Microsoft-Windows-WPDClassInstaller
90 events across 4 channels
Event ID 100 — WPD device installation function (%1, %2) begin.
Message
Fields
| Name | Description |
|---|---|
InstallFunctionCode | — |
InstallFunctionName | — |
Event ID 101 — WPD device installation function (%1, %2) end with this return code (%3).
Message
Fields
| Name | Description |
|---|---|
InstallFunctionCode | — |
InstallFunctionName | — |
ReturnCode | — |
Event ID 102 — WPD device metadata retrieval for device %1 begin.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
Event ID 103 — WPD device metadata retrieval for device %1 end with this return code (%2).
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
ReturnCode | — |
Event ID 104 — WPD device metadata retrieval for device %1 begin.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
Event ID 105 — WPD device metadata retrieval for device %1 end with this return code (%2).
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
ReturnCode | — |
Event ID 200 — Device marked for reinstallation on subsequent connect.
Message
Event ID 201 — %1: Transfer of metadata (%2, %3) succeeded.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
MetadataLocaleName | — |
MetadataContentId | — |
Event ID 202 — %1: Transfer of metadata (%2, %3) skipped.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
MetadataLocaleName | — |
MetadataContentId | — |
ReturnCode | — |
Event ID 203 — %1: Transfer of metadata (%2, %3) failed.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
MetadataLocaleName | — |
MetadataContentId | — |
ReturnCode | — |
Event ID 204 — %1: Transfer of metadata failed as the Device Metadata Service could not be accessed.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
ReturnCode | — |
Event ID 205 — %1: Successfully opened the Device Metadata Service to retrieve metadata: %2.
Message
Fields
| Name | Description |
|---|---|
DevicePath | — |
ServicePath | — |
Event ID 206 — Transfer of metadata (%1, %2) is skipped because the metadata already exists on the system.
Message
Fields
| Name | Description |
|---|---|
MetadataLocaleName | — |
MetadataContentId | — |
Event ID 207 — Policy %1 enforced for user account %2, device instance %7.
Message
Fields
| Name | Description |
|---|---|
PolicyName | — |
UserAccountName | — |
DeviceName | — |
ClassName | — |
ClassGuid | — |
HardwareIds | — |
InstanceId | — |
BusTypeGuid | — |
EventSource | — |
Event ID 24576 —
Event ID 24576 —
Fields
| Name | Description |
|---|---|
Data_0 | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-WPDClassInstaller
guid: '{AD5162D8-DAF0-4A25-88A7-01CBEB33902E}'
event_source_name: WPDClassInstaller
event_id: 24576
version: 0
level: 4
task: 16
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T16:53:01.520198+00:00'
event_record_id: 372
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: ''
event_data:
Data_0: WPD Device
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 24577 —
Event ID 24577 —
Fields
| Name | Description |
|---|---|
Data_0 | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-WPDClassInstaller
guid: '{AD5162D8-DAF0-4A25-88A7-01CBEB33902E}'
event_source_name: WPDClassInstaller
event_id: 24577
version: 0
level: 4
task: 32
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T16:53:01.598397+00:00'
event_record_id: 373
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: ''
event_data:
Data_0: ''
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 24578 —
Event ID 24578 —
Event ID 24579 —
Event ID 24579 —
Fields
| Name | Description |
|---|---|
Data_0 | — |
Binary | — |
Example Event
system:
provider: Microsoft-Windows-WPDClassInstaller
guid: '{AD5162D8-DAF0-4A25-88A7-01CBEB33902E}'
event_source_name: WPDClassInstaller
event_id: 24579
version: 0
level: 4
task: 32
opcode: 0
keywords: 36028797018963968
time_created: '2022-04-07T16:53:01.598397+00:00'
event_record_id: 374
correlation: {}
execution:
process_id: 0
thread_id: 0
channel: System
computer: WIN-FPV0DSIC9O6
security:
user_id: ''
event_data:
Data_0: ''
Binary: ''
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline