Skip to main content

Windows network event channels

43channels
0curated reasons
0themes fed
Plannedstatus

Connectivity, name resolution, file sharing and remote access channels, bound as one feed: DHCP, DNS client, WLAN, connectivity probes, the firewall and filtering platform, SMB client and server, RDP and SSH. Light curation: severity capped at Warning, nothing dropped, no reasons yet.

Feed id: win.eventlog.network.

Channels

This feed binds 43 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

The ticket class is the subject area an event on the channel is evidence for, and it is what fleet-wide questions group by.

ChannelTicket class
Microsoft-Windows-AllJoyn/Operationalnetworking
Microsoft-Windows-BranchCacheSMB/Operationalfile_sharing
Microsoft-Windows-CloudFiles-Filter/Operationalfile_sync
Microsoft-Windows-CoreSystem-SmsRouter-Events/Operationalnetworking
Microsoft-Windows-Dhcp-Client/Adminnetworking
Microsoft-Windows-Dhcp-Client/Operationalnetworking
Microsoft-Windows-Dhcpv6-Client/Adminnetworking
Microsoft-Windows-DNS-Client/Operationalnetworking
Microsoft-Windows-EapHost/Operationalauth
Microsoft-Windows-Host-Network-Service-Adminnetworking
Microsoft-Windows-Host-Network-Service-Operationalnetworking
Microsoft-Windows-NcdAutoSetup/Operationalnetworking
Microsoft-Windows-NCSI/Operationalnetworking
Microsoft-Windows-NetworkLocationWizard/Operationalnetworking
Microsoft-Windows-NetworkProfile/Operationalnetworking
Microsoft-Windows-NlaSvc/Operationalnetworking
Microsoft-Windows-OfflineFiles/Operationalfile_sharing
Microsoft-Windows-RemoteAssistance/Operationalremote_access
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Adminremote_access
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operationalremote_access
Microsoft-Windows-RemoteDesktopServices-SessionServices/Operationalremote_access
Microsoft-Windows-SmbClient/Connectivityfile_sharing
Microsoft-Windows-SMBClient/Operationalfile_sharing
Microsoft-Windows-SmbClient/Securityfile_sharing
Microsoft-Windows-SMBServer/Connectivityfile_sharing
Microsoft-Windows-SMBServer/Operationalfile_sharing
Microsoft-Windows-SMBServer/Securityfile_sharing
Microsoft-Windows-TerminalServices-LocalSessionManager/Adminremote_access
Microsoft-Windows-TerminalServices-LocalSessionManager/Operationalremote_access
Microsoft-Windows-TerminalServices-PnPDevices/Adminremote_access
Microsoft-Windows-TerminalServices-Printers/Adminprinting
Microsoft-Windows-TerminalServices-RDPClient/Operationalremote_access
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Adminremote_access
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalremote_access
Microsoft-Windows-TerminalServices-ServerUSBDevices/Adminremote_access
Microsoft-Windows-Wcmsvc/Operationalnetworking
Microsoft-Windows-WFP/Operationalnetworking
Microsoft-Windows-Windows Firewall With Advanced Security/Firewallnetworking
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallDiagnosticsnetworking
Microsoft-Windows-WinINet-Config/ProxyConfigChangednetworking
Microsoft-Windows-WLAN-AutoConfig/Operationalnetworking
OpenSSH/Adminremote_access
OpenSSH/Operationalremote_access

Severity

This feed is bound for collection but is not yet curated per event. Every event keeps the severity its own provider stated, capped at Warning.

Ask this feed a question

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.