Microsoft-Windows-WMI
62 events across 1 channel
Event ID 4 — Error %1 encountered when trying to load MOF %2 while recovering .
Message
Fields
| Name | Description |
|---|---|
Error | — |
MOF | — |
Event ID 10 — Event filter with query ".
Message
Fields
| Name | Description |
|---|---|
Query | — |
Namespace | — |
Error | — |
Event ID 21 — Event provider %1 attempted to register a syntactically invalid query "%2".
Message
Fields
| Name | Description |
|---|---|
EventProvider | — |
Query | — |
Event ID 22 — Event provider %1 attempted to register an intrinsic event query "%2" in %3 namespace for which the set of target object classes could not be deter...
Message
Fields
| Name | Description |
|---|---|
EventProvider | — |
Query | — |
Namespace | — |
Event ID 23 — Event provider %1 attempted to register query "%2" in %3 namespace which is too broad.
Message
Fields
| Name | Description |
|---|---|
EventProvider | — |
Query | — |
Namespace | — |
Event ID 24 — Event provider %1 attempted to register query "%2" whose target class "%3" in %4 namespace does not exist.
Message
Fields
| Name | Description |
|---|---|
EventProvider | — |
Query | — |
Class | — |
Namespace | — |
Event ID 25 — Event provider %1 attempted to register query "%2" whose target class "%3" is not an event class.
Message
Fields
| Name | Description |
|---|---|
EventProvider | — |
Query | — |
Class | — |
Event ID 28 — Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number %1.
Message
Fields
| Name | Description |
|---|---|
ErrorNumber | — |
Event ID 29 — Error number %1 was returned in trying to initialize Windows Management Instrumentation Service.
Message
Fields
| Name | Description |
|---|---|
ErrorNumber | — |
Event ID 43 — Windows Management Instrumentation ADAP failed to connect to namespace %1 with the following error %2.
Message
Fields
| Name | Description |
|---|---|
Namespace | — |
Error | — |
Event ID 48 — Windows Management Instrumentation ADAP was unable to save object %1 in namespace %2 because of the following error %3.
Message
Fields
| Name | Description |
|---|---|
Object | — |
Namespace | — |
Error | — |
Event ID 58 — Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in %1:Result=%2.
Message
Fields
| Name | Description |
|---|---|
Class | — |
Result | — |
Event ID 59 — Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class %1.
Message
Fields
| Name | Description |
|---|---|
Class | — |
Event ID 63 — A provider, NlbsNicProv, has been registered in the Windows Management Instrumentation namespace Root\microsoftnlb to use the LocalSystem account.
Message
Fields
| Name | Description |
|---|---|
data_0x8000003F.Provider | — |
data_0x8000003F.Namespace | — |
Example Event
system:
provider: Microsoft-Windows-WMI
guid: 1EDEEE53-0AFE-4609-B846-D8C0B2075B1F
event_source_name: ''
event_id: 63
version: 2
level: 3
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2022-04-04T11:12:30.841914+00:00'
event_record_id: 181
correlation: {}
execution:
process_id: 1136
thread_id: 2060
channel: Application
computer: WIN-TKC15D7KHUR
security:
user_id: S-1-5-18
user_data:
data_0x8000003F:
Provider: NlbsNicProv
Namespace: Root\microsoftnlb
message: A provider, NlbsNicProv, has been registered in the Windows Management Instrumentation
namespace Root\microsoftnlb to use the LocalSystem account. This account is privileged
and the provider may cause a security violation if it does not correctly impersonate
user requests.
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 65 — Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
Message
Event ID 66 — The Windows Management Instrumentation Service has recovered from the following backup repository.
Message
Fields
| Name | Description |
|---|---|
BackupRepository | — |
Event ID 67 — The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following f...
Message
Fields
| Name | Description |
|---|---|
BackupFile | — |
Event ID 68 — The Windows Management Instrumentation repository backup operation completed copying data to %1 with error %2.
Message
Fields
| Name | Description |
|---|---|
BackupFile | — |
Error | — |
Event ID 5600 — The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system3...
Message
Event ID 5601 — The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.
Message
Event ID 5602 — The Windows Management Instrumentation service detected an inconsistency in the following backup file.
Message
Fields
| Name | Description |
|---|---|
BackupFile | — |
Event ID 5604 — The Windows Management Instrumentation service encountered the error %1 and was not able to restore from the following backup repository: %2.
Message
Fields
| Name | Description |
|---|---|
Error | — |
BackupRepository | — |
Event ID 5605 — The %1 namespace is marked with the RequiresEncryption flag.
Message
Fields
| Name | Description |
|---|---|
Namespace | — |
Event ID 5606 — Windows Management Instrumentation Service could not deliver results asynchronously for %1 namespace.
Message
Fields
| Name | Description |
|---|---|
Namespace | — |
Event ID 5611 — The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Message
Event ID 5612 — Windows Management Instrumentation has stopped WMIPRVSE.
Message
Fields
| Name | Description |
|---|---|
QuotaName | — |
QuotaValue | — |
QuotaThreshold | — |
HostProcessID | — |
ProvidersInHost | — |
Event ID 5614 — During the service startup, the Windows Management Instrumentation service was unable to locate the repository files.
Message
Event ID 5615 — Windows Management Instrumentation Service started sucessfully
Message
Example Event
system:
provider: Microsoft-Windows-WMI
guid: 1EDEEE53-0AFE-4609-B846-D8C0B2075B1F
event_source_name: ''
event_id: 5615
version: 2
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:43.964888+00:00'
event_record_id: 1440
correlation: {}
execution:
process_id: 3788
thread_id: 3880
channel: Application
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: Windows Management Instrumentation Service started sucessfully
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 5616 — The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Message
Event ID 5617 — Windows Management Instrumentation Service subsystems initialized successfully
Message
Example Event
system:
provider: Microsoft-Windows-WMI
guid: 1EDEEE53-0AFE-4609-B846-D8C0B2075B1F
event_source_name: ''
event_id: 5617
version: 2
level: 4
task: 0
opcode: 0
keywords: 9223372036854775808
time_created: '2023-11-06T06:25:45.613226+00:00'
event_record_id: 1441
correlation: {}
execution:
process_id: 3788
thread_id: 3564
channel: Application
computer: WinDev2310Eval
security:
user_id: S-1-5-18
event_data: {}
message: Windows Management Instrumentation Service subsystems initialized successfully
References
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 5631 — WMI interop namespace class ".
Message
Fields
| Name | Description |
|---|---|
Class | — |