Microsoft-Windows-ZTDNS

8 events across 3 channels

Event ID 1 — PERMIT - Connection [.

Provider
Microsoft-Windows-ZTDNS
Channel
PermittedConnections

Message

PERMIT - Connection [%2]:%3 -> [%5]:%6 by process (%8) %9 because of %10 %11 from service %12

Fields

NameDescription
LocalAddressLength
LocalAddress
LocalPort
RemoteAddressLength
RemoteAddress
RemotePort
Protocol
ProcessId
ProcessPath
PermitType
PermitInfo
ServiceName

Event ID 2 — BLOCK - Connection [.

Provider
Microsoft-Windows-ZTDNS
Channel
BlockedConnections

Message

BLOCK - Connection [%2]:%3 -> [%5]:%6 by process (%8) %9 from service %10

Fields

NameDescription
LocalAddressLength
LocalAddress
LocalPort
RemoteAddressLength
RemoteAddress
RemotePort
Protocol
ProcessId
ProcessPath
ServiceName

Event ID 3 — UPDATE - Trusted servers by process (%1) %2.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

UPDATE - Trusted servers by process (%1) %2

Fields

NameDescription
ProcessId
ProcessPath

Event ID 4 — REMOVE - %1%2 by process (%3) %4.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

REMOVE - %1%2 by process (%3) %4

Fields

NameDescription
ExceptionsUpdateType
ExceptionName
ProcessId
ProcessPath

Event ID 5 — ADD - %1%2 by process (%3) %4.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

ADD - %1%2 by process (%3) %4

Fields

NameDescription
ExceptionsUpdateType
ExceptionName
ProcessId
ProcessPath

Event ID 6 — UPDATE - State to %1 by process (%2) %3.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

UPDATE - State to %1 by process (%2) %3

Fields

NameDescription
ServiceState
ProcessId
ProcessPath

Event ID 7 — START - ZTDNS service with status %1.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

START - ZTDNS service with status %1

Fields

NameDescription
Status

Event ID 8 — STOP - ZTDNS service with status %1.

Provider
Microsoft-Windows-ZTDNS
Channel
Operational

Message

STOP - ZTDNS service with status %1

Fields

NameDescription
Status