Microsoft-Windows-Winsrv

13 events across 2 channels

Event IDTitleChannel
10001The following application attempted to veto the shutdown: VetoAppEvent.AppName.Application
10002The following application was terminated because it was hung: ServerManager.Application
12001Analytic
12002Analytic
12003Analytic
12005Analytic
12006Analytic
12007Analytic
12008Analytic
12009Analytic
12010Analytic
12011Analytic
12012Analytic

Event ID 10001 — The following application attempted to veto the shutdown: VetoAppEvent.AppName.

Provider
Microsoft-Windows-Winsrv
Channel
Application
Level
Informational
Opcode
Info

Description

The following application attempted to veto the shutdown: VetoAppEvent.AppName.

Message #

The following application attempted to veto the shutdown: %1.

Fields #

NameDescription
VetoAppEvent.AppName UnicodeString
VetoAppEvent.ResponseTime UInt32
AppName UnicodeString
ResponseTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsrv",
    "guid": "9D55B53D-449B-4824-A637-24F9D69AA02F",
    "event_source_name": "",
    "event_id": 10001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-14T21:57:27.378644+00:00",
    "event_record_id": 5369,
    "correlation": {},
    "execution": {
      "process_id": 788,
      "thread_id": 4912
    },
    "channel": "Application",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "VetoAppEvent": {
      "AppName": "WINWORD.EXE",
      "ResponseTime": 141
    }
  },
  "message": ""
}

Event ID 10002 — The following application was terminated because it was hung: ServerManager.

#
Provider
Microsoft-Windows-Winsrv
Channel
Application
Level
Informational
Opcode
Info

Description

The following application was terminated because it was hung: .

Message #

The following application was terminated because it was hung: %1.

Fields #

NameDescription
HungAppEvent.AppName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Winsrv",
    "guid": "9D55B53D-449B-4824-A637-24F9D69AA02F",
    "event_source_name": "",
    "event_id": 10002,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-03-04T12:03:13.945898+00:00",
    "event_record_id": 68,
    "correlation": {},
    "execution": {
      "process_id": 464,
      "thread_id": 3484
    },
    "channel": "Application",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "HungAppEvent": {
      "AppName": "ServerManager.exe"
    }
  },
  "message": "The following application was terminated because it was hung: ServerManager.exe."
}

References #

Event ID 12001 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
ThreadShutdown
Opcode
Start

Fields #

NameDescription
ThreadId UInt32
Flags UInt32
ProcessId UInt32

Event ID 12002 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
ThreadShutdown
Opcode
Stop

Fields #

NameDescription
Command UInt32
ThreadId UInt32

Event ID 12003 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
ThreadShutdown_SentMessage

Fields #

NameDescription
MessageId UInt32
Flags UInt32
ThreadId UInt32

Event ID 12005 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
TerminateProcess
Opcode
Start

Fields #

NameDescription
ProcessId UInt32

Event ID 12006 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
TerminateProcess
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
TerminateStatus UInt32

Event ID 12007 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
WaitForProcess
Opcode
Start

Fields #

NameDescription
ProcessId UInt32

Event ID 12008 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
WaitForProcess
Opcode
Stop

Fields #

NameDescription
WaitStatus UInt32
ProcessId UInt32

Event ID 12009 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
ShutdownProcess
Opcode
Start

Fields #

NameDescription
ProcessId UInt32
Flags UInt32

Event ID 12010 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
ShutdownProcess
Opcode
Stop

Fields #

NameDescription
ProcessId UInt32
Status UInt32NTSTATUS reference

Event ID 12011 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
NotificationEvent
Opcode
Start

Fields #

NameDescription
EventType UInt32

Event ID 12012 —

Provider
Microsoft-Windows-Winsrv
Channel
Analytic
Task
NotificationEvent
Opcode
Stop

Fields #

NameDescription
EventType UInt32