-88BE-9634F4E02139
event_source_name: ''
event_id: 20010
version: 0
level: 4
task: 7010
opcode: 0
keywords: 9223372036854775808
time_created: '2013-10-23T16:18:04.750000+00:00'
event_record_id: 255
correlation: {}
execution:
process_id: 616
thread_id: 1644
channel: System
computer: 37L4247D28-05
security:
user_id: S-1-5-18
user_data:
INFO_PNP_STATE:
xmlns:auto-ns2: http://schemas.microsoft.com/win/2004/08/events
InstallSubsystemState: true
CachingSubsystemState: true
message: ''
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 20011 — Device action request for device '.
Message
Fields
| Name | Description |
|---|---|
VetoDevice | — |
VetoName | — |
VetoType | — |