Microsoft-Windows-WinRM

326 events across 4 channels

Event IDTitleChannel
2Initializing WSMan APIOperational
3Initialization of WSMan API failed, error code errorCode.Operational
4Deinitializing WSMan APIOperational
5Deinitialization of WSMan API failed, error code errorCode.Operational
6Creating WSMan Session.Operational
7WSMan Create Session operation failed, error code errorCode.Operational
8Closing WSMan SessionOperational
9Closing WSMan Session failed, error code errorCode.Operational
10Setting WSMan Session Option (optionCode) - optionName with value (optionValue) …Operational
11Creating WSMan shell with the ResourceUri: resourceUri and ShellId: shellId.Operational
12WSMan shell creation failed, error code errorCode.Operational
13Running WSMan command with CommandId: commandId.Operational
14Running WSMan command failed, error code errorCode.Operational
15Closing WSMan commandOperational
16Closing WSMan shellOperational
17Signaling WSMan shellOperational
18Signaling WSMan shell; error code {errorCode}.Operational
19Closing WSMan operationOperational
20Sending input to the shellOperational
21Sending input operation failed; error code {errorCode}.Operational
22Calling into WSMan to receive output from the shellOperational
23WSMan receive operation failed; error code {errorCode}.Operational
24Calling into WSMan to receive output from the commandOperational
26Getting message for error code {inputErrorCode} completed successfully.Operational
27Getting WSMan Session Option ({optionCode}).Operational
28Access Denied error: the apiCall API caller does not match the creator of the …Operational
29Initialization of WSMan API completed successfulyOperational
30Deinitialization of WSMan API completed successfulyOperational
31WSMan Create Session operation completed successfulyOperational
32Setting WSMan Session Option (optionCode) - optionName failed, error code …Operational
33Closing WSMan Session completed successfulyOperational
34Getting message for error code {inputErrorCode} failed; the resulting error code …Operational
35Signaling WSMan command failed; error code {errorCode}.Operational
36Signaling WSMan commandOperational
37Closing WSMan shell failed, error code errorCode.Operational
38Closing WSMan command failed, error code errorCode.Operational
39Closing WSMan {operationName} operation completed successfully.Operational
40Closing WSMan operationName operation failed, error code errorCode.Operational
41The WinRM protocol handler has began loading for application applicationID.Operational
42The WinRM protocol handler completed unloading.Operational
43The WinRM protocol handler unloaded prematurely due to the following error: …Operational
44The WinRM protocol handler started to create a session at the following …Operational
45The WinRM protocol handler closed the session.Operational
46The WinRM protocol session closed prematurely due to the following error: …Operational
47The WinRM protocol session began an operation of type operationType to the …Operational
48The WinRM protocol session successfully completed the operation.Operational
49The WinRM protocol operation failed due to the following error: errorMessage.Operational
64Auto-detecting proxy settingsOperational
65Proxy AutoDetect done.Operational
66Setting proxy info Proxy list: {proxyList} Bypass list: {bypassList}.Operational
80Sending the request for operation {operationName} to destination machine and …Operational
81Processing client request for operation {operationName}.Operational
82Entering the plugin for operation {operation} with a ResourceURI of …Operational
83Leaving the plugin for operation {operation}.Operational
84The maximum number of users (users) executing shell operations has been …Operational
85The senderName user is allowed a maximum number of concurrentShells concurrent …Operational
86The WSMan service could not launch a host process to process the given request.Operational
87The WSMan host process was unexpectedly terminated.Operational
90RunAs was disabled by Group Policy; WSMan service has erased all RunAs …Operational
91Creating WSMan shell on server with ResourceUri: resourceUri.Operational
129Received the response from Network layer; status: {status}.Operational
130Received the response from Network layer; status: {status}.Operational
131Received redirect status code from Network layer; status: 302 …Operational
132WSMan operation operationName completed successfully.Operational
133Sending response error packet for ActionURI: {actionUri}.Operational
134Sending response for operation {operationName}.Operational
135Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next …Operational
136Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using …Operational
137Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot …Operational
138The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)Operational
139The client got a login failure from the network layer …Operational
140Sending HTTP error back to the client due to a transport failure.Operational
141Sending timeout response for operation: {operationName}.Operational
142WSMan operation operationName failed, error code errorCode.Operational
143Received the response from Network layer; status: 200 (HTTP_STATUS_OK)Operational
145WSMan operation operationName started with resourceUri resourceUri.Operational
160Authenticating the user using {authentication} mechanism.Operational
161authFailureMessage.Operational
162Authenticating the user failed.Operational
163The authentication mechanism (authClient) requested by the client is not …Operational
164The destination computer (destinationMachine) returned an 'access denied' error.Operational
165The authentication mechanism requested by the proxy is not supported by the …Operational
166The chosen authentication mechanism is {auth}.Operational
168Sending HTTP 401 response to the client and disconnect the connection after …Operational
169Operational
170The authentication using client certificate with subject {subject} done …Operational
171Authenticating the user with the proxy failed.Operational
172The server certificate on the destination computer (machineName:port) has the …Operational
173The WinRM service has terminated param1 unauthenticated connections over the …Operational
192The authorization of the user failed with error errorCode.Operational
193Request for user param1 (param2) will be executed using WinRM virtual account …Operational
194The authorization of the user failed with error {errorCode}.Operational
208The Winrm service is startingOperational
209The Winrm service started successfullyOperational
210The WinRM service is unable to start because of a failure during initialization.Operational
211The Winrm service is stoppingOperational
212The Winrm service was stopped successfullyOperational
213The WSMan service could not load current configuration settings as the settings …Operational
214The WSMan client could not load current configuration settings as the settings …Operational
215The WSMan service failed to read configuration of the following plugin.Operational
216The WSMan service failed to restart the plugins marked for AutoRestart.Operational
217The WSMan service failed to restart the pluginName plugin on service startup.Operational
218The WSMan service successfully restarted the following plugin on service …Operational
219The WSMan shell instance param1 will no longer support disconnect reconnect …Operational
224message.Operational
229The WinRM param1 failed to register for group policy change notifications.Operational
230Deletion of registry key param1 resulted in access denied.Operational
254Activity TransferOperational
255Activity TransferAnalytic
257Initializing WSMan APIAnalytic
258Initialization of WSMan API failed; error code {errorCode}.Analytic
259Deinitializing WSMan APIAnalytic
260Deinitialization of WSMan API failed; error code {errorCode}.Analytic
261Creating WSMan Session.Analytic
262WSMan Create Session operation failed; error code {errorCode}.Analytic
263Closing WSMan SessionAnalytic
264Closing WSMan Session failed; error code {errorCode}.Analytic
265Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed …Analytic
266Creating WSMan shell with the ResourceUri: {resourceUri}.Analytic
267WSMan shell creation failed; error code {errorCode}.Analytic
268Running WSMan commandAnalytic
269Running WSMan command failed; error code {errorCode}.Analytic
270Closing WSMan commandAnalytic
271Closing WSMan shellAnalytic
272Signaling WSMan shellAnalytic
273Signaling WSMan shell; error code {errorCode}.Analytic
274Closing WSMan operationAnalytic
275Sending input to the shellAnalytic
276Sending input operation failed; error code {errorCode}.Analytic
277Calling into WSMan to receive output from the shellAnalytic
278WSMan receive operation failed; error code {errorCode}.Analytic
279Calling into WSMan to receive output from the commandAnalytic
280Getting message for error code {inputErrorCode} completed successfully.Analytic
281Getting WSMan Session Option ({optionCode}).Analytic
282Access Denied error: the {apiCall} API caller does not match the creator of the …Analytic
283Plug-in reporting context for operation operationName.Analytic
284Plug-in reporting data object for operation operationName.Analytic
285Plug-in reporting data object and EPR for operation operationName.Analytic
286Plug-in reporting data object and bookmark for operation operationName.Analytic
287Plug-in reporting data for operation ReceiveAnalytic
288Plug-in reporting operation complete for operationName.Analytic
289Plug-in getting operational information for parameter parameters and operation …Analytic
290Plug-in reporting the authorization for user username completed with error code …Analytic
291Plug-in reporting the authorization operation completed with error errorCode for …Analytic
292Updating the quota for the user username with error code errorCode.Analytic
293Initialization of WSMan API completed successfulyAnalytic
294Deinitialization of WSMan API completed successfulyAnalytic
295WSMan Create Session operation completed successfulyAnalytic
296Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}.Analytic
297Closing WSMan Session completed successfulyAnalytic
298Getting message for error code {inputErrorCode} failed; the resulting error code …Analytic
299Signaling WSMan command failed; error code {errorCode}.Analytic
300Signaling WSMan commandAnalytic
301Closing WSMan shell failed; error code {errorCode}.Analytic
302Closing WSMan command failed; error code {errorCode}.Analytic
303Closing WSMan {operationName} operation completed successfully.Analytic
304Closing WSMan {operationName} operation failed; error code {errorCode}.Analytic
305Sending input to the commandAnalytic
306The WinRM service loaded the following plugin: provider (path).Analytic
307The WinRM service unloaded the following plugin: provider (path).Analytic
308The plugin called WSManPluginGetConfiguration with the parameter Flags and …Analytic
309The plugin called WSManPluginReportCompletion with the parameter Flags and …Analytic
310The plugin Plugin is being shut down because it was idle for longer than the …Analytic
311Signaling WSMan command failed, error code errorCode.Analytic
312Signaling WSMan commandAnalytic
313Sending input to the commandAnalytic
314Sending input to the shellAnalytic
315Sending input operation failed, error code errorCode.Analytic
316Calling into WSMan to receive output from the shellAnalytic
317WSMan receive operation failed, error code errorCode.Analytic
318Calling into WSMan to receive output from the commandAnalytic
319Getting message for error code inputErrorCode completed successfully.Analytic
320Getting WSMan Session Option (optionCode) - optionName.Analytic
321Signaling WSMan shellAnalytic
322Signaling WSMan shell, error code errorCode.Analytic
323Closing WSMan operationAnalytic
324Closing WSMan operationName operation completed successfully.Analytic
325Disconnecting shell with Id : argument.Analytic
326Disconnecting shell failed, error code errorCode.Analytic
327Reconnecting shell with Id : argument.Analytic
328Reconnecting shell failed, error code errorCode.Analytic
329Connecting shell with Id : argument.Analytic
330Connecting shell failed, error code errorCode.Analytic
331Reconnecting shell command with Id : argument.Analytic
332Reconnecting shell command failed, error code errorCode.Analytic
333Connecting shell command with Id : argument.Analytic
334Connecting shell command failed, error code errorCode.Analytic
512Auto-detecting proxy settingsAnalytic
513Proxy AutoDetect done.Analytic
514Setting proxy info.Analytic
768Processing client request for operation {operationName}.Analytic
769Entering the plugin for operation {operation} with a ResourceURI of …Analytic
770Leaving the plugin for operation {operation}.Analytic
771SOAP [client sending index index of totalChunks total chunks (bytes bytes)] …Analytic
772SOAP [listener receiving index index of totalChunks total chunks (bytes bytes)] …Analytic
773The {senderName} user is allowed a maximum number of {concurrentShells} …Analytic
774The senderName user is allowed a maximum number of concurrentOperations …Analytic
775The user load quota of requests requests per windowTime seconds has been …Analytic
776The system load quota of requests requests per windowTime seconds has been …Analytic
777The maximum number of users ({users}) executing shell operations has been …Analytic
778Sending the request for operation {operationName} to destination machine and …Analytic
779SOAP [client sending index index of totalChunks total chunks (bytes bytes)] …Analytic
780The WinRM param1 has encountered network connectivity issues.Analytic
781The WinRM Client is attempting to re-establish a network connection.Analytic
782The WinRM Service has detected a new network connection from the client.Analytic
783The WinRM param1 has successfully re-established a network connection.Analytic
784The WinRM param1 failed to re-establish a network connection and is reporting a …Analytic
785The WSMan host process was started for user userName.Analytic
786The WSMan host process was terminated for user userName.Analytic
787Sending the request for operation operationName to destination machine and port …Analytic
788Processing client request for operation operationName.Analytic
789Entering the plugin for operation operation with a ResourceURI of <resourceURI>.Analytic
790Leaving the plugin for operation operation.Analytic
791The WinRM service failed to enumerate DASH/SMASH specifications with MI error: …Analytic
1024Sending response for operation {operationName}.Analytic
1025Sending response error packet for ActionURI: actionUri.Analytic
1026SOAP [client receiving index index of totalChunks total chunks (bytes bytes)] …Analytic
1027SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] …Analytic
1028Received the response from Network layer; status: {status}.Analytic
1029Received the response from Network layer; status: {status}.Analytic
1030Received redirect status code from Network layer; status: 302 …Analytic
1031WSMan operation {operationName} completed successfully.Analytic
1032Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next …Analytic
1033Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using …Analytic
1034Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot …Analytic
1035The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)Analytic
1036The client got a login failure from the network layer …Analytic
1037The WSMan service could not launch a host process to process the given request.Analytic
1038The WSMan host process was unexpectedly terminated.Analytic
1039Sending HTTP error back to the client due to a transport failure.Analytic
1040Sending timeout response for operation: {operationName}.Analytic
1041Enumeration is shutting downAnalytic
1042WSMan operation {operationName} failed; error code {errorCode}.Analytic
1043Subscription is shutting downAnalytic
1044SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] …Analytic
1045Received the response from Network layer; status: 200 (HTTP_STATUS_OK)Analytic
1046An extended semantics callback timed out for the operationName operation.Analytic
1047Received the response from Network layer; status: status.Analytic
1048Sending HTTP error back to the client due to a transport failure.Analytic
1049Sending timeout response for operation: operationName.Analytic
1050Sending response for operation operationName.Analytic
1051Received the response from Network layer; status: status.Analytic
1052WSMan operation operationName completed successfully.Analytic
1053WSMan operation operationName got suspended because of WSMan Shell …Analytic
1054WSMan operation operationName resuming because of WSMan Shell reconnection.Analytic
1280Sending HTTP 401 response to the client and disconnect the connection after …Analytic
1281User {username} authenticated successfully using {authenticationMechanism} …Analytic
1282The authentication using client certificate with subject {subject} done …Analytic
1283Authenticating the user using {authentication} mechanism.Analytic
1285Authenticating the user failed.Analytic
1286The authentication mechanism ({authClient}) requested by the client is not …Analytic
1287The destination computer ({destinationMachine}) returned an 'access denied' …Analytic
1288The authentication mechanism requested by the proxy is not supported by the …Analytic
1289The chosen authentication mechanism is {auth}.Analytic
1291Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response …Analytic
1292Network layer AutoLogon policy was set to HighAnalytic
1293The chosen authentication mechanism is auth.Analytic
1294Sending HTTP 401 response to the client and disconnect the connection after …Analytic
1295User username authenticated successfully using authenticationMechanism …Analytic
1296The authentication using client certificate with subject subject done …Analytic
1297Authenticating the user using authentication mechanism.Analytic
1536Authorizing the userAnalytic
1537The authorization of the user was done successfullyAnalytic
1538The authorization of the user failed with error {errorCode}.Analytic
1792The Winrm service is startingAnalytic
1793The Winrm service started successfullyAnalytic
1794The WinRM service is unable to start because of a failure during initialization.Analytic
1795The Winrm service is stoppingAnalytic
1796The Winrm service was stopped successfullyAnalytic
1797The WSMan service could not load current configuration settings as the settings …Analytic
1798The WSMan client could not load current configuration settings as the settings …Analytic
1799The WSMan service failed to read configuration of the following plugin: …Analytic
1808Analytic
1840An error was encountered while processing an operation.Analytic
1841An error was encountered while processing an operation.Analytic
1842Extra information.Analytic
1843An unauthenticated connection from client clientIP is terminated.Analytic
2048[Filename:- param1; Line:- param2; Function:- param3;] param4.Debug
2049[Filename:- param1; Line:- param2; Function:- param3; ErrorCode:- param4] …Debug
10148System
10149System
10154System
468853The WinRM service is not listening for requests since it failed to listen on at …Operational
468854The WinRM service is not listening for param1 requests because there was a …Operational
468855The WS-Management client is not listening for pushed events because there was a …Operational
468856The WinRM service is not listening for HTTPS requests because there was a …Operational
468857The WS-Management client is not listening for pushed events because there was a …Operational
468862The WinRM service cannot validate the client certificate because the revocation …Operational
468863User authentication using Basic authentication scheme failed.Operational
468864The client certificate exceeded the maximum size allowed by the WinRM service.Operational
468865Request processing failed because the WinRM service cannot load data or event …Operational
468866The SSL configuration for IP param1 and port param2 is shared with another …Operational
468871The WinRM service is unable to start because of a failure during initialization.Operational
468872The WinRM service has received an unsecure HTTP connection from param1.Operational
468873The WinRM service has been configured to accept basic authentication for …Operational
468880The WinRM service is not listening for HTTP requests because there was a failure …Operational
468881The WS-Management client is not listening for pushed events because there was a …Operational
468882IP Filter param1 specified in the GPO policy for Auto Configuration of listeners …Operational
468883The IP Range param1 is invalid and it will be ignored.Operational
468884The WinRM service is not listening for policy changes because there was a …Operational
468888The WinRM service encountered a catastrophic security failure.Operational
468889The WinRM service cannot migrate the listener with IP address param1 and Port …Operational
468890The WinRM service cannot migrate the listener with Address param1 and Transport …Operational
468891The WinRM service cannot migrate the listener with IP address param1 and Port …Operational
468892The WinRM service cannot migrate the listener with Address param1 and Transport …Operational
468893The WinRM service cannot migrate the listener with IP address param1, Port …Operational
468894The WinRM service cannot migrate the listener with Address param1 and Transport …Operational
468895The WinRM service had a failure during migration.Operational
468896The WinRM service had a failure reading the current configuration and is …Operational
468897The WinRM service had a failure applying the current configuration and is …Operational
468898The WinRM service had a failure reading the current configuration and is …Operational
468899The host name pattern "param1" is invalid and it will be ignored.Operational
468900The WinRM service is listening for WS-Management requests.Operational
468901The WinRM service is not listening for WS-Management requests.Operational
468902The WinRM service could not use the following listener to receive WS-Management …Operational
468903The WinRM service had a failure (param1) reading configuration during ip address …Operational
468904The WinRM service successfully processed an address change notification.Operational
468905The WSMan IIS module failed to read configuration.Operational
468906The WinRM service failed to create the following SPNs: spn1; spn2.Operational
468907The WSMan service failed to read configuration of the following plugin.Operational
468908The WinRM service failed to initialize CredSSP.Operational
468909The WinRM service received an error while trying to unloading a data or event …Operational
468910The WinRM service is listening on the default param1 port param2 and on param1 …Operational
468911The WinRM service has terminated param1 unauthenticated connections over the …Operational
3221734403The WinRM service is stopping because there was a failure registering for …Operational
3221734404The WinRM service is stopping because there was a failure registering for …Operational

Event ID 2 — Initializing WSMan API

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIInitialize
Opcode
Start

Description

Initializing WSMan API.

Message #

Initializing WSMan API

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.458003+00:00",
    "event_record_id": 96,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 3 — Initialization of WSMan API failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIInitialize
Opcode
Stop

Description

Initialization of WSMan API failed, error code errorCode.

Message #

Initialization of WSMan API failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 4 — Deinitializing WSMan API

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIDeinitialize
Opcode
Start

Description

Deinitializing WSMan API.

Message #

Deinitializing WSMan API

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.792427+00:00",
    "event_record_id": 379,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5972
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 5 — Deinitialization of WSMan API failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIDeinitialize
Opcode
Stop

Description

Deinitialization of WSMan API failed, error code errorCode.

Message #

Deinitialization of WSMan API failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 6 — Creating WSMan Session.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManSessioninitialize
Opcode
Start

Description

Creating WSMan Session. The connection string is: connection.

Message #

Creating WSMan Session. The connection string is: %1

Fields #

NameDescription
connection UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 6,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.465878+00:00",
    "event_record_id": 98,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "connection": "localhost:47001/WSMan?MSP=7a83d074-bb86-4e52-aa3e-6cc73cc066c8;PSVersion=5.1.20348.617"
  },
  "message": ""
}

References #

Event ID 7 — WSMan Create Session operation failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManSessioninitialize
Opcode
Stop

Description

WSMan Create Session operation failed, error code errorCode.

Message #

WSMan Create Session operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 8 — Closing WSMan Session

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManSessiondeinitialize
Opcode
Start

Description

Closing WSMan Session.

Message #

Closing WSMan Session

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.790604+00:00",
    "event_record_id": 378,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5944
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 9 — Closing WSMan Session failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManSessiondeinitialize
Opcode
Stop

Description

Closing WSMan Session failed, error code errorCode.

Message #

Closing WSMan Session failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 10 — Setting WSMan Session Option (optionCode) - optionName with value (optionValue) completed successfully.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall

Description

Setting WSMan Session Option (optionCode) - optionName with value (optionValue) completed successfully.

Message #

Setting WSMan Session Option (%1) - %2 with value (%3) completed successfully.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString
optionValue UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 0,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.476896+00:00",
    "event_record_id": 106,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "optionCode": 16,
    "optionName": "WSMAN_OPTION_TIMEOUTMS_SIGNAL_SHELL",
    "optionValue": "60000"
  },
  "message": ""
}

References #

Event ID 11 — Creating WSMan shell with the ResourceUri: resourceUri and ShellId: shellId.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Description

Creating WSMan shell with the ResourceUri: resourceUri and ShellId: shellId.

Message #

Creating WSMan shell with the ResourceUri: %1 and ShellId: %2

Fields #

NameDescription
resourceUri UnicodeString
shellId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.628784+00:00",
    "event_record_id": 107,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "resourceUri": "http://schemas.microsoft.com/powershell/Microsoft.Windows.ServerManagerWorkflows",
    "shellId": "1480B89F-E871-42E4-BFB4-C8F88B053137"
  },
  "message": ""
}

References #

Event ID 12 — WSMan shell creation failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
WSManAPIcall
Opcode
Stop

Description

WSMan shell creation failed, error code errorCode.

Message #

WSMan shell creation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 2,
    "task": 5,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T19:30:27.006555+00:00",
    "event_record_id": 14808,
    "correlation": {
      "ActivityID": "FAA0C715-5567-44CF-A321-805CC6FC7AE4"
    },
    "execution": {
      "process_id": 4488,
      "thread_id": 4272
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "errorCode": 2150859195
  },
  "message": ""
}

Event ID 13 — Running WSMan command with CommandId: commandId.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Description

Running WSMan command with CommandId: commandId.

Message #

Running WSMan command with CommandId: %1

Fields #

NameDescription
commandId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:40.298938+00:00",
    "event_record_id": 111,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4100
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "commandId": "69F6EC7D-1A5C-485B-B375-C500E469097C"
  },
  "message": ""
}

References #

Event ID 14 — Running WSMan command failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Description

Running WSMan command failed, error code errorCode.

Message #

Running WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 15 — Closing WSMan command

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Description

Closing WSMan command.

Message #

Closing WSMan command

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 15,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:43.025520+00:00",
    "event_record_id": 112,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 940
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 16 — Closing WSMan shell

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Description

Closing WSMan shell.

Message #

Closing WSMan shell

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 16,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T08:14:07.049150+00:00",
    "event_record_id": 63,
    "correlation": {
      "ActivityID": "DD7B0B6A-4A9E-0001-93A4-7BDD9E4AD801"
    },
    "execution": {
      "process_id": 1460,
      "thread_id": 3116
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 17 — Signaling WSMan shell

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Signaling WSMan shell.

Message #

Signaling WSMan shell

Event ID 18 — Signaling WSMan shell; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Signaling WSMan shell; error code {errorCode}.

Message #

Signaling WSMan shell; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 19 — Closing WSMan operation

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Closing WSMan operation.

Message #

Closing WSMan operation

Event ID 20 — Sending input to the shell

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending input to the shell.

Message #

Sending input to the shell

Event ID 21 — Sending input operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending input operation failed; error code {errorCode}.

Message #

Sending input operation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 22 — Calling into WSMan to receive output from the shell

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Calling into WSMan to receive output from the shell.

Message #

Calling into WSMan to receive output from the shell

Event ID 23 — WSMan receive operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

WSMan receive operation failed; error code {errorCode}.

Message #

WSMan receive operation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 24 — Calling into WSMan to receive output from the command

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Calling into WSMan to receive output from the command.

Message #

Calling into WSMan to receive output from the command

Event ID 26 — Getting message for error code {inputErrorCode} completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}.

Message #

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}

Fields #

NameDescription
inputErrorCode
languageCode

Event ID 27 — Getting WSMan Session Option ({optionCode}).

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Getting WSMan Session Option ({optionCode}).

Message #

Getting WSMan Session Option ({optionCode})

Fields #

NameDescription
optionCode

Event ID 28 — Access Denied error: the apiCall API caller does not match the creator of the application object.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Description

Access Denied error: the apiCall API caller does not match the creator of the application object.

Message #

Access Denied error: the %1 API caller does not match the creator of the application object

Fields #

NameDescription
apiCall UnicodeString

Event ID 29 — Initialization of WSMan API completed successfuly

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIInitialize
Opcode
Stop

Description

Initialization of WSMan API completed successfuly.

Message #

Initialization of WSMan API completed successfuly

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 29,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.458595+00:00",
    "event_record_id": 97,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 30 — Deinitialization of WSMan API completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIDeinitialize
Opcode
Stop

Description

Deinitialization of WSMan API completed successfuly.

Message #

Deinitialization of WSMan API completed successfuly

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 30,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.857484+00:00",
    "event_record_id": 396,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5972
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 31 — WSMan Create Session operation completed successfuly

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManSessioninitialize
Opcode
Stop

Description

WSMan Create Session operation completed successfuly.

Message #

WSMan Create Session operation completed successfuly

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 31,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:29.472808+00:00",
    "event_record_id": 99,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 32 — Setting WSMan Session Option (optionCode) - optionName failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall

Description

Setting WSMan Session Option (optionCode) - optionName failed, error code errorCode.

Message #

Setting WSMan Session Option (%1) - %2 failed, error code %3.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString
errorCode UInt32

Event ID 33 — Closing WSMan Session completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManSessiondeinitialize
Opcode
Stop

Description

Closing WSMan Session completed successfuly.

Message #

Closing WSMan Session completed successfuly

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 33,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2025-12-31T19:35:53.857495+00:00",
    "event_record_id": 397,
    "correlation": {
      "ActivityID": "448C0251-84E6-4F2F-9CCC-D1000CB02549"
    },
    "execution": {
      "process_id": 5364,
      "thread_id": 5944
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 34 — Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

Message #

Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}

Fields #

NameDescription
inputErrorCode
errorCode

Event ID 35 — Signaling WSMan command failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Signaling WSMan command failed; error code {errorCode}.

Message #

Signaling WSMan command failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 36 — Signaling WSMan command

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Signaling WSMan command.

Message #

Signaling WSMan command

Event ID 37 — Closing WSMan shell failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Description

Closing WSMan shell failed, error code errorCode.

Message #

Closing WSMan shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 38 — Closing WSMan command failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Description

Closing WSMan command failed, error code errorCode.

Message #

Closing WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 39 — Closing WSMan {operationName} operation completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Closing WSMan {operationName} operation completed successfully.

Message #

Closing WSMan {operationName} operation completed successfully

Fields #

NameDescription
operationName

Event ID 40 — Closing WSMan operationName operation failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WSManAPIcall
Opcode
Stop

Description

Closing WSMan operationName operation failed, error code errorCode.

Message #

Closing WSMan %1 operation failed, error code %2

Fields #

NameDescription
operationName UnicodeString
errorCode UInt32

Event ID 41 — The WinRM protocol handler has began loading for application applicationID.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMIProtocolHandler
Opcode
Start

Description

The WinRM protocol handler has began loading for application applicationID.

Message #

The WinRM protocol handler has began loading for application %1.

Fields #

NameDescription
applicationID UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 4,
    "task": 14,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:21:54.064765+00:00",
    "event_record_id": 113,
    "correlation": {
      "ActivityID": "1480B89F-E871-42E4-BFB4-C8F88B053137"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4780
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "applicationID": "ServerManager.exe"
  },
  "message": ""
}

References #

Event ID 42 — The WinRM protocol handler completed unloading.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMIProtocolHandler
Opcode
Stop

Description

The WinRM protocol handler completed unloading.

Message #

The WinRM protocol handler completed unloading.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 42,
    "version": 0,
    "level": 4,
    "task": 14,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:57:49.982619+00:00",
    "event_record_id": 1760,
    "correlation": {
      "ActivityID": "028C3802-AD9E-000D-4C43-8D029EADDC01"
    },
    "execution": {
      "process_id": 8788,
      "thread_id": 10176
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 43 — The WinRM protocol handler unloaded prematurely due to the following error: errorMessage.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WinRMMIProtocolHandler
Opcode
Stop

Description

The WinRM protocol handler unloaded prematurely due to the following error: errorMessage.

Message #

The WinRM protocol handler unloaded prematurely due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Event ID 44 — The WinRM protocol handler started to create a session at the following destination: destination.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMISession
Opcode
Start

Description

The WinRM protocol handler started to create a session at the following destination: destination.

Message #

The WinRM protocol handler started to create a session at the following destination: %1.

Fields #

NameDescription
destination UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 44,
    "version": 0,
    "level": 4,
    "task": 15,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.208888+00:00",
    "event_record_id": 276,
    "correlation": {},
    "execution": {
      "process_id": 4444,
      "thread_id": 2008
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "destination": "<local>"
  },
  "message": ""
}

References #

Event ID 45 — The WinRM protocol handler closed the session.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMISession
Opcode
Stop

Description

The WinRM protocol handler closed the session.

Message #

The WinRM protocol handler closed the session.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 45,
    "version": 0,
    "level": 4,
    "task": 15,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.283057+00:00",
    "event_record_id": 283,
    "correlation": {},
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 46 — The WinRM protocol session closed prematurely due to the following error: errorMessage.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
WinRMMISession
Opcode
Stop

Description

The WinRM protocol session closed prematurely due to the following error: errorMessage.

Message #

The WinRM protocol session closed prematurely due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Event ID 47 — The WinRM protocol session began an operation of type operationType to the server.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMIOperation
Opcode
Start

Description

The WinRM protocol session began an operation of type operationType to the server. The operation accesses class className under the namespaceName namespace.

Message #

The WinRM protocol session began an operation of type %1 to the server. The operation accesses class %3 under the %2 namespace.

Fields #

NameDescription
operationType UnicodeString
namespaceName UnicodeString
className UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 47,
    "version": 0,
    "level": 4,
    "task": 16,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.268345+00:00",
    "event_record_id": 278,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-B210-ABE09F4AD801"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "operationType": "GetClass",
    "namespaceName": "root/microsoft/windows/smb",
    "className": "MSFT_SmbServerConfiguration"
  },
  "message": ""
}

References #

Event ID 48 — The WinRM protocol session successfully completed the operation.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WinRMMIOperation
Opcode
Stop

Description

The WinRM protocol session successfully completed the operation.

Message #

The WinRM protocol session successfully completed the operation.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 48,
    "version": 0,
    "level": 4,
    "task": 16,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.278922+00:00",
    "event_record_id": 281,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-B210-ABE09F4AD801"
    },
    "execution": {
      "process_id": 4444,
      "thread_id": 4432
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 49 — The WinRM protocol operation failed due to the following error: errorMessage.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
WinRMMIOperation
Opcode
Stop

Description

The WinRM protocol operation failed due to the following error: errorMessage.

Message #

The WinRM protocol operation failed due to the following error: %2.

Fields #

NameDescription
errorCode UInt32
errorMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 49,
    "version": 0,
    "level": 2,
    "task": 16,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:57:49.042601+00:00",
    "event_record_id": 1757,
    "correlation": {
      "ActivityID": "028C3802-AD9E-000D-4C43-8D029EADDC01"
    },
    "execution": {
      "process_id": 8788,
      "thread_id": 9388
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "errorCode": 2150859195,
    "errorMessage": "The WinRM client cannot process the request. Default authentication may be used with an IP address under the following conditions: the transport is HTTPS or the destination is in the TrustedHosts list, and explicit credentials are provided. Use winrm.cmd to configure TrustedHosts. Note that computers in the TrustedHosts list might not be authenticated. For more information on how to set TrustedHosts run the following command: winrm help config."
  },
  "message": ""
}

Event ID 64 — Auto-detecting proxy settings

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Auto-detecting proxy settings.

Message #

Auto-detecting proxy settings

Event ID 65 — Proxy AutoDetect done.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Proxy AutoDetect done.Proxy list: {proxyList} Bypass list: {bypassList}.

Message #

Proxy AutoDetect done.Proxy list: {proxyList} Bypass list: {bypassList}

Fields #

NameDescription
proxyList
bypassList

Event ID 66 — Setting proxy info Proxy list: {proxyList} Bypass list: {bypassList}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Setting proxy info Proxy list: {proxyList} Bypass list: {bypassList}.

Message #

Setting proxy info  Proxy list: {proxyList}  Bypass list: {bypassList}

Fields #

NameDescription
proxyList
bypassList

Event ID 80 — Sending the request for operation {operationName} to destination machine and port {url}:{port}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending the request for operation {operationName} to destination machine and port {url}:{port}.

Message #

Sending the request for operation {operationName} to destination machine and port {url}:{port}

Fields #

NameDescription
operationName
url
port

Event ID 81 — Processing client request for operation {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Processing client request for operation {operationName}.

Message #

Processing client request for operation {operationName}

Fields #

NameDescription
operationName

Event ID 82 — Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

Message #

Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>

Fields #

NameDescription
operation
resourceURI

Event ID 83 — Leaving the plugin for operation {operation}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Leaving the plugin for operation {operation}.

Message #

Leaving the plugin for operation {operation}

Fields #

NameDescription
operation

Event ID 84 — The maximum number of users (users) executing shell operations has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Requesthandling

Description

The maximum number of users (users) executing shell operations has been exceeded.

Message #

The maximum number of users (%1) executing shell operations has been exceeded.
Retry after sometime or raise the quota for concurrent shell users.

Fields #

NameDescription
users UInt32

Event ID 85 — The senderName user is allowed a maximum number of concurrentShells concurrent shells, which has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Requesthandling

Description

The senderName user is allowed a maximum number of concurrentShells concurrent shells, which has been exceeded.

Message #

The %1 user is allowed a maximum number of %2 concurrent shells, which has been exceeded.
Close existing shells or raise the quota for this user.

Fields #

NameDescription
senderName UnicodeString
concurrentShells UInt32

Event ID 86 — The WSMan service could not launch a host process to process the given request.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Requesthandling

Description

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code errorCode.

Message #

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 87 — The WSMan host process was unexpectedly terminated.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
Requesthandling

Description

The WSMan host process was unexpectedly terminated. Error code errorCode.

Message #

The WSMan host process was unexpectedly terminated. Error code %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 87,
    "version": 0,
    "level": 2,
    "task": 9,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T08:14:06.985298+00:00",
    "event_record_id": 62,
    "correlation": {
      "ActivityID": "DD7B0B6A-4A9E-0000-F00E-7BDD9E4AD801"
    },
    "execution": {
      "process_id": 2576,
      "thread_id": 4764
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "errorCode": 1726
  },
  "message": ""
}

References #

Event ID 90 — RunAs was disabled by Group Policy; WSMan service has erased all RunAs credentials.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Requesthandling

Description

RunAs was disabled by Group Policy; WSMan service has erased all RunAs credentials.

Message #

RunAs was disabled by Group Policy; WSMan service has erased all RunAs credentials.

Event ID 91 — Creating WSMan shell on server with ResourceUri: resourceUri.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Requesthandling

Description

Creating WSMan shell on server with ResourceUri: resourceUri.

Message #

Creating WSMan shell on server with ResourceUri: %1

Fields #

NameDescription
resourceUri UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 91,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T17:21:30.499992+00:00",
    "event_record_id": 108,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-35B9-AAE09F4AD801"
    },
    "execution": {
      "process_id": 4644,
      "thread_id": 4428
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "resourceUri": "http://schemas.microsoft.com/powershell/Microsoft.Windows.ServerManagerWorkflows"
  },
  "message": ""
}

References #

Event ID 129 — Received the response from Network layer; status: {status}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Received the response from Network layer; status: {status}.

Message #

Received the response from Network layer; status: {status}

Fields #

NameDescription
statusNTSTATUS reference

Event ID 130 — Received the response from Network layer; status: {status}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Received the response from Network layer; status: {status}.

Message #

Received the response from Network layer; status: {status}

Fields #

NameDescription
statusNTSTATUS reference

Event ID 131 — Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: location.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Responsehandling

Description

Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: location.

Message #

Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: %1

Fields #

NameDescription
location UnicodeString

Event ID 132 — WSMan operation operationName completed successfully.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Responsehandling
Opcode
Stop

Description

WSMan operation operationName completed successfully.

Message #

WSMan operation %1 completed successfully

Fields #

NameDescription
operationName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 132,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2022-04-07T17:38:36.279410+00:00",
    "event_record_id": 282,
    "correlation": {},
    "execution": {
      "process_id": 4444,
      "thread_id": 4908
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-21-2121334350-1110938707-2888912545-500"
    }
  },
  "event_data": {
    "operationName": "Invoke"
  },
  "message": ""
}

References #

Event ID 133 — Sending response error packet for ActionURI: {actionUri}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending response error packet for ActionURI: {actionUri}.

Message #

Sending response error packet for ActionURI: {actionUri}

Fields #

NameDescription
actionUri

Event ID 134 — Sending response for operation {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending response for operation {operationName}.

Message #

Sending response for operation {operationName}

Fields #

NameDescription
operationName

Event ID 135 — Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next proxy

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Responsehandling

Description

Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next proxy.

Message #

Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT, using next proxy

Event ID 136 — Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using next proxy

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Responsehandling

Description

Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using next proxy.

Message #

Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED, using next proxy

Event ID 137 — Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Responsehandling

Description

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation.

Message #

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation

Event ID 138 — The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
Responsehandling

Description

The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT).

Message #

The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 138,
    "version": 0,
    "level": 2,
    "task": 10,
    "opcode": 0,
    "keywords": 4611686018427387906,
    "time_created": "2026-03-13T16:58:52.389986+00:00",
    "event_record_id": 1804,
    "correlation": {
      "ActivityID": "028C3802-AD9E-0009-DEA5-8C029EADDC01"
    },
    "execution": {
      "process_id": 1528,
      "thread_id": 10360
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 139 — The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Responsehandling

Description

The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE).

Message #

The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

Event ID 140 — Sending HTTP error back to the client due to a transport failure.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}.

Message #

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}

Fields #

NameDescription
httpStatus
errorCode

Event ID 141 — Sending timeout response for operation: {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending timeout response for operation: {operationName}.

Message #

Sending timeout response for operation: {operationName}

Fields #

NameDescription
operationName

Event ID 142 — WSMan operation operationName failed, error code errorCode.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
Responsehandling
Opcode
Stop

Description

WSMan operation operationName failed, error code errorCode.

Message #

WSMan operation %1 failed, error code %2

Fields #

NameDescription
operationName UnicodeString
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 142,
    "version": 0,
    "level": 2,
    "task": 10,
    "opcode": 2,
    "keywords": 4611686018427387906,
    "time_created": "2023-11-06T00:47:48.782597+00:00",
    "event_record_id": 84,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-9DAB-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "operationName": "Enumeration",
    "errorCode": 2150858770
  },
  "message": ""
}

References #

Event ID 143 — Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Received the response from Network layer; status: 200 (HTTP_STATUS_OK).

Message #

Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

Event ID 145 — WSMan operation operationName started with resourceUri resourceUri.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
WSManAPIcall
Opcode
Start

Description

WSMan operation operationName started with resourceUri resourceUri.

Message #

WSMan operation %1 started with resourceUri %2

Fields #

NameDescription
operationName UnicodeString
resourceUri UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 145,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": 4611686018427387906,
    "time_created": "2023-11-06T00:47:39.837811+00:00",
    "event_record_id": 81,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0000-9DAB-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16220
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "operationName": "Enumeration",
    "resourceUri": "http://schemas.microsoft.com/wbem/wsman/1/config/listener"
  },
  "message": ""
}

References #

Event ID 160 — Authenticating the user using {authentication} mechanism.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Authenticating the user using {authentication} mechanism.

Message #

Authenticating the user using {authentication} mechanism

Fields #

NameDescription
authentication

Event ID 161 — authFailureMessage.

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
Userauthentication

Message #

%1

Fields #

NameDescription
authFailureMessage UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 161,
    "version": 0,
    "level": 2,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387914,
    "time_created": "2023-11-06T00:47:48.782381+00:00",
    "event_record_id": 83,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-A38B-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "authFailureMessage": "The client cannot connect to the destination specified in the request. Verify that the service on the destination is running and is accepting requests. Consult the logs and documentation for the WS-Management service running on the destination, most commonly IIS or WinRM. If the destination is the WinRM service, run the following command on the destination to analyze and configure the WinRM service: \"winrm quickconfig\"."
  },
  "message": ""
}

References #

Event ID 162 — Authenticating the user failed.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Error
Task
Userauthentication

Description

Authenticating the user failed. The credentials didn't work.

Message #

Authenticating the user failed. The credentials didn't work.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 2,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387914,
    "time_created": "2026-03-13T17:03:29.975606+00:00",
    "event_record_id": 1873,
    "correlation": {
      "ActivityID": "028C3802-AD9E-0009-E2AC-8C029EADDC01"
    },
    "execution": {
      "process_id": 8184,
      "thread_id": 4952
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 163 — The authentication mechanism (authClient) requested by the client is not supported by the server.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Description

The authentication mechanism (authClient) requested by the client is not supported by the server.

Message #

The authentication mechanism (%1) requested by the client is not supported by the server.
Possible authentication mechanisms reported by server: %2 %3 %4 %5 %6

Fields #

NameDescription
authClient UnicodeString
authServer1 UnicodeString
authServer2 UnicodeString
authServer3 UnicodeString
authServer4 UnicodeString
authServer5 UnicodeString

Event ID 164 — The destination computer (destinationMachine) returned an 'access denied' error.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Description

The destination computer (destinationMachine) returned an 'access denied' error. Verify your credentials are correct.

Message #

The destination computer (%1) returned an 'access denied' error. Verify your credentials are correct.

Fields #

NameDescription
destinationMachine UnicodeString

Event ID 165 — The authentication mechanism requested by the proxy is not supported by the client.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Description

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate, Basic or Digest.

Message #

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate, Basic or Digest. 
Possible authentication mechanisms reported by proxy: %1 %2 %3 %4 %5

Fields #

NameDescription
authProxy1 UnicodeString
authProxy2 UnicodeString
authProxy3 UnicodeString
authProxy4 UnicodeString
authProxy5 UnicodeString

Event ID 166 — The chosen authentication mechanism is {auth}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The chosen authentication mechanism is {auth}.

Message #

The chosen authentication mechanism is {auth}

Fields #

NameDescription
auth

Event ID 168 — Sending HTTP 401 response to the client and disconnect the connection after sending the response

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Sending HTTP 401 response to the client and disconnect the connection after sending the response.

Message #

Sending HTTP 401 response to the client and disconnect the connection after sending the response

Event ID 169 —

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational

Fields #

NameDescription
username
authenticationMechanism

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 169,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2019-05-20T15:54:32.564901+00:00",
    "event_record_id": 861,
    "correlation": {
      "ActivityID": "8534C364-2CC0-0001-C84D-A5F46C0FD501"
    },
    "execution": {
      "process_id": 1204,
      "thread_id": 3068
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "IEWIN7",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "username": "iewin7\\ieuser",
    "authenticationMechanism": "NTLM"
  },
  "message": ""
}

References #

Event ID 170 — The authentication using client certificate with subject {subject} done successfully.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The authentication using client certificate with subject {subject} done successfully.

Message #

The authentication using client certificate with subject {subject} done successfully

Fields #

NameDescription
subject

Event ID 171 — Authenticating the user with the proxy failed.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Description

Authenticating the user with the proxy failed. The credentials didn't work.

Message #

Authenticating the user with the proxy failed. The credentials didn't work.

Event ID 172 — The server certificate on the destination computer (machineName:port) has the following errors: error1 error2 error3 error4 error5 error6 error7 error8.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Description

The server certificate on the destination computer (machineName:port) has the following errors: error1 error2 error3 error4 error5 error6 error7 error8. Fix the server certificate and try again.

Message #

The server certificate on the destination computer (%1:%2) has the following errors: %3 %4 %5 %6 %7 %8 %9 %10. Fix the server certificate and try again.

Fields #

NameDescription
machineName UnicodeString
port UnicodeString
error1 UnicodeString
error2 UnicodeString
error3 UnicodeString
error4 UnicodeString
error5 UnicodeString
error6 UnicodeString
error7 UnicodeString
error8 UnicodeString

Event ID 173 — The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Userauthentication

Message #

The WinRM service has terminated %1 unauthenticated connections over the past %2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. 

 Action: 
Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 192 — The authorization of the user failed with error errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Userauthorization

Description

The authorization of the user failed with error errorCode.

Message #

The authorization of the user failed with error %1

Fields #

NameDescription
errorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 192,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2026-03-13T17:30:10.610317+00:00",
    "event_record_id": 2649,
    "correlation": {
      "ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
    },
    "execution": {
      "process_id": 6952,
      "thread_id": 2464
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "errorCode": 5
  },
  "message": ""
}

Event ID 193 — Request for user param1 (param2) will be executed using WinRM virtual account param3 (param4).

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Userauthorization

Description

Request for user param1 (param2) will be executed using WinRM virtual account param3 (param4).

Message #

Request for user %1 (%2) will be executed using WinRM virtual account %3 (%4)

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 193,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 0,
    "keywords": 4611686018427387916,
    "time_created": "2019-05-20T15:54:32.564901+00:00",
    "event_record_id": 863,
    "correlation": {
      "ActivityID": "8534C364-2CC0-0001-C84D-A5F46C0FD501"
    },
    "execution": {
      "process_id": 1204,
      "thread_id": 3068
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "IEWIN7",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 194 — The authorization of the user failed with error {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The authorization of the user failed with error {errorCode}.

Message #

The authorization of the user failed with error {errorCode}

Fields #

NameDescription
errorCode

Event ID 208 — The Winrm service is starting

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop
Opcode
Start

Description

The Winrm service is starting.

Message #

The Winrm service is starting

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 208,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 1,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T16:53:23.340882+00:00",
    "event_record_id": 82,
    "correlation": {},
    "execution": {
      "process_id": 2416,
      "thread_id": 2528
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 209 — The Winrm service started successfully

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop

Description

The Winrm service started successfully.

Message #

The Winrm service started successfully

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 209,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T16:53:23.453821+00:00",
    "event_record_id": 83,
    "correlation": {
      "ActivityID": "E0AAB88C-4A9F-0001-35B9-AAE09F4AD801"
    },
    "execution": {
      "process_id": 2416,
      "thread_id": 2528
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 210 — The WinRM service is unable to start because of a failure during initialization.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop
Opcode
Stop

Description

The WinRM service is unable to start because of a failure during initialization. The error code is errorCode.

Message #

The WinRM service is unable to start because of a failure during initialization. The error code is %1

Fields #

NameDescription
errorCode UInt32

Event ID 211 — The Winrm service is stopping

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop

Description

The Winrm service is stopping.

Message #

The Winrm service is stopping

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 211,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T16:45:07.009526+00:00",
    "event_record_id": 3,
    "correlation": {
      "ActivityID": "C1DC836A-4A9E-0001-8686-DCC19E4AD801"
    },
    "execution": {
      "process_id": 2348,
      "thread_id": 2608
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 212 — The Winrm service was stopped successfully

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Winrmservicestart/stop
Opcode
Stop

Description

The Winrm service was stopped successfully.

Message #

The Winrm service was stopped successfully

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 212,
    "version": 0,
    "level": 4,
    "task": 11,
    "opcode": 2,
    "keywords": 4611686018427387908,
    "time_created": "2022-04-07T16:45:07.526668+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "C1DC836A-4A9E-0001-8686-DCC19E4AD801"
    },
    "execution": {
      "process_id": 2348,
      "thread_id": 2608
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 213 — The WSMan service could not load current configuration settings as the settings are corrupted.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead.

Message #

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{}

Event ID 214 — The WSMan client could not load current configuration settings as the settings are corrupted.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead.

Message #

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead. 

 User Action 
 Start the WinRM service and use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{}

Event ID 215 — The WSMan service failed to read configuration of the following plugin.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service failed to read configuration of the following plugin.

Message #

The WSMan service failed to read configuration of the following plugin: 
 %1. 

The error received was %2: %%%2 
 %3.

 User Action 
 Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName UnicodeString
errorcode UnicodeString
errordetail UnicodeString

Event ID 216 — The WSMan service failed to restart the plugins marked for AutoRestart.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service failed to restart the plugins marked for AutoRestart. The error code received was errorcode.

Message #

The WSMan service failed to restart the plugins marked for AutoRestart. The error code received was %1.

Fields #

NameDescription
errorcode UnicodeString

Event ID 217 — The WSMan service failed to restart the pluginName plugin on service startup.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service failed to restart the pluginName plugin on service startup. The error code received was errorcode.

Message #

The WSMan service failed to restart the %1 plugin on service startup. The error code received was %2.

Fields #

NameDescription
pluginName UnicodeString
errorcode UInt32

Event ID 218 — The WSMan service successfully restarted the following plugin on service startup: pluginName.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan service successfully restarted the following plugin on service startup: pluginName.

Message #

The WSMan service successfully restarted the following plugin on service startup: %1.

Fields #

NameDescription
pluginName UnicodeString

Event ID 219 — The WSMan shell instance param1 will no longer support disconnect reconnect functionality because a non-supported request was sent by the client.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmservicestart/stop

Description

The WSMan shell instance param1 will no longer support disconnect reconnect functionality because a non-supported request was sent by the client.

Message #

The WSMan shell instance %1 will no longer support disconnect reconnect functionality because a non-supported request was sent by the client.

Fields #

NameDescription
param1 UnicodeString

Event ID 224 — message.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational
Task
Winrmconfiguration

Message #

%1

Fields #

NameDescription
message UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 224,
    "version": 0,
    "level": 4,
    "task": 12,
    "opcode": 0,
    "keywords": 4611686018427387908,
    "time_created": "2026-03-13T17:01:46.087745+00:00",
    "event_record_id": 873,
    "correlation": {
      "ActivityID": "A84E255E-A05B-0007-9C29-4EA85BA0DC01"
    },
    "execution": {
      "process_id": 1732,
      "thread_id": 9060
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "message": "Enable the WinRM firewall exception. "
  },
  "message": ""
}

Event ID 229 — The WinRM param1 failed to register for group policy change notifications.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmconfiguration

Description

The WinRM param1 failed to register for group policy change notifications. The error code is param2.

Message #

The WinRM %1 failed to register for group policy change notifications. The error code is %2.

Fields #

NameDescription
param1 UnicodeString
param2 UInt32

Event ID 230 — Deletion of registry key param1 resulted in access denied.

Provider
Microsoft-Windows-WinRM
Channel
Operational
Task
Winrmconfiguration

Description

Deletion of registry key param1 resulted in access denied. If this registry entry is not marked specifically as read only, this seems like a potential issue.

Message #

Deletion of registry key %1 resulted in access denied. If this registry entry is not marked specifically as read only, this seems like a potential issue.

Fields #

NameDescription
param1 UnicodeString

Event ID 254 — Activity Transfer

#
Provider
Microsoft-Windows-WinRM
Channel
Operational
Level
Informational

Description

Activity Transfer.

Message #

Activity Transfer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "A7975C8F-AC13-49F1-87DA-5A984A4AB417",
    "event_source_name": "",
    "event_id": 254,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387942,
    "time_created": "2023-11-06T00:47:48.782378+00:00",
    "event_record_id": 82,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-A38B-E4E43710DA01",
      "RelatedActivityID": "E4DB489E-1037-0000-9DAB-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 16312
    },
    "channel": "Microsoft-Windows-WinRM/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 255 — Activity Transfer

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Activity Transfer.

Message #

Activity Transfer

Event ID 257 — Initializing WSMan API

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Initializing WSMan API.

Message #

Initializing WSMan API

Event ID 258 — Initialization of WSMan API failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Initialization of WSMan API failed; error code {errorCode}.

Message #

Initialization of WSMan API failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 259 — Deinitializing WSMan API

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Deinitializing WSMan API.

Message #

Deinitializing WSMan API

Event ID 260 — Deinitialization of WSMan API failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Deinitialization of WSMan API failed; error code {errorCode}.

Message #

Deinitialization of WSMan API failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 261 — Creating WSMan Session.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Creating WSMan Session. The connection string is: {connection}.

Message #

Creating WSMan Session. The connection string is: {connection}

Fields #

NameDescription
connection

Event ID 262 — WSMan Create Session operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan Create Session operation failed; error code {errorCode}.

Message #

WSMan Create Session operation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 263 — Closing WSMan Session

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan Session.

Message #

Closing WSMan Session

Event ID 264 — Closing WSMan Session failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan Session failed; error code {errorCode}.

Message #

Closing WSMan Session failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 265 — Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed successfuly.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed successfuly.

Message #

Setting WSMan Session Option ({optionCode}) with value ({optionValue}) completed successfuly

Fields #

NameDescription
optionCode
optionValue

Event ID 266 — Creating WSMan shell with the ResourceUri: {resourceUri}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Creating WSMan shell with the ResourceUri: {resourceUri}.

Message #

Creating WSMan shell with the ResourceUri: {resourceUri}

Fields #

NameDescription
resourceUri

Event ID 267 — WSMan shell creation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan shell creation failed; error code {errorCode}.

Message #

WSMan shell creation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 268 — Running WSMan command

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Running WSMan command.

Message #

Running WSMan command

Event ID 269 — Running WSMan command failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Running WSMan command failed; error code {errorCode}.

Message #

Running WSMan command failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 270 — Closing WSMan command

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan command.

Message #

Closing WSMan command

Event ID 271 — Closing WSMan shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan shell.

Message #

Closing WSMan shell

Event ID 272 — Signaling WSMan shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Signaling WSMan shell.

Message #

Signaling WSMan shell

Event ID 273 — Signaling WSMan shell; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Signaling WSMan shell; error code {errorCode}.

Message #

Signaling WSMan shell; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 274 — Closing WSMan operation

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan operation.

Message #

Closing WSMan operation

Event ID 275 — Sending input to the shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending input to the shell.

Message #

Sending input to the shell

Event ID 276 — Sending input operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending input operation failed; error code {errorCode}.

Message #

Sending input operation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 277 — Calling into WSMan to receive output from the shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Calling into WSMan to receive output from the shell.

Message #

Calling into WSMan to receive output from the shell

Event ID 278 — WSMan receive operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan receive operation failed; error code {errorCode}.

Message #

WSMan receive operation failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 279 — Calling into WSMan to receive output from the command

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Calling into WSMan to receive output from the command.

Message #

Calling into WSMan to receive output from the command

Event ID 280 — Getting message for error code {inputErrorCode} completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}.

Message #

Getting message for error code {inputErrorCode} completed successfully. The languageCode parameter was: {languageCode}

Fields #

NameDescription
inputErrorCode
languageCode

Event ID 281 — Getting WSMan Session Option ({optionCode}).

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Getting WSMan Session Option ({optionCode}).

Message #

Getting WSMan Session Option ({optionCode})

Fields #

NameDescription
optionCode

Event ID 282 — Access Denied error: the {apiCall} API caller does not match the creator of the application object.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Access Denied error: the {apiCall} API caller does not match the creator of the application object.

Message #

Access Denied error: the {apiCall} API caller does not match the creator of the application object

Fields #

NameDescription
apiCall

Event ID 283 — Plug-in reporting context for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting context for operation operationName.

Message #

Plug-in reporting context for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 284 — Plug-in reporting data object for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting data object for operation operationName.

Message #

Plug-in reporting data object for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 285 — Plug-in reporting data object and EPR for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting data object and EPR for operation operationName.

Message #

Plug-in reporting data object and EPR for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 286 — Plug-in reporting data object and bookmark for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting data object and bookmark for operation operationName.

Message #

Plug-in reporting data object and bookmark for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 287 — Plug-in reporting data for operation Receive

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting data for operation Receive.

Message #

Plug-in reporting data for operation Receive

Event ID 288 — Plug-in reporting operation complete for operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting operation complete for operationName.

Message #

Plug-in reporting operation complete for %1

Fields #

NameDescription
operationName UnicodeString

Event ID 289 — Plug-in getting operational information for parameter parameters and operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in getting operational information for parameter parameters and operation operationName.

Message #

Plug-in getting operational information for parameter %1 and operation %2

Fields #

NameDescription
parameters UInt32
operationName UnicodeString

Event ID 290 — Plug-in reporting the authorization for user username completed with error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting the authorization for user username completed with error code errorCode.

Message #

Plug-in reporting the authorization for user %1 completed with error code %2

Fields #

NameDescription
username UnicodeString
errorCode UInt32

Event ID 291 — Plug-in reporting the authorization operation completed with error errorCode for operation operation and ResourceUri resourceUri.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Plug-in reporting the authorization operation completed with error errorCode for operation operation and ResourceUri resourceUri.

Message #

Plug-in reporting the authorization operation completed with error %1 for operation %2 and ResourceUri %3

Fields #

NameDescription
errorCode UInt32
operation UnicodeString
resourceUri UnicodeString

Event ID 292 — Updating the quota for the user username with error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

Updating the quota for the user username with error code errorCode.

Message #

Updating the quota for the user %1 with error code %2
 maxAllowedConcurrentShells=%3
 maxAllowedConcurrentOperations=%4
 timeslotSize=%5
 maxAllowedOperationsPerTimeslot=%6

Fields #

NameDescription
username UnicodeString
errorCode UInt32
maxAllowedConcurrentShells UInt32
maxAllowedConcurrentOperations UInt32
timeslotSize UInt32
maxAllowedOperationsPerTimeslot UInt32

Event ID 293 — Initialization of WSMan API completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Initialization of WSMan API completed successfuly.

Message #

Initialization of WSMan API completed successfuly

Event ID 294 — Deinitialization of WSMan API completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Deinitialization of WSMan API completed successfuly.

Message #

Deinitialization of WSMan API completed successfuly

Event ID 295 — WSMan Create Session operation completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan Create Session operation completed successfuly.

Message #

WSMan Create Session operation completed successfuly

Event ID 296 — Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}.

Message #

Setting WSMan Session Option ({optionCode}) failed; error code {errorCode}

Fields #

NameDescription
optionCode
errorCode

Event ID 297 — Closing WSMan Session completed successfuly

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan Session completed successfuly.

Message #

Closing WSMan Session completed successfuly

Event ID 298 — Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}.

Message #

Getting message for error code {inputErrorCode} failed; the resulting error code is {errorCode}

Fields #

NameDescription
inputErrorCode
errorCode

Event ID 299 — Signaling WSMan command failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Signaling WSMan command failed; error code {errorCode}.

Message #

Signaling WSMan command failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 300 — Signaling WSMan command

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Signaling WSMan command.

Message #

Signaling WSMan command

Event ID 301 — Closing WSMan shell failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan shell failed; error code {errorCode}.

Message #

Closing WSMan shell failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 302 — Closing WSMan command failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan command failed; error code {errorCode}.

Message #

Closing WSMan command failed; error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 303 — Closing WSMan {operationName} operation completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan {operationName} operation completed successfully.

Message #

Closing WSMan {operationName} operation completed successfully

Fields #

NameDescription
operationName

Event ID 304 — Closing WSMan {operationName} operation failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Closing WSMan {operationName} operation failed; error code {errorCode}.

Message #

Closing WSMan {operationName} operation failed; error code {errorCode}

Fields #

NameDescription
operationName
errorCode

Event ID 305 — Sending input to the command

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending input to the command.

Message #

Sending input to the command

Event ID 306 — The WinRM service loaded the following plugin: provider (path).

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

The WinRM service loaded the following plugin: provider (path).

Message #

The WinRM service loaded the following plugin: %1 (%2)

Fields #

NameDescription
provider UnicodeString
path UnicodeString

Event ID 307 — The WinRM service unloaded the following plugin: provider (path).

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

The WinRM service unloaded the following plugin: provider (path).

Message #

The WinRM service unloaded the following plugin: %1 (%2)

Fields #

NameDescription
provider UnicodeString
path UnicodeString

Event ID 308 — The plugin called WSManPluginGetConfiguration with the parameter Flags and obtained a return value of Result.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

The plugin called WSManPluginGetConfiguration with the parameter Flags and obtained a return value of Result.

Message #

The plugin called WSManPluginGetConfiguration with the parameter %1 and obtained a return value of %2.

Fields #

NameDescription
Flags UInt32
Result UInt32

Event ID 309 — The plugin called WSManPluginReportCompletion with the parameter Flags and obtained a return value of Result.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

The plugin called WSManPluginReportCompletion with the parameter Flags and obtained a return value of Result.

Message #

The plugin called WSManPluginReportCompletion with the parameter %1 and obtained a return value of %2.

Fields #

NameDescription
Flags UInt32
Result UInt32

Event ID 310 — The plugin Plugin is being shut down because it was idle for longer than the configured HostIdleTimeoutSecs quota.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall

Description

The plugin Plugin is being shut down because it was idle for longer than the configured HostIdleTimeoutSecs quota.

Message #

The plugin %1 is being shut down because it was idle for longer than the configured HostIdleTimeoutSecs quota.

Fields #

NameDescription
Plugin UnicodeString

Event ID 311 — Signaling WSMan command failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Signaling WSMan command failed, error code errorCode.

Message #

Signaling WSMan command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 312 — Signaling WSMan command

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Signaling WSMan command.

Message #

Signaling WSMan command

Event ID 313 — Sending input to the command

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Sending input to the command.

Message #

Sending input to the command

Event ID 314 — Sending input to the shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Sending input to the shell.

Message #

Sending input to the shell

Event ID 315 — Sending input operation failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Sending input operation failed, error code errorCode.

Message #

Sending input operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 316 — Calling into WSMan to receive output from the shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Calling into WSMan to receive output from the shell.

Message #

Calling into WSMan to receive output from the shell

Event ID 317 — WSMan receive operation failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

WSMan receive operation failed, error code errorCode.

Message #

WSMan receive operation failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 318 — Calling into WSMan to receive output from the command

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Calling into WSMan to receive output from the command.

Message #

Calling into WSMan to receive output from the command

Event ID 319 — Getting message for error code inputErrorCode completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Getting message for error code inputErrorCode completed successfully. The languageCode parameter was: languageCode.

Message #

Getting message for error code %1 completed successfully. The languageCode parameter was: %2

Fields #

NameDescription
inputErrorCode UInt32
languageCode UnicodeString

Event ID 320 — Getting WSMan Session Option (optionCode) - optionName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Getting WSMan Session Option (optionCode) - optionName.

Message #

Getting WSMan Session Option (%1) - %2.

Fields #

NameDescription
optionCode UInt32
optionName UnicodeString

Event ID 321 — Signaling WSMan shell

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Signaling WSMan shell.

Message #

Signaling WSMan shell

Event ID 322 — Signaling WSMan shell, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Signaling WSMan shell, error code errorCode.

Message #

Signaling WSMan shell, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 323 — Closing WSMan operation

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Closing WSMan operation.

Message #

Closing WSMan operation

Event ID 324 — Closing WSMan operationName operation completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Closing WSMan operationName operation completed successfully.

Message #

Closing WSMan %1 operation completed successfully

Fields #

NameDescription
operationName UnicodeString

Event ID 325 — Disconnecting shell with Id : argument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Disconnecting shell with Id : argument.

Message #

Disconnecting shell with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 326 — Disconnecting shell failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Disconnecting shell failed, error code errorCode.

Message #

Disconnecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 327 — Reconnecting shell with Id : argument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Reconnecting shell with Id : argument.

Message #

Reconnecting shell  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 328 — Reconnecting shell failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Reconnecting shell failed, error code errorCode.

Message #

Reconnecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 329 — Connecting shell with Id : argument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Connecting shell with Id : argument.

Message #

Connecting shell  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 330 — Connecting shell failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Connecting shell failed, error code errorCode.

Message #

Connecting shell failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 331 — Reconnecting shell command with Id : argument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Reconnecting shell command with Id : argument.

Message #

Reconnecting shell command  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 332 — Reconnecting shell command failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Reconnecting shell command failed, error code errorCode.

Message #

Reconnecting shell command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 333 — Connecting shell command with Id : argument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Start

Description

Connecting shell command with Id : argument.

Message #

Connecting shell command  with Id : %1

Fields #

NameDescription
argument UnicodeString

Event ID 334 — Connecting shell command failed, error code errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WSManAPIcall
Opcode
Stop

Description

Connecting shell command failed, error code errorCode.

Message #

Connecting shell command failed, error code %1

Fields #

NameDescription
errorCode UInt32

Event ID 512 — Auto-detecting proxy settings

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Auto_detectingproxysettings
Opcode
Start

Description

Auto-detecting proxy settings.

Message #

Auto-detecting proxy settings

Event ID 513 — Proxy AutoDetect done.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Auto_detectingproxysettings
Opcode
Stop

Description

Proxy AutoDetect done.

Message #

Proxy AutoDetect done.
Proxy list: %1 
Bypass list: %2

Fields #

NameDescription
proxyList UnicodeString
bypassList UnicodeString

Event ID 514 — Setting proxy info.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Auto_detectingproxysettings

Description

Setting proxy info.

Message #

Setting proxy info 
 Proxy list: %1 
 Bypass list: %2

Fields #

NameDescription
proxyList UnicodeString
bypassList UnicodeString

Event ID 768 — Processing client request for operation {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Processing client request for operation {operationName}.

Message #

Processing client request for operation {operationName}

Fields #

NameDescription
operationName

Event ID 769 — Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>.

Message #

Entering the plugin for operation {operation} with a ResourceURI of <{resourceURI}>

Fields #

NameDescription
operation
resourceURI

Event ID 770 — Leaving the plugin for operation {operation}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Leaving the plugin for operation {operation}.

Message #

Leaving the plugin for operation {operation}

Fields #

NameDescription
operation

Event ID 771 — SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [client sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 772 — SOAP [listener receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

SOAP [listener receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [listener receiving index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 773 — The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.Close existing shells or raise the quota for this user.

Message #

The {senderName} user is allowed a maximum number of {concurrentShells} concurrent shells; which has been exceeded.Close existing shells or raise the quota for this user.

Fields #

NameDescription
senderName
concurrentShells

Event ID 774 — The senderName user is allowed a maximum number of concurrentOperations concurrent operations, which has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The senderName user is allowed a maximum number of concurrentOperations concurrent operations, which has been exceeded.

Message #

The %1 user is allowed a maximum number of %2 concurrent operations, which has been exceeded.
Close existing operations for this user, or raise the quota for this user.

Fields #

NameDescription
senderName UnicodeString
concurrentOperations UInt32

Event ID 775 — The user load quota of requests requests per windowTime seconds has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The user load quota of requests requests per windowTime seconds has been exceeded.

Message #

The user load quota of %1 requests per %2 seconds has been exceeded.
Send future requests at a slower rate or raise the quota for the %3 user.
The next request from this user will not be approved for at least %4 milliseconds.

Fields #

NameDescription
requests UInt32
windowTime UInt32
senderName UnicodeString
delayHint UInt32

Event ID 776 — The system load quota of requests requests per windowTime seconds has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The system load quota of requests requests per windowTime seconds has been exceeded.

Message #

The system load quota of %1 requests per %2 seconds has been exceeded.
Send future requests at a slower rate or raise the system quota.
The next request from the user %3 will not be approved for at least %4 milliseconds.

Fields #

NameDescription
requests UInt32
windowTime UInt32
senderName UnicodeString
delayHint UInt32

Event ID 777 — The maximum number of users ({users}) executing shell operations has been exceeded.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The maximum number of users ({users}) executing shell operations has been exceeded.Retry after sometime or raise the quota for concurrent shell users.

Message #

The maximum number of users ({users}) executing shell operations has been exceeded.Retry after sometime or raise the quota for concurrent shell users.

Fields #

NameDescription
users

Event ID 778 — Sending the request for operation {operationName} to destination machine and port {url}:{port}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending the request for operation {operationName} to destination machine and port {url}:{port}.

Message #

Sending the request for operation {operationName} to destination machine and port {url}:{port}

Fields #

NameDescription
operationName
url
port

Event ID 779 — SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

SOAP [client sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [client sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument AnsiString

Event ID 780 — The WinRM param1 has encountered network connectivity issues.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM param1 has encountered network connectivity issues.

Message #

The WinRM %1 has encountered network connectivity issues.

Fields #

NameDescription
param1 UnicodeString

Event ID 781 — The WinRM Client is attempting to re-establish a network connection.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM Client is attempting to re-establish a network connection.

Message #

The WinRM Client is attempting to re-establish a network connection.

Event ID 782 — The WinRM Service has detected a new network connection from the client.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM Service has detected a new network connection from the client.

Message #

The WinRM Service has detected a new network connection from the client.

Event ID 783 — The WinRM param1 has successfully re-established a network connection.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM param1 has successfully re-established a network connection.

Message #

The WinRM %1 has successfully re-established a network connection.

Fields #

NameDescription
param1 UnicodeString

Event ID 784 — The WinRM param1 failed to re-establish a network connection and is reporting a failure.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM param1 failed to re-establish a network connection and is reporting a failure.

Message #

The WinRM %1 failed to re-establish a network connection and is reporting a failure.

Fields #

NameDescription
param1 UnicodeString

Event ID 785 — The WSMan host process was started for user userName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WSMan host process was started for user userName.

Message #

The WSMan host process was started for user %1.

Fields #

NameDescription
userName UnicodeString

Event ID 786 — The WSMan host process was terminated for user userName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WSMan host process was terminated for user userName.

Message #

The WSMan host process was terminated for user %1.

Fields #

NameDescription
userName UnicodeString

Event ID 787 — Sending the request for operation operationName to destination machine and port url:port.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling
Opcode
Start

Description

Sending the request for operation operationName to destination machine and port url:port.

Message #

Sending the request for operation %1 to destination machine and port %2:%3

Fields #

NameDescription
operationName UnicodeString
url UnicodeString
port UInt32

Event ID 788 — Processing client request for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

Processing client request for operation operationName.

Message #

Processing client request for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 789 — Entering the plugin for operation operation with a ResourceURI of <resourceURI>.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

Entering the plugin for operation operation with a ResourceURI of <resourceURI>.

Message #

Entering the plugin for operation %1 with a ResourceURI of <%2>

Fields #

NameDescription
operation UnicodeString
resourceURI UnicodeString

Event ID 790 — Leaving the plugin for operation operation.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling
Opcode
Stop

Description

Leaving the plugin for operation operation.

Message #

Leaving the plugin for operation %1

Fields #

NameDescription
operation UnicodeString

Event ID 791 — The WinRM service failed to enumerate DASH/SMASH specifications with MI error: errorCode.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Requesthandling

Description

The WinRM service failed to enumerate DASH/SMASH specifications with MI error: errorCode.

Message #

The WinRM service failed to enumerate DASH/SMASH specifications with MI error: %1.

Fields #

NameDescription
errorCode UInt32

Event ID 1024 — Sending response for operation {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending response for operation {operationName}.

Message #

Sending response for operation {operationName}

Fields #

NameDescription
operationName

Event ID 1025 — Sending response error packet for ActionURI: actionUri.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Sending response error packet for ActionURI: actionUri.

Message #

Sending response error packet for ActionURI: %1

Fields #

NameDescription
actionUri UnicodeString

Event ID 1026 — SOAP [client receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

SOAP [client receiving index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [client receiving index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 1027 — SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [listener sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument UnicodeString

Event ID 1028 — Received the response from Network layer; status: {status}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Received the response from Network layer; status: {status}.

Message #

Received the response from Network layer; status: {status}

Fields #

NameDescription
statusNTSTATUS reference

Event ID 1029 — Received the response from Network layer; status: {status}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Received the response from Network layer; status: {status}.

Message #

Received the response from Network layer; status: {status}

Fields #

NameDescription
statusNTSTATUS reference

Event ID 1030 — Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: {location}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: {location}.

Message #

Received redirect status code from Network layer; status: 302 (HTTP_STATUS_REDIRECT); location: {location}

Fields #

NameDescription
location

Event ID 1031 — WSMan operation {operationName} completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan operation {operationName} completed successfully.

Message #

WSMan operation {operationName} completed successfully

Fields #

NameDescription
operationName

Event ID 1032 — Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next proxy

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next proxy.

Message #

Re-sending the request as a result of ERROR_WINHTTP_CANNOT_CONNECT; using next proxy

Event ID 1033 — Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using next proxy

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using next proxy.

Message #

Re-sending the request as a result of ERROR_WINHTTP_NAME_NOT_RESOLVED; using next proxy

Event ID 1034 — Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation.

Message #

Network layer returned ERROR_WINHTTP_NAME_NOT_RESOLVED - The server name cannot be resolved. Aborting the operation

Event ID 1035 — The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT).

Message #

The client got a timeout from the network layer (ERROR_WINHTTP_TIMEOUT)

Event ID 1036 — The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE).

Message #

The client got a login failure from the network layer (ERROR_WINHTTP_LOGIN_FAILURE)

Event ID 1037 — The WSMan service could not launch a host process to process the given request.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code {errorCode}.

Message #

The WSMan service could not launch a host process to process the given request. Make sure the WSMan provider host server and proxy are properly registered. Error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 1038 — The WSMan host process was unexpectedly terminated.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The WSMan host process was unexpectedly terminated. Error code {errorCode}.

Message #

The WSMan host process was unexpectedly terminated. Error code {errorCode}

Fields #

NameDescription
errorCode

Event ID 1039 — Sending HTTP error back to the client due to a transport failure.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}.

Message #

Sending HTTP error back to the client due to a transport failure.The HTTP status code is {httpStatus}The error code is {errorCode}

Fields #

NameDescription
httpStatus
errorCode

Event ID 1040 — Sending timeout response for operation: {operationName}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending timeout response for operation: {operationName}.

Message #

Sending timeout response for operation: {operationName}

Fields #

NameDescription
operationName

Event ID 1041 — Enumeration is shutting down

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Enumeration is shutting down.

Message #

Enumeration is shutting down

Event ID 1042 — WSMan operation {operationName} failed; error code {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

WSMan operation {operationName} failed; error code {errorCode}.

Message #

WSMan operation {operationName} failed; error code {errorCode}

Fields #

NameDescription
operationName
errorCode

Event ID 1043 — Subscription is shutting down

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Subscription is shutting down.

Message #

Subscription is shutting down

Event ID 1044 — SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

SOAP [listener sending index index of totalChunks total chunks (bytes bytes)] SoapDocument.

Message #

SOAP [listener sending index %1 of %2 total chunks (%3 bytes)] %4

Fields #

NameDescription
index UInt32
totalChunks UInt32
bytes UInt32
SoapDocument AnsiString

Event ID 1045 — Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling
Opcode
Start

Description

Received the response from Network layer; status: 200 (HTTP_STATUS_OK).

Message #

Received the response from Network layer; status: 200 (HTTP_STATUS_OK)

Event ID 1046 — An extended semantics callback timed out for the operationName operation.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

An extended semantics callback timed out for the operationName operation.

Message #

An extended semantics callback timed out for the %1 operation.

Fields #

NameDescription
operationName UnicodeString

Event ID 1047 — Received the response from Network layer; status: status.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling
Opcode
Start

Description

Received the response from Network layer; status: status.

Message #

Received the response from Network layer; status: %1

Fields #

NameDescription
status UnicodeStringNTSTATUS reference

Event ID 1048 — Sending HTTP error back to the client due to a transport failure.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Sending HTTP error back to the client due to a transport failure.

Message #

Sending HTTP error back to the client due to a transport failure.
The HTTP status code is %1
The error code is %2

Fields #

NameDescription
httpStatus UInt16
errorCode UInt32
extraErrorInfo1 UnicodeString
extraErrorInfo2 UnicodeString

Event ID 1049 — Sending timeout response for operation: operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Sending timeout response for operation: operationName.

Message #

Sending timeout response for operation: %1

Fields #

NameDescription
operationName UnicodeString

Event ID 1050 — Sending response for operation operationName.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Sending response for operation operationName.

Message #

Sending response for operation %1

Fields #

NameDescription
operationName UnicodeString

Event ID 1051 — Received the response from Network layer; status: status.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling

Description

Received the response from Network layer; status: status.

Message #

Received the response from Network layer; status: %1

Fields #

NameDescription
status UInt32NTSTATUS reference

Event ID 1052 — WSMan operation operationName completed successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Responsehandling
Opcode
Stop

Description

WSMan operation operationName completed successfully.

Message #

WSMan operation %1 completed successfully

Fields #

NameDescription
operationName UnicodeString

Event ID 1053 — WSMan operation operationName got suspended because of WSMan Shell disconnection.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WinrmOperation
Opcode
Stop

Description

WSMan operation operationName got suspended because of WSMan Shell disconnection.

Message #

WSMan operation %1 got suspended because of WSMan Shell disconnection.

Fields #

NameDescription
operationName UnicodeString

Event ID 1054 — WSMan operation operationName resuming because of WSMan Shell reconnection.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WinrmOperation
Opcode
Stop

Description

WSMan operation operationName resuming because of WSMan Shell reconnection.

Message #

WSMan operation %1 resuming because of WSMan Shell reconnection.

Fields #

NameDescription
operationName UnicodeString

Event ID 1280 — Sending HTTP 401 response to the client and disconnect the connection after sending the response

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Sending HTTP 401 response to the client and disconnect the connection after sending the response.

Message #

Sending HTTP 401 response to the client and disconnect the connection after sending the response

Event ID 1281 — User {username} authenticated successfully using {authenticationMechanism} authentication.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

User {username} authenticated successfully using {authenticationMechanism} authentication.

Message #

User {username} authenticated successfully using {authenticationMechanism} authentication

Fields #

NameDescription
username
authenticationMechanism

Event ID 1282 — The authentication using client certificate with subject {subject} done successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The authentication using client certificate with subject {subject} done successfully.

Message #

The authentication using client certificate with subject {subject} done successfully

Fields #

NameDescription
subject

Event ID 1283 — Authenticating the user using {authentication} mechanism.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Authenticating the user using {authentication} mechanism.

Message #

Authenticating the user using {authentication} mechanism

Fields #

NameDescription
authentication

Event ID 1285 — Authenticating the user failed.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

Authenticating the user failed. The credentials didn't work.

Message #

Authenticating the user failed. The credentials didn't work.

Event ID 1286 — The authentication mechanism ({authClient}) requested by the client is not supported by the server.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The authentication mechanism ({authClient}) requested by the client is not supported by the server.Possible authentication mechanisms reported by server: {authServer1} {authServer2} {authServer3} {authServer4} {authServer5}

Fields #

NameDescription
authClient
authServer1
authServer2
authServer3
authServer4
authServer5

Event ID 1287 — The destination computer ({destinationMachine}) returned an 'access denied' error.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The destination computer ({destinationMachine}) returned an 'access denied' error.Possible authentication mechanisms reported by server: {authServer1} {authServer2} {authServer3} {authServer4} {authServer5}.Verify your credentials are correct.

Fields #

NameDescription
destinationMachine
authServer1
authServer2
authServer3
authServer4
authServer5

Event ID 1288 — The authentication mechanism requested by the proxy is not supported by the client.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The authentication mechanism requested by the proxy is not supported by the client. The only proxy authentication mechanism supported are Negotiate; Basic or Digest. Possible authentication mechanisms reported by proxy: {authProxy1} {authProxy2} {authProxy3} {authProxy4} {authProxy5}

Fields #

NameDescription
authProxy1
authProxy2
authProxy3
authProxy4
authProxy5

Event ID 1289 — The chosen authentication mechanism is {auth}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The chosen authentication mechanism is {auth}.

Message #

The chosen authentication mechanism is {auth}

Fields #

NameDescription
auth

Event ID 1291 — Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response from Network layer

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response from Network layer.

Message #

Network layer AutoLogon policy was set to Low as a result of a HTTP 401 response from Network layer

Event ID 1292 — Network layer AutoLogon policy was set to High

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

Network layer AutoLogon policy was set to High.

Message #

Network layer AutoLogon policy was set to High

Event ID 1293 — The chosen authentication mechanism is auth.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

The chosen authentication mechanism is auth.

Message #

The chosen authentication mechanism is %1

Fields #

NameDescription
auth UnicodeString

Event ID 1294 — Sending HTTP 401 response to the client and disconnect the connection after sending the response

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

Sending HTTP 401 response to the client and disconnect the connection after sending the response.

Message #

Sending HTTP 401 response to the client and disconnect the connection after sending the response

Event ID 1295 — User username authenticated successfully using authenticationMechanism authentication.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

User username authenticated successfully using authenticationMechanism authentication.

Message #

User %1 authenticated successfully using %2 authentication

Fields #

NameDescription
username UnicodeString
authenticationMechanism UnicodeString

Event ID 1296 — The authentication using client certificate with subject subject done successfully.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

The authentication using client certificate with subject subject done successfully.

Message #

The authentication using client certificate with subject %1 done successfully

Fields #

NameDescription
subject UnicodeString

Event ID 1297 — Authenticating the user using authentication mechanism.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

Authenticating the user using authentication mechanism.

Message #

Authenticating the user using %1 mechanism

Fields #

NameDescription
authentication UnicodeString

Event ID 1536 — Authorizing the user

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthorization

Description

Authorizing the user.

Message #

Authorizing the user

Event ID 1537 — The authorization of the user was done successfully

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthorization

Description

The authorization of the user was done successfully.

Message #

The authorization of the user was done successfully

Event ID 1538 — The authorization of the user failed with error {errorCode}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The authorization of the user failed with error {errorCode}.

Message #

The authorization of the user failed with error {errorCode}

Fields #

NameDescription
errorCode

Event ID 1792 — The Winrm service is starting

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The Winrm service is starting.

Message #

The Winrm service is starting

Event ID 1793 — The Winrm service started successfully

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The Winrm service started successfully.

Message #

The Winrm service started successfully

Event ID 1794 — The WinRM service is unable to start because of a failure during initialization.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The WinRM service is unable to start because of a failure during initialization. The error code is {errorCode}.

Message #

The WinRM service is unable to start because of a failure during initialization. The error code is {errorCode}

Fields #

NameDescription
errorCode

Event ID 1795 — The Winrm service is stopping

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The Winrm service is stopping.

Message #

The Winrm service is stopping

Event ID 1796 — The Winrm service was stopped successfully

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

The Winrm service was stopped successfully.

Message #

The Winrm service was stopped successfully

Event ID 1797 — The WSMan service could not load current configuration settings as the settings are corrupted.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The WSMan service could not load current configuration settings as the settings are corrupted. The service is started with default settings instead.  User Action  Use the following command to restore defaults:  winrm invoke Restore winrm/config @{}

Event ID 1798 — The WSMan client could not load current configuration settings as the settings are corrupted.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The WSMan client could not load current configuration settings as the settings are corrupted. The client is operating with default settings instead.  User Action  Start the WinRM service and use the following command to restore defaults:  winrm invoke Restore winrm/config @{}

Event ID 1799 — The WSMan service failed to read configuration of the following plugin: {pluginName}.

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Message #

The WSMan service failed to read configuration of the following plugin:  {pluginName}. The error received was {errorcode}: %%{errorcode}  {errordetail}. User Action  Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName
errorcode
errordetail

Event ID 1808 —

Provider
Microsoft-Windows-WinRM
Channel
Analytic

Description

{message}.

Message #

{message}

Fields #

NameDescription
message

Event ID 1840 — An error was encountered while processing an operation.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WinrmOperation

Description

An error was encountered while processing an operation.

Message #

An error was encountered while processing an operation.
Error Code: %1
Error String:%2

Fields #

NameDescription
errorCode UInt32
errorString UnicodeString
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Event ID 1841 — An error was encountered while processing an operation.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WinrmOperation

Description

An error was encountered while processing an operation.

Message #

An error was encountered while processing an operation.
Error Code: %1

Fields #

NameDescription
errorCode UInt32
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Event ID 1842 — Extra information.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
WinrmOperation

Description

Extra information. Refer to the XML parameters for more details.

Message #

Extra information.  Refer to the XML parameters for more details.

Fields #

NameDescription
level UInt32
extraInformation1 UnicodeString
extraInformation2 UnicodeString
extraInformation3 UnicodeString
extraInformation4 UnicodeString

Event ID 1843 — An unauthenticated connection from client clientIP is terminated.

Provider
Microsoft-Windows-WinRM
Channel
Analytic
Task
Userauthentication

Description

An unauthenticated connection from client clientIP is terminated.

Message #

An unauthenticated connection from client %1 is terminated.

Fields #

NameDescription
clientIP UnicodeString

Event ID 2048 — [Filename:- param1; Line:- param2; Function:- param3;] param4.

Provider
Microsoft-Windows-WinRM
Channel
Debug
Task
WinrmVerboseMessage

Description

[Filename:- param1; Line:- param2; Function:- param3;] param4.

Message #

[Filename:- %1; Line:- %2; Function:- %3;] %4

Fields #

NameDescription
param1 UnicodeString
param2 UInt32
param3 UnicodeString
param4 UnicodeString

Event ID 2049 — [Filename:- param1; Line:- param2; Function:- param3; ErrorCode:- param4] param5.

Provider
Microsoft-Windows-WinRM
Channel
Debug
Task
WinrmVerboseMessage

Description

[Filename:- param1; Line:- param2; Function:- param3; ErrorCode:- param4] param5.

Message #

[Filename:- %1; Line:- %2; Function:- %3; ErrorCode:- %4] %5

Fields #

NameDescription
param1 UnicodeString
param2 UInt32
param3 UnicodeString
param4 UInt32
param5 UnicodeString

Event ID 10148 —

#
Provider
Microsoft-Windows-WinRM
Channel
System
Level
Informational

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "WinRM",
    "event_id": 10148,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:53:23.372389+00:00",
    "event_record_id": 1223,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Name": "Started Listening"
  },
  "message": ""
}

References #

Event ID 10149 —

#
Provider
Microsoft-Windows-WinRM
Channel
System
Level
Warning

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "WinRM",
    "event_id": 10149,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:45:07.008717+00:00",
    "event_record_id": 157,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Name": "Stopped Listening"
  },
  "message": ""
}

References #

Event ID 10154 —

#
Provider
Microsoft-Windows-WinRM
Channel
System
Level
Warning

Fields #

NameDescription
spn1
spn2
error

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WinRM",
    "guid": "{A7975C8F-AC13-49F1-87DA-5A984A4AB417}",
    "event_source_name": "WinRM",
    "event_id": 10154,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2022-04-07T16:53:23.388188+00:00",
    "event_record_id": 1224,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "spn1": "WSMAN/WIN-FPV0DSIC9O6.lab.local",
    "spn2": "WSMAN/WIN-FPV0DSIC9O6",
    "error": "1355"
  },
  "message": ""
}

References #

Event ID 468853 — The WinRM service is not listening for requests since it failed to listen on at least one address and port.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for requests since it failed to listen on at least one address and port.

Message #

The WinRM service is not listening for requests since it failed to listen on at least one address and port. 

 Remote management using WinRM will fail. 

 User Action 
 Configure listeners by enabling GPO policy for Auto Configuration of listeners or manually create a listener using WinRM command line tool.

Event ID 468854 — The WinRM service is not listening for param1 requests because there was a failure binding to the URL (param2) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for param1 requests because there was a failure binding to the URL (param2) in HTTP.SYS.

Message #

The WinRM service is not listening for %1 requests because there was a failure binding to the URL (%2) in HTTP.SYS. 

 Another process is registered to listen on the WinRM service URL prefix. 

 User Action 
 Correct this problem by stopping the other process, changing its URL prefix, or by changing the configuration for the WS-Management listening address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for
param2 UnicodeStringrequests because there was a failure binding to the URL (

Event ID 468855 — The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 Another process is registered to listen on the WinRM client URL prefix. 

 User Action 
 Correct this problem by stopping the other process, changing its URL prefix, or by changing the configuration for the WS-Management listening address.

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (

Event ID 468856 — The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (param1) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (%1) in HTTP.SYS.  

 No remote requests will be serviced on that URL. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys is %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for HTTPS requests because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys is

Event ID 468857 — The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys was %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys was

Event ID 468862 — The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certifi...

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certificate chain is either offline or stale.

Message #

The WinRM service cannot validate the client certificate because the revocation status of the certificate or one of the certificates in the certificate chain is either offline or stale. 

 User Action 
 Please ensure that the Certificate Revocation List is accessible and up-to-date.

Event ID 468863 — User authentication using Basic authentication scheme failed.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

User authentication using Basic authentication scheme failed.

Message #

User authentication using Basic authentication scheme failed. 

 Additional Data 
 Unexpected error received from LogonUser %1: %%%1.

Fields #

NameDescription
param1 UnicodeStringUnexpected error received from LogonUser

Event ID 468864 — The client certificate exceeded the maximum size allowed by the WinRM service.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The client certificate exceeded the maximum size allowed by the WinRM service.

Message #

The client certificate exceeded the maximum size allowed by the WinRM service.

 User Action 
 Please use a different client certificate or a different authentication mechanism.

Event ID 468865 — Request processing failed because the WinRM service cannot load data or event source: DLL="param1" User Action Please check if "param1" exists.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

Request processing failed because the WinRM service cannot load data or event source: DLL="param1".

Message #

Request processing failed because the WinRM service cannot load data or event source: DLL="%1" 

 User Action 
 Please check if "%1" exists. 

 Additional Data 
 Loading %1 failed with error="%2" (%%%2).

Fields #

NameDescription
param1 UnicodeStringRequest processing failed because the WinRM service cannot load data or event source: DLL="
param2 UnicodeStringfailed with error="

Event ID 468866 — The SSL configuration for IP param1 and port param2 is shared with another service, such as Internet Information Services (IIS).

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The SSL configuration for IP param1 and port param2 is shared with another service, such as Internet Information Services (IIS).

Message #

The SSL configuration for IP %1 and port %2 is shared with another service, such as Internet Information Services (IIS).

Fields #

NameDescription
param1 UnicodeStringThe SSL configuration for IP
param2 UnicodeStringand port

Event ID 468871 — The WinRM service is unable to start because of a failure during initialization.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is unable to start because of a failure during initialization.

Message #

The WinRM service is unable to start because of a failure during initialization. 

 Additional Data 
 The error code is %1.

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468872 — The WinRM service has received an unsecure HTTP connection from param1.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service has received an unsecure HTTP connection from param1.

Message #

The WinRM service has received an unsecure HTTP connection from %1. 

 This is not a secure configuration. 

 User Action 
 Set AllowUnencrypted to False in WinRM configuration to ensure packets are encrypted on the wire.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service has received an unsecure HTTP connection from

Event ID 468873 — The WinRM service has been configured to accept basic authentication for unsecure HTTP connections.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service has been configured to accept basic authentication for unsecure HTTP connections.

Message #

The WinRM service has been configured to accept basic authentication for unsecure HTTP connections. 

 This is not a secure configuration. 

 User Action 
 Set AllowUnencrypted to False in WinRM configuration to ensure packets are encrypted on the wire.

Event ID 468880 — The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (param1) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WinRM service is not listening for HTTP requests because there was a failure binding to the URL (%1) in HTTP.SYS. 

 No remote requests will be serviced on that URL. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys is %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is not listening for HTTP requests because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys is

Event ID 468881 — The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (param1) in HTTP.SYS.

Message #

The WS-Management client is not listening for pushed events because there was a failure binding to the URL (%1) in HTTP.SYS. 

 User Action 
 Please use "netsh http" to check if ACL for URL (%1) is set to Network Service. 

 Additional Data 
 The error code received from HTTP.sys was %2: %%%2

Fields #

NameDescription
param1 UnicodeStringThe WS-Management client is not listening for pushed events because there was a failure binding to the URL (
param2 UnicodeStringThe error code received from HTTP.sys was

Event ID 468882 — IP Filter param1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

IP Filter param1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored. Due to this issue, the WinRM service cannot use the autoconfigured listener.

Message #

IP Filter %1 specified in the GPO policy for Auto Configuration of listeners is invalid and it will be ignored. Due to this issue, the WinRM service cannot use the autoconfigured listener. 

 "*" is used to indicate that the service should listen on all available IPs on the machine. When "*" is used, other ranges cannot be specified in the filter. 

 User Action 
 Remove other IP ranges if "*" needs to be included in the IP Filter.

Fields #

NameDescription
param1 UnicodeStringIP Filter

Event ID 468883 — The IP Range param1 is invalid and it will be ignored.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The IP Range param1 is invalid and it will be ignored.

Message #

The IP Range %1 is invalid and it will be ignored.  

 Ranges are specified using the syntax IP1-IP2. Multiple ranges are separated using "," as delimiter. 
 Example IPv4 ranges:  2.0.0.1-2.0.0.20, 24.0.0.1-24.0.0.22 
Example IPv6 ranges:  3FFE:FFFF:7654:FEDA:1245:BA98:0000:0000-3FFE:FFFF:7654:FEDA:1245:BA98:3210:4562 

 User Action 
 Correct the IP filter %1 using the syntax described above.

Fields #

NameDescription
param1 UnicodeStringThe IP Range

Event ID 468884 — The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management poli...

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management policy key.

Message #

The WinRM service is not listening for policy changes because there was a failure registering for changes to the contents of the WS-Management policy key. 

 No group policy change will be serviced. 

 User Action 
 Stop and restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeStringThe error code was

Event ID 468888 — The WinRM service encountered a catastrophic security failure.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service encountered a catastrophic security failure. The service can no longer run under its security context.

Message #

The WinRM service encountered a catastrophic security failure. The service can no longer run under its security context. 

 User Action 
 Stop and restart the WinRM service. 

 Additional Data 
 The error code is %1.

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468889 — The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the IP address does not exist on the destination computer.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the IP address does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with IP address %1 and Port %2 because the IP address does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct IP address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeStringand Port

Event ID 468890 — The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the IP address param3 does not exist on the destination computer.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the IP address param3 does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2 because the IP address %3 does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct IP address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport
param3 UnicodeStringbecause the IP address

Event ID 468891 — The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the MAC address param3 does not exist on the destination computer.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1 and Port param2 because the MAC address param3 does not exist on the destination computer. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with IP address %1 and Port %2 because the MAC address %3 does not exist on the destination computer. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct MAC address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeStringand Port
param3 UnicodeStringbecause the MAC address

Event ID 468892 — The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the MAC address param3 does not exist on the destination machine.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2 because the MAC address param3 does not exist on the destination machine. This listener was ignored during migration.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2 because the MAC address %3 does not exist on the destination machine. This listener was ignored during migration. 

 User Action 
 Create the listener again with the correct MAC address.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport
param3 UnicodeStringbecause the MAC address

Event ID 468893 — The WinRM service cannot migrate the listener with IP address param1, Port param2 and Transport param3.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with IP address param1, Port param2 and Transport param3. A listener that has Address=param4 and Transport=param5 configuration already exists.

Message #

The WinRM service cannot migrate the listener with IP address %1, Port %2 and Transport %3. A listener that has Address=%4 and Transport=%5 configuration already exists.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with IP address
param2 UnicodeString, Port
param3 UnicodeStringand Transport
param4 UnicodeString. A listener that has Address=
param5 UnicodeStringand Transport=

Event ID 468894 — The WinRM service cannot migrate the listener with Address param1 and Transport param2.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service cannot migrate the listener with Address param1 and Transport param2. A listener that has the same Address and Transport configuration already exists.

Message #

The WinRM service cannot migrate the listener with Address %1 and Transport %2. A listener that has the same Address and Transport configuration already exists.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service cannot migrate the listener with Address
param2 UnicodeStringand Transport

Event ID 468895 — The WinRM service had a failure during migration.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service had a failure during migration.

Message #

The WinRM service had a failure during migration. 

 User Action 
 Create the configuration again using the WinRM command line tool. 

 Additional Data 
 The error code is: %1 %%%1

Fields #

NameDescription
param1 UnicodeStringThe error code is
param2 UnicodeString

Event ID 468896 — The WinRM service had a failure reading the current configuration and is stopping.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service had a failure reading the current configuration and is stopping.

Message #

The WinRM service had a failure reading the current configuration and is stopping. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{} 

 Then add any custom configuration settings and restart the service. 

 Additional Data 
 The error code is: %1 %%%1

Fields #

NameDescription
param1 UnicodeStringThe error code is

Event ID 468897 — The WinRM service had a failure applying the current configuration and is stopping.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service had a failure applying the current configuration and is stopping.

Message #

The WinRM service had a failure applying the current configuration and is stopping. 

 User Action 
 Check for previous event log messages and restart the service.

Fields #

NameDescription
param1 UnicodeString

Event ID 468898 — The WinRM service had a failure reading the current configuration and is stopping.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service had a failure reading the current configuration and is stopping.

Message #

The WinRM service had a failure reading the current configuration and is stopping. 

 User Action 
 Use the following command to restore defaults: 

 winrm invoke Restore winrm/config @{} 

 Then add any custom configuration settings and restart the service. 

 Additional Data 
 The error code is: %1 %%%1

Event ID 468899 — The host name pattern "param1" is invalid and it will be ignored.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Message #

The host name pattern "%1" is invalid and it will be ignored. Host name patterns must not be empty and they can contain at most one wildcard ("*"). "*" pattern can be used to indicate all hosts; if this pattern is used, no other pattern can show up in the list. Special string "<local>" can be used to indicate all host names that do not have a '.'

 User Action 
 Correct the host name pattern using the syntax described above.

Fields #

NameDescription
param1 UnicodeStringThe host name pattern "

Event ID 468900 — The WinRM service is listening for WS-Management requests.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is listening for WS-Management requests.

Message #

The WinRM service is listening for WS-Management requests. 

 User Action 
 Use the following command to see the specific IPs on which WinRM is listening: 

 winrm enumerate winrm/config/listener

Event ID 468901 — The WinRM service is not listening for WS-Management requests.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is not listening for WS-Management requests.

Message #

The WinRM service is not listening for WS-Management requests. 

 User Action 
 If you did not intentionally stop the service, use the following command to see the WinRM configuration: 

 winrm enumerate winrm/config/listener

Event ID 468902 — The WinRM service could not use the following listener to receive WS-Management requests.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service could not use the following listener to receive WS-Management requests. The listener is enabled but the listener does not have an IP address configured.

Message #

The WinRM service could not use the following listener to receive WS-Management requests.  The listener is enabled but the listener does not have an IP address configured. 

 User Action 
 Check the underlying network configuration to determine if this listener has at least one valid IP. If the IP is valid, ensure that WinRM configuration does not exclude that IP address by using the following command: 

 winrm get winrm/config/service 

 Additional Data 
 Listener transport: %1 
 Listener address: %2

Fields #

NameDescription
transport UnicodeStringListener transport
address UnicodeStringListener address

Event ID 468903 — The WinRM service had a failure (param1) reading configuration during ip address change notification.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service had a failure (param1) reading configuration during ip address change notification.

Message #

The WinRM service had a failure (%1) reading configuration during ip address change notification. 

 Service will continue running with old configuration.

 User Action 
 If immediae changes are required manually restart the service

Fields #

NameDescription
param1 UnicodeStringThe WinRM service had a failure (

Event ID 468904 — The WinRM service successfully processed an address change notification.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service successfully processed an address change notification.

Message #

The WinRM service successfully processed an address change notification.

Event ID 468905 — The WSMan IIS module failed to read configuration.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WSMan IIS module failed to read configuration. The error received was : %.

Message #

The WSMan IIS module failed to read configuration. The error received was %1: %%%1 
 %2.

 User Action 
 Make sure both the schema and validation files are present and valid.

Fields #

NameDescription
errorcode UnicodeStringThe WSMan IIS module failed to read configuration. The error received was
errordetail UnicodeString

Event ID 468906 — The WinRM service failed to create the following SPNs: spn1; spn2.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service failed to create the following SPNs: spn1; spn2.

Message #

The WinRM service failed to create the following SPNs: %1; %2. 

 Additional Data 
 The error received was %3: %%%3.

 User Action 
 The SPNs can be created by an administrator using setspn.exe utility.

Fields #

NameDescription
spn1 UnicodeStringThe WinRM service failed to create the following SPNs
spn2 UnicodeString
error UnicodeStringThe error received was

Event ID 468907 — The WSMan service failed to read configuration of the following plugin.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WSMan service failed to read configuration of the following plugin.

Message #

The WSMan service failed to read configuration of the following plugin: 
 %1. 

The error received was %2: %%%2 
 %3.

 User Action 
 Make sure this plugin configuration is valid.

Fields #

NameDescription
pluginName UnicodeString
errorcode UnicodeStringThe error received was
errordetail UnicodeString

Event ID 468908 — The WinRM service failed to initialize CredSSP.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service failed to initialize CredSSP.

Message #

The WinRM service failed to initialize CredSSP. 

 Additional Data 
 The error received was %1.

 User Action 
 Configure CertificateThumbprint setting under the WinRM configuration for the service. Use the thumbprint of a valid certificate and make sure that Network Service has access to the private key of the certificate.

Fields #

NameDescription
error UnicodeStringThe error received was

Event ID 468909 — The WinRM service received an error while trying to unloading a data or event source: DLL="param1" User Action Please check if there is an updated vers...

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service received an error while trying to unloading a data or event source: DLL="param1".

Message #

The WinRM service received an error while trying to unloading a data or event source: DLL="%1" 

 User Action 
 Please check if there is an updated version of this file available: "%1". 

 Additional Data 
 Shutting down %1 failed with error="%2" (%%%2).

Fields #

NameDescription
param1 UnicodeStringThe WinRM service received an error while trying to unloading a data or event source: DLL="
param2 UnicodeStringfailed with error="

Event ID 468910 — The WinRM service is listening on the default param1 port param2 and on param1 (Compatibility) port param3 for WS-Management requests.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is listening on the default port and on (Compatibility) port for WS-Management requests. port is no longer the default port for the WinRM service.

Message #

The WinRM service is listening on the default %1 port %2 and on %1 (Compatibility) port %3 for WS-Management requests. %1 port %3 is no longer the default port for the WinRM service.

 If you want to disable the listener on the (Compatibility) port %3, run the following command:

 Winrm set winrm/config/service @{%4="False"}

Fields #

NameDescription
param1 UnicodeStringThe WinRM service is listening on the default
param2 UnicodeString
param3 UnicodeString(Compatibility) port
param4 UnicodeStringWinrm set winrm/config/service @{

Event ID 468911 — The WinRM service has terminated param1 unauthenticated connections over the past param2 minutes to maintain healthy system state.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Message #

The WinRM service has terminated %1 unauthenticated connections over the past %2 minutes to maintain healthy system state. This will likely happen if the service is overloaded or if the service is under an authentication based attack. 

 Action: 
Enable and observe Windows Remote Management Analytic log and look for warning events with Id 1843. These include additional information about the clients that got abruptly terminated.

Fields #

NameDescription
param1 UnicodeStringThe WinRM service has terminated
param2 UnicodeStringunauthenticated connections over the past

Event ID 3221734403 — The WinRM service is stopping because there was a failure registering for changes to the IP addresses.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is stopping because there was a failure registering for changes to the IP addresses.

Message #

The WinRM service is stopping because there was a failure registering for changes to the IP addresses. 

 User Action 
 Restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeString

Event ID 3221734404 — The WinRM service is stopping because there was a failure registering for changes to the configuration.

Provider
Microsoft-Windows-WinRM
Channel
Operational

Description

The WinRM service is stopping because there was a failure registering for changes to the configuration.

Message #

The WinRM service is stopping because there was a failure registering for changes to the configuration. 

 User Action 
 Restart the WinRM service. 

 Additional Data 
 The error code was %1.

Fields #

NameDescription
param1 UnicodeString