Microsoft-Windows-WAS
430 events across 1 channel
Event ID 5001 —
Event ID 5002 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5003 —
Event ID 5004 —
Event ID 5005 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5006 —
Event ID 5007 —
Event ID 5008 —
Event ID 5009 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
ExitCode | — |
Event ID 5010 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5011 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5012 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5013 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5014 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5015 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
OrphanAction | — |
__binLength | — |
binary | — |
Event ID 5016 —
Event ID 5017 —
Event ID 5018 —
Event ID 5019 —
Event ID 5020 —
Event ID 5021 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5022 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5023 —
Event ID 5024 —
Fields
| Name | Description |
|---|---|
SiteID | — |
LogFileTruncateBytes | — |
Event ID 5025 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5026 —
Event ID 5027 —
Event ID 5028 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5029 —
Event ID 5030 —
Event ID 5031 —
Event ID 5032 —
Event ID 5033 —
Event ID 5034 —
Event ID 5035 —
Event ID 5036 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5037 —
Event ID 5038 —
Event ID 5039 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5040 —
Event ID 5041 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Property | — |
Value | — |
RangeLow | — |
RangeHigh | — |
DefaultValue | — |
Event ID 5042 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
CmdValue | — |
Event ID 5043 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5044 —
Event ID 5045 —
Event ID 5046 —
Fields
| Name | Description |
|---|---|
SiteID | — |
CmdValue | — |
Event ID 5047 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 5048 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
AppPoolID | — |
Event ID 5049 —
Event ID 5050 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
NameLength | — |
MaxLength | — |
Event ID 5051 —
Event ID 5052 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 5053 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5054 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
AutoStopAction | — |
__binLength | — |
binary | — |
Event ID 5055 —
Fields
| Name | Description |
|---|---|
SiteID | — |
AppPoolID | — |
Event ID 5056 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5057 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5058 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5059 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5060 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5061 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5062 —
Event ID 5063 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5064 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5065 —
Fields
| Name | Description |
|---|---|
Bytes | — |
Event ID 5066 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5067 —
Fields
| Name | Description |
|---|---|
Property | — |
Value | — |
RangeLow | — |
RangeHigh | — |
DefaultValue | — |
Event ID 5068 —
Event ID 5069 —
Event ID 5070 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5071 —
Event ID 5072 —
Event ID 5073 —
Event ID 5074 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5075 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5076 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5077 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5078 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5079 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5080 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5081 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5082 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5083 —
Event ID 5084 —
Event ID 5085 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5086 —
Event ID 5087 —
Event ID 5088 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5089 —
Event ID 5090 —
Event ID 5091 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5092 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5093 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5094 —
Fields
| Name | Description |
|---|---|
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 5095 —
Event ID 5096 —
Event ID 5097 —
Event ID 5098 —
Event ID 5099 —
Event ID 5100 —
Fields
| Name | Description |
|---|---|
SiteID | — |
Application | — |
__binLength | — |
binary | — |
Event ID 5101 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5102 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5103 —
Fields
| Name | Description |
|---|---|
SiteID | — |
Application | — |
__binLength | — |
binary | — |
Event ID 5104 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5105 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5106 —
Fields
| Name | Description |
|---|---|
SiteID | — |
Application | — |
__binLength | — |
binary | — |
Event ID 5107 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5108 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5109 —
Event ID 5110 —
Event ID 5111 —
Event ID 5112 —
Event ID 5113 —
Event ID 5114 —
Event ID 5115 —
Event ID 5116 —
Event ID 5117 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5118 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5119 —
Event ID 5120 —
Event ID 5121 —
Event ID 5122 —
Event ID 5123 —
Event ID 5124 —
Event ID 5125 —
Event ID 5126 —
Event ID 5127 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5128 —
Event ID 5129 —
Event ID 5130 —
Event ID 5131 —
Event ID 5132 —
Event ID 5133 —
Event ID 5134 —
Event ID 5135 —
Event ID 5136 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5137 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
param3 | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5138 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
param3 | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5139 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
param3 | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5140 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5141 —
Event ID 5142 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5143 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5144 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5145 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5146 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5147 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5148 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
AppPoolID | — |
Event ID 5149 —
Fields
| Name | Description |
|---|---|
Property | — |
Value | — |
DefaultValue | — |
Event ID 5150 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
SiteID | — |
Application | — |
__binLength | — |
binary | — |
Event ID 5151 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
SiteID | — |
Application | — |
__binLength | — |
binary | — |
Event ID 5152 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
IdleTimeout | — |
PeriodicRestartTime | — |
Event ID 5153 —
Event ID 5154 —
Event ID 5155 —
Event ID 5156 —
Event ID 5157 —
Event ID 5158 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
param3 | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5159 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5160 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5161 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5162 —
Fields
| Name | Description |
|---|---|
SiteID | — |
Application | — |
BadAppRoot | — |
RequiredAppRoot | — |
Event ID 5163 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5164 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5165 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5167 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5168 —
Event ID 5169 —
Fields
| Name | Description |
|---|---|
ListenerAdapter | — |
__binLength | — |
binary | — |
Event ID 5170 —
Fields
| Name | Description |
|---|---|
ListenerAdapter | — |
__binLength | — |
binary | — |
Event ID 5171 —
Fields
| Name | Description |
|---|---|
ListenerAdapter | — |
__binLength | — |
binary | — |
Event ID 5172 —
Fields
| Name | Description |
|---|---|
File | — |
LineNumber | — |
Error | — |
__binLength | — |
binary | — |
Event ID 5173 —
Fields
| Name | Description |
|---|---|
ConfigSection | — |
File | — |
LineNumber | — |
Error | — |
__binLength | — |
binary | — |
Event ID 5174 —
Fields
| Name | Description |
|---|---|
param1 | — |
param2 | — |
Property | — |
Value | — |
DefaultValue | — |
Event ID 5175 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5176 —
Event ID 5177 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
Application | — |
SiteID | — |
__binLength | — |
binary | — |
Event ID 5178 —
Fields
| Name | Description |
|---|---|
ProtocolID | — |
__binLength | — |
binary | — |
Event ID 5179 —
Fields
| Name | Description |
|---|---|
ConfigNode | — |
Property | — |
Value | — |
DefaultValue | — |
Event ID 5180 —
Fields
| Name | Description |
|---|---|
ConfigNode | — |
Property | — |
Value | — |
DefaultValue | — |
ValidValues | — |
Event ID 5181 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5182 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5183 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5184 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5185 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5186 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
Minutes | — |
Event ID 5187 —
Fields
| Name | Description |
|---|---|
ListenerAdapter | — |
__binLength | — |
binary | — |
Event ID 5188 —
Event ID 5189 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ErrorType | — |
__binLength | — |
binary | — |
Event ID 5190 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5191 —
Event ID 5192 —
Fields
| Name | Description |
|---|---|
DynamicIdleLoad | — |
NumWorkerProcesses | — |
TotalCommitMB | — |
PhysMemoryMB | — |
PhysMemoryFreeMB | — |
__binLength | — |
binary | — |
Event ID 5193 —
Fields
| Name | Description |
|---|---|
DynamicIdleLoad | — |
NumWorkerProcesses | — |
TotalCommitMB | — |
PhysMemoryMB | — |
PhysMemoryFreeMB | — |
__binLength | — |
binary | — |
Event ID 5194 —
Fields
| Name | Description |
|---|---|
DynamicIdleLoad | — |
NumWorkerProcesses | — |
TotalCommitMB | — |
PhysMemoryMB | — |
PhysMemoryFreeMB | — |
__binLength | — |
binary | — |
Event ID 5195 —
Fields
| Name | Description |
|---|---|
ProcessID | — |
AppPoolID | — |
Minutes | — |
DynamicIdle | — |
Event ID 5196 —
Fields
| Name | Description |
|---|---|
Threshold | — |
__binLength | — |
binary | — |
Event ID 5197 —
Event ID 5198 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5199 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5200 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5201 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5202 —
Fields
| Name | Description |
|---|---|
ErrorCode | — |
__binLength | — |
binary | — |
Event ID 5203 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5204 —
Fields
| Name | Description |
|---|---|
ErrorCode | — |
ConfigPath | — |
ConfigFile | — |
__binLength | — |
binary | — |
Event ID 5205 —
Event ID 5207 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5208 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5209 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
ProcessID | — |
__binLength | — |
binary | — |
Event ID 5210 —
Fields
| Name | Description |
|---|---|
AppPoolID | — |
__binLength | — |
binary | — |
Event ID 5211 —
Fields
| Name | Description |
|---|---|
RunningMode | — |
ConfigurationReader | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-WAS
guid: '{524B5D04-133C-4A62-8362-64E8EDB9CE40}'
event_source_name: WAS
event_id: 5211
version: 0
level: 4
task: 0
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-04T13:11:26.622206+00:00'
event_record_id: 1622
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: System
computer: WIN-TKC15D7KHUR
security:
user_id: ''
event_data:
RunningMode: Classic
ConfigurationReader: ConfigurationSystem
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 5212 —
Fields
| Name | Description |
|---|---|
SiteID | — |
__binLength | — |
binary | — |
Event ID 5213 —
Fields
| Name | Description |
|---|---|
BindingInformation | — |
__binLength | — |
binary | — |
Event ID 5214 —
Fields
| Name | Description |
|---|---|
ConfigErrorDescription | — |
__binLength | — |
binary | — |
Event ID 5215 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5216 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |
Event ID 5217 —
Fields
| Name | Description |
|---|---|
__binLength | — |
binary | — |