Windows network event channels
Connectivity, name resolution, file sharing and remote access channels, bound as one feed: DHCP, DNS client, WLAN, connectivity probes, the firewall and filtering platform, SMB client and server, RDP and SSH. Reviewed connectivity, sharing, and remote-access failures receive reasons and diagnostic fields. Other events retain the Warning ceiling.
Feed id: win.eventlog.network.
Channels
This feed binds 43 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.
| Channel | Ticket class |
|---|---|
Microsoft-Windows-AllJoyn/Operational | networking |
Microsoft-Windows-BranchCacheSMB/Operational | file_sharing |
Microsoft-Windows-CloudFiles-Filter/Operational | file_sync |
Microsoft-Windows-CoreSystem-SmsRouter-Events/Operational | networking |
Microsoft-Windows-Dhcp-Client/Admin | networking |
Microsoft-Windows-Dhcp-Client/Operational (disabled by default on client Windows; enable it on the host to produce data) | networking |
Microsoft-Windows-Dhcpv6-Client/Admin | networking |
Microsoft-Windows-DNS-Client/Operational (disabled by default on client Windows; enable it on the host to produce data) | networking |
Microsoft-Windows-EapHost/Operational | auth |
Microsoft-Windows-Host-Network-Service-Admin | networking |
Microsoft-Windows-Host-Network-Service-Operational | networking |
Microsoft-Windows-NcdAutoSetup/Operational | networking |
Microsoft-Windows-NCSI/Operational | networking |
Microsoft-Windows-NetworkLocationWizard/Operational | networking |
Microsoft-Windows-NetworkProfile/Operational | networking |
Microsoft-Windows-NlaSvc/Operational | networking |
Microsoft-Windows-OfflineFiles/Operational | file_sharing |
Microsoft-Windows-RemoteAssistance/Operational | remote_access |
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Admin | remote_access |
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational | remote_access |
Microsoft-Windows-RemoteDesktopServices-SessionServices/Operational | remote_access |
Microsoft-Windows-SmbClient/Connectivity | file_sharing |
Microsoft-Windows-SMBClient/Operational | file_sharing |
Microsoft-Windows-SmbClient/Security | file_sharing |
Microsoft-Windows-SMBServer/Connectivity | file_sharing |
Microsoft-Windows-SMBServer/Operational | file_sharing |
Microsoft-Windows-SMBServer/Security | file_sharing |
Microsoft-Windows-TerminalServices-LocalSessionManager/Admin | remote_access |
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational | remote_access |
Microsoft-Windows-TerminalServices-PnPDevices/Admin | remote_access |
Microsoft-Windows-TerminalServices-Printers/Admin | printing |
Microsoft-Windows-TerminalServices-RDPClient/Operational | remote_access |
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin | remote_access |
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational | remote_access |
Microsoft-Windows-TerminalServices-ServerUSBDevices/Admin | remote_access |
Microsoft-Windows-Wcmsvc/Operational | networking |
Microsoft-Windows-WFP/Operational | networking |
Microsoft-Windows-Windows Firewall With Advanced Security/Firewall | networking |
Microsoft-Windows-Windows Firewall With Advanced Security/FirewallDiagnostics | networking |
Microsoft-Windows-WinINet-Config/ProxyConfigChanged | networking |
Microsoft-Windows-WLAN-AutoConfig/Operational | networking |
OpenSSH/Admin | remote_access |
OpenSSH/Operational | remote_access |
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.network.dns_query_name | string | DNS query name from a client resolution timeout. | |
win.eventlog.network.firewall_rule_action | int | Firewall rule action code from the dedicated channel. | |
win.eventlog.network.firewall_rule_direction | int | Firewall rule direction code. | |
win.eventlog.network.firewall_rule_origin | int | Firewall rule origin code. | |
win.eventlog.network.firewall_rule_profiles | int | Firewall rule profile bitmask. | |
win.eventlog.network.offline_files_failed_count | int | Offline-files sync failure count. | |
win.eventlog.network.offline_files_path | string | Offline-files scope path. | |
win.eventlog.network.printer_name | string | Redirected printer name from RDS setup. | |
win.eventlog.network.rule_id | string | Firewall rule identifier. | |
win.eventlog.network.rule_name | string | Firewall rule label. | |
win.eventlog.network.smb_auth_protocol_new | int | SMB authentication protocol after re-auth. | |
win.eventlog.network.smb_auth_protocol_old | int | SMB authentication protocol before re-auth. | |
win.eventlog.network.smb_call_duration_secs | int | SMB security call duration in seconds. | |
win.eventlog.network.smb_call_function | string | SMB security function that ran slow. | |
win.eventlog.network.smb_call_threshold_secs | int | SMB security call threshold in seconds. | |
win.eventlog.network.smb_command | int | SMB2 command number. | |
win.eventlog.network.smb_connection_type | int | SMB connection type code. | |
win.eventlog.network.smb_durable_handle | bool | Whether the SMB handle was durable. | |
win.eventlog.network.smb_elapsed_ms | int | SMB operation elapsed milliseconds. | |
win.eventlog.network.smb_encryption_used | bool | Whether SMB encryption was used. | |
win.eventlog.network.smb_granted_access | string | SMB granted access mask. | |
win.eventlog.network.smb_logon_id | string | SMB logon identifier. | |
win.eventlog.network.smb_mapped_access | string | SMB mapped access mask. | |
win.eventlog.network.smb_message_id | int | SMB message identifier. | |
win.eventlog.network.smb_mutual_auth_lost | bool | Whether mutual authentication was lost. | |
win.eventlog.network.smb_ntlm_blocked | bool | Whether NTLM was blocked on the connection. | |
win.eventlog.network.smb_operation_duration | int | SMB server operation duration. | |
win.eventlog.network.smb_operation_threshold | int | SMB server operation threshold. | |
win.eventlog.network.smb_persistent_handle | bool | Whether the SMB handle was persistent. | |
win.eventlog.network.smb_reason_code | int | SMB provider reason code. | |
win.eventlog.network.smb_resilient_handle | bool | Whether the SMB handle was resilient. | |
win.eventlog.network.smb_retry_count | int | SMB retry count. | |
win.eventlog.network.smb_session_id | string | SMB session identifier. | |
win.eventlog.network.smb_setting_default | int | Shipped default for an SMB security setting. | |
win.eventlog.network.smb_setting_name | string | SMB security setting name. | |
win.eventlog.network.smb_setting_value | int | Configured SMB security setting value. | |
win.eventlog.network.smb_share_name | string | SMB share the event is about: the share segment of a UNC the provider wrote under ServerName, or the ShareName field where the provider states one. | |
win.eventlog.network.smb_signing_used | bool | Whether SMB signing was used. | |
win.eventlog.network.smb_spn_validation_policy | int | SMB SPN validation policy code. | |
win.eventlog.network.smb_tree_id | int | SMB tree connection identifier. | |
win.eventlog.network.wlan_adapter | string | Wireless adapter description. | |
win.eventlog.network.wlan_bss_type | string | Wireless BSS type. | |
win.eventlog.network.wlan_connection_mode | string | Wireless connection mode. | |
win.eventlog.network.wlan_failure_reason | string | Wireless failure reason sentence. | |
win.eventlog.network.wlan_profile_name | string | Wireless profile name. | |
win.eventlog.network.wlan_reason_code | int | Wireless reason code. | |
win.eventlog.network.wlan_reason_text | string | Wireless security reason text. |
Severity
A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
dhcp_address_conflict_detected
The DHCP client detected an address conflict.
Severity: Warning
Impact: Connectivity may flap until the conflict is resolved.
Channel: Microsoft-Windows-Dhcp-Client/Admin
Provider: Microsoft-Windows-Dhcp-Client
Event ids: 1004
Where to look next:
- Take no action on a single conflict: the client requests a new address on its own.
- Repeated conflicts on one subnet point at the DHCP scope or the lease period, not at the client.
Related reasons:
dhcp_lease_failed: the lease failure that can follow an unresolved address conflict
dhcp_lease_denied
The DHCP server denied a lease request.
Severity: Warning
Impact: The host stays unaddressed until policy or server configuration changes.
Channel: Microsoft-Windows-Dhcp-Client/Admin
Provider: Microsoft-Windows-Dhcp-Client
Event ids: 1002
Where to look next:
- Take no action on an isolated denial: the client asks for a new address on its own, and ipconfig /release then /renew retries immediately instead of waiting for that.
- A run of denials means the address is no longer valid in the scope; check the scope and lease period on the DHCP server.
Related reasons:
dhcp_lease_failed: the client-side symptom when the server denies every lease
dhcp_lease_failed
The DHCP client could not obtain a lease.
Severity: Warning
Impact: The host may have no IPv4 address until DHCP succeeds.
Channel: Microsoft-Windows-Dhcp-Client/Admin
Provider: Microsoft-Windows-Dhcp-Client
Event ids: 1001, 1003
Related reasons:
dhcp_address_conflict_detected: an address conflict that can also block the leasedhcp_lease_denied: a server-side denial that produces this symptom
dns_client_resolution_timed_out
A DNS client query timed out.
Severity: Warning
Impact: Name-dependent services fail until resolution succeeds.
Channel: Microsoft-Windows-DNS-Client/Operational
Provider: Microsoft-Windows-DNS-Client
Event ids: 1013, 1015
Where to look next:
- Read this as unreachable DNS servers, not a missing record: a negative answer stops the client without a timeout.
- The client works through the servers configured on the adapter on one short fixed budget, so how many are listed and in what order decides whether a reachable one is reached before it gives up; put a reachable server first. The reference below carries the current timings.
Related reasons:
smb_server_name_unresolved: the SMB-specific symptom of the same resolution failure
Fields it can set: win.eventlog.network.dns_query_name
firewall_rule_changed
The Windows Firewall service reported that a rule was modified. The payload identifies the rule and selected properties.
Also reported by: Windows Security event log
Severity: Notice
Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.
Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider: Microsoft-Windows-Windows Firewall With Advanced Security
Event ids: 2005, 2099
Where to look next:
- Use the event to identify the rule change and its actor or source where available.
- Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.
Related reasons:
firewall_rule_created: a new rule added, a different factfirewall_rule_deleted: a rule removed, a different factfirewall_service_stopped: the firewall being down entirely, a stronger version of the same policy risk
Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name
firewall_rule_created
The Windows Firewall service reported that a rule was added. The payload identifies the rule and selected properties.
Also reported by: Windows Security event log
Severity: Notice
Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.
Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider: Microsoft-Windows-Windows Firewall With Advanced Security
Event ids: 2004, 2097
Where to look next:
- Use the event to identify the rule change and its actor or source where available.
- Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.
Related reasons:
firewall_rule_changed: an existing rule modified, a different factfirewall_rule_deleted: a rule removed, a different factfirewall_service_stopped: the firewall being down entirely, a stronger version of the same policy risk
Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name
firewall_rule_deleted
The Windows Firewall service reported that a rule was deleted. The payload identifies the rule and selected properties.
Also reported by: Windows Security event log
Severity: Notice
Impact: This record describes firewall configuration activity. It does not prove effective enforcement or network exposure.
Channel: Microsoft-Windows-Windows Firewall With Advanced Security/Firewall
Provider: Microsoft-Windows-Windows Firewall With Advanced Security
Event ids: 2006, 2052
Where to look next:
- Use the event to identify the rule change and its actor or source where available.
- Inspect the resulting firewall policy and test the relevant traffic path before deciding whether the change altered effective access.
Related reasons:
firewall_rule_changed: an existing rule modified, a different factfirewall_rule_created: a new rule added, a different factfirewall_service_stopped: the firewall being down entirely, a stronger version of the same policy risk
Fields it can set: win.eventlog.network.firewall_rule_action, win.eventlog.network.firewall_rule_direction, win.eventlog.network.firewall_rule_origin, win.eventlog.network.firewall_rule_profiles, win.eventlog.network.rule_id, win.eventlog.network.rule_name
offline_files_slow_link_transition_blocked
Offline Files could not change sync mode for a slow link.
Severity: Warning
Impact: The folder stays in its prior mode until policy or connectivity allows the transition.
Channel: Microsoft-Windows-OfflineFiles/Operational
Provider: Microsoft-Windows-OfflineFiles
Event ids: 1008
Where to look next:
- Check the Configure slow-link mode policy before treating this as a fault: a latency threshold of 1 ms is Always Offline mode, where no transition to online is expected.
- Where Always Offline is not intended, the folder in the promoted path is waiting on link latency against whatever threshold that policy sets.
Related reasons:
offline_files_sync_failed: the sync failure that can follow when the link-speed transition is blocked
Fields it can set: win.eventlog.network.offline_files_path
offline_files_sync_failed
Offline Files background synchronization failed.
Severity: Warning
Impact: Redirected folders may be stale until sync succeeds.
Channel: Microsoft-Windows-OfflineFiles/Operational
Provider: Microsoft-Windows-OfflineFiles
Event ids: 1006
Related reasons:
offline_files_slow_link_transition_blocked: the slow-link transition failure that can leave sync stuck
Fields it can set: win.eventlog.network.offline_files_failed_count, win.eventlog.network.offline_files_path
rds_redirected_printer_setup_failed
RDS redirected printer setup failed.
Severity: Warning
Impact: Session printing may be unavailable until setup succeeds.
Channel: Microsoft-Windows-TerminalServices-Printers/Admin
Provider: Microsoft-Windows-TerminalServices-Printers
Event ids: 1108, 1109
| Case | Severity | Ticket class |
|---|---|---|
default_not_set | Warning | printing |
config_not_restored | Warning | printing |
Where to look next:
- Take no action on the configuration-not-restored arm: Windows applies the default configuration when the queue is created.
- On the default-not-set arm, expect it on sessions with more than one redirected queue after a reconnect, where the spooler did not enumerate a disconnected queue.
- Where the queue itself is missing rather than misconfigured, check whether Easy Print is disabled, which makes the host require a matching driver for the promoted printer name.
Related reasons:
printer_driver_install_failed: the driver failure that commonly causes this setup to fail
Fields it can set: win.eventlog.network.printer_name
smb_anonymous_access_denied
This server refused anonymous access at the share or server scope.
Severity: Notice
Impact: The refusal is expected when anonymous access is disabled.
Channel: Microsoft-Windows-SMBServer/Security
Provider: Microsoft-Windows-SMBServer
Event ids: 1007, 1009
| Case | Severity | Ticket class |
|---|---|---|
share | Notice | file_sharing |
server | Notice | file_sharing |
Related reasons:
smb_anonymous_access_enabled: the posture setting this refusal depends on
Fields it can set: win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name
smb_anonymous_access_enabled
The server reported that one or more named pipes or shares are marked for anonymous access. The event does not identify the resource or prove that a remote client can reach it.
Severity: Notice
Impact: This is a posture finding. Confirm the affected resources and the intended access path before treating it as an exposure.
Channel: Microsoft-Windows-SMBServer/Operational
Provider: Microsoft-Windows-SMBServer
Event ids: 1025
Where to look next:
- List the server's named pipes and shares, then check which are marked for anonymous access.
- Test the intended access path separately.
- Where the setting is deliberate, record why; where it is not, remove it.
Related reasons:
smb_anonymous_access_denied: what happens when this posture is off insteadsmb_insecure_guest_allowed: another anonymous or guest access posture finding on the same server
smb_client_auth_context_failed
The SMB client could not build an authentication context for a server.
Severity: Warning
Impact: The user cannot open resources on that server until credentials or domain reachability recover.
Channel: Microsoft-Windows-SmbClient/Security, Microsoft-Windows-SmbClient/Connectivity
Provider: Microsoft-Windows-SmbClient
Event ids: 30801, 31000, 31001, 31002
| Case | Severity | Ticket class |
|---|---|---|
no_authority | Warning | file_sharing |
wrong_principal | Warning | file_sharing |
logon_denied | Warning | file_sharing |
other | Warning | file_sharing |
Where to look next:
- On the wrong-principal arm, check whether the promoted server name is a CNAME alias: the server needs an SPN registered for the alias it is reached by.
- Where the alias SPN is correct and the failure persists, check SMB server name hardening on the server (SmbServerNameHardeningLevel).
- On the no-authority arm, connect by the server's Kerberos-capable FQDN rather than an IP address or workgroup name, and confirm the client can reach a domain controller.
Related reasons:
smb_session_auth_failed: the session-level authentication failure this can lead to
Fields it can set: win.eventlog.network.smb_logon_id, win.eventlog.network.smb_reason_code
smb_client_mutual_auth_lost
SMB mutual authentication was lost after the client re-authenticated.
Severity: Warning
Impact: The client may continue but without the mutual authentication guarantee.
Channel: Microsoft-Windows-SmbClient/Security
Provider: Microsoft-Windows-SmbClient
Event ids: 31019
Where to look next:
- Compare the old and new auth protocol ids: a move off Kerberos is what removed the mutual-authentication guarantee.
- Check how the promoted server name is reached: connecting by IP address or by a CNAME alias makes the client use NTLM instead of Kerberos.
Related reasons:
smb_client_auth_context_failed: the authentication-context failure that can precede this loss
Fields it can set: win.eventlog.network.smb_auth_protocol_new, win.eventlog.network.smb_auth_protocol_old, win.eventlog.network.smb_mutual_auth_lost
smb_client_security_call_slow
An SMB client security call exceeded its slow threshold.
Severity: Notice
Impact: Operations may lag until the call completes; nothing failed.
Channel: Microsoft-Windows-SMBClient/Operational
Provider: Microsoft-Windows-SMBClient
Event ids: 30955
Related reasons:
smb_server_operation_slow: the server-side counterpart of a slow SMB security call
Fields it can set: win.eventlog.network.smb_call_duration_secs, win.eventlog.network.smb_call_function, win.eventlog.network.smb_call_threshold_secs
smb_connect_failed
An SMB connection attempt failed after the server name resolved.
Severity: Warning
Impact: Applications cannot reach the share or server until connectivity or permissions improve.
Channel: Microsoft-Windows-SmbClient/Connectivity, Microsoft-Windows-SmbClient/Security
Provider: Microsoft-Windows-SmbClient
Event ids: 30803, 30809, 30816, 30823, 31010
| Case | Severity | Ticket class |
|---|---|---|
timeout | Warning | file_sharing |
access_denied | Warning | file_sharing |
connection_failed | Warning | file_sharing |
Where to look next:
- On the timeout arm, check for a listener on TCP 445 on the named server and that the File and Printer Sharing (SMB-In) rules are enabled; a blocking firewall is the usual cause.
- Where the firewall looks clean, run a netsh wfp trace during a retry to name the rule or program dropping the traffic.
- On the access-denied arm, check whether the client now requires SMB signing or blocks NTLM: both became defaults in Windows 11 24H2 and Windows Server 2025 and both deny connections that worked before an upgrade.
Related reasons:
smb_server_name_unresolved: the earlier name-resolution step that can also block the connection
Fields it can set: win.eventlog.network.smb_connection_type, win.eventlog.network.smb_elapsed_ms, win.eventlog.network.smb_reason_code, win.eventlog.network.smb_retry_count, win.eventlog.network.smb_share_name
smb_insecure_guest_allowed
The SMB client allowed an insecure guest connection.
Severity: Warning
Impact: Traffic to that server may proceed without proving user identity.
Channel: Microsoft-Windows-SmbClient/Security
Provider: Microsoft-Windows-SmbClient
Event ids: 31022
Where to look next:
- Treat the traffic to the promoted server as unsigned and unencrypted: guest logons support neither, which is what makes them interceptable.
- Find what set AllowInsecureGuestAuth on this client and give the target real credentials instead; the setting is a temporary workaround, not a configuration to leave in place.
Related reasons:
smb_anonymous_access_enabled: a related anonymous-access posture findingsmb_insecure_guest_rejected: the opposite outcome under a stricter policy
smb_insecure_guest_rejected
The SMB client rejected an insecure guest connection.
Severity: Warning
Impact: The share stays unreachable until guest access is allowed or proper credentials are supplied.
Channel: Microsoft-Windows-SmbClient/Security
Provider: Microsoft-Windows-SmbClient
Event ids: 31017
Where to look next:
- Give the promoted server real credentials: it accepted the client as an unauthenticated guest, and the client refused.
- Do not re-enable insecure guest logons to clear this; it exposes the client to rogue-server and interception attacks.
Related reasons:
smb_insecure_guest_allowed: the opposite outcome under a looser policy
smb_legacy_dialect_rejected
This server rejected a legacy SMB dialect.
Severity: Notice
Impact: Older clients cannot connect until they negotiate a supported dialect.
Channel: Microsoft-Windows-SMBServer/Operational
Provider: Microsoft-Windows-SMBServer
Event ids: 1001
Where to look next:
- Read the rejected client name and address from the event: that device, not the server, is the thing to fix.
- Expect scan-to-share printers and other appliances here; they are the documented casualties of disabling SMB 1.0.
- Do not re-enable SMB 1.0 to clear this; secure dialect negotiation cannot stop a downgrade to SMB 1.0.
Related reasons:
smb_connect_failed: the connection failure a client sees after this rejection
smb_security_setting_nondefault
An SMB security setting on this device differs from the Windows default. The payload names the setting and configured value.
Severity: Notice
Impact: The value can strengthen or weaken protection depending on the setting and the direction of the change. The event alone does not classify the change as safer or weaker.
Channel: Microsoft-Windows-SmbClient/Security, Microsoft-Windows-SMBServer/Security
Provider: Microsoft-Windows-SmbClient, Microsoft-Windows-SMBServer
Event ids: 1021, 31003, 31016, 31018
| Case | Severity | Ticket class |
|---|---|---|
guest_auth | Notice | file_sharing |
lm_compatibility | Notice | file_sharing |
signing | Notice | file_sharing |
Where to look next:
- Read the setting name, configured value, and stated default.
- Identify the policy that set it, then interpret the value for that setting.
- Review guest authentication, compatibility, and signing settings separately.
Related reasons:
group_policy_file_share_unhardened: a related unhardened file-share posture findingsmb_signing_validation_failed: a concrete failure a nondefault signing setting can cause
Fields it can set: win.eventlog.network.smb_setting_default, win.eventlog.network.smb_setting_name, win.eventlog.network.smb_setting_value
smb_server_name_unresolved
The SMB client could not resolve a server name.
Severity: Warning
Impact: File shares on that server name stay unreachable until name resolution works.
Channel: Microsoft-Windows-SmbClient/Connectivity
Provider: Microsoft-Windows-SmbClient
Event ids: 30800
Related reasons:
dns_client_resolution_timed_out: the DNS failure likely behind this unresolved namesmb_connect_failed: the connection failure that follows once the name does resolve
Fields it can set: win.eventlog.network.smb_reason_code
smb_server_operation_slow
An SMB server operation exceeded its slow threshold.
Severity: Notice
Impact: The operation completed but took longer than the server expected.
Channel: Microsoft-Windows-SMBServer/Operational
Provider: Microsoft-Windows-SMBServer
Event ids: 1020, 1047, 1054
| Case | Severity | Ticket class |
|---|---|---|
filesystem | Notice | file_sharing |
network | Notice | file_sharing |
session_setup | Notice | file_sharing |
Where to look next:
- On the filesystem arm, look at storage rather than SMB: the default threshold is 15 seconds and the server is waiting on the local file system.
- Check the usual delay sources on that host: file system filter drivers such as antivirus, disk load, and backup or VSS freezes.
- For extreme delays, check for events 1031 and 1032 on the same host and collect the dump from %SystemRoot%\LiveKernelReports.
Related reasons:
smb_client_security_call_slow: the client-side counterpart of a slow SMB operation
Fields it can set: win.eventlog.network.smb_operation_duration, win.eventlog.network.smb_operation_threshold, win.eventlog.network.smb_share_name
smb_session_auth_failed
An SMB session authentication attempt on this server failed.
Severity: Warning or Notice
Impact: Clients cannot open a session until credentials or policy change.
Channel: Microsoft-Windows-SMBServer/Security
Provider: Microsoft-Windows-SMBServer
Event ids: 551
| Case | Severity | Ticket class |
|---|---|---|
anonymous_refused | Notice | file_sharing |
credential_refused | Warning | file_sharing |
Where to look next:
- Where the promoted SPN validation policy requires the client to supply an SPN, pair this with Security 5168 on the same host: a client still using NTLMv1 or LM sends no SPN and always fails.
- On the anonymous arm, the client sent no credentials at all; give the device an account rather than loosening the server.
- On a run of failures, expect the authentication rate limiter on Windows Server 2022 and later to add about 2 seconds per attempt, which reads as slowness rather than denial.
Related reasons:
smb_client_auth_context_failed: the client-side authentication failure that can cause this
Fields it can set: win.eventlog.network.smb_reason_code, win.eventlog.network.smb_session_id, win.eventlog.network.smb_spn_validation_policy
smb_session_lost
An SMB session to a server was lost or recovered.
Severity: Warning or Info
Impact: Open files on that session fail until the client reconnects.
Channel: Microsoft-Windows-SmbClient/Connectivity
Provider: Microsoft-Windows-SmbClient
Event ids: 30805, 30806
| Case | Severity | Ticket class |
|---|---|---|
lost | Warning | file_sharing |
recovered | Info | file_sharing |
Related reasons:
smb_session_reopen_failed: the reopen failure users see once the session dropssmb_share_connection_lost: the narrower per-share loss on the same session
Fields it can set: win.eventlog.network.smb_session_id
smb_session_reopen_failed
The server could not reopen an SMB file after the client returned.
Severity: Warning
Impact: The application may hang or report a lost document until the user reopens the file.
Channel: Microsoft-Windows-SMBServer/Operational
Provider: Microsoft-Windows-SMBServer
Event ids: 1016
Related reasons:
smb_session_lost: the session loss that this reopen attempt follows
Fields it can set: win.eventlog.network.smb_durable_handle, win.eventlog.network.smb_persistent_handle, win.eventlog.network.smb_reason_code, win.eventlog.network.smb_resilient_handle, win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name
smb_share_access_denied
A share on this server denied access to a client.
Severity: Warning
Impact: The user cannot open the share until permissions change.
Channel: Microsoft-Windows-SMBServer/Security
Provider: Microsoft-Windows-SMBServer
Event ids: 1006
Where to look next:
- Check both the share permissions and the NTFS permissions on the promoted share: either one denying is enough.
- Compare the granted and mapped access in the promoted fields; where the two disagree on a NAS target, check for a missing SYNCHRONIZE entry on the folder.
Related reasons:
smb_anonymous_access_denied: a narrower version of the same access refusal
Fields it can set: win.eventlog.network.smb_granted_access, win.eventlog.network.smb_mapped_access, win.eventlog.network.smb_share_name
smb_share_connection_lost
An SMB share tree connection was lost or recovered.
Severity: Warning or Info
Impact: Applications using that share see I/O errors until the tree reconnects.
Channel: Microsoft-Windows-SmbClient/Connectivity
Provider: Microsoft-Windows-SmbClient
Event ids: 30807, 30808
| Case | Severity | Ticket class |
|---|---|---|
lost | Warning | file_sharing |
recovered | Info | file_sharing |
Related reasons:
smb_session_lost: the broader session loss this share disconnect can be part of
Fields it can set: win.eventlog.network.smb_encryption_used, win.eventlog.network.smb_session_id, win.eventlog.network.smb_share_name, win.eventlog.network.smb_signing_used, win.eventlog.network.smb_tree_id
smb_signing_validation_failed
SMB signing or encryption validation failed for a session.
Severity: Warning
Impact: The client refuses or drops traffic that does not meet the configured security requirement.
Channel: Microsoft-Windows-SmbClient/Security
Provider: Microsoft-Windows-SmbClient
Event ids: 31013, 31014
| Case | Severity | Ticket class |
|---|---|---|
signing | Warning | file_sharing |
encryption | Warning | file_sharing |
Where to look next:
- Check what the promoted server is: third-party servers and NAS appliances that do not sign error responses fail this check, and the fix is a firmware update from the vendor.
- Do not disable secure negotiate or drop the signing requirement to clear it; that removes the protection the check exists for.
- Where the target is a Windows server, check whether clients reach it by IP address or CNAME: both force NTLM instead of Kerberos and weaken the session key.
Related reasons:
smb_security_setting_nondefault: the configuration change that can cause signing to fail validation
Fields it can set: win.eventlog.network.smb_command, win.eventlog.network.smb_message_id, win.eventlog.network.smb_session_id, win.eventlog.network.smb_tree_id
wfp_transaction_watchdog_timeout
A Windows Filtering Platform transaction hit a watchdog timeout.
Severity: Warning
Impact: Firewall or filter policy changes may be incomplete until the platform recovers.
Channel: Microsoft-Windows-WFP/Operational
Provider: Microsoft-Windows-WFP
Event ids: 1030, 5150
wlan_connect_failed
WLAN AutoConfig failed to connect using a saved profile.
Severity: Warning or Info
Impact: Wireless apps on that profile stay offline until the join succeeds.
Channel: Microsoft-Windows-WLAN-AutoConfig/Operational
Provider: Microsoft-Windows-WLAN-AutoConfig
Event ids: 8002
| Case | Severity | Ticket class |
|---|---|---|
not_visible | Info | networking |
join_failed | Warning | networking |
Where to look next:
- On the not-visible arm, treat this as the profile's network being out of range, not as a credential problem.
- On the join arm, read the promoted failure reason first; on an 802.1X network, check NPS event 6273 on the RADIUS server for the rejection reason.
- Check the client and server certificates before the profile: invalid, expired or unrevocable certificates are the most common 802.1X cause.
Related reasons:
wlan_security_handshake_failed: the handshake failure that is one cause of a failed wireless connect
Fields it can set: win.eventlog.network.wlan_adapter, win.eventlog.network.wlan_bss_type, win.eventlog.network.wlan_connection_mode, win.eventlog.network.wlan_failure_reason, win.eventlog.network.wlan_profile_name, win.eventlog.network.wlan_reason_code
wlan_security_handshake_failed
A wireless security handshake did not finish.
Severity: Warning
Impact: The device cannot use the network until the key exchange succeeds.
Channel: Microsoft-Windows-WLAN-AutoConfig/Operational
Provider: Microsoft-Windows-WLAN-AutoConfig
Event ids: 11006
Where to look next:
- Read the promoted reason text, then check NPS event 6273 on the RADIUS server for the matching rejection.
- Where the reason points at the certificate, enable the CAPI2 operational log on the client and reproduce: it is off by default and carries the chain and revocation detail.
Related reasons:
wlan_connect_failed: the overall connect failure this handshake problem produces
Fields it can set: win.eventlog.network.wlan_adapter, win.eventlog.network.wlan_bss_type, win.eventlog.network.wlan_reason_code, win.eventlog.network.wlan_reason_text
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.