Skip to main content

Windows Setup event log

1channels
2curated reasons
1themes fed
Livestatus

Classic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing). Covers servicing failures (event 3, with the HRESULT surfaced) and component-store corruption scan results (1014/1015); the begin, success and reboot events are kept as context. Nothing is deleted.

Feed id: win.eventlog.setup.

Channels​

This feed reads one Windows Event Log channel, Setup.

Fields​

FieldTypeUnitMeaning
win.eventlog.setup.packagestringPackageIdentifier: KB number or component/package name. The join + recurrence key (a package failing repeatedly is a stuck-update loop; correlates with WU-layer copies by KB).
win.eventlog.setup.error_codestringErrorCode hex HRESULT as logged (0x0 success; 0x800F####/0x8007#### servicing failure on event 3; scan Status on 1014). Kept a string: codes are identifiers, not quantities.
win.eventlog.setup.target_statestringIntendedPackageStateTextized: target state of the transition (Installed | Staged | Absent).
win.eventlog.setup.initial_statestringInitialPackageStateTextized: prior state (event 1 only; Staged | Absent | Installed | Superseded).
win.eventlog.setup.clientstringServicing client that drove the operation (CbsTask, UpdateAgentLCU, DISM, TrustedInstaller, WindowsUpdate, ...).
win.eventlog.setup.corruption_totalintTotalCorruption count from a component-store corruption scan (events 1014/1015).
win.eventlog.setup.corruption_repairedintRepaired count from a component-store corruption scan (events 1014/1015).
win.eventlog.setup.detection_onlyboolScan ran in detection-only mode (no repair attempted); qualifies whether 0 repaired is expected (events 1013/1014).
win.eventlog.setup.auto_triggeredboolCorruption scan was automatically triggered rather than operator-run (event 1013).

Curated reasons​

Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.

ReasonTicket classSeverity
patch_install_failedpatchingError
win_component_store_corruptionpatchingWarning or Notice

patch_install_failed​

Windows servicing failed to change a package to the requested state.

Also reported by: Windows System event log

Severity: Error

Impact: The install, uninstall, or update transaction did not complete for that package.

Channel: Setup

Provider: Microsoft-Windows-Servicing

Event ids: 3

Where to look next:

  • Pivot on PackageIdentifier and ErrorCode.
  • Check nearby Setup and CBS records for the start event and component-store scan results.

Related reasons:

Fields it can set: win.eventlog.setup.client, win.eventlog.setup.error_code, win.eventlog.setup.package, win.eventlog.setup.target_state

win_component_store_corruption​

Windows servicing reported unrepaired component-store corruption.

Also reported by: Windows CBS (Component-Based Servicing) log

Severity: Warning or Notice

Impact: Future Windows servicing operations may fail until the component store is repaired.

Channel: Setup

Provider: Microsoft-Windows-Servicing

Event ids: 1014, 1015

CaseSeverityTicket class
unrepairedWarningpatching
detection_onlyNoticepatching

Where to look next:

  • Compare TotalCorruption and Repaired.
  • Check whether the scan was detection-only before treating zero repaired as a failed repair.

Related reasons:

Fields it can set: win.eventlog.setup.corruption_repaired, win.eventlog.setup.corruption_total, win.eventlog.setup.detection_only, win.eventlog.setup.error_code

Ask this feed a question​

Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.