Skip to main content

Windows application platform event channels

25channels
11curated reasons
3themes fed
Livestatus

Application platform and user shell channels, bound as one feed: packaged-app deployment and readiness, the shell and modern app launch surface, application compatibility, Windows Error Reporting health, and Office alert dialogs. Curated failure, cleanup, and lifecycle records retain a Warning ceiling for unmatched events.

Feed id: win.eventlog.apps.

Channels​

This feed binds 25 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
Microsoft-Windows-AppID/Operationalsecurity_audit
Microsoft-Windows-Application Server-Applications/Operationalapp_stability
Microsoft-Windows-Application-Experience/Program-Inventoryinventory
Microsoft-Windows-ApplicationResourceManagementSystem/Operationalapp_stability
Microsoft-Windows-AppModel-Runtime/Adminapp_stability
Microsoft-Windows-AppReadiness/Adminapp_stability
Microsoft-Windows-AppReadiness/Operationalapp_stability
Microsoft-Windows-AppXDeployment-Server/Operationalpatching
Microsoft-Windows-AppXDeployment/Operationalpatching
Microsoft-Windows-AppXDeploymentServer/Operationalpatching
Microsoft-Windows-AppXDeploymentServer/Restrictedpatching
Microsoft-Windows-AppxPackaging/Operationalpatching
Microsoft-Windows-Containers-BindFlt/Operationalapp_stability
Microsoft-Windows-Containers-Wcifs/Operationalapp_stability
Microsoft-Windows-CoreApplication/Operationalapp_stability
Microsoft-Windows-Diagnosis-PCW/Operationalapp_stability
Microsoft-Windows-Fault-Tolerant-Heap/Operationalapp_stability
Microsoft-Windows-Kernel-ShimEngine/Operationalapp_stability
Microsoft-Windows-Shell-Core/Operationalapp_stability
Microsoft-Windows-TWinUI/Operationalapp_stability
Microsoft-Windows-UAC-FileVirtualization/Operationalapp_stability
Microsoft-Windows-WER-Diag/Operationalapp_stability
Microsoft-Windows-WER-PayloadHealth/Operationalapp_stability
OAlertsapp_stability
OSessionapp_stability

Fields​

FieldTypeUnitMeaning
win.eventlog.apps.appx_package_full_namestringFull packaged-application identity reported by deployment, readiness, or runtime records.
win.eventlog.apps.appx_package_family_namestringPackage family identity reported by the shell or application runtime.
win.eventlog.apps.appx_operationstringDeployment or readiness operation as the provider wrote it. Numeric deployment values remain raw.
win.eventlog.apps.appx_deployment_operationintRaw AppX DeploymentOperation integer. No local name map is inferred.
win.eventlog.apps.appx_requeue_reasonstringReason the deployment provider gives for putting an attempt back on its queue, as written.
win.eventlog.apps.appx_calling_processstringProcess label the deployment provider reports as the caller.
win.eventlog.apps.appx_package_typestringPackage type reported by the deployment provider.
win.eventlog.apps.appx_cleanup_error_countintNumber of package files a cleanup summary says remain.
win.eventlog.apps.appx_cleanup_registry_keystringRegistry key name a package cleanup record could not remove.
win.eventlog.apps.appx_app_idstringPackaged-application identity reported by an activation record.
win.eventlog.apps.appx_activation_phasestringActivation phase flags as the provider wrote them.
win.eventlog.apps.appx_contract_idstringApplication contract the shell attempted to activate.
win.eventlog.apps.appx_service_namestringPackaged-application service the deployment client tried to start.
win.eventlog.apps.perf_counter_set_guidstringCounter-set identifier whose provider registration failed.
win.eventlog.apps.perf_provider_guidstringPerformance-counter provider identifier that failed to register.
win.eventlog.apps.perf_counter_idintPerformance-counter identifier reported by the provider.
win.eventlog.apps.app_domainstringHosted application domain that raised a request exception.
win.eventlog.apps.exception_typestringFramework exception type parsed from the provider exception detail.

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
appid_certificate_store_verification_failedsecurity_auditDebug
appid_certificate_store_verifiedsecurity_auditInfo
appx_activation_failedapp_stabilityNotice or Info
appx_cleanup_residuepatchingDebug
appx_deployment_failedpatchingNotice, Info or Verbose
appx_deployment_requeuedpatchingVerbose
appx_package_runtime_corruptapp_stabilityWarning or Notice
appx_provisioning_failedapp_stabilityNotice or Info
appx_service_start_failedpatchingNotice or Info
perf_counter_provider_failedapp_stabilityDebug
wcf_request_failedapp_stabilityMinor

appid_certificate_store_verification_failed​

The AppID service reported a certificate-store verification failure.

Severity: Debug

Impact: This is AppID context until AppLocker records establish an enforcement impact.

Channel: Microsoft-Windows-AppID/Operational

Provider: Microsoft-Windows-AppID

Event ids: 4005

Where to look next:

  • Compare the result with AppLocker records before treating it as a rule-evaluation failure.

Related reasons:

appid_certificate_store_verified​

The AppID service reported a successful certificate-store verification.

Severity: Info

Impact: Retained as context for nearby failures; does not by itself establish enforcement.

Channel: Microsoft-Windows-AppID/Operational

Provider: Microsoft-Windows-AppID

Event ids: 4006

Where to look next:

  • Read this as the denominator beside nearby verification failures.

Related reasons:

appx_activation_failed​

A packaged application did not start.

Also reported by: Windows Application event log

Severity: Notice or Info

Impact: The event describes one application activation attempt.

Channel: Microsoft-Windows-TWinUI/Operational, Microsoft-Windows-AppModel-Runtime/Admin

Provider: Microsoft-Windows-Immersive-Shell, Microsoft-Windows-AppModel-Runtime

Event ids: 4, 5, 18, 20, 21, 22, 26, 27, 31, 32, 35, 36, 38, 65, 66, 67, 69, 202, 203, 207, 208, 212, 215, 216, 2825, 5955, 5961, 5962, 5990

CaseSeverityTicket class
administrator_tokenInfoapp_stability
activation_timeoutNoticeapp_stability
shell_failureNoticeapp_stability
runtime_failureNoticeapp_stability

Where to look next:

  • Read the app identity and error code.
  • A timeout is not proof that the package is damaged.

Related reasons:

Fields it can set: win.eventlog.apps.appx_activation_phase, win.eventlog.apps.appx_app_id, win.eventlog.apps.appx_contract_id, win.eventlog.apps.appx_package_full_name

appx_cleanup_residue​

During package cleanup, Windows could not remove every file or registry entry.

Severity: Debug

Impact: A later cleanup pass may remove the residue.

Channel: Microsoft-Windows-AppXDeploymentServer/Operational

Provider: Microsoft-Windows-AppXDeployment-Server

Event ids: 471, 472, 493, 494, 503, 516, 801, 802, 808, 5224, 5230

CaseSeverityTicket class
summaryDebugpatching
detailDebugpatching
registry_absentDebugpatching
registry_otherDebugpatching

Where to look next:

  • Use the folder count when disk space is a concern.
  • Investigate a rising count or other error codes.

Related reasons:

Fields it can set: win.eventlog.apps.appx_cleanup_error_count, win.eventlog.apps.appx_cleanup_registry_key

appx_deployment_failed​

A packaged-app operation failed for a user on this device.

Severity: Notice, Info or Verbose

Impact: The event records one failed attempt and does not establish how long the package remains unavailable.

Channel: Microsoft-Windows-AppXDeploymentServer/Operational, Microsoft-Windows-AppXDeploymentServer/Restricted, Microsoft-Windows-AppXDeployment-Server/Operational, Microsoft-Windows-Shell-Core/Operational

Provider: Microsoft-Windows-AppXDeployment-Server, Microsoft-Windows-AppXDeployment-Server-UndockedDeh, Microsoft-Windows-Shell-Core

Event ids: 401, 413, 441, 697, 698, 707, 10004, 10005, 10010, 62164

CaseSeverityTicket class
packages_in_useVerbosepatching
blocked_by_policyNoticepatching
other_failureInfopatching

Where to look next:

  • Read the operation and error code first.
  • Pivot on the package across users and hosts.

Related reasons:

Fields it can set: win.eventlog.apps.appx_calling_process, win.eventlog.apps.appx_deployment_operation, win.eventlog.apps.appx_package_family_name, win.eventlog.apps.appx_package_full_name, win.eventlog.apps.appx_package_type, win.eventlog.apps.appx_requeue_reason

appx_deployment_requeued​

The deployment service put a packaged-app attempt back on its queue, and the requeue reason says why.

Severity: Verbose

Channel: Microsoft-Windows-AppXDeploymentServer/Operational

Provider: Microsoft-Windows-AppXDeployment-Server

Event ids: 626

Where to look next:

  • Read the requeue reason and the operation, then pivot on the package across devices.
  • A package family that reappears day after day is a deployment that never completes.

Related reasons:

Fields it can set: win.eventlog.apps.appx_calling_process, win.eventlog.apps.appx_deployment_operation, win.eventlog.apps.appx_package_full_name, win.eventlog.apps.appx_requeue_reason

These records are rate-bounded: one per package family per device per day, with the count of what a day suppressed carried on the next day's first record.

appx_package_runtime_corrupt​

A package runtime record is corrupted.

Severity: Warning or Notice

Impact: Apps in that package family can fail to launch until the package is repaired.

Channel: Microsoft-Windows-AppModel-Runtime/Admin

Provider: Microsoft-Windows-AppModel-Runtime

Event ids: 79, 80

CaseSeverityTicket class
repair_attemptedNoticeapp_stability
repair_unavailableWarningapp_stability

Where to look next:

  • Check whether a repair-unavailable record follows the repair attempt.

Related reasons:

Fields it can set: win.eventlog.apps.appx_package_family_name

appx_provisioning_failed​

App Readiness reported a failed packaged-app operation.

Severity: Notice or Info

Impact: The event records one operation and its result.

Channel: Microsoft-Windows-AppReadiness/Admin, Microsoft-Windows-AppReadiness/Operational

Provider: Microsoft-Windows-AppReadiness

Event ids: 10, 11, 214, 215, 218, 304, 319

CaseSeverityTicket class
retry_scheduledInfoapp_stability
packages_in_useInfoapp_stability
other_failureNoticeapp_stability

Where to look next:

  • Read the operation and result code.
  • Pivot on package and user context across hosts.

Related reasons:

Fields it can set: win.eventlog.apps.appx_operation, win.eventlog.apps.appx_package_full_name

appx_service_start_failed​

The packaged-app deployment client could not start or reach a service.

Severity: Notice or Info

Impact: Packaged apps may not deploy for that logon.

Channel: Microsoft-Windows-AppXDeployment/Operational

Provider: Microsoft-Windows-AppXDeployment

Event ids: 302, 303, 311, 328

CaseSeverityTicket class
shutdown_in_progressInfopatching
other_failureNoticepatching

Where to look next:

  • Read the error code before treating a restart race as a service failure.

Related reasons:

Fields it can set: win.eventlog.apps.appx_service_name

perf_counter_provider_failed​

A performance-counter provider could not register or create a counter object.

Severity: Debug

Impact: A monitoring tool can miss readings from that provider.

Channel: Microsoft-Windows-Diagnosis-PCW/Operational

Provider: Microsoft-Windows-Diagnosis-PCW

Event ids: 2, 3

CaseSeverityTicket class
registrationDebugapp_stability
instanceDebugapp_stability

Where to look next:

  • Read the counter identifier and error code in the preserved payload.

Fields it can set: win.eventlog.apps.perf_counter_id, win.eventlog.apps.perf_counter_set_guid, win.eventlog.apps.perf_provider_guid

wcf_request_failed​

A hosted service reported an exception while processing a request.

Also reported by: Windows Application event log

Severity: Minor

Impact: The record identifies an application request path that raised an exception.

Channel: Microsoft-Windows-Application Server-Applications/Operational

Provider: Microsoft-Windows-Application Server-Applications

Event ids: 57397, 57405, 57408

Where to look next:

  • Compare exception families with the application's request records.

Fields it can set: win.eventlog.apps.app_domain, win.eventlog.apps.exception_type

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.