Skip to main content

Windows management event channels

42channels
20curated reasons
3themes fed
Livestatus

Scheduled and remote management, servicing, backup, virtualization and print channels, bound as one feed: Task Scheduler, WMI, WinRM, Windows Update, BITS, VSS, Hyper-V, MDM and provisioning, Server Manager, printing, licensing. Unread channels keep the severity the provider stated, capped at Warning. Measured clockwork telemetry is dropped by provider and event id. Twenty curated reasons over scheduled tasks, Windows Update, DFS Replication, printing, device management, locale and Hyper-V, plus a pinned band for every measured no-reason family.

Feed id: win.eventlog.management.

Channels​

This feed binds 42 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
DFS Replicationdirectory_services
Microsoft-Client-Licensing-Platform/Adminlicensing
Microsoft-Windows-Bits-Client/Operationalpatching
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admindevice_management
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Autopilotdevice_management
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Enrollmentdevice_management
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Operationaldevice_management
Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Syncdevice_management
Microsoft-Windows-FileShareShadowCopyProvider/Operationalbackup
Microsoft-Windows-HostGuardianService-Client/Operationalvirtualization
Microsoft-Windows-Hyper-V-Compute-Adminvirtualization
Microsoft-Windows-Hyper-V-Compute-Operationalvirtualization
Microsoft-Windows-Hyper-V-Hypervisor-Adminvirtualization
Microsoft-Windows-Hyper-V-Hypervisor-Operationalvirtualization
Microsoft-Windows-Hyper-V-StorageVSP-Adminvirtualization
Microsoft-Windows-Hyper-V-VMMS-Adminvirtualization
Microsoft-Windows-Hyper-V-VMMS-Networkingvirtualization
Microsoft-Windows-Hyper-V-VMMS-Operationalvirtualization
Microsoft-Windows-Hyper-V-Worker-Adminvirtualization
Microsoft-Windows-Hyper-V-Worker-Operationalvirtualization
Microsoft-Windows-International/Operationaluser_profiles
Microsoft-Windows-LanguagePackSetup/Operationalpatching
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Admindevice_management
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Autopilotdevice_management
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/Diagnosticsdevice_management
Microsoft-Windows-ModernDeployment-Diagnostics-Provider/ManagementServicedevice_management
Microsoft-Windows-MUI/Operationalpatching
Microsoft-Windows-PrintBRM/Adminprinting
Microsoft-Windows-PrintService/Adminprinting
Microsoft-Windows-PrintService/Operational (disabled by default on client Windows; enable it on the host to produce data)printing
Microsoft-Windows-Provisioning-Diagnostics-Provider/Admindevice_management
Microsoft-Windows-Provisioning-Diagnostics-Provider/AutoPilotdevice_management
Microsoft-Windows-Provisioning-Diagnostics-Provider/ManagementServicedevice_management
Microsoft-Windows-Security-SPP-UX-Notifications/ActionCenterlicensing
Microsoft-Windows-ServerManager-DeploymentProvider/Operationalpatching
Microsoft-Windows-ServerManager-MgmtProvider/Operational
Microsoft-Windows-TaskScheduler/Operationalscheduled_tasks
Microsoft-Windows-VHDMP-Operationalvirtualization
Microsoft-Windows-VolumeSnapshot-Driver/Operationalbackup
Microsoft-Windows-WindowsUpdateClient/Operationalpatching
Microsoft-Windows-WinRM/Operationalrmm
Microsoft-Windows-WMI-Activity/Operationalrmm

Fields​

FieldTypeUnitMeaning
win.eventlog.management.job_namestringBITS transfer job display name from Bits-Client 61 (name), e.g. the update-download job a servicing client created. The recurrence pivot for a transfer that keeps failing.
win.eventlog.management.task_namestringScheduled task path from the Task Scheduler failure ids (TaskName), e.g. \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker. The recurrence pivot for one task that keeps failing to start or to load.
win.eventlog.management.task_error_descriptionstringThe internal operation Task Scheduler names beside the failure on ids 104 and 311 (ErrorDescription), e.g. the logon call or the elevation check that returned the code.
win.eventlog.management.task_engine_commandstringHost process Task Scheduler tried to start for a task engine, from TaskScheduler 311 (Command).
win.eventlog.management.update_service_idstringIdentifier of the update service a scan was run against, from WindowsUpdateClient 25 (serviceGuid), casefolded. Separates a local update server from the public update service.
win.eventlog.management.update_titlestringDisplay title of the update whose download failed, from WindowsUpdateClient 31 (updateTitle).
win.eventlog.management.printer_driver_namestringPrinter driver a failed install was for, from the PrintService driver ids (DriverName, Driver or ObjectName). The pivot that collapses one hash per driver name into one group.
win.eventlog.management.driver_install_stagestringStage of the driver install the spooler was in when it failed, from the PrintService driver ids (Label).
win.eventlog.management.driver_install_messagestringThe spooler operation that returned the failure on a driver install, from the PrintService driver ids (Message). Separates a real add or import from a driver-store lookup.
win.eventlog.management.bitlocker_drive_rolestringDrive role a BitLocker compliance check was about, from DeviceManagement 2900 (Message1), e.g. the operating-system volume or a fixed data volume.
win.eventlog.management.bitlocker_fve_statusstringRaw BitLocker status bitmask the device management client reported beside a compliance failure (HexInt1). Promoted undecoded: no published value map was read for it.
win.eventlog.management.bitlocker_method_foundstringEncryption method the operating-system volume is actually using, from DeviceManagement 2902 (HexInt1).
win.eventlog.management.bitlocker_method_wantedstringEncryption method the policy requires for the operating-system volume, from DeviceManagement 2902 (HexInt2).
win.eventlog.management.mdm_csp_uristringConfiguration node a management command was addressed to, from the MDM ConfigurationManager ids (Message5). The pivot that says WHICH setting did not take effect.
win.eventlog.management.mdm_policy_areastringPolicy area a management setting belongs to, from the MDM PolicyManager ids (Message1).
win.eventlog.management.mdm_policy_namestringPolicy setting a management command tried to set, from the MDM PolicyManager ids (Message2).
win.eventlog.management.locale_registry_keystringRegistry key holding the locale settings a process could not read, from International 1001 (RegistryKey). Separates a machine-wide fault from a per-user one.
win.eventlog.management.vm_namestringVirtual machine an event is about, from the Hyper-V ids (VmName). An administrator-chosen machine label and the pivot every virtualization reason here needs.
win.eventlog.management.vm_storage_request_msintMilliseconds one guest storage request took to complete, from Hyper-V-StorageVSP 9 (Duration).
win.eventlog.management.vm_storage_opcodeintSCSI operation code of the guest storage request, from Hyper-V-StorageVSP 9 (Command). Promoted as the number: no constant-name table is claimed for it here.
win.eventlog.management.vm_storage_transfer_bytesintBytes the guest storage request was transferring, from Hyper-V-StorageVSP 9 (DataTransferLength).
win.eventlog.management.vhd_parent_guid_expectedstringParent identity a differencing virtual disk expected, from VHDMP 7 (ExpectedParentLastWriteGUID1).
win.eventlog.management.vhd_parent_guid_actualstringParent identity the parent virtual disk actually carries, from VHDMP 7 (ParentLastWriteGUID). Differs from the expected one when the chain is broken.
win.eventlog.management.replica_retry_minutesintMinutes Hyper-V will wait before retrying replication for a virtual machine, from VMMS 32315 (Parameter0).

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
bitlocker_policy_noncompliantdevice_managementWarning where the operating-system volume is the one out of compliance. Notice for a data volume or where the event cannot say which drive it is about.
bits_transfer_failedpatchingWarning
dfsr_partner_communication_faileddirectory_servicesWarning
dfsr_replication_stoppeddirectory_servicesSerious or Warning
dfsr_sysvol_initial_sync_pendingdirectory_servicesWarning
hyperv_replication_failedvirtualizationWarning or Notice
hyperv_vm_backup_checkpoint_failedvirtualizationWarning, Notice or Info
hyperv_vm_start_failedvirtualizationWarning
hyperv_vm_storage_request_slowvirtualizationWarning for a slow request. Minor where the request took more than thirty seconds.
hyperv_vm_vhd_chain_corruptedvirtualizationSerious or Info
mdm_policy_apply_faileddevice_managementWarning, Notice or Info
patch_download_failedpatchingWarning
patch_scan_failedpatchingWarning or Info
print_connection_reopen_failedprintingWarning or Info
printer_driver_install_failedprintingWarning where an add or an import failed. Notice where the spooler was only asking the driver store whether it already held the driver.
scheduled_task_engine_failedscheduled_tasksWarning or Info
scheduled_task_load_failedscheduled_tasksWarning
scheduled_task_sign_in_failedscheduled_tasksWarning
scheduled_task_start_failedscheduled_tasksWarning where a named automation stopped running. Lower where the task ships with Windows and the program it points at was removed by Windows.
win_locale_registry_read_faileduser_profilesWarning

bitlocker_policy_noncompliant​

A device does not match the BitLocker encryption policy set for it: a drive is unencrypted, or encrypted with a method or scope the policy does not allow.

Severity: Warning where the operating-system volume is the one out of compliance. Notice for a data volume or where the event cannot say which drive it is about.

Impact: An unencrypted operating-system volume means every file on the machine is readable to anyone who takes it.

Channel: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin

Provider: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider

Event ids: 2900, 2902, 2903, 2905, 2906, 2910, 2914

Where to look next:

  • Read the drive role first, then the drive status bits.
  • Two of these event ids cannot say which drive they are about. Pair them with the device's own encryption state.
  • This repeats at the management sync cadence, so one device produces many records for one finding.

Related reasons:

Fields it can set: win.eventlog.management.bitlocker_drive_role, win.eventlog.management.bitlocker_fve_status, win.eventlog.management.bitlocker_method_found, win.eventlog.management.bitlocker_method_wanted

The management client is the authority on what the policy requires. The device's own state reading says what the volume is, without knowing the policy.

bits_transfer_failed​

A Background Intelligent Transfer Service job reported an error on one transfer attempt.

Severity: Warning

Channel: Microsoft-Windows-Bits-Client/Operational

Provider: Microsoft-Windows-Bits-Client

Event ids: 61

Where to look next:

  • Pivot on the job name and the result code to find a destination or a code that keeps repeating.
  • For an update download, read the outcome from the Windows Update records in the Setup channel.

Related reasons:

Fields it can set: win.eventlog.management.job_name

BITS retries a failed transfer, so these records come in runs. The stream is rate-bounded: one record per job and result code per device per hour, with the count of what an hour suppressed carried on the next hour's first record. A job and code that reappear hour after hour, with no completed transfer between them, is the shape worth reading.

dfsr_partner_communication_failed​

DFS Replication could not reach a replication partner for a replication group.

Severity: Warning

Impact: Content does not converge with that partner while the link is down.

Channel: DFS Replication

Provider: DFSR

Event ids: 5002, 5008, 5012, 5014

Where to look next:

  • Read the rate against the service's own reconnection records on the same host.
  • A link that flaps and recovers is ordinary on a wide-area connection.

Related reasons:

The partner and the replication group are named in the message text rather than in fields, because these events carry no named payload.

dfsr_replication_stopped​

DFS Replication stopped replicating a folder or a volume, or stopped because it could not read its own configuration.

Severity: Serious or Warning

Impact: Every member of that replication group keeps serving its own copy, and the copies diverge with nothing visible to the people using them.

Channel: DFS Replication

Provider: DFSR

Event ids: 1202, 2004, 2104, 4004, 4012

CaseSeverityTicket classEvent ids
offline_too_longSeriousdirectory_services4012
folder_stoppedSeriousdirectory_services2004, 2104, 4004
config_unreachableWarningdirectory_services1202

Where to look next:

  • The offline-too-long case needs a deliberate resume. It will not restart by itself.
  • A database recovery failure on a volume needs the replication database rebuilt.
  • Check the folder's other members before resuming, so the copy that wins is the one you want.

Related reasons:

The replicated folder, the partner and the directory server are named in the message text rather than in fields, because these events carry no named payload.

dfsr_sysvol_initial_sync_pending​

A server holds a SYSVOL copy that has never completed its first synchronisation with a partner.

Severity: Warning

Impact: Policy and logon scripts are not served from that copy, and a domain controller promotion that was in progress has not finished.

Channel: DFS Replication

Provider: DFSR

Event ids: 4612, 4614

Where to look next:

  • Check whether the named partner is reachable and replicating.
  • This does not resolve on its own if the partner never answers.

Related reasons:

The partner and the local path are named in the message text rather than in fields, because these events carry no named payload.

hyperv_replication_failed​

Hyper-V could not replicate a virtual machine to its replica server.

Severity: Warning or Notice

Impact: The recovery copy of that machine stops being updated and gets older, with nothing visible to anyone using the machine.

Channel: Microsoft-Windows-Hyper-V-VMMS-Admin

Provider: Microsoft-Windows-Hyper-V-VMMS

Event ids: 29292, 29312, 32022, 32315, 32552, 33676

CaseSeverityTicket classEvent ids
retryingWarningvirtualization32315
unreachableWarningvirtualization29292, 29312, 32022, 32552
state_conflictNoticevirtualization33676

Where to look next:

  • Check whether the replica server is reachable at all: the server and port are named in the message text.
  • A stated retry means the host will try again on its own. Repeated unreachable records are the ones that matter.

Related reasons:

Fields it can set: win.eventlog.management.replica_retry_minutes, win.eventlog.management.vm_name

The machine keeps running throughout, so nobody finds out the copy is stale until they need it.

hyperv_vm_backup_checkpoint_failed​

A backup of a virtual machine did not take a consistent snapshot.

Severity: Warning, Notice or Info

Impact: The backup either did not run or ran without being application-consistent, so the restore point it produced is weaker than it looks.

Channel: Microsoft-Windows-Hyper-V-VMMS-Admin, Microsoft-Windows-Hyper-V-Worker-Admin

Provider: Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker, Microsoft-Windows-Hyper-V-Integration

Event ids: 3280, 4093, 10150, 10172, 18012

CaseSeverityTicket class
serialisation_waitInfovirtualization
checkpoint_failedWarningvirtualization
guest_writer_failedWarningvirtualization
integration_service_disabledNoticevirtualization

Where to look next:

  • Read the result code: a snapshot set already in progress is two jobs overlapping and is fixed by scheduling.
  • A file-already-exists result is a stale checkpoint file left behind by an earlier failure.
  • The integration-service line is a per-machine setting rather than a failure of this run.

Related reasons:

Fields it can set: win.eventlog.management.vm_name

A failed guest writer still usually leaves a crash-consistent copy, which is not the same as no backup at all.

hyperv_vm_start_failed​

A virtual machine, or the worker process that runs one, did not start.

Severity: Warning

Impact: A workload that was supposed to be running is not, and on the memory ids the host did not have room for it.

Channel: Microsoft-Windows-Hyper-V-VMMS-Admin, Microsoft-Windows-Hyper-V-Worker-Admin

Provider: Microsoft-Windows-Hyper-V-VMMS, Microsoft-Windows-Hyper-V-Worker

Event ids: 3050, 3122, 15130, 15500

Where to look next:

  • Check the host's free memory when the worker ids are the ones reporting.
  • The machine name is the pivot: one machine failing every start is a different ticket from a host that is full.

Related reasons:

Fields it can set: win.eventlog.management.vm_name

These templates carry no result code, so the machine name and the id are what the row offers.

hyperv_vm_storage_request_slow​

A storage request a virtualization host made for one of its guests took longer than expected to complete.

Severity: Warning for a slow request. Minor where the request took more than thirty seconds.

Impact: Every guest on that host shares the same storage path, so a steady rate of these degrades all of them.

Channel: Microsoft-Windows-Hyper-V-StorageVSP-Admin

Provider: Microsoft-Windows-Hyper-V-StorageVSP

Event ids: 9

Where to look next:

  • Read the rate before the duration: one slow request is a flake.
  • The virtual disk the request was against is named in the message text.

Related reasons:

Fields it can set: win.eventlog.management.vm_storage_opcode, win.eventlog.management.vm_storage_request_ms, win.eventlog.management.vm_storage_transfer_bytes

The duration measures one request rather than how long a condition has held.

hyperv_vm_vhd_chain_corrupted​

A differencing virtual disk and its parent disagree on the parent identity, so the disk chain cannot be merged or checkpointed.

Severity: Serious or Info

Impact: Checkpoints and backups of that machine are not usable, and the chain grows while the merge keeps failing.

Channel: Microsoft-Windows-VHDMP-Operational, Microsoft-Windows-Hyper-V-VMMS-Admin

Provider: Microsoft-Windows-VHDMP, Microsoft-Windows-Hyper-V-VMMS

Event ids: 7, 16370, 19100

CaseSeverityTicket class
chain_brokenSeriousvirtualization
file_in_useInfovirtualization

Where to look next:

  • Stop taking checkpoints of that machine and repair the chain before anything merges it.
  • Watch the volume the chain lives on: a merge that keeps failing is how it fills.

Related reasons:

Fields it can set: win.eventlog.management.vhd_parent_guid_actual, win.eventlog.management.vhd_parent_guid_expected, win.eventlog.management.vm_name

The machine keeps running while this holds, so nothing else reports it until a restore is attempted.

mdm_policy_apply_failed​

A device management command did not take effect on the device.

Severity: Warning, Notice or Info

Impact: A setting the MSP believes is enforced is not enforced, and the management console will not say so.

Channel: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Admin, Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Sync, Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider/Enrollment

Provider: Microsoft-Windows-DeviceManagement-Enterprise-Diagnostics-Provider

Event ids: 201, 404, 454, 806, 821, 4022

CaseSeverityTicket class
node_absentInfodevice_management
throttledInfodevice_management
access_deniedWarningdevice_management
other_resultNoticedevice_management

Where to look next:

  • Read the status word before the wording: two of the common outcomes here are not failures.
  • On a refusal, the configuration node path and the policy name say which setting is missing.

Related reasons:

Fields it can set: win.eventlog.management.mdm_csp_uri, win.eventlog.management.mdm_policy_area, win.eventlog.management.mdm_policy_name

This family repeats at the management sync cadence, so one unresolved setting produces many records.

patch_download_failed​

Windows Update could not download an update the device needed.

Severity: Warning

Impact: That update is not installed and will not be until a later attempt succeeds.

Channel: Microsoft-Windows-WindowsUpdateClient/Operational

Provider: Microsoft-Windows-WindowsUpdateClient

Event ids: 31

Where to look next:

  • Read the code beside the update title: disk space and memory are the usual causes.
  • A device failing every download is a different ticket from one that cannot reach the service.

Related reasons:

  • patch_scan_failed: The device could not find out what it needed in the first place.

Fields it can set: win.eventlog.management.update_title

The client retries on its own cycle, so a single record is not proof the update is stuck.

patch_scan_failed​

A Windows Update scan did not complete, so the device was offered no updates on that cycle.

Severity: Warning or Info

Impact: A device that keeps failing its scans stops being patched, with no symptom a user would notice.

Channel: Microsoft-Windows-WindowsUpdateClient/Operational

Provider: Microsoft-Windows-WindowsUpdateClient

Event ids: 25

CaseSeverityTicket class
service_unreachableWarningpatching
bad_criteriaInfopatching
other_failureWarningpatching

Where to look next:

  • Read the code and the update service identifier together: they separate an unreachable service from a caller defect.
  • The rate matters more than one record: a host failing every cycle is the ticket.

Related reasons:

Fields it can set: win.eventlog.management.update_service_id

The update client retries on its own cycle, so single records are expected on a healthy device.

The print spooler could not read one profile's saved printer connections when it restarted.

Severity: Warning or Info

Impact: On a real user's profile, their mapped printers are gone until they reconnect or sign in again.

Channel: Microsoft-Windows-PrintService/Operational

Provider: Microsoft-Windows-PrintService

Event ids: 603

CaseSeverityTicket class
user_profileWarningprinting
service_profileInfoprinting

Where to look next:

  • The same user on the same host at every spooler restart is the signal, rather than a single record.

Related reasons:

Built-in service accounts produce this line as a matter of course, because they have no printer connections saved.

printer_driver_install_failed​

A printer driver did not install, and the stage and code say which part of the install failed.

Severity: Warning where an add or an import failed. Notice where the spooler was only asking the driver store whether it already held the driver.

Impact: The print queue that needed the driver does not work, and on a print server that affects everyone who prints to it.

Channel: Microsoft-Windows-PrintService/Admin, Microsoft-Windows-PrintService/Operational

Provider: Microsoft-Windows-PrintService

Event ids: 213, 215, 217, 219, 225, 600, 601, 869

Where to look next:

  • Read the stage and the operation name first, then the code.
  • An access-denied result is a permissions problem on the driver store. A rejected signature is a driver the machine will not accept at all.
  • Pivot on the driver name to tell one broken driver from a broken deployment.

Related reasons:

Fields it can set: win.eventlog.management.driver_install_message, win.eventlog.management.driver_install_stage, win.eventlog.management.printer_driver_name

One install attempt can report from several of these ids, on both print channels.

scheduled_task_engine_failed​

Task Scheduler could not start the host process a scheduled task runs inside.

Severity: Warning or Info

Impact: Where the cause is not an absent session, nothing scheduled runs on that machine while it holds.

Channel: Microsoft-Windows-TaskScheduler/Operational

Provider: Microsoft-Windows-TaskScheduler

Event ids: 311

CaseSeverityTicket class
no_user_sessionInfoscheduled_tasks
engine_unavailableWarningscheduled_tasks

Where to look next:

  • Read the result code before the wording: a not-logged-on code means a per-user engine had no session to start in.
  • Any other cause is worth checking against whether the machine's other scheduled work is running.

Related reasons:

Fields it can set: win.eventlog.management.task_engine_command, win.eventlog.management.task_error_description

A per-user task engine only starts when that user has a session, so this line is expected on a machine nobody is signed in to.

scheduled_task_load_failed​

A scheduled task definition could not be read at service start, so the task is not in the schedule at all.

Severity: Warning

Impact: The task is gone rather than failing, so nothing else reports that its work has stopped.

Channel: Microsoft-Windows-TaskScheduler/Operational

Provider: Microsoft-Windows-TaskScheduler

Event ids: 146, 151

Where to look next:

  • Re-register the task from source.
  • Check the other tasks registered by the same tool, which often go together.

Related reasons:

Fields it can set: win.eventlog.management.task_name

The two event ids report one load attempt twice, so they arrive as a pair for the same task.

scheduled_task_sign_in_failed​

Task Scheduler could not log on as the account a scheduled task stores, so the task did not run.

Severity: Warning

Impact: Every task registered to that account is in the same state, and none of them is running.

Channel: Microsoft-Windows-TaskScheduler/Operational

Provider: Microsoft-Windows-TaskScheduler

Event ids: 104

Where to look next:

  • Re-register the task with a current credential.
  • Pivot on the account rather than the task: one changed password stops every task that stores it.

Related reasons:

Fields it can set: win.eventlog.management.task_error_description

A service-account password change is the usual cause, and the tasks stop silently.

scheduled_task_start_failed​

A scheduled task did not run, and the result code says whether the program was missing, the identity was refused, or the action itself failed.

Severity: Warning where a named automation stopped running. Lower where the task ships with Windows and the program it points at was removed by Windows.

Impact: Whatever that task does is not being done. On a backup pre-job or a patch orchestration task, that is a gap nothing else reports.

Channel: Microsoft-Windows-TaskScheduler/Operational

Provider: Microsoft-Windows-TaskScheduler

Event ids: 101, 103, 202, 203

CaseSeverityTicket class
missing_actionDebug to Warningscheduled_tasks
access_deniedWarningscheduled_tasks
other_failureWarningscheduled_tasks

Where to look next:

  • Read the result code first, then the task path.
  • A missing program on a management, backup or patch task is a broken automation nobody will notice any other way.
  • Pivot on the task path to see whether one task fails every time it is triggered.

Related reasons:

Fields it can set: win.eventlog.management.task_name

The four event ids report one launch from four places, so a single failed run can produce more than one of them.

win_locale_registry_read_failed​

A process could not open the registry key holding the machine or user locale settings, and fell back to a default.

Severity: Warning

Impact: Nothing is unavailable while this fires. It points at profile or permission damage on that host.

Channel: Microsoft-Windows-International/Operational

Provider: Microsoft-Windows-International

Event ids: 1001

Where to look next:

  • Read the registry key path: it separates a machine-wide fault from one user's profile.
  • The rate is the whole signal, since one process in a loop produces thousands of records.

Related reasons:

Fields it can set: win.eventlog.management.locale_registry_key

The calling process continues with a default locale, so this is evidence of damage rather than an outage.

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.