Microsoft-Windows-Application Server-Applications
Event ID 100: TrackRecord= WorkflowInstanceRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, Annotations = Annotatio...
#Description
TrackRecord= WorkflowInstanceRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, Annotations = Annotations, ProfileName = ProfileName.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
State UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 101: TrackRecord = WorkflowInstanceUnhandledExceptionRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, SourceName =...
#Description
TrackRecord = WorkflowInstanceUnhandledExceptionRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, SourceName = SourceName, SourceId = SourceId, SourceInstanceId = SourceInstanceId, SourceTypeName=SourceTypeName, Exception=Exception, Annotations= Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
SourceName UnicodeString | |
SourceId UnicodeString | |
SourceInstanceId UnicodeString | |
SourceTypeName UnicodeString | |
Exception UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 102: TrackRecord = WorkflowInstanceAbortedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotation...
#Description
TrackRecord = WorkflowInstanceAbortedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotations = Annotations, ProfileName = ProfileName.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 103: TrackRecord = ActivityStateRecord, InstanceID = InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, State = State, Name=Name, ActivityId=ActivityId, ActivityInstanceId=ActivityInstanceId, A...
#Description
TrackRecord = ActivityStateRecord, InstanceID = , RecordNumber=, EventTime=, State = , Name=, ActivityId=, ActivityInstanceId=, ActivityTypeName=, Arguments=, Variables=, Annotations=, ProfileName =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
State UnicodeString | |
Name UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
Arguments UnicodeString | |
Variables UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 104: TrackRecord = ActivityScheduledRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, Name = Name, ActivityId = ActivityId, ActivityInstanceId = ActivityInstanceId, Ac...
#Description
TrackRecord = ActivityScheduledRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, Name = Name, ActivityId = ActivityId, ActivityInstanceId = ActivityInstanceId, ActivityTypeName = ActivityTypeName, ChildActivityName = ChildActivityName, ChildActivityId = ChildActivityId, ChildActivityInstanceId = ChildActivityInstanceId, ChildActivityTypeName =ChildActivityTypeName, Annotations=Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
ChildActivityName UnicodeString | |
ChildActivityId UnicodeString | |
ChildActivityInstanceId UnicodeString | |
ChildActivityTypeName UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 105: TrackRecord = FaultPropagationRecord, InstanceID=.
#Description
TrackRecord = FaultPropagationRecord, InstanceID=InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, FaultSourceActivityName=FaultSourceActivityName, FaultSourceActivityId=FaultSourceActivityId, FaultSourceActivityInstanceId=FaultSourceActivityInstanceId, FaultSourceActivityTypeName=FaultSourceActivityTypeName, FaultHandlerActivityName=FaultHandlerActivityName, FaultHandlerActivityId = FaultHandlerActivityId, FaultHandlerActivityInstanceId =FaultHandlerActivityInstanceId, FaultHandlerActivityTypeName=FaultHandlerActivityTypeName, Fault=Fault, IsFaultSource=IsFaultSource, Annotations=Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
FaultSourceActivityName UnicodeString | |
FaultSourceActivityId UnicodeString | |
FaultSourceActivityInstanceId UnicodeString | |
FaultSourceActivityTypeName UnicodeString | |
FaultHandlerActivityName UnicodeString | |
FaultHandlerActivityId UnicodeString | |
FaultHandlerActivityInstanceId UnicodeString | |
FaultHandlerActivityTypeName UnicodeString | |
Fault UnicodeString | |
IsFaultSource UInt8 | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 106: TrackRecord = CancelRequestedRecord, InstanceID=.
#Description
TrackRecord = CancelRequestedRecord, InstanceID=InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, Name=Name, ActivityId=ActivityId, ActivityInstanceId=ActivityInstanceId, ActivityTypeName = ActivityTypeName, ChildActivityName = ChildActivityName, ChildActivityId = ChildActivityId, ChildActivityInstanceId = ChildActivityInstanceId, ChildActivityTypeName =ChildActivityTypeName, Annotations=Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
ChildActivityName UnicodeString | |
ChildActivityId UnicodeString | |
ChildActivityInstanceId UnicodeString | |
ChildActivityTypeName UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 107: TrackRecord = BookmarkResumptionRecord, InstanceID=.
#Description
TrackRecord = BookmarkResumptionRecord, InstanceID=InstanceId, RecordNumber=RecordNumber,EventTime=EventTime, Name=Name, SubInstanceID=SubInstanceID, OwnerActivityName=OwnerActivityName, OwnerActivityId =OwnerActivityId, OwnerActivityInstanceId=OwnerActivityInstanceId, OwnerActivityTypeName=OwnerActivityTypeName, Annotations=Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
SubInstanceID GUID | |
OwnerActivityName UnicodeString | |
OwnerActivityId UnicodeString | |
OwnerActivityInstanceId UnicodeString | |
OwnerActivityTypeName UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 108: TrackRecord = CustomTrackingRecord, InstanceID = InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, Name=Name, ActivityName=ActivityName, ActivityId=ActivityId, ActivityInstanceId=Activity...
#Description
TrackRecord = CustomTrackingRecord, InstanceID = , RecordNumber=, EventTime=, Name=, ActivityName=, ActivityId=, ActivityInstanceId=, ActivityTypeName=, Data=, Annotations=, ProfileName =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
ActivityName UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
Data UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 110: TrackRecord = CustomTrackingRecord, InstanceID = InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, Name=Name, ActivityName=ActivityName, ActivityId=ActivityId, ActivityInstanceId=Activity...
#Description
TrackRecord = CustomTrackingRecord, InstanceID = , RecordNumber=, EventTime=, Name=, ActivityName=, ActivityId=, ActivityInstanceId=, ActivityTypeName=, Data=, Annotations=, ProfileName =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
ActivityName UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
Data UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 111: TrackRecord = CustomTrackingRecord, InstanceID = InstanceId, RecordNumber=RecordNumber, EventTime=EventTime, Name=Name, ActivityName=ActivityName, ActivityId=ActivityId, ActivityInstanceId=Activity...
#Description
TrackRecord = CustomTrackingRecord, InstanceID = , RecordNumber=, EventTime=, Name=, ActivityName=, ActivityId=, ActivityInstanceId=, ActivityTypeName=, Data=, Annotations=, ProfileName =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
Name UnicodeString | |
ActivityName UnicodeString | |
ActivityId UnicodeString | |
ActivityInstanceId UnicodeString | |
ActivityTypeName UnicodeString | |
Data UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 112: TrackRecord = WorkflowInstanceSuspendedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotati...
#Description
TrackRecord = WorkflowInstanceSuspendedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotations = Annotations, ProfileName = ProfileName.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 113: TrackRecord = WorkflowInstanceTerminatedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotat...
#Description
TrackRecord = WorkflowInstanceTerminatedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotations = Annotations, ProfileName = ProfileName.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 114: TrackRecord= WorkflowInstanceRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, Annotations = Annotatio...
#Description
TrackRecord= WorkflowInstanceRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, Annotations = Annotations, ProfileName = ProfileName, WorkflowDefinitionIdentity = WorkflowDefinitionIdentity.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
State UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
WorkflowDefinitionIdentity UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 115: TrackRecord = WorkflowInstanceAbortedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotation...
#Description
TrackRecord = WorkflowInstanceAbortedRecord, InstanceID = , RecordNumber = , EventTime = , ActivityDefinitionId = , Reason = , Annotations = , ProfileName = , WorkflowDefinitionIdentity =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
WorkflowDefinitionIdentity UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 116: TrackRecord = WorkflowInstanceSuspendedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotati...
#Description
TrackRecord = WorkflowInstanceSuspendedRecord, InstanceID = , RecordNumber = , EventTime = , ActivityDefinitionId = , Reason = , Annotations = , ProfileName = , WorkflowDefinitionIdentity =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
WorkflowDefinitionIdentity UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 117: TrackRecord = WorkflowInstanceTerminatedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, Reason = Reason, Annotat...
#Description
TrackRecord = WorkflowInstanceTerminatedRecord, InstanceID = , RecordNumber = , EventTime = , ActivityDefinitionId = , Reason = , Annotations = , ProfileName = , WorkflowDefinitionIdentity =.
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
Reason UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
WorkflowDefinitionIdentity UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 118: TrackRecord = WorkflowInstanceUnhandledExceptionRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, SourceName =...
#Description
TrackRecord = WorkflowInstanceUnhandledExceptionRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, SourceName = SourceName, SourceId = SourceId, SourceInstanceId = SourceInstanceId, SourceTypeName=SourceTypeName, Exception=Exception, Annotations= Annotations, ProfileName = ProfileName, WorkflowDefinitionIdentity = WorkflowDefinitionIdentity
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
SourceName UnicodeString | |
SourceId UnicodeString | |
SourceInstanceId UnicodeString | |
SourceTypeName UnicodeString | |
Exception UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
WorkflowDefinitionIdentity UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 119: TrackRecord= WorkflowInstanceUpdatedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, OriginalDefi...
#Description
TrackRecord= WorkflowInstanceUpdatedRecord, InstanceID = InstanceId, RecordNumber = RecordNumber, EventTime = EventTime, ActivityDefinitionId = ActivityDefinitionId, State = State, OriginalDefinitionIdentity = OriginalDefinitionIdentity, UpdatedDefinitionIdentity = UpdatedDefinitionIdentity, Annotations = Annotations, ProfileName = ProfileName
Message #
Fields #
| Name | Description |
|---|---|
InstanceId GUID | |
RecordNumber Int64 | |
EventTime FILETIME | |
ActivityDefinitionId UnicodeString | |
State UnicodeString | |
OriginalDefinitionIdentity UnicodeString | |
UpdatedDefinitionIdentity UnicodeString | |
Annotations UnicodeString | |
ProfileName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 131: Pool allocating Size Bytes.
#Message #
Fields #
| Name | Description |
|---|---|
Size Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "131",
"version": "0",
"level": "5",
"task": "2509",
"opcode": "12",
"keywords": 1152921504606912512,
"time_created": "2026-03-15T23:29:50.493381100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Size": "512",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 132: BufferPool of size PoolSize, changing quota by Delta.
#Message #
Fields #
| Name | Description |
|---|---|
PoolSize Int32 | |
Delta Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "132",
"version": "0",
"level": "5",
"task": "2509",
"opcode": "13",
"keywords": 1152921504606912512,
"time_created": "2026-03-15T23:30:24.092322400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{a63d8622-0688-48d2-ba27-d3a099f2fe3d}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PoolSize": "262144",
"Delta": "-1",
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 133: IO Thread scheduler callback invoked.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "133",
"version": "0",
"level": "5",
"task": "2593",
"opcode": "1",
"keywords": 1152921504608944128,
"time_created": "2026-03-15T23:29:50.489398700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fb0a7822-7b4b-45f4-bf59-3e1c0df8827e}"
},
"execution": {
"process_id": "7780",
"thread_id": "7796"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 134: IO Thread scheduler callback invoked.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "134",
"version": "0",
"level": "5",
"task": "2593",
"opcode": "2",
"keywords": 1152921504608944128,
"time_created": "2026-03-15T23:29:50.489603500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fb0a7822-7b4b-45f4-bf59-3e1c0df8827e}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 201: The Dispatcher invoked 'AfterReceiveReply' on a ClientMessageInspector of type 'TypeName'.
#Event ID 202: The Dispatcher invoked 'BeforeSendRequest' on a ClientMessageInspector of type 'TypeName'.
#Event ID 203: The Dispatcher invoked 'AfterCall' on a ClientParameterInspector of type 'TypeName'.
#Event ID 204: The Dispatcher invoked 'BeforeCall' on a ClientParameterInspector of type 'TypeName'.
#Event ID 205: An OperationInvoker invoked the 'MethodName' method.
#Description
An OperationInvoker invoked the 'MethodName' method. Caller information: 'CallerInfo'.
Message #
Fields #
| Name | Description |
|---|---|
MethodName UnicodeString | |
CallerInfo UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "205",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "53",
"keywords": 2305843009214218244,
"time_created": "2026-03-15T23:29:50.496508900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"MethodName": "TryAcquireTaskOwnershipLease",
"CallerInfo": "::1:51230",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 206: The Dispatcher invoked an ErrorHandler of type 'TypeName' with an exception of type 'ExceptionTypeName'.
#Event ID 207: The Dispatcher invoked a FaultProvider of type 'TypeName' with an exception of type 'ExceptionTypeName'.
#Event ID 208: The Dispatcher invoked 'AfterReceiveReply' on a MessageInspector of type 'TypeName'.
#Message #
Fields #
| Name | Description |
|---|---|
TypeName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "208",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "51",
"keywords": 2305843009214218244,
"time_created": "2026-03-15T23:30:19.363350200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11da94e5-a08b-4071-9f06-9cc69bdc3867}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"TypeName": "Microsoft.ActiveDirectory.WebServices.Shared.WebServices.IdentityManagementOperations.IdentityManagementMessageInspector",
"HostReference": "",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 209: The Dispatcher invoked 'BeforeSendRequest' on a MessageInspector of type 'TypeName'.
#Message #
Fields #
| Name | Description |
|---|---|
TypeName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "209",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "52",
"keywords": 2305843009214218244,
"time_created": "2026-03-15T23:30:19.493348800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11da94e5-a08b-4071-9f06-9cc69bdc3867}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"TypeName": "Microsoft.ActiveDirectory.WebServices.Shared.WebServices.IdentityManagementOperations.IdentityManagementMessageInspector",
"HostReference": "",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 210: The 'ThrottleName' throttle limit of 'Limit' was hit.
#Event ID 211: The Dispatcher invoked 'AfterCall' on a ParameterInspector of type 'TypeName'.
#Event ID 212: The Dispatcher invoked 'BeforeCall' on a ParameterInspector of type 'TypeName'.
#Event ID 213: ServiceHost started: 'ServiceTypeName'.
#Event ID 214: An OperationInvoker completed the call to the 'MethodName' method.
#Description
An OperationInvoker completed the call to the 'MethodName' method. The method call duration was 'Duration' ms.
Message #
Fields #
| Name | Description |
|---|---|
MethodName UnicodeString | |
Duration Int64 | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "214",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "54",
"keywords": 2305843009214611460,
"time_created": "2026-03-15T23:29:50.497903800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"MethodName": "TryAcquireTaskOwnershipLease",
"Duration": "15",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 215: The transport received a message from 'ListenAddress'.
#Message #
Fields #
| Name | Description |
|---|---|
ListenAddress UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "215",
"version": "0",
"level": "4",
"task": "2599",
"opcode": "2",
"keywords": 2305843009214219264,
"time_created": "2026-03-15T23:29:50.494160400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}",
"RelatedActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ListenAddress": "net.tcp://localhost:1500/policy",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 216: The transport sent a message to 'DestinationAddress'.
#Message #
Fields #
| Name | Description |
|---|---|
DestinationAddress UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "216",
"version": "0",
"level": "4",
"task": "2600",
"opcode": "2",
"keywords": 2305843009214219264,
"time_created": "2026-03-15T23:29:50.493824000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"DestinationAddress": "net.tcp://localhost:1500/policy",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 217: The Client is executing Action 'Action' associated with the 'ContractName' contract.
#Description
The Client is executing Action 'Action' associated with the 'ContractName' contract. The message will be sent to 'Destination'.
Message #
Fields #
| Name | Description |
|---|---|
Action UnicodeString | |
ContractName UnicodeString | |
Destination UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "217",
"version": "0",
"level": "4",
"task": "2514",
"opcode": "20",
"keywords": 1152921504607371268,
"time_created": "2026-03-15T23:29:50.483821000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}",
"RelatedActivityID": "{d0302fac-41f0-4eb2-9a47-143bb68642d5}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Action": "http://schemas.microsoft.com/ws/2009/12/identityserver/protocols/policystore/IPolicyStore/TryAcquireTaskOwnershipLease",
"ContractName": "IPolicyStore",
"Destination": "net.tcp://localhost:1500/policy",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 218: The Client completed executing Action 'Action' associated with the 'ContractName' contract.
#Description
The Client completed executing Action 'Action' associated with the 'ContractName' contract. The message was sent to 'Destination'.
Message #
Fields #
| Name | Description |
|---|---|
Action UnicodeString | |
ContractName UnicodeString | |
Destination UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "218",
"version": "0",
"level": "4",
"task": "2576",
"opcode": "2",
"keywords": 2305843009214218244,
"time_created": "2026-03-15T23:29:50.498428800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Action": "http://schemas.microsoft.com/ws/2009/12/identityserver/protocols/policystore/IPolicyStore/TryAcquireTaskOwnershipLease",
"ContractName": "IPolicyStore",
"Destination": "net.tcp://localhost:1500/policy",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 219: There was an unhandled exception of type 'ExceptionTypeName' during message processing.
#Description
There was an unhandled exception of type 'ExceptionTypeName' during message processing. Full Exception Details: ExceptionToString.
Message #
Fields #
| Name | Description |
|---|---|
ExceptionToString UnicodeString | |
ExceptionTypeName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "219",
"version": "0",
"level": "2",
"task": "2533",
"opcode": "0",
"keywords": 2305843009214611460,
"time_created": "2026-03-15T23:30:27.680010500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{79d7d62d-1a6a-435e-b74a-b71f353b47cc}"
},
"execution": {
"process_id": "3912",
"thread_id": "12988"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ExceptionToString": "System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '10675199.02:48:05.4775807'. ---> System.IO.IOException: The read operation failed, see inner exception. ---> System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '10675199.02:48:05.4775807'. ---> System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.Runtime.AsyncResult.End[TAsyncResult](IAsyncResult result)\n at System.ServiceModel.Channels.ConnectionStream.EndRead(IAsyncResult asyncResult)\n at System.Net.FixedSizeReader.ReadCallback(IAsyncResult transportResult)\n --- End of inner exception stack trace ---\n at System.Net.Security.NegotiateStream.EndRead(IAsyncResult asyncResult)\n at System.ServiceModel.Channels.StreamConnection.EndRead()\n --- End of inner exception stack trace ---\n at System.Runtime.AsyncResult.End[TAsyncResult](IAsyncResult result)\n at System.ServiceModel.Channels.TransportDuplexSessionChannel.EndTryReceive(IAsyncResult result, Message& message)\n at System.ServiceModel.Dispatcher.DuplexChannelBinder.EndTryReceive(IAsyncResult result, RequestContext& requestContext)\n at System.ServiceModel.Dispatcher.ErrorHandlingReceiver.EndTryReceive(IAsyncResult result, RequestContext& requestContext)",
"ExceptionTypeName": "System.ServiceModel.CommunicationException",
"HostReference": "",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 220: The Dispatcher sent a message to the transport.
#Event ID 221: The Dispatcher received a message from the transport.
#Event ID 222: The 'MethodName' method threw an unhandled exception when invoked by the OperationInvoker.
#Event ID 223: The 'MethodName' method threw a FaultException when invoked by the OperationInvoker.
#Description
The 'MethodName' method threw a FaultException when invoked by the OperationInvoker. The method call duration was 'Duration' ms.
Message #
Fields #
| Name | Description |
|---|---|
MethodName UnicodeString | |
Duration Int64 | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{C651F5F6-1C0D-492E-8AE1-B4EFD7C9D503}",
"event_source_name": "",
"event_id": 223,
"version": 0,
"level": 3,
"task": 2533,
"opcode": 0,
"keywords": "0x20000000000E0004",
"time_created": "2026-06-02T05:18:59.146+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{77F3E607-361B-4E1B-94A1-97AA6C5D1BC1}"
},
"execution": {
"process_id": 4444,
"thread_id": 8268
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe",
"Duration": 46,
"HostReference": "",
"MethodName": "GetADDomain"
},
"message": "DispatchMessage"
}
Event ID 224: The 'ThrottleName' throttle limit of 'Limit' is at 70%.
#Event ID 225: Calculated correlation key 'InstanceKey' using values 'Values' in parent scope 'ParentScope'.
#Event ID 226: ClosedCount idle services out of total TotalCount activated services closed.
#Event ID 302: Name:'Name', Reference:'HostReference', Payload:Payload.
#Event ID 303: Name:'Name', Reference:'HostReference', Payload:Payload.
#Event ID 401: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 402: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 403: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 404: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 440: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 441: Activity boundary.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 499: Transfer event emitted.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 507: HostedTransportConfigurationManager begin configuration initialization
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 508: HostedTransportConfigurationManager end configuration initialization
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 513: Received request with virtual path 'VirtualPath' from the AppDomain 'AppDomainFriendlyName'.
#Event ID 601: Processed ServiceActivation Element Relative Address:'RelativeAddress', Normalized Relative Address 'NormalizedAddress' .
#Event ID 602: Incoming request matches a ServiceActivation element with address 'IncomingAddress'.
#Event ID 603: Incoming request matches a WCF Service defined in Asp.
#Event ID 604: A new Asp.
#Description
A new Asp.Net route 'AspNetRoutePrefix' with serviceType 'ServiceType' and serviceHostFactoryType 'ServiceHostFactoryType' is added.
Message #
Fields #
| Name | Description |
|---|---|
AspNetRoutePrefix UnicodeString | |
ServiceType UnicodeString | Known values
|
ServiceHostFactoryType UnicodeString | |
AppDomain UnicodeString |
Event ID 605: IncrementBusyCount called.
#Event ID 606: DecrementBusyCount called.
#Event ID 701: ServiceChannelOpen started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "701",
"version": "0",
"level": "4",
"task": "2577",
"opcode": "1",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.494289900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fcff2a0b-f8d0-44a1-9ab2-8fe8ebc88bf4}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 702: ServiceChannelOpen completed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "702",
"version": "0",
"level": "4",
"task": "2577",
"opcode": "2",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.494292400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fcff2a0b-f8d0-44a1-9ab2-8fe8ebc88bf4}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 703: ServiceChannelCall started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "703",
"version": "0",
"level": "4",
"task": "2576",
"opcode": "1",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.483733900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{d0302fac-41f0-4eb2-9a47-143bb68642d5}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 704: ServiceChannel asynchronous calls started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 709: Message dispatching started.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "709",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "49",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.494301700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 710: Start authentication for message dispatching
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 711: Start authorization for message dispatching
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "711",
"version": "0",
"level": "5",
"task": "2533",
"opcode": "48",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.494332600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 712: Message dispatching completed
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "712",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "50",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.498184700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 715: ServiceChannel Open Start.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "715",
"version": "0",
"level": "4",
"task": "2514",
"opcode": "14",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.483833400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{aca24a28-f099-40ed-bfed-5272eec6c576}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 716: ServiceChannel Open Stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "716",
"version": "0",
"level": "4",
"task": "2514",
"opcode": "15",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.493346800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{aca24a28-f099-40ed-bfed-5272eec6c576}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1001: WorkflowInstance Id: 'data1' has completed in the Closed state.
#Event ID 1002: WorkflowApplication Id: 'data1' was terminated.
#Event ID 1003: WorkflowInstance Id: 'data1' has completed in the Canceled state.
#Event ID 1004: WorkflowInstance Id: 'data1' was aborted with an exception.
#Event ID 1005: WorkflowApplication Id: 'data1' went idle.
#Event ID 1006: WorkflowInstance Id: 'data1' has encountered an unhandled exception.
#Description
WorkflowInstance Id: 'data1' has encountered an unhandled exception. The exception originated from Activity 'data2', DisplayName: 'data3'. The following action will be taken: data4.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 1008: WorkflowInstance Id: 'data1' was Unloaded.
#Event ID 1009: Parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3' scheduled child Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
#Event ID 1010: Activity 'data1', DisplayName: 'data2', InstanceId: 'data3' has completed in the 'data4' state.
#Event ID 1011: An ExecuteActivityWorkItem has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1012: Starting execution of an ExecuteActivityWorkItem for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1013: An ExecuteActivityWorkItem has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1014: A CompletionWorkItem has been scheduled for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
A CompletionWorkItem has been scheduled for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. Completed Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
AppDomain UnicodeString |
Event ID 1015: Starting execution of a CompletionWorkItem for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
Starting execution of a CompletionWorkItem for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. Completed Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
AppDomain UnicodeString |
Event ID 1016: A CompletionWorkItem has completed for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
A CompletionWorkItem has completed for parent Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. Completed Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
AppDomain UnicodeString |
Event ID 1017: A CancelActivityWorkItem has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1018: Starting execution of a CancelActivityWorkItem for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1019: A CancelActivityWorkItem has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1020: A Bookmark has been created for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'.
#Description
A Bookmark has been created for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'. BookmarkName: data3, BookmarkScope: data4.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
AppDomain UnicodeString |
Event ID 1021: A BookmarkWorkItem has been scheduled for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'.
#Description
A BookmarkWorkItem has been scheduled for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'. BookmarkName: data3, BookmarkScope: data4.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
AppDomain UnicodeString |
Event ID 1022: Starting execution of a BookmarkWorkItem for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'.
#Description
Starting execution of a BookmarkWorkItem for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'. BookmarkName: data3, BookmarkScope: data4.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
AppDomain UnicodeString |
Event ID 1023: A BookmarkWorkItem has completed for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'.
#Description
A BookmarkWorkItem has completed for Activity 'BookmarkScope', DisplayName: 'data1', InstanceId: 'data2'. BookmarkName: data3, BookmarkScope: data4.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
AppDomain UnicodeString |
Event ID 1024: A BookmarkScope has been created: data1.
#Event ID 1025: The BookmarkScope that had TemporaryId: 'data1' has been initialized with Id: 'data2'.
#Event ID 1026: A TransactionContextWorkItem has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1027: Starting execution of a TransactionContextWorkItem for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1028: A TransactionContextWorkItem has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1029: A FaultWorkItem has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
A FaultWorkItem has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. The exception was propagated from Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 1030: Starting execution of a FaultWorkItem for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
Starting execution of a FaultWorkItem for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. The exception was propagated from Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 1031: A FaultWorkItem has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
A FaultWorkItem has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. The exception was propagated from Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 1032: A runtime work item has been scheduled for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1033: Starting execution of a runtime work item for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1034: A runtime work item has completed for Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Event ID 1035: The runtime transaction has been set by Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'.
#Description
The runtime transaction has been set by Activity 'data1', DisplayName: 'data2', InstanceId: 'data3'. Execution isolated to Activity 'data4', DisplayName: 'data5', InstanceId: 'data6'.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
data3 UnicodeString | |
data4 UnicodeString | |
data5 UnicodeString | |
data6 UnicodeString | |
AppDomain UnicodeString |
Event ID 1036: Activity 'data1', DisplayName: 'data2', InstanceId: 'data3' has scheduled completion of the runtime transaction.
#Event ID 1037: The runtime transaction has completed with the state 'data1'.
#Event ID 1040: In argument 'data1' on Activity 'data2', DisplayName: 'data3', InstanceId: 'data4' has been bound with value: data5.
#Event ID 1041: WorkflowApplication Id: 'data1' is idle and persistable.
#Event ID 1101: WorkflowInstance Id: 'Id' E2E Activity.
#Event ID 1102: WorkflowInstance Id: 'Id' E2E Activity.
#Event ID 1103: WorkflowInstance Id: 'Id' E2E Activity.
#Event ID 1104: WorkflowInstance Id: 'Id' E2E Activity.
#Event ID 1124: InvokeMethod 'data1' - method is Static.
#Event ID 1125: InvokeMethod 'data1' - method is not Static.
#Event ID 1126: An exception was thrown in the method called by the activity 'data1'.
#Event ID 1131: InvokeMethod 'data1' - method uses asynchronous pattern of 'data2' and 'data3'.
#Event ID 1132: InvokeMethod 'data1' - method does not use asynchronous pattern.
#Event ID 1140: Flowchart 'data1' - Start has been scheduled.
#Event ID 1141: Flowchart 'data1' - was executed with no Nodes.
#Event ID 1143: Flowchart 'data1'/FlowStep - Next node is null.
#Event ID 1146: Flowchart 'data1'/FlowSwitch - Case 'data2' was selected.
#Event ID 1147: Flowchart 'data1'/FlowSwitch - Default Case was selected.
#Event ID 1148: Flowchart 'data1'/FlowSwitch - could find neither a Case activity nor a Default Case matching the Expression result.
#Event ID 1223: The Switch activity 'data1' could not find a Case activity matching the Expression result.
#Event ID 1400: data1.
#Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1400",
"version": "0",
"level": "2",
"task": "2596",
"opcode": "0",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:32:51.515060000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f3bc138c-5a6a-4c0b-96a0-fb45a3d794a5}"
},
"execution": {
"process_id": "7780",
"thread_id": "14132"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"data1": "A newly accepted connection did not receive initialization data from the sender within the configured ChannelInitializationTimeout (00:00:30). As a result, the connection will be aborted. If you are on a highly congested network, or your sending machine is heavily loaded, consider increasing this value or load-balancing your server.",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1402: msg Connection pool key: key.
#Message #
Fields #
| Name | Description |
|---|---|
msg UnicodeString | |
key UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1402",
"version": "0",
"level": "2",
"task": "2596",
"opcode": "0",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.483892800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"msg": "A connection has exceeded the idle timeout of this connection pool (00:02:00) and been closed.",
"key": "[LOCALHOST, 1500]",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1403: msg Connection pool key: key.
#Event ID 1423: Negotiate token authenticator state cache ratio: cur/max.
#Event ID 1424: Security session ratio: Security_session_ratio/cur.
#Event ID 1430: Pending connections ratio: cur/max.
#Message #
Fields #
| Name | Description |
|---|---|
cur Int32 | |
max Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1430",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:29:50.489050700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{a4cd1ab9-04c0-43f1-ba00-237da5991559}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"cur": "1",
"max": "168",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1431: Concurrent calls ratio: cur/max.
#Message #
Fields #
| Name | Description |
|---|---|
cur Int32 | |
max Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1431",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:29:50.494175100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5ab13fb1-eddd-4703-b6a8-cc26fc39c8e5}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"cur": "1",
"max": "3136",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1432: Concurrent sessions ratio: cur/max.
#Message #
Fields #
| Name | Description |
|---|---|
cur Int32 | |
max Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1432",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:29:50.489387400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "7796"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"cur": "1",
"max": "19600",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1433: Outbound connections per endpoint ratio: cur/max.
#Message #
Fields #
| Name | Description |
|---|---|
cur Int32 | |
max Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1433",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:29:50.483853300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"cur": "0",
"max": "10",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1436: Pending messages per channel ratio: Pending_messages_per_channel_ratio/cur.
#Event ID 1438: Concurrent instances ratio: cur/max.
#Message #
Fields #
| Name | Description |
|---|---|
cur Int32 | |
max Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1438",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:30:19.363264500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{81bb4176-a5ae-476a-93c3-dd922ce34e3f}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"cur": "1",
"max": "532",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 1442: Receive retry count reached on MSMQ message with id 'data1'.
#Event ID 1443: Max retry cycles exceeded on MSMQ message with id 'data1'.
#Event ID 1445: Created new 'itemTypeName'.
#Message #
Fields #
| Name | Description |
|---|---|
itemTypeName UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "1445",
"version": "0",
"level": "5",
"task": "2560",
"opcode": "0",
"keywords": 2305843009217888256,
"time_created": "2026-03-15T23:29:50.498334200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"itemTypeName": "BinaryBufferedMessageData",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 1446: Created new 'itemTypeName'.
#Event ID 2024: InternalCacheMetadata started on activity 'id'.
#Event ID 2025: InternalCacheMetadata stopped on activity 'id'.
#Event ID 2026: Compiling VB expression 'expr'.
#Event ID 2027: CacheRootMetadata started on activity 'activityName'.
#Event ID 2028: CacheRootMetadata stopped on activity activityName.
#Event ID 2576: The TryCatch activity 'data1' has caught an exception of type 'data2'.
#Event ID 2577: A child activity of the TryCatch activity 'data1' has thrown an exception during cancelation.
#Event ID 2578: A Catch or Finally activity that is associated with the TryCatch activity 'data1' has thrown an exception.
#Event ID 3300: Failed to Complete TypeName.
#Event ID 3301: Failed to Abandon TypeName.
#Event ID 3302: Receive Context faulted.
#Fields #
| Name | Description |
|---|---|
EventSource UnicodeString | |
AppDomain UnicodeString |
Event ID 3303: TypeName was Abandoned with exception ExceptionToString.
#Event ID 3305: Number of cached channel factories is: 'Count'.
#Event ID 3307: Used matching channel factory found in cache.
#Fields #
| Name | Description |
|---|---|
EventSource UnicodeString | |
AppDomain UnicodeString |
Event ID 3308: Not using channel factory from cache, i.
#Description
Not using channel factory from cache, i.e. caching disabled for instance.
Message #
Fields #
| Name | Description |
|---|---|
EventSource UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3308",
"version": "0",
"level": "4",
"task": "2511",
"opcode": "0",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.483138500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"EventSource": "Microsoft.IdentityServer.PolicyModel.Client.PolicyStoreClient/5896758",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3309: Query composition using 'TypeName' was executed on the Request Uri: 'Uri'.
#Event ID 3310: The 'OperationName' operation was dispatched with errors.
#Event ID 3311: The 'OperationName' operation was dispatched successfully.
#Message #
Fields #
| Name | Description |
|---|---|
OperationName UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3311",
"version": "0",
"level": "4",
"task": "2533",
"opcode": "2",
"keywords": 2305843009213693956,
"time_created": "2026-03-15T23:29:50.498190000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"OperationName": "TryAcquireTaskOwnershipLease",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3312: A message with size 'Size' bytes was read by the encoder.
#Message #
Fields #
| Name | Description |
|---|---|
Size Int32 | |
EventSource UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3312",
"version": "0",
"level": "4",
"task": "2555",
"opcode": "2",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.494139500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Size": "95",
"EventSource": "System.ServiceModel.Channels.BinaryMessageEncoderFactory+BinaryMessageEncoder/36920218",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3313: A message with size 'Size' bytes was written by the encoder.
#Message #
Fields #
| Name | Description |
|---|---|
Size Int32 | |
EventSource UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3313",
"version": "0",
"level": "4",
"task": "2556",
"opcode": "2",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.493611600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Size": "381",
"EventSource": "System.ServiceModel.Channels.BinaryMessageEncoderFactory+BinaryMessageEncoder/16754362",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3314: Session aborting for idle channel to uri:'RemoteAddress'.
#Event ID 3319: Connection accept started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3319",
"version": "0",
"level": "5",
"task": "2521",
"opcode": "1",
"keywords": 1152921504606847488,
"time_created": "2026-03-15T23:29:50.489056900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{df7d849a-75b7-4340-9cea-e51ef07a2950}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3320: ListenerId:ListenerHashCode accepted SocketId:SocketHashCode.
#Message #
Fields #
| Name | Description |
|---|---|
ListenerHashCode Int32 | |
SocketHashCode Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3320",
"version": "0",
"level": "5",
"task": "2521",
"opcode": "2",
"keywords": 1152921504606847488,
"time_created": "2026-03-15T23:29:50.488868900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{a4cd1ab9-04c0-43f1-ba00-237da5991559}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ListenerHashCode": "18819585",
"SocketHashCode": "44246512",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3321: Pool for PoolKey has no available connection and busy busy connections.
#Message #
Fields #
| Name | Description |
|---|---|
PoolKey UnicodeString | |
busy Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3321",
"version": "0",
"level": "5",
"task": "2522",
"opcode": "0",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.488176900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"PoolKey": "[LOCALHOST, 1500]",
"busy": "1",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3322: Dispatcher started deserialization the request message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3322",
"version": "0",
"level": "5",
"task": "2540",
"opcode": "1",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.496440100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3323: Dispatcher completed deserialization the request message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3323",
"version": "0",
"level": "5",
"task": "2540",
"opcode": "2",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.496452500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3324: Dispatcher started serialization of the reply message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3324",
"version": "0",
"level": "5",
"task": "2541",
"opcode": "1",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.497908600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3325: Dispatcher completed serialization of the reply message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3325",
"version": "0",
"level": "5",
"task": "2541",
"opcode": "2",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.497930000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3326: Client request serialization started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3326",
"version": "0",
"level": "5",
"task": "2542",
"opcode": "1",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.483738700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{d0302fac-41f0-4eb2-9a47-143bb68642d5}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3327: Client completed serialization of the request message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3327",
"version": "0",
"level": "5",
"task": "2542",
"opcode": "2",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.483742500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{d0302fac-41f0-4eb2-9a47-143bb68642d5}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3328: Client started deserializing the reply message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3328",
"version": "0",
"level": "5",
"task": "2539",
"opcode": "1",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.498396700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3329: Client completed deserializing the reply message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3329",
"version": "0",
"level": "5",
"task": "2539",
"opcode": "2",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.498404200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3332: SecurityTokenProvider opening completed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3335: Service instance retrieval started.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3335",
"version": "0",
"level": "5",
"task": "2584",
"opcode": "1",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.496393300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3336: Service instance retrieved.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3336",
"version": "0",
"level": "5",
"task": "2584",
"opcode": "2",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.496395100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3337: ChannelHandlerId:ChannelId - Message receive loop started.
#Message #
Fields #
| Name | Description |
|---|---|
ChannelId Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3337",
"version": "0",
"level": "5",
"task": "2513",
"opcode": "1",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.493270200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5ab13fb1-eddd-4703-b6a8-cc26fc39c8e5}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ChannelId": "9458587",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3338: ChannelHandlerId:ChannelId - Message receive loop stopped.
#Message #
Fields #
| Name | Description |
|---|---|
ChannelId Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3338",
"version": "0",
"level": "5",
"task": "2513",
"opcode": "2",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.494166800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{5ab13fb1-eddd-4703-b6a8-cc26fc39c8e5}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ChannelId": "9458587",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3339: ChannelFactory created.
#Fields #
| Name | Description |
|---|---|
EventSource UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3339",
"version": "0",
"level": "5",
"task": "2512",
"opcode": "0",
"keywords": 1152921504606846980,
"time_created": "2026-03-15T23:29:50.483605300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"EventSource": "System.ServiceModel.ChannelFactory`1[Microsoft.IdentityServer.Protocols.PolicyStore.IPolicyStore]/60375305",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3340: Pipe connection accept started on uri .
#Event ID 3342: Connection establishment started for Key.
#Message #
Fields #
| Name | Description |
|---|---|
Key UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3342",
"version": "0",
"level": "5",
"task": "2519",
"opcode": "1",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.483837400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Key": "net.tcp://localhost:1500/policy",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3343: Connection established.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3343",
"version": "0",
"level": "5",
"task": "2519",
"opcode": "2",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.493342900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3345: Session preamble for 'Via' understood.
#Message #
Fields #
| Name | Description |
|---|---|
Via UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3345",
"version": "0",
"level": "5",
"task": "2519",
"opcode": "0",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.489342200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "7796"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Via": "net.tcp://localhost:1500/policy",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3346: Connection reader sending fault 'FaultString'.
#Event ID 3348: Service host faulted.
#Fields #
| Name | Description |
|---|---|
EventSource UnicodeString | |
AppDomain UnicodeString |
Event ID 3349: Listener opening for 'Uri'.
#Event ID 3351: Server max pooled connections quota reached.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3352: SocketId:SocketId to remote address Uri timed out.
#Event ID 3353: SocketId:SocketId to remote address Uri had a connection reset error.
#Message #
Fields #
| Name | Description |
|---|---|
SocketId Int32 | |
Uri UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3353",
"version": "0",
"level": "3",
"task": "2519",
"opcode": "0",
"keywords": 2305843009213694464,
"time_created": "2026-03-15T23:29:50.487223900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketId": "49129953",
"Uri": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3354: Service security negotiation completed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3355: Security negotiation processing failed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3358: Socket duplicated for Uri.
#Event ID 3359: Security impersonation succeeded.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3359",
"version": "0",
"level": "5",
"task": "2572",
"opcode": "0",
"keywords": 1152921504606846992,
"time_created": "2026-03-15T23:30:19.363562100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{11da94e5-a08b-4071-9f06-9cc69bdc3867}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 3364: SharedListenerProxy registration started for uri 'Uri'.
#Event ID 3366: SharedListenerProxy register failed with status 'Status'.
#Message #
Fields #
| Name | Description |
|---|---|
Status UnicodeString | NTSTATUS reference |
AppDomain UnicodeString |
Event ID 3370: BinaryMessageEncoder started encoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3370",
"version": "0",
"level": "5",
"task": "2556",
"opcode": "1",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.493364200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{1fe3f4e0-acac-428c-ac3c-63cdb7478c5b}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3371: MtomMessageEncoder started encoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3372: TextMessageEncoder started encoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3373: BinaryMessageEncoder started decoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3373",
"version": "0",
"level": "5",
"task": "2555",
"opcode": "1",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.494031200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "14764"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3374: MtomMessageEncoder started decoding the message.
#Event ID 3375: TextMessageEncoder started decoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3376: Http transport started receiving a message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3377: SocketId:SocketId read 'Size' bytes read from 'Endpoint'.
#Message #
Fields #
| Name | Description |
|---|---|
SocketId Int32 | |
Size Int32 | |
Endpoint UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3377",
"version": "0",
"level": "5",
"task": "2599",
"opcode": "2",
"keywords": 1152921504606847488,
"time_created": "2026-03-15T23:29:50.489738400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{6d527f13-9021-4c84-9477-5c2595600833}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketId": "10675717",
"Size": "1",
"Endpoint": "::1:1500",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3378: SocketId:SocketId read 'Size' bytes read from 'Endpoint'.
#Message #
Fields #
| Name | Description |
|---|---|
SocketId Int32 | |
Size Int32 | |
Endpoint UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3378",
"version": "0",
"level": "5",
"task": "2599",
"opcode": "2",
"keywords": 1152921504606847488,
"time_created": "2026-03-15T23:29:50.489301600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "7780",
"thread_id": "7796"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketId": "44246512",
"Size": "63",
"Endpoint": "::1:51230",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3379: SocketId:SocketId writing 'Size' bytes to 'Endpoint'.
#Message #
Fields #
| Name | Description |
|---|---|
SocketId Int32 | |
Size Int32 | |
Endpoint UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3379",
"version": "0",
"level": "5",
"task": "2600",
"opcode": "1",
"keywords": 1152921504606847488,
"time_created": "2026-03-15T23:29:50.488777000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{6d527f13-9021-4c84-9477-5c2595600833}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketId": "10675717",
"Size": "40",
"Endpoint": "::1:1500",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3380: SocketId:SocketId writing 'Size' bytes to 'Endpoint'.
#Event ID 3381: SessionId:SessionId acknowledgement sent.
#Event ID 3382: SessionId:SessionId reconnecting.
#Event ID 3383: SessionId:SessionId faulted.
#Event ID 3384: WindowsStreamSecurity initiating security upgrade.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3384",
"version": "0",
"level": "5",
"task": "2587",
"opcode": "115",
"keywords": 2305843009213693968,
"time_created": "2026-03-15T23:29:50.489746300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{6d527f13-9021-4c84-9477-5c2595600833}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3385: Windows streaming security on accepting upgrade.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3385",
"version": "0",
"level": "5",
"task": "2587",
"opcode": "114",
"keywords": 2305843009213693968,
"time_created": "2026-03-15T23:29:50.489756300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fb0a7822-7b4b-45f4-bf59-3e1c0df8827e}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3386: SocketId:SocketId is aborting.
#Message #
Fields #
| Name | Description |
|---|---|
SocketId Int32 | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3386",
"version": "0",
"level": "3",
"task": "2520",
"opcode": "0",
"keywords": 2305843009213694464,
"time_created": "2026-03-15T23:29:50.488076600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f2b7ffc9-ec9a-496e-aa19-4c35d3b3e1f3}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"SocketId": "49129953",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3389: Client sending preamble start.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3389",
"version": "0",
"level": "5",
"task": "2515",
"opcode": "1",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.488737000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{6d527f13-9021-4c84-9477-5c2595600833}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3390: Client sending preamble stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "3390",
"version": "0",
"level": "5",
"task": "2515",
"opcode": "2",
"keywords": 1152921504606851072,
"time_created": "2026-03-15T23:29:50.493340500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{6d527f13-9021-4c84-9477-5c2595600833}"
},
"execution": {
"process_id": "7780",
"thread_id": "5228"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 3392: TransactionScope is being created with LocalIdentifier:'LocalId' and DistributedIdentifier:'Distributed'.
#Event ID 3393: A streamed message was read by the encoder.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3394: A streamed message was written by the encoder.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3395: A message was written asynchronously by the encoder.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3396: BufferId:BufferId completed writing 'Size' bytes to underlying stream.
#Event ID 3397: A message was written asynchronously by the encoder.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3398: Pipe shared memory created at 'sharedMemoryName' .
#Event ID 3399: NamedPipe 'pipeName' created.
#Event ID 3407: Http message handler started processing the inbound request.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3408: Http message handler started processing the inbound request asynchronously.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3409: Http message handler completed processing an inbound request.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3414: Http message handler completed processing the response.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3415: WebSocket connection request to 'remoteAddress' send start.
#Event ID 3416: WebSocketId:WebSocketId connection request sent.
#Event ID 3418: WebSocketId:WebSocketId connection accepted.
#Event ID 3419: WebSocket connection declined with status code 'errorMessage'.
#Event ID 3420: WebSocket connection request failed: 'errorMessage'.
#Event ID 3421: WebSocketId:WebSocketId connection is aborted.
#Event ID 3422: WebSocketId:WebSocketId writing 'websocketId' bytes to 'byteCount'.
#Event ID 3423: WebSocketId:WebSocketId asynchronous write stop.
#Event ID 3424: WebSocketId:WebSocketId read start.
#Event ID 3425: WebSocketId:WebSocketId read 'websocketId' bytes from 'byteCount'.
#Event ID 3426: WebSocketId:WebSocketId sending close message to 'websocketId' with close status 'remoteAddress'.
#Event ID 3427: WebSocketId:WebSocketId sending close output message to 'websocketId' with close status 'remoteAddress'.
#Event ID 3428: WebSocketId:WebSocketId connection closed.
#Event ID 3429: WebSocketId:WebSocketId connection close message received with status 'websocketId'.
#Event ID 3430: Using the WebSocketVersion from a client WebSocket factory of type 'clientWebSocketFactoryType'.
#Event ID 3431: Creating the client WebSocket with a factory of type 'clientWebSocketFactoryType'.
#Event ID 3501: ContractDescription with Name='data1' and Namespace='data2' has been inferred from WorkflowService.
#Event ID 3502: OperationDescription with Name='data1' in contract 'data2' has been inferred from WorkflowService.
#Event ID 3503: A duplicate CorrelationQuery was found with Where='data1'.
#Event ID 3507: A service endpoint has been added for address 'data1', binding 'data2', and contract 'data3'.
#Event ID 3508: TrackingProfile 'TrackingProfile' for the ActivityDefinitionId 'ActivityDefinitionId' not found.
#Description
TrackingProfile 'TrackingProfile' for the ActivityDefinitionId 'ActivityDefinitionId' not found. Either the TrackingProfile is not found in the config file or the ActivityDefinitionId does not match.
Message #
Fields #
| Name | Description |
|---|---|
TrackingProfile UnicodeString | |
ActivityDefinitionId UnicodeString | |
AppDomain UnicodeString |
Event ID 3550: Operation 'data1' cannot be performed at this time.
#Event ID 3551: Operation 'data2' on service instance 'data1' cannot be performed at this time.
#Event ID 3552: The throttle 'MaxPendingMessagesPerChannel' limit of 'limit' was hit.
#Event ID 3557: The call to EndCommit on the CommittableTransaction with id = 'data1' threw a TransactionException with the following message: 'data2'.
#Event ID 3560: Available memory (bytes): Available_memory_bytes.
#Event ID 3561: The service could not be activated.
#Event ID 3800: The Routing Service is closing client 'data1'.
#Event ID 3801: Routing Service client 'data1' has faulted.
#Event ID 3802: A Routing Service one way message is completing.
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 3803: The Routing Service failed while processing a message on the endpoint with address 'data1'.
#Event ID 3804: The Routing Service is creating a client for endpoint: 'data1'.
#Event ID 3805: The Routing Service is configured with RouteOnHeadersOnly: data1, SoapProcessingEnabled: data2, EnsureOrderedDispatch: data3.
#Event ID 3807: A Routing Service request reply message is completing.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3809: The Routing Service routed message with ID: 'data1' to data2 endpoint lists.
#Event ID 3810: A new RoutingConfiguration has been applied to the Routing Service.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3815: The Routing Service is processing a message with ID: 'data1', Action: 'data2', Inbound URL: 'data3' Received in Transaction: data4.
#Event ID 3816: The Routing Service is transmitting the message with ID: 'data1' [operation data2] to 'data3'.
#Event ID 3817: The Routing Service is committing a transaction with id: 'data1'.
#Event ID 3818: Routing Service component data1 encountered a duplex callback exception.
#Event ID 3819: Routing Service message with ID: 'data1' [operation data2] moved to backup endpoint 'data3'.
#Event ID 3821: The Routing Service failed while closing outbound client 'data1'.
#Event ID 3822: The Routing Service is sending back a response message with Action 'data1'.
#Event ID 3823: The Routing Service is sending back a Fault response message with Action 'data1'.
#Event ID 3824: The Routing Service is calling ReceiveContext.
#Event ID 3825: The Routing Service is calling ReceiveContext.
#Event ID 3826: The Routing Service will send messages using existing transaction 'data1'.
#Event ID 3827: The Routing Service failed while sending to 'data1'.
#Event ID 3828: Routing Service MessageFilterTable Match Start.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3829: Routing Service MessageFilterTable Match Stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 3830: The Routing Service is calling abort on channel: 'data1'.
#Event ID 3831: The Routing Service has handled an exception.
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 3832: The Routing Service successfully transmitted Message with ID: 'data1 [operation data2] to 'data3'.
#Event ID 4001: Transport listener session received with via 'via'.
#Event ID 4002: FailFastException.
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4003: Service start pipe error.
#Fields #
| Name | Description |
|---|---|
Endpoint UnicodeString | |
AppDomain UnicodeString |
Event ID 4010: Session dispatch for 'Uri' failed since pending session queue is full with 'count' pending items.
#Event ID 4012: Message queue registration aborted with status:'Status' for uri:'Uri'.
#Message #
Fields #
| Name | Description |
|---|---|
Status UnicodeString | NTSTATUS reference |
Uri UnicodeString | |
AppDomain UnicodeString |
Event ID 4013: Message queue unregister succeeded for uri:'Uri'.
#Event ID 4014: Message queue registration for uri:'Uri' failed with status:'Status'.
#Message #
Fields #
| Name | Description |
|---|---|
Uri UnicodeString | |
Status UnicodeString | NTSTATUS reference |
AppDomain UnicodeString |
Event ID 4015: Message queue registration completed for uri 'Uri'.
#Event ID 4016: Message queue failed duplicating socket.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4020: Tcp transport listener starting to listen on uri:'Uri'.
#Event ID 4022: Error Code:Error_Code.
#Event ID 4023: Was closing all listener channel instances completed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4024: Error Code:Error_Code.
#Event ID 4025: Error Code:Error_Code.
#Event ID 4028: Pipe transport listener listening start on uri:Uri.
#Event ID 4029: Pipe transport listener listening stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4035: Pending session queue ratio: Pending_session_queue_ratio/curr.
#Event ID 4201: End SQL command execution: End_SQL_command_execution.
#Event ID 4202: Starting SQL command execution: Starting_SQL_command_execution.
#Event ID 4203: Failed to extend lock expiration, lock expiration already passed or the lock owner was deleted.
#Event ID 4205: Command failed: Command_failed.
#Event ID 4206: Encountered exception data1 while attempting to unlock instance.
#Event ID 4207: Giving up retrying a SQL command as the maximum number of retries have been performed.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4208: Retrying a SQL command due to SQL error number data1.
#Event ID 4209: Timeout trying to open a SQL connection.
#Event ID 4210: Caught SQL Exception number data1 message data2.
#Event ID 4212: Timeout trying to acquire the instance lock.
#Event ID 4213: Detection of runnable instances failed due to the following exception
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4214: Recovering instance locks failed due to the following exception
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4600: Message could not be logged as it exceeds the ETW event size
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4801: The DiscoveryClient created inside DiscoveryClientChannel failed to close and hence has been aborted.
#Fields #
| Name | Description |
|---|---|
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4802: A ProtocolException was suppressed while closing the DiscoveryClient.
#Event ID 4803: The DiscoveryClient received a multicast suppression message from a DiscoveryProxy.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4804: A discoveryMessageName message with messageId='messageId' was dropped by the DiscoveryClient because the corresponding discoveryOperationName operation was completed.
#Event ID 4805: A messageType message with messageId='messageId' was dropped because it had invalid content.
#Event ID 4806: A discoveryMessageName message with messageId='messageId' and relatesTo='relatesTo' was dropped by the DiscoveryClient because either the corresponding discoveryOperationName operation was complete...
#Description
A discoveryMessageName message with messageId='messageId' and relatesTo='relatesTo' was dropped by the DiscoveryClient because either the corresponding discoveryOperationName operation was completed or the relatesTo value is invalid.
Message #
Fields #
| Name | Description |
|---|---|
discoveryMessageName UnicodeString | |
messageId UnicodeString | |
relatesTo UnicodeString | |
discoveryOperationName UnicodeString | |
AppDomain UnicodeString |
Event ID 4807: A discovery request message with messageId='messageId' was dropped because it had an invalid ReplyTo address.
#Event ID 4808: A messageType message was dropped because it did not have any content.
#Event ID 4809: A messageType message was dropped because the message header did not contain the required MessageId property.
#Event ID 4810: A discoveryMessageName message with messageId='messageId' was dropped by the DiscoveryClient because it did not have the DiscoveryMessageSequence property.
#Event ID 4811: A discoveryMessageName message with messageId='messageId' was dropped by the DiscoveryClient because the message header did not contain the required RelatesTo property.
#Event ID 4812: A discovery request message with messageId='messageId' was dropped because it did not have a ReplyTo address.
#Event ID 4813: A messageType message with messageId='messageId' was dropped because it was a duplicate.
#Event ID 4814: The discoverability of endpoint with EndpointAddress='endpointAddress' and ListenUri='listenUri' has been disabled.
#Event ID 4815: The discoverability of endpoint with EndpointAddress='endpointAddress' and ListenUri='listenUri' has been enabled.
#Event ID 4816: A Find operation was initiated in the DiscoveryClientChannel to discover endpoint(s).
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 4817: The DiscoveryClientChannel failed to create the channel with a discovered endpoint with EndpointAddress='.
#Description
The DiscoveryClientChannel failed to create the channel with a discovered endpoint with EndpointAddress='endpointAddress' and Via='via'. The DiscoveryClientChannel will now attempt to use the next available discovered endpoint.
Message #
Fields #
| Name | Description |
|---|---|
endpointAddress UnicodeString | |
via UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4818: The DiscoveryClientChannel failed to open the channel with a discovered endpoint with EndpointAddress='.
#Description
The DiscoveryClientChannel failed to open the channel with a discovered endpoint with EndpointAddress='endpointAddress' and Via='via'. The DiscoveryClientChannel will now attempt to use the next available discovered endpoint.
Message #
Fields #
| Name | Description |
|---|---|
endpointAddress UnicodeString | |
via UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Event ID 4819: The DiscoveryClientChannel successfully discovered an endpoint and opened the channel using it.
#Event ID 4820: The SynchronizationContext has been reset to its original value of synchronizationContextType by DiscoveryClientChannel.
#Event ID 4821: The SynchronizationContext has been set to null by DiscoveryClientChannel before initiating the Find operation.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 5001: DataContract serialize SurrogateType with surrogates start.
#Event ID 5002: DataContract serialize with surrogates stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 5003: DataContract deserialize SurrogateType with surrogates start.
#Event ID 5004: DataContract deserialize with surrogates stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 5005: ImportKnownTypes start.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5005",
"version": "0",
"level": "5",
"task": "2547",
"opcode": "1",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.049562700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5006: ImportKnownTypes stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5006",
"version": "0",
"level": "5",
"task": "2547",
"opcode": "2",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.051207900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5007: DataContract resolver resolving TypeName start.
#Event ID 5008: DataContract generate Kind writer for TypeName start.
#Message #
Fields #
| Name | Description |
|---|---|
Kind UnicodeString | |
TypeName UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5008",
"version": "0",
"level": "5",
"task": "2544",
"opcode": "1",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.051265600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Kind": "Collection",
"TypeName": "System.String[]",
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5009: DataContract generate writer stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5009",
"version": "0",
"level": "5",
"task": "2544",
"opcode": "2",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.054617100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5010: DataContract generate Kind reader for TypeName start.
#Message #
Fields #
| Name | Description |
|---|---|
Kind UnicodeString | |
TypeName UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5010",
"version": "0",
"level": "5",
"task": "2543",
"opcode": "1",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.187432400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"Kind": "Collection",
"TypeName": "schemas.microsoft.com._2008._1.ActiveDirectory.CustomActions.ActiveDirectoryDomainController[]",
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5011: DataContract generation stop.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5011",
"version": "0",
"level": "5",
"task": "2543",
"opcode": "2",
"keywords": 1152921504606846978,
"time_created": "2026-03-15T23:30:25.199340100+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{f76b74ad-e2a7-4365-b905-7714c206fadf}"
},
"execution": {
"process_id": "8484",
"thread_id": "2808"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"AppDomain": "DefaultDomain"
},
"message": ""
}
Event ID 5012: Json generate Kind reader for TypeName start.
#Event ID 5014: Json generate Kind writer for TypeName start.
#Event ID 5016: Generate Xml serializable for 'DCType' start.
#Event ID 5203: JsonMessageEncoder started decoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 5204: JsonMessageEncoder started encoding the message.
#Fields #
| Name | Description |
|---|---|
AppDomain UnicodeString |
Event ID 5402: SecurityToken (type 'tokenType' and id 'tokenID') validation started.
#Message #
Fields #
| Name | Description |
|---|---|
tokenType UnicodeString | |
tokenID UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5402",
"version": "0",
"level": "5",
"task": "2612",
"opcode": "0",
"keywords": 1152921504606846992,
"time_created": "2026-03-15T23:29:50.492472600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fb0a7822-7b4b-45f4-bf59-3e1c0df8827e}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"tokenType": "System.IdentityModel.Tokens.WindowsSecurityToken",
"tokenID": "uuid-d684443e-9e7d-4f56-8a9b-cc2a6b01c173-61",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 5403: SecurityToken (type 'tokenType' and id 'tokenID') validation succeeded.
#Message #
Fields #
| Name | Description |
|---|---|
tokenType UnicodeString | |
tokenID UnicodeString | |
HostReference UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "5403",
"version": "0",
"level": "5",
"task": "2612",
"opcode": "0",
"keywords": 1152921504606846992,
"time_created": "2026-03-15T23:29:50.492480800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{fb0a7822-7b4b-45f4-bf59-3e1c0df8827e}"
},
"execution": {
"process_id": "7780",
"thread_id": "8452"
},
"channel": "Microsoft-Windows-Application Server-Applications/Debug",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"tokenType": "System.IdentityModel.Tokens.WindowsSecurityToken",
"tokenID": "uuid-d684443e-9e7d-4f56-8a9b-cc2a6b01c173-61",
"HostReference": "",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 5404: SecurityToken (type 'tokenType' and id 'tokenID') validation failed.
#Event ID 5405: Retrieval of issuer name:issuerName from tokenId:tokenID succeeded.
#Event ID 5406: Retrieval of issuer name from tokenId:tokenID failed.
#Event ID 5601: Federation message processing succeeded.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5602: Creating federation message from form post started.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5603: Creating federation message from form post succeeded.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5604: Reading session token from session cookie started.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5605: Reading session token from session cookie succeeded.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5606: Principal setting from session token started.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 5607: Principal setting from session token succeeded.
#Fields #
| Name | Description |
|---|---|
HostReference UnicodeString | |
AppDomain UnicodeString |
Event ID 39456: Size of tracking record RecordNumber exceeds maximum allowed by the ETW session for provider ProviderId.
#Event ID 39457: Tracking Record data1 raised to data2.
#Event ID 39458: Truncated tracking record RecordNumber written to ETW session with provider ProviderId.
#Event ID 39459: Tracking data Data extracted in activity Activity.
#Event ID 39460: The extracted argument/variable 'name' is not serializable.
#Event ID 57393: AppDomain unloading.
#Event ID 57394: Handling an exception.
#Description
Handling an exception. Exception details: data1.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "57394",
"version": "0",
"level": "4",
"task": "0",
"opcode": "0",
"keywords": 2305843009213759488,
"time_created": "2026-03-15T23:30:27.676114200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{bf62ba95-04a7-46ba-8a97-f026ab57ec47}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"data1": "System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'. ---> System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.ConnectionModeReader.GetConnectionMode()\n at System.ServiceModel.Channels.ConnectionDemuxer.OnConnectionModeKnownCore(ConnectionModeReader modeReader, Boolean isCached)",
"SerializedException": "<Exception><ExceptionType>System.ServiceModel.CommunicationException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.</Message><StackTrace> at System.ServiceModel.Channels.ConnectionModeReader.GetConnectionMode()\n at System.ServiceModel.Channels.ConnectionDemuxer.OnConnectionModeKnownCore(ConnectionModeReader modeReader, Boolean isCached)</StackTrace><ExceptionString>System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'. ---&amp;gt; System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.ConnectionModeReader.GetConnectionMode()\n at System.ServiceModel.Channels.ConnectionDemuxer.OnConnectionModeKnownCore(ConnectionModeReader modeReader, Boolean isCached)</ExceptionString><InnerException><Exception><ExceptionType>System.Net.Sockets.SocketException, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>An existing connection was forcibly closed by the remote host</Message><StackTrace> at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</StackTrace><ExceptionString>System.Net.Sockets.SocketException (0x80004005): An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</ExceptionString><NativeErrorCode>2746</NativeErrorCode></Exception></InnerException></Exception>",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 57395: An unexpected failure occurred.
#Event ID 57396: Throwing an exception.
#Description
Throwing an exception. Source: data1. Exception details: data2.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "57396",
"version": "0",
"level": "3",
"task": "0",
"opcode": "0",
"keywords": 2305843009213759488,
"time_created": "2026-03-15T23:30:27.675855200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{bf62ba95-04a7-46ba-8a97-f026ab57ec47}"
},
"execution": {
"process_id": "3912",
"thread_id": "12988"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"data1": "System.Runtime",
"data2": "System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '10675199.02:48:05.4775807'. ---> System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionStream.ReadAsyncResult.HandleIO(IConnection connection)\n at System.ServiceModel.Channels.ConnectionStream.IOAsyncResult.OnAsyncIOComplete(Object state)",
"SerializedException": "<Exception><ExceptionType>System.ServiceModel.CommunicationException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '10675199.02:48:05.4775807'.</Message><StackTrace> at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionStream.ReadAsyncResult.HandleIO(IConnection connection)\n at System.ServiceModel.Channels.ConnectionStream.IOAsyncResult.OnAsyncIOComplete(Object state)</StackTrace><ExceptionString>System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '10675199.02:48:05.4775807'. ---&amp;gt; System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionStream.ReadAsyncResult.HandleIO(IConnection connection)\n at System.ServiceModel.Channels.ConnectionStream.IOAsyncResult.OnAsyncIOComplete(Object state)</ExceptionString><InnerException><Exception><ExceptionType>System.Net.Sockets.SocketException, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>An existing connection was forcibly closed by the remote host</Message><StackTrace> at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</StackTrace><ExceptionString>System.Net.Sockets.SocketException (0x80004005): An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</ExceptionString><NativeErrorCode>2746</NativeErrorCode></Exception></InnerException></Exception>",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 57397: Unhandled exception.
#Event ID 57398: The system hit the limit set for throttle 'MaxConcurrentInstances'.
#Description
The system hit the limit set for throttle 'MaxConcurrentInstances'. Limit for this throttle was set to limit. Throttle value can be changed by modifying attribute 'maxConcurrentInstances' in serviceThrottle element or by modifying 'MaxConcurrentInstances' property on behavior ServiceThrottlingBehavior.
Message #
Fields #
| Name | Description |
|---|---|
limit Int32 | |
AppDomain UnicodeString |
Event ID 57399: Wrote to the EventLog.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 57400: Wrote to the EventLog.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 57401: Wrote to the EventLog.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 57402: Wrote to the EventLog.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 57403: Wrote to the EventLog.
#Fields #
| Name | Description |
|---|---|
ExtendedData UnicodeString | |
AppDomain UnicodeString |
Event ID 57404: Handling an exception.
#Event ID 57405: Handling an exception.
#Description
Handling an exception. Exception details: data1.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "C651F5F6-1C0D-492E-8AE1-B4EFD7C9D503",
"event_source_name": "",
"event_id": 57405,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 4611686018427453440,
"time_created": "2026-03-13T23:07:36.849516+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "FCDC6F25-76F3-4BC2-B0EB-7EFEBD19BD6C"
},
"execution": {
"process_id": 9844,
"thread_id": 11496
},
"channel": "Microsoft-Windows-Application Server-Applications/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1283"
}
},
"event_data": {
"data1": "Microsoft.IdentityModel.Tokens.FailedAuthenticationFaultException: ID3242: The security token could not be authenticated or authorized.\r\n at Microsoft.IdentityModel.ExceptionMapper.HandleSecurityTokenProcessingException(Exception ex)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.ValidateDelayedTokenHandlers(FederatedServiceCredentials serviceCreds, SecurityToken token)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.CheckAccessCore(OperationContext operationContext)\r\n at System.ServiceModel.Dispatcher.AuthorizationBehavior.Authorize(MessageRpc& rpc)\r\n at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage11(MessageRpc& rpc)\r\n at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)",
"SerializedException": "<Exception><ExceptionType>Microsoft.IdentityModel.Tokens.FailedAuthenticationFaultException, Microsoft.IdentityServer.IdentityModel, Version=10.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35</ExceptionType><Message>ID3242: The security token could not be authenticated or authorized.</Message><StackTrace> at Microsoft.IdentityModel.ExceptionMapper.HandleSecurityTokenProcessingException(Exception ex)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.ValidateDelayedTokenHandlers(FederatedServiceCredentials serviceCreds, SecurityToken token)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.CheckAccessCore(OperationContext operationContext)\r\n at System.ServiceModel.Dispatcher.AuthorizationBehavior.Authorize(MessageRpc&amp;amp; rpc)\r\n at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage11(MessageRpc&amp;amp; rpc)\r\n at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)</StackTrace><ExceptionString>Microsoft.IdentityModel.Tokens.FailedAuthenticationFaultException: ID3242: The security token could not be authenticated or authorized.\r\n at Microsoft.IdentityModel.ExceptionMapper.HandleSecurityTokenProcessingException(Exception ex)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.ValidateDelayedTokenHandlers(FederatedServiceCredentials serviceCreds, SecurityToken token)\r\n at Microsoft.IdentityServer.Service.SecurityTokenService.MSISIdentityModelAuthorizationManager.CheckAccessCore(OperationContext operationContext)\r\n at System.ServiceModel.Dispatcher.AuthorizationBehavior.Authorize(MessageRpc&amp;amp; rpc)\r\n at System.ServiceModel.Dispatcher.ImmutableDispatchRuntime.ProcessMessage11(MessageRpc&amp;amp; rpc)\r\n at System.ServiceModel.Dispatcher.MessageRpc.Process(Boolean isOperationContextSet)</ExceptionString></Exception>",
"AppDomain": "Microsoft.IdentityServer.ServiceHost.exe"
},
"message": ""
}
Event ID 57406: Handling an exception Exception details: data1.
#Event ID 57407: Throwing an exception.
#Event ID 57408: Unhandled exception.
#Event ID 57409: Throwing an exception.
#Description
Throwing an exception. Source: data1. Exception details: data2.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "57409",
"version": "0",
"level": "5",
"task": "0",
"opcode": "0",
"keywords": 2305843009213759488,
"time_created": "2026-03-15T23:30:27.675853200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{bf62ba95-04a7-46ba-8a97-f026ab57ec47}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"data1": "System.ServiceModel 4.0.0.0",
"data2": "System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'. ---> System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionModeReader.GetReadResult()\n at System.ServiceModel.Channels.ConnectionModeReader.ReadCallback(Object state)",
"SerializedException": "<Exception><ExceptionType>System.ServiceModel.CommunicationException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'.</Message><StackTrace> at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionModeReader.GetReadResult()\n at System.ServiceModel.Channels.ConnectionModeReader.ReadCallback(Object state)</StackTrace><ExceptionString>System.ServiceModel.CommunicationException: The socket connection was aborted. This could be caused by an error processing your message or a receive timeout being exceeded by the remote host, or an underlying network resource issue. Local socket timeout was '00:02:00'. ---&amp;gt; System.Net.Sockets.SocketException: An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n --- End of inner exception stack trace ---\n at System.ServiceModel.Channels.SocketConnection.EndRead()\n at System.ServiceModel.Channels.ConnectionModeReader.GetReadResult()\n at System.ServiceModel.Channels.ConnectionModeReader.ReadCallback(Object state)</ExceptionString><InnerException><Exception><ExceptionType>System.Net.Sockets.SocketException, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>An existing connection was forcibly closed by the remote host</Message><StackTrace> at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</StackTrace><ExceptionString>System.Net.Sockets.SocketException (0x80004005): An existing connection was forcibly closed by the remote host\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)</ExceptionString><NativeErrorCode>2746</NativeErrorCode></Exception></InnerException></Exception>",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 57410: Throwing an exception.
#Description
Throwing an exception. Source: data1. Exception details: data2.
Message #
Fields #
| Name | Description |
|---|---|
data1 UnicodeString | |
data2 UnicodeString | |
SerializedException UnicodeString | |
AppDomain UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Application Server-Applications",
"guid": "{c651f5f6-1c0d-492e-8ae1-b4efd7c9d503}",
"event_source_name": "",
"event_id": "57410",
"version": "0",
"level": "3",
"task": "0",
"opcode": "0",
"keywords": 2305843009213759488,
"time_created": "2026-03-15T23:30:27.675042300+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{bf62ba95-04a7-46ba-8a97-f026ab57ec47}"
},
"execution": {
"process_id": "3912",
"thread_id": "1108"
},
"channel": "Microsoft-Windows-Application Server-Applications/Analytic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"data1": "System.ServiceModel 4.0.0.0",
"data2": "System.Net.Sockets.SocketException (0x80004005): An existing connection was forcibly closed by the remote host",
"SerializedException": "<Exception><ExceptionType>System.Net.Sockets.SocketException, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089</ExceptionType><Message>An existing connection was forcibly closed by the remote host</Message><StackTrace> at System.Runtime.Diagnostics.EtwDiagnosticTrace.WriteExceptionToTraceString(XmlTextWriter xml, Exception exception, Int32 remainingLength, Int32 remainingAllowedRecursionDepth)\n at System.Runtime.Diagnostics.EtwDiagnosticTrace.ExceptionToTraceString(Exception exception, Int32 maxTraceStringLength)\n at System.Runtime.Diagnostics.EtwDiagnosticTrace.GetSerializedPayload(Object source, TraceRecord traceRecord, Exception exception, Boolean getServiceReference)\n at System.Runtime.TraceCore.ThrowingEtwException(EtwDiagnosticTrace trace, String param0, String param1, Exception exception)\n at System.ServiceModel.Diagnostics.ExceptionUtility.ThrowHelper(Exception exception, TraceEventType eventType, TraceRecord extendedData)\n at System.ServiceModel.Channels.SocketConnection.HandleReceiveAsyncCompleted()\n at System.ServiceModel.Channels.SocketConnection.OnReceiveAsync(Object sender, SocketAsyncEventArgs eventArgs)\n at System.Net.Sockets.SocketAsyncEventArgs.OnCompleted(SocketAsyncEventArgs e)\n at System.Net.Sockets.SocketAsyncEventArgs.FinishOperationAsyncFailure(SocketError socketError, Int32 bytesTransferred, SocketFlags flags)\n at System.Net.Sockets.SocketAsyncEventArgs.CompletionPortCallback(UInt32 errorCode, UInt32 numBytes, NativeOverlapped* nativeOverlapped)\n at System.Threading._IOCompletionCallback.PerformIOCompletionCallback(UInt32 errorCode, UInt32 numBytes, NativeOverlapped* pOVERLAP)\n</StackTrace><ExceptionString>System.Net.Sockets.SocketException (0x80004005): An existing connection was forcibly closed by the remote host</ExceptionString><NativeErrorCode>2746</NativeErrorCode></Exception>",
"AppDomain": "Microsoft.ActiveDirectory.WebServices.exe"
},
"message": ""
}
Event ID 62326: The url 'data1' hosts XAML document with root element type 'data2'.
#Provenance
ETW provider GUID {C651F5F6-1C0D-492E-8AE1-B4EFD7C9D503}
Defined in Microsoft.Windows.ApplicationServer.Applications.dll, which carries the event manifest.
- WS2022-20348.4893, sample captured from a live trace, binary version 4.8.4161.0 built by: NET48REL1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 4.8.4161.0, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 4.8.9032.0, captured 2026-06-02