Skip to main content

Reason Codes

A reason code is the name SparkLogs gives one fault or one host state it recognizes. The same code reaches you from every endpoint that hits it, whatever channel or log file it arrived on, so one query answers for the fleet.

Codes are alphabetical, with the one-line meaning beside each. Follow a code to the source that reports it for the events behind it, its severity and what to do when it lands. Two sources report some of the same facts, and those codes name both.

Reason codeWhat it meansReported by
account_changedAn attribute on an existing user or computer account was modified.Windows Security event log
account_createdA user or computer account was created in the directory or local SAM.Windows Security event log
account_deletedA user or computer account was deleted from the directory or local SAM.Windows Security event log
account_disabledA user or computer account was disabled and can no longer authenticate.Windows Security event log
account_enabledA user or computer account that was disabled has been enabled and can authenticate again.Windows Security event log
account_locked_outAn account was locked out after failed sign-ins. CallerComputerName names the machine that caused the lockout (often a stale cached credential).Windows Security event log
account_password_change_failedA principal tried to change its own password and the change was rejected.Windows Security event log
account_password_resetOne principal reset the password of another principal, and the reset completed.Windows Security event log
account_password_reset_failedOne principal attempted to reset the password of another principal and the reset did not complete.Windows Security event log
adcs_audit_evidence_tamperedThe Certification Authority audit filter was changed, or rows were deleted from the CA database.Windows Security event log
adcs_ca_chain_failedActive Directory Certificate Services reported a CA chain or publication failure family event.Windows Application event log
adcs_config_changedCertification Authority control settings changed: the security permissions on Certificate Services, or who may act as a certificate manager.Windows Security event log
adcs_crl_publish_failedActive Directory Certificate Services reported a CRL publication failure.Windows Application event log
adcs_request_failedA certification authority denied or failed a certificate request.Windows Security event log
agent_cpu_over_budgetThe agent stack is over CPU budget.Agent overhead
agent_handle_over_budgetThe agent stack is over its handle budget.Agent overhead
agent_ram_over_budgetThe agent stack is over memory budget.Agent overhead
anonymous_remote_logonA sign-in succeeded with no identity, from a machine other than this one. Windows uses anonymous logons routinely for its own local plumbing, but those name no source machine; this one did.Windows Security event log
app_crashA Windows application process crashed.Windows Application event log
app_crash_reportWindows Error Reporting recorded a crash or hang report.Windows Application event log
app_hangA Windows application stopped responding and was closed.Windows Application event log
appid_certificate_store_verification_failedThe AppID service reported a certificate-store verification result.Windows application platform event channels
applocker_audit_would_blockAn application-control policy running in audit mode would have blocked this file under enforcement.Windows identity and security event channels
applocker_component_unavailableAn application-control policy reached a device whose Windows edition cannot enforce it.Windows identity and security event channels
appx_app_activation_failedA packaged application did not start.Windows Application event log, Windows application platform event channels
appx_cleanup_residueDuring package cleanup, Windows could not remove every file or registry entry.Windows application platform event channels
appx_deployment_failedA packaged-app operation failed for a user on this device.Windows application platform event channels
appx_deployment_requeuedThe deployment service put a packaged-app attempt back on its queue, and the requeue reason says why.Windows application platform event channels
appx_package_runtime_corruptA package runtime record is corrupted.Windows application platform event channels
appx_provisioning_failedApp Readiness reported a failed packaged-app operation.Windows application platform event channels
appx_service_start_failedThe packaged-app deployment client could not start or reach a service.Windows application platform event channels
aspnet_compilation_failedA web application on this host could not be compiled and is not serving requests.Windows Application event log
aspnet_unhandled_exceptionA web application on this host raised an unhandled exception while serving a request.Windows Application event log
audit_events_droppedThe Windows event log transport discarded audit records before they reached the log. The number discarded rides the event.Windows Security event log
audit_log_clearedThe Security audit log was cleared. When a non-system account cleared it, treat as critical; system-account clears stay high but admit automated log management.Windows Security event log
audit_log_fullThe Security log is full. This usually means retention is set to do-not-overwrite and new audit events may be lost.Windows Security event log
audit_pipeline_errorThe Windows logging service failed to process an incoming audit event. Some security events may not have been recorded.Windows Security event log
audit_policy_changedLocal audit policy changed (system, object security descriptor, or per-user). These events are dependable even when other audit subcategories are off.Windows Security event log
av_config_changedMicrosoft Defender recorded a configuration change to a protection-sensitive setting.Microsoft Defender Antivirus event log
av_definition_update_failedMicrosoft Defender failed to update or reverted security intelligence.Microsoft Defender Antivirus event log
av_engine_failedMicrosoft Defender reported a protection feature or engine failure.Microsoft Defender Antivirus event log
av_protection_disabledMicrosoft Defender protection was disabled, or later re-enabled for the same protection family.Microsoft Defender Antivirus event log
av_scan_failedA Microsoft Defender scan failed before completing.Microsoft Defender Antivirus event log
av_suspicious_behavior_detectedMicrosoft Defender behavior monitoring detected suspicious behavior.Microsoft Defender Antivirus event log
av_tamper_blockedMicrosoft Defender tamper protection blocked a settings change.Microsoft Defender Antivirus event log
av_threat_detectedMicrosoft Defender detected malware or potentially unwanted software.Microsoft Defender Antivirus event log
av_threat_not_remediatedMicrosoft Defender recorded a detection outcome where the item was allowed instead of remediated.Microsoft Defender Antivirus event log
av_threat_remediatedMicrosoft Defender took a remediation action for a detected threat.Microsoft Defender Antivirus event log
av_threat_remediation_failedMicrosoft Defender tried to remediate a detected threat and failed.Microsoft Defender Antivirus event log
av_unsigned_code_blockedA security agent blocked a process whose image contained unsigned or corrupted code from performing a privileged operation.Windows System event log
bitlocker_policy_noncompliantA device does not match the BitLocker encryption policy set for it: a drive is unencrypted, or encrypted with a method or scope the policy does not allow.Windows management event channels
bitlocker_recovery_key_backup_failedBitLocker reported that a recovery-key backup or retrieval operation failed for a volume.Windows identity and security event channels
bitlocker_secure_boot_unavailableBitLocker reported that Secure Boot integrity data could not be used for a volume.Windows identity and security event channels
bits_transfer_failedA Background Intelligent Transfer Service job reported an error on one transfer attempt.Windows management event channels
boot_integrity_measurement_failedWindows reported a boot-measurement library failure or a TPM initialization failure during boot.Windows platform event channels
bugcheckWindows rebooted from a bugcheck.Windows System event log
cert_enroll_failedA Windows certificate enrollment failed or did not complete. Enrollment against a Microsoft attestation-identity endpoint that no longer serves requests is labeled separately as expected noise.Windows Application event log
cert_expiredA certificate in the machine or the user store has expired.Windows identity and security event channels
cert_expiringA certificate held by this machine is about to expire or has already expired, and has not been replaced.Windows Application event log, Windows identity and security event channels
cluster_csv_unavailableA Cluster Shared Volume became unavailable or paused.Windows System event log
cluster_node_removedA failover cluster node was removed from active membership.Windows System event log
cluster_quorum_lossThe failover cluster lost quorum or its quorum resource.Windows System event log
cluster_resource_failedA failover cluster resource failed.Windows System event log
cluster_resource_hangA clustered resource became unresponsive and was terminated.Windows System event log
cluster_rhs_crashThe cluster Resource Hosting Subsystem crashed.Windows System event log
cluster_service_downThe cluster service stopped or was forced down.Windows System event log
code_integrity_catalog_load_failedWindows could not read a signature catalog, so the files that catalog vouches for have no signature until it is replaced.Windows identity and security event channels
code_integrity_driver_revokedA driver on this device is on the platform vendor's revoked-driver list, and the kernel refused to load it.Windows identity and security event channels
code_integrity_image_hash_missingWindows found no signature on a file it was asked to load, so it could not verify the file's integrity.Windows identity and security event channels
code_integrity_load_blocked_signing_levelAn application-control policy or a code-signing requirement on this device blocked a file from loading.Windows identity and security event channels
code_integrity_policy_blockA configured Code Integrity policy refused a file, or recorded that enforcement would have refused it.Windows identity and security event channels
cpu_busyCPU is busy.Host performance
cpu_interrupt_stormCPU time is dominated by interrupt and DPC handling.Host performance
cpu_kernel_dominatedBusy CPU time is mostly kernel time rather than application work.Host performance
cpu_throttled_under_loadThe CPU is running below its rated frequency while under load.Host performance
crypto_key_operation_failedA key operation failed against one of the Windows key-storage providers.Windows identity and security event channels
crypto_selftest_failedA FIPS cryptographic self-test failed. The platform could not verify its crypto primitives.Windows Security event log
dcom_activation_timeoutDCOM activation timed out.Windows System event log
dcom_register_timeoutA DCOM server did not register in time.Windows System event log
dcom_start_errorDCOM failed while starting an application or service.Windows System event log
defender_asr_blockMicrosoft Defender Attack Surface Reduction blocked an operation.Microsoft Defender Antivirus event log
defender_network_protection_blockMicrosoft Defender Network Protection blocked a connection.Microsoft Defender Antivirus event log
defender_sensor_connection_failedThe endpoint detection sensor cannot reach its cloud service, or cannot get a token to talk to it.Windows identity and security event channels
device_encryption_enable_failedThe device qualifies for automatic device encryption, tried to turn it on and failed.Windows identity and security event channels
device_install_reboot_pendingWindows installed a driver and cannot finish until the host restarts.Windows platform event channels
device_registration_failedThe device tried to register itself with the directory and failed.Windows identity and security event channels
device_removal_vetoedSomething on the device still holds the hardware open, so Windows refused the removal request.Windows platform event channels
device_removed_after_failureA device dropped off its bus while the driver was still reporting it as failing.Windows platform event channels
device_security_assessment_reportedA Dell security assessment scored this machine's platform posture.Windows platform event channels
device_software_install_failedWindows failed to install companion software or a driver for a device.Windows platform event channels
device_start_failedWindows enumerated a device and its driver refused to start it.Windows platform event channels
dfsr_partner_communication_failedDFS Replication could not reach a replication partner for a replication group.Windows management event channels
dfsr_replication_stoppedDFS Replication stopped replicating a folder or a volume, or stopped because it could not read its own configuration.Windows management event channels
dfsr_sysvol_initial_sync_pendingA server holds a SYSVOL copy that has never completed its first synchronisation with a partner.Windows management event channels
dhcp_address_conflict_detectedThe DHCP client detected an address conflict.Windows network event channels
dhcp_lease_deniedThe DHCP server denied a lease request.Windows network event channels
dhcp_lease_failedThe DHCP client could not obtain a lease.Windows network event channels
directory_object_access_deniedSomething asked for access to a directory service object and was refused. Windows records this only for objects an administrator chose to audit, so the object itself was considered worth watching.Windows Security event log
directory_object_changedA directory service object was created, modified, moved, or deleted. Typical on domain controllers when Directory Service Changes auditing is enabled for the object.Windows Security event log
directory_replication_access_requestedAn account asked a domain controller for directory replication rights, the access that lets a caller read directory content in bulk. Domain controllers do this with each other constantly; almost nothing else has a reason to.Windows Security event log
disk_bad_blockA storage device returned a fault instead of the data.Windows storage event channels, Windows System event log
disk_controller_errorA disk controller error was reported for a storage device.Windows System event log
disk_corruptionThe disk provider reported file-system corruption.Windows System event log
disk_failure_predictedA storage device reported that its own reliability is degraded or that it has passed its rated write endurance.Windows storage event channels
disk_io_retriedA disk IO operation had to be retried.Windows System event log
disk_latency_degradedStorage latency is severe while the disk is busy.Storage IO
disk_paging_errorA paging read or write to a storage device failed.Windows storage event channels, Windows System event log
disk_saturatedThe disk is busy, queueing and slow to respond.Storage IO
disk_surprise_removalA device disappeared without an orderly removal.Windows storage event channels, Windows System event log
disk_unresponsiveA storage device is busy but moving almost no data.Storage device IO
dns_client_resolution_timed_outA DNS client query timed out.Windows network event channels
domain_policy_changedPassword or lockout policy for a domain was changed.Windows Security event log
dotnet_unhandled_exceptionA .NET application terminated because of an unhandled managed exception.Windows Application event log
dpapi_unprotect_failedWindows could not decrypt a protected blob, such as a saved credential or a certificate private key.Windows identity and security event channels
driver_load_failedA device driver failed to load.Windows System event log
dsrm_password_change_failedAn attempt to set the Directory Services Restore Mode (DSRM) password on a domain controller did not succeed. That password unlocks offline DC recovery.Windows Security event log
dsrm_password_changedThe Directory Services Restore Mode (DSRM) password was set on a domain controller. That password unlocks offline DC recovery.Windows Security event log
entra_device_certificate_update_failedThe device failed to refresh the certificate that proves its identity to the directory.Windows identity and security event channels
entra_logon_failedThe cloud authentication plugin refused a sign-in on this device.Windows identity and security event channels
entra_password_hash_sync_failedPassword hash synchronization failed for an on-premises domain.Windows Application event log
entra_sync_run_failedA directory synchronization run profile failed to complete.Windows Application event log
entra_sync_scheduler_abortedThe directory synchronization scheduler stopped, so no further synchronization cycles run on this server.Windows Application event log
entra_token_acquisition_failedThe device failed to get a token for a cloud resource.Windows identity and security event channels
ephemeral_port_alloc_failedA local port could not be allocated from the ephemeral port range.Windows System event log
esent_db_corruptionESENT reported embedded database corruption or a corruption-adjacent failure.Windows Application event log
event_logging_stoppedThe Windows event logging service stopped, which is what a clean shutdown or restart of the host looks like in this channel.Windows Security event log
explicit_credential_useA process used another account's credentials to sign on (explicit credential use), and the caller was not a routine OS component. Often runas, remote tools, or lateral movement.Windows Security event log
exploit_mitigation_blockExploit protection stopped a process from an action its policy forbids, or recorded that enforcement would have stopped it.Windows identity and security event channels
exploit_mitigation_shadow_stack_mismatchA process returned to a different address from the one the hardware shadow stack recorded, and the platform either allowed it to continue or refused the operation.Windows identity and security event channels
firewall_rule_changedThe Windows Firewall service reported that a rule was added, modified, or deleted. The payload identifies the rule and selected properties.Windows network event channels, Windows Security event log
firewall_service_stoppedThe Windows Firewall service or driver stopped. Host network filtering may be down until it recovers.Windows Security event log
firmware_event_store_unavailableA Dell secure firmware-event store cannot be verified.Windows platform event channels
firmware_verification_scan_failedA vendor firmware verification scan did not finish.Windows platform event channels
font_load_blockedA process tried to load a font while a font-loading restriction was in force.Windows platform event channels
gpu_driver_errorThe NVIDIA display stack reported a warning-or-worse driver error.Windows Application event log
gpu_driver_resetThe NVIDIA display driver reset.Windows System event log
gpu_resource_contentionThe desktop compositor ran short of graphics memory or bandwidth.Windows platform event channels
group_member_addedA member was added to a security-enabled group. Adds to privileged groups (Administrators, Domain Admins, and similar) carry the highest band, because they grant rights nothing takes back on its own.Windows Security event log
group_member_removedA member was removed from a security-enabled group. Removals from privileged groups carry a higher band than ordinary group churn, because losing the last administrator or leaving Protected Users weakens the host in ways nothing else reports.Windows Security event log
group_policy_cse_apply_failedA Group Policy preference extension could not apply the settings from a policy object.Windows Application event log, Windows identity and security event channels
group_policy_domain_controller_unresolvedThe machine could not find or could not reach a domain controller.Windows identity and security event channels
group_policy_drive_map_failedA Group Policy drive mapping did not complete on this host.Windows Application event log
group_policy_file_share_unhardenedThe machine reads Group Policy files from a file share without mutual authentication or integrity protection.Windows identity and security event channels
group_policy_pref_item_failedA Group Policy preference item did not apply on this host. A refused stored credential is held one rung higher, because no later refresh can improve on it.Windows Application event log
group_policy_processing_failedGroup Policy failed to apply for that boot or that logon.Windows identity and security event channels
guest_account_sign_inThe built-in guest account signed in successfully. Windows disables that account by default, so a sign-in on it means somebody enabled it.Windows Security event log
hardware_error_correctedWindows Hardware Error Architecture reported a CORRECTED hardware error.Windows System event log
hardware_error_uncorrectedWindows Hardware Error Architecture reported an UNCORRECTED hardware error.Windows System event log
http_ssl_binding_createdAn HTTPS certificate binding was created for a listener endpoint on this host.Windows System event log
http_ssl_binding_deletedThe HTTPS certificate binding for a listener endpoint was removed on this host.Windows System event log
http_ssl_config_failedAn HTTPS listener endpoint on this host could not use its SSL configuration.Windows System event log
hyperv_replication_failedHyper-V could not replicate a virtual machine to its replica server.Windows management event channels
iis_apppool_disabledAn IIS application pool was disabled by rapid-fail protection.Windows System event log
iis_apppool_failedIIS reported an application pool worker, configuration, or mapping failure.Windows System event log
iis_worker_crashAn IIS worker process terminated unexpectedly.Windows System event log
insecure_boot_configThe host booted with insecure Boot Configuration Data flags (test signing, kernel debug, or integrity checks disabled). The boot chain may accept unsigned or debugger-attached code.Windows Security event log
kerberos_cert_domain_unresolvedKerberos could not resolve the domain named in a certificate offered for sign-in.Windows System event log
kerberos_etype_unsupportedA Kerberos exchange failed because the encryption types the client, the service account and the domain controller support do not overlap.Windows System event log
kerberos_pac_verify_failedA domain controller could not verify the signature on the privilege data inside a Kerberos ticket.Windows System event log
kerberos_preauth_failedKerberos pre-authentication failed at the domain controller. The decoded reason is on the line, so a wrong password reads differently from a disabled account or a clock that has drifted.Windows Security event log
kerberos_rc4_ticketA Kerberos service ticket used weak RC4 encryption for a user-backed service principal. Often a credential-theft / downgrade signal when unexpected.Windows Security event log
kerberos_smartcard_cert_missingA domain controller has no usable certificate for smart card logon.Windows System event log
kerberos_ticket_failedA Kerberos ticket request, service-ticket request or renewal was denied. The reason the domain gave is on the line, and the variant says which of the three operations failed.Windows Security event log
kerberos_weak_krbtgt_keyThe domain ticket-granting account has no strong encryption key, so Kerberos tickets are issued using legacy cryptography.Windows System event log
laps_password_backup_failedThe device manages its local administrator password and the backup of that password is failing.Windows identity and security event channels
live_kernel_dump_requestedA kernel component requested a live kernel dump and Windows completed the request.Windows platform event channels
logon_failedA sign-in attempt failed. Account-state failures (disabled, locked, expired, denied by policy) are more actionable than a single bad password.Windows Security event log
logon_right_grantedA system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was granted to a principal in local security policy.Windows Security event log
logon_right_removedA system logon right (interactive, network, batch, service, or remote desktop sign-in, or one of their deny counterparts) was removed from a principal in local security policy.Windows Security event log
mdm_policy_apply_failedA device management command did not take effect on the device.Windows management event channels
mfa_login_succeededA sign-in completed with its second factor verified.Windows Application event log
mfa_not_configuredA multi-factor logon agent is installed on this host but holds no configuration, so it enforces no second factor.Windows Application event log
mfa_unavailable_access_grantedA sign-in was allowed without its second factor because the multi-factor service could not be reached.Windows Application event log
mfa_user_not_enrolledA sign-in was refused because the account is not enrolled with the multi-factor service.Windows Application event log
mssql_db_corruptionSQL Server reported database I/O failure, logical page corruption, or a read retry warning.Windows Application event log
network_share_addedA new network share was created on the host.Windows Security event log
nic_driver_fault_reportedA loaded wireless network adapter driver reported a fault in the adapter or in itself.Windows System event log
nic_driver_load_failedA wireless network adapter driver could not load, normally because of a resource conflict.Windows System event log
nic_link_downA network adapter reported that its link went down.Windows System event log
nic_link_upA network adapter reported that its link came up.Windows System event log
nps_access_deniedNetwork Policy Server denied a connection request. The decoded decision is on the line, so a wrong password reads differently from a request that matched no policy at all.Windows Security event log
nps_lockoutNetwork Policy Server locked an account after repeated failed authentication attempts, so the account cannot authenticate through RADIUS until the lockout clears.Windows Security event log
nps_request_discardedNetwork Policy Server discarded a connection request without processing it, which is different from denying one: the request never reached a policy decision.Windows Security event log
ntfs_corruptionNTFS moved this machine's global corruption-handling state off nominal.Windows storage event channels, Windows System event log
ntfs_delayed_write_lostWindows could not save cached file data to the volume and the data was lost.Windows System event log
ntfs_transaction_log_errorThe NTFS transaction log on a volume could not be written, replayed, or brought up.Windows System event log
ntlm_authentication_usedThis machine used the legacy NTLM authentication protocol, as a client or as a server.Windows identity and security event channels
ntlm_validation_failedNTLM credential validation failed for an account. Can appear on workstations (local accounts) as well as domain controllers, and the decoded reason is on the line.Windows Security event log
office_alertOffice displayed a dialog to a user.Windows application platform event channels
office_subscription_licensing_failedThe subscription licensing check for the installed office suite failed.Windows Application event log
offline_files_slow_link_transition_blockedOffline Files could not change sync mode for a slow link.Windows network event channels
offline_files_sync_failedOffline Files background synchronization failed.Windows network event channels
os_boot_duration_highWindows logged a slow boot or a slow startup component.Windows platform event channels
os_bsod_recurringThe host is bugchecking repeatedly.Crash dump configuration
os_clock_driftThis host's clock hardware runs at the wrong rate.Windows platform event channels
os_crash_dump_newA new crash dump appeared.Crash dump configuration
os_crash_dump_unavailableWindows could not set up the path it writes a crash dump through.Windows platform event channels
os_dump_pagefile_too_smallThe page file is too small for the configured crash dump.Crash dump configuration
os_shutdown_duration_highWindows logged a slow shutdown or a service that delayed shutdown.Windows platform event channels
patch_download_failedWindows Update could not download an update the device needed.Windows management event channels
patch_install_failedWindows Update reports the outcome of an update install attempt on this device.Windows System event log
patch_scan_failedA Windows Update scan did not complete, so the device was offered no updates on that cycle.Windows management event channels
patch_scan_staleWindows Update scan data is stale.Windows Update agent state
patch_updates_pausedWindows Updates are paused for too long.Windows Update agent state
perf_counter_provider_failedA performance-counter provider could not register or create a counter object.Windows application platform event channels
platform_tamper_indicator_reportedA platform-security agent reported a tamper indicator against this machine.Windows platform event channels, Windows System event log
portable_device_unresponsiveA phone, camera, or media player on USB stopped answering.Windows platform event channels
principal_renamedA security principal was renamed. The identifier is unchanged, so events before and after this row describe the same principal under two different names.Windows Security event log
print_connection_reopen_failedThe print spooler could not read one profile's saved printer connections when it restarted.Windows management event channels
printer_driver_install_failedA printer driver did not install, and the stage and code say which part of the install failed.Windows management event channels
proc_handle_count_highA process has a very high handle count.Processes
process_exited_abnormallyA process was stopped by Windows part way through something it could not execute, such as a bad memory access or a corrupted heap. The program did not exit on its own terms.Windows Security event log
psdirect_handshake_probeHyper-V opened a PowerShell Direct channel to a guest virtual machine. The legacy handshake negotiates through the sign-in path, so Windows records it as a failed sign-in, but no account was involved and no action is needed.Windows Security event log
ram_commit_highCommitted memory on this host reached its limit.Windows platform event channels, Host performance
ram_growth_sustainedA process may be leaking memory: its working set grew at every sample of a consecutive run and is now large in absolute bytes or as a share of host RAM.Processes
ram_hard_fault_stormThe host is thrashing memory.Host performance
rds_license_server_unactivatedA Remote Desktop license server is not activated and is issuing only temporary licences.Windows System event log
rds_license_tracking_failedA Remote Desktop license server could not record a per-user licence in the directory.Windows System event log
rds_licensing_service_failedA Remote Desktop license server could not run, or hit an error in its licensing database.Windows System event log
rds_redirected_printer_setup_failedRDS redirected printer setup failed.Windows network event channels
registry_value_changedAn audited registry value was created, modified, or deleted. These events appear only where a SACL and the registry audit subcategory are aimed at that object.Windows Security event log
remote_assist_session_startedA remote assistance session started on this host and a remote party could see the desktop.Windows Application event log
replay_attack_detectedWindows reported a Kerberos authentication replay. Rare; treat as high-signal even as a single event.Windows Security event log
restart_manager_app_pendingRestart Manager could not shut down or restart an app during an update session.Windows Application event log
scheduled_task_createdA scheduled task was created.Windows Security event log
scheduled_task_deletedA scheduled task was deleted.Windows Security event log
scheduled_task_disabledA scheduled task was disabled. The task still exists and no longer runs.Windows Security event log
scheduled_task_engine_failedTask Scheduler could not start the host process a scheduled task runs inside.Windows management event channels
scheduled_task_load_failedA scheduled task definition could not be read at service start, so the task is not in the schedule at all.Windows management event channels
scheduled_task_logon_failedTask Scheduler could not log on as the account a scheduled task stores, so the task did not run.Windows management event channels
scheduled_task_start_failedA scheduled task did not run, and the result code says whether the program was missing, the identity was refused, or the action itself failed.Windows management event channels
scheduled_task_updatedAn existing scheduled task's definition was updated.Windows Security event log
secure_boot_cert_update_pendingA Secure Boot certificate update has not been applied on this device.Windows System event log
secure_boot_revocation_update_failedWindows tried to write its boot revocation level into firmware and the firmware refused.Windows platform event channels
security_agent_config_fetch_failedA security agent could not retrieve its configuration because its credentials were refused.Windows Application event log
security_agent_host_isolatedAn endpoint detection agent isolated this host from the network, or later released it.Windows Application event log
security_agent_service_start_failedA sub-service of an endpoint protection agent failed to start.Windows System event log
security_agent_service_terminatedA sub-service of an endpoint protection agent terminated unexpectedly.Windows System event log
security_group_changedA security group's scope, type, or attributes changed. Changes to privileged groups (Administrators, Domain Admins, and similar) carry a higher band.Windows Security event log
security_group_createdA security group was created. Creation of a privileged group (Administrators, Domain Admins, and similar) carries a higher band.Windows Security event log
security_group_deletedA security group was deleted. Deletion of a privileged group (Administrators, Domain Admins, and similar) carries a higher band.Windows Security event log
service_crashedA Windows service crashed or terminated unexpectedly.Windows System event log
service_exited_errorA Windows service exited with an error.Windows System event log
service_hangA Windows service stopped responding to a control transaction.Windows System event log
service_installedA Windows service was installed. This Security-channel event appears when service-install auditing is enabled; the System channel often carries the same fact by default.Windows Security event log, Windows System event log
service_start_failedA Windows service failed to start.Windows System event log
service_start_timeoutA Windows service did not connect before the startup timeout.Windows System event log
sid_history_add_failedAn attempt to add SID History to an account did not succeed. Rare outside migrations.Windows Security event log
sid_history_addedSID History was added to an account. Rare outside migrations; often a privilege-inheritance or persistence tell.Windows Security event log
smb_anonymous_access_deniedThis server refused anonymous access at the share or server scope.Windows network event channels
smb_anonymous_access_enabledThe server reported that one or more named pipes or shares are marked for anonymous access. The event does not identify the resource or prove that a remote client can reach it.Windows network event channels
smb_client_auth_context_failedThe SMB client could not build an authentication context for a server.Windows network event channels
smb_client_mutual_auth_lostSMB mutual authentication was lost after the client re-authenticated.Windows network event channels
smb_client_security_call_slowAn SMB client security call exceeded its slow threshold.Windows network event channels
smb_connect_failedAn SMB connection attempt failed after the server name resolved.Windows network event channels
smb_delayed_write_lostWindows could not save cached file data to a network share and the data was lost.Windows System event log
smb_insecure_guest_allowedThe SMB client allowed an insecure guest connection.Windows network event channels
smb_insecure_guest_rejectedThe SMB client rejected an insecure guest connection.Windows network event channels
smb_legacy_dialect_rejectedThis server rejected a legacy SMB dialect.Windows network event channels
smb_security_setting_nondefaultAn SMB security setting on this device differs from the Windows default. The payload names the setting and configured value.Windows network event channels
smb_server_name_unresolvedThe SMB client could not resolve a server name.Windows network event channels
smb_server_operation_slowAn SMB server operation exceeded its slow threshold.Windows network event channels
smb_server_transport_bind_failedThe Windows file-sharing service could not bind to a network transport.Windows System event log
smb_session_auth_failedAn SMB session authentication attempt on this server failed.Windows network event channels
smb_session_lostAn SMB session to a server was lost or recovered.Windows network event channels
smb_session_reopen_failedThe server could not reopen an SMB file after the client returned.Windows network event channels
smb_share_access_deniedA share on this server denied access to a client.Windows network event channels
smb_share_connection_lostAn SMB share tree connection was lost or recovered.Windows network event channels
smb_share_recreate_failedA file share could not be recreated because the folder it points at no longer exists.Windows System event log
smb_signing_validation_failedSMB signing or encryption validation failed for a session.Windows network event channels
special_group_logonA logon matched an administrator-configured special-groups watchlist. These events exist only where that watchlist is enabled.Windows Security event log
storage_controller_resetThe storage port driver reset the path to a device.Windows storage event channels, Windows System event log
storage_device_command_failedA storage device did not complete a command, and reported sense data saying why.Windows storage event channels
svc_auto_not_runningAn automatic service is not running.Windows services
svc_flappingA Windows service is flapping.Windows services
svc_stuck_pendingA Windows service is stuck pending.Windows services
system_time_changedThe system clock was changed. Routine time-service adjustments are quiet; changes from other processes are treated as integrity events.Windows Security event log
thermal_cooling_engagedThe platform reached a temperature trip point and engaged cooling.Windows platform event channels
time_sync_failedWindows Time could not reach or resolve its time source.Windows System event log
tls_cert_expiredA remote server presented a certificate that has expired or is not yet valid, and the TLS connection failed.Windows System event log
tls_cert_name_mismatchA TLS certificate name did not match the expected server name.Windows System event log
tls_cert_untrusted_caA remote server presented a certificate issued by an authority this host does not trust, and the TLS connection failed.Windows System event log
tls_cipher_mismatchA remote client offered no cipher suite this host accepts, and the TLS handshake failed.Windows System event log
tls_client_credential_failedThe host could not create a TLS client credential, so a connection that needed to present a client certificate could not build one.Windows System event log
tls_server_credential_failedThe private key behind this host's TLS server certificate could not be accessed.Windows System event log
tpm_attestation_failedTPM attestation failed for a critical component.Windows System event log
unexpected_shutdownThe previous shutdown was not clean: the host stopped without shutting down and came back on the next start.Windows System event log
usb_controller_errorThe USB host controller or USB-C connector manager reported a fault.Windows platform event channels
vbs_key_isolation_failedThe isolated key environment that virtualization-based security provides is failing on this device.Windows identity and security event channels
vm_backup_checkpoint_failedA backup of a virtual machine did not take a consistent snapshot.Windows management event channels
vm_start_failedA virtual machine, or the worker process that runs one, did not start.Windows management event channels
vm_storage_request_slowA storage request a virtualization host made for one of its guests took longer than expected to complete.Windows management event channels
vm_vhd_chain_corruptedA differencing virtual disk and its parent disagree on the parent identity, so the disk chain cannot be merged or checkpointed.Windows management event channels
vol_bitlocker_droppedBitLocker protection is off or suspended on a fixed volume.Disk volumes
vol_data_space_exhaustingA data volume is projected to run out of space.Disk volumes
vol_data_space_lowA fixed data volume is low on free space.Disk volumes
vol_fill_rate_highA volume has a high fill rate that current capacity is absorbing.Disk volumes
vol_mount_failedNTFS could not mount a volume.Windows storage event channels
vol_os_space_exhaustingThe OS volume is projected to run out of space.Disk volumes
vol_os_space_lowThe OS volume is low on free space.Disk volumes
vol_unreadableA fixed volume filesystem is unavailable or unreadable.Disk volumes
vpn_connectedA remote-access connection was established.Windows System event log
vpn_dial_failedA remote-access dial attempt failed.Windows Application event log
vss_data_integrity_writer_failedA backup writer for a database, mail store, virtual machine host, or directory service reported a failure during shadow copy creation.Windows Application event log
vss_legacy_driver_scanThe VSS System Writer could not read a driver binary while enumerating for a snapshot.Windows Application event log
vss_optimization_time_budget_reachedShadow copy optimization did not finish excluding temporary files within its time budget.Windows Application event log
vss_provider_class_not_registeredA component the Volume Shadow Copy Service needs is not registered, so shadow copies cannot be created on this machine.Windows Application event log
vss_shadow_abortedA volume shadow-copy operation was aborted by shadow storage limits.Windows System event log
vss_shadow_lostVolume shadow copies were deleted because shadow storage could not grow.Windows System event log
vss_shadowstorage_near_capShadow storage is near capacity.VSS shadow storage
vss_snapshot_call_failedA call the Volume Shadow Copy Service makes while working with shadow copies did not complete.Windows Application event log
vss_snapshots_failing_for_spaceShadow copy storage is full, so restore points are being deleted or no longer created.Windows Application event log, VSS shadow storage
vss_writer_callback_queryThe Volume Shadow Copy Service could not read a writer's callback interface because of process permissions, and continued.Windows Application event log
vss_writer_failedA VSS writer is failed or unstable.VSS writers
vswitch_config_restore_failedHyper-V virtual switch failed to restore port configuration.Windows System event log
wcf_request_failedA hosted service on this machine could not process a request.Windows Application event log, Windows application platform event channels
wfp_transaction_watchdog_timeoutA Windows Filtering Platform transaction hit a watchdog timeout.Windows network event channels
win_app_error_dialog_shownAn application error popup was recorded.Windows System event log
win_component_store_assembly_missingA component assembly is missing from the store.Windows CBS (Component-Based Servicing) log
win_component_store_corrupt_blocks_packageA Windows package failed to apply because the component store is corrupt.Windows CBS (Component-Based Servicing) log
win_component_store_corruption_recurrenceWindows reported how often component-store corruption has been detected.Windows CBS (Component-Based Servicing) log
win_component_store_file_repairedWindows repaired a file from its component store or backup.Windows CBS (Component-Based Servicing) log
win_component_store_flag_corruption_suspectedWindows suspects component-store file-flag corruption.Windows CBS (Component-Based Servicing) log
win_component_store_payload_corruptA payload file in the component store is corrupt.Windows CBS (Component-Based Servicing) log
win_component_store_payload_unrepairableWindows could not repair a damaged payload file.Windows CBS (Component-Based Servicing) log
win_component_store_repair_completedWindows repaired all recorded component-store corruption.Windows CBS (Component-Based Servicing) log
win_component_store_repair_unavailableWindows could not repair a damaged component.Windows CBS (Component-Based Servicing) log
win_component_store_reprojection_failedWindows could not reproject a component.Windows CBS (Component-Based Servicing) log
win_component_store_scan_found_corruptionWindows servicing reported unrepaired component-store corruption.Windows Setup event log, Windows CBS (Component-Based Servicing) log
win_component_store_scan_repaired_corruptionA component-store scan repaired corruption it found.Windows CBS (Component-Based Servicing) log
win_component_store_source_missingA servicing operation could not find the source files it needed.Windows CBS (Component-Based Servicing) log
win_component_store_sxs_corruptThe side-by-side component store is corrupt.Windows CBS (Component-Based Servicing) log
win_dism_command_failedA DISM command reported failure.Windows DISM servicing log
win_dism_feature_change_failedA Windows optional feature could not be enabled or disabled.Windows DISM servicing log
win_dism_health_command_runA DISM health or repair command was run on this machine.Windows DISM servicing log
win_dism_reboot_requiredA DISM change needs a reboot to take effect.Windows DISM servicing log
win_dism_source_files_missingA DISM operation could not find the source files it needed.Windows DISM servicing log
win_locale_registry_read_failedA process could not open the registry key holding the machine or user locale settings, and fell back to a default.Windows management event channels
win_msi_install_errorWindows Installer reported an install or configuration error. If the installer status says another install is already running, the same event is treated as retry-later context.Windows Application event log
win_msi_operation_failedA Windows Installer operation did not complete. If the installer status says another install is already running, the same event is treated as retry-later context, and an operation refused for want of administrator rights or blocked by an open file is recorded as blocked rather than failed.Windows Application event log
win_msi_product_install_succeededA Windows Installer product install completed successfully.Windows Application event log
win_msi_product_reconfigure_succeededA Windows Installer product configuration operation completed successfully.Windows Application event log
win_msi_product_removal_succeededA Windows Installer product removal completed successfully.Windows Application event log
win_powershell_script_block_framework_codeA PowerShell script block that is generated framework code, such as a proxy module built when a command set is imported, rather than a script someone wrote.Windows PowerShell event channels
win_powershell_script_block_repeatA PowerShell script block ran again with the same content as one already recorded on this host, so this event is a receipt for the run rather than a second copy of the script.Windows PowerShell event channels
win_powershell_script_block_watchlist_hitA PowerShell script block named a command on the watchlist of operations worth reviewing, such as deleting data, changing a protection setting, handling a credential, or sending data out.Windows PowerShell event channels
win_servicing_commit_skipped_reboot_requiredA servicing change was deferred because a reboot is pending.Windows CBS (Component-Based Servicing) log
win_servicing_delta_patch_failedA component delta patch could not be applied.Windows CBS (Component-Based Servicing) log
win_servicing_duplicate_update_nameWindows found a duplicate update name in a package.Windows CBS (Component-Based Servicing) log
win_servicing_manifest_malformedA component manifest is malformed.Windows CBS (Component-Based Servicing) log
win_servicing_manifest_unparseableWindows could not parse a package manifest.Windows CBS (Component-Based Servicing) log
win_servicing_package_change_reportedA Windows package was added, removed or updated.Windows CBS (Component-Based Servicing) log
win_servicing_package_stage_failedA Windows package could not be staged for installation.Windows CBS (Component-Based Servicing) log
win_servicing_package_state_change_failedWindows servicing failed to change a package to the requested state.Windows Setup event log
win_servicing_session_finalizedA Windows servicing session started and finished.Windows CBS (Component-Based Servicing) log
win_servicing_startup_package_failedA Windows package failed during startup processing.Windows CBS (Component-Based Servicing) log
win_servicing_update_package_create_failedWindows could not create an update package.Windows CBS (Component-Based Servicing) log
win_sfc_repairing_componentsSystem File Checker started repairing components.Windows CBS (Component-Based Servicing) log
win_trace_session_failedA Windows tracing session could not start, write, or continue.Windows platform event channels
win_user_profile_load_failedWindows could not load a user profile, or loaded a temporary profile.Windows Application event log
windows_hello_key_registration_failedA Windows Hello key or container operation failed after provisioning had already passed its prerequisites.Windows identity and security event channels
windows_hello_provisioning_blockedWindows Hello for Business will not set up on this device for this user.Windows identity and security event channels
winre_servicing_failedServicing of the Windows recovery environment failed on this device.Windows System event log
wlan_connect_failedWLAN AutoConfig failed to connect using a saved profile.Windows network event channels
wlan_limited_connectivityWireless networking entered limited connectivity.Windows System event log
wlan_security_handshake_failedA wireless security handshake did not finish.Windows network event channels
wmi_provider_registered_as_localsystemA WMI provider registered to run under the LocalSystem account.Windows Application event log