Reason Codes
A reason code is the name SparkLogs gives one fault or one host state it recognizes. The same code reaches you from every endpoint that hits it, whatever channel or log file it arrived on, so one query answers for the fleet.
Codes are alphabetical, with the one-line meaning beside each. Follow a code to the source that reports it for the events behind it, its severity and what to do when it lands. Two sources report some of the same facts, and those codes name both.
| Reason code | What it means | Reported by |
|---|---|---|
account_changed | An attribute on an existing user or computer account was modified. | Windows Security event log |
account_created | A user or computer account was created in the directory or local SAM. | Windows Security event log |
account_deleted | A user or computer account was deleted from the directory or local SAM. | Windows Security event log |
account_disabled | A user or computer account was disabled and can no longer authenticate. | Windows Security event log |
account_enabled | A user or computer account that was disabled has been enabled and can authenticate again. | Windows Security event log |
account_locked_out | An account was locked out after failed sign-ins. CallerComputerName names the machine that caused the lockout (often a stale cached credential). | Windows Security event log |
account_password_change_failed | A principal tried to change its own password and the change was rejected. | Windows Security event log |
account_password_reset | One principal reset the password of another principal, and the reset completed. | Windows Security event log |
account_password_reset_failed | One principal attempted to reset the password of another principal and the reset did not complete. | Windows Security event log |
adcs_audit_evidence_tampered | The Certification Authority audit filter was changed, or rows were deleted from the CA database. | Windows Security event log |
adcs_ca_chain_failed | Active Directory Certificate Services reported a CA chain or publication failure family event. | Windows Application event log |
adcs_config_changed | Certification Authority control settings changed: the security permissions on Certificate Services, or who may act as a certificate manager. | Windows Security event log |
adcs_crl_publish_failed | Active Directory Certificate Services reported a CRL publication failure. | Windows Application event log |
adcs_request_failed | A certification authority denied or failed a certificate request. | Windows Security event log |
agent_cpu_over_budget | The agent stack is over CPU budget. | Agent overhead |
agent_handle_over_budget | The agent stack is over its handle budget. | Agent overhead |
agent_ram_over_budget | The agent stack is over memory budget. | Agent overhead |
anonymous_remote_logon | A sign-in succeeded with no identity, from a machine other than this one. Windows uses anonymous logons routinely for its own local plumbing, but those name no source machine; this one did. | Windows Security event log |
app_crash | A Windows application process crashed. | Windows Application event log |
app_crash_report | Windows Error Reporting recorded a crash or hang report. | Windows Application event log |
app_hang | A Windows application stopped responding and was closed. | Windows Application event log |
appid_certificate_store_verification_failed | The AppID service reported a certificate-store verification result. | Windows application platform event channels |
applocker_audit_would_block | An application-control policy running in audit mode would have blocked this file under enforcement. | Windows identity and security event channels |
applocker_component_unavailable | An application-control policy reached a device whose Windows edition cannot enforce it. | Windows identity and security event channels |
appx_app_activation_failed | A packaged application did not start. | Windows Application event log, Windows application platform event channels |
appx_cleanup_residue | During package cleanup, Windows could not remove every file or registry entry. | Windows application platform event channels |
appx_deployment_failed | A packaged-app operation failed for a user on this device. | Windows application platform event channels |
appx_deployment_requeued | The deployment service put a packaged-app attempt back on its queue, and the requeue reason says why. | Windows application platform event channels |
appx_package_runtime_corrupt | A package runtime record is corrupted. | Windows application platform event channels |
appx_provisioning_failed | App Readiness reported a failed packaged-app operation. | Windows application platform event channels |
appx_service_start_failed | The packaged-app deployment client could not start or reach a service. | Windows application platform event channels |
aspnet_compilation_failed | A web application on this host could not be compiled and is not serving requests. | Windows Application event log |
aspnet_unhandled_exception | A web application on this host raised an unhandled exception while serving a request. | Windows Application event log |
audit_events_dropped | The Windows event log transport discarded audit records before they reached the log. The number discarded rides the event. | Windows Security event log |
audit_log_cleared | The Security audit log was cleared. When a non-system account cleared it, treat as critical; system-account clears stay high but admit automated log management. | Windows Security event log |
audit_log_full | The Security log is full. This usually means retention is set to do-not-overwrite and new audit events may be lost. | Windows Security event log |
audit_pipeline_error | The Windows logging service failed to process an incoming audit event. Some security events may not have been recorded. | Windows Security event log |
audit_policy_changed | Local audit policy changed (system, object security descriptor, or per-user). These events are dependable even when other audit subcategories are off. | Windows Security event log |
av_config_changed | Microsoft Defender recorded a configuration change to a protection-sensitive setting. | Microsoft Defender Antivirus event log |
av_definition_update_failed | Microsoft Defender failed to update or reverted security intelligence. | Microsoft Defender Antivirus event log |
av_engine_failed | Microsoft Defender reported a protection feature or engine failure. | Microsoft Defender Antivirus event log |
av_protection_disabled | Microsoft Defender protection was disabled, or later re-enabled for the same protection family. | Microsoft Defender Antivirus event log |
av_scan_failed | A Microsoft Defender scan failed before completing. | Microsoft Defender Antivirus event log |
av_suspicious_behavior_detected | Microsoft Defender behavior monitoring detected suspicious behavior. | Microsoft Defender Antivirus event log |
av_tamper_blocked | Microsoft Defender tamper protection blocked a settings change. | Microsoft Defender Antivirus event log |
av_threat_detected | Microsoft Defender detected malware or potentially unwanted software. | Microsoft Defender Antivirus event log |
av_threat_not_remediated | Microsoft Defender recorded a detection outcome where the item was allowed instead of remediated. | Microsoft Defender Antivirus event log |
av_threat_remediated | Microsoft Defender took a remediation action for a detected threat. | Microsoft Defender Antivirus event log |
av_threat_remediation_failed | Microsoft Defender tried to remediate a detected threat and failed. | Microsoft Defender Antivirus event log |
av_unsigned_code_blocked | A security agent blocked a process whose image contained unsigned or corrupted code from performing a privileged operation. | Windows System event log |
bitlocker_policy_noncompliant | A device does not match the BitLocker encryption policy set for it: a drive is unencrypted, or encrypted with a method or scope the policy does not allow. | Windows management event channels |
bitlocker_recovery_key_backup_failed | BitLocker reported that a recovery-key backup or retrieval operation failed for a volume. | Windows identity and security event channels |
bitlocker_secure_boot_unavailable | BitLocker reported that Secure Boot integrity data could not be used for a volume. | Windows identity and security event channels |
bits_transfer_failed | A Background Intelligent Transfer Service job reported an error on one transfer attempt. | Windows management event channels |
boot_integrity_measurement_failed | Windows reported a boot-measurement library failure or a TPM initialization failure during boot. | Windows platform event channels |
bugcheck | Windows rebooted from a bugcheck. | Windows System event log |
cert_enroll_failed | A Windows certificate enrollment failed or did not complete. Enrollment against a Microsoft attestation-identity endpoint that no longer serves requests is labeled separately as expected noise. | Windows Application event log |
cert_expired | A certificate in the machine or the user store has expired. | Windows identity and security event channels |
cert_expiring | A certificate held by this machine is about to expire or has already expired, and has not been replaced. | Windows Application event log, Windows identity and security event channels |
cluster_csv_unavailable | A Cluster Shared Volume became unavailable or paused. | Windows System event log |
cluster_node_removed | A failover cluster node was removed from active membership. | Windows System event log |
cluster_quorum_loss | The failover cluster lost quorum or its quorum resource. | Windows System event log |
cluster_resource_failed | A failover cluster resource failed. | Windows System event log |
cluster_resource_hang | A clustered resource became unresponsive and was terminated. | Windows System event log |
cluster_rhs_crash | The cluster Resource Hosting Subsystem crashed. | Windows System event log |
cluster_service_down | The cluster service stopped or was forced down. | Windows System event log |
code_integrity_catalog_load_failed | Windows could not read a signature catalog, so the files that catalog vouches for have no signature until it is replaced. | Windows identity and security event channels |
code_integrity_driver_revoked | A driver on this device is on the platform vendor's revoked-driver list, and the kernel refused to load it. | Windows identity and security event channels |
code_integrity_image_hash_missing | Windows found no signature on a file it was asked to load, so it could not verify the file's integrity. | Windows identity and security event channels |
code_integrity_load_blocked_signing_level | An application-control policy or a code-signing requirement on this device blocked a file from loading. | Windows identity and security event channels |
code_integrity_policy_block | A configured Code Integrity policy refused a file, or recorded that enforcement would have refused it. | Windows identity and security event channels |
cpu_busy | CPU is busy. | Host performance |
cpu_interrupt_storm | CPU time is dominated by interrupt and DPC handling. | Host performance |
cpu_kernel_dominated | Busy CPU time is mostly kernel time rather than application work. | Host performance |
cpu_throttled_under_load | The CPU is running below its rated frequency while under load. | Host performance |
crypto_key_operation_failed | A key operation failed against one of the Windows key-storage providers. | Windows identity and security event channels |
crypto_selftest_failed | A FIPS cryptographic self-test failed. The platform could not verify its crypto primitives. | Windows Security event log |
dcom_activation_timeout | DCOM activation timed out. | Windows System event log |
dcom_register_timeout | A DCOM server did not register in time. | Windows System event log |
dcom_start_error | DCOM failed while starting an application or service. | Windows System event log |
defender_asr_block | Microsoft Defender Attack Surface Reduction blocked an operation. | Microsoft Defender Antivirus event log |
defender_network_protection_block | Microsoft Defender Network Protection blocked a connection. | Microsoft Defender Antivirus event log |
defender_sensor_connection_failed | The endpoint detection sensor cannot reach its cloud service, or cannot get a token to talk to it. | Windows identity and security event channels |
device_encryption_enable_failed | The device qualifies for automatic device encryption, tried to turn it on and failed. | Windows identity and security event channels |
device_install_reboot_pending | Windows installed a driver and cannot finish until the host restarts. | Windows platform event channels |
device_registration_failed | The device tried to register itself with the directory and failed. | Windows identity and security event channels |
device_removal_vetoed | Something on the device still holds the hardware open, so Windows refused the removal request. | Windows platform event channels |
device_removed_after_failure | A device dropped off its bus while the driver was still reporting it as failing. | Windows platform event channels |
device_security_assessment_reported | A Dell security assessment scored this machine's platform posture. | Windows platform event channels |
device_software_install_failed | Windows failed to install companion software or a driver for a device. | Windows platform event channels |
device_start_failed | Windows enumerated a device and its driver refused to start it. | Windows platform event channels |
dfsr_partner_communication_failed | DFS Replication could not reach a replication partner for a replication group. | Windows management event channels |
dfsr_replication_stopped | DFS Replication stopped replicating a folder or a volume, or stopped because it could not read its own configuration. | Windows management event channels |
dfsr_sysvol_initial_sync_pending | A server holds a SYSVOL copy that has never completed its first synchronisation with a partner. | Windows management event channels |
dhcp_address_conflict_detected | The DHCP client detected an address conflict. | Windows network event channels |
dhcp_lease_denied | The DHCP server denied a lease request. | Windows network event channels |
dhcp_lease_failed | The DHCP client could not obtain a lease. | Windows network event channels |
directory_object_access_denied | Something asked for access to a directory service object and was refused. Windows records this only for objects an administrator chose to audit, so the object itself was considered worth watching. | Windows Security event log |
directory_object_changed | A directory service object was created, modified, moved, or deleted. Typical on domain controllers when Directory Service Changes auditing is enabled for the object. | Windows Security event log |
directory_replication_access_requested | An account asked a domain controller for directory replication rights, the access that lets a caller read directory content in bulk. Domain controllers do this with each other constantly; almost nothing else has a reason to. | Windows Security event log |
disk_bad_block | A storage device returned a fault instead of the data. | Windows storage event channels, Windows System event log |
disk_controller_error | A disk controller error was reported for a storage device. | Windows System event log |
disk_corruption | The disk provider reported file-system corruption. | Windows System event log |
disk_failure_predicted | A storage device reported that its own reliability is degraded or that it has passed its rated write endurance. | Windows storage event channels |
disk_io_retried | A disk IO operation had to be retried. | Windows System event log |
disk_latency_degraded | Storage latency is severe while the disk is busy. | Storage IO |
disk_paging_error | A paging read or write to a storage device failed. | Windows storage event channels, Windows System event log |
disk_saturated | The disk is busy, queueing and slow to respond. | Storage IO |
disk_surprise_removal | A device disappeared without an orderly removal. | Windows storage event channels, Windows System event log |
disk_unresponsive | A storage device is busy but moving almost no data. | Storage device IO |
dns_client_resolution_timed_out | A DNS client query timed out. | Windows network event channels |
domain_policy_changed | Password or lockout policy for a domain was changed. | Windows Security event log |
dotnet_unhandled_exception | A .NET application terminated because of an unhandled managed exception. | Windows Application event log |
dpapi_unprotect_failed | Windows could not decrypt a protected blob, such as a saved credential or a certificate private key. | Windows identity and security event channels |
driver_load_failed | A device driver failed to load. | Windows System event log |
dsrm_password_change_failed | An attempt to set the Directory Services Restore Mode (DSRM) password on a domain controller did not succeed. That password unlocks offline DC recovery. | Windows Security event log |
dsrm_password_changed | The Directory Services Restore Mode (DSRM) password was set on a domain controller. That password unlocks offline DC recovery. | Windows Security event log |
entra_device_certificate_update_failed | The device failed to refresh the certificate that proves its identity to the directory. | Windows identity and security event channels |
entra_logon_failed | The cloud authentication plugin refused a sign-in on this device. | Windows identity and security event channels |
entra_password_hash_sync_failed | Password hash synchronization failed for an on-premises domain. | Windows Application event log |
entra_sync_run_failed | A directory synchronization run profile failed to complete. | Windows Application event log |
entra_sync_scheduler_aborted | The directory synchronization scheduler stopped, so no further synchronization cycles run on this server. | Windows Application event log |
entra_token_acquisition_failed | The device failed to get a token for a cloud resource. | Windows identity and security event channels |
ephemeral_port_alloc_failed | A local port could not be allocated from the ephemeral port range. | Windows System event log |
esent_db_corruption | ESENT reported embedded database corruption or a corruption-adjacent failure. | Windows Application event log |
event_logging_stopped | The Windows event logging service stopped, which is what a clean shutdown or restart of the host looks like in this channel. | Windows Security event log |
explicit_credential_use | A process used another account's credentials to sign on (explicit credential use), and the caller was not a routine OS component. Often runas, remote tools, or lateral movement. | Windows Security event log |
exploit_mitigation_block | Exploit protection stopped a process from an action its policy forbids, or recorded that enforcement would have stopped it. | Windows identity and security event channels |
exploit_mitigation_shadow_stack_mismatch | A process returned to a different address from the one the hardware shadow stack recorded, and the platform either allowed it to continue or refused the operation. | Windows identity and security event channels |
firewall_rule_changed | The Windows Firewall service reported that a rule was added, modified, or deleted. The payload identifies the rule and selected properties. | Windows network event channels, Windows Security event log |
firewall_service_stopped | The Windows Firewall service or driver stopped. Host network filtering may be down until it recovers. | Windows Security event log |
firmware_event_store_unavailable | A Dell secure firmware-event store cannot be verified. | Windows platform event channels |
firmware_verification_scan_failed | A vendor firmware verification scan did not finish. | Windows platform event channels |
font_load_blocked | A process tried to load a font while a font-loading restriction was in force. | Windows platform event channels |
gpu_driver_error | The NVIDIA display stack reported a warning-or-worse driver error. | Windows Application event log |
gpu_driver_reset | The NVIDIA display driver reset. | Windows System event log |
gpu_resource_contention | The desktop compositor ran short of graphics memory or bandwidth. | Windows platform event channels |
group_member_added | A member was added to a security-enabled group. Adds to privileged groups (Administrators, Domain Admins, and similar) carry the highest band, because they grant rights nothing takes back on its own. | Windows Security event log |
group_member_removed | A member was removed from a security-enabled group. Removals from privileged groups carry a higher band than ordinary group churn, because losing the last administrator or leaving Protected Users weakens the host in ways nothing else reports. | Windows Security event log |
group_policy_cse_apply_failed | A Group Policy preference extension could not apply the settings from a policy object. | Windows Application event log, Windows identity and security event channels |
group_policy_domain_controller_unresolved | The machine could not find or could not reach a domain controller. | Windows identity and security event channels |
group_policy_drive_map_failed | A Group Policy drive mapping did not complete on this host. | Windows Application event log |
group_policy_file_share_unhardened | The machine reads Group Policy files from a file share without mutual authentication or integrity protection. | Windows identity and security event channels |
group_policy_pref_item_failed | A Group Policy preference item did not apply on this host. A refused stored credential is held one rung higher, because no later refresh can improve on it. | Windows Application event log |
group_policy_processing_failed | Group Policy failed to apply for that boot or that logon. | Windows identity and security event channels |
guest_account_sign_in | The built-in guest account signed in successfully. Windows disables that account by default, so a sign-in on it means somebody enabled it. | Windows Security event log |
hardware_error_corrected | Windows Hardware Error Architecture reported a CORRECTED hardware error. | Windows System event log |
hardware_error_uncorrected | Windows Hardware Error Architecture reported an UNCORRECTED hardware error. | Windows System event log |
http_ssl_binding_created | An HTTPS certificate binding was created for a listener endpoint on this host. | Windows System event log |
http_ssl_binding_deleted | The HTTPS certificate binding for a listener endpoint was removed on this host. | Windows System event log |
http_ssl_config_failed | An HTTPS listener endpoint on this host could not use its SSL configuration. | Windows System event log |
hyperv_replication_failed | Hyper-V could not replicate a virtual machine to its replica server. | Windows management event channels |
iis_apppool_disabled | An IIS application pool was disabled by rapid-fail protection. | Windows System event log |
iis_apppool_failed | IIS reported an application pool worker, configuration, or mapping failure. | Windows System event log |
iis_worker_crash | An IIS worker process terminated unexpectedly. | Windows System event log |
insecure_boot_config | The host booted with insecure Boot Configuration Data flags (test signing, kernel debug, or integrity checks disabled). The boot chain may accept unsigned or debugger-attached code. | Windows Security event log |
kerberos_cert_domain_unresolved | Kerberos could not resolve the domain named in a certificate offered for sign-in. | Windows System event log |
kerberos_etype_unsupported | A Kerberos exchange failed because the encryption types the client, the service account and the domain controller support do not overlap. | Windows System event log |
kerberos_pac_verify_failed | A domain controller could not verify the signature on the privilege data inside a Kerberos ticket. | Windows System event log |
kerberos_preauth_failed | Kerberos pre-authentication failed at the domain controller. The decoded reason is on the line, so a wrong password reads differently from a disabled account or a clock that has drifted. | Windows Security event log |
kerberos_rc4_ticket | A Kerberos service ticket used weak RC4 encryption for a user-backed service principal. Often a credential-theft / downgrade signal when unexpected. | Windows Security event log |
kerberos_smartcard_cert_missing | A domain controller has no usable certificate for smart card logon. | Windows System event log |
kerberos_ticket_failed | A Kerberos ticket request, service-ticket request or renewal was denied. The reason the domain gave is on the line, and the variant says which of the three operations failed. | Windows Security event log |
kerberos_weak_krbtgt_key | The domain ticket-granting account has no strong encryption key, so Kerberos tickets are issued using legacy cryptography. | Windows System event log |
laps_password_backup_failed | The device manages its local administrator password and the backup of that password is failing. | Windows identity and security event channels |
live_kernel_dump_requested | A kernel component requested a live kernel dump and Windows completed the request. | Windows platform event channels |
logon_failed | A sign-in attempt failed. Account-state failures (disabled, locked, expired, denied by policy) are more actionable than a single bad password. | Windows Security event log |
logon_right_granted | A system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was granted to a principal in local security policy. | Windows Security event log |
logon_right_removed | A system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was removed from a principal in local security policy. | Windows Security event log |
mdm_policy_apply_failed | A device management command did not take effect on the device. | Windows management event channels |
mfa_login_succeeded | A sign-in completed with its second factor verified. | Windows Application event log |
mfa_not_configured | A multi-factor logon agent is installed on this host but holds no configuration, so it enforces no second factor. | Windows Application event log |
mfa_unavailable_access_granted | A sign-in was allowed without its second factor because the multi-factor service could not be reached. | Windows Application event log |
mfa_user_not_enrolled | A sign-in was refused because the account is not enrolled with the multi-factor service. | Windows Application event log |
mssql_db_corruption | SQL Server reported database I/O failure, logical page corruption, or a read retry warning. | Windows Application event log |
network_share_added | A new network share was created on the host. | Windows Security event log |
nic_driver_fault_reported | A loaded wireless network adapter driver reported a fault in the adapter or in itself. | Windows System event log |
nic_driver_load_failed | A wireless network adapter driver could not load, normally because of a resource conflict. | Windows System event log |
nic_link_down | A network adapter reported that its link went down. | Windows System event log |
nic_link_up | A network adapter reported that its link came up. | Windows System event log |
nps_access_denied | Network Policy Server denied a connection request. The decoded decision is on the line, so a wrong password reads differently from a request that matched no policy at all. | Windows Security event log |
nps_lockout | Network Policy Server locked an account after repeated failed authentication attempts, so the account cannot authenticate through RADIUS until the lockout clears. | Windows Security event log |
nps_request_discarded | Network Policy Server discarded a connection request without processing it, which is different from denying one: the request never reached a policy decision. | Windows Security event log |
ntfs_corruption | NTFS moved this machine's global corruption-handling state off nominal. | Windows storage event channels, Windows System event log |
ntfs_delayed_write_lost | Windows could not save cached file data to the volume and the data was lost. | Windows System event log |
ntfs_transaction_log_error | The NTFS transaction log on a volume could not be written, replayed, or brought up. | Windows System event log |
ntlm_authentication_used | This machine used the legacy NTLM authentication protocol, as a client or as a server. | Windows identity and security event channels |
ntlm_validation_failed | NTLM credential validation failed for an account. Can appear on workstations (local accounts) as well as domain controllers, and the decoded reason is on the line. | Windows Security event log |
office_alert | Office displayed a dialog to a user. | Windows application platform event channels |
office_subscription_licensing_failed | The subscription licensing check for the installed office suite failed. | Windows Application event log |
offline_files_slow_link_transition_blocked | Offline Files could not change sync mode for a slow link. | Windows network event channels |
offline_files_sync_failed | Offline Files background synchronization failed. | Windows network event channels |
os_boot_duration_high | Windows logged a slow boot or a slow startup component. | Windows platform event channels |
os_bsod_recurring | The host is bugchecking repeatedly. | Crash dump configuration |
os_clock_drift | This host's clock hardware runs at the wrong rate. | Windows platform event channels |
os_crash_dump_new | A new crash dump appeared. | Crash dump configuration |
os_crash_dump_unavailable | Windows could not set up the path it writes a crash dump through. | Windows platform event channels |
os_dump_pagefile_too_small | The page file is too small for the configured crash dump. | Crash dump configuration |
os_shutdown_duration_high | Windows logged a slow shutdown or a service that delayed shutdown. | Windows platform event channels |
patch_download_failed | Windows Update could not download an update the device needed. | Windows management event channels |
patch_install_failed | Windows Update reports the outcome of an update install attempt on this device. | Windows System event log |
patch_scan_failed | A Windows Update scan did not complete, so the device was offered no updates on that cycle. | Windows management event channels |
patch_scan_stale | Windows Update scan data is stale. | Windows Update agent state |
patch_updates_paused | Windows Updates are paused for too long. | Windows Update agent state |
perf_counter_provider_failed | A performance-counter provider could not register or create a counter object. | Windows application platform event channels |
platform_tamper_indicator_reported | A platform-security agent reported a tamper indicator against this machine. | Windows platform event channels, Windows System event log |
portable_device_unresponsive | A phone, camera, or media player on USB stopped answering. | Windows platform event channels |
principal_renamed | A security principal was renamed. The identifier is unchanged, so events before and after this row describe the same principal under two different names. | Windows Security event log |
print_connection_reopen_failed | The print spooler could not read one profile's saved printer connections when it restarted. | Windows management event channels |
printer_driver_install_failed | A printer driver did not install, and the stage and code say which part of the install failed. | Windows management event channels |
proc_handle_count_high | A process has a very high handle count. | Processes |
process_exited_abnormally | A process was stopped by Windows part way through something it could not execute, such as a bad memory access or a corrupted heap. The program did not exit on its own terms. | Windows Security event log |
psdirect_handshake_probe | Hyper-V opened a PowerShell Direct channel to a guest virtual machine. The legacy handshake negotiates through the sign-in path, so Windows records it as a failed sign-in, but no account was involved and no action is needed. | Windows Security event log |
ram_commit_high | Committed memory on this host reached its limit. | Windows platform event channels, Host performance |
ram_growth_sustained | A process may be leaking memory: its working set grew at every sample of a consecutive run and is now large in absolute bytes or as a share of host RAM. | Processes |
ram_hard_fault_storm | The host is thrashing memory. | Host performance |
rds_license_server_unactivated | A Remote Desktop license server is not activated and is issuing only temporary licences. | Windows System event log |
rds_license_tracking_failed | A Remote Desktop license server could not record a per-user licence in the directory. | Windows System event log |
rds_licensing_service_failed | A Remote Desktop license server could not run, or hit an error in its licensing database. | Windows System event log |
rds_redirected_printer_setup_failed | RDS redirected printer setup failed. | Windows network event channels |
registry_value_changed | An audited registry value was created, modified, or deleted. These events appear only where a SACL and the registry audit subcategory are aimed at that object. | Windows Security event log |
remote_assist_session_started | A remote assistance session started on this host and a remote party could see the desktop. | Windows Application event log |
replay_attack_detected | Windows reported a Kerberos authentication replay. Rare; treat as high-signal even as a single event. | Windows Security event log |
restart_manager_app_pending | Restart Manager could not shut down or restart an app during an update session. | Windows Application event log |
scheduled_task_created | A scheduled task was created. | Windows Security event log |
scheduled_task_deleted | A scheduled task was deleted. | Windows Security event log |
scheduled_task_disabled | A scheduled task was disabled. The task still exists and no longer runs. | Windows Security event log |
scheduled_task_engine_failed | Task Scheduler could not start the host process a scheduled task runs inside. | Windows management event channels |
scheduled_task_load_failed | A scheduled task definition could not be read at service start, so the task is not in the schedule at all. | Windows management event channels |
scheduled_task_logon_failed | Task Scheduler could not log on as the account a scheduled task stores, so the task did not run. | Windows management event channels |
scheduled_task_start_failed | A scheduled task did not run, and the result code says whether the program was missing, the identity was refused, or the action itself failed. | Windows management event channels |
scheduled_task_updated | An existing scheduled task's definition was updated. | Windows Security event log |
secure_boot_cert_update_pending | A Secure Boot certificate update has not been applied on this device. | Windows System event log |
secure_boot_revocation_update_failed | Windows tried to write its boot revocation level into firmware and the firmware refused. | Windows platform event channels |
security_agent_config_fetch_failed | A security agent could not retrieve its configuration because its credentials were refused. | Windows Application event log |
security_agent_host_isolated | An endpoint detection agent isolated this host from the network, or later released it. | Windows Application event log |
security_agent_service_start_failed | A sub-service of an endpoint protection agent failed to start. | Windows System event log |
security_agent_service_terminated | A sub-service of an endpoint protection agent terminated unexpectedly. | Windows System event log |
security_group_changed | A security group's scope, type, or attributes changed. Changes to privileged groups (Administrators, Domain Admins, and similar) carry a higher band. | Windows Security event log |
security_group_created | A security group was created. Creation of a privileged group (Administrators, Domain Admins, and similar) carries a higher band. | Windows Security event log |
security_group_deleted | A security group was deleted. Deletion of a privileged group (Administrators, Domain Admins, and similar) carries a higher band. | Windows Security event log |
service_crashed | A Windows service crashed or terminated unexpectedly. | Windows System event log |
service_exited_error | A Windows service exited with an error. | Windows System event log |
service_hang | A Windows service stopped responding to a control transaction. | Windows System event log |
service_installed | A Windows service was installed. This Security-channel event appears when service-install auditing is enabled; the System channel often carries the same fact by default. | Windows Security event log, Windows System event log |
service_start_failed | A Windows service failed to start. | Windows System event log |
service_start_timeout | A Windows service did not connect before the startup timeout. | Windows System event log |
sid_history_add_failed | An attempt to add SID History to an account did not succeed. Rare outside migrations. | Windows Security event log |
sid_history_added | SID History was added to an account. Rare outside migrations; often a privilege-inheritance or persistence tell. | Windows Security event log |
smb_anonymous_access_denied | This server refused anonymous access at the share or server scope. | Windows network event channels |
smb_anonymous_access_enabled | The server reported that one or more named pipes or shares are marked for anonymous access. The event does not identify the resource or prove that a remote client can reach it. | Windows network event channels |
smb_client_auth_context_failed | The SMB client could not build an authentication context for a server. | Windows network event channels |
smb_client_mutual_auth_lost | SMB mutual authentication was lost after the client re-authenticated. | Windows network event channels |
smb_client_security_call_slow | An SMB client security call exceeded its slow threshold. | Windows network event channels |
smb_connect_failed | An SMB connection attempt failed after the server name resolved. | Windows network event channels |
smb_delayed_write_lost | Windows could not save cached file data to a network share and the data was lost. | Windows System event log |
smb_insecure_guest_allowed | The SMB client allowed an insecure guest connection. | Windows network event channels |
smb_insecure_guest_rejected | The SMB client rejected an insecure guest connection. | Windows network event channels |
smb_legacy_dialect_rejected | This server rejected a legacy SMB dialect. | Windows network event channels |
smb_security_setting_nondefault | An SMB security setting on this device differs from the Windows default. The payload names the setting and configured value. | Windows network event channels |
smb_server_name_unresolved | The SMB client could not resolve a server name. | Windows network event channels |
smb_server_operation_slow | An SMB server operation exceeded its slow threshold. | Windows network event channels |
smb_server_transport_bind_failed | The Windows file-sharing service could not bind to a network transport. | Windows System event log |
smb_session_auth_failed | An SMB session authentication attempt on this server failed. | Windows network event channels |
smb_session_lost | An SMB session to a server was lost or recovered. | Windows network event channels |
smb_session_reopen_failed | The server could not reopen an SMB file after the client returned. | Windows network event channels |
smb_share_access_denied | A share on this server denied access to a client. | Windows network event channels |
smb_share_connection_lost | An SMB share tree connection was lost or recovered. | Windows network event channels |
smb_share_recreate_failed | A file share could not be recreated because the folder it points at no longer exists. | Windows System event log |
smb_signing_validation_failed | SMB signing or encryption validation failed for a session. | Windows network event channels |
special_group_logon | A logon matched an administrator-configured special-groups watchlist. These events exist only where that watchlist is enabled. | Windows Security event log |
storage_controller_reset | The storage port driver reset the path to a device. | Windows storage event channels, Windows System event log |
storage_device_command_failed | A storage device did not complete a command, and reported sense data saying why. | Windows storage event channels |
svc_auto_not_running | An automatic service is not running. | Windows services |
svc_flapping | A Windows service is flapping. | Windows services |
svc_stuck_pending | A Windows service is stuck pending. | Windows services |
system_time_changed | The system clock was changed. Routine time-service adjustments are quiet; changes from other processes are treated as integrity events. | Windows Security event log |
thermal_cooling_engaged | The platform reached a temperature trip point and engaged cooling. | Windows platform event channels |
time_sync_failed | Windows Time could not reach or resolve its time source. | Windows System event log |
tls_cert_expired | A remote server presented a certificate that has expired or is not yet valid, and the TLS connection failed. | Windows System event log |
tls_cert_name_mismatch | A TLS certificate name did not match the expected server name. | Windows System event log |
tls_cert_untrusted_ca | A remote server presented a certificate issued by an authority this host does not trust, and the TLS connection failed. | Windows System event log |
tls_cipher_mismatch | A remote client offered no cipher suite this host accepts, and the TLS handshake failed. | Windows System event log |
tls_client_credential_failed | The host could not create a TLS client credential, so a connection that needed to present a client certificate could not build one. | Windows System event log |
tls_server_credential_failed | The private key behind this host's TLS server certificate could not be accessed. | Windows System event log |
tpm_attestation_failed | TPM attestation failed for a critical component. | Windows System event log |
unexpected_shutdown | The previous shutdown was not clean: the host stopped without shutting down and came back on the next start. | Windows System event log |
usb_controller_error | The USB host controller or USB-C connector manager reported a fault. | Windows platform event channels |
vbs_key_isolation_failed | The isolated key environment that virtualization-based security provides is failing on this device. | Windows identity and security event channels |
vm_backup_checkpoint_failed | A backup of a virtual machine did not take a consistent snapshot. | Windows management event channels |
vm_start_failed | A virtual machine, or the worker process that runs one, did not start. | Windows management event channels |
vm_storage_request_slow | A storage request a virtualization host made for one of its guests took longer than expected to complete. | Windows management event channels |
vm_vhd_chain_corrupted | A differencing virtual disk and its parent disagree on the parent identity, so the disk chain cannot be merged or checkpointed. | Windows management event channels |
vol_bitlocker_dropped | BitLocker protection is off or suspended on a fixed volume. | Disk volumes |
vol_data_space_exhausting | A data volume is projected to run out of space. | Disk volumes |
vol_data_space_low | A fixed data volume is low on free space. | Disk volumes |
vol_fill_rate_high | A volume has a high fill rate that current capacity is absorbing. | Disk volumes |
vol_mount_failed | NTFS could not mount a volume. | Windows storage event channels |
vol_os_space_exhausting | The OS volume is projected to run out of space. | Disk volumes |
vol_os_space_low | The OS volume is low on free space. | Disk volumes |
vol_unreadable | A fixed volume filesystem is unavailable or unreadable. | Disk volumes |
vpn_connected | A remote-access connection was established. | Windows System event log |
vpn_dial_failed | A remote-access dial attempt failed. | Windows Application event log |
vss_data_integrity_writer_failed | A backup writer for a database, mail store, virtual machine host, or directory service reported a failure during shadow copy creation. | Windows Application event log |
vss_legacy_driver_scan | The VSS System Writer could not read a driver binary while enumerating for a snapshot. | Windows Application event log |
vss_optimization_time_budget_reached | Shadow copy optimization did not finish excluding temporary files within its time budget. | Windows Application event log |
vss_provider_class_not_registered | A component the Volume Shadow Copy Service needs is not registered, so shadow copies cannot be created on this machine. | Windows Application event log |
vss_shadow_aborted | A volume shadow-copy operation was aborted by shadow storage limits. | Windows System event log |
vss_shadow_lost | Volume shadow copies were deleted because shadow storage could not grow. | Windows System event log |
vss_shadowstorage_near_cap | Shadow storage is near capacity. | VSS shadow storage |
vss_snapshot_call_failed | A call the Volume Shadow Copy Service makes while working with shadow copies did not complete. | Windows Application event log |
vss_snapshots_failing_for_space | Shadow copy storage is full, so restore points are being deleted or no longer created. | Windows Application event log, VSS shadow storage |
vss_writer_callback_query | The Volume Shadow Copy Service could not read a writer's callback interface because of process permissions, and continued. | Windows Application event log |
vss_writer_failed | A VSS writer is failed or unstable. | VSS writers |
vswitch_config_restore_failed | Hyper-V virtual switch failed to restore port configuration. | Windows System event log |
wcf_request_failed | A hosted service on this machine could not process a request. | Windows Application event log, Windows application platform event channels |
wfp_transaction_watchdog_timeout | A Windows Filtering Platform transaction hit a watchdog timeout. | Windows network event channels |
win_app_error_dialog_shown | An application error popup was recorded. | Windows System event log |
win_component_store_assembly_missing | A component assembly is missing from the store. | Windows CBS (Component-Based Servicing) log |
win_component_store_corrupt_blocks_package | A Windows package failed to apply because the component store is corrupt. | Windows CBS (Component-Based Servicing) log |
win_component_store_corruption_recurrence | Windows reported how often component-store corruption has been detected. | Windows CBS (Component-Based Servicing) log |
win_component_store_file_repaired | Windows repaired a file from its component store or backup. | Windows CBS (Component-Based Servicing) log |
win_component_store_flag_corruption_suspected | Windows suspects component-store file-flag corruption. | Windows CBS (Component-Based Servicing) log |
win_component_store_payload_corrupt | A payload file in the component store is corrupt. | Windows CBS (Component-Based Servicing) log |
win_component_store_payload_unrepairable | Windows could not repair a damaged payload file. | Windows CBS (Component-Based Servicing) log |
win_component_store_repair_completed | Windows repaired all recorded component-store corruption. | Windows CBS (Component-Based Servicing) log |
win_component_store_repair_unavailable | Windows could not repair a damaged component. | Windows CBS (Component-Based Servicing) log |
win_component_store_reprojection_failed | Windows could not reproject a component. | Windows CBS (Component-Based Servicing) log |
win_component_store_scan_found_corruption | Windows servicing reported unrepaired component-store corruption. | Windows Setup event log, Windows CBS (Component-Based Servicing) log |
win_component_store_scan_repaired_corruption | A component-store scan repaired corruption it found. | Windows CBS (Component-Based Servicing) log |
win_component_store_source_missing | A servicing operation could not find the source files it needed. | Windows CBS (Component-Based Servicing) log |
win_component_store_sxs_corrupt | The side-by-side component store is corrupt. | Windows CBS (Component-Based Servicing) log |
win_dism_command_failed | A DISM command reported failure. | Windows DISM servicing log |
win_dism_feature_change_failed | A Windows optional feature could not be enabled or disabled. | Windows DISM servicing log |
win_dism_health_command_run | A DISM health or repair command was run on this machine. | Windows DISM servicing log |
win_dism_reboot_required | A DISM change needs a reboot to take effect. | Windows DISM servicing log |
win_dism_source_files_missing | A DISM operation could not find the source files it needed. | Windows DISM servicing log |
win_locale_registry_read_failed | A process could not open the registry key holding the machine or user locale settings, and fell back to a default. | Windows management event channels |
win_msi_install_error | Windows Installer reported an install or configuration error. If the installer status says another install is already running, the same event is treated as retry-later context. | Windows Application event log |
win_msi_operation_failed | A Windows Installer operation did not complete. If the installer status says another install is already running, the same event is treated as retry-later context, and an operation refused for want of administrator rights or blocked by an open file is recorded as blocked rather than failed. | Windows Application event log |
win_msi_product_install_succeeded | A Windows Installer product install completed successfully. | Windows Application event log |
win_msi_product_reconfigure_succeeded | A Windows Installer product configuration operation completed successfully. | Windows Application event log |
win_msi_product_removal_succeeded | A Windows Installer product removal completed successfully. | Windows Application event log |
win_powershell_script_block_framework_code | A PowerShell script block that is generated framework code, such as a proxy module built when a command set is imported, rather than a script someone wrote. | Windows PowerShell event channels |
win_powershell_script_block_repeat | A PowerShell script block ran again with the same content as one already recorded on this host, so this event is a receipt for the run rather than a second copy of the script. | Windows PowerShell event channels |
win_powershell_script_block_watchlist_hit | A PowerShell script block named a command on the watchlist of operations worth reviewing, such as deleting data, changing a protection setting, handling a credential, or sending data out. | Windows PowerShell event channels |
win_servicing_commit_skipped_reboot_required | A servicing change was deferred because a reboot is pending. | Windows CBS (Component-Based Servicing) log |
win_servicing_delta_patch_failed | A component delta patch could not be applied. | Windows CBS (Component-Based Servicing) log |
win_servicing_duplicate_update_name | Windows found a duplicate update name in a package. | Windows CBS (Component-Based Servicing) log |
win_servicing_manifest_malformed | A component manifest is malformed. | Windows CBS (Component-Based Servicing) log |
win_servicing_manifest_unparseable | Windows could not parse a package manifest. | Windows CBS (Component-Based Servicing) log |
win_servicing_package_change_reported | A Windows package was added, removed or updated. | Windows CBS (Component-Based Servicing) log |
win_servicing_package_stage_failed | A Windows package could not be staged for installation. | Windows CBS (Component-Based Servicing) log |
win_servicing_package_state_change_failed | Windows servicing failed to change a package to the requested state. | Windows Setup event log |
win_servicing_session_finalized | A Windows servicing session started and finished. | Windows CBS (Component-Based Servicing) log |
win_servicing_startup_package_failed | A Windows package failed during startup processing. | Windows CBS (Component-Based Servicing) log |
win_servicing_update_package_create_failed | Windows could not create an update package. | Windows CBS (Component-Based Servicing) log |
win_sfc_repairing_components | System File Checker started repairing components. | Windows CBS (Component-Based Servicing) log |
win_trace_session_failed | A Windows tracing session could not start, write, or continue. | Windows platform event channels |
win_user_profile_load_failed | Windows could not load a user profile, or loaded a temporary profile. | Windows Application event log |
windows_hello_key_registration_failed | A Windows Hello key or container operation failed after provisioning had already passed its prerequisites. | Windows identity and security event channels |
windows_hello_provisioning_blocked | Windows Hello for Business will not set up on this device for this user. | Windows identity and security event channels |
winre_servicing_failed | Servicing of the Windows recovery environment failed on this device. | Windows System event log |
wlan_connect_failed | WLAN AutoConfig failed to connect using a saved profile. | Windows network event channels |
wlan_limited_connectivity | Wireless networking entered limited connectivity. | Windows System event log |
wlan_security_handshake_failed | A wireless security handshake did not finish. | Windows network event channels |
wmi_provider_registered_as_localsystem | A WMI provider registered to run under the LocalSystem account. | Windows Application event log |