Microsoft-Windows-Wcmsvc
67 events across 2 channels
Event ID 1001 — WCMSVC: Service Startup
Description
WCMSVC: Service Startup.
Message #
Event ID 1002 — WCMSVC: Service Shutdown
Description
WCMSVC: Service Shutdown.
Message #
Event ID 1003 — CDE reported a state change.
#Description
CDE reported a state change.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Name UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-11-06T06:25:42.259570+00:00",
"event_record_id": 100,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Status": 1,
"Name": 2
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1004 — A Group Policy change was processed
#Description
A Group Policy change was processed.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:44:38.754171+00:00",
"event_record_id": 124,
"correlation": {},
"execution": {
"process_id": 2484,
"thread_id": 6636
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1005 — A Power change was processed.
Event ID 1006 — A Terminal Services session change was processed.
#Description
A Terminal Services session change was processed.
Message #
Fields #
| Name | Description |
|---|---|
Reason UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-11-05T22:32:23.678433+00:00",
"event_record_id": 123,
"correlation": {},
"execution": {
"process_id": 2484,
"thread_id": 2872
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"Reason": 5
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1007 — CDE reported a state change.
Description
CDE reported a state change.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | — NTSTATUS reference |
Event ID 1008 — NLA interface property change.
Event ID 1009 — CDE reported an L2 adapter arrival.
#Description
CDE reported an L2 adapter arrival.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
MediaType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-11-06T06:25:42.356663+00:00",
"event_record_id": 103,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D",
"MediaType": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1010 — CDE reported an L2 adapter removal.
Description
CDE reported an L2 adapter removal.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
MediaType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255303+00:00",
"event_record_id": 170,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1011 — CDE reported a successful connection.
Event ID 1012 — CDE reported a connection failure.
Description
CDE reported a connection failure.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
MediaType UInt32 | — |
Status UInt32 | — NTSTATUS reference |
Event ID 1013 — CDE reported a disconnection.
Event ID 1014 — WcmSetParameter Called.
Event ID 1015 — Interface Token Applied.
Event ID 1016 — Interface Token Failed.
Event ID 1017 — Soft disconnect over thresholds for interface: InterfaceGUID.
Event ID 1018 — Soft disconnect under thresholds for interface: InterfaceGUID.
Event ID 1019 — CDE reported an unblocked profile.
Event ID 1020 — WCM Preferred Order List.
#Description
WCM Preferred Order List.
Message #
Fields #
| Name | Description |
|---|---|
WCM Preferred Order List UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1020,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2023-10-26T04:17:43.215170+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 2288,
"thread_id": 2612
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WIN-OQ6R0RVA4NF",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"WCM Preferred Order List": "0: {3D03B11E-98A0-4304-84E2-CD3AAE8EFE1D}, Ethernet, 1\n1: {8E4162AD-6500-4899-BA95-24051405E207}, Ethernet, 1\n"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1022 — WCM entered connected standby
Description
WCM entered connected standby.
Message #
Event ID 1023 — WCM exited connected standby
Description
WCM exited connected standby.
Message #
Event ID 1024 — Acquired NDIS NIC Active Reference for interface: InterfaceGUID.
Event ID 1025 — Released NDIS NIC Active Reference for interface: InterfaceGUID.
Event ID 1026 — CDE reported an NDIS adapter arrival.
#Description
CDE reported an NDIS adapter arrival.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
MediaType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1026,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2022-04-07T16:53:13.091504+00:00",
"event_record_id": 39,
"correlation": {},
"execution": {
"process_id": 1488,
"thread_id": 1596
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WIN-FPV0DSIC9O6.lab.local",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "00C20B5F-2254-4D8F-9391-4EED3B6F783D",
"MediaType": 1
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 1027 — CDE reported an NDIS adapter removal.
Description
CDE reported an NDIS adapter removal.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
MediaType UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 1027,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775840,
"time_created": "2026-03-13T20:18:51.255300+00:00",
"event_record_id": 169,
"correlation": {},
"execution": {
"process_id": 2572,
"thread_id": 2756
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {
"InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
"MediaType": 1
},
"message": ""
}
Event ID 1028 — WCM entered net quiet mode
Description
WCM entered net quiet mode.
Message #
Event ID 1029 — WCM exited net quiet mode
Description
WCM exited net quiet mode.
Message #
Event ID 1030 — Billing Cycle Reset Successful
Event ID 1031 — Server Time Retrieval Failure
Event ID 1032 — Acquire NDIS NIC Active Reference Failed for interface: InterfaceGUID.
Event ID 1033 — Release NDIS NIC Active Reference Failed for interface: InterfaceGUID.
Event ID 1034 — OnDemandInterfaceStateChanged.
Description
OnDemandInterfaceStateChanged. OnDemandType:OnDemandType, Interface: InterfaceGUID, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, NewState:NewState, Ref counter:Refcount.
Message #
Fields #
| Name | Description |
|---|---|
OnDemandType UInt32 | — |
InterfaceGUID GUID | — |
OnDemandInfo UnicodeString | — |
ProviderID UnicodeString | — |
NewState UInt32 | — |
Refcount UInt32 | — |
Event ID 1035 — OnDemand PDP Profile Created.
Event ID 1036 — OnDemand PDP Profile Deleted.
Event ID 1037 — OnDemand Request opened.
Description
OnDemand Request opened. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | — |
ProcessID UInt32 | — |
OnDemandType UInt32 | — |
OnDemandInfo UnicodeString | — |
ProviderID UnicodeString | — |
Error UInt32 | — |
Event ID 1038 — OnDemand Request closed.
Description
OnDemand Request closed. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | — |
ProcessID UInt32 | — |
OnDemandType UInt32 | — |
OnDemandInfo UnicodeString | — |
ProviderID UnicodeString | — |
Error UInt32 | — |
Event ID 1039 — OnDemand Request started.
Description
OnDemand Request started. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | — |
ProcessID UInt32 | — |
OnDemandType UInt32 | — |
OnDemandInfo UnicodeString | — |
ProviderID UnicodeString | — |
Error UInt32 | — |
Event ID 1040 — OnDemand Request cancelled.
Description
OnDemand Request cancelled. App ID:AppID, ProcessID:ProcessID,OnDemandType:OnDemandType, OnDemandInfo:OnDemandInfo, ProviderID:ProviderID, Error: Error.
Message #
Fields #
| Name | Description |
|---|---|
AppID UnicodeString | — |
ProcessID UInt32 | — |
OnDemandType UInt32 | — |
OnDemandInfo UnicodeString | — |
ProviderID UnicodeString | — |
Error UInt32 | — |
Event ID 1050 — WcmSvc acquired the NIC reference for Interface: InterfaceGUID for reason: ActionType.
Event ID 1051 — WcmSvc released the NIC reference for Interface: InterfaceGUID for reason: ActionType.
Event ID 1052 — WcmSvc signalled disconnected standby
Description
WcmSvc signalled disconnected standby.
Message #
Event ID 1053 — WcmSvc signalled end of disconnected standby
Description
WcmSvc signalled end of disconnected standby.
Message #
Event ID 1054 — WcmSvc received power policy update for networking in standby - the new policy value is PolicyValue.
Event ID 4020 — End of Wwan Resume Reconnect
Event ID 4021 — End of Wlan Resume Reconnect to Same Network
Event ID 4022 — End of Wlan Resume Reconnect to Same Network OneX
Event ID 4023 — End of Wlan Resume Reconnect to Different Network
Event ID 4024 — End of Wlan Resume Reconnect to Different Network OneX
Event ID 4025 — Cancel of Wlan Resume Reconnect2
Event ID 4026 —
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | — |
Event ID 4027 — WcmSvc CmPdcActivationClientRegister - Status [Status].
Description
WcmSvc CmPdcActivationClientRegister - Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
Event ID 4028 — WcmSvc CmPdcActivationClientUnregister - Status [Status].
Description
WcmSvc CmPdcActivationClientUnregister - Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Status HexInt32 | — NTSTATUS reference |
Event ID 4029 — WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].
Description
WcmSvc CmPdcActivationClientActivityRequest - Activate [Activity], Status [Status].
Message #
Fields #
| Name | Description |
|---|---|
Activity Boolean | — |
Status HexInt32 | — NTSTATUS reference |
Event ID 4030 — WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppNa...
Description
WcmSvc SetNetworkReference - Activate [Activate], Result [Result], TotalNetworkRefCount [TotalNetworkRefCount], ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Activate Boolean | — |
Result UInt32 | — |
TotalNetworkRefCount UInt32 | — |
ProcessId UInt32 | — |
ProcessNetworkRefCount UInt32 | — |
AppName UnicodeString | — |
Event ID 4031 — WcmSvc ReleaseNetworkReferenceInProcess - ProcessId [ProcessId], PerProcessNetworkRefCount [ProcessNetworkRefCount], TotalNetworkRefCount [TotalNetworkRefCount].
Event ID 4032 — WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Description
WcmSvc AcquireNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Result UInt32 | — |
TotalCmNdisRefCount UInt32 | — |
ProcessId UInt32 | — |
PerProcessCmNdisRefCount UInt32 | — |
AppName UnicodeString | — |
Event ID 4033 — WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Description
WcmSvc ReleaseNdisReference - Result [Result], TotalCmNdisRefCount [TotalCmNdisRefCount], ProcessId [ProcessId], PerProcessCmNdisRefCount [PerProcessCmNdisRefCount], App [AppName].
Message #
Fields #
| Name | Description |
|---|---|
Result UInt32 | — |
TotalCmNdisRefCount UInt32 | — |
ProcessId UInt32 | — |
PerProcessCmNdisRefCount UInt32 | — |
AppName UnicodeString | — |
Event ID 4034 — WcmSvc ReleaseNdisReferenceInProcess - ProcessId [ProcessId], PerProcessCmNdisRefCount [ProcessNetworkRefCount], TotalCmNdisRefCount [TotalNetworkRefCount].
Event ID 4035 — WcmSvc NdisReferenceError - [FunctionName]: Result [Error].
Event ID 4036 — CmService::NdisReference - [AcquireRelease] InterfaceLuid [InterfaceLuid], Result [Result].
Event ID 10001 — WCMSVC: Start WCM Service Startup
#Description
WCMSVC: Start WCM Service Startup.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 10001,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:41.759091+00:00",
"event_record_id": 98,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 2940
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10002 — WCMSVC: Complete WCM Service Startup
#Description
WCMSVC: Complete WCM Service Startup.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 10002,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:42.274933+00:00",
"event_record_id": 102,
"correlation": {},
"execution": {
"process_id": 2540,
"thread_id": 2940
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10003 — WCMSVC: Start Service Shutdown
#Description
WCMSVC: Start Service Shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 10003,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:31:36.633156+00:00",
"event_record_id": 115,
"correlation": {},
"execution": {
"process_id": 2584,
"thread_id": 5648
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10004 — WCMSVC: Complete Service Shutdown
#Description
WCMSVC: Complete Service Shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Wcmsvc",
"guid": "67D07935-283A-4791-8F8D-FA9117F3E6F2",
"event_source_name": "",
"event_id": 10004,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-05T22:31:37.882676+00:00",
"event_record_id": 116,
"correlation": {},
"execution": {
"process_id": 2584,
"thread_id": 5648
},
"channel": "Microsoft-Windows-Wcmsvc/Operational",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-19"
}
},
"event_data": {},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 10005 — Tethering Manager Loaded Successfully
Description
Tethering Manager Loaded Successfully.
Message #
Event ID 10006 — Tethering Manager Unloaded Successfully
Description
Tethering Manager Unloaded Successfully.