Microsoft-Windows-Wcmsvc
67 events across 2 channels
Event ID 1001 — WCMSVC: Service Startup
Message
Event ID 1002 — WCMSVC: Service Shutdown
Message
Event ID 1003 — CDE reported a state change State: %1 Name: %2.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Name | — |
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1003
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775840
time_created: '2023-11-06T06:25:42.259570+00:00'
event_record_id: 100
correlation: {}
execution:
process_id: 2540
thread_id: 3204
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
Status: 1
Name: 2
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1004 — A Group Policy change was processed
Message
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1004
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:44:38.754171+00:00'
event_record_id: 124
correlation: {}
execution:
process_id: 2484
thread_id: 6636
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1005 — A Power change was processed.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Event ID 1006 — A Terminal Services session change was processed.
Message
Fields
| Name | Description |
|---|---|
Reason | — |
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1006
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775840
time_created: '2023-11-05T22:32:23.678433+00:00'
event_record_id: 123
correlation: {}
execution:
process_id: 2484
thread_id: 2872
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
Reason: 5
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1007 — CDE reported a state change State: %1 Name: Nlasvc.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 1008 — NLA interface property change Interface: %1 Internet v4: %2 Internet v6: %3 Probe Complete v4: %4 Probe Complete v6: %5 Domain Authenticated: %6 Do...
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
InternetConnectivityv4 | — |
InternetConnectivityv6 | — |
InternetProbeCompletev4 | — |
InternetProbeCompletev6 | — |
DomainConnectivity | — |
DomainProbeComplete | — |
Event ID 1009 — CDE reported an L2 adapter arrival Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1009
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775840
time_created: '2023-11-06T06:25:42.356663+00:00'
event_record_id: 103
correlation: {}
execution:
process_id: 2540
thread_id: 3204
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data:
InterfaceGuid: 3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D
MediaType: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1010 — CDE reported an L2 adapter removal Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Event ID 1011 — CDE reported a successful connection Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Event ID 1012 — CDE reported a connection failure Interface: %1 Type: %2 Status: %3.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Status | — |
Event ID 1013 — CDE reported a disconnection Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Event ID 1014 — WcmSetParameter Called Interface: %1 Profile Name: %2 Wcm Opcode: %3 Data Length: %4 Caller Process ID: %5 Return Value: %6.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
ProfileName | — |
WcmOpcode | — |
Datalength | — |
CallerProcessID | — |
ReturnValue | — |
Event ID 1015 — Interface Token Applied Interface: %1 Media Type: %2 Manual enabled: %3 Manual Filter: %4 Num Manual: %5 Manual Profiles: %6 Auto enabled: %7 Auto ...
Message
Fields
| Name | Description |
|---|---|
Interface GUID | — |
Mediatype | — |
manualConnectEnabled | — |
autoConnectEnabled | — |
Event ID 1016 — Interface Token Failed Interface: %1 Media Type: %2 Manual enabled: %3 Manual Filter: %4 Num Manual: %5 Manual Profiles: %6 Auto enabled: %7 Auto f...
Message
Fields
| Name | Description |
|---|---|
Interface GUID | — |
Mediatype | — |
manualConnectEnabled | — |
autoConnectEnabled | — |
Error | — |
Event ID 1017 — Soft disconnect over thresholds for interface: %1 AvgIn: %2 AvgOut: %3 SpikeIn: %4 SpikeOut: %5 Thresholds: AvgIn: %6 AvgOut: %7 SpikeIn: %8 SpikeO...
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
AvgIn | — |
AvgOut | — |
SpikeIn | — |
SpikeOut | — |
ThresholdAvgIn | — |
ThresholdAvgOut | — |
ThresholdSpikeIn | — |
ThresholdSpikeOut | — |
Event ID 1018 — Soft disconnect under thresholds for interface: %1 AvgIn: %2 AvgOut: %3 SpikeIn: %4 SpikeOut: %5 Thresholds: AvgIn: %6 AvgOut: %7 SpikeIn: %8 Spike...
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
AvgIn | — |
AvgOut | — |
SpikeIn | — |
SpikeOut | — |
ThresholdAvgIn | — |
ThresholdAvgOut | — |
ThresholdSpikeIn | — |
ThresholdSpikeOut | — |
Event ID 1019 — CDE reported an unblocked profile Interface: %1 Type: %2 Profile: %3.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
ProfileName | — |
Event ID 1020 — WCM Preferred Order List.
Message
Fields
| Name | Description |
|---|---|
WCM Preferred Order List | — |
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1020
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775840
time_created: '2023-10-26T04:17:43.215170+00:00'
event_record_id: 9
correlation: {}
execution:
process_id: 2288
thread_id: 2612
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WIN-OQ6R0RVA4NF
security:
user_id: S-1-5-19
event_data:
WCM Preferred Order List: '0: {3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}, Ethernet,
1
1: {8E4162AD-6500-4899-BA95-24051405E207}, Ethernet, 1
'
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1022 — WCM entered connected standby
Message
Event ID 1023 — WCM exited connected standby
Message
Event ID 1024 — Acquired NDIS NIC Active Reference for interface.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
Event ID 1025 — Released NDIS NIC Active Reference for interface.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
Event ID 1026 — CDE reported an NDIS adapter arrival Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 1026
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775840
time_created: '2022-04-07T16:53:13.091504+00:00'
event_record_id: 39
correlation: {}
execution:
process_id: 1488
thread_id: 1596
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WIN-FPV0DSIC9O6.sigma.fr
security:
user_id: S-1-5-19
event_data:
InterfaceGuid: 00C20B5F-2254-4D8F-9391-4EED3B6F783D
MediaType: 1
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1027 — CDE reported an NDIS adapter removal Interface: %1 Type: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
MediaType | — |
Event ID 1028 — WCM entered net quiet mode
Message
Event ID 1029 — WCM exited net quiet mode
Message
Event ID 1030 — Billing Cycle Reset Successful
Message
Fields
| Name | Description |
|---|---|
ProfileName | — |
InterfaceGuid | — |
ProfileUpdatedorDeleted | — |
Event ID 1031 — Server Time Retrieval Failure
Message
Fields
| Name | Description |
|---|---|
ConfigtoSyncWithTimeServer | — |
TimeServerName | — |
NumServerTimeRetries | — |
ServerTimeRetrievalError | — |
Event ID 1032 — Acquire NDIS NIC Active Reference Failed for interface.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
NdisRefError | — |
Event ID 1033 — Release NDIS NIC Active Reference Failed for interface.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
NdisRefError | — |
Event ID 1034 — OnDemandInterfaceStateChanged.
Message
Fields
| Name | Description |
|---|---|
OnDemandType | — |
InterfaceGUID | — |
OnDemandInfo | — |
ProviderID | — |
NewState | — |
Refcount | — |
Event ID 1035 — OnDemand PDP Profile Created.
Message
Fields
| Name | Description |
|---|---|
APNname | — |
ProviderID | — |
SubscriberID | — |
Profilename | — |
Event ID 1036 — OnDemand PDP Profile Deleted.
Message
Fields
| Name | Description |
|---|---|
Profilename | — |
Event ID 1037 — OnDemand Request opened.
Message
Fields
| Name | Description |
|---|---|
AppID | — |
ProcessID | — |
OnDemandType | — |
OnDemandInfo | — |
ProviderID | — |
Error | — |
Event ID 1038 — OnDemand Request closed.
Message
Fields
| Name | Description |
|---|---|
AppID | — |
ProcessID | — |
OnDemandType | — |
OnDemandInfo | — |
ProviderID | — |
Error | — |
Event ID 1039 — OnDemand Request started.
Message
Fields
| Name | Description |
|---|---|
AppID | — |
ProcessID | — |
OnDemandType | — |
OnDemandInfo | — |
ProviderID | — |
Error | — |
Event ID 1040 — OnDemand Request cancelled.
Message
Fields
| Name | Description |
|---|---|
AppID | — |
ProcessID | — |
OnDemandType | — |
OnDemandInfo | — |
ProviderID | — |
Error | — |
Event ID 1050 — WcmSvc acquired the NIC reference for Interface: %1 for reason: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
ActionType | — |
Event ID 1051 — WcmSvc released the NIC reference for Interface: %1 for reason: %2.
Message
Fields
| Name | Description |
|---|---|
InterfaceGUID | — |
ActionType | — |
Event ID 1052 — WcmSvc signalled disconnected standby
Message
Event ID 1053 — WcmSvc signalled end of disconnected standby
Message
Event ID 1054 — WcmSvc received power policy update for networking in standby - the new policy value is %1.
Message
Fields
| Name | Description |
|---|---|
PolicyValue | — |
Event ID 4020 — End of Wwan Resume Reconnect
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4021 — End of Wlan Resume Reconnect to Same Network
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4022 — End of Wlan Resume Reconnect to Same Network OneX
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4023 — End of Wlan Resume Reconnect to Different Network
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4024 — End of Wlan Resume Reconnect to Different Network OneX
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4025 — Cancel of Wlan Resume Reconnect2
Message
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4026 —
Fields
| Name | Description |
|---|---|
InterfaceGuid | — |
Event ID 4027 — WcmSvc CmPdcActivationClientRegister - Status [.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 4028 — WcmSvc CmPdcActivationClientUnregister - Status [.
Message
Fields
| Name | Description |
|---|---|
Status | — |
Event ID 4029 — WcmSvc CmPdcActivationClientActivityRequest - Activate [.
Message
Fields
| Name | Description |
|---|---|
Activity | — |
Status | — |
Event ID 4030 — WcmSvc SetNetworkReference - Activate [.
Message
Fields
| Name | Description |
|---|---|
Activate | — |
Result | — |
TotalNetworkRefCount | — |
ProcessId | — |
ProcessNetworkRefCount | — |
AppName | — |
Event ID 4031 — WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [.
Message
Fields
| Name | Description |
|---|---|
ProcessId | — |
ProcessNetworkRefCount | — |
TotalNetworkRefCount | — |
Event ID 4032 — WcmSvc AcquireNdisReference - Result [.
Message
Fields
| Name | Description |
|---|---|
Result | — |
TotalCmNdisRefCount | — |
ProcessId | — |
PerProcessCmNdisRefCount | — |
AppName | — |
Event ID 4033 — WcmSvc ReleaseNdisReference - Result [.
Message
Fields
| Name | Description |
|---|---|
Result | — |
TotalCmNdisRefCount | — |
ProcessId | — |
PerProcessCmNdisRefCount | — |
AppName | — |
Event ID 4034 — WcmSvc ReleaseNdisReferenceInProcess - ProcessId [.
Message
Fields
| Name | Description |
|---|---|
ProcessId | — |
ProcessNetworkRefCount | — |
TotalNetworkRefCount | — |
Event ID 4035 — WcmSvc NdisReferenceError - [.
Message
Fields
| Name | Description |
|---|---|
FunctionName | — |
Error | — |
Event ID 4036 — CmService::NdisReference - [.
Message
Fields
| Name | Description |
|---|---|
AcquireRelease | — |
InterfaceLuid | — |
Result | — |
Event ID 10001 — WCMSVC: Start WCM Service Startup
Message
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 10001
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:41.759091+00:00'
event_record_id: 98
correlation: {}
execution:
process_id: 2540
thread_id: 2940
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10002 — WCMSVC: Complete WCM Service Startup
Message
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 10002
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:42.274933+00:00'
event_record_id: 102
correlation: {}
execution:
process_id: 2540
thread_id: 2940
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10003 — WCMSVC: Start Service Shutdown
Message
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 10003
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:31:36.633156+00:00'
event_record_id: 115
correlation: {}
execution:
process_id: 2584
thread_id: 5648
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10004 — WCMSVC: Complete Service Shutdown
Message
Example Event
system:
provider: Microsoft-Windows-Wcmsvc
guid: 67D07935-283A-4791-8F8D-FA9117F3E6F2
event_source_name: ''
event_id: 10004
version: 0
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-05T22:31:37.882676+00:00'
event_record_id: 116
correlation: {}
execution:
process_id: 2584
thread_id: 5648
channel: Microsoft-Windows-Wcmsvc/Operational
computer: WinDev2310Eval
security:
user_id: S-1-5-19
event_data: {}
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline