You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

34 KiB

1LogNameEventCodeEventCodeDescription
2Security10Noise Entry
3Security512Windows NT is starting up
4Security513Windows is shutting down
5Security514An authentication package has been loaded by the Local Security Authority
6Security515A trusted logon process has registered with the Local Security Authority
7Security516Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits
8Security517The audit log was cleared
9Security518A notification package has been loaded by the Security Account Manager
10Security519A process is using an invalid local procedure call (LPC) port
11Security520The system time was changed
12Security528Successful Logon
13Security529Logon Failure - Unknown user name or bad password
14Security530Logon Failure - Account logon time restriction violation
15Security531Logon Failure - Account currently disabled
16Security532Logon Failure - The specified user account has expired
17Security533Logon Failure - User not allowed to logon at this computer
18Security534Logon Failure - The user has not been granted the requested logon type at this machine
19Security535Logon Failure - The specified account's password has expired
20Security536Logon Failure - The NetLogon component is not active
21Security537Logon failure - The logon attempt failed for other reasons.
22Security538User Logoff
23Security539Logon Failure - Account locked out
24Security540Successful Network Logon
25Security551User initiated logoff
26Security552Logon attempt using explicit credentials
27Security560Object Open
28Security561Handle Allocated
29Security562Handle Closed
30Security563Object Open for Delete
31Security564Object Deleted
32Security565Object Open (Active Directory)
33Security566Object Operation (W3 Active Directory)
34Security567Object Access Attempt
35Security576Special privileges assigned to new logon
36Security577Privileged Service Called
37Security578Privileged object operation
38Security592A new process has been created
39Security593A process has exited
40Security594A handle to an object has been duplicated
41Security595Indirect access to an object has been obtained
42Security600A process was assigned a primary token
43Security601Attempt to install service
44Security602Scheduled Task created
45Security608User Right Assigned
46Security609User Right Removed
47Security610New Trusted Domain
48Security611Removing Trusted Domain
49Security612Audit Policy Change
50Security613IPSec policy agent started
51Security614IPSec policy agent disabled
52Security615IPSEC PolicyAgent Service
53Security616IPSec policy agent encountered a potentially serious failure.
54Security617Kerberos Policy Changed
55Security618Encrypted Data Recovery Policy Changed
56Security619Quality of Service Policy Changed
57Security620Trusted Domain Information Modified
58Security621System Security Access Granted
59Security622System Security Access Removed
60Security623Per User Audit Policy was refreshed
61Security624User Account Created
62Security625User Account Type Changed
63Security626User Account Enabled
64Security627Change Password Attempt
65Security628User Account password set
66Security629User Account Disabled
67Security630User Account Deleted
68Security631Security Enabled Global Group Created
69Security632Security Enabled Global Group Member Added
70Security633Security Enabled Global Group Member Removed
71Security634Security Enabled Global Group Deleted
72Security635Security Enabled Local Group Created
73Security636Security Enabled Local Group Member Added
74Security637Security Enabled Local Group Member Removed
75Security638Security Enabled Local Group Deleted
76Security639Security Enabled Local Group Changed
77Security640General Account Database Change
78Security641Security Enabled Global Group Changed
79Security642User Account Changed
80Security643Domain Policy Changed
81Security644User Account Locked Out
82Security645Computer Account Created
83Security646Computer Account Changed
84Security647Computer Account Deleted
85Security648Security Disabled Local Group Created
86Security649Security Disabled Local Group Changed
87Security650Security Disabled Local Group Member Added
88Security651Security Disabled Local Group Member Removed
89Security652Security Disabled Local Group Deleted
90Security653Security Disabled Global Group Created
91Security654Security Disabled Global Group Changed
92Security655Security Disabled Global Group Member Added
93Security656Security Disabled Global Group Member Removed
94Security657Security Disabled Global Group Deleted
95Security658Security Enabled Universal Group Created
96Security659Security Enabled Universal Group Changed
97Security660Security Enabled Universal Group Member Added
98Security661Security Enabled Universal Group Member Removed
99Security662Security Enabled Universal Group Deleted
100Security663Security Disabled Universal Group Created
101Security664Security Disabled Universal Group Changed
102Security665Security Disabled Universal Group Member Added
103Security666Security Disabled Universal Group Member Removed
104Security667Security Disabled Universal Group Deleted
105Security668Group Type Changed
106Security669Add SID History
107Security670Add SID History
108Security671User Account Unlocked
109Security672Authentication Ticket Granted
110Security673Service Ticket Granted
111Security674Ticket Granted Renewed
112Security675Pre-authentication failed
113Security676Authentication Ticket Request Failed
114Security677Service Ticket Request Failed
115Security678Account Mapped for Logon by
116Security679The name: %2 could not be mapped for logon by: %1
117Security680Account Used for Logon by
118Security681The logon to account: %2 by: %1 from workstation: %3 failed.
119Security682Session reconnected to winstation
120Security683Session disconnected from winstation
121Security684Set ACLs of members in administrators groups
122Security685Account Name Changed
123Security686Password of the following user accessed
124Security687Basic Application Group Created
125Security688Basic Application Group Changed
126Security689Basic Application Group Member Added
127Security690Basic Application Group Member Removed
128Security691Basic Application Group Non-Member Added
129Security692Basic Application Group Non-Member Removed
130Security693Basic Application Group Deleted
131Security694LDAP Query Group Created
132Security695LDAP Query Group Changed
133Security696LDAP Query Group Deleted
134Security697Password Policy Checking API is called
135Security806Per User Audit Policy was refreshed
136Security807Per user auditing policy set for user
137Security808A security event source has attempted to register
138Security809A security event source has attempted to unregister
139Security848The following policy was active when the Windows Firewall started
140Security849An application was listed as an exception when the Windows Firewall started
141Security850A port was listed as an exception when the Windows Firewall started
142Security851A change has been made to Windows Firewall exception list
143Security852A change has been made to the Windows Firewall port exception list
144Security854A Windows Firewall setting has changed
145Security855ICMP settings changed
146Security856A rule has been partially ignored because its minor version number was not recognized by Windows Firewall
147Security857A rule has been rejected by Windows Firewall
148Security858The Windows Firewall group policy settings have been removed
149Security859The Windows Firewall group policy settings have been removed
150Security860The Windows Firewall has switched the active policy profile
151Security861The Windows Firewall has detected an application listening for incoming traffic
152Security1100The event logging service has shut down
153Security1101Audit events have been dropped by the transport.
154Security1102The audit log was cleared
155Security1104The security Log is now full
156Security1105Event log automatic backup
157Security1108The event logging service encountered an error
158Security4500Metabase Add Key
159Security4501Metabase Delete Key
160Security4502Metabase Delete Chid Keys
161Security4503Metabase Copy Key
162Security4504Metabase Rename Key
163Security4505Metabase Set Data
164Security4506Metabase Delete Data
165Security4507Metabase Delete All Data
166Security4508Metabase Copy Data
167Security4509Metabase Set Last Change Time
168Security4510Metabase Restore
169Security4511Metabase Delete Backup
170Security4512Metabase Import
171Security4608Windows is starting up
172Security4609Windows is shutting down
173Security4610An authentication package has been loaded by the Local Security Authority
174Security4611A trusted logon process has been registered with the Local Security Authority
175Security4612Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
176Security4614A notification package has been loaded by the Security Account Manager.
177Security4615Invalid use of LPC port
178Security4616The system time was changed.
179Security4618A monitored security event pattern has occurred
180Security4621Administrator recovered system from CrashOnAuditFail
181Security4622A security package has been loaded by the Local Security Authority.
182Security4624An account was successfully logged on
183Security4625An account failed to log on
184Security4634An account was logged off
185Security4646IKE DoS-prevention mode started.
186Security4647User initiated logoff
187Security4648A logon was attempted using explicit credentials
188Security4649A replay attack was detected
189Security4650An IPsec Main Mode security association was established
190Security4651An IPsec Main Mode security association was established
191Security4652An IPsec Main Mode negotiation failed
192Security4653An IPsec Main Mode negotiation failed
193Security4654An IPsec Quick Mode negotiation failed
194Security4655An IPsec Main Mode security association ended
195Security4656A handle to an object was requested
196Security4657A registry value was modified
197Security4658The handle to an object was closed
198Security4659A handle to an object was requested with intent to delete
199Security4660An object was deleted
200Security4661A handle to an object was requested
201Security4662An operation was performed on an object
202Security4663An attempt was made to access an object
203Security4664An attempt was made to create a hard link
204Security4665An attempt was made to create an application client context.
205Security4666An application attempted an operation
206Security4667An application client context was deleted
207Security4668An application was initialized
208Security4670Permissions on an object were changed
209Security4671An application attempted to access a blocked ordinal through the TBS
210Security4672Special privileges assigned to new logon
211Security4673A privileged service was called
212Security4674An operation was attempted on a privileged object
213Security4675SIDs were filtered
214Security4688A new process has been created
215Security4689A process has exited
216Security4690An attempt was made to duplicate a handle to an object
217Security4691Indirect access to an object was requested
218Security4692Backup of data protection master key was attempted
219Security4693Recovery of data protection master key was attempted
220Security4694Protection of auditable protected data was attempted
221Security4695Unprotection of auditable protected data was attempted
222Security4696A primary token was assigned to process
223Security4697A service was installed in the system
224Security4698A scheduled task was created
225Security4699A scheduled task was deleted
226Security4700A scheduled task was enabled
227Security4701A scheduled task was disabled
228Security4702A scheduled task was updated
229Security4704A user right was assigned
230Security4705A user right was removed
231Security4706A new trust was created to a domain
232Security4707A trust to a domain was removed
233Security4709IPsec Services was started
234Security4710IPsec Services was disabled
235Security4711PAStore Engine (1%)
236Security4712IPsec Services encountered a potentially serious failure
237Security4713Kerberos policy was changed
238Security4714Encrypted data recovery policy was changed
239Security4715The audit policy (SACL) on an object was changed
240Security4716Trusted domain information was modified
241Security4717System security access was granted to an account
242Security4718System security access was removed from an account
243Security4719System audit policy was changed
244Security4720A user account was created
245Security4722A user account was enabled
246Security4723An attempt was made to change an account's password
247Security4724An attempt was made to reset an accounts password
248Security4725A user account was disabled
249Security4726A user account was deleted
250Security4727A security-enabled global group was created
251Security4728A member was added to a security-enabled global group
252Security4729A member was removed from a security-enabled global group
253Security4730A security-enabled global group was deleted
254Security4731A security-enabled local group was created
255Security4732A member was added to a security-enabled local group
256Security4733A member was removed from a security-enabled local group
257Security4734A security-enabled local group was deleted
258Security4735A security-enabled local group was changed
259Security4737A security-enabled global group was changed
260Security4738A user account was changed
261Security4739Domain Policy was changed
262Security4740A user account was locked out
263Security4741A computer account was created
264Security4742A computer account was changed
265Security4743A computer account was deleted
266Security4744A security-disabled local group was created
267Security4745A security-disabled local group was changed
268Security4746A member was added to a security-disabled local group
269Security4747A member was removed from a security-disabled local group
270Security4748A security-disabled local group was deleted
271Security4749A security-disabled global group was created
272Security4750A security-disabled global group was changed
273Security4751A member was added to a security-disabled global group
274Security4752A member was removed from a security-disabled global group
275Security4753A security-disabled global group was deleted
276Security4754A security-enabled universal group was created
277Security4755A security-enabled universal group was changed
278Security4756A member was added to a security-enabled universal group
279Security4757A member was removed from a security-enabled universal group
280Security4758A security-enabled universal group was deleted
281Security4759A security-disabled universal group was created
282Security4760A security-disabled universal group was changed
283Security4761A member was added to a security-disabled universal group
284Security4762A member was removed from a security-disabled universal group
285Security4763A security-disabled universal group was deleted
286Security4764A groups type was changed
287Security4765SID History was added to an account
288Security4766An attempt to add SID History to an account failed
289Security4767A user account was unlocked
290Security4768A Kerberos authentication ticket (TGT) was requested
291Security4769A Kerberos service ticket was requested
292Security4770A Kerberos service ticket was renewed
293Security4771Kerberos pre-authentication failed
294Security4772A Kerberos authentication ticket request failed
295Security4773A Kerberos service ticket request failed
296Security4774An account was mapped for logon
297Security4775An account could not be mapped for logon
298Security4776The domain controller attempted to validate the credentials for an account
299Security4777The domain controller failed to validate the credentials for an account
300Security4778A session was reconnected to a Window Station
301Security4779A session was disconnected from a Window Station
302Security4780The ACL was set on accounts which are members of administrators groups
303Security4781The name of an account was changed
304Security4782The password hash an account was accessed
305Security4783A basic application group was created
306Security4784A basic application group was changed
307Security4785A member was added to a basic application group
308Security4786A member was removed from a basic application group
309Security4787A non-member was added to a basic application group
310Security4788A non-member was removed from a basic application group..
311Security4789A basic application group was deleted
312Security4790An LDAP query group was created
313Security4791A basic application group was changed
314Security4792An LDAP query group was deleted
315Security4793The Password Policy Checking API was called
316Security4794An attempt was made to set the Directory Services Restore Mode administrator password
317Security4800The workstation was locked
318Security4801The workstation was unlocked
319Security4802The screen saver was invoked
320Security4803The screen saver was dismissed
321Security4816RPC detected an integrity violation while decrypting an incoming message
322Security4817Auditing settings on object were changed.
323Security4864A namespace collision was detected
324Security4865A trusted forest information entry was added
325Security4866A trusted forest information entry was removed
326Security4867A trusted forest information entry was modified
327Security4868The certificate manager denied a pending certificate request
328Security4869Certificate Services received a resubmitted certificate request
329Security4870Certificate Services revoked a certificate
330Security4871Certificate Services received a request to publish the certificate revocation list (CRL)
331Security4872Certificate Services published the certificate revocation list (CRL)
332Security4873A certificate request extension changed
333Security4874One or more certificate request attributes changed.
334Security4875Certificate Services received a request to shut down
335Security4876Certificate Services backup started
336Security4877Certificate Services backup completed
337Security4878Certificate Services restore started
338Security4879Certificate Services restore completed
339Security4880Certificate Services started
340Security4881Certificate Services stopped
341Security4882The security permissions for Certificate Services changed
342Security4883Certificate Services retrieved an archived key
343Security4884Certificate Services imported a certificate into its database
344Security4885The audit filter for Certificate Services changed
345Security4886Certificate Services received a certificate request
346Security4887Certificate Services approved a certificate request and issued a certificate
347Security4888Certificate Services denied a certificate request
348Security4889Certificate Services set the status of a certificate request to pending
349Security4890The certificate manager settings for Certificate Services changed.
350Security4891A configuration entry changed in Certificate Services
351Security4892A property of Certificate Services changed
352Security4893Certificate Services archived a key
353Security4894Certificate Services imported and archived a key
354Security4895Certificate Services published the CA certificate to Active Directory Domain Services
355Security4896One or more rows have been deleted from the certificate database
356Security4897Role separation enabled
357Security4898Certificate Services loaded a template
358Security4899A Certificate Services template was updated
359Security4900Certificate Services template security was updated
360Security4902The Per-user audit policy table was created
361Security4904An attempt was made to register a security event source
362Security4905An attempt was made to unregister a security event source
363Security4906The CrashOnAuditFail value has changed
364Security4907Auditing settings on object were changed
365Security4908Special Groups Logon table modified
366Security4909The local policy settings for the TBS were changed
367Security4910The group policy settings for the TBS were changed
368Security4912Per User Audit Policy was changed
369Security4928An Active Directory replica source naming context was established
370Security4929An Active Directory replica source naming context was removed
371Security4930An Active Directory replica source naming context was modified
372Security4931An Active Directory replica destination naming context was modified
373Security4932Synchronization of a replica of an Active Directory naming context has begun
374Security4933Synchronization of a replica of an Active Directory naming context has ended
375Security4934Attributes of an Active Directory object were replicated
376Security4935Replication failure begins
377Security4936Replication failure ends
378Security4937A lingering object was removed from a replica
379Security4944The following policy was active when the Windows Firewall started
380Security4945A rule was listed when the Windows Firewall started
381Security4946A change has been made to Windows Firewall exception list. A rule was added
382Security4947A change has been made to Windows Firewall exception list. A rule was modified
383Security4948A change has been made to Windows Firewall exception list. A rule was deleted
384Security4949Windows Firewall settings were restored to the default values
385Security4950A Windows Firewall setting has changed
386Security4951A rule has been ignored because its major version number was not recognized by Windows Firewall
387Security4952Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
388Security4953A rule has been ignored by Windows Firewall because it could not parse the rule
389Security4954Windows Firewall Group Policy settings has changed. The new settings have been applied
390Security4956Windows Firewall has changed the active profile
391Security4957Windows Firewall did not apply the following rule
392Security4958Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer
393Security4960IPsec dropped an inbound packet that failed an integrity check
394Security4961IPsec dropped an inbound packet that failed a replay check
395Security4962IPsec dropped an inbound packet that failed a replay check
396Security4963IPsec dropped an inbound clear text packet that should have been secured
397Security4964Special groups have been assigned to a new logon
398Security4965IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).
399Security4976During Main Mode negotiation, IPsec received an invalid negotiation packet.
400Security4977During Quick Mode negotiation, IPsec received an invalid negotiation packet.
401Security4978During Extended Mode negotiation, IPsec received an invalid negotiation packet.
402Security4979IPsec Main Mode and Extended Mode security associations were established.
403Security4980IPsec Main Mode and Extended Mode security associations were established
404Security4981IPsec Main Mode and Extended Mode security associations were established
405Security4982IPsec Main Mode and Extended Mode security associations were established
406Security4983An IPsec Extended Mode negotiation failed
407Security4984An IPsec Extended Mode negotiation failed
408Security4985The state of a transaction has changed
409Security5024The Windows Firewall Service has started successfully
410Security5025The Windows Firewall Service has been stopped
411Security5027The Windows Firewall Service was unable to retrieve the security policy from the local storage
412Security5028The Windows Firewall Service was unable to parse the new security policy.
413Security5029The Windows Firewall Service failed to initialize the driver
414Security5030The Windows Firewall Service failed to start
415Security5031The Windows Firewall Service blocked an application from accepting incoming connections on the network.
416Security5032Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network
417Security5033The Windows Firewall Driver has started successfully
418Security5034The Windows Firewall Driver has been stopped
419Security5035The Windows Firewall Driver failed to start
420Security5037The Windows Firewall Driver detected critical runtime error. Terminating
421Security5038Code integrity determined that the image hash of a file is not valid
422Security5039A registry key was virtualized.
423Security5040A change has been made to IPsec settings. An Authentication Set was added.
424Security5041A change has been made to IPsec settings. An Authentication Set was modified
425Security5042A change has been made to IPsec settings. An Authentication Set was deleted
426Security5043A change has been made to IPsec settings. A Connection Security Rule was added
427Security5044A change has been made to IPsec settings. A Connection Security Rule was modified
428Security5045A change has been made to IPsec settings. A Connection Security Rule was deleted
429Security5046A change has been made to IPsec settings. A Crypto Set was added
430Security5047A change has been made to IPsec settings. A Crypto Set was modified
431Security5048A change has been made to IPsec settings. A Crypto Set was deleted
432Security5049An IPsec Security Association was deleted
433Security5050An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE
434Security5051A file was virtualized
435Security5056A cryptographic self test was performed
436Security5057A cryptographic primitive operation failed
437Security5058Key file operation
438Security5059Key migration operation
439Security5060Verification operation failed
440Security5061Cryptographic operation
441Security5062A kernel-mode cryptographic self test was performed
442Security5063A cryptographic provider operation was attempted
443Security5064A cryptographic context operation was attempted
444Security5065A cryptographic context modification was attempted
445Security5066A cryptographic function operation was attempted
446Security5067A cryptographic function modification was attempted
447Security5068A cryptographic function provider operation was attempted
448Security5069A cryptographic function property operation was attempted
449Security5070A cryptographic function property operation was attempted
450Security5120OCSP Responder Service Started
451Security5121OCSP Responder Service Stopped
452Security5122A Configuration entry changed in the OCSP Responder Service
453Security5123A configuration entry changed in the OCSP Responder Service
454Security5124A security setting was updated on OCSP Responder Service
455Security5125A request was submitted to OCSP Responder Service
456Security5126Signing Certificate was automatically updated by the OCSP Responder Service
457Security5127The OCSP Revocation Provider successfully updated the revocation information
458Security5136A directory service object was modified
459Security5137A directory service object was created
460Security5138A directory service object was undeleted
461Security5139A directory service object was moved
462Security5140A network share object was accessed
463Security5141A directory service object was deleted
464Security5142A network share object was added.
465Security5143A network share object was modified
466Security5144A network share object was deleted.
467Security5145A network share object was checked to see whether client can be granted desired access
468Security5148The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
469Security5149The DoS attack has subsided and normal processing is being resumed.
470Security5150The Windows Filtering Platform has blocked a packet.
471Security5151A more restrictive Windows Filtering Platform filter has blocked a packet.
472Security5152The Windows Filtering Platform blocked a packet
473Security5153A more restrictive Windows Filtering Platform filter has blocked a packet
474Security5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections
475Security5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections
476Security5156The Windows Filtering Platform has allowed a connection
477Security5157The Windows Filtering Platform has blocked a connection
478Security5158The Windows Filtering Platform has permitted a bind to a local port
479Security5159The Windows Filtering Platform has blocked a bind to a local port
480Security5168Spn check for SMB/SMB2 fails.
481Security5376Credential Manager credentials were backed up
482Security5377Credential Manager credentials were restored from a backup
483Security5378The requested credentials delegation was disallowed by policy
484Security5440The following callout was present when the Windows Filtering Platform Base Filtering Engine started
485Security5441The following filter was present when the Windows Filtering Platform Base Filtering Engine started
486Security5442The following provider was present when the Windows Filtering Platform Base Filtering Engine started
487Security5443The following provider context was present when the Windows Filtering Platform Base Filtering Engine started
488Security5444The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
489Security5446A Windows Filtering Platform callout has been changed
490Security5447A Windows Filtering Platform filter has been changed
491Security5448A Windows Filtering Platform provider has been changed
492Security5449A Windows Filtering Platform provider context has been changed
493Security5450A Windows Filtering Platform sub-layer has been changed
494Security5451An IPsec Quick Mode security association was established
495Security5452An IPsec Quick Mode security association ended
496Security5453An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started
497Security5456PAStore Engine applied Active Directory storage IPsec policy on the computer
498Security5457PAStore Engine failed to apply Active Directory storage IPsec policy on the computer
499Security5458PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
500Security5459PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
501Security5460PAStore Engine applied local registry storage IPsec policy on the computer
502Security5461PAStore Engine failed to apply local registry storage IPsec policy on the computer
503Security5462PAStore Engine failed to apply some rules of the active IPsec policy on the computer
504Security5463PAStore Engine polled for changes to the active IPsec policy and detected no changes
505Security5464PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services
506Security5465PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
507Security5466PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead
508Security5467PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy
509Security5468PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes
510Security5471PAStore Engine loaded local storage IPsec policy on the computer
511Security5472PAStore Engine failed to load local storage IPsec policy on the computer
512Security5473PAStore Engine loaded directory storage IPsec policy on the computer
513Security5474PAStore Engine failed to load directory storage IPsec policy on the computer
514Security5477PAStore Engine failed to add quick mode filter
515Security5478IPsec Services has started successfully
516Security5479IPsec Services has been shut down successfully
517Security5480IPsec Services failed to get the complete list of network interfaces on the computer
518Security5483IPsec Services failed to initialize RPC server. IPsec Services could not be started
519Security5484IPsec Services has experienced a critical failure and has been shut down
520Security5485IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
521Security5632A request was made to authenticate to a wireless network
522Security5633A request was made to authenticate to a wired network
523Security5712A Remote Procedure Call (RPC) was attempted
524Security5888An object in the COM+ Catalog was modified
525Security5889An object was deleted from the COM+ Catalog
526Security5890An object was added to the COM+ Catalog
527Security6144Security policy in the group policy objects has been applied successfully
528Security6145One or more errors occured while processing security policy in the group policy objects
529Security6272Network Policy Server granted access to a user
530Security6273Network Policy Server denied access to a user
531Security6274Network Policy Server discarded the request for a user
532Security6275Network Policy Server discarded the accounting request for a user
533Security6276Network Policy Server quarantined a user
534Security6277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
535Security6278Network Policy Server granted full access to a user because the host met the defined health policy
536Security6279Network Policy Server locked the user account due to repeated failed authentication attempts
537Security6280Network Policy Server unlocked the user account
538Security6281Code Integrity determined that the page hashes of an image file are not valid...
539Security6400BranchCache: Received an incorrectly formatted response while discovering availability of content.
540Security6401BranchCache: Received invalid data from a peer. Data discarded.
541Security6402BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
542Security6403BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.
543Security6404BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
544Security6405BranchCache: %2 instance(s) of event id %1 occurred.
545Security6406%1 registered to Windows Firewall to control filtering for the following:
546Security6407%1
547Security6408Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.