You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

36 KiB

1EventCodeLogNamedesc
2614Directory ServiceA corrupt index has been detected
31014Directory ServiceThe KCC failed to update the replication topology for the local DS
41083Directory ServiceDirectory is busy and cannot complete replication (KB296714)
51084Directory ServiceInbound Replication Failure
61115Directory ServiceOutbound replication has been disabled by the user
71173Directory ServiceAD DS encountered an exception (see event details)
81188Directory ServiceA replication thread "hung" and was cancelled
91203Directory ServiceReplication failed because of a schema mismatch
101220Directory ServiceLDAP over Secure Sockets Layer (SSL) will be unavailable at this time because the server was unable to obtain a certificate
111232Directory ServiceAn RPC Call initiated by AD DS timed out
121307Directory ServiceAttempts to connect for replication have failed
131308Directory ServiceAttempts to connect for replication have failed
141311Directory ServiceNot enough information to generate a complete spanning tree topology (KB214745)
151419Directory ServiceLocal DC is both GC and Infrastructure Master. These are incompatible roles
161458Directory ServiceA FSMO Role has moved
171463Directory ServiceCorrupt indices have been detected and will be rebuilt.
181481Directory ServiceOperation on an object failed (see event details)
191566Directory ServiceNo available DCs in the site are available for replication
201659Directory ServiceRemoval of a directory partition has resumed
211699Directory ServiceReplication access was denied (KB953392)
221800Directory ServicePartial replica found,but no writeable source found
231801Directory ServiceDirectory Partition has not been instantiated and no replication hosts found
241844Directory ServiceLocal DC cannot connect to a remote DC for name resolution
251865Directory ServiceProduction of the AD Spanning Tree failed (replication will fail)
261925Directory ServiceAttempt to establish a writable replication link failed
271926Directory ServiceAttempt to establish a replication link failed
281988Directory ServiceAttempt to replicate a non-existant object (KB870695)
292002Directory ServiceThe KCC did not run successfully (problem with object)
302041Directory ServiceDuplicate Event Log Entries were suppressed
312052Directory ServiceReplication: Bridgeheads created back channel due to issues connecting for Replication
322054Directory ServiceReplciation: KCC detected a back channel between bridgeheads (Replication Failure)
332087Directory ServiceDNS Name Resolution of a DC Failed (KB824449)
342088Directory ServiceReplication used NetBIOS because DNS Failed (KB824449)
352089Directory ServiceA Directory Partition has not been backed up (KB914034)
362108Directory ServiceRepair Procedures for a preceding Event ID 1084 (KB837932)
372513Directory ServiceFailed to set the desired authentication protocol for a connection to a DSA
382886Directory ServiceAD Server is accepting insecure SASL LDAP binds
392887Directory ServiceSome clients performed insecure LDAP binds
4016650Directory ServiceAccount Identifier Allocator failed to initialize properly (KB839879)
4136886Directory ServiceNo default server credentials available
42512SecurityWindows NT is starting up
43513SecurityWindows is shutting down
44514SecurityAn authentication package has been loaded by the Local Security Authority
45515SecurityA trusted logon process has registered with the Local Security Authority
46516SecurityInternal resources exhausted - loss of events
47517SecurityThe audit log was cleared
48518SecurityA notification package has been loaded by the Security Account Manager
49519SecurityA process is using an invalid local procedure call (LPC) port
50520SecurityThe system time was changed
51528SecuritySuccessful Logon
52529SecurityLogon Failure - Unknown user name or bad password
53530SecurityLogon Failure - Account logon time restriction violation
54531SecurityLogon Failure - Account currently disabled
55532SecurityLogon Failure - The specified user account has expired
56533SecurityLogon Failure - User not allowed to logon at this computer
57534SecurityLogon Failure - The user has not been granted the requested logon type at this machine
58535SecurityLogon Failure - The specified account's password has expired
59536SecurityLogon Failure - The NetLogon component is not active
60537SecurityLogon failure - The logon attempt failed for other reasons.
61538SecurityUser Logoff
62539SecurityLogon Failure - Account locked out
63540SecuritySuccessful Network Logon
64551SecurityUser initiated logoff
65552SecurityLogon attempt using explicit credentials
66560SecurityObject Open
67561SecurityHandle Allocated
68562SecurityHandle Closed
69563SecurityObject Open for Delete
70564SecurityObject Deleted
71565SecurityObject Open (Active Directory)
72566SecurityObject Operation (W3 Active Directory)
73567SecurityObject Access Attempt
74576SecuritySpecial privileges assigned to new logon
75577SecurityPrivileged Service Called
76578SecurityPrivileged object operation
77592SecurityA new process has been created
78593SecurityA process has exited
79594SecurityA handle to an object has been duplicated
80595SecurityIndirect access to an object has been obtained
81600SecurityA process was assigned a primary token
82601SecurityAttempt to install service
83602SecurityScheduled Task created
84608SecurityUser Right Assigned
85609SecurityUser Right Removed
86610SecurityNew Trusted Domain
87611SecurityRemoving Trusted Domain
88612SecurityAudit Policy Change
89613SecurityIPSec policy agent started
90614SecurityIPSec policy agent disabled
91615SecurityIPSEC PolicyAgent Service
92616SecurityIPSec policy agent encountered a potentially serious failure.
93617SecurityKerberos Policy Changed
94618SecurityEncrypted Data Recovery Policy Changed
95619SecurityQuality of Service Policy Changed
96620SecurityTrusted Domain Information Modified
97621SecuritySystem Security Access Granted
98622SecuritySystem Security Access Removed
99623SecurityPer User Audit Policy was refreshed
100624SecurityUser Account Created
101625SecurityUser Account Type Changed
102626SecurityUser Account Enabled
103627SecurityChange Password Attempt
104628SecurityUser Account password set
105629SecurityUser Account Disabled
106630SecurityUser Account Deleted
107631SecuritySecurity Enabled Global Group Created
108632SecuritySecurity Enabled Global Group Member Added
109633SecuritySecurity Enabled Global Group Member Removed
110634SecuritySecurity Enabled Global Group Deleted
111635SecuritySecurity Enabled Local Group Created
112636SecuritySecurity Enabled Local Group Member Added
113637SecuritySecurity Enabled Local Group Member Removed
114638SecuritySecurity Enabled Local Group Deleted
115639SecuritySecurity Enabled Local Group Changed
116640SecurityGeneral Account Database Change
117641SecuritySecurity Enabled Global Group Changed
118642SecurityUser Account Changed
119643SecurityDomain Policy Changed
120644SecurityUser Account Locked Out
121645SecurityComputer Account Created
122646SecurityComputer Account Changed
123647SecurityComputer Account Deleted
124648SecuritySecurity Disabled Local Group Created
125649SecuritySecurity Disabled Local Group Changed
126650SecuritySecurity Disabled Local Group Member Added
127651SecuritySecurity Disabled Local Group Member Removed
128652SecuritySecurity Disabled Local Group Deleted
129653SecuritySecurity Disabled Global Group Created
130654SecuritySecurity Disabled Global Group Changed
131655SecuritySecurity Disabled Global Group Member Added
132656SecuritySecurity Disabled Global Group Member Removed
133657SecuritySecurity Disabled Global Group Deleted
134658SecuritySecurity Enabled Universal Group Created
135659SecuritySecurity Enabled Universal Group Changed
136660SecuritySecurity Enabled Universal Group Member Added
137661SecuritySecurity Enabled Universal Group Member Removed
138662SecuritySecurity Enabled Universal Group Deleted
139663SecuritySecurity Disabled Universal Group Created
140664SecuritySecurity Disabled Universal Group Changed
141665SecuritySecurity Disabled Universal Group Member Added
142666SecuritySecurity Disabled Universal Group Member Removed
143667SecuritySecurity Disabled Universal Group Deleted
144668SecurityGroup Type Changed
145669SecurityAdd SID History
146670SecurityAdd SID History
147671SecurityUser Account Unlocked
148672SecurityAuthentication Ticket Granted
149673SecurityService Ticket Granted
150674SecurityTicket Granted Renewed
151675SecurityPre-authentication failed
152676SecurityAuthentication Ticket Request Failed
153677SecurityService Ticket Request Failed
154678SecurityAccount Mapped for Logon by
155679SecurityAccount could not be mapped for logon
156680SecurityAccount Used for Logon by
157681SecurityLogon to Account failed
158682SecuritySession reconnected to winstation
159683SecuritySession disconnected from winstation
160684SecuritySet ACLs of members in administrators groups
161685SecurityAccount Name Changed
162686SecurityPassword of the following user accessed
163687SecurityBasic Application Group Created
164688SecurityBasic Application Group Changed
165689SecurityBasic Application Group Member Added
166690SecurityBasic Application Group Member Removed
167691SecurityBasic Application Group Non-Member Added
168692SecurityBasic Application Group Non-Member Removed
169693SecurityBasic Application Group Deleted
170694SecurityLDAP Query Group Created
171695SecurityLDAP Query Group Changed
172696SecurityLDAP Query Group Deleted
173697SecurityPassword Policy Checking API is called
174806SecurityPer User Audit Policy was refreshed
175807SecurityPer user auditing policy set for user
176808SecurityA security event source has attempted to register
177809SecurityA security event source has attempted to unregister
178848SecurityThe following policy was active when the Windows Firewall started
179849SecurityAn application was listed as an exception when the Windows Firewall started
180850SecurityA port was listed as an exception when the Windows Firewall started
181851SecurityA change has been made to Windows Firewall exception list
182852SecurityA change has been made to the Windows Firewall port exception list
183854SecurityA Windows Firewall setting has changed
184855SecurityICMP settings changed
185856SecurityA rule has been partially ignored by Windows Firewall
186857SecurityA rule has been rejected by Windows Firewall
187858SecurityThe Windows Firewall group policy settings have been removed
188859SecurityThe Windows Firewall group policy settings have been removed
189860SecurityThe Windows Firewall has switched the active policy profile
190861SecurityThe Windows Firewall has detected an application listening for incoming traffic
1911100SecurityThe event logging service has shut down
1921101SecurityAudit events have been dropped by the transport.
1931102SecurityThe audit log was cleared
1941104SecurityThe security Log is now full
1951105SecurityEvent log automatic backup
1961108SecurityThe event logging service encountered an error
1974500SecurityMetabase Add Key
1984501SecurityMetabase Delete Key
1994502SecurityMetabase Delete Chid Keys
2004503SecurityMetabase Copy Key
2014504SecurityMetabase Rename Key
2024505SecurityMetabase Set Data
2034506SecurityMetabase Delete Data
2044507SecurityMetabase Delete All Data
2054508SecurityMetabase Copy Data
2064509SecurityMetabase Set Last Change Time
2074510SecurityMetabase Restore
2084511SecurityMetabase Delete Backup
2094512SecurityMetabase Import
2104608SecurityWindows is starting up
2114609SecurityWindows is shutting down
2124610SecurityAn authentication package has been loaded by the Local Security Authority
2134611SecurityA trusted logon process has been registered with the Local Security Authority
2144612SecurityInternal resources exhausted - loss of events
2154614SecurityA notification package has been loaded by the Security Account Manager.
2164615SecurityInvalid use of LPC port
2174616SecurityThe system time was changed.
2184618SecurityA monitored security event pattern has occurred
2194621SecurityAdministrator recovered system from CrashOnAuditFail
2204622SecurityA security package has been loaded by the Local Security Authority.
2214624SecurityAn account was successfully logged on
2224625SecurityAn account failed to log on
2234634SecurityAn account was logged off
2244646SecurityIKE DoS-prevention mode started.
2254647SecurityUser initiated logoff
2264648SecurityA logon was attempted using explicit credentials
2274649SecurityA replay attack was detected
2284650SecurityAn IPsec Main Mode security association was established
2294651SecurityAn IPsec Main Mode security association was established
2304652SecurityAn IPsec Main Mode negotiation failed
2314653SecurityAn IPsec Main Mode negotiation failed
2324654SecurityAn IPsec Quick Mode negotiation failed
2334655SecurityAn IPsec Main Mode security association ended
2344656SecurityA handle to an object was requested
2354657SecurityA registry value was modified
2364658SecurityThe handle to an object was closed
2374659SecurityA handle to an object was requested with intent to delete
2384660SecurityAn object was deleted
2394661SecurityA handle to an object was requested
2404662SecurityAn operation was performed on an object
2414663SecurityAn attempt was made to access an object
2424664SecurityAn attempt was made to create a hard link
2434665SecurityAn attempt was made to create an application client context.
2444666SecurityAn application attempted an operation
2454667SecurityAn application client context was deleted
2464668SecurityAn application was initialized
2474670SecurityPermissions on an object were changed
2484671SecurityAn application attempted to access a blocked ordinal through the TBS
2494672SecuritySpecial privileges assigned to new logon
2504673SecurityA privileged service was called
2514674SecurityAn operation was attempted on a privileged object
2524675SecuritySIDs were filtered
2534688SecurityA new process has been created
2544689SecurityA process has exited
2554690SecurityAn attempt was made to duplicate a handle to an object
2564691SecurityIndirect access to an object was requested
2574692SecurityBackup of data protection master key was attempted
2584693SecurityRecovery of data protection master key was attempted
2594694SecurityProtection of auditable protected data was attempted
2604695SecurityUnprotection of auditable protected data was attempted
2614696SecurityA primary token was assigned to process
2624697SecurityA service was installed in the system
2634698SecurityA scheduled task was created
2644699SecurityA scheduled task was deleted
2654700SecurityA scheduled task was enabled
2664701SecurityA scheduled task was disabled
2674702SecurityA scheduled task was updated
2684704SecurityA user right was assigned
2694705SecurityA user right was removed
2704706SecurityA new trust was created to a domain
2714707SecurityA trust to a domain was removed
2724709SecurityIPsec Services was started
2734710SecurityIPsec Services was disabled
2744711SecurityPAStore Engine (1%)
2754712SecurityIPsec Services encountered a potentially serious failure
2764713SecurityKerberos policy was changed
2774714SecurityEncrypted data recovery policy was changed
2784715SecurityThe audit policy (SACL) on an object was changed
2794716SecurityTrusted domain information was modified
2804717SecuritySystem security access was granted to an account
2814718SecuritySystem security access was removed from an account
2824719SecuritySystem audit policy was changed
2834720SecurityA user account was created
2844722SecurityA user account was enabled
2854723SecurityAn attempt was made to change an account's password
2864724SecurityAn attempt was made to reset an accounts password
2874725SecurityA user account was disabled
2884726SecurityA user account was deleted
2894727SecurityA security-enabled global group was created
2904728SecurityA member was added to a security-enabled global group
2914729SecurityA member was removed from a security-enabled global group
2924730SecurityA security-enabled global group was deleted
2934731SecurityA security-enabled local group was created
2944732SecurityA member was added to a security-enabled local group
2954733SecurityA member was removed from a security-enabled local group
2964734SecurityA security-enabled local group was deleted
2974735SecurityA security-enabled local group was changed
2984737SecurityA security-enabled global group was changed
2994738SecurityA user account was changed
3004739SecurityDomain Policy was changed
3014740SecurityA user account was locked out
3024741SecurityA computer account was created
3034742SecurityA computer account was changed
3044743SecurityA computer account was deleted
3054744SecurityA security-disabled local group was created
3064745SecurityA security-disabled local group was changed
3074746SecurityA member was added to a security-disabled local group
3084747SecurityA member was removed from a security-disabled local group
3094748SecurityA security-disabled local group was deleted
3104749SecurityA security-disabled global group was created
3114750SecurityA security-disabled global group was changed
3124751SecurityA member was added to a security-disabled global group
3134752SecurityA member was removed from a security-disabled global group
3144753SecurityA security-disabled global group was deleted
3154754SecurityA security-enabled universal group was created
3164755SecurityA security-enabled universal group was changed
3174756SecurityA member was added to a security-enabled universal group
3184757SecurityA member was removed from a security-enabled universal group
3194758SecurityA security-enabled universal group was deleted
3204759SecurityA security-disabled universal group was created
3214760SecurityA security-disabled universal group was changed
3224761SecurityA member was added to a security-disabled universal group
3234762SecurityA member was removed from a security-disabled universal group
3244763SecurityA security-disabled universal group was deleted
3254764SecurityA groups type was changed
3264765SecuritySID History was added to an account
3274766SecurityAn attempt to add SID History to an account failed
3284767SecurityA user account was unlocked
3294768SecurityA Kerberos authentication ticket (TGT) was requested
3304769SecurityA Kerberos service ticket was requested
3314770SecurityA Kerberos service ticket was renewed
3324771SecurityKerberos pre-authentication failed
3334772SecurityA Kerberos authentication ticket request failed
3344773SecurityA Kerberos service ticket request failed
3354774SecurityAn account was mapped for logon
3364775SecurityAn account could not be mapped for logon
3374776SecurityThe domain controller attempted to validate the credentials for an account
3384777SecurityThe domain controller failed to validate the credentials for an account
3394778SecurityA session was reconnected to a Window Station
3404779SecurityA session was disconnected from a Window Station
3414780SecurityThe ACL was set on accounts which are members of administrators groups
3424781SecurityThe name of an account was changed
3434782SecurityThe password hash an account was accessed
3444783SecurityA basic application group was created
3454784SecurityA basic application group was changed
3464785SecurityA member was added to a basic application group
3474786SecurityA member was removed from a basic application group
3484787SecurityA non-member was added to a basic application group
3494788SecurityA non-member was removed from a basic application group..
3504789SecurityA basic application group was deleted
3514790SecurityAn LDAP query group was created
3524791SecurityA basic application group was changed
3534792SecurityAn LDAP query group was deleted
3544793SecurityThe Password Policy Checking API was called
3554794SecurityAn attempt was made to set the Directory Services Restore Mode administrator password
3564800SecurityThe workstation was locked
3574801SecurityThe workstation was unlocked
3584802SecurityThe screen saver was invoked
3594803SecurityThe screen saver was dismissed
3604816SecurityRPC detected an integrity violation while decrypting an incoming message
3614817SecurityAuditing settings on object were changed.
3624864SecurityA namespace collision was detected
3634865SecurityA trusted forest information entry was added
3644866SecurityA trusted forest information entry was removed
3654867SecurityA trusted forest information entry was modified
3664868SecurityThe certificate manager denied a pending certificate request
3674869SecurityCertificate Services received a resubmitted certificate request
3684870SecurityCertificate Services revoked a certificate
3694871SecurityCertificate Services received a request to publish the certificate revocation list (CRL)
3704872SecurityCertificate Services published the certificate revocation list (CRL)
3714873SecurityA certificate request extension changed
3724874SecurityOne or more certificate request attributes changed.
3734875SecurityCertificate Services received a request to shut down
3744876SecurityCertificate Services backup started
3754877SecurityCertificate Services backup completed
3764878SecurityCertificate Services restore started
3774879SecurityCertificate Services restore completed
3784880SecurityCertificate Services started
3794881SecurityCertificate Services stopped
3804882SecurityThe security permissions for Certificate Services changed
3814883SecurityCertificate Services retrieved an archived key
3824884SecurityCertificate Services imported a certificate into its database
3834885SecurityThe audit filter for Certificate Services changed
3844886SecurityCertificate Services received a certificate request
3854887SecurityCertificate Services approved a certificate request and issued a certificate
3864888SecurityCertificate Services denied a certificate request
3874889SecurityCertificate Services set the status of a certificate request to pending
3884890SecurityThe certificate manager settings for Certificate Services changed.
3894891SecurityA configuration entry changed in Certificate Services
3904892SecurityA property of Certificate Services changed
3914893SecurityCertificate Services archived a key
3924894SecurityCertificate Services imported and archived a key
3934895SecurityCertificate Services published the CA certificate to Active Directory Domain Services
3944896SecurityOne or more rows have been deleted from the certificate database
3954897SecurityRole separation enabled
3964898SecurityCertificate Services loaded a template
3974899SecurityA Certificate Services template was updated
3984900SecurityCertificate Services template security was updated
3994902SecurityThe Per-user audit policy table was created
4004904SecurityAn attempt was made to register a security event source
4014905SecurityAn attempt was made to unregister a security event source
4024906SecurityThe CrashOnAuditFail value has changed
4034907SecurityAuditing settings on object were changed
4044908SecuritySpecial Groups Logon table modified
4054909SecurityThe local policy settings for the TBS were changed
4064910SecurityThe group policy settings for the TBS were changed
4074912SecurityPer User Audit Policy was changed
4084928SecurityAn Active Directory replica source naming context was established
4094929SecurityAn Active Directory replica source naming context was removed
4104930SecurityAn Active Directory replica source naming context was modified
4114931SecurityAn Active Directory replica destination naming context was modified
4124932SecuritySynchronization of a replica of an Active Directory naming context has begun
4134933SecuritySynchronization of a replica of an Active Directory naming context has ended
4144934SecurityAttributes of an Active Directory object were replicated
4154935SecurityReplication failure begins
4164936SecurityReplication failure ends
4174937SecurityA lingering object was removed from a replica
4184944SecurityThe following policy was active when the Windows Firewall started
4194945SecurityA rule was listed when the Windows Firewall started
4204946SecurityA change has been made to Windows Firewall exception list. A rule was added
4214947SecurityA change has been made to Windows Firewall exception list. A rule was modified
4224948SecurityA change has been made to Windows Firewall exception list. A rule was deleted
4234949SecurityWindows Firewall settings were restored to the default values
4244950SecurityA Windows Firewall setting has changed
4254951SecurityA rule has been ignored by Windows Firewall
4264952SecurityParts of a rule have been ignored by Windows Firewall
4274953SecurityA rule has been ignored by Windows Firewall because it could not parse the rule
4284954SecurityWindows Firewall Group Policy settings has changed. The new settings have been applied
4294956SecurityWindows Firewall has changed the active profile
4304957SecurityWindows Firewall did not apply a rule
4314958SecurityWindows Firewall did not apply a rule
4324960SecurityIPsec dropped an inbound packet that failed an integrity check
4334961SecurityIPsec dropped an inbound packet that failed a replay check
4344962SecurityIPsec dropped an inbound packet that failed a replay check
4354963SecurityIPsec dropped an inbound clear text packet that should have been secured
4364964SecuritySpecial groups have been assigned to a new logon
4374965SecurityIPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).
4384976SecurityDuring Main Mode negotiation,Security,IPsec received an invalid negotiation packet.
4394977SecurityDuring Quick Mode negotiation,Security,IPsec received an invalid negotiation packet.
4404978SecurityDuring Extended Mode negotiation,Security,IPsec received an invalid negotiation packet.
4414979SecurityIPsec Main Mode and Extended Mode security associations were established.
4424980SecurityIPsec Main Mode and Extended Mode security associations were established
4434981SecurityIPsec Main Mode and Extended Mode security associations were established
4444982SecurityIPsec Main Mode and Extended Mode security associations were established
4454983SecurityAn IPsec Extended Mode negotiation failed
4464984SecurityAn IPsec Extended Mode negotiation failed
4474985SecurityThe state of a transaction has changed
4485024SecurityThe Windows Firewall Service has started successfully
4495025SecurityThe Windows Firewall Service has been stopped
4505027SecurityThe Windows Firewall Service was unable to retrieve the security policy from the local storage
4515028SecurityThe Windows Firewall Service was unable to parse the new security policy.
4525029SecurityThe Windows Firewall Service failed to initialize the driver
4535030SecurityThe Windows Firewall Service failed to start
4545031SecurityThe Windows Firewall Service blocked an application on the network.
4555032SecurityWindows Firewall was unable to notify the user about blocked connections
4565033SecurityThe Windows Firewall Driver has started successfully
4575034SecurityThe Windows Firewall Driver has been stopped
4585035SecurityThe Windows Firewall Driver failed to start
4595037SecurityThe Windows Firewall Driver detected critical runtime error. Terminating
4605038SecurityCode integrity determined that the image hash of a file is not valid
4615039SecurityA registry key was virtualized.
4625040SecurityA change has been made to IPsec settings. An Authentication Set was added.
4635041SecurityA change has been made to IPsec settings. An Authentication Set was modified
4645042SecurityA change has been made to IPsec settings. An Authentication Set was deleted
4655043SecurityA change has been made to IPsec settings. A Connection Security Rule was added
4665044SecurityA change has been made to IPsec settings. A Connection Security Rule was modified
4675045SecurityA change has been made to IPsec settings. A Connection Security Rule was deleted
4685046SecurityA change has been made to IPsec settings. A Crypto Set was added
4695047SecurityA change has been made to IPsec settings. A Crypto Set was modified
4705048SecurityA change has been made to IPsec settings. A Crypto Set was deleted
4715049SecurityAn IPsec Security Association was deleted
4725050SecurityAn attempt to programmatically disable the Windows Firewall
4735051SecurityA file was virtualized
4745056SecurityA cryptographic self test was performed
4755057SecurityA cryptographic primitive operation failed
4765058SecurityKey file operation
4775059SecurityKey migration operation
4785060SecurityVerification operation failed
4795061SecurityCryptographic operation
4805062SecurityA kernel-mode cryptographic self test was performed
4815063SecurityA cryptographic provider operation was attempted
4825064SecurityA cryptographic context operation was attempted
4835065SecurityA cryptographic context modification was attempted
4845066SecurityA cryptographic function operation was attempted
4855067SecurityA cryptographic function modification was attempted
4865068SecurityA cryptographic function provider operation was attempted
4875069SecurityA cryptographic function property operation was attempted
4885070SecurityA cryptographic function property operation was attempted
4895120SecurityOCSP Responder Service Started
4905121SecurityOCSP Responder Service Stopped
4915122SecurityA Configuration entry changed in the OCSP Responder Service
4925123SecurityA configuration entry changed in the OCSP Responder Service
4935124SecurityA security setting was updated on OCSP Responder Service
4945125SecurityA request was submitted to OCSP Responder Service
4955126SecuritySigning Certificate was automatically updated by the OCSP Responder Service
4965127SecurityThe OCSP Revocation Provider successfully updated the revocation information
4975136SecurityA directory service object was modified
4985137SecurityA directory service object was created
4995138SecurityA directory service object was undeleted
5005139SecurityA directory service object was moved
5015140SecurityA network share object was accessed
5025141SecurityA directory service object was deleted
5035142SecurityA network share object was added.
5045143SecurityA network share object was modified
5055144SecurityA network share object was deleted.
5065145SecurityA network share object was checked to see whether client can be granted desired access
5075148SecurityThe Windows Filtering Platform has detected a DoS attack and entered a defensive mode
5085149SecurityThe DoS attack has subsided and normal processing is being resumed.
5095150SecurityThe Windows Filtering Platform has blocked a packet.
5105151SecurityA more restrictive Windows Filtering Platform filter has blocked a packet.
5115152SecurityThe Windows Filtering Platform blocked a packet
5125153SecurityA more restrictive Windows Filtering Platform filter has blocked a packet
5135154SecurityThe Windows Filtering Platform has permitted an application or service to listen
5145155SecurityThe Windows Filtering Platform has blocked an application or service from listening
5155156SecurityThe Windows Filtering Platform has allowed a connection
5165157SecurityThe Windows Filtering Platform has blocked a connection
5175158SecurityThe Windows Filtering Platform has permitted a bind to a local port
5185159SecurityThe Windows Filtering Platform has blocked a bind to a local port
5195168SecuritySpn check for SMB/SMB2 fails.
5205376SecurityCredential Manager credentials were backed up
5215377SecurityCredential Manager credentials were restored from a backup
5225378SecurityThe requested credentials delegation was disallowed by policy
5235440SecurityThe following callout was present when the Windows Filtering Platform Base Filtering Engine started
5245441SecurityThe following filter was present when the Windows Filtering Platform Base Filtering Engine started
5255442SecurityThe following provider was present when the Windows Filtering Platform Base Filtering Engine started
5265443SecurityThe following provider context was present when the Windows Filtering Platform Base Filtering Engine started
5275444SecurityThe following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
5285446SecurityA Windows Filtering Platform callout has been changed
5295447SecurityA Windows Filtering Platform filter has been changed
5305448SecurityA Windows Filtering Platform provider has been changed
5315449SecurityA Windows Filtering Platform provider context has been changed
5325450SecurityA Windows Filtering Platform sub-layer has been changed
5335451SecurityAn IPsec Quick Mode security association was established
5345452SecurityAn IPsec Quick Mode security association ended
5355453SecurityAn IPsec negotiation with a remote computer failed
5365456SecurityPAStore Engine applied Active Directory storage IPsec policy on the computer
5375457SecurityPAStore Engine failed to apply Active Directory storage IPsec policy on the computer
5385458SecurityPAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
5395459SecurityPAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
5405460SecurityPAStore Engine applied local registry storage IPsec policy on the computer
5415461SecurityPAStore Engine failed to apply local registry storage IPsec policy on the computer
5425462SecurityPAStore Engine failed to apply some rules of the active IPsec policy on the computer
5435463SecurityPAStore Engine polled for changes to the active IPsec policy and detected no changes
5445464SecurityPAStore Engine applied changes to IPsec Services
5455465SecurityPAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
5465466SecurityPAStore Engine determined that Active Directory cannot be reached and will use the cached copy of the Active Directory IPsec policy instead
5475467SecurityPAStore Engine found no changes to the IPSec policy
5485468SecurityPAStore Engine found changes to the policy and applied those changes
5495471SecurityPAStore Engine loaded local storage IPsec policy on the computer
5505472SecurityPAStore Engine failed to load local storage IPsec policy on the computer
5515473SecurityPAStore Engine loaded directory storage IPsec policy on the computer
5525474SecurityPAStore Engine failed to load directory storage IPsec policy on the computer
5535477SecurityPAStore Engine failed to add quick mode filter
5545478SecurityIPsec Services has started successfully
5555479SecurityIPsec Services has been shut down successfully
5565480SecurityIPsec Services failed to get the complete list of network interfaces on the computer
5575483SecurityIPsec Services failed to initialize RPC server. IPsec Services could not be started
5585484SecurityIPsec Services has experienced a critical failure and has been shut down
5595485SecurityIPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
5605632SecurityA request was made to authenticate to a wireless network
5615633SecurityA request was made to authenticate to a wired network
5625712SecurityA Remote Procedure Call (RPC) was attempted
5635888SecurityAn object in the COM+ Catalog was modified
5645889SecurityAn object was deleted from the COM+ Catalog
5655890SecurityAn object was added to the COM+ Catalog
5666144SecuritySecurity policy in the group policy objects has been applied successfully
5676145SecurityOne or more errors occured while processing security policy in the group policy objects
5686272SecurityNetwork Policy Server granted access to a user
5696273SecurityNetwork Policy Server denied access to a user
5706274SecurityNetwork Policy Server discarded the request for a user
5716275SecurityNetwork Policy Server discarded the accounting request for a user
5726276SecurityNetwork Policy Server quarantined a user
5736277SecurityNetwork Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
5746278SecurityNetwork Policy Server granted full access to a user because the host met the defined health policy
5756279SecurityNetwork Policy Server locked the user account due to repeated failed authentication attempts
5766280SecurityNetwork Policy Server unlocked the user account
5776281SecurityCode Integrity determined that the page hashes of an image file are not valid...
5786400SecurityBranchCache: Received an incorrectly formatted response while discovering availability of content.
5796401SecurityBranchCache: Received invalid data from a peer. Data discarded.
5806402SecurityBranchCache: The message to the hosted cache offering it data is incorrectly formatted.
5816403SecurityBranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.
5826404SecurityBranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
5836405SecurityBranchCache: Multiple instances of another Event ID
5846406SecurityA application registered to Windows Firewall to control filtering for the following:
5856407SecurityUnknown - see event
5866408SecurityRegistered product failed and Windows Firewall is now controlling the filtering.
5871014SystemName resolution for critical SRV timed out
5881056SystemDynamic DNS Registration credentials not set
5895782SystemNo DNS servers configured for local system