Skip to main content

Windows Application event log

1channels
44curated reasons
6themes fed
Livestatus

Classic Windows Event Log Application channel. Covers application crashes and hangs (Application Error/Hang, WER reports, .NET unhandled exceptions), MSI install outcomes (retry-later result codes read as benign), profile-load failures, ESENT and SQL Server corruption records, AD CS CRL and chain failures, and vendor GPU and service failures. Nothing is deleted: licensing, vendor and transaction chatter is retained at the Debug severity tier. Some events state a severity that does not match their real impact; the stored severity is authoritative, and severity_original keeps the event's own value when the two differ.

Feed id: win.eventlog.application.

Channels​

This feed reads one Windows Event Log channel, Application.

Fields​

FieldTypeUnitMeaning
win.eventlog.application.event_namestringWER report EventName from Windows Error Reporting 1001 (APPCRASH | AppHangB1 | BEX | BlueScreen | StoreAgentInstall* | ...). The discriminator of the heterogeneous 1001 id; the recognition pivot for crash-report queries.
win.eventlog.application.fault_bucketstringWER fault bucket id from Windows Error Reporting 1001. The dedup/recurrence key: same bucket = same crash signature.
win.eventlog.application.appx_app_idstringPackaged-application identity reported by an activation record, the package family plus the application id. The same key the packaged-apps feed promotes, so one application reads the same way on both feeds.
win.eventlog.application.app_namestringApplication the crash/hang record is about: WER 1001 (P1), Application Error 1000, Application Hang 1002, .NET Runtime 1026. The cross-family crash-recurrence join key.
win.eventlog.application.app_versionstringVersion of the crashed application: Application Error 1000, and WER 1001 APPCRASH and CLR20r3 reports (P2).
win.eventlog.application.module_namestringFaulting module from Application Error 1000 and the WER 1001 APPCRASH report (P4). The module where the fault was reported, which is not always its cause.
win.eventlog.application.module_versionstringVersion of the faulting module: Application Error 1000, WER 1001 APPCRASH (P5).
win.eventlog.application.module_pathstringFull path of the faulting module from Application Error 1000.
win.eventlog.application.exception_codestringException code as logged, eight hex digits (c0000005, or 0xc0000005 on builds that render the prefix): Application Error 1000, WER 1001 APPCRASH (P7). The decoded name rides the result code family.
win.eventlog.application.fault_offsetstringOffset of the fault inside the faulting module, hex as logged: Application Error 1000, WER 1001 APPCRASH (P8). With module_name and module_version it locates the instruction.
win.eventlog.application.process_start_filetimestringCreation time of the crashed process from Application Error 1000, as logged: a Windows FILETIME in hex. With the process id it identifies the one process instance that crashed.
win.eventlog.application.managed_exception_typestringUnhandled .NET exception type (System.NullReferenceException): .NET Runtime 1026 and the WER 1001 CLR20r3 report (P9). The type only; the exception message is not promoted.
win.eventlog.application.bugcheck_namestringBug check constant name (DRIVER_IRQL_NOT_LESS_OR_EQUAL) for the stop code in a WER 1001 BlueScreen report (P1). Absent when the code is not a documented bug check.
win.eventlog.application.framework_versionstring.NET runtime version from .NET Runtime 1026 (v4.0.30319).
win.eventlog.application.report_idstringWER report GUID: Windows Error Reporting 1001, Application Error 1000, Application Hang 1002. Joins the crash event to its report record and the local WER archive.
win.eventlog.application.hang_typestringHang type from Application Hang 1002; often Unknown.
win.eventlog.application.productstringProduct name from MsiInstaller 1033.
win.eventlog.application.msi_statusstringRetry-later Windows Installer code an installer failure record carries among its inserts (1618, or its HRESULT form 0x80070652): an install that will come back rather than a failure. The MsiInstaller 1033 outcome code rides the portable result family instead.
win.eventlog.application.rm_session_idstringRestart Manager session id from the RestartManager 100xx family. Joins the shutdown/restart narration around one install operation.
win.eventlog.application.blocked_appstringDisplay name of the app that could not be shut down/restarted, from RestartManager 10006/10007 (user_data DisplayName).
win.eventlog.application.blocked_app_pathstringFull binary path of the blocking app, from RestartManager 10006/10007 (user_data FullPath).
win.eventlog.application.rm_statusstringRestart Manager status code from RestartManager 10006/10007 (user_data Status), as logged.
win.eventlog.application.drivestringDrive letter the Group Policy Drive Maps diagnostic (4117) was mapping, with its colon. The per-user configuration value: the same failure on two letters is one finding, so it is a field rather than part of the message head.
win.eventlog.application.sharestringUNC path the Group Policy Drive Maps diagnostic (4117) was mapping the drive to. The pivot for "which share is failing across the fleet".
win.eventlog.application.msi_code_meaningstringDecoded meaning of the Windows Installer outcome code the event id carries (MsiInstaller 1xxxx, id = 10000 + code), as a stable token from the library decode table. The table names completions as well as failures, so the token states which. The pivot for "which installer condition is this", independent of the rendered language.
win.eventlog.application.vss_routinestringThe routine VSS was executing when a call failed, from the VSS call-failure ids (8193, 12289, 12293), as the API symbol the message names. Group by this rather than by the message pattern when asking which routine is failing: the pattern does not carry the routine on every shape it takes, so the same routine appears under more than one pattern. Absent where the message names free prose in place of a routine, and on a non-English host.
win.eventlog.application.vss_operation_callstringFirst line of the Operation call stack on a VSS event: the immediate call that failed. Constant across an entire event population on the busiest ids, so it answers "which call" and is the wrong thing to group by on its own; pair it with vss_operation_intent. Absent where the event carries no Operation block, and on a non-English host.
win.eventlog.application.vss_operation_intentstringLast line of the Operation call stack on a VSS event: what the call was being made FOR, in the coordinator vocabulary (checking volume support, getting shadow copy properties, deleting shadow copies). The half of the stack that varies, and the grouping key for "what was VSS trying to do when this failed". Equal to vss_operation_call on a one-line stack. Absent where the event carries no Operation block, and on a non-English host.
win.eventlog.application.vss_writerstringWriter Name from the VSS Context block, verbatim and in the vendor casing (SqlServerWriter, Registry Writer, Shadow Copy Optimization Writer). The pivot for "which writer is failing across the estate". Absent where the block names no writer, which is a real answer rather than a gap: many VSS failures are coordinator-side and belong to no writer.
win.eventlog.application.vss_statestringCurrent State from the VSS Context block, verbatim: the phase of the snapshot the coordinator was in (GatherWriterMetadata, DoSnapshotSet, BackupComplete and the like). Requester-side call and phase names, NOT the documented writer-state enum, and not a closed set: treat an unseen value as new vocabulary rather than as a defect.
win.eventlog.application.vss_execution_contextstringThe architecture ROLE the failing code was running as, from Execution Context in the VSS Context block: Coordinator, Requestor, Writer or System Provider, spelled as the event spells them. Writer product names occupy the same slot in the raw text and deliberately do not reach this field, so it stays a role axis; use vss_writer for the product. Absent where the slot names something else.
win.eventlog.application.vss_snapshot_contextstringThe KIND of shadow copy, from Snapshot Context in the VSS Context block, as the Microsoft constant name (VSS_CTX_BACKUP, VSS_CTX_APP_ROLLBACK, VSS_CTX_CLIENT_ACCESSIBLE, VSS_CTX_ALL and the rest). The base context only: modifier attributes composed onto it ride vss_snapshot_attrs. VSS_CTX_CLIENT_ACCESSIBLE is the Previous Versions and Shadow Copies for Shared Folders axis, so this is the field that separates those copies from backup copies. Absent where the value composes to no published constant.
win.eventlog.application.vss_snapshot_setstringThe Snapshot Set identifier a requester was given when it asked for a shadow copy, from the snapshot-initiation record. The join key between the request and everything the coordinator later logs about that set, and the axis that answers how many snapshot attempts a host makes in a window.
win.eventlog.application.vss_snapshot_attrsstringModifier attributes a requester composed onto the snapshot context, as space-separated Microsoft constant names (VSS_VOLSNAP_ATTR_AUTORECOVER and siblings), ascending by bit so the same value always renders the same string. Absent when the context carries no modifiers, which is the common case. A bit the library holds no name for contributes nothing here; the raw value stays in the retained event body.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
adcs_ca_chain_failedcertificatesError
adcs_crl_publish_failedcertificatesError
app_crashapp_stabilityError
app_hangapp_stabilityError
appx_activation_failedapp_stabilityInfo when Windows declines to run the application under the built-in Administrator account, Notice otherwise
aspnet_compilation_failedwebError
aspnet_unhandled_exceptionwebMinor
cert_enroll_failedcertificatesWarning or Verbose
cert_expiringcertificatesWarning
dotnet_unhandled_exceptionapp_stabilityError
entra_password_hash_sync_faileddirectory_servicesError
entra_sync_run_faileddirectory_servicesError
entra_sync_scheduler_aborteddirectory_servicesError
esent_db_corruptiondatabaseError
gpu_driver_errorhardwareNotice at most; native level decides below
group_policy_drive_map_faileddevice_managementWarning
group_policy_extension_apply_faileddevice_managementMinor
group_policy_preference_item_faileddevice_managementMinor or Warning
mfa_not_configuredauthWarning
mfa_sign_in_succeededauthInfo
mfa_unavailable_access_grantedauthError
mfa_user_not_enrolledauthNotice
mssql_db_io_faileddatabaseError
mssql_db_page_corruptiondatabaseCritical
mssql_db_read_retrieddatabaseWarning
office_subscription_licensing_failedlicensingWarning
remote_assist_session_startedremote_accessNotice
restart_manager_app_pendingpatchingInfo cap
security_agent_config_fetch_failedendpoint_protectionError
security_agent_host_isolatedendpoint_protectionSerious or Notice
vpn_dial_failedvpnMinor
vss_optimization_time_budget_reachedbackupDebug
vss_provider_class_not_registeredbackupError
vss_snapshot_call_failedbackupWarning
vss_snapshots_failing_for_spacebackupError
vss_writer_callback_querybackupInfo
vss_writer_failedbackupError
wcf_request_failedwebMinor
win_msi_operation_failedpatchingMinor / Notice when blocked / Info cap for retry-later
win_msi_product_install_succeededpatchingNotice
win_msi_product_reconfigure_succeededpatchingNotice
win_msi_product_removal_succeededpatchingNotice
win_user_profile_load_faileduser_profilesSerious
wmi_provider_registered_as_localsysteminventoryInfo cap

adcs_ca_chain_failed​

Active Directory Certificate Services reported a chain-certificate expiry.

Severity: Error

Impact: Certificate trust may be unhealthy until the CA chain issue is corrected.

Channel: Application

Provider: Microsoft-Windows-CertificationAuthority

Event ids: 58, 65, 66

Where to look next:

  • Check CA chain and certificate expiry together.

Related reasons:

adcs_crl_publish_failed​

Active Directory Certificate Services reported a CRL publication failure.

Severity: Error

Impact: Revocation checks may fail or use stale data once the published CRL expires.

Channel: Application

Provider: Microsoft-Windows-CertificationAuthority

Event ids: 74

Where to look next:

  • Check the CA, CRL distribution point, and CRL freshness.
  • Read adjacent CertificationAuthority events before assuming the exact sub-family.

Related reasons:

app_crash​

A Windows application process crashed.

Severity: Error

Impact: The app exited unexpectedly; user work, background processing, or service functionality may have been interrupted.

Channel: Application

Provider: Application Error

Event ids: 1000

Where to look next:

  • Group by app name and version, faulting module and version, exception code, and fault offset.
  • The faulting module is where the fault was reported, which is not always its cause.
  • Check for recurrence after updates or driver changes.

Related reasons:

Fields it can set: win.eventlog.application.app_name, win.eventlog.application.app_version, win.eventlog.application.exception_code, win.eventlog.application.fault_offset, win.eventlog.application.module_name, win.eventlog.application.module_path, win.eventlog.application.module_version, win.eventlog.application.process_start_filetime, win.eventlog.application.report_id

app_hang​

A Windows application stopped responding and was closed.

Severity: Error

Impact: The user-facing app or background process became unusable until Windows terminated it.

Channel: Application

Provider: Application Hang

Event ids: 1002

Where to look next:

  • Group by app name, report id, and hang type.
  • Check whether hangs cluster around updates, add-ins, or file paths.

Related reasons:

  • app_crash: process terminated by crash rather than hang

Fields it can set: win.eventlog.application.app_name, win.eventlog.application.hang_type, win.eventlog.application.report_id

appx_activation_failed​

A packaged application did not start.

Also reported by: Windows application platform event channels

Severity: Info when Windows declines to run the application under the built-in Administrator account, Notice otherwise

Impact: The user sees the application fail to open. Where the code is the built-in Administrator refusal, nothing is broken: Windows does not run packaged applications under that account.

Channel: Application

Provider: Microsoft-Windows-Immersive-Shell

Event ids: 5973

CaseSeverityTicket class
administrator_tokenInfoapp_stability
other_failureNoticeapp_stability

Where to look next:

  • Read the application identity and the error code.
  • Check whether the launch came from an automated task running as the built-in Administrator.

Fields it can set: win.eventlog.application.appx_app_id

aspnet_compilation_failed​

A web application on this host could not be compiled and is not serving requests.

Severity: Error

Impact: Every request to that application fails until the source or the deployment is corrected. Other applications on the host are unaffected.

Channel: Application

Provider: ASP.NET <version>

Event ids: 1310

Where to look next:

  • Read the compiler error and the file it names from the message.
  • A compilation error immediately after a deployment usually means the deployment was partial.
  • Confirm whether the application answered at all in the window before the first occurrence.

Related reasons:

aspnet_unhandled_exception​

A web application on this host raised an unhandled exception while serving a request.

Severity: Minor

Impact: That request failed for the user who made it. The application keeps serving other requests.

Channel: Application

Provider: ASP.NET <version>

Event ids: 1309

Where to look next:

  • Read the exception type and stack from the message before treating this as an infrastructure question.
  • A count that jumps after a deployment points at the deployment.
  • A steady low rate is normal for most web applications.

Related reasons:

cert_enroll_failed​

A Windows certificate enrollment failed or did not complete. Enrollment against a Microsoft attestation-identity endpoint that no longer serves requests is labeled separately as expected noise.

Severity: Warning or Verbose

Impact: Certificate-dependent authentication, attestation, or device trust workflows may fail later.

Channel: Application

Provider: Microsoft-Windows-CertificateServicesClient-CertEnroll, Microsoft-Windows-CertificateServicesClient-AutoEnrollment

Event ids: 1, 6, 86, 87

CaseSeverityTicket class
failedWarningcertificates
retired_aikVerbosecertificates
autoenroll_cycle_failedWarningcertificates

Where to look next:

  • Review enrollment URL, status, and template or policy context in the event.
  • Check whether the device later received the expected certificate.

Related reasons:

The retired-endpoint shape needs no action: the endpoint no longer serves requests. It repeats on consumer TPM devices and is kept out of the attention bands.

cert_expiring​

A certificate held by this machine is about to expire or has already expired, and has not been replaced.

Also reported by: Windows identity and security event channels

Severity: Warning

Impact: Nothing fails until something asks for the certificate. When something does, it fails with an error that usually names neither the certificate nor its age: a service refusing connections, a network sign-in rejected, or a trust check that stops passing.

Channel: Application

Provider: Microsoft-Windows-CertificateServicesClient-AutoEnrollment

Event ids: 64

Where to look next:

  • Check whether the same thumbprint keeps being reported, which means the renewal is not happening.
  • Read the enrollment failures on the same provider: they usually name why the renewal cannot run.
  • Confirm the machine can reach a domain controller and the certification authority.
  • Check the certificate template's autoenrollment permissions for the machine account.

Related reasons:

dotnet_unhandled_exception​

A .NET application terminated because of an unhandled managed exception.

Severity: Error

Impact: The affected .NET app stopped unexpectedly; repeated events can point to an application defect, dependency issue, or bad input path.

Channel: Application

Provider: .NET Runtime

Event ids: 1026

Where to look next:

  • Group by managed_exception_type and app_name.
  • Correlate with deploy, update, and dependency changes.

Related reasons:

  • app_crash: native Application Error crash record
  • process_crash: one row per crashed process, carrying this exception type when the record could be attached

Fields it can set: win.eventlog.application.app_name, win.eventlog.application.framework_version, win.eventlog.application.managed_exception_type

entra_password_hash_sync_failed​

Password hash synchronization failed for an on-premises domain.

Severity: Error

Impact: Password changes made in that domain do not reach the cloud directory, so affected users sign in to cloud services with an outdated password.

Channel: Application

Provider: Directory Synchronization

Event ids: 611

Where to look next:

  • Read the domain and the domain controller from the message and confirm the controller is reachable.
  • One occurrence around a controller restart is expected; a repeating pattern is not.

Related reasons:

entra_sync_run_failed​

A directory synchronization run profile failed to complete.

Severity: Error

Impact: The changes that run profile carries did not move on this cycle. Repeated failures leave the cloud directory progressively out of date.

Channel: Application

Provider: ADSync

Event ids: 6056

Where to look next:

  • Read the connector and run profile names from the message.
  • Check the connector's own run history in the synchronization console for the underlying error.

Related reasons:

entra_sync_scheduler_aborted​

The directory synchronization scheduler stopped, so no further synchronization cycles run on this server.

Severity: Error

Impact: Directory changes stop reaching the cloud directory from this server until the synchronization service is restarted.

Channel: Application

Provider: Directory Synchronization

Event ids: 906

Where to look next:

  • Restart the synchronization service and confirm cycles resume.
  • Read the exception in the message: memory exhaustion points at the host rather than at the product.
  • Confirm whether this server is the active one or is in staging mode.

Related reasons:

esent_db_corruption​

ESENT reported embedded database corruption or a corruption-adjacent failure.

Severity: Error

Impact: Windows features backed by that embedded store may fail, rebuild state, or lose local cached state.

Channel: Application

Provider: ESENT

Event ids: 447, 448, 474

Where to look next:

  • Identify which ESENT database path or component is named in the event.
  • Correlate with Search, SRUM, token broker, profile, or OS feature symptoms.

Related reasons:

gpu_driver_error​

The NVIDIA display stack reported a warning-or-worse driver error.

Severity: Notice at most; native level decides below

Impact: Users may see display resets, graphics hangs, application crashes, or GPU-accelerated workload interruption. A single event is commonly benign: driver upgrades reset the display stack.

Channel: Application

Provider: nvlddmkm, NVIDIA OpenGL Driver

Where to look next:

  • Check whether a GPU driver was installed or updated around the same time.
  • Look for REPETITION without an adjacent driver install: rate is the signal here, not any one event.
  • Inspect GPU driver version, hardware health, and workload timing.

This reason names a provider-level driver-error family, not a specific mechanism.

group_policy_drive_map_failed​

A Group Policy drive mapping did not complete on this host.

Severity: Warning

Impact: The affected user does not have the mapped drive for that session. Nothing else on the machine is affected, and the mapping is attempted again at every policy refresh.

Channel: Application

Provider: Group Policy Drive Maps

Event ids: 4117

CaseSeverityTicket class
share_unreachableWarningdevice_management
network_name_invalidWarningdevice_management
credential_rejectedMinordevice_management
letter_in_useNoticedevice_management
other_errorWarningdevice_management

Where to look next:

  • The error name in the tail says which question to ask: reachability of the server, resolution of the name, or the stored password.
  • A rejected stored credential repeats against the share at every refresh and can lock the account out.
  • The drive letter and the share ride the event as fields, so the same share failing across many hosts is one query.

Related reasons:

Fields it can set: win.eventlog.application.drive, win.eventlog.application.share

group_policy_extension_apply_failed​

A Group Policy preference extension could not apply the settings from a policy object.

Also reported by: Windows identity and security event channels

Severity: Minor

Impact: None of that policy object's preference items were delivered to the affected user or machine on this refresh.

Channel: Application

Provider: Group Policy Shortcuts, Group Policy Files, and the other preference extensions

Event ids: 8194

Where to look next:

  • A network path error normally means the host could not reach the policy share at that moment.
  • Repeated failures on the same host are the shape worth investigating, not one occurrence.

Related reasons:

group_policy_preference_item_failed​

A Group Policy preference item did not apply on this host. A refused stored credential is held one rung higher, because no later refresh can improve on it.

Severity: Minor or Warning

Impact: The configured item is missing for the affected user or machine. The rest of the policy object applied normally.

Channel: Application

Provider: Group Policy Shortcuts, Group Policy Files, and the other preference extensions

Event ids: 4098

CaseSeverityTicket class
credential_rejectedMinordevice_management
other_errorWarningdevice_management

Where to look next:

  • Read the item name, the policy object and the error code from the message.
  • Access denied and file-not-found on a preference item usually mean the source path or its permissions changed.
  • An item failing at every refresh will not clear itself.
  • A refused stored credential repeats against the target on every refresh and can lock the account out.

Related reasons:

mfa_not_configured​

A multi-factor logon agent is installed on this host but holds no configuration, so it enforces no second factor.

Severity: Warning

Impact: Sign-ins on this host complete with a single factor while the product is present and appears deployed.

Channel: Application

Provider: Duo Security

Event ids: 0

Where to look next:

  • Confirm whether this host is inside the intended rollout scope.
  • Compare against hosts of the same group that do enforce, to see whether the gap is deliberate.

Related reasons:

mfa_sign_in_succeeded​

A sign-in completed with its second factor verified.

Severity: Info

Channel: Application

Provider: Duo Security

Event ids: 0

Where to look next:

  • Read these beside the fail-open rows on the same host: the ratio is what says how long a gap lasted.
  • The absence of these on a host that has the product installed is itself the finding.

Related reasons:

mfa_unavailable_access_granted​

A sign-in was allowed without its second factor because the multi-factor service could not be reached.

Severity: Error

Impact: Multi-factor authentication was not applied to that sign-in. While the service stays unreachable, sign-ins on this host continue to complete with a single factor.

Channel: Application

Provider: Duo Security

Event ids: 0

Where to look next:

  • Check network reachability from this host to the verification service.
  • Count these against successful sign-ins on the same host to see how long the gap lasted.
  • Review the configured failure mode: allowing the sign-in through is a deliberate setting.

Related reasons:

mfa_user_not_enrolled​

A sign-in was refused because the account is not enrolled with the multi-factor service.

Severity: Notice

Impact: The user cannot sign in on this host until the account is enrolled or excluded from the policy.

Channel: Application

Provider: Duo Security

Event ids: 0

Where to look next:

  • Enrol the account, or place it in the exclusion the policy intends.
  • Service accounts appearing here usually need a policy exclusion rather than an enrolment.

Related reasons:

mssql_db_io_failed​

SQL Server reported an I/O error on a database file.

Severity: Error

Impact: A SQL database may have an unreliable storage path; affected data or application workloads can be at risk.

Channel: Application

Provider: MSSQLSERVER, MSSQL$<instance>

Event ids: 823

Where to look next:

  • Identify the database, file, and storage path named in the event.

Related reasons:

mssql_db_page_corruption​

SQL Server confirmed logical page corruption in a database.

Severity: Critical

Impact: The database has confirmed corrupted pages; affected data or application workloads can be at risk, and the condition does not self-heal.

Channel: Application

Provider: MSSQLSERVER, MSSQL$<instance>

Event ids: 824

Where to look next:

  • Identify the database, file, and page named in the event.
  • Treat this as confirmed corruption, not a suspicion.

Related reasons:

mssql_db_read_retried​

SQL Server retried a database read after it failed, and the retry succeeded.

Severity: Warning

Impact: Not confirmed corruption, but an early-warning signal for the storage path a database sits on.

Channel: Application

Provider: MSSQLSERVER, MSSQL$<instance>

Event ids: 825

Where to look next:

  • Identify the database, file, and storage path named in the event.
  • Treat this as an early warning, not confirmed corruption.

Related reasons:

office_subscription_licensing_failed​

The subscription licensing check for the installed office suite failed.

Severity: Warning

Impact: The suite keeps working on the licence it already holds. If the check keeps failing, the applications eventually drop to reduced functionality and documents become read-only.

Channel: Application

Provider: Office 2016 Licensing Service

Event ids: 0

Where to look next:

  • Check whether the same host reports it repeatedly, or only around periods of being offline.
  • Confirm the signed-in account still holds a licence in the tenant.
  • Check outbound access to the licensing endpoints from that machine.

remote_assist_session_started​

A remote assistance session started on this host and a remote party could see the desktop.

Severity: Notice

Impact: Someone remote had a view of this desktop from this moment. Whether that was expected depends on whether a support session was arranged.

Channel: Application

Provider: Quick Assist

Event ids: 0

Where to look next:

  • Confirm the session was arranged with the user before treating it as routine.
  • Compare the time against the helpdesk record for that user.
  • Unexpected sessions on a workstation are the shape support-desk impersonation leaves.

Related reasons:

restart_manager_app_pending​

Restart Manager could not shut down or restart an app during an update session.

Severity: Info cap

Impact: The update may need a retry, reboot, or user action to close the blocking app.

Channel: Application

Provider: Microsoft-Windows-RestartManager

Event ids: 10006, 10007

Where to look next:

  • Join by Restart Manager session id when present.
  • Review blocked app name, path, and status.

Related reasons:

Fields it can set: win.eventlog.application.blocked_app, win.eventlog.application.blocked_app_path, win.eventlog.application.rm_session_id, win.eventlog.application.rm_status

security_agent_config_fetch_failed​

A security agent could not retrieve its configuration because its credentials were refused.

Severity: Error

Impact: The agent takes no new configuration or detection content and drifts from the policy it is meant to enforce, while continuing to appear installed.

Channel: Application

Provider: HuntressAgent

Event ids: 4

Where to look next:

  • Re-register the agent with a valid identifier and key.
  • Check the vendor console for whether this host is reporting at all.

Related reasons:

security_agent_host_isolated​

An endpoint detection agent isolated this host from the network, or later released it.

Severity: Serious or Notice

Impact: While isolated the host cannot reach the network, so the user cannot work and the machine's other telemetry may stop arriving.

Channel: Application

Provider: HuntressAgent

Event ids: 1, 2

CaseSeverityTicket class
isolatedSeriousendpoint_protection
releasedNoticeendpoint_protection

Where to look next:

  • Confirm from the vendor console whether the isolation was automatic or triggered by an analyst.
  • Pair the isolation with its release before judging how long the host was off the network.
  • The event names no threat: read the detection that preceded it in the vendor console.

Related reasons:

vpn_dial_failed​

A remote-access dial attempt failed.

Severity: Minor

Impact: The user did not reach the network through that profile on that attempt. A single failure is normally retried successfully; repeated failures on one profile are the tunnel rather than the user.

Channel: Application

Provider: RasClient

Event ids: 20227

Where to look next:

  • Read the error code from the message: an authentication code points at the credential.
  • Check whether the same profile connected successfully soon afterwards.
  • The same profile failing across many hosts points at the concentrator, not the users.

Related reasons:

  • vpn_connected: a dial that succeeded, which is what makes a failure readable

vss_optimization_time_budget_reached​

Shadow copy optimization did not finish excluding temporary files within its time budget.

Severity: Debug

Impact: The shadow copy is larger than it would otherwise be. Backup correctness is unaffected.

Channel: Application

Provider: VSS

Event ids: 8219, 8220, 8226

Where to look next:

  • Persistent occurrences on a host with tight free space are worth a disk-space check, not a backup investigation.

Related reasons:

Fields it can set: win.eventlog.application.vss_execution_context, win.eventlog.application.vss_operation_call, win.eventlog.application.vss_operation_intent, win.eventlog.application.vss_writer

vss_provider_class_not_registered​

A component the Volume Shadow Copy Service needs is not registered, so shadow copies cannot be created on this machine.

Severity: Error

Impact: Snapshot-based backups, System Restore and anything else that needs a shadow copy fail on this host until the registration is repaired. A backup product may still complete a job by other means, so a green backup report does not clear this.

Channel: Application

Provider: VSS

Event ids: 22, 8193, 12292

Where to look next:

  • Confirm the Volume Shadow Copy and COM+ Event System services are installed and start.
  • Re-register the shadow copy provider and the VSS component libraries on the host.
  • Expect the host to keep producing this at high volume until it is repaired; it does not self-heal.

Related reasons:

Fields it can set: win.eventlog.application.vss_execution_context, win.eventlog.application.vss_operation_call, win.eventlog.application.vss_operation_intent, win.eventlog.application.vss_routine, win.eventlog.application.vss_snapshot_attrs, win.eventlog.application.vss_snapshot_context

vss_snapshot_call_failed​

A call the Volume Shadow Copy Service makes while working with shadow copies was refused or rejected.

Severity: Warning

Impact: Shadow copy handling on the affected volume is constrained: the storage area cannot be resized, or a snapshot phase did not complete as asked. Backups may still succeed, so this is context for a backup problem rather than proof of one.

Channel: Application

Provider: VSS

Event ids: 12289

What you see: A VSS error in the Application log naming the call that did not complete and the coordinator operation it was made for: resizing the shadow copy storage area, or a snapshot preparation or commit phase.

What it means: One call inside shadow copy handling was refused or rejected. A refused resize means the storage area on that volume stays the size it is. A rejected preparation or commit call points at the storage driver or a third-party shadow copy provider. Neither says the backup failed: this event sees one call and not the job.

What to do: Match the remedy to the call: permissions on the volume and its shadow storage association for a refused resize, the storage driver or provider for a rejected phase call, and the backup product's own report for whether the job succeeded.

When to ignore it: A call abandoned because the machine was shutting down, or a process image lookup against an already-exited process, ship as reasonless shapes (vss_snapshot_shutdown_in_progress, vss_snapshot_process_exited) rather than under this reason.

References:

Example

Volume Shadow Copy Service error: Unexpected error DeviceIoControl(\\?\Volume{00000000-0000-0000-0000-000000000060} - 0000000000000001,0x0053c008,0000000000000002,0,0000000000000003,4096,[0]). hr = 0x80070057, The parameter is incorrect.
.

Operation:
Processing EndPrepareSnapshots

Context:
Execution Context: System Provider

channel: Application
provider_name: VSS
event_id: 12289

SparkLogs: vss_snapshot_call_failed, Warning, vss_snapshot_call_failed: NOTABLE: Volume Shadow Copy Service error: Unexpected error DeviceIoControl(\\?\Volume{00000000-0000-0000-0000-000000000060} - 0000000000000001,0x0053c008,0000000000000002,0,0000000000000003,4096,[0]). hr = 0x80070057, The parameter is incorrect. . Operation: Processing EndPrepareSnapshots Context: Execution Context: System Provider | error_code=87 error_code_name=ERROR_INVALID_PARAMETER

CaseSeverityTicket classEvent ids
diff_area_resize_deniedWarningbackup12289
phase_parameter_rejectedWarningbackup12289

Where to look next:

  • Check the permissions on the volume and its shadow storage association for the resize refusal.
  • Check the storage driver and any third-party shadow copy provider for the parameter rejections.
  • Confirm the backup job outcome separately; this line does not report it.

Related reasons:

Fields it can set: win.eventlog.application.vss_execution_context, win.eventlog.application.vss_operation_call, win.eventlog.application.vss_operation_intent, win.eventlog.application.vss_routine, win.eventlog.application.vss_snapshot_attrs, win.eventlog.application.vss_snapshot_context

vss_snapshots_failing_for_space​

Shadow copy storage is full, so restore points are being deleted or no longer created.

Also reported by: Windows System event log, VSS shadow storage

Severity: Error

Impact: Snapshot-based backups and System Restore lose history or stop working on the affected volume. A backup job may still report success while protecting less than it appears to.

Channel: Application, System

Provider: VSS, Volsnap

Event ids: 25, 8193

What you see: A VSS event in the Application log saying there is no room left for shadow copy data on a volume: no remaining diff area candidates, copies deleted because the storage could not grow, or the insufficient-storage result.

What it means: Shadow copy storage is at its cap on that volume: Windows is either deleting restore points to stay under it or has stopped taking new ones, and the loss already happened. A backup job can still report success while protecting less history than expected.

What to do: Check the shadow storage association and maximum size for the volume, compare the oldest surviving restore point against the retention the customer expects, then free space or raise the cap.

When to ignore it: A refused resize of the storage area is a different event with a different remedy: it is about changing a maximum size, not about having room to create a copy.

References:

Example

Volume Shadow Copy Service error: There is insufficient storage available to create either the shadow copy storage file or other shadow copy data. hr = 0x8004231f.

channel: Application
provider_name: VSS
event_id: 8193

SparkLogs: vss_snapshots_failing_for_space, Error, vss_snapshots_failing_for_space: NOTABLE: Volume Shadow Copy Service error: There is insufficient storage available to create either the shadow copy storage file or other shadow copy data. hr = 0x8004231f.

Where to look next:

  • Check the shadow storage association and maximum size for the affected volume.
  • Verify the oldest surviving restore point against the retention the customer expects.
  • Free space or raise the cap; the condition recurs until the allocation changes.

Related reasons:

vss_writer_callback_query​

The Volume Shadow Copy Service could not read a writer's callback interface because of process permissions, and continued.

Severity: Info

Impact: None on its own. Shadow copy creation is not blocked by this check.

Channel: Application

Provider: VSS

Event ids: 8194

Where to look next:

  • Treat as a real finding only alongside a failed backup on the same host and window.

Related reasons:

Fields it can set: win.eventlog.application.vss_operation_call, win.eventlog.application.vss_operation_intent, win.eventlog.application.vss_routine, win.eventlog.application.vss_writer

vss_writer_failed​

A backup writer for a database, mail store, virtual machine host, or directory service reported a failure during shadow copy creation.

Also reported by: VSS writers

Severity: Error

Impact: The backup of that data store may be incomplete or inconsistent, even if the backup job itself reported success.

Channel: Application

Provider: VSS, SQLWRITER

Event ids: 8193, 24581, 24582, 24583

What you see: A VSS or SQLWRITER event in the Application log naming a writer that fronts a data store (SQL Server, Exchange, Hyper-V, Active Directory, a failover cluster, a Certificate Authority) and the snapshot phase it failed in.

What it means: That writer could not do its part of the shadow copy: the backup of the store it fronts may be inconsistent or unusable even though the snapshot finished and the job reported success. VSS does not report a per-writer recovery, and the risk shows only at restore time.

What to do: Identify the named writer, then check the most recent restore point for the store it protects and the application's own log in the same window, where the cause is usually recorded.

When to ignore it: Ignore a registry probe from the writer service reporting an error constant beside a result of zero; that combination means success.

References:

Example

A VSS writer has rejected an event with error 0x800423f4, The writer experienced a non-transient error. If the backup process is retried, the error is likely to reoccur.
. Changes that the writer made to the writer components while handling the event will not be available to the requester.

Operation:
PrepareForSnapshot Event

Context:
Execution Context: Writer
Writer Class Id: {00000000-0000-0000-0000-000000000010}
Writer Name: SqlServerWriter
Writer Instance ID: {00000000-0000-0000-0000-000000000011}
Command Line: "C:\Program Files\Example\sqlwriter.exe"
Process ID: 4321

channel: Application
provider_name: VSS
event_id: 8229

SparkLogs: vss_writer_failed, Error, vss_writer_failed: NOTABLE: A VSS writer has rejected an event with error 0x800423f4, The writer experienced a non-transient error. If the backup process is retried, the error is likely to reoccur. . Changes that the writer made to the writer components while handling the event will not be available to the requester. Operation: PrepareForSnapshot Event Context: Execution Context: Writer Writer Class Id: {00000000-0000-0000-0000-000000000010} Writer Name: SqlServerWriter Writer Instance ID: {00000000-0000-0000-0000-000000000011} Command Line: "C:\Program Files\Example\sqlwriter.exe" Process ID: 4321

Where to look next:

  • Identify the named writer and verify the most recent restore point for that store.
  • Check the application's own logs in the same window; the writer failure usually has a cause recorded there.
  • Recurring failures for the same writer mean the protected data has no verified recent backup.

Related reasons:

Fields it can set: win.eventlog.application.vss_execution_context, win.eventlog.application.vss_operation_call, win.eventlog.application.vss_operation_intent, win.eventlog.application.vss_routine, win.eventlog.application.vss_writer

wcf_request_failed​

A hosted service on this machine could not process a request.

Also reported by: Windows application platform event channels

Severity: Minor

Impact: The caller did not get an answer for that request. Other requests and other applications on the host are unaffected.

Channel: Application

Provider: System.ServiceModel <version>

Event ids: 3

Where to look next:

  • Read the endpoint path from the message: an endpoint that does not exist usually means a caller pointed at the wrong address or a deployment that did not land.
  • Compare the count against the web server's own request log for the same window.
  • The same endpoint failing across several hosts points at the deployment rather than at a client.

win_msi_operation_failed​

A Windows Installer operation did not complete. If the installer status says another install is already running, the same event is treated as retry-later context, and an operation refused for want of administrator rights or blocked by an open file is recorded as blocked rather than failed.

Severity: Minor / Notice when blocked / Info cap for retry-later

Impact: The product may be absent or partially configured until the install is retried or repaired.

Channel: Application

Provider: MsiInstaller

Event ids: 1013, 1032, 1033, 10005, 11306, 11321, 11500, 11708, 11714, 11729, 11730

CaseSeverityTicket class
failedMinorpatching
install_errorWarningpatching
privilege_refusedNoticepatching
file_in_useNoticepatching
outcome_failedMinorpatching
retry_laterInfopatching

Where to look next:

  • The decoded installer error in the tail says which condition it was, and it reads the same on a machine whose text is not English.
  • A blocked record means the operation never ran: elevate it, or find what keeps attempting it unelevated.
  • Check product name and MSI status when present.
  • Look for nearby 11707 success or repeated 11708 failures.
  • Compare against the completed installs of the same product to see whether it landed later.

Related reasons:

Fields it can set: win.eventlog.application.msi_code_meaning, win.eventlog.application.msi_status, win.eventlog.application.product

Retry-later detection reads the installer status value rather than the message text, so it behaves the same on a non-English system.

win_msi_product_install_succeeded​

A Windows Installer product install completed successfully.

Severity: Notice

Impact: The product is installed. The record is the change-history anchor for what arrived on the machine and when.

Channel: Application

Provider: MsiInstaller

Event ids: 1033, 11707

Where to look next:

  • Join on the product name to find the failed attempts that preceded it.
  • Compare against the software inventory when a product is expected and absent.

Related reasons:

Fields it can set: win.eventlog.application.msi_code_meaning, win.eventlog.application.product

The outcome is read from the installer result field rather than from the message text, so it behaves the same on a non-English system.

win_msi_product_reconfigure_succeeded​

A Windows Installer product configuration operation completed successfully.

Severity: Notice

Impact: The product's installed configuration changed. The record is the change-history anchor for what was reconfigured and when.

Channel: Application

Provider: MsiInstaller

Event ids: 11728

Where to look next:

  • Join on the product name to see what was reconfigured and how often.
  • A product reconfiguring on a timer is normally a management agent driving it, not a person.

Related reasons:

Fields it can set: win.eventlog.application.msi_code_meaning, win.eventlog.application.product

The outcome is read from the installer error code the event id carries rather than from the message text, so it behaves the same on a non-English system.

win_msi_product_removal_succeeded​

A Windows Installer product removal completed successfully.

Severity: Notice

Impact: The product is no longer installed. The record is the change-history anchor for what left the machine and when.

Channel: Application

Provider: MsiInstaller

Event ids: 11724

Where to look next:

  • Join on the product name to see whether the product returned afterwards.
  • Compare against the software inventory when a product is expected and absent.

Related reasons:

Fields it can set: win.eventlog.application.msi_code_meaning, win.eventlog.application.product

The outcome is read from the installer error code the event id carries rather than from the message text, so it behaves the same on a non-English system.

win_user_profile_load_failed​

Windows could not load a user profile, or loaded a temporary profile.

Severity: Serious

Impact: The user cannot work normally on that machine: they log on with missing settings, missing data paths, or a temporary profile until the profile issue is fixed.

Channel: Application

Provider: Microsoft-Windows-User Profiles Service

Event ids: 1511, 1542

Where to look next:

  • Identify the affected user profile from the event message.
  • Check profile service errors, disk space, permissions, and roaming or FSLogix state.

wmi_provider_registered_as_localsystem​

A WMI provider registered to run under the LocalSystem account.

Severity: Info cap

Impact: None. This states what the provider is permitted to do, not that anything happened.

Channel: Application

Provider: Microsoft-Windows-WMI

Event ids: 63

Where to look next:

  • Do not treat this line as a security finding: it reports a registration, never an action.

Vocabularies​

These token sets are closed: a value outside the set leaves its field unset instead of invented.

result_constant​

Published Microsoft constant for the result this compact family named. Minted to the constants these rows emit, not bound to the full win32 table. Inline because the constant is the action-changing token and the string an engineer searches for.

  • VSS_E_WRITERERROR_TIMEOUT
  • VSS_E_WRITERERROR_RETRYABLE
  • VSS_E_WRITERERROR_NONRETRYABLE
  • VSS_E_FLUSH_WRITES_TIMEOUT
  • VSS_E_HOLD_WRITES_TIMEOUT
  • ERROR_NO_SUCH_ALIAS

Portable vocabularies​

Library-wide sets, so the same token means the same thing on every data feed.

sparklogs.result.code_space​

  • msi: Windows Installer error code
  • vss: Volume Shadow Copy Service private result code (VSS_E_*/VSS_S_*)

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.