Microsoft-Windows-WMI
62 events across 1 channel
Event ID 4 — Error Error encountered when trying to load MOF MOF while recovering .
Event ID 10 — Event filter with query "Query" could not be reactivated in namespace "Namespace" because of error Error.
Event ID 21 — Event provider EventProvider attempted to register a syntactically invalid query "Query".
Event ID 22 — Event provider EventProvider attempted to register an intrinsic event query "Query" in Namespace namespace for which the set of target object classes could not be deter...
Description
Event provider EventProvider attempted to register an intrinsic event query "Query" in Namespace namespace for which the set of target object classes could not be determined. The query will be ignored.
Message #
Fields #
| Name | Description |
|---|---|
EventProvider UnicodeString | — |
Query UnicodeString | — |
Namespace UnicodeString | — |
Event ID 23 — Event provider EventProvider attempted to register query "Query" in Namespace namespace which is too broad.
Event ID 24 — Event provider EventProvider attempted to register query "Query" whose target class "Class" in Namespace namespace does not exist.
Event ID 25 — Event provider EventProvider attempted to register query "Query" whose target class "Class" is not an event class.
Event ID 28 — Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number ErrorNumber.
Event ID 29 — Error number ErrorNumber was returned in trying to initialize Windows Management Instrumentation Service.
Event ID 43 — Windows Management Instrumentation ADAP failed to connect to namespace Namespace with the following error Error.
Event ID 48 — Windows Management Instrumentation ADAP was unable to save object Object in namespace Namespace because of the following error Error.
Event ID 58 — Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in Class:Result=Result.
Event ID 59 — Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class Class.
Event ID 63 — A provider, NlbsNicProv, has been registered in the Windows Management Instrumentation namespace Root\microsoftnlb to use the LocalSystem account.
#Message #
Fields #
| Name | Description |
|---|---|
data_0x8000003F.Provider | — |
data_0x8000003F.Namespace | — |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "1EDEEE53-0AFE-4609-B846-D8C0B2075B1F",
"event_source_name": "",
"event_id": 63,
"version": 2,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2022-04-04T11:12:30.841914+00:00",
"event_record_id": 181,
"correlation": {},
"execution": {
"process_id": 1136,
"thread_id": 2060
},
"channel": "Application",
"computer": "WIN-TKC15D7KHUR",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"data_0x8000003F": {
"Provider": "NlbsNicProv",
"Namespace": "Root\\microsoftnlb"
}
},
"message": "A provider, NlbsNicProv, has been registered in the Windows Management Instrumentation namespace Root\\microsoftnlb to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests."
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 65 — Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
Description
Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository.
Message #
Event ID 66 — The Windows Management Instrumentation Service has recovered from the following backup repository: BackupRepository.
Event ID 67 — The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following f...
Event ID 68 — The Windows Management Instrumentation repository backup operation completed copying data to BackupFile with error Error.
Event ID 5600 — The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system3...
Message #
Event ID 5601 — The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.
Message #
Event ID 5602 — The Windows Management Instrumentation service detected an inconsistency in the following backup file: BackupFile.
Event ID 5604 — The Windows Management Instrumentation service encountered the error Error and was not able to restore from the following backup repository: BackupRepository.
Event ID 5605 — The Namespace namespace is marked with the RequiresEncryption flag.
Event ID 5606 — Windows Management Instrumentation Service could not deliver results asynchronously for Namespace namespace.
Event ID 5611 — The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Description
The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "1EDEEE53-0AFE-4609-B846-D8C0B2075B1F",
"event_source_name": "",
"event_id": 5611,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-14T00:02:46.971764+00:00",
"event_record_id": 4411,
"correlation": {},
"execution": {
"process_id": 4020,
"thread_id": 4688
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": ""
}
Event ID 5612 — Windows Management Instrumentation has stopped WMIPRVSE.
Description
Windows Management Instrumentation has stopped WMIPRVSE.EXE because a quota reached a warning value. Quota: QuotaName Value: QuotaValue Maximum value: QuotaThreshold WMIPRVSE PID: HostProcessID Providers hosted in this process: ProvidersInHost.
Message #
Fields #
| Name | Description |
|---|---|
QuotaName UnicodeString | — |
QuotaValue UnicodeString | — |
QuotaThreshold UnicodeString | — |
HostProcessID UnicodeString | — |
ProvidersInHost UnicodeString | — |
Event ID 5614 — During the service startup, the Windows Management Instrumentation service was unable to locate the repository files.
Description
During the service startup, the Windows Management Instrumentation service was unable to locate the repository files. A new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 5615 — Windows Management Instrumentation Service started sucessfully
#Description
Windows Management Instrumentation Service started sucessfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "1EDEEE53-0AFE-4609-B846-D8C0B2075B1F",
"event_source_name": "",
"event_id": 5615,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:43.964888+00:00",
"event_record_id": 1440,
"correlation": {},
"execution": {
"process_id": 3788,
"thread_id": 3880
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Windows Management Instrumentation Service started sucessfully"
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 5616 — The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Description
The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Message #
Event ID 5617 — Windows Management Instrumentation Service subsystems initialized successfully
#Description
Windows Management Instrumentation Service subsystems initialized successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-WMI",
"guid": "1EDEEE53-0AFE-4609-B846-D8C0B2075B1F",
"event_source_name": "",
"event_id": 5617,
"version": 2,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2023-11-06T06:25:45.613226+00:00",
"event_record_id": 1441,
"correlation": {},
"execution": {
"process_id": 3788,
"thread_id": 3564
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Windows Management Instrumentation Service subsystems initialized successfully"
}
References #
- Example event sourced from https://github.com/Yamato-Security/hayabusa-sample-evtx
Event ID 5631 — WMI interop namespace class "Class" has been overwritten.
Event ID 1073747424 — The Windows Management Instrumentation (WMI) service detected an inconsistency with the WMI repository in the following directory: %windir%\system3...
Message #
Event ID 2147483711 — A provider, %1, has been registered in the Windows Management Instrumentation namespace %2 to use the LocalSystem account.
Message #
Event ID 3221225476 — Error %1 encountered when trying to load MOF %2 while recovering .
Description
Error encountered when trying to load MOF while recovering .MOF file marked with autorecover.
Message #
Event ID 3221225482 — Event filter with query "%2" could not be reactivated in namespace "%1" because of error %3.
Description
Event filter with query "%2" could not be reactivated in namespace "%1" because of error %3. Events cannot be delivered through this filter until the problem is corrected.
Message #
Event ID 3221225493 — Event provider %1 attempted to register a syntactically invalid query "%2".
Message #
Event ID 3221225494 — Event provider %1 attempted to register an intrinsic event query "%2" in %3 namespace for which the set of target object classes could not be deter...
Description
Event provider %1 attempted to register an intrinsic event query "%2" in %3 namespace for which the set of target object classes could not be determined. The query will be ignored.
Message #
Event ID 3221225495 — Event provider %1 attempted to register query "%2" in %3 namespace which is too broad.
Message #
Event ID 3221225496 — Event provider %1 attempted to register query "%2" whose target class "%3" in %4 namespace does not exist.
Description
Event provider %1 attempted to register query "%2" whose target class "%3" in %4 namespace does not exist. The query will be ignored.
Message #
Event ID 3221225497 — Event provider %1 attempted to register query "%2" whose target class "%3" is not an event class.
Description
Event provider %1 attempted to register query "%2" whose target class "%3" is not an event class. The query will be ignored. Contact the application vendor.
Message #
Event ID 3221225500 — Failed to Initialize WMI Core or Provider SubSystem or Event SubSystem with error number %1.
Message #
Event ID 3221225501 — Error number %1 was returned in trying to initialize Windows Management Instrumentation Service.
Message #
Event ID 3221225515 — Windows Management Instrumentation ADAP failed to connect to namespace %1 with the following error %2.
Description
Windows Management Instrumentation ADAP failed to connect to namespace with the following error.
Message #
Event ID 3221225520 — Windows Management Instrumentation ADAP was unable to save object %1 in namespace %2 because of the following error %3.
Description
Windows Management Instrumentation ADAP was unable to save object in namespace because of the following error.
Message #
Event ID 3221225530 — Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in %1:Result=%2.
Description
Windows Management Instrumentation ADAP was unable to create the Win32_Perf base class in :Result=.
Message #
Event ID 3221225531 — Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class %1.
Description
Windows Management Instrumentation ADAP was unable to create the Win32_PerfRawData base class.
Message #
Event ID 3221225537 — Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository
Description
Windows Management Instrumentation (WMI) Service is starting to restore the WMI repository.
Message #
Event ID 3221225538 — The Windows Management Instrumentation Service has recovered from the following backup repository.
Description
The Windows Management Instrumentation Service has recovered from the following backup repository: .
Message #
Event ID 3221225539 — The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following f...
Description
The Windows Management Instrumentation (WMI) Service is starting the backup operation for the WMI repository and is copying data to the following file.
Message #
Event ID 3221225540 — The Windows Management Instrumentation repository backup operation completed copying data to %1 with error %2.
Description
The Windows Management Instrumentation repository backup operation completed copying data to with error .
Message #
Event ID 3221231073 — The Windows Management Instrumentation Service failed to load the repository files under the directory %windir%\system32\wbem\repository.
Message #
Event ID 3221231074 — The Windows Management Instrumentation service detected an inconsistency in the following backup file.
Description
The Windows Management Instrumentation service detected an inconsistency in the following backup file: .
Message #
Event ID 3221231076 — The Windows Management Instrumentation service encountered the error %2 and was not able to restore from the following backup repository: %1.
Description
The Windows Management Instrumentation service encountered the error and was not able to restore from the following backup repository: .
Message #
Event ID 3221231077 — The %1 namespace is marked with the RequiresEncryption flag.
Message #
Event ID 3221231078 — Windows Management Instrumentation Service could not deliver results asynchronously for %1 namespace.
Message #
Event ID 3221231083 — The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Description
The Windows Management Instrumentation service has detected an inconsistent system shutdown.
Message #
Event ID 3221231084 — Windows Management Instrumentation has stopped WMIPRVSE.
Description
Windows Management Instrumentation has stopped WMIPRVSE.EXE because a quota reached a warning value. Quota: Value: Maximum value: WMIPRVSE PID: Providers hosted in this process.
Message #
Event ID 3221231086 — During the service startup, the Windows Management Instrumentation service was unable to locate the repository files.
Description
During the service startup, the Windows Management Instrumentation service was unable to locate the repository files. A new repository will be created based on the auto-recovery mechanism.
Message #
Event ID 3221231087 — Windows Management Instrumentation Service started sucessfully
Description
Windows Management Instrumentation Service started sucessfully.
Message #
Event ID 3221231088 — The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Description
The Windows Management Instrumentation (WMI) repository was successfully re-created by the auto-recovery mechanism.
Message #
Event ID 3221231089 — Windows Management Instrumentation Service subsystems initialized successfully
Description
Windows Management Instrumentation Service subsystems initialized successfully.