Windows Setup event log
Classic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing). Covers servicing failures (event 3, with the HRESULT surfaced) and component-store corruption scan results (1014/1015); the begin, success and reboot events are kept as context. Nothing is deleted.
Feed id: win.eventlog.setup.
Channels
This feed reads one Windows Event Log channel, Setup.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
win_component_store_scan_found_corruption | patching | Warning or Notice |
win_servicing_package_state_change_failed | patching | Error |
win_component_store_scan_found_corruption
Windows servicing reported unrepaired component-store corruption.
Severity: Warning or Notice
Impact: Future Windows servicing operations may fail until the component store is repaired.
Channel: Setup
Provider: Microsoft-Windows-Servicing
Event ids: 1014, 1015
| Case | Severity | Ticket class |
|---|---|---|
unrepaired | Warning | patching |
detection_only | Notice | patching |
Where to look next:
- Compare TotalCorruption and Repaired.
- Check whether the scan was detection-only before treating zero repaired as a failed repair.
Related reasons:
win_servicing_package_state_change_failed: realized package transition failure that corruption may explain
Fields it can set: win.eventlog.setup.corruption_repaired, win.eventlog.setup.corruption_total, win.eventlog.setup.detection_only, win.eventlog.setup.error_code
win_servicing_package_state_change_failed
Windows servicing failed to change a package to the requested state.
Severity: Error
Impact: The install, uninstall, or update transaction did not complete for that package.
Channel: Setup
Provider: Microsoft-Windows-Servicing
Event ids: 3
Where to look next:
- Pivot on PackageIdentifier and ErrorCode.
- Check nearby Setup and CBS records for the start event and component-store scan results.
Related reasons:
win_component_store_scan_found_corruption: component-store corruption can cause later servicing failures
Fields it can set: win.eventlog.setup.client, win.eventlog.setup.error_code, win.eventlog.setup.package, win.eventlog.setup.target_state
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.