Skip to main content

Windows Setup event log

1channels
2curated reasons
1themes fed
Livestatus

Classic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing). Covers servicing failures (event 3, with the HRESULT surfaced) and component-store corruption scan results (1014/1015); the begin, success and reboot events are kept as context. Nothing is deleted.

Feed id: win.eventlog.setup.

Channels

This feed reads one Windows Event Log channel, Setup.

Curated reasons

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
win_component_store_scan_found_corruptionpatchingWarning or Notice
win_servicing_package_state_change_failedpatchingError

win_component_store_scan_found_corruption

Windows servicing reported unrepaired component-store corruption.

Severity: Warning or Notice

Impact: Future Windows servicing operations may fail until the component store is repaired.

Channel: Setup

Provider: Microsoft-Windows-Servicing

Event ids: 1014, 1015

CaseSeverityTicket class
unrepairedWarningpatching
detection_onlyNoticepatching

Where to look next:

  • Compare TotalCorruption and Repaired.
  • Check whether the scan was detection-only before treating zero repaired as a failed repair.

Related reasons:

Fields it can set: win.eventlog.setup.corruption_repaired, win.eventlog.setup.corruption_total, win.eventlog.setup.detection_only, win.eventlog.setup.error_code

win_servicing_package_state_change_failed

Windows servicing failed to change a package to the requested state.

Severity: Error

Impact: The install, uninstall, or update transaction did not complete for that package.

Channel: Setup

Provider: Microsoft-Windows-Servicing

Event ids: 3

Where to look next:

  • Pivot on PackageIdentifier and ErrorCode.
  • Check nearby Setup and CBS records for the start event and component-store scan results.

Related reasons:

Fields it can set: win.eventlog.setup.client, win.eventlog.setup.error_code, win.eventlog.setup.package, win.eventlog.setup.target_state

Ask this feed a question

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.