Skip to main content

Windows network event channels

43channels
31curated reasons
3themes fed
Livestatus

Connectivity, name resolution, file sharing and remote access channels, bound as one feed: DHCP, DNS client, WLAN, connectivity probes, the firewall and filtering platform, SMB client and server, RDP and SSH. Reviewed connectivity, sharing, and remote-access failures receive reasons and diagnostic fields. Other events retain the Warning ceiling.

Feed id: win.eventlog.network.

Channels​

This feed binds 43 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
Microsoft-Windows-AllJoyn/Operationalnetworking
Microsoft-Windows-BranchCacheSMB/Operationalfile_sharing
Microsoft-Windows-CloudFiles-Filter/Operationalfile_sync
Microsoft-Windows-CoreSystem-SmsRouter-Events/Operationalnetworking
Microsoft-Windows-Dhcp-Client/Adminnetworking
Microsoft-Windows-Dhcp-Client/Operational (disabled by default on client Windows; enable it on the host to produce data)networking
Microsoft-Windows-Dhcpv6-Client/Adminnetworking
Microsoft-Windows-DNS-Client/Operational (disabled by default on client Windows; enable it on the host to produce data)networking
Microsoft-Windows-EapHost/Operationalauth
Microsoft-Windows-Host-Network-Service-Adminnetworking
Microsoft-Windows-Host-Network-Service-Operationalnetworking
Microsoft-Windows-NcdAutoSetup/Operationalnetworking
Microsoft-Windows-NCSI/Operationalnetworking
Microsoft-Windows-NetworkLocationWizard/Operationalnetworking
Microsoft-Windows-NetworkProfile/Operationalnetworking
Microsoft-Windows-NlaSvc/Operationalnetworking
Microsoft-Windows-OfflineFiles/Operationalfile_sharing
Microsoft-Windows-RemoteAssistance/Operationalremote_access
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Adminremote_access
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operationalremote_access
Microsoft-Windows-RemoteDesktopServices-SessionServices/Operationalremote_access
Microsoft-Windows-SmbClient/Connectivityfile_sharing
Microsoft-Windows-SMBClient/Operationalfile_sharing
Microsoft-Windows-SmbClient/Securityfile_sharing
Microsoft-Windows-SMBServer/Connectivityfile_sharing
Microsoft-Windows-SMBServer/Operationalfile_sharing
Microsoft-Windows-SMBServer/Securityfile_sharing
Microsoft-Windows-TerminalServices-LocalSessionManager/Adminremote_access
Microsoft-Windows-TerminalServices-LocalSessionManager/Operationalremote_access
Microsoft-Windows-TerminalServices-PnPDevices/Adminremote_access
Microsoft-Windows-TerminalServices-Printers/Adminprinting
Microsoft-Windows-TerminalServices-RDPClient/Operationalremote_access
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Adminremote_access
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operationalremote_access
Microsoft-Windows-TerminalServices-ServerUSBDevices/Adminremote_access
Microsoft-Windows-Wcmsvc/Operationalnetworking
Microsoft-Windows-WFP/Operationalnetworking
Microsoft-Windows-Windows Firewall With Advanced Security/Firewallnetworking
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallDiagnosticsnetworking
Microsoft-Windows-WinINet-Config/ProxyConfigChangednetworking
Microsoft-Windows-WLAN-AutoConfig/Operationalnetworking
OpenSSH/Adminremote_access
OpenSSH/Operationalremote_access

Fields​

FieldTypeUnitMeaning
win.eventlog.network.dns_query_namestringDNS query name from a client resolution timeout.
win.eventlog.network.firewall_rule_actionintFirewall rule action code from the dedicated channel.
win.eventlog.network.firewall_rule_directionintFirewall rule direction code.
win.eventlog.network.firewall_rule_originintFirewall rule origin code.
win.eventlog.network.firewall_rule_profilesintFirewall rule profile bitmask.
win.eventlog.network.offline_files_failed_countintOffline-files sync failure count.
win.eventlog.network.offline_files_pathstringOffline-files scope path.
win.eventlog.network.printer_namestringRedirected printer name from RDS setup.
win.eventlog.network.rule_idstringFirewall rule identifier.
win.eventlog.network.rule_namestringFirewall rule label.
win.eventlog.network.smb_auth_protocol_newintSMB authentication protocol after re-auth.
win.eventlog.network.smb_auth_protocol_oldintSMB authentication protocol before re-auth.
win.eventlog.network.smb_call_duration_secsintSMB security call duration in seconds.
win.eventlog.network.smb_call_functionstringSMB security function that ran slow.
win.eventlog.network.smb_call_threshold_secsintSMB security call threshold in seconds.
win.eventlog.network.smb_commandintSMB2 command number.
win.eventlog.network.smb_connection_typeintSMB connection type code.
win.eventlog.network.smb_durable_handleboolWhether the SMB handle was durable.
win.eventlog.network.smb_elapsed_msintSMB operation elapsed milliseconds.
win.eventlog.network.smb_encryption_usedboolWhether SMB encryption was used.
win.eventlog.network.smb_granted_accessstringSMB granted access mask.
win.eventlog.network.smb_logon_idstringSMB logon identifier.
win.eventlog.network.smb_mapped_accessstringSMB mapped access mask.
win.eventlog.network.smb_message_idintSMB message identifier.
win.eventlog.network.smb_mutual_auth_lostboolWhether mutual authentication was lost.
win.eventlog.network.smb_ntlm_blockedboolWhether NTLM was blocked on the connection.
win.eventlog.network.smb_operation_durationintSMB server operation duration.
win.eventlog.network.smb_operation_thresholdintSMB server operation threshold.
win.eventlog.network.smb_persistent_handleboolWhether the SMB handle was persistent.
win.eventlog.network.smb_reason_codeintSMB provider reason code.
win.eventlog.network.smb_resilient_handleboolWhether the SMB handle was resilient.
win.eventlog.network.smb_retry_countintSMB retry count.
win.eventlog.network.smb_session_idstringSMB session identifier.
win.eventlog.network.smb_setting_defaultintShipped default for an SMB security setting.
win.eventlog.network.smb_setting_namestringSMB security setting name.
win.eventlog.network.smb_setting_valueintConfigured SMB security setting value.
win.eventlog.network.smb_share_namestringSMB share the event is about: the share segment of a UNC the provider wrote under ServerName, or the ShareName field where the provider states one.
win.eventlog.network.smb_signing_usedboolWhether SMB signing was used.
win.eventlog.network.smb_spn_validation_policyintSMB SPN validation policy code.
win.eventlog.network.smb_tree_idintSMB tree connection identifier.
win.eventlog.network.wlan_adapterstringWireless adapter description.
win.eventlog.network.wlan_bss_typestringWireless BSS type.
win.eventlog.network.wlan_connection_modestringWireless connection mode.
win.eventlog.network.wlan_failure_reasonstringWireless failure reason sentence.
win.eventlog.network.wlan_profile_namestringWireless profile name.
win.eventlog.network.wlan_reason_codeintWireless reason code.
win.eventlog.network.wlan_reason_textstringWireless security reason text.

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
dhcp_address_conflict_detectednetworkingWarning
dhcp_lease_deniednetworkingWarning
dhcp_lease_failednetworkingWarning
dns_client_resolution_timed_outnetworkingWarning
firewall_rule_changednetworkingNotice
firewall_rule_creatednetworkingNotice
firewall_rule_deletednetworkingNotice
offline_files_slow_link_transition_blockedfile_sharingWarning
offline_files_sync_failedfile_sharingWarning
rds_redirected_printer_setup_failedprintingWarning
smb_anonymous_access_deniedfile_sharingNotice
smb_anonymous_access_enabledfile_sharingNotice
smb_client_auth_context_failedfile_sharingWarning
smb_client_mutual_auth_lostfile_sharingWarning
smb_client_security_call_slowfile_sharingNotice
smb_connect_failedfile_sharingWarning
smb_insecure_guest_allowedfile_sharingWarning
smb_insecure_guest_rejectedfile_sharingWarning
smb_legacy_dialect_rejectedfile_sharingNotice
smb_security_setting_nondefaultfile_sharingNotice
smb_server_name_unresolvedfile_sharingWarning
smb_server_operation_slowfile_sharingNotice
smb_session_auth_failedfile_sharingWarning or Notice
smb_session_lostfile_sharingWarning or Info
smb_session_reopen_failedfile_sharingWarning
smb_share_access_deniedfile_sharingWarning
smb_share_connection_lostfile_sharingWarning or Info
smb_signing_validation_failedfile_sharingWarning
wfp_transaction_watchdog_timeoutnetworkingWarning
wlan_connect_failednetworkingWarning or Info
wlan_security_handshake_failednetworkingWarning

dhcp_address_conflict_detected​

The DHCP client detected an address conflict.

Severity: Warning

Impact: Connectivity may flap until the conflict is resolved.

Channel: Microsoft-Windows-Dhcp-Client/Admin

Provider: Microsoft-Windows-Dhcp-Client

Event ids: 1004

Where to look next:

  • Take no action on a single conflict: the client requests a new address on its own.
  • Repeated conflicts on one subnet point at the DHCP scope or the lease period, not at the client.

Related reasons:

  • dhcp_lease_failed: the lease failure that can follow an unresolved address conflict

dhcp_lease_denied​

The DHCP server denied a lease request.

Severity: Warning

Impact: The host stays unaddressed until policy or server configuration changes.

Channel: Microsoft-Windows-Dhcp-Client/Admin

Provider: Microsoft-Windows-Dhcp-Client

Event ids: 1002

Where to look next:

  • Take no action on an isolated denial: the client asks for a new address on its own, and ipconfig /release then /renew retries immediately instead of waiting for that.
  • A run of denials means the address is no longer valid in the scope; check the scope and lease period on the DHCP server.

Related reasons:

dhcp_lease_failed​

The DHCP client could not obtain a lease.

Severity: Warning

Impact: The host may have no IPv4 address until DHCP succeeds.

Channel: Microsoft-Windows-Dhcp-Client/Admin

Provider: Microsoft-Windows-Dhcp-Client

Event ids: 1001, 1003

Related reasons:

dns_client_resolution_timed_out​

A DNS client query timed out.

Severity: Warning

Impact: Name-dependent services fail until resolution succeeds.

Channel: Microsoft-Windows-DNS-Client/Operational

Provider: Microsoft-Windows-DNS-Client

Event ids: 1013, 1015

Where to look next:

  • Read this as unreachable DNS servers, not a missing record: a negative answer stops the client without a timeout.
  • The client works through the servers configured on the adapter on one short fixed budget, so how many are listed and in what order decides whether a reachable one is reached before it gives up; put a reachable server first. The reference below carries the current timings.

Related reasons:

Fields it can set: win.eventlog.network.dns_query_name

firewall_rule_changed​

The Windows Firewall service reported that a rule was modified. The payload identifies the rule and selected properties.

Also reported by: Windows Security event log

Severity: Notice

Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.

Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

Provider: Microsoft-Windows-Windows Firewall With Advanced Security

Event ids: 2005, 2099

Where to look next:

  • Use the event to identify the rule change and its actor or source where available.
  • Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.

Related reasons:

Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name

firewall_rule_created​

The Windows Firewall service reported that a rule was added. The payload identifies the rule and selected properties.

Also reported by: Windows Security event log

Severity: Notice

Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.

Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

Provider: Microsoft-Windows-Windows Firewall With Advanced Security

Event ids: 2004, 2097

Where to look next:

  • Use the event to identify the rule change and its actor or source where available.
  • Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.

Related reasons:

Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name

firewall_rule_deleted​

The Windows Firewall service reported that a rule was deleted. The payload identifies the rule and selected properties.

Also reported by: Windows Security event log

Severity: Notice

Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.

Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall

Provider: Microsoft-Windows-Windows Firewall With Advanced Security

Event ids: 2006, 2052

Where to look next:

  • Use the event to identify the rule change and its actor or source where available.
  • Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.

Related reasons:

Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name

Offline Files could not change sync mode for a slow link.

Severity: Warning

Impact: The folder stays in its prior mode until policy or connectivity allows the transition.

Channel: Microsoft-Windows-OfflineFiles/Operational

Provider: Microsoft-Windows-OfflineFiles

Event ids: 1008

Where to look next:

  • Check the Configure slow-link mode policy before treating this as a fault: a latency threshold of 1 ms is Always Offline mode, where no transition to online is expected.
  • Where Always Offline is not intended, the folder in the promoted path is waiting on link latency against whatever threshold that policy sets.

Related reasons:

Fields it can set: win.eventlog.network.offline_files_path

offline_files_sync_failed​

Offline Files background synchronization failed.

Severity: Warning

Impact: Redirected folders may be stale until sync succeeds.

Channel: Microsoft-Windows-OfflineFiles/Operational

Provider: Microsoft-Windows-OfflineFiles

Event ids: 1006

Related reasons:

Fields it can set: win.eventlog.network.offline_files_failed_count, win.eventlog.network.offline_files_path

rds_redirected_printer_setup_failed​

RDS redirected printer setup failed.

Severity: Warning

Impact: Session printing may be unavailable until setup succeeds.

Channel: Microsoft-Windows-TerminalServices-Printers/Admin

Provider: Microsoft-Windows-TerminalServices-Printers

Event ids: 1108, 1109

CaseSeverityTicket class
default_not_setWarningprinting
config_not_restoredWarningprinting

Where to look next:

  • Take no action on the configuration-not-restored arm: Windows applies the default configuration when the queue is created.
  • On the default-not-set arm, expect it on sessions with more than one redirected queue after a reconnect, where the spooler did not enumerate a disconnected queue.
  • Where the queue itself is missing rather than misconfigured, check whether Easy Print is disabled, which makes the host require a matching driver for the promoted printer name.

Related reasons:

Fields it can set: win.eventlog.network.printer_name

smb_anonymous_access_denied​

This server refused anonymous access at the share or server scope.

Severity: Notice

Impact: The refusal is expected when anonymous access is disabled.

Channel: Microsoft-Windows-SMBServer/Security

Provider: Microsoft-Windows-SMBServer

Event ids: 1007, 1009

CaseSeverityTicket class
shareNoticefile_sharing
serverNoticefile_sharing

Related reasons:

Fields it can set: win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name

smb_anonymous_access_enabled​

The server reported that one or more named pipes or shares are marked for anonymous access. The event does not identify the resource or prove that a remote client can reach it.

Severity: Notice

Impact: This is a posture finding. Confirm the affected resources and the intended access path before treating it as an exposure.

Channel: Microsoft-Windows-SMBServer/Operational

Provider: Microsoft-Windows-SMBServer

Event ids: 1025

Where to look next:

  • List the server's named pipes and shares, then check which are marked for anonymous access.
  • Test the intended access path separately.
  • Where the setting is deliberate, record why; where it is not, remove it.

Related reasons:

smb_client_auth_context_failed​

The SMB client could not build an authentication context for a server.

Severity: Warning

Impact: The user cannot open resources on that server until credentials or domain reachability recover.

Channel: Microsoft-Windows-SmbClient/Security, Microsoft-Windows-SmbClient/Connectivity

Provider: Microsoft-Windows-SmbClient

Event ids: 30801, 31000, 31001, 31002

CaseSeverityTicket class
no_authorityWarningfile_sharing
wrong_principalWarningfile_sharing
logon_deniedWarningfile_sharing
otherWarningfile_sharing

Where to look next:

  • On the wrong-principal arm, check whether the promoted server name is a CNAME alias: the server needs an SPN registered for the alias it is reached by.
  • Where the alias SPN is correct and the failure persists, check SMB server name hardening on the server (SmbServerNameHardeningLevel).
  • On the no-authority arm, connect by the server's Kerberos-capable FQDN rather than an IP address or workgroup name, and confirm the client can reach a domain controller.

Related reasons:

Fields it can set: win.eventlog.network.smb_logon_id, win.eventlog.network.smb_reason_code

smb_client_mutual_auth_lost​

SMB mutual authentication was lost after the client re-authenticated.

Severity: Warning

Impact: The client may continue but without the mutual authentication guarantee.

Channel: Microsoft-Windows-SmbClient/Security

Provider: Microsoft-Windows-SmbClient

Event ids: 31019

Where to look next:

  • Compare the old and new auth protocol ids: a move off Kerberos is what removed the mutual-authentication guarantee.
  • Check how the promoted server name is reached: connecting by IP address or by a CNAME alias makes the client use NTLM instead of Kerberos.

Related reasons:

Fields it can set: win.eventlog.network.smb_auth_protocol_new, win.eventlog.network.smb_auth_protocol_old, win.eventlog.network.smb_mutual_auth_lost

smb_client_security_call_slow​

An SMB client security call exceeded its slow threshold.

Severity: Notice

Impact: Operations may lag until the call completes; nothing failed.

Channel: Microsoft-Windows-SMBClient/Operational

Provider: Microsoft-Windows-SMBClient

Event ids: 30955

Related reasons:

Fields it can set: win.eventlog.network.smb_call_duration_secs, win.eventlog.network.smb_call_function, win.eventlog.network.smb_call_threshold_secs

smb_connect_failed​

An SMB connection attempt failed after the server name resolved.

Severity: Warning

Impact: Applications cannot reach the share or server until connectivity or permissions improve.

Channel: Microsoft-Windows-SmbClient/Connectivity, Microsoft-Windows-SmbClient/Security

Provider: Microsoft-Windows-SmbClient

Event ids: 30803, 30809, 30816, 30823, 31010

CaseSeverityTicket class
timeoutWarningfile_sharing
access_deniedWarningfile_sharing
connection_failedWarningfile_sharing

Where to look next:

  • On the timeout arm, check for a listener on TCP 445 on the named server and that the File and Printer Sharing (SMB-In) rules are enabled; a blocking firewall is the usual cause.
  • Where the firewall looks clean, run a netsh wfp trace during a retry to name the rule or program dropping the traffic.
  • On the access-denied arm, check whether the client now requires SMB signing or blocks NTLM: both became defaults in Windows 11 24H2 and Windows Server 2025 and both deny connections that worked before an upgrade.

Related reasons:

Fields it can set: win.eventlog.network.smb_connection_type, win.eventlog.network.smb_elapsed_ms, win.eventlog.network.smb_reason_code, win.eventlog.network.smb_retry_count, win.eventlog.network.smb_share_name

smb_insecure_guest_allowed​

The SMB client allowed an insecure guest connection.

Severity: Warning

Impact: Traffic to that server may proceed without proving user identity.

Channel: Microsoft-Windows-SmbClient/Security

Provider: Microsoft-Windows-SmbClient

Event ids: 31022

Where to look next:

  • Treat the traffic to the promoted server as unsigned and unencrypted: guest logons support neither, which is what makes them interceptable.
  • Find what set AllowInsecureGuestAuth on this client and give the target real credentials instead; the setting is a temporary workaround, not a configuration to leave in place.

Related reasons:

smb_insecure_guest_rejected​

The SMB client rejected an insecure guest connection.

Severity: Warning

Impact: The share stays unreachable until guest access is allowed or proper credentials are supplied.

Channel: Microsoft-Windows-SmbClient/Security

Provider: Microsoft-Windows-SmbClient

Event ids: 31017

Where to look next:

  • Give the promoted server real credentials: it accepted the client as an unauthenticated guest, and the client refused.
  • Do not re-enable insecure guest logons to clear this; it exposes the client to rogue-server and interception attacks.

Related reasons:

smb_legacy_dialect_rejected​

This server rejected a legacy SMB dialect.

Severity: Notice

Impact: Older clients cannot connect until they negotiate a supported dialect.

Channel: Microsoft-Windows-SMBServer/Operational

Provider: Microsoft-Windows-SMBServer

Event ids: 1001

Where to look next:

  • Read the rejected client name and address from the event: that device, not the server, is the thing to fix.
  • Expect scan-to-share printers and other appliances here; they are the documented casualties of disabling SMB 1.0.
  • Do not re-enable SMB 1.0 to clear this; secure dialect negotiation cannot stop a downgrade to SMB 1.0.

Related reasons:

smb_security_setting_nondefault​

An SMB security setting on this device differs from the Windows default. The payload names the setting and configured value.

Severity: Notice

Impact: The value can strengthen or weaken protection depending on the setting and the direction of the change. The event alone does not classify the change as safer or weaker.

Channel: Microsoft-Windows-SmbClient/Security, Microsoft-Windows-SMBServer/Security

Provider: Microsoft-Windows-SmbClient, Microsoft-Windows-SMBServer

Event ids: 1021, 31003, 31016, 31018

CaseSeverityTicket class
guest_authNoticefile_sharing
lm_compatibilityNoticefile_sharing
signingNoticefile_sharing

Where to look next:

  • Read the setting name, configured value, and stated default.
  • Identify the policy that set it, then interpret the value for that setting.
  • Review guest authentication, compatibility, and signing settings separately.

Related reasons:

Fields it can set: win.eventlog.network.smb_setting_default, win.eventlog.network.smb_setting_name, win.eventlog.network.smb_setting_value

smb_server_name_unresolved​

The SMB client could not resolve a server name.

Severity: Warning

Impact: File shares on that server name stay unreachable until name resolution works.

Channel: Microsoft-Windows-SmbClient/Connectivity

Provider: Microsoft-Windows-SmbClient

Event ids: 30800

Related reasons:

Fields it can set: win.eventlog.network.smb_reason_code

smb_server_operation_slow​

An SMB server operation exceeded its slow threshold.

Severity: Notice

Impact: The operation completed but took longer than the server expected.

Channel: Microsoft-Windows-SMBServer/Operational

Provider: Microsoft-Windows-SMBServer

Event ids: 1020, 1047, 1054

CaseSeverityTicket class
filesystemNoticefile_sharing
networkNoticefile_sharing
session_setupNoticefile_sharing

Where to look next:

  • On the filesystem arm, look at storage rather than SMB: the default threshold is 15 seconds and the server is waiting on the local file system.
  • Check the usual delay sources on that host: file system filter drivers such as antivirus, disk load, and backup or VSS freezes.
  • For extreme delays, check for events 1031 and 1032 on the same host and collect the dump from %SystemRoot%\LiveKernelReports.

Related reasons:

Fields it can set: win.eventlog.network.smb_operation_duration, win.eventlog.network.smb_operation_threshold, win.eventlog.network.smb_share_name

smb_session_auth_failed​

An SMB session authentication attempt on this server failed.

Severity: Warning or Notice

Impact: Clients cannot open a session until credentials or policy change.

Channel: Microsoft-Windows-SMBServer/Security

Provider: Microsoft-Windows-SMBServer

Event ids: 551

CaseSeverityTicket class
anonymous_refusedNoticefile_sharing
credential_refusedWarningfile_sharing

Where to look next:

  • Where the promoted SPN validation policy requires the client to supply an SPN, pair this with Security 5168 on the same host: a client still using NTLMv1 or LM sends no SPN and always fails.
  • On the anonymous arm, the client sent no credentials at all; give the device an account rather than loosening the server.
  • On a run of failures, expect the authentication rate limiter on Windows Server 2022 and later to add about 2 seconds per attempt, which reads as slowness rather than denial.

Related reasons:

Fields it can set: win.eventlog.network.smb_reason_code, win.eventlog.network.smb_session_id, win.eventlog.network.smb_spn_validation_policy

smb_session_lost​

An SMB session to a server was lost or recovered.

Severity: Warning or Info

Impact: Open files on that session fail until the client reconnects.

Channel: Microsoft-Windows-SmbClient/Connectivity

Provider: Microsoft-Windows-SmbClient

Event ids: 30805, 30806

CaseSeverityTicket class
lostWarningfile_sharing
recoveredInfofile_sharing

Related reasons:

Fields it can set: win.eventlog.network.smb_session_id

smb_session_reopen_failed​

The server could not reopen an SMB file after the client returned.

Severity: Warning

Impact: The application may hang or report a lost document until the user reopens the file.

Channel: Microsoft-Windows-SMBServer/Operational

Provider: Microsoft-Windows-SMBServer

Event ids: 1016

Related reasons:

Fields it can set: win.eventlog.network.smb_durable_handle, win.eventlog.network.smb_persistent_handle, win.eventlog.network.smb_reason_code, win.eventlog.network.smb_resilient_handle, win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name

smb_share_access_denied​

A share on this server denied access to a client.

Severity: Warning

Impact: The user cannot open the share until permissions change.

Channel: Microsoft-Windows-SMBServer/Security

Provider: Microsoft-Windows-SMBServer

Event ids: 1006

Where to look next:

  • Check both the share permissions and the NTFS permissions on the promoted share: either one denying is enough.
  • Compare the granted and mapped access in the promoted fields; where the two disagree on a NAS target, check for a missing SYNCHRONIZE entry on the folder.

Related reasons:

Fields it can set: win.eventlog.network.smb_granted_access, win.eventlog.network.smb_mapped_access, win.eventlog.network.smb_share_name

smb_share_connection_lost​

An SMB share tree connection was lost or recovered.

Severity: Warning or Info

Impact: Applications using that share see I/O errors until the tree reconnects.

Channel: Microsoft-Windows-SmbClient/Connectivity

Provider: Microsoft-Windows-SmbClient

Event ids: 30807, 30808

CaseSeverityTicket class
lostWarningfile_sharing
recoveredInfofile_sharing

Related reasons:

  • smb_session_lost: the broader session loss this share disconnect can be part of

Fields it can set: win.eventlog.network.smb_encryption_used, win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name, win.eventlog.network.smb_signing_used, win.eventlog.network.smb_tree_id

smb_signing_validation_failed​

SMB signing or encryption validation failed for a session.

Severity: Warning

Impact: The client refuses or drops traffic that does not meet the configured security requirement.

Channel: Microsoft-Windows-SmbClient/Security

Provider: Microsoft-Windows-SmbClient

Event ids: 31013, 31014

CaseSeverityTicket class
signingWarningfile_sharing
encryptionWarningfile_sharing

Where to look next:

  • Check what the promoted server is: third-party servers and NAS appliances that do not sign error responses fail this check, and the fix is a firmware update from the vendor.
  • Do not disable secure negotiate or drop the signing requirement to clear it; that removes the protection the check exists for.
  • Where the target is a Windows server, check whether clients reach it by IP address or CNAME: both force NTLM instead of Kerberos and weaken the session key.

Related reasons:

Fields it can set: win.eventlog.network.smb_command, win.eventlog.network.smb_message_id, win.eventlog.network.smb_session_id, win.eventlog.network.smb_tree_id

wfp_transaction_watchdog_timeout​

A Windows Filtering Platform transaction hit a watchdog timeout.

Severity: Warning

Impact: Firewall or filter policy changes may be incomplete until the platform recovers.

Channel: Microsoft-Windows-WFP/Operational

Provider: Microsoft-Windows-WFP

Event ids: 1030, 5150

wlan_connect_failed​

WLAN AutoConfig failed to connect using a saved profile.

Severity: Warning or Info

Impact: Wireless apps on that profile stay offline until the join succeeds.

Channel: Microsoft-Windows-WLAN-AutoConfig/Operational

Provider: Microsoft-Windows-WLAN-AutoConfig

Event ids: 8002

CaseSeverityTicket class
not_visibleInfonetworking
join_failedWarningnetworking

Where to look next:

  • On the not-visible arm, treat this as the profile's network being out of range, not as a credential problem.
  • On the join arm, read the promoted failure reason first; on an 802.1X network, check NPS event 6273 on the RADIUS server for the rejection reason.
  • Check the client and server certificates before the profile: invalid, expired or unrevocable certificates are the most common 802.1X cause.

Related reasons:

Fields it can set: win.eventlog.network.wlan_adapter, win.eventlog.network.wlan_bss_type, win.eventlog.network.wlan_connection_mode, win.eventlog.network.wlan_failure_reason, win.eventlog.network.wlan_profile_name, win.eventlog.network.wlan_reason_code

wlan_security_handshake_failed​

A wireless security handshake did not finish.

Severity: Warning

Impact: The device cannot use the network until the key exchange succeeds.

Channel: Microsoft-Windows-WLAN-AutoConfig/Operational

Provider: Microsoft-Windows-WLAN-AutoConfig

Event ids: 11006

Where to look next:

  • Read the promoted reason text, then check NPS event 6273 on the RADIUS server for the matching rejection.
  • Where the reason points at the certificate, enable the CAPI2 operational log on the client and reproduce: it is off by default and carries the chain and revocation detail.

Related reasons:

Fields it can set: win.eventlog.network.wlan_adapter, win.eventlog.network.wlan_bss_type, win.eventlog.network.wlan_reason_code, win.eventlog.network.wlan_reason_text

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.