Skip to main content

Windows application platform event channels

25channels
0curated reasons
0themes fed
Plannedstatus

Application platform and user shell channels, bound as one feed: packaged-app deployment and readiness, the shell and modern app launch surface, application compatibility, Windows Error Reporting health, and Office alert dialogs. Light curation: severity capped at Warning, nothing dropped, no reasons yet.

Feed id: win.eventlog.apps.

Channels

This feed binds 25 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by.

ChannelTicket class
Microsoft-Windows-AppID/Operationalsecurity_audit
Microsoft-Windows-Application Server-Applications/Operationalapp_stability
Microsoft-Windows-Application-Experience/Program-Inventoryinventory
Microsoft-Windows-ApplicationResourceManagementSystem/Operationalapp_stability
Microsoft-Windows-AppModel-Runtime/Adminapp_stability
Microsoft-Windows-AppReadiness/Adminapp_stability
Microsoft-Windows-AppReadiness/Operationalapp_stability
Microsoft-Windows-AppXDeployment-Server/Operationalpatching
Microsoft-Windows-AppXDeployment/Operationalpatching
Microsoft-Windows-AppXDeploymentServer/Operationalpatching
Microsoft-Windows-AppXDeploymentServer/Restrictedpatching
Microsoft-Windows-AppxPackaging/Operationalpatching
Microsoft-Windows-Containers-BindFlt/Operationalapp_stability
Microsoft-Windows-Containers-Wcifs/Operationalapp_stability
Microsoft-Windows-CoreApplication/Operationalapp_stability
Microsoft-Windows-Diagnosis-PCW/Operationalapp_stability
Microsoft-Windows-Fault-Tolerant-Heap/Operationalapp_stability
Microsoft-Windows-Kernel-ShimEngine/Operationalapp_stability
Microsoft-Windows-Shell-Core/Operationalapp_stability
Microsoft-Windows-TWinUI/Operationalapp_stability
Microsoft-Windows-UAC-FileVirtualization/Operationalapp_stability
Microsoft-Windows-WER-Diag/Operationalapp_stability
Microsoft-Windows-WER-PayloadHealth/Operationalapp_stability
OAlertsapp_stability
OSessionapp_stability

Severity

This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.

Ask this feed a question

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.