Windows application platform event channels
Application platform and user shell channels, bound as one feed: packaged-app deployment and readiness, the shell and modern app launch surface, application compatibility, Windows Error Reporting health, and Office alert dialogs. Curated failure, cleanup, and lifecycle records retain a Warning ceiling for unmatched events.
Feed id: win.eventlog.apps.
Channels
This feed binds 25 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
Microsoft-Windows-AppID/Operational | security_audit |
Microsoft-Windows-Application Server-Applications/Operational | app_stability |
Microsoft-Windows-Application-Experience/Program-Inventory | inventory |
Microsoft-Windows-ApplicationResourceManagementSystem/Operational | app_stability |
Microsoft-Windows-AppModel-Runtime/Admin | app_stability |
Microsoft-Windows-AppReadiness/Admin | app_stability |
Microsoft-Windows-AppReadiness/Operational | app_stability |
Microsoft-Windows-AppXDeployment-Server/Operational | patching |
Microsoft-Windows-AppXDeployment/Operational | patching |
Microsoft-Windows-AppXDeploymentServer/Operational | patching |
Microsoft-Windows-AppXDeploymentServer/Restricted | patching |
Microsoft-Windows-AppxPackaging/Operational | patching |
Microsoft-Windows-Containers-BindFlt/Operational | app_stability |
Microsoft-Windows-Containers-Wcifs/Operational | app_stability |
Microsoft-Windows-CoreApplication/Operational | app_stability |
Microsoft-Windows-Diagnosis-PCW/Operational | app_stability |
Microsoft-Windows-Fault-Tolerant-Heap/Operational | app_stability |
Microsoft-Windows-Kernel-ShimEngine/Operational | app_stability |
Microsoft-Windows-Shell-Core/Operational | app_stability |
Microsoft-Windows-TWinUI/Operational | app_stability |
Microsoft-Windows-UAC-FileVirtualization/Operational | app_stability |
Microsoft-Windows-WER-Diag/Operational | app_stability |
Microsoft-Windows-WER-PayloadHealth/Operational | app_stability |
OAlerts | app_stability |
OSession | app_stability |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.apps.appx_package_full_name | string | Full packaged-application identity reported by deployment, readiness, or runtime records. | |
win.eventlog.apps.appx_package_family_name | string | Package family identity reported by the shell or application runtime. | |
win.eventlog.apps.appx_operation | string | Deployment or readiness operation as the provider wrote it. Numeric deployment values remain raw. | |
win.eventlog.apps.appx_deployment_operation | int | Raw AppX DeploymentOperation integer. No local name map is inferred. | |
win.eventlog.apps.appx_requeue_reason | string | Reason the deployment provider gives for putting an attempt back on its queue, as written. | |
win.eventlog.apps.appx_calling_process | string | Process label the deployment provider reports as the caller. | |
win.eventlog.apps.appx_package_type | string | Package type reported by the deployment provider. | |
win.eventlog.apps.appx_cleanup_error_count | int | Number of package files a cleanup summary says remain. | |
win.eventlog.apps.appx_cleanup_registry_key | string | Registry key name a package cleanup record could not remove. | |
win.eventlog.apps.appx_app_id | string | Packaged-application identity reported by an activation record. | |
win.eventlog.apps.appx_activation_phase | string | Activation phase flags as the provider wrote them. | |
win.eventlog.apps.appx_contract_id | string | Application contract the shell attempted to activate. | |
win.eventlog.apps.appx_service_name | string | Packaged-application service the deployment client tried to start. | |
win.eventlog.apps.perf_counter_set_guid | string | Counter-set identifier whose provider registration failed. | |
win.eventlog.apps.perf_provider_guid | string | Performance-counter provider identifier that failed to register. | |
win.eventlog.apps.perf_counter_id | int | Performance-counter identifier reported by the provider. | |
win.eventlog.apps.app_domain | string | Hosted application domain that raised a request exception. | |
win.eventlog.apps.exception_type | string | Framework exception type parsed from the provider exception detail. |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
appid_certificate_store_verification_failed | security_audit | Debug |
appid_certificate_store_verified | security_audit | Info |
appx_activation_failed | app_stability | Notice or Info |
appx_cleanup_residue | patching | Debug |
appx_deployment_failed | patching | Notice, Info or Verbose |
appx_deployment_requeued | patching | Verbose |
appx_package_runtime_corrupt | app_stability | Warning or Notice |
appx_provisioning_failed | app_stability | Notice or Info |
appx_service_start_failed | patching | Notice or Info |
perf_counter_provider_failed | app_stability | Debug |
wcf_request_failed | app_stability | Minor |
appid_certificate_store_verification_failed
The AppID service reported a certificate-store verification failure.
Severity: Debug
Impact: This is AppID context until AppLocker records establish an enforcement impact.
Channel: Microsoft-Windows-AppID/Operational
Provider: Microsoft-Windows-AppID
Event ids: 4005
Where to look next:
- Compare the result with AppLocker records before treating it as a rule-evaluation failure.
Related reasons:
appid_certificate_store_verified: the same check succeeding, a different factapplocker_audit_would_block: the AppLocker audit record that turns a failed check into an enforcement finding
appid_certificate_store_verified
The AppID service reported a successful certificate-store verification.
Severity: Info
Impact: Retained as context for nearby failures; does not by itself establish enforcement.
Channel: Microsoft-Windows-AppID/Operational
Provider: Microsoft-Windows-AppID
Event ids: 4006
Where to look next:
- Read this as the denominator beside nearby verification failures.
Related reasons:
appid_certificate_store_verification_failed: the same check failing, a different fact
appx_activation_failed
A packaged application did not start.
Also reported by: Windows Application event log
Severity: Notice or Info
Impact: The event describes one application activation attempt.
Channel: Microsoft-Windows-TWinUI/Operational, Microsoft-Windows-AppModel-Runtime/Admin
Provider: Microsoft-Windows-Immersive-Shell, Microsoft-Windows-AppModel-Runtime
Event ids: 4, 5, 18, 20, 21, 22, 26, 27, 31, 32, 35, 36, 38, 65, 66, 67, 69, 202, 203, 207, 208, 212, 215, 216, 2825, 5955, 5961, 5962, 5990
| Case | Severity | Ticket class |
|---|---|---|
administrator_token | Info | app_stability |
activation_timeout | Notice | app_stability |
shell_failure | Notice | app_stability |
runtime_failure | Notice | app_stability |
Where to look next:
- Read the app identity and error code.
- A timeout is not proof that the package is damaged.
Related reasons:
appx_package_runtime_corrupt: a corrupted package runtime record that can stop the app launching
Fields it can set: win.eventlog.apps.appx_activation_phase, win.eventlog.apps.appx_app_id, win.eventlog.apps.appx_contract_id, win.eventlog.apps.appx_package_full_name
appx_cleanup_residue
During package cleanup, Windows could not remove every file or registry entry.
Severity: Debug
Impact: A later cleanup pass may remove the residue.
Channel: Microsoft-Windows-AppXDeploymentServer/Operational
Provider: Microsoft-Windows-AppXDeployment-Server
Event ids: 471, 472, 493, 494, 503, 516, 801, 802, 808, 5224, 5230
| Case | Severity | Ticket class |
|---|---|---|
summary | Debug | patching |
detail | Debug | patching |
registry_absent | Debug | patching |
registry_other | Debug | patching |
Where to look next:
- Use the folder count when disk space is a concern.
- Investigate a rising count or other error codes.
Related reasons:
appx_deployment_failed: the failed operation that can leave files or registry entries behind
Fields it can set: win.eventlog.apps.appx_cleanup_error_count, win.eventlog.apps.appx_cleanup_registry_key
appx_deployment_failed
A packaged-app operation failed for a user on this device.
Severity: Notice, Info or Verbose
Impact: The event records one failed attempt and does not establish how long the package remains unavailable.
Channel: Microsoft-Windows-AppXDeploymentServer/Operational, Microsoft-Windows-AppXDeploymentServer/Restricted, Microsoft-Windows-AppXDeployment-Server/Operational, Microsoft-Windows-Shell-Core/Operational
Provider: Microsoft-Windows-AppXDeployment-Server, Microsoft-Windows-AppXDeployment-Server-UndockedDeh, Microsoft-Windows-Shell-Core
Event ids: 401, 413, 441, 697, 698, 707, 10004, 10005, 10010, 62164
| Case | Severity | Ticket class |
|---|---|---|
packages_in_use | Verbose | patching |
blocked_by_policy | Notice | patching |
other_failure | Info | patching |
Where to look next:
- Read the operation and error code first.
- Pivot on the package across users and hosts.
Related reasons:
appx_cleanup_residue: leftover files or registry entries a failed operation can leaveappx_deployment_requeued: the attempts the service put back on its queue instead of failingappx_service_start_failed: the deployment client outage that blocks operations like this one
Fields it can set: win.eventlog.apps.appx_calling_process, win.eventlog.apps.appx_deployment_operation, win.eventlog.apps.appx_package_family_name, win.eventlog.apps.appx_package_full_name, win.eventlog.apps.appx_package_type, win.eventlog.apps.appx_requeue_reason
appx_deployment_requeued
The deployment service put a packaged-app attempt back on its queue, and the requeue reason says why.
Severity: Verbose
Channel: Microsoft-Windows-AppXDeploymentServer/Operational
Provider: Microsoft-Windows-AppXDeployment-Server
Event ids: 626
Where to look next:
- Read the requeue reason and the operation, then pivot on the package across devices.
- A package family that reappears day after day is a deployment that never completes.
Related reasons:
appx_deployment_failed: the failure records for attempts that did not completeappx_service_start_failed: the deployment client outage that stalls operations like this one
Fields it can set: win.eventlog.apps.appx_calling_process, win.eventlog.apps.appx_deployment_operation, win.eventlog.apps.appx_package_full_name, win.eventlog.apps.appx_requeue_reason
These records are rate-bounded: one per package family per device per day, with the count of what a day suppressed carried on the next day's first record.
appx_package_runtime_corrupt
A package runtime record is corrupted.
Severity: Warning or Notice
Impact: Apps in that package family can fail to launch until the package is repaired.
Channel: Microsoft-Windows-AppModel-Runtime/Admin
Provider: Microsoft-Windows-AppModel-Runtime
Event ids: 79, 80
| Case | Severity | Ticket class |
|---|---|---|
repair_attempted | Notice | app_stability |
repair_unavailable | Warning | app_stability |
Where to look next:
- Check whether a repair-unavailable record follows the repair attempt.
Related reasons:
appx_activation_failed: the launch failure this corrupted record causes
Fields it can set: win.eventlog.apps.appx_package_family_name
appx_provisioning_failed
App Readiness reported a failed packaged-app operation.
Severity: Notice or Info
Impact: The event records one operation and its result.
Channel: Microsoft-Windows-AppReadiness/Admin, Microsoft-Windows-AppReadiness/Operational
Provider: Microsoft-Windows-AppReadiness
Event ids: 10, 11, 214, 215, 218, 304, 319
| Case | Severity | Ticket class |
|---|---|---|
retry_scheduled | Info | app_stability |
packages_in_use | Info | app_stability |
other_failure | Notice | app_stability |
Where to look next:
- Read the operation and result code.
- Pivot on package and user context across hosts.
Related reasons:
appx_service_start_failed: the deployment client outage that blocks provisioning too
Fields it can set: win.eventlog.apps.appx_operation, win.eventlog.apps.appx_package_full_name
appx_service_start_failed
The packaged-app deployment client could not start or reach a service.
Severity: Notice or Info
Impact: Packaged apps may not deploy for that logon.
Channel: Microsoft-Windows-AppXDeployment/Operational
Provider: Microsoft-Windows-AppXDeployment
Event ids: 302, 303, 311, 328
| Case | Severity | Ticket class |
|---|---|---|
shutdown_in_progress | Info | patching |
other_failure | Notice | patching |
Where to look next:
- Read the error code before treating a restart race as a service failure.
Related reasons:
appx_deployment_failed: deployment operations that fail while this client is downappx_provisioning_failed: provisioning attempts that fail for the same reason
Fields it can set: win.eventlog.apps.appx_service_name
perf_counter_provider_failed
A performance-counter provider could not register or create a counter object.
Severity: Debug
Impact: A monitoring tool can miss readings from that provider.
Channel: Microsoft-Windows-Diagnosis-PCW/Operational
Provider: Microsoft-Windows-Diagnosis-PCW
Event ids: 2, 3
| Case | Severity | Ticket class |
|---|---|---|
registration | Debug | app_stability |
instance | Debug | app_stability |
Where to look next:
- Read the counter identifier and error code in the preserved payload.
Fields it can set: win.eventlog.apps.perf_counter_id, win.eventlog.apps.perf_counter_set_guid, win.eventlog.apps.perf_provider_guid
wcf_request_failed
A hosted service reported an exception while processing a request.
Also reported by: Windows Application event log
Severity: Minor
Impact: The record identifies an application request path that raised an exception.
Channel: Microsoft-Windows-Application Server-Applications/Operational
Provider: Microsoft-Windows-Application Server-Applications
Event ids: 57397, 57405, 57408
Where to look next:
- Compare exception families with the application's request records.
Fields it can set: win.eventlog.apps.app_domain, win.eventlog.apps.exception_type
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.