You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

34 KiB

1signature_idsignatureCategoryStringactionresultcommand
2512Windows NT is starting up
3513Windows is shutting down
4514An authentication package has been loaded by the Local Security Authority
5515A trusted logon process has registered with the Local Security Authority
6516Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits
7517The audit log was cleared
8518A notification package has been loaded by the Security Account Manager
9519A process is using an invalid local procedure call (LPC) port
10520The system time was changed
11528Successful Logon
12529Unknown user name or bad password
13530Account logon time restriction violation
14531Account currently disabled
15532The specified user account has expired
16533User not allowed to logon at this computer
17534The user has not been granted the requested logon type at this machine
18535The specified account's password has expired
19536The NetLogon component is not active
20537The logon attempt failed for other reasons.
21538User Logoff
22539Logon Failure - Account locked out
23540Successful Network Logon
24551User initiated logoff
25552Logon attempt using explicit credentials
26560Object Open
27561Handle Allocated
28562Handle Closed
29563Object Open for Delete
30564Object Deleted
31565Object Open (Active Directory)
32566Object Operation (W3 Active Directory)
33567Object Access Attempt
34576Special privileges assigned to new logon
35577Privileged Service Called
36578Privileged object operation
37592A new process has been created
38593A process has exited
39594A handle to an object has been duplicated
40595Indirect access to an object has been obtained
41600A process was assigned a primary token
42601Attempt to install service
43602Scheduled Task created
44608User Right Assigned
45609User Right Removed
46610New Trusted Domain
47611Removing Trusted Domain
48612Audit Policy Change
49613IPSec policy agent started
50614IPSec policy agent disabled
51615IPSEC PolicyAgent Service
52616IPSec policy agent encountered a potentially serious failure.
53617Kerberos Policy Changed
54618Encrypted Data Recovery Policy Changed
55619Quality of Service Policy Changed
56620Trusted Domain Information Modified
57621System Security Access Granted
58622System Security Access Removed
59623Per User Audit Policy was refreshed
60624User Account CreatedAccount Managementcreated
61625User Account Type Changed
62626User Account EnabledAccount Management
63627Change Password AttemptAccount Management
64628User Account password setAccount Managementmodified
65629User Account DisabledAccount Management
66630User Account DeletedAccount Managementdeleted
67631Security Enabled Global Group CreatedAccount Management
68632Security Enabled Global Group Member AddedAccount Management
69633Security Enabled Global Group Member RemovedAccount Management
70634Security Enabled Global Group DeletedAccount Management
71635Security Enabled Local Group CreatedAccount Management
72636Security Enabled Local Group Member AddedAccount Management
73637Security Enabled Local Group Member RemovedAccount Management
74638Security Enabled Local Group DeletedAccount Management
75639Security Enabled Local Group ChangedAccount Management
76640General Account Database ChangeAccount Management
77641Security Enabled Global Group ChangedAccount Management
78642User Account ChangedAccount Managementmodified
79643Domain Policy ChangedAccount Management
80644User Account Locked OutAccount Managementmodifiedlockout
81645Computer Account CreatedAccount Management
82646Computer Account ChangedAccount Management
83647Computer Account DeletedAccount Management
84648Security Disabled Local Group CreatedAccount Management
85649Security Disabled Local Group ChangedAccount Management
86650Security Disabled Local Group Member AddedAccount Management
87651Security Disabled Local Group Member RemovedAccount Management
88652Security Disabled Local Group DeletedAccount Management
89653Security Disabled Global Group CreatedAccount Management
90654Security Disabled Global Group ChangedAccount Management
91655Security Disabled Global Group Member AddedAccount Management
92656Security Disabled Global Group Member RemovedAccount Management
93657Security Disabled Global Group DeletedAccount Management
94658Security Enabled Universal Group CreatedAccount Management
95659Security Enabled Universal Group ChangedAccount Management
96660Security Enabled Universal Group Member AddedAccount Management
97661Security Enabled Universal Group Member RemovedAccount Management
98662Security Enabled Universal Group DeletedAccount Management
99663Security Disabled Universal Group CreatedAccount Management
100664Security Disabled Universal Group ChangedAccount Management
101665Security Disabled Universal Group Member AddedAccount Management
102666Security Disabled Universal Group Member RemovedAccount Management
103667Security Disabled Universal Group DeletedAccount Management
104668Group Type ChangedAccount Management
105669Add SID HistoryAccount Management
106670Add SID HistoryAccount Management
107671User Account UnlockedAccount Management
108672Authentication Ticket Granted
109673Service Ticket Granted
110674Ticket Granted Renewed
111675Pre-authentication failed
112676Authentication Ticket Request Failed
113677Service Ticket Request Failed
114678Account Mapped for Logon by
115679The name: %2 could not be mapped for logon by: %1
116680Account Used for Logon by
117681The logon to account: %2 by: %1 from workstation: %3 failed.
118682Session reconnected to winstation
119683Session disconnected from winstation
120684Set ACLs of members in administrators groupsAccount Management
121685Account Name ChangedAccount Management
122686Password of the following user accessedAccount Management
123687Basic Application Group CreatedAccount Management
124688Basic Application Group ChangedAccount Management
125689Basic Application Group Member AddedAccount Management
126690Basic Application Group Member RemovedAccount Management
127691Basic Application Group Non-Member AddedAccount Management
128692Basic Application Group Non-Member RemovedAccount Management
129693Basic Application Group DeletedAccount Management
130694LDAP Query Group CreatedAccount Management
131695LDAP Query Group ChangedAccount Management
132696LDAP Query Group DeletedAccount Management
133697Password Policy Checking API is calledAPI Calls
134806Per User Audit Policy was refreshed
135807Per user auditing policy set for user
136808A security event source has attempted to register
137809A security event source has attempted to unregister
138848The following policy was active when the Windows Firewall started
139849An application was listed as an exception when the Windows Firewall started
140850A port was listed as an exception when the Windows Firewall started
141852A change has been made to the Windows Firewall port exception list
142861The Windows Firewall has detected an application listening for incoming traffic
1431100The event logging service has shut down
1441101Audit events have been dropped by the transport.
1451102The audit log was cleared
1461104The security Log is now full
1471105Event log automatic backup
1481108The event logging service encountered an error
1494500Metabase Add Key
1504501Metabase Delete Key
1514502Metabase Delete Chid Keys
1524503Metabase Copy Key
1534504Metabase Rename Key
1544505Metabase Set Data
1554506Metabase Delete Data
1564507Metabase Delete All Data
1574508Metabase Copy Data
1584509Metabase Set Last Change Time
1594510Metabase Restore
1604511Metabase Delete Backup
1614512Metabase Import
1624608Windows is starting up
1634609Windows is shutting down
1644610An authentication package has been loaded by the Local Security Authority
1654611A trusted logon process has been registered with the Local Security Authority
1664612Internal resources allocated for the queuing of audit messages have been exhausted, leading to the loss of some audits.
1674614A notification package has been loaded by the Security Account Manager.
1684615Invalid use of LPC port
1694616The system time was changed.
1704618A monitored security event pattern has occurred
1714621Administrator recovered system from CrashOnAuditFail
1724622A security package has been loaded by the Local Security Authority.
1734624An account was successfully logged on
1744625An account failed to log on
1754634An account was logged off
1764646%1
1774647User initiated logoff
1784648A logon was attempted using explicit credentials
1794649A replay attack was detected
1804650An IPsec Main Mode security association was established
1814651An IPsec Main Mode security association was established
1824652An IPsec Main Mode negotiation failed
1834653An IPsec Main Mode negotiation failed
1844654An IPsec Quick Mode negotiation failed
1854655An IPsec Main Mode security association ended
1864656A handle to an object was requested
1874657A registry value was modified
1884658The handle to an object was closed
1894659A handle to an object was requested with intent to delete
1904660An object was deleted
1914661A handle to an object was requested
1924662An operation was performed on an object
1934663An attempt was made to access an object
1944664An attempt was made to create a hard link
1954665An attempt was made to create an application client context.
1964666An application attempted an operation
1974667An application client context was deleted
1984668An application was initialized
1994670Permissions on an object were changed
2004671An application attempted to access a blocked ordinal through the TBS
2014672Special privileges assigned to new logon
2024673A privileged service was called
2034674An operation was attempted on a privileged object
2044675SIDs were filtered
2054685The state of a transaction has changed
2064688A new process has been created
2074689A process has exited
2084690An attempt was made to duplicate a handle to an object
2094691Indirect access to an object was requested
2104692Backup of data protection master key was attempted
2114693Recovery of data protection master key was attempted
2124694Protection of auditable protected data was attempted
2134695Unprotection of auditable protected data was attempted
2144696A primary token was assigned to process
2154697A service was installed in the system
2164698A scheduled task was created
2174699A scheduled task was deleted
2184700A scheduled task was enabled
2194701A scheduled task was disabled
2204702A scheduled task was updated
2214704A user right was assigned
2224705A user right was removed
2234706A new trust was created to a domainA new trust was created to a domainA new trust was created to a domain.
2244707A trust to a domain was removed
2254709IPsec Services was started
2264710IPsec Services was disabled
2274711PAStore Engine (1%)
2284712IPsec Services encountered a potentially serious failure
2294713Kerberos policy was changedKerberos policy was changedKerberos policy was changed.
2304714Encrypted data recovery policy was changed
2314715The audit policy (SACL) on an object was changed
2324716Trusted domain information was modified
2334717System security access was granted to an account
2344718System security access was removed from an account
2354719System audit policy was changed
2364720A user account was createdAccount Management
2374722A user account was enabledAccount Management
2384723An attempt was made to change an account's passwordAccount Management
2394724An attempt was made to reset an accounts passwordAccount Management
2404725A user account was disabledAccount Management
2414726A user account was deletedAccount Management
2424727A security-enabled global group was createdAccount Management
2434728A member was added to a security-enabled global groupAccount Management
2444729A member was removed from a security-enabled global groupAccount Management
2454730A security-enabled global group was deletedAccount Management
2464731A security-enabled local group was createdAccount Management
2474732A member was added to a security-enabled local groupAccount Management
2484733A member was removed from a security-enabled local groupAccount Management
2494734A security-enabled local group was deletedAccount Management
2504735A security-enabled local group was changedAccount Management
2514737A security-enabled global group was changedAccount Management
2524738A user account was changedAccount Management
2534739Domain Policy was changedAccount Management
2544740A user account was locked outAccount Management
2554741A computer account was createdAccount Management
2564742A computer account was changedAccount Management
2574743A computer account was deletedAccount Management
2584744A security-disabled local group was createdA security-disabled local group was createdA security-disabled local group was created.
2594745A security-disabled local group was changedAccount Management
2604746A member was added to a security-disabled local groupAccount Management
2614747A member was removed from a security-disabled local groupAccount Management
2624748A security-disabled local group was deletedAccount Management
2634749A security-disabled global group was createdA security-disabled global group was createdA security-disabled global group was created.
2644750A security-disabled global group was changedA security-disabled global group was changedA security-disabled global group was changed.
2654751A member was added to a security-disabled global groupAccount Management
2664752A member was removed from a security-disabled global groupAccount Management
2674753A security-disabled global group was deletedAccount Management
2684754A security-enabled universal group was createdAccount Management
2694755A security-enabled universal group was changedAccount Management
2704756A member was added to a security-enabled universal groupAccount Management
2714757A member was removed from a security-enabled universal groupAccount Management
2724758A security-enabled universal group was deletedAccount Management
2734759A security-disabled universal group was createdA security-disabled universal group was createdA security-disabled universal group was created.
2744760A security-disabled universal group was changedAccount Management
2754761A member was added to a security-disabled universal groupAccount Management
2764762A member was removed from a security-disabled universal groupAccount Management
2774763A security-disabled universal group was deletedAccount Management
2784764A group's type was changedAccount Management
2794765SID History was added to an accountAccount Management
2804766An attempt to add SID History to an account failedAccount Management
2814767A user account was unlockedAccount Management
2824768A Kerberos authentication ticket (TGT) was requested
2834769A Kerberos service ticket was requested
2844770A Kerberos service ticket was renewed
2854771Kerberos pre-authentication failed
2864772A Kerberos authentication ticket request failed
2874773A Kerberos service ticket request failed
2884774An account was mapped for logon
2894775An account could not be mapped for logon
2904776The domain controller attempted to validate the credentials for an account
2914777The domain controller failed to validate the credentials for an account
2924778A session was reconnected to a Window Station
2934779A session was disconnected from a Window Station
2944780The ACL was set on accounts which are members of administrators groupsAccount Management
2954781The name of an account was changedAccount Management
2964782The password hash an account was accessedAccount Management
2974783A basic application group was createdAccount Management
2984784A basic application group was changedAccount Management
2994785A member was added to a basic application groupAccount Management
3004786A member was removed from a basic application groupAccount Management
3014787A non-member was added to a basic application groupAccount Management
3024788A non-member was removed from a basic application group..Account Management
3034789A basic application group was deletedAccount Management
3044790An LDAP query group was createdAccount Management
3054791A basic application group was changedAccount Management
3064792An LDAP query group was deletedAccount Management
3074793The Password Policy Checking API was calledAPI Calls
3084794An attempt was made to set the Directory Services Restore Mode administrator passwordAccount Managementset the Directory Services Restore Mode administrator password.
3094798A user's local group membership was enumerated.
3104799A security-enabled local group membership was enumerated
3114800The workstation was locked
3124801The workstation was unlocked
3134802The screen saver was invoked
3144803The screen saver was dismissed
3154816RPC detected an integrity violation while decrypting an incoming message
3164817Auditing settings on object were changed.
3174864A namespace collision was detected
3184865A trusted forest information entry was added
3194866A trusted forest information entry was removed
3204867A trusted forest information entry was modified
3214868The certificate manager denied a pending certificate request
3224869Certificate Services received a resubmitted certificate request
3234870Certificate Services revoked a certificate
3244871Certificate Services received a request to publish the certificate revocation list (CRL)
3254872Certificate Services published the certificate revocation list (CRL)
3264873A certificate request extension changed
3274874One or more certificate request attributes changed.
3284875Certificate Services received a request to shut down
3294876Certificate Services backup startedCertificate Services backup startedCertificate Services backup started.
3304877Certificate Services backup completed
3314878Certificate Services restore started
3324879Certificate Services restore completed
3334880Certificate Services started
3344881Certificate Services stopped
3354882The security permissions for Certificate Services changed
3364883Certificate Services retrieved an archived key
3374884Certificate Services imported a certificate into its database
3384885The audit filter for Certificate Services changed
3394886Certificate Services received a certificate request
3404887Certificate Services approved a certificate request and issued a certificate
3414888Certificate Services denied a certificate request
3424889Certificate Services set the status of a certificate request to pending
3434890The certificate manager settings for Certificate Services changed.
3444891A configuration entry changed in Certificate Services
3454892A property of Certificate Services changed
3464893Certificate Services archived a key
3474894Certificate Services imported and archived a key
3484895Certificate Services published the CA certificate to Active Directory Domain Services
3494896One or more rows have been deleted from the certificate database
3504897Role separation enabled
3514898Certificate Services loaded a template
3524899A Certificate Services template was updated
3534900Certificate Services template security was updated
3544902The Per-user audit policy table was created
3554904An attempt was made to register a security event source
3564905An attempt was made to unregister a security event source
3574906The CrashOnAuditFail value has changed
3584907Auditing settings on object were changed
3594908Special Groups Logon table modified
3604909The local policy settings for the TBS were changed
3614910The group policy settings for the TBS were changed
3624912Per User Audit Policy was changed
3634928An Active Directory replica source naming context was established
3644929An Active Directory replica source naming context was removed
3654930An Active Directory replica source naming context was modified
3664931An Active Directory replica destination naming context was modified
3674932Synchronization of a replica of an Active Directory naming context has begun
3684933Synchronization of a replica of an Active Directory naming context has ended
3694934Attributes of an Active Directory object were replicated
3704935Replication failure begins
3714936Replication failure ends
3724937A lingering object was removed from a replica
3734944The following policy was active when the Windows Firewall started
3744945A rule was listed when the Windows Firewall started
3754946A change has been made to Windows Firewall exception list. A rule was added
3764947A change has been made to Windows Firewall exception list. A rule was modified
3774948A change has been made to Windows Firewall exception list. A rule was deleted
3784949Windows Firewall settings were restored to the default values
3794950A Windows Firewall setting has changed
3804951A rule has been ignored because its major version number was not recognized by Windows Firewall
3814952Parts of a rule have been ignored because its minor version number was not recognized by Windows Firewall
3824953A rule has been ignored by Windows Firewall because it could not parse the rule
3834954Windows Firewall Group Policy settings has changed. The new settings have been applied
3844956Windows Firewall has changed the active profile
3854957Windows Firewall did not apply the following rule
3864958Windows Firewall did not apply the following rule because the rule referred to items not configured on this computer
3874960IPsec dropped an inbound packet that failed an integrity check
3884961IPsec dropped an inbound packet that failed a replay check
3894962IPsec dropped an inbound packet that failed a replay check
3904963IPsec dropped an inbound clear text packet that should have been secured
3914964Special groups have been assigned to a new logon
3924965IPsec received a packet from a remote computer with an incorrect Security Parameter Index (SPI).
3934976During Main Mode negotiation, IPsec received an invalid negotiation packet.
3944977During Quick Mode negotiation, IPsec received an invalid negotiation packet.
3954978During Extended Mode negotiation, IPsec received an invalid negotiation packet.
3964979IPsec Main Mode and Extended Mode security associations were established.
3974980IPsec Main Mode and Extended Mode security associations were established
3984981IPsec Main Mode and Extended Mode security associations were established
3994982IPsec Main Mode and Extended Mode security associations were established
4004983An IPsec Extended Mode negotiation failed
4014984An IPsec Extended Mode negotiation failed
4024985The state of a transaction has changed
4035024The Windows Firewall Service has started successfully
4045025The Windows Firewall Service has been stopped
4055027The Windows Firewall Service was unable to retrieve the security policy from the local storage
4065028The Windows Firewall Service was unable to parse the new security policy.
4075029The Windows Firewall Service failed to initialize the driver
4085030The Windows Firewall Service failed to start
4095031The Windows Firewall Service blocked an application from accepting incoming connections on the network.
4105032Windows Firewall was unable to notify the user that it blocked an application from accepting incoming connections on the network
4115033The Windows Firewall Driver has started successfully
4125034The Windows Firewall Driver has been stopped
4135035The Windows Firewall Driver failed to start
4145037The Windows Firewall Driver detected critical runtime error. Terminating
4155038Code integrity determined that the image hash of a file is not valid
4165039A registry key was virtualized.
4175040A change has been made to IPsec settings. An Authentication Set was added.
4185041A change has been made to IPsec settings. An Authentication Set was modified
4195042A change has been made to IPsec settings. An Authentication Set was deleted
4205043A change has been made to IPsec settings. A Connection Security Rule was added
4215044A change has been made to IPsec settings. A Connection Security Rule was modified
4225045A change has been made to IPsec settings. A Connection Security Rule was deleted
4235046A change has been made to IPsec settings. A Crypto Set was added
4245047A change has been made to IPsec settings. A Crypto Set was modified
4255048A change has been made to IPsec settings. A Crypto Set was deleted
4265049An IPsec Security Association was deleted
4275050An attempt to programmatically disable the Windows Firewall using a call to INetFwProfile.FirewallEnabled(FALSE
4285051A file was virtualized
4295056A cryptographic self test was performed
4305057A cryptographic primitive operation failed
4315058Key file operation
4325059Key migration operation
4335060Verification operation failed
4345061Cryptographic operation
4355062A kernel-mode cryptographic self test was performed
4365063A cryptographic provider operation was attempted
4375064A cryptographic context operation was attempted
4385065A cryptographic context modification was attempted
4395066A cryptographic function operation was attempted
4405067A cryptographic function modification was attempted
4415068A cryptographic function provider operation was attempted
4425069A cryptographic function property operation was attempted
4435070A cryptographic function property operation was attempted
4445120OCSP Responder Service Started
4455121OCSP Responder Service Stopped
4465122A Configuration entry changed in the OCSP Responder Service
4475123A configuration entry changed in the OCSP Responder Service
4485124A security setting was updated on OCSP Responder Service
4495125A request was submitted to OCSP Responder Service
4505126Signing Certificate was automatically updated by the OCSP Responder Service
4515127The OCSP Revocation Provider successfully updated the revocation information
4525136A directory service object was modified
4535137A directory service object was created
4545138A directory service object was undeleted
4555139A directory service object was moved
4565140A network share object was accessed
4575141A directory service object was deleted
4585142A network share object was added.
4595143A network share object was modified
4605144A network share object was deleted.
4615145A network share object was checked to see whether client can be granted desired access
4625148The Windows Filtering Platform has detected a DoS attack and entered a defensive mode; packets associated with this attack will be discarded.
4635149The DoS attack has subsided and normal processing is being resumed.
4645150The Windows Filtering Platform has blocked a packet.
4655151A more restrictive Windows Filtering Platform filter has blocked a packet.
4665152The Windows Filtering Platform blocked a packet
4675153A more restrictive Windows Filtering Platform filter has blocked a packet
4685154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections
4695155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections
4705156The Windows Filtering Platform has allowed a connection
4715157The Windows Filtering Platform has blocked a connection
4725158The Windows Filtering Platform has permitted a bind to a local port
4735159The Windows Filtering Platform has blocked a bind to a local port
4745168Spn check for SMB/SMB2 fails.
4755376Credential Manager credentials were backed upAccount Management
4765377Credential Manager credentials were restored from a backupAccount Management
4775378The requested credentials delegation was disallowed by policy
4785440The following callout was present when the Windows Filtering Platform Base Filtering Engine started
4795441The following filter was present when the Windows Filtering Platform Base Filtering Engine started
4805442The following provider was present when the Windows Filtering Platform Base Filtering Engine started
4815443The following provider context was present when the Windows Filtering Platform Base Filtering Engine started
4825444The following sub-layer was present when the Windows Filtering Platform Base Filtering Engine started
4835446A Windows Filtering Platform callout has been changed
4845447A Windows Filtering Platform filter has been changed
4855448A Windows Filtering Platform provider has been changed
4865449A Windows Filtering Platform provider context has been changed
4875450A Windows Filtering Platform sub-layer has been changed
4885451An IPsec Quick Mode security association was established
4895452An IPsec Quick Mode security association ended
4905453An IPsec negotiation with a remote computer failed because the IKE and AuthIP IPsec Keying Modules (IKEEXT) service is not started
4915456PAStore Engine applied Active Directory storage IPsec policy on the computer
4925457PAStore Engine failed to apply Active Directory storage IPsec policy on the computer
4935458PAStore Engine applied locally cached copy of Active Directory storage IPsec policy on the computer
4945459PAStore Engine failed to apply locally cached copy of Active Directory storage IPsec policy on the computer
4955460PAStore Engine applied local registry storage IPsec policy on the computer
4965461PAStore Engine failed to apply local registry storage IPsec policy on the computer
4975462PAStore Engine failed to apply some rules of the active IPsec policy on the computer
4985463PAStore Engine polled for changes to the active IPsec policy and detected no changes
4995464PAStore Engine polled for changes to the active IPsec policy, detected changes, and applied them to IPsec Services
5005465PAStore Engine received a control for forced reloading of IPsec policy and processed the control successfully
5015466PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory cannot be reached, and will use the cached copy of the Active Directory IPsec policy instead
5025467PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, and found no changes to the policy
5035468PAStore Engine polled for changes to the Active Directory IPsec policy, determined that Active Directory can be reached, found changes to the policy, and applied those changes
5045471PAStore Engine loaded local storage IPsec policy on the computer
5055472PAStore Engine failed to load local storage IPsec policy on the computer
5065473PAStore Engine loaded directory storage IPsec policy on the computer
5075474PAStore Engine failed to load directory storage IPsec policy on the computer
5085477PAStore Engine failed to add quick mode filter
5095478IPsec Services has started successfully
5105479IPsec Services has been shut down successfully
5115480IPsec Services failed to get the complete list of network interfaces on the computer
5125483IPsec Services failed to initialize RPC server. IPsec Services could not be started
5135484IPsec Services has experienced a critical failure and has been shut down
5145485IPsec Services failed to process some IPsec filters on a plug-and-play event for network interfaces
5155632A request was made to authenticate to a wireless network
5165633A request was made to authenticate to a wired network
5175712A Remote Procedure Call (RPC) was attempted
5185888An object in the COM+ Catalog was modified
5195889An object was deleted from the COM+ Catalog
5205890An object was added to the COM+ Catalog
5216144Security policy in the group policy objects has been applied successfully
5226145One or more errors occured while processing security policy in the group policy objects
5236272Network Policy Server granted access to a user
5246273Network Policy Server denied access to a user
5256274Network Policy Server discarded the request for a user
5266275Network Policy Server discarded the accounting request for a user
5276276Network Policy Server quarantined a user
5286277Network Policy Server granted access to a user but put it on probation because the host did not meet the defined health policy
5296278Network Policy Server granted full access to a user because the host met the defined health policy
5306279Network Policy Server locked the user account due to repeated failed authentication attempts
5316280Network Policy Server unlocked the user account
5326281Code Integrity determined that the page hashes of an image file are not valid...
5336400BranchCache: Received an incorrectly formatted response while discovering availability of content.
5346401BranchCache: Received invalid data from a peer. Data discarded.
5356402BranchCache: The message to the hosted cache offering it data is incorrectly formatted.
5366403BranchCache: The hosted cache sent an incorrectly formatted response to the client's message to offer it data.
5376404BranchCache: Hosted cache could not be authenticated using the provisioned SSL certificate.
5386405BranchCache: %2 instance(s) of event id %1 occurred.
5396406%1 registered to Windows Firewall to control filtering for the following:
5406407%1
5416408Registered product %1 failed and Windows Firewall is now controlling the filtering for %2.