Microsoft-Windows-Winsock-NameResolution
16 events across 1 channel
Event ID 1000 — GetAddrInfoW is called for queryName NodeName, serviceName ServiceName, flags Flags, family Family, socketType SocketType, protocol Protocol and seq Location.
Description
GetAddrInfoW is called for queryName NodeName, serviceName ServiceName, flags Flags, family Family, socketType SocketType, protocol Protocol and seq Location.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
ServiceName UnicodeString | — |
Location UInt32 | — |
Flags UInt32 | — |
Family UInt32 | — |
SocketType UInt32 | — |
Protocol UInt32 | — Known values
|
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:41.692985+00:00",
"event_record_id": 17,
"correlation": {
"ActivityID": "4EC9235F-7114-46CF-A033-E58E6B97986C"
},
"execution": {
"process_id": 832,
"thread_id": 3636
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "ludus",
"ServiceName": "NULL",
"Location": 118,
"Flags": 5,
"Family": 0,
"SocketType": 0,
"Protocol": 0
},
"message": ""
}
Event ID 1001 — GetAddrInfoW is completed for queryName NodeName with status Status and result Result.
Description
GetAddrInfoW is completed for queryName NodeName with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Result UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:41.692988+00:00",
"event_record_id": 18,
"correlation": {
"ActivityID": "4EC9235F-7114-46CF-A033-E58E6B97986C"
},
"execution": {
"process_id": 832,
"thread_id": 3636
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "ludus",
"Status": 11001,
"Result": ""
},
"message": ""
}
Event ID 1002 — GetAddrInfoExW is called for queryName NodeName, serviceName ServiceName, nameSpace NameSpace, nameSpace GUID NameSpaceGuid, flags Flags, family Family, socketType SocketType, protocol protocol, in...
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
ServiceName UnicodeString | — |
Location UInt32 | — |
NameSpace UInt32 | — |
NameSpaceGuid GUID | — |
Flags UInt32 | — |
Family UInt32 | — |
SocketType UInt32 | — |
protocol UInt32 | — |
InterfaceIndex UInt32 | — |
TimeOutInSec UInt32 | — |
AsyncWithCallback UInt32 | — |
AsyncWithOverlapped UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1002,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033434+00:00",
"event_record_id": 188,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceName": "NULL",
"Location": 226,
"NameSpace": 12,
"NameSpaceGuid": "00000000-0000-0000-0000-000000000000",
"Flags": 131074,
"Family": 0,
"SocketType": 1,
"protocol": 6,
"InterfaceIndex": 0,
"TimeOutInSec": 0,
"AsyncWithCallback": 0,
"AsyncWithOverlapped": 1
},
"message": ""
}
Event ID 1003 — GetAddrInfoExW asynchronous query is pending for queryName: NodeName with cancel Handle CancelHandle.
Description
GetAddrInfoExW asynchronous query is pending for queryName: NodeName with cancel Handle CancelHandle.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
CancelHandle UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1003,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033473+00:00",
"event_record_id": 195,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"CancelHandle": 0
},
"message": ""
}
Event ID 1004 — GetAddrInfoExW is completed for queryName NodeName with status Status and result Result.
Description
GetAddrInfoExW is completed for queryName NodeName with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
Status UInt32 | — NTSTATUS reference |
Result UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1004,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.072980+00:00",
"event_record_id": 206,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"Status": 0,
"Result": "20.42.65.85;"
},
"message": ""
}
Event ID 1005 — GetAddrInfoExCancel is called for query CancelHandle and seq Location.
Event ID 1006 — NSPLookupServiceBegin is called for provider ProviderGUID, queryName QueryName, serviceGUID ServiceGUID, interface index InterfaceIndex and control flags ControlFlags.
Description
NSPLookupServiceBegin is called for provider ProviderGUID, queryName QueryName, serviceGUID ServiceGUID, interface index InterfaceIndex and control flags ControlFlags.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
QueryName UnicodeString | — |
ServiceGUID GUID | — |
InterfaceIndex UInt32 | — |
ControlFlags UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1006,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033445+00:00",
"event_record_id": 189,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"QueryName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceGUID": "0002A803-0000-0000-C000-000000000046",
"InterfaceIndex": 0,
"ControlFlags": 3146000
},
"message": ""
}
Event ID 1007 — NSPLookupServiceBegin is completed for provider ProviderGUID, queryName QueryName serviceGUID ServiceGUID, interface index InterfaceIndex, control flags ControlFlags and lookup handle LookupHandle ...
Description
NSPLookupServiceBegin is completed for provider ProviderGUID, queryName QueryName serviceGUID ServiceGUID, interface index InterfaceIndex, control flags ControlFlags and lookup handle LookupHandle with status Status.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
QueryName UnicodeString | — |
ServiceGUID GUID | — |
InterfaceIndex UInt32 | — |
ControlFlags UInt32 | — |
LookupHandle UInt64 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1007,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033450+00:00",
"event_record_id": 190,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"QueryName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceGUID": "0002A803-0000-0000-C000-000000000046",
"InterfaceIndex": 0,
"ControlFlags": 3146000,
"LookupHandle": 1894238103792,
"Status": 0
},
"message": ""
}
Event ID 1008 — NSPLookupServiceNext is called for provider ProviderGUID, control Flags ControlFlags and lookup handle LookupHandle.
Description
NSPLookupServiceNext is called for provider ProviderGUID, control Flags ControlFlags and lookup handle LookupHandle.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
ControlFlags UInt32 | — |
LookupHandle UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1008,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033491+00:00",
"event_record_id": 196,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"ControlFlags": 0,
"LookupHandle": 1894238104368
},
"message": ""
}
Event ID 1009 — NSPLookupServiceNext is completed for provider ProviderGUID, control Flags ControlFlags and lookup Handle LookupHandle with status Status and result Result.
Description
NSPLookupServiceNext is completed for provider ProviderGUID, control Flags ControlFlags and lookup Handle LookupHandle with status Status and result Result.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
ControlFlags UInt32 | — |
LookupHandle UInt64 | — |
Status UInt32 | — NTSTATUS reference |
Result UnicodeString | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1009,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033541+00:00",
"event_record_id": 198,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"ControlFlags": 0,
"LookupHandle": 1894238103792,
"Status": 11001,
"Result": ""
},
"message": ""
}
Event ID 1010 — NSPLookupServiceEnd is called for provider ProviderGUID and lookup handle LookupHandle.
Description
NSPLookupServiceEnd is called for provider ProviderGUID and lookup handle LookupHandle.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
LookupHandle UInt64 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1010,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033551+00:00",
"event_record_id": 199,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"LookupHandle": 1894238103792
},
"message": ""
}
Event ID 1011 — NSPLookupServiceEnd completed for provider ProviderGUID and lookup handle LookupHandle with status Status.
Description
NSPLookupServiceEnd completed for provider ProviderGUID and lookup handle LookupHandle with status Status.
Message #
Fields #
| Name | Description |
|---|---|
ProviderGUID GUID | — |
LookupHandle UInt64 | — |
Status UInt32 | — NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1011,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033553+00:00",
"event_record_id": 200,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 7344
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ProviderGUID": "22059D40-7E9E-11CF-AE5A-00AA00A7112B",
"LookupHandle": 1894238103792,
"Status": 0
},
"message": ""
}
Event ID 1012 — GetAddrInfoExW info.
Message #
Fields #
| Name | Description |
|---|---|
NodeName UnicodeString | — |
ServiceName UnicodeString | — |
Location UInt32 | — |
NameSpace UInt32 | — |
NameSpaceGuid GUID | — |
Flags UInt32 | — |
Family UInt32 | — |
SocketType UInt32 | — |
protocol UInt32 | — |
InterfaceIndex UInt32 | — |
TimeOutInSec UInt32 | — |
AsyncWithCallback UInt32 | — |
AsyncWithOverlapped UInt32 | — |
Error Int32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1012,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:57.033417+00:00",
"event_record_id": 187,
"correlation": {
"ActivityID": "30000002-0002-FE00-D015-D40C380D840C"
},
"execution": {
"process_id": 3384,
"thread_id": 3204
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"NodeName": "us-v20.events.endpoint.security.microsoft.com",
"ServiceName": "NULL",
"Location": 307,
"NameSpace": 12,
"NameSpaceGuid": "00000000-0000-0000-0000-000000000000",
"Flags": 131074,
"Family": 0,
"SocketType": 1,
"protocol": 6,
"InterfaceIndex": 0,
"TimeOutInSec": 0,
"AsyncWithCallback": 0,
"AsyncWithOverlapped": 1,
"Error": 0
},
"message": ""
}
Event ID 1013 — Wsa Startup.
Description
Wsa Startup. seq: Location.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1013,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:38.230772+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
},
"execution": {
"process_id": 6952,
"thread_id": 6108
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"Location": 101
},
"message": ""
}
Event ID 1014 — Wsa Cleanup.
Description
Wsa Cleanup. seq: Location. Refcount: RefCount.
Message #
Fields #
| Name | Description |
|---|---|
Location UInt32 | — |
RefCount UInt32 | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Winsock-NameResolution",
"guid": "55404E71-4DB9-4DEB-A5F5-8F86E46DDE56",
"event_source_name": "",
"event_id": 1014,
"version": 0,
"level": 4,
"task": 1000,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T19:59:38.230787+00:00",
"event_record_id": 2,
"correlation": {
"ActivityID": "DF92C490-B30B-0005-A2C8-92DF0BB3DC01"
},
"execution": {
"process_id": 6952,
"thread_id": 6108
},
"channel": "Microsoft-Windows-Winsock-NameResolution/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"Location": 201,
"RefCount": 2
},
"message": ""
}