Windows Setup event log
Classic Windows Event Log Setup channel: the package-servicing state machine (Microsoft-Windows-Servicing). Covers servicing failures (event 3, with the HRESULT surfaced) and component-store corruption scan results (1014/1015); the begin, success and reboot events are kept as context. Nothing is deleted.
Feed id: win.eventlog.setup.
Channels
This feed reads one Windows Event Log channel, Setup.
Fields
| Field | Type | Unit | Meaning |
|---|---|---|---|
win.eventlog.setup.package | string | PackageIdentifier: KB number or component/package name. The join + recurrence key (a package failing repeatedly is a stuck-update loop; correlates with WU-layer copies by KB). | |
win.eventlog.setup.error_code | string | ErrorCode hex HRESULT as logged (0x0 success; 0x800F####/0x8007#### servicing failure on event 3; scan Status on 1014). Kept a string: codes are identifiers, not quantities. | |
win.eventlog.setup.target_state | string | IntendedPackageStateTextized: target state of the transition (Installed | Staged | Absent). | |
win.eventlog.setup.initial_state | string | InitialPackageStateTextized: prior state (event 1 only; Staged | Absent | Installed | Superseded). | |
win.eventlog.setup.client | string | Servicing client that drove the operation (CbsTask, UpdateAgentLCU, DISM, TrustedInstaller, WindowsUpdate, ...). | |
win.eventlog.setup.corruption_total | int | TotalCorruption count from a component-store corruption scan (events 1014/1015). | |
win.eventlog.setup.corruption_repaired | int | Repaired count from a component-store corruption scan (events 1014/1015). | |
win.eventlog.setup.detection_only | bool | Scan ran in detection-only mode (no repair attempted); qualifies whether 0 repaired is expected (events 1013/1014). | |
win.eventlog.setup.auto_triggered | bool | Corruption scan was automatically triggered rather than operator-run (event 1013). |
Curated reasons
Severity here is what the condition is worth to the person holding the ticket, not the level the provider stated for itself.
| Reason | Ticket class | Severity |
|---|---|---|
patch_install_failed | patching | Error |
win_component_store_corruption | patching | Warning or Notice |
patch_install_failed
Windows servicing failed to change a package to the requested state.
Also reported by: Windows System event log
Severity: Error
Impact: The install, uninstall, or update transaction did not complete for that package.
Channel: Setup
Provider: Microsoft-Windows-Servicing
Event ids: 3
Where to look next:
- Pivot on PackageIdentifier and ErrorCode.
- Check nearby Setup and CBS records for the start event and component-store scan results.
Related reasons:
win_component_store_corruption: component-store corruption can cause later servicing failures
Fields it can set: win.eventlog.setup.client, win.eventlog.setup.error_code, win.eventlog.setup.package, win.eventlog.setup.target_state
win_component_store_corruption
Windows servicing reported unrepaired component-store corruption.
Also reported by: Windows CBS (Component-Based Servicing) log
Severity: Warning or Notice
Impact: Future Windows servicing operations may fail until the component store is repaired.
Channel: Setup
Provider: Microsoft-Windows-Servicing
Event ids: 1014, 1015
| Case | Severity | Ticket class |
|---|---|---|
unrepaired | Warning | patching |
detection_only | Notice | patching |
Where to look next:
- Compare TotalCorruption and Repaired.
- Check whether the scan was detection-only before treating zero repaired as a failed repair.
Related reasons:
patch_install_failed: realized package transition failure that corruption may explain
Fields it can set: win.eventlog.setup.corruption_repaired, win.eventlog.setup.corruption_total, win.eventlog.setup.detection_only, win.eventlog.setup.error_code
Ask this feed a question
Every reason code, token and field on this page is queryable across the endpoints you manage. Connect your AI and ask in plain language, or open the same evidence in Explore.