You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

33 KiB

1signature_idsignatureCategoryStringactionresult
2512Windows NT is starting up
3513Windows is shutting down
4514An authentication package has been loaded by the Local Security Authority
5515A trusted logon process has registered with the Local Security Authority
6516Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits
7517The audit log was cleared
8518A notification package has been loaded by the Security Account Manager
9519A process is using an invalid local procedure call (LPC) port
10520The system time was changed
11528Successful Logon
12529Unknown user name or bad password
13530Account logon time restriction violation
14531Account currently disabled
15532The specified user account has expired
16533User not allowed to logon at this computer
17534The user has not been granted the requested logon type at this machine
18535The specified account's password has expired
19536The NetLogon component is not active
20537The logon attempt failed for other reasons.
21538User Logoff
22539Logon Failure - Account locked out
23540Successful Network Logon
24551User initiated logoff
25552Logon attempt using explicit credentials
26560Object Open
27561Handle Allocated
28562Handle Closed
29563Object Open for Delete
30564Object Deleted
31565Object Open (Active Directory)
32566Object Operation (W3 Active Directory)
33567Object Access Attempt
34576Special privileges assigned to new logon
35577Privileged Service Called
36578Privileged object operation
37592A new process has been created
38593A process has exited
39594A handle to an object has been duplicated
40595Indirect access to an object has been obtained
41600A process was assigned a primary token
42601Attempt to install service
43602Scheduled Task created
44608User Right Assigned
45609User Right Removed
46610New Trusted Domain
47611Removing Trusted Domain
48612Audit Policy Change
49613IPSec policy agent started
50614IPSec policy agent disabled
51615IPSEC PolicyAgent Service
52616IPSec policy agent encountered a potentially serious failure.
53617Kerberos Policy Changed
54618Encrypted Data Recovery Policy Changed
55619Quality of Service Policy Changed
56620Trusted Domain Information Modified
57621System Security Access Granted
58622System Security Access Removed
59623Per User Audit Policy was refreshed
60624User Account CreatedAccount Managementcreated
61625User Account Type Changed
62626User Account EnabledAccount Management
63627Change Password AttemptAccount Management
64628User Account password setAccount Managementmodified
65629User Account DisabledAccount Management
66630User Account DeletedAccount Managementdeleted
67631Security Enabled Global Group CreatedAccount Management
68632Security Enabled Global Group Member AddedAccount Management
69633Security Enabled Global Group Member RemovedAccount Management
70634Security Enabled Global Group DeletedAccount Management
71635Security Enabled Local Group CreatedAccount Management
72636Security Enabled Local Group Member AddedAccount Management
73637Security Enabled Local Group Member RemovedAccount Management
74638Security Enabled Local Group DeletedAccount Management
75639Security Enabled Local Group ChangedAccount Management
76640General Account Database ChangeAccount Management
77641Security Enabled Global Group ChangedAccount Management
78642User Account ChangedAccount Managementmodified
79643Domain Policy ChangedAccount Management
80644User Account Locked OutAccount Managementmodifiedlockout
81645Computer Account CreatedAccount Management
82646Computer Account ChangedAccount Management
83647Computer Account DeletedAccount Management
84648Security Disabled Local Group CreatedAccount Management
85649Security Disabled Local Group ChangedAccount Management
86650Security Disabled Local Group Member AddedAccount Management
87651Security Disabled Local Group Member RemovedAccount Management
88652Security Disabled Local Group DeletedAccount Management
89653Security Disabled Global Group CreatedAccount Management
90654Security Disabled Global Group ChangedAccount Management
91655Security Disabled Global Group Member AddedAccount Management
92656Security Disabled Global Group Member RemovedAccount Management
93657Security Disabled Global Group DeletedAccount Management
94658Security Enabled Universal Group CreatedAccount Management
95659Security Enabled Universal Group ChangedAccount Management
96660Security Enabled Universal Group Member AddedAccount Management
97661Security Enabled Universal Group Member RemovedAccount Management
98662Security Enabled Universal Group DeletedAccount Management
99663Security Disabled Universal Group CreatedAccount Management
100664Security Disabled Universal Group ChangedAccount Management
101665Security Disabled Universal Group Member AddedAccount Management
102666Security Disabled Universal Group Member RemovedAccount Management
103667Security Disabled Universal Group DeletedAccount Management
104668Group Type ChangedAccount Management
105669Add SID HistoryAccount Management
106670Add SID HistoryAccount Management
107671User Account UnlockedAccount Management
108672Authentication Ticket Granted
109673Service Ticket Granted
110674Ticket Granted Renewed
111675Pre-authentication failed
112676Authentication Ticket Request Failed
113677Service Ticket Request Failed
114678Account Mapped for Logon by
115679The name: %2 could not be mapped for logon by: %1
116680Account Used for Logon by
117681The logon to account: %2 by: %1 from workstation: %3 failed.
118682Session reconnected to winstation
119683Session disconnected from winstation
120684Set ACLs of members in administrators groupsAccount Management
121685Account Name ChangedAccount Management
122686Password of the following user accessedAccount Management
123687Basic Application Group CreatedAccount Management
124688Basic Application Group ChangedAccount Management
125689Basic Application Group Member AddedAccount Management
126690Basic Application Group Member RemovedAccount Management
127691Basic Application Group Non-Member AddedAccount Management
128692Basic Application Group Non-Member RemovedAccount Management
129693Basic Application Group DeletedAccount Management
130694LDAP Query Group CreatedAccount Management
131695LDAP Query Group ChangedAccount Management
132696LDAP Query Group DeletedAccount Management
133697Password Policy Checking API is calledAPI Calls
134806Per User Audit Policy was refreshed
135807Per user auditing policy set for user
136808A security event source has attempted to register
137809A security event source has attempted to unregister
138848The following policy was active when the Windows Firewall started
139849An application was listed as an exception when the Windows Firewall started
140850A port was listed as an exception when the Windows Firewall started
141852A change has been made to the Windows Firewall port exception list
142861The Windows Firewall has detected an application listening for incoming traffic
1431100The event logging service has shut down
1441101Audit events have been dropped by the transport.
1451102The audit log was cleared
1461104The security Log is now full
1471105Event log automatic backup
1481108The event logging service encountered an error
1494500Metabase Add Key
1504501Metabase Delete Key
1514502Metabase Delete Chid Keys
1524503Metabase Copy Key
1534504Metabase Rename Key
1544505Metabase Set Data
1554506Metabase Delete Data
1564507Metabase Delete All Data
1574508Metabase Copy Data
1584509Metabase Set Last Change Time
1594510Metabase Restore
1604511Metabase Delete Backup
1614512Metabase Import
1624608Windows is starting up
1634609Windows is shutting down
1644610An authentication package has been loaded by the Local Security Authority
1654611A trusted logon process has been registered with the Local Security Authority
1664612Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
1674614A notification package has been loaded by the Security Account Manager.
1684615Invalid use of LPC port
1694616The system time was changed.
1704618A monitored security event pattern has occurred
1714621Administrator recovered system from CrashOnAuditFail
1724622A security package has been loaded by the Local Security Authority.
1734624An account was successfully logged on
1744625An account failed to log on
1754634An account was logged off
1764646%1
1774647User initiated logoff
1784648A logon was attempted using explicit credentials
1794649A replay attack was detected
1804650An IPsec Main Mode security association was established
1814651An IPsec Main Mode security association was established
1824652An IPsec Main Mode negotiation failed
1834653An IPsec Main Mode negotiation failed
1844654An IPsec Quick Mode negotiation failed
1854655An IPsec Main Mode security association ended
1864656A handle to an object was requested
1874657A registry value was modified
1884658The handle to an object was closed
1894659A handle to an object was requested with intent to delete
1904660An object was deleted
1914661A handle to an object was requested
1924662An operation was performed on an object
1934663An attempt was made to access an object
1944664An attempt was made to create a hard link
1954665An attempt was made to create an application client context.
1964666An application attempted an operation
1974667An application client context was deleted
1984668An application was initialized
1994670Permissions on an object were changed
2004671An application attempted to access a blocked ordinal through the TBS
2014672Special privileges assigned to new logon
2024673A privileged service was called
2034674An operation was attempted on a privileged object
2044675SIDs were filtered
2054685The state of a transaction has changed
2064688A new process has been created
2074689A process has exited
2084690An attempt was made to duplicate a handle to an object
2094691Indirect access to an object was requested
2104692Backup of data protection master key was attempted
2114693Recovery of data protection master key was attempted
2124694Protection of auditable protected data was attempted
2134695Unprotection of auditable protected data was attempted
2144696A primary token was assigned to process
2154697A service was installed in the system
2164698A scheduled task was created
2174699A scheduled task was deleted
2184700A scheduled task was enabled
2194701A scheduled task was disabled
2204702A scheduled task was updated
2214704A user right was assigned
2224705A user right was removed
2234706A new trust was created to a domain
2244707A trust to a domain was removed
2254709IPsec Services was started
2264710IPsec Services was disabled
2274711PAStore Engine (1%)
2284712IPsec Services encountered a potentially serious failure
2294713Kerberos policy was changed
2304714Encrypted data recovery policy was changed
2314715The audit policy (SACL) on an object was changed
2324716Trusted domain information was modified
2334717System security access was granted to an account
2344718System security access was removed from an account
2354719System audit policy was changed
2364720A user account was createdAccount Management
2374722A user account was enabledAccount Management
2384723An attempt was made to change an account's passwordAccount Management
2394724An attempt was made to reset an accounts passwordAccount Management
2404725A user account was disabledAccount Management
2414726A user account was deletedAccount Management
2424727A security-enabled global group was createdAccount Management
2434728A member was added to a security-enabled global groupAccount Management
2444729A member was removed from a security-enabled global groupAccount Management
2454730A security-enabled global group was deletedAccount Management
2464731A security-enabled local group was createdAccount Management
2474732A member was added to a security-enabled local groupAccount Management
2484733A member was removed from a security-enabled local groupAccount Management
2494734A security-enabled local group was deletedAccount Management
2504735A security-enabled local group was changedAccount Management
2514737A security-enabled global group was changedAccount Management
2524738A user account was changedAccount Management
2534739Domain Policy was changedAccount Management
2544740A user account was locked outAccount Management
2554741A computer account was createdAccount Management
2564742A computer account was changedAccount Management
2574743A computer account was deletedAccount Management
2584744A security-disabled local group was createdAccount Management
2594745A security-disabled local group was changedAccount Management
2604746A member was added to a security-disabled local groupAccount Management
2614747A member was removed from a security-disabled local groupAccount Management
2624748A security-disabled local group was deletedAccount Management
2634749A security-disabled global group was createdAccount Management
2644750A security-disabled global group was changedAccount Management
2654751A member was added to a security-disabled global groupAccount Management
2664752A member was removed from a security-disabled global groupAccount Management
2674753A security-disabled global group was deletedAccount Management
2684754A security-enabled universal group was createdAccount Management
2694755A security-enabled universal group was changedAccount Management
2704756A member was added to a security-enabled universal groupAccount Management
2714757A member was removed from a security-enabled universal groupAccount Management
2724758A security-enabled universal group was deletedAccount Management
2734759A security-disabled universal group was createdAccount Management
2744760A security-disabled universal group was changedAccount Management
2754761A member was added to a security-disabled universal groupAccount Management
2764762A member was removed from a security-disabled universal groupAccount Management
2774763A security-disabled universal group was deletedAccount Management
2784764A group's type was changedAccount Management
2794765SID History was added to an accountAccount Management
2804766An attempt to add SID History to an account failedAccount Management
2814767A user account was unlockedAccount Management
2824768A Kerberos authentication ticket (TGT) was requested
2834769A Kerberos service ticket was requested
2844770A Kerberos service ticket was renewed
2854771Kerberos pre-authentication failed
2864772A Kerberos authentication ticket request failed
2874773A Kerberos service ticket request failed
2884774An account was mapped for logon
2894775An account could not be mapped for logon
2904776The domain controller attempted to validate the credentials for an account
2914777The domain controller failed to validate the credentials for an account
2924778A session was reconnected to a Window Station
2934779A session was disconnected from a Window Station
2944780The ACL was set on accounts which are members of administrators groupsAccount Management
2954781The name of an account was changedAccount Management
2964782The password hash an account was accessedAccount Management
2974783A basic application group was createdAccount Management
2984784A basic application group was changedAccount Management
2994785A member was added to a basic application groupAccount Management
3004786A member was removed from a basic application groupAccount Management
3014787A non-member was added to a basic application groupAccount Management
3024788A non-member was removed from a basic application group..Account Management
3034789A basic application group was deletedAccount Management
3044790An LDAP query group was createdAccount Management
3054791A basic application group was changedAccount Management
3064792An LDAP query group was deletedAccount Management
3074793The Password Policy Checking API was calledAPI Calls
3084794An attempt was made to set the Directory Services Restore Mode administrator passwordAccount Management
3094799A security-enabled local group membership was enumerated
3104800The workstation was locked
3114801The workstation was unlocked
3124802The screen saver was invoked
3134803The screen saver was dismissed
3144816RPC detected an integrity violation while decrypting an incoming message
3154817Auditing settings on object were changed.
3164864A namespace collision was detected
3174865A trusted forest information entry was added
3184866A trusted forest information entry was removed
3194867A trusted forest information entry was modified
3204868The certificate manager denied a pending certificate request
3214869Certificate Services received a resubmitted certificate request
3224870Certificate Services revoked a certificate
3234871Certificate Services received a request to publish the certificate revocation list (CRL)
3244872Certificate Services published the certificate revocation list (CRL)
3254873A certificate request extension changed
3264874One or more certificate request attributes changed.
3274875Certificate Services received a request to shut down
3284876Certificate Services backup started
3294877Certificate Services backup completed
3304878Certificate Services restore started
3314879Certificate Services restore completed
3324880Certificate Services started
3334881Certificate Services stopped
3344882The security permissions for Certificate Services changed
3354883Certificate Services retrieved an archived key
3364884Certificate Services imported a certificate into its database
3374885The audit filter for Certificate Services changed
3384886Certificate Services received a certificate request
3394887Certificate Services approved a certificate request and issued a certificate
3404888Certificate Services denied a certificate request
3414889Certificate Services set the status of a certificate request to pending
3424890The certificate manager settings for Certificate Services changed.
3434891A configuration entry changed in Certificate Services
3444892A property of Certificate Services changed
3454893Certificate Services archived a key
3464894Certificate Services imported and archived a key
3474895Certificate Services published the CA certificate to Active Directory Domain Services
3484896One or more rows have been deleted from the certificate database
3494897Role separation enabled
3504898Certificate Services loaded a template
3514899A Certificate Services template was updated
3524900Certificate Services template security was updated
3534902The Per-user audit policy table was created
3544904An attempt was made to register a security event source
3554905An attempt was made to unregister a security event source
3564906The CrashOnAuditFail value has changed
3574907Auditing settings on object were changed
3584908Special Groups Logon table modified
3594909The local policy settings for the TBS were changed
3604910The group policy settings for the TBS were changed
3614912Per User Audit Policy was changed
3624928An Active Directory replica source naming context was established
3634929An Active Directory replica source naming context was removed
3644930An Active Directory replica source naming context was modified
3654931An Active Directory replica destination naming context was modified
3664932Synchronization of a replica of an Active Directory naming context has begun
3674933Synchronization of a replica of an Active Directory naming context has ended
3684934Attributes of an Active Directory object were replicated
3694935Replication failure begins
3704936Replication failure ends
3714937A lingering object was removed from a replica
3724944The following policy was active when the Windows Firewall started
3734945A rule was listed when the Windows Firewall started
3744946A change has been made to Windows Firewall exception list. A rule was added
3754947A change has been made to Windows Firewall exception list. A rule was modified
3764948A change has been made to Windows Firewall exception list. A rule was deleted
3774949Windows Firewall settings were restored to the default values
3784950A Windows Firewall setting has changed
3794951A rule has been ignored because its major version number was not recognized by Windows Firewall
3804952Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
3814953A rule has been ignored by Windows Firewall because it could not parse the rule
3824954Windows Firewall Group Policy settings has changed. The new settings have been applied
3834956Windows Firewall has changed the active profile
3844957Windows Firewall did not apply the following rule
3854958Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer
3864960IPsec dropped an inbound packet that failed an integrity check
3874961IPsec dropped an inbound packet that failed a replay check
3884962IPsec dropped an inbound packet that failed a replay check
3894963IPsec dropped an inbound clear text packet that should have been secured
3904964Special groups have been assigned to a new logon
3914965IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).
3924976During Main Mode negotiation, IPsec received an invalid negotiation packet.
3934977During Quick Mode negotiation, IPsec received an invalid negotiation packet.
3944978During Extended Mode negotiation, IPsec received an invalid negotiation packet.
3954979IPsec Main Mode and Extended Mode security associations were established.
3964980IPsec Main Mode and Extended Mode security associations were established
3974981IPsec Main Mode and Extended Mode security associations were established
3984982IPsec Main Mode and Extended Mode security associations were established
3994983An IPsec Extended Mode negotiation failed
4004984An IPsec Extended Mode negotiation failed
4014985The state of a transaction has changed
4025024The Windows Firewall Service has started successfully
4035025The Windows Firewall Service has been stopped
4045027The Windows Firewall Service was unable to retrieve the security policy from the local storage
4055028The Windows Firewall Service was unable to parse the new security policy.
4065029The Windows Firewall Service failed to initialize the driver
4075030The Windows Firewall Service failed to start
4085031The Windows Firewall Service blocked an application from accepting incoming connections on the network.
4095032Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network
4105033The Windows Firewall Driver has started successfully
4115034The Windows Firewall Driver has been stopped
4125035The Windows Firewall Driver failed to start
4135037The Windows Firewall Driver detected critical runtime error. Terminating
4145038Code integrity determined that the image hash of a file is not valid
4155039A registry key was virtualized.
4165040A change has been made to IPsec settings. An Authentication Set was added.
4175041A change has been made to IPsec settings. An Authentication Set was modified
4185042A change has been made to IPsec settings. An Authentication Set was deleted
4195043A change has been made to IPsec settings. A Connection Security Rule was added
4205044A change has been made to IPsec settings. A Connection Security Rule was modified
4215045A change has been made to IPsec settings. A Connection Security Rule was deleted
4225046A change has been made to IPsec settings. A Crypto Set was added
4235047A change has been made to IPsec settings. A Crypto Set was modified
4245048A change has been made to IPsec settings. A Crypto Set was deleted
4255049An IPsec Security Association was deleted
4265050An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE
4275051A file was virtualized
4285056A cryptographic self test was performed
4295057A cryptographic primitive operation failed
4305058Key file operation
4315059Key migration operation
4325060Verification operation failed
4335061Cryptographic operation
4345062A kernel-mode cryptographic self test was performed
4355063A cryptographic provider operation was attempted
4365064A cryptographic context operation was attempted
4375065A cryptographic context modification was attempted
4385066A cryptographic function operation was attempted
4395067A cryptographic function modification was attempted
4405068A cryptographic function provider operation was attempted
4415069A cryptographic function property operation was attempted
4425070A cryptographic function property operation was attempted
4435120OCSP Responder Service Started
4445121OCSP Responder Service Stopped
4455122A Configuration entry changed in the OCSP Responder Service
4465123A configuration entry changed in the OCSP Responder Service
4475124A security setting was updated on OCSP Responder Service
4485125A request was submitted to OCSP Responder Service
4495126Signing Certificate was automatically updated by the OCSP Responder Service
4505127The OCSP Revocation Provider successfully updated the revocation information
4515136A directory service object was modified
4525137A directory service object was created
4535138A directory service object was undeleted
4545139A directory service object was moved
4555140A network share object was accessed
4565141A directory service object was deleted
4575142A network share object was added.
4585143A network share object was modified
4595144A network share object was deleted.
4605145A network share object was checked to see whether client can be granted desired access
4615148The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
4625149The DoS attack has subsided and normal processing is being resumed.
4635150The Windows Filtering Platform has blocked a packet.
4645151A more restrictive Windows Filtering Platform filter has blocked a packet.
4655152The Windows Filtering Platform blocked a packet
4665153A more restrictive Windows Filtering Platform filter has blocked a packet
4675154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections
4685155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections
4695156The Windows Filtering Platform has allowed a connection
4705157The Windows Filtering Platform has blocked a connection
4715158The Windows Filtering Platform has permitted a bind to a local port
4725159The Windows Filtering Platform has blocked a bind to a local port
4735168Spn check for SMB/SMB2 fails.
4745376Credential Manager credentials were backed upAccount Management
4755377Credential Manager credentials were restored from a backupAccount Management
4765378The requested credentials delegation was disallowed by policy
4775440The following callout was present when the Windows Filtering Platform Base Filtering Engine started
4785441The following filter was present when the Windows Filtering Platform Base Filtering Engine started
4795442The following provider was present when the Windows Filtering Platform Base Filtering Engine started
4805443The following provider context was present when the Windows Filtering Platform Base Filtering Engine started
4815444The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
4825446A Windows Filtering Platform callout has been changed
4835447A Windows Filtering Platform filter has been changed
4845448A Windows Filtering Platform provider has been changed
4855449A Windows Filtering Platform provider context has been changed
4865450A Windows Filtering Platform sub-layer has been changed
4875451An IPsec Quick Mode security association was established
4885452An IPsec Quick Mode security association ended
4895453An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started
4905456PAStore Engine applied Active Directory storage IPsec policy on the computer
4915457PAStore Engine failed to apply Active Directory storage IPsec policy on the computer
4925458PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
4935459PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
4945460PAStore Engine applied local registry storage IPsec policy on the computer
4955461PAStore Engine failed to apply local registry storage IPsec policy on the computer
4965462PAStore Engine failed to apply some rules of the active IPsec policy on the computer
4975463PAStore Engine polled for changes to the active IPsec policy and detected no changes
4985464PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services
4995465PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
5005466PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead
5015467PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy
5025468PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes
5035471PAStore Engine loaded local storage IPsec policy on the computer
5045472PAStore Engine failed to load local storage IPsec policy on the computer
5055473PAStore Engine loaded directory storage IPsec policy on the computer
5065474PAStore Engine failed to load directory storage IPsec policy on the computer
5075477PAStore Engine failed to add quick mode filter
5085478IPsec Services has started successfully
5095479IPsec Services has been shut down successfully
5105480IPsec Services failed to get the complete list of network interfaces on the computer
5115483IPsec Services failed to initialize RPC server. IPsec Services could not be started
5125484IPsec Services has experienced a critical failure and has been shut down
5135485IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
5145632A request was made to authenticate to a wireless network
5155633A request was made to authenticate to a wired network
5165712A Remote Procedure Call (RPC) was attempted
5175888An object in the COM+ Catalog was modified
5185889An object was deleted from the COM+ Catalog
5195890An object was added to the COM+ Catalog
5206144Security policy in the group policy objects has been applied successfully
5216145One or more errors occured while processing security policy in the group policy objects
5226272Network Policy Server granted access to a user
5236273Network Policy Server denied access to a user
5246274Network Policy Server discarded the request for a user
5256275Network Policy Server discarded the accounting request for a user
5266276Network Policy Server quarantined a user
5276277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
5286278Network Policy Server granted full access to a user because the host met the defined health policy
5296279Network Policy Server locked the user account due to repeated failed authentication attempts
5306280Network Policy Server unlocked the user account
5316281Code Integrity determined that the page hashes of an image file are not valid...
5326400BranchCache: Received an incorrectly formatted response while discovering availability of content.
5336401BranchCache: Received invalid data from a peer. Data discarded.
5346402BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
5356403BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.
5366404BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
5376405BranchCache: %2 instance(s) of event id %1 occurred.
5386406%1 registered to Windows Firewall to control filtering for the following:
5396407%1
5406408Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.