Skip to main content

Windows platform event channels

44channels
26curated reasons
4themes fed
Livestatus

Kernel, boot, power, device and driver, hardware, clock and performance channels, bound as one feed. Disks, volumes and the filesystem have their own feed, win.eventlog.storage. Reviewed platform failures, conditions, and lifecycle records receive reasons and diagnostic fields. Other events retain the Warning ceiling.

Feed id: win.eventlog.platform.

Channels​

This feed binds 44 Windows Event Log channels as one reporting axis. A channel that a given Windows edition, role or OEM does not provide is absent on that endpoint; the rest still collect.

ChannelTicket class
Dellhardware
Intel Graphics Softwarehardware
Intel-GFX-Info/Applicationhardware
Lenovo-Power-BaseModule/Operationalhardware
Lenovo-Power-SmartStandby/Operationalhardware
Lenovo-Sif-Core/Operationalhardware
Microsoft-Windows-DeviceSetupManager/Adminhardware
Microsoft-Windows-DeviceSetupManager/Operationalhardware
Microsoft-Windows-Diagnosis-DPS/Operational
Microsoft-Windows-Diagnosis-Scheduled/Operational
Microsoft-Windows-Diagnosis-Scripted/Admin
Microsoft-Windows-Diagnosis-Scripted/Operational
Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational
Microsoft-Windows-Diagnostics-Performance/Operationalperformance
Microsoft-Windows-DxgKrnl-Adminhardware
Microsoft-Windows-DxgKrnl-Operationalhardware
Microsoft-Windows-Kernel-Boot/Operationalos_stability
Microsoft-Windows-Kernel-Cache/Operationalos_stability
Microsoft-Windows-Kernel-Dump/Operationalos_stability
Microsoft-Windows-Kernel-EventTracing/Adminos_stability
Microsoft-Windows-Kernel-LiveDump/Operationalos_stability
Microsoft-Windows-Kernel-PnP/Configurationhardware
Microsoft-Windows-Kernel-PnP/Device Managementhardware
Microsoft-Windows-Kernel-PnP/Driver Watchdoghardware
Microsoft-Windows-Kernel-PnPConfig/Configurationhardware
Microsoft-Windows-Kernel-Power/Thermal-Operationalhardware
Microsoft-Windows-Kernel-WHEA/Errorshardware
Microsoft-Windows-Kernel-WHEA/Operationalhardware
Microsoft-Windows-PCI/Operationalhardware
Microsoft-Windows-PerceptionSensorDataService/Operationalhardware
Microsoft-Windows-Perflib/Operationalperformance
Microsoft-Windows-Resource-Exhaustion-Detector/Operationalperformance
Microsoft-Windows-Resource-Exhaustion-Resolver/Operationalperformance
Microsoft-Windows-Time-Service/Operationaltime_sync
Microsoft-Windows-TZSync/Operationaltime_sync
Microsoft-Windows-USB-UCMUCSICX/Operationalhardware
Microsoft-Windows-USB-USBXHCI-Operationalhardware
Microsoft-Windows-UserPnp/DeviceInstallhardware
Microsoft-Windows-WerKernel/Operationalos_stability
Microsoft-Windows-Win32k/Operationalos_stability
Microsoft-Windows-WindowsSystemAssessmentTool/Operationalperformance
Microsoft-Windows-WPD-ClassInstaller/Operationalhardware
Microsoft-Windows-WPD-MTPClassDriver/Operationalhardware
OneApp_IGCChardware

Fields​

FieldTypeUnitMeaning
win.eventlog.platform.pnp_problem_codeintDevice Manager problem code reported for a device start failure.
win.eventlog.platform.pnp_problem_code_namestringPublished CM_PROB name for the device problem code.
win.eventlog.platform.pnp_veto_typeintPublished PnP removal veto type number.
win.eventlog.platform.pnp_veto_type_namestringPublished PNP_Veto name for the removal veto type.
win.eventlog.platform.pnp_veto_holderstringProvider label for the component that vetoed device removal.
win.eventlog.platform.driver_infstringINF basename reported for a device start failure.
win.eventlog.platform.device_servicestringDriver service label reported for a device.
win.eventlog.platform.device_classstringLeading device-instance class without the identifying path tail.
win.eventlog.platform.device_countintNumber of child devices reported in a removal event.
win.eventlog.platform.mem_commit_bytesintCommitted virtual-memory bytes reported by Windows.
win.eventlog.platform.mem_commit_limit_bytesintVirtual-memory commit limit in bytes reported by Windows.
win.eventlog.platform.mem_commit_ratiofloatCommit charge divided by the positive commit limit.
win.eventlog.platform.clock_freq_error_ppmfloatMeasured hardware-clock frequency error in parts per million.
win.eventlog.platform.clock_drift_seconds_per_dayfloatMeasured clock drift in seconds per day.
win.eventlog.platform.clock_measure_window_minutesfloatClock frequency measurement window in minutes.
win.eventlog.platform.secure_boot_sbat_failure_pointintFirmware revocation update failure point.
win.eventlog.platform.secure_boot_sbat_update_statusintFirmware revocation update status number.
win.eventlog.platform.secure_boot_sbat_firmware_levelstringFirmware SBAT generation list reported by Windows.
win.eventlog.platform.firmware_indicator_categorystringCategory reported for a platform tamper indicator.
win.eventlog.platform.firmware_indicator_eventsstringFirmware setting names reported behind a tamper indicator.
win.eventlog.platform.firmware_scan_namestringVendor firmware verification scan label.
win.eventlog.platform.firmware_scan_resultstringResult clause reported by a firmware verification scan.
win.eventlog.platform.firmware_scan_result_codeintNumeric result code reported by a firmware verification scan.
win.eventlog.platform.security_assessment_resultstringResult clause reported by the device security assessment.
win.eventlog.platform.security_assessment_scoreintDevice security assessment score.
win.eventlog.platform.security_assessment_failed_areasstringRisk areas the device security assessment marked failed or high.
win.eventlog.platform.firmware_event_storestringVendor secure event-store label.
win.eventlog.platform.trace_session_namestringWindows tracing session that reported a failure.
win.eventlog.platform.boot_duration_msintMeasured whole-boot duration in milliseconds.
win.eventlog.platform.boot_main_path_msintMeasured main boot-path duration in milliseconds.
win.eventlog.platform.boot_post_boot_msintMeasured post-boot duration in milliseconds.
win.eventlog.platform.boot_is_degradationboolWhether Windows classified the boot measurement as degraded.
win.eventlog.platform.boot_startup_app_countintStartup application count reported for a boot.
win.eventlog.platform.startup_componentstringExecutable or service basename associated with a startup delay.
win.eventlog.platform.startup_component_total_msintTotal startup component duration in milliseconds.
win.eventlog.platform.startup_component_degradation_msintStartup component degradation duration in milliseconds.
win.eventlog.platform.shutdown_duration_msintMeasured whole-shutdown duration in milliseconds.
win.eventlog.platform.shutdown_is_degradationboolWhether Windows classified the shutdown measurement as degraded.
win.eventlog.platform.shutdown_services_msintMeasured shutdown service duration in milliseconds.
win.eventlog.platform.shutdown_user_session_msintMeasured user-session shutdown duration in milliseconds.
win.eventlog.platform.shutdown_componentstringService basename associated with a shutdown delay.
win.eventlog.platform.shutdown_component_degradation_msintShutdown component degradation duration in milliseconds.
win.eventlog.platform.usb_failure_typeintUSB controller failure type reported by Windows.
win.eventlog.platform.usb_failure_subtypeintUSB controller failure subtype reported by Windows.
win.eventlog.platform.usb_error_reasonintUSB controller error reason reported by Windows.
win.eventlog.platform.usb_ucsi_commandintUCSI command number associated with a connector-manager fault.
win.eventlog.platform.mtp_operation_codeintMedia transfer operation code reported for an unresponsive device.
win.eventlog.platform.font_load_blockedboolWhether Windows blocked the font load.
win.eventlog.platform.font_source_typeintFont source type reported by Windows.
win.eventlog.platform.font_filestringFont filename without its source path.
win.eventlog.platform.thermal_zonestringACPI thermal zone object reported by firmware.
win.eventlog.platform.thermal_temperature_kfloatThermal zone temperature reported in Kelvin.
win.eventlog.platform.thermal_active_trip_kfloatActive cooling trip point reported in Kelvin.
win.eventlog.platform.thermal_passive_trip_kfloatPassive cooling trip point reported in Kelvin.
win.eventlog.platform.thermal_min_throttlefloatMinimum processor throttle reported for passive cooling.
win.eventlog.platform.live_dump_componentstringKernel component that requested a live dump.
win.eventlog.platform.live_dump_requested_policyintRequested live-dump policy number.
win.eventlog.platform.live_dump_granted_policyintGranted live-dump policy number.
win.eventlog.platform.live_dump_throttledboolWhether the live-dump request was throttled.
win.eventlog.platform.gpu_memory_bytesintGraphics memory involved in compositor contention.
win.eventlog.platform.gpu_memory_bandwidthintGraphics memory bandwidth reported during contention.
win.eventlog.platform.gpu_contention_scenariointDesktop compositor contention scenario number.
win.eventlog.platform.boot_measure_reason_codeintMeasured-boot library reason code.
win.eventlog.platform.boot_measure_init_stateintMeasured-boot library initialization state.
win.eventlog.platform.tpm_init_positionintBoot position where TPM initialization failed.
win.eventlog.platform.device_software_namestringDevice companion software label reported by setup.
win.eventlog.platform.device_software_exit_codeintRaw process exit code reported by device software setup.
win.eventlog.platform.intel_graphics_categorystringCategory parsed from an Intel Graphics Software JSON insert.

Severity​

A curated reason states its own severity, listed below. Every other event on these channels keeps the severity its own provider stated, capped at Warning, so a pattern no rule here has read cannot page anyone.

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
device_install_reboot_pendinghardwareNotice
device_removal_vetoedhardwareNotice
device_removed_after_failurehardwareWarning
device_security_assessment_failedhardwareNotice
device_security_assessment_passedhardwareNotice or Info
device_software_install_failedhardwareWarning when a vendor installer exit code is present, Notice otherwise; Info for retry or stopped-update cases
device_start_failedhardwareWarning
firmware_event_store_unavailablehardwareWarning or Notice
firmware_verification_scan_failedhardwareNotice or Info
font_load_allowedos_stabilityInfo
font_load_blockedos_stabilityNotice
gpu_resources_saturatedperformanceNotice
live_kernel_dump_requestedos_stabilityNotice
measured_boot_failedos_stabilityWarning
os_boot_duration_highperformanceWarning for whole boot at 120 s or with BootIsDegradation; Notice for component degradation at 30 s or whole boot at 60 s
os_clock_drifttime_syncNotice
os_crash_dump_unavailableos_stabilityWarning
os_shutdown_duration_highperformanceWarning when ShutdownIsDegradation is true; Notice for long shutdown or slow service
platform_tamper_indicator_reportedendpoint_protectionError, Warning or Notice
portable_device_unresponsivehardwareInfo
ram_commit_exhaustedperformanceWarning at or above 95% commit ratio, Notice for diagnosis failure or lower ratio
secure_boot_revocation_update_failedos_stabilityInfo
thermal_cooling_engagedhardwareNotice or Info
tpm_initialization_failedos_stabilityWarning
usb_controller_errorhardwareNotice
win_trace_session_failedos_stabilityWarning or Info

device_install_reboot_pending​

Windows installed a driver and cannot finish until the host restarts.

Severity: Notice

Impact: The device may work only partly until the host restarts.

Channel: Microsoft-Windows-UserPnp/DeviceInstall

Provider: Microsoft-Windows-UserPnp

Event ids: 8000

Where to look next:

  • Restart the host at the next maintenance window.
  • When the same device asks on every boot, reinstall the driver package.

Related reasons:

Fields it can set: win.eventlog.platform.device_class

device_removal_vetoed​

Something on the device still holds the hardware open, so Windows refused the removal request.

Severity: Notice

Impact: The payload names the holder. The user sees a device-in-use dialog until the holder releases it.

Channel: Microsoft-Windows-Kernel-PnP/Device Management

Provider: Microsoft-Windows-Kernel-PnP

Event ids: 1000

Where to look next:

  • Read VetoName in the promoted fields.
  • Close the named application or service when the veto type says an app or service holds it.
  • Update the driver when the veto type says the driver refused to release the device.

Related reasons:

Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.pnp_veto_holder, win.eventlog.platform.pnp_veto_type, win.eventlog.platform.pnp_veto_type_name

device_removed_after_failure​

A device dropped off its bus while the driver was still reporting it as failing.

Severity: Warning

Impact: Windows removed the device immediately. Internal storage or network devices need hardware attention; USB peripherals often mean cable, hub, or port issues.

Channel: Microsoft-Windows-Kernel-PnP/Device Management

Provider: Microsoft-Windows-Kernel-PnP

Event ids: 1011

Where to look next:

  • Read the device class from the promoted fields.
  • Treat internal storage or network removal as a hardware ticket.
  • For USB peripherals, check cable, hub, and port when it repeats.

Related reasons:

Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_count

device_security_assessment_failed​

A Dell security assessment reported a failing result for this machine's platform posture.

Severity: Notice

Impact: The result and risk-area lines name settings an administrator controls. The score alone does not say what to fix.

Channel: Dell

Provider: Trusted Device | Security Assessment

Event ids: 14, 15

Where to look next:

  • Read the risk-area lines, not just the score.
  • Fix FAIL or HIGH areas such as missing BIOS password or disk encryption.
  • Treat UNAVAILABLE areas as scans that did not run; see firmware verification scan failures.

Related reasons:

Fields it can set: win.eventlog.platform.security_assessment_failed_areas, win.eventlog.platform.security_assessment_result, win.eventlog.platform.security_assessment_score

device_security_assessment_passed​

A Dell security assessment reported a passing result (with or without warnings) for this machine's platform posture.

Severity: Notice or Info

Impact: The result and risk-area lines name settings an administrator controls.

Channel: Dell

Provider: Trusted Device | Security Assessment

Event ids: 14, 15

CaseSeverityTicket class
passed_with_warningsNoticehardware
other_assessmentInfohardware

Where to look next:

  • Read the risk-area lines even on a pass, if warnings are present.

Related reasons:

Fields it can set: win.eventlog.platform.security_assessment_failed_areas, win.eventlog.platform.security_assessment_result, win.eventlog.platform.security_assessment_score

device_software_install_failed​

Windows failed to install companion software or a driver for a device.

Severity: Warning when a vendor installer exit code is present, Notice otherwise; Info for retry or stopped-update cases

Impact: The user may lack a control panel, vendor utility, or full driver until setup succeeds.

Channel: Microsoft-Windows-DeviceSetupManager/Admin

Provider: Microsoft-Windows-DeviceSetupManager

Event ids: 121, 151, 152, 163, 164, 172, 191

CaseSeverityTicket class
transientInfohardware
update_service_stoppedInfohardware
removal_failedNoticehardware
install_failedNotice to Warninghardware

Where to look next:

  • Read the exit code on id 163 and the status on id 121.
  • Wait or retry when Windows marks the error transient or the update service was stopped.
  • Reinstall or replace the vendor package when a fatal installer exit code appears.

Related reasons:

Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_software_exit_code, win.eventlog.platform.device_software_name

device_start_failed​

Windows enumerated a device and its driver refused to start it.

Severity: Warning

Impact: The device does not work until someone fixes the driver or hardware conflict.

Channel: Microsoft-Windows-Kernel-PnP/Configuration

Provider: Microsoft-Windows-Kernel-PnP

Event ids: 411

Where to look next:

  • Read the problem code first.
  • Code 10: reinstall or update the driver.
  • Code 12: resolve the resource conflict between two devices.

Related reasons:

Fields it can set: win.eventlog.platform.device_class, win.eventlog.platform.device_service, win.eventlog.platform.driver_inf, win.eventlog.platform.pnp_problem_code, win.eventlog.platform.pnp_problem_code_name

firmware_event_store_unavailable​

A Dell secure firmware-event store cannot be verified.

Severity: Warning or Notice

Impact: The platform-security agent cannot verify records from the named store until it is rebuilt.

Channel: Dell

Provider: Trusted Device | Secure Event Log

Event ids: 21, 45

CaseSeverityTicket class
keys_missingNoticehardware
repair_failedWarninghardware

Where to look next:

  • Read the store name from the promoted fields.
  • Reinstall the vendor agent on affected hosts when repair failed.
  • Treat tamper-indicator silence on those hosts as unknown, not clean, until the store is rebuilt.

Related reasons:

Fields it can set: win.eventlog.platform.firmware_event_store

firmware_verification_scan_failed​

A vendor firmware verification scan did not finish.

Severity: Notice or Info

Impact: The result text says why the scan stopped. It does not report a firmware integrity failure by itself.

Channel: Dell

Provider: Trusted Device | BIOS Verification, Trusted Device | Intel ME Verification, Trusted Device | Common Vulnerabilities and Exposures, Trusted Device | Secured Component Verification

Event ids: 2, 20, 42, 43, 47

CaseSeverityTicket class
unreachableNoticehardware
unsupportedInfohardware
verification_failedNoticehardware

Where to look next:

  • Read the result text from the promoted fields.
  • Open the proxy or firewall path when the result names a network error.
  • Ignore unsupported-platform results; the check never applies to that model.

Related reasons:

Fields it can set: win.eventlog.platform.firmware_scan_name, win.eventlog.platform.firmware_scan_result, win.eventlog.platform.firmware_scan_result_code

font_load_allowed​

A process loaded a font under an audit-mode font-loading policy.

Severity: Info

Impact: Audit-only context; nothing was refused.

Channel: Microsoft-Windows-Win32k/Operational

Provider: Microsoft-Windows-Win32k

Event ids: 260

Where to look next:

  • Treat this as audit-only context, not a user failure.

Related reasons:

Fields it can set: win.eventlog.platform.font_file, win.eventlog.platform.font_load_blocked, win.eventlog.platform.font_source_type

font_load_blocked​

A process tried to load a font while a font-loading restriction was in force, and Windows refused it.

Severity: Notice

Impact: The named application renders or prints text incorrectly until the font is installed system-wide or the app is exempted.

Channel: Microsoft-Windows-Win32k/Operational

Provider: Microsoft-Windows-Win32k

Event ids: 260

Where to look next:

  • Install the font system-wide or exempt the application.

Related reasons:

Fields it can set: win.eventlog.platform.font_file, win.eventlog.platform.font_load_blocked, win.eventlog.platform.font_source_type

gpu_resources_saturated​

The desktop compositor ran short of graphics memory or bandwidth.

Severity: Notice

Impact: The user sees stutter or display interruptions while contention lasts.

Channel: Microsoft-Windows-Diagnostics-Performance/Operational

Provider: Microsoft-Windows-Diagnostics-Performance

Event ids: 500

Where to look next:

  • Check the display memory figure in the promoted fields.
  • Reduce display count or resolution, or move the user to hardware with more graphics memory, when it repeats on one host.

Related reasons:

  • gpu_driver_reset: the driver reset that can follow sustained resource contention

Fields it can set: win.eventlog.platform.gpu_contention_scenario, win.eventlog.platform.gpu_memory_bandwidth, win.eventlog.platform.gpu_memory_bytes

live_kernel_dump_requested​

A kernel component requested a live kernel dump and Windows completed the request.

Severity: Notice

Impact: The component name points to the subsystem that stalled long enough to trip a watchdog.

Channel: Microsoft-Windows-WerKernel/Operational

Provider: Microsoft-Windows-WerKernel

Event ids: 1001, 1002

Where to look next:

  • Read the component name from the promoted fields.
  • Update the driver behind a network or power watchdog when it repeats daily on one host.

Related reasons:

Fields it can set: win.eventlog.platform.live_dump_component, win.eventlog.platform.live_dump_granted_policy, win.eventlog.platform.live_dump_requested_policy, win.eventlog.platform.live_dump_throttled

measured_boot_failed​

Windows reported a boot-measurement library failure during boot.

Severity: Warning

Impact: This event identifies a boot-measurement problem. It does not establish TPM absence, BitLocker behavior, attestation results, or a boot-chain attack.

Channel: Microsoft-Windows-Kernel-Boot/Operational

Provider: Microsoft-Windows-Kernel-Boot

Event ids: 208

Where to look next:

  • Read the event id and status from the promoted fields.
  • Check TPM readiness, Secure Boot state, firmware state, and related Windows boot records on the affected host.
  • Apply the vendor or Windows remediation for the reported status before changing TPM state.

Related reasons:

Fields it can set: win.eventlog.platform.boot_measure_init_state, win.eventlog.platform.boot_measure_reason_code

os_boot_duration_high​

Windows logged a slow boot or a slow startup component.

Severity: Warning for whole boot at 120 s or with BootIsDegradation; Notice for component degradation at 30 s or whole boot at 60 s

Impact: The duration fields show whether the whole boot or one named startup item caused the delay.

Channel: Microsoft-Windows-Diagnostics-Performance/Operational

Provider: Microsoft-Windows-Diagnostics-Performance

Event ids: 100, 101, 103, 107, 108

CaseSeverityTicket class
whole_bootInfo to Warningperformance
componentInfo to Noticeperformance

Where to look next:

  • Read DegradationTime and the component name on startup delay ids.
  • Remove or update the named product from startup when the same host is slow for several days.

Related reasons:

Fields it can set: win.eventlog.platform.boot_duration_ms, win.eventlog.platform.boot_is_degradation, win.eventlog.platform.boot_main_path_ms, win.eventlog.platform.boot_post_boot_ms, win.eventlog.platform.boot_startup_app_count, win.eventlog.platform.startup_component, win.eventlog.platform.startup_component_degradation_ms, win.eventlog.platform.startup_component_total_ms

os_clock_drift​

This host's clock hardware runs at the wrong rate.

Severity: Notice

Impact: The time service holds the clock in place with continuous correction. When synchronization stops, the clock walks away at the stated rate.

Channel: Microsoft-Windows-Time-Service/Operational

Provider: Microsoft-Windows-Time-Service

Event ids: 282

Where to look next:

  • Check that the host reaches its time source.
  • Replace the board battery on a desktop when correction exceeds about 50 parts per million.

Fields it can set: win.eventlog.platform.clock_drift_seconds_per_day, win.eventlog.platform.clock_freq_error_ppm, win.eventlog.platform.clock_measure_window_minutes

os_crash_dump_unavailable​

Windows could not set up the path it writes a crash dump through.

Severity: Warning

Impact: The next bugcheck on this host may leave no dump to analyse.

Channel: Microsoft-Windows-Kernel-Dump/Operational

Provider: Microsoft-Windows-Kernel-Dump

Event ids: 5, 9

Where to look next:

  • A kernel crash reported without dump analysis after this event is explained by it; the crash itself is still counted once.
  • Check the page file on the system volume.
  • Size the page file for the configured dump type when the status says the file was not found.

Related reasons:

  • kernel_crash: a kernel crash on this host still ships as one row, with its dump analysis reported unavailable when the dump path was never ready
  • os_dump_pagefile_too_small: a pagefile misconfiguration that can also prevent a usable crash dump

os_shutdown_duration_high​

Windows logged a slow shutdown or a service that delayed shutdown.

Severity: Warning when ShutdownIsDegradation is true; Notice for long shutdown or slow service

Impact: The duration fields show whether the whole shutdown or one named service caused the delay.

Channel: Microsoft-Windows-Diagnostics-Performance/Operational

Provider: Microsoft-Windows-Diagnostics-Performance

Event ids: 200, 203

CaseSeverityTicket class
whole_shutdownWarningperformance
measuredInfo to Noticeperformance
componentInfo to Noticeperformance

Where to look next:

  • Read Name on id 203 for the service that held shutdown open.
  • Update or reconfigure that service when degraded shutdown repeats on one host.

Related reasons:

Fields it can set: win.eventlog.platform.shutdown_component, win.eventlog.platform.shutdown_component_degradation_ms, win.eventlog.platform.shutdown_duration_ms, win.eventlog.platform.shutdown_is_degradation, win.eventlog.platform.shutdown_services_ms, win.eventlog.platform.shutdown_user_session_ms

platform_tamper_indicator_reported​

A platform-security agent reported a tamper indicator against this machine.

Also reported by: Windows System event log

Severity: Error, Warning or Notice

Impact: The agent names the category it matched and the firmware or chassis events it built the indicator from. An indicator names what the agent matched; read the named settings to see what the machine is actually set to.

Channel: Dell

Provider: Trusted Device | BIOS Events and IoA

Event ids: 10, 11, 12

CaseSeverityTicket class
partialWarningendpoint_protection
escalatedErrorendpoint_protection
detectedErrorendpoint_protection
reportedWarningendpoint_protection
clearedNoticeendpoint_protection

Where to look next:

  • Read the Category and the listed events from the message: they name what was matched.
  • Check whether a deliberate BIOS change or a hardware service visit explains it.
  • Where nothing explains it, treat the named firmware settings as the thing to put back.
  • When event 10 clears an indicator, match the category to the earlier partial or escalated event on the same host.

Fields it can set: win.eventlog.platform.firmware_indicator_category, win.eventlog.platform.firmware_indicator_events

portable_device_unresponsive​

A phone, camera, or media player on USB stopped answering.

Severity: Info

Impact: Nothing on the managed host is affected. The user unlocks the device and plugs it back in.

Channel: Microsoft-Windows-WPD-MTPClassDriver/Operational

Provider: Microsoft-Windows-WPD-MTPClassDriver

Event ids: 1006, 1007, 1008

Where to look next:

  • Have the user unplug the device, unlock it, and plug it back in.

Fields it can set: win.eventlog.platform.mtp_operation_code

ram_commit_exhausted​

Committed memory on this host reached its limit.

Severity: Warning at or above 95% commit ratio, Notice for diagnosis failure or lower ratio

Impact: Applications can fail allocations while committed memory stays near its limit.

Channel: Microsoft-Windows-Resource-Exhaustion-Detector/Operational

Provider: Microsoft-Windows-Resource-Exhaustion-Detector

Event ids: 1003, 1007, 1008

CaseSeverityTicket class
notifiedNotice to Warningperformance
allocation_failedWarningperformance
diagnosis_failedNoticeperformance

Where to look next:

  • Find the process holding the commit and restart or update it.
  • Add memory or a larger page file when no single process explains it.

Fields it can set: win.eventlog.platform.mem_commit_bytes, win.eventlog.platform.mem_commit_limit_bytes, win.eventlog.platform.mem_commit_ratio

secure_boot_revocation_update_failed​

Windows tried to write its boot revocation level into firmware and the firmware refused.

Severity: Info

Impact: Revocations Microsoft ships in the SBAT list are not enforced on this host until the update succeeds.

Channel: Microsoft-Windows-Kernel-Boot/Operational

Provider: Microsoft-Windows-Kernel-Boot

Event ids: 292

Where to look next:

  • Check what else boots this machine; dual-boot hosts may hold a different revocation level on purpose.
  • On a Windows-only host, apply a firmware update when this appears on a minority of the fleet.

Related reasons:

Fields it can set: win.eventlog.platform.secure_boot_sbat_failure_point, win.eventlog.platform.secure_boot_sbat_firmware_level, win.eventlog.platform.secure_boot_sbat_update_status

thermal_cooling_engaged​

The platform reached a temperature trip point and engaged cooling.

Severity: Notice or Info

Impact: Active cooling is fan noise. Passive cooling slows the processor while heat persists.

Channel: Microsoft-Windows-Kernel-Power/Thermal-Operational

Provider: Microsoft-Windows-Kernel-Power

Event ids: 114, 116

CaseSeverityTicket class
activeInfohardware
passiveNoticehardware
disengagedInfohardware

Where to look next:

  • Take no action for a single active-cooling event.
  • Clean fans or improve airflow when passive cooling runs for hours on one host.

Related reasons:

  • cpu_busy: sustained CPU load that can trigger this cooling response

Fields it can set: win.eventlog.platform.thermal_active_trip_k, win.eventlog.platform.thermal_min_throttle, win.eventlog.platform.thermal_passive_trip_k, win.eventlog.platform.thermal_temperature_k, win.eventlog.platform.thermal_zone

tpm_initialization_failed​

Windows reported a TPM initialization failure during boot.

Severity: Warning

Impact: This event identifies a TPM initialization problem. It does not establish TPM absence, BitLocker behavior, attestation results, or a boot-chain attack.

Channel: Microsoft-Windows-Kernel-Boot/Operational

Provider: Microsoft-Windows-Kernel-Boot

Event ids: 235

Where to look next:

  • Read the event id and status from the promoted fields.
  • Check TPM readiness, Secure Boot state, firmware state, and related Windows boot records on the affected host.
  • Apply the vendor or Windows remediation for the reported status before changing TPM state.

Related reasons:

Fields it can set: win.eventlog.platform.tpm_init_position

usb_controller_error​

The USB host controller or USB-C connector manager reported a fault.

Severity: Notice

Impact: Devices on that controller stop working or charging until it resets.

Channel: Microsoft-Windows-USB-USBXHCI-Operational, Microsoft-Windows-USB-UCMUCSICX/Operational

Provider: Microsoft-Windows-USB-USBXHCI, Microsoft-Windows-USB-UCMUCSICX

Event ids: 1, 50, 62

Where to look next:

  • Unplug and replug the device or dock.
  • Update platform firmware when the same host reports this daily.

Related reasons:

Fields it can set: win.eventlog.platform.usb_error_reason, win.eventlog.platform.usb_failure_subtype, win.eventlog.platform.usb_failure_type, win.eventlog.platform.usb_ucsi_command

win_trace_session_failed​

A Windows tracing session could not start, write, or continue.

Severity: Warning or Info

Impact: The status word separates an existing session, a full trace file, a full disk, and other failures.

Channel: Microsoft-Windows-Kernel-EventTracing/Admin

Provider: Microsoft-Windows-Kernel-EventTracing

Event ids: 0, 1, 2, 3, 4, 28

CaseSeverityTicket class
already_runningInfoos_stability
file_fullInfoos_stability
disk_fullWarningos_stability
other_failureInfoos_stability

Where to look next:

  • Read the status word from the promoted fields.
  • Ignore name-collision and log-file-full statuses; the session already exists or wrapped by design.
  • Free disk space when the status says the volume is full.

Fields it can set: win.eventlog.platform.trace_session_name

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.