Microsoft-Windows-Bits-Client

EventTitleChannelSampleRule
0task_0StartAnalyticNN
1BITS job "Title" with ID JobGuid has been resumed.OperationalNN
2BITS job "Title" with ID JobGuid has been suspended.OperationalNN
3The BITS service created a new job: jobTitle, with owner jobId.OperationalYY
4The transfer job is complete.OperationalYN
5Job cancelled.OperationalYN
6Command-line command set for job jobId with owner jobOwner.OperationalYN
10BITS started listening for peer-client requests.AnalyticNN
11BITS was not able to listen for peer-client requests.AnalyticNN
12BITS stopped listening for peer-client requests.AnalyticNN
13BITS started listening for peer-server announcements.AnalyticNN
14BITS was not able to listen for peer-server announcements.AnalyticNN
15BITS stopped listening for peer-server announcements.AnalyticNN
16BITS has sent an inquiry for peer servers.AnalyticNN
17BITS has read the policy parameters for peer-caching.OperationalNN
18The peer list rejected an incoming server announcement.OperationalNN
19A new peer was added.AnalyticNN
20A peer was updated.AnalyticNN
21A peer was removed from the peer list.AnalyticNN
22A cached peer was restored from disk.AnalyticNN
23An application cleared the peer list.OperationalNN
24BITS has replied to a client's inquiry for peer servers.AnalyticNN
25The server received a peer inquiry but rejected it.AnalyticNN
27A peer search for an URL has begun.AnalyticNN
28A peer search ended.AnalyticNN
29A search request is being sent.AnalyticNN
30A search request has completed.AnalyticNN
31A search request has completed unsuccessfully.AnalyticNN
32The peer's record id matched the request.AnalyticNN
33BITS updated the set of IP addresses used for peer-caching.AnalyticNN
34Job cannot be transferred because job transfer cost policy preventing it.AnalyticNN
37The cost state has changed.AnalyticNN
59BITS started the name transfer job that is associated with the url URL.OperationalYN
60BITS stopped transferring the name transfer job that is associated with the url …OperationalYY
61BITS stopped transferring the name transfer job that is associated with the url …OperationalYN
62The BITS job named "Title" belonging to user Owner received inconsistent data …OperationalNN
63The BITS job Job is configured to launch Pgm after transfer of Url.OperationalNN
64The BITS job Job is configured to launch Pgm after transfer of Url.OperationalNN
70BITS received a peer-cache request from a client at address clientAddress.AnalyticNN
71The client's search request is for "url" with timestamp timestamp.AnalyticNN
72The cache found a matching cache record with ID id.AnalyticNN
73While processing the client's request, BITS encountered error ErrorCode.AnalyticNN
74BITS rejected the client's request with HTTP status status.AnalyticNN
75BITS has finished processing the client request.AnalyticNN
76The request includes the client's event-log activity ID.AnalyticNN
77BITS search for peer-servers has started.AnalyticNN
78BITS has encountered ErrorCode error while reading the peer-cache information.OperationalNN
79BITS has successfully deleted the peer-cache.OperationalNN
80BITS has successfully enabled peer-client and/or peer-server related components.OperationalNN
81BITS has encountered ErrorCode error while starting one or more peer-client or …OperationalNN
82BITS accessed group policy value Title : PolicyValue.AnalyticYN
83BITS defaulted group policy value Title : PolicyValue.AnalyticYN
101The peer's response to a search was invalid.AnalyticNN
102The file ranges associated with a transfer attemptAnalyticNN
200While transferring URL, BITS encountered error hr using owner as the HTTP proxy …AnalyticNN
201The BITS job named "job" was unable to contact any HTTP proxy server in its …OperationalNN
202While transferring owner, BITS encountered error urlContentLength using hr as …OperationalNN
203The BITS service provided job credentials in response to an authentication …OperationalNN
204The BITS service provided job credentials in response to an authentication …OperationalYN
205A bandwidth slot transition occurred.AnalyticNN
206The URL "url" in BITS job "jobName" does not support the HTTP HEAD verb, which …OperationalNN
207The URL "url" in BITS job "jobName" does not support the HTTP Content-Length …OperationalNN
208A flash-Crowd situation is detected for the URL "url" in BITS job "jobName".OperationalNN
209High performance property for BITS job "jobName" with ID "jobId" isRoaming.OperationalYN
210The URL "url" in BITS job "jobName" does not support the HTTP Content-Range …OperationalNN
211BITS job "Title" with ID "JobGuid" encountered an error ErrorCode.OperationalNN
212BITS service has detected a 'SystemEvent' system event.AnalyticYN
213Job is not currently transferring because one of its transfer policies conflicts …AnalyticNN
281The service is generating its common global data.AnalyticYN
282The service is reading its group policy settings.AnalyticYN
283The service is creating its performance counters.AnalyticYN
284The service is searching for gateway devices.AnalyticNN
285The service is starting the peer-caching client.AnalyticNN
286The service is starting the peer-caching server.AnalyticNN
287The service is reading the job list from the disk.AnalyticYN
288The service is updating its list of active network connections.AnalyticNN
289The service is updating its list of logged-in users.AnalyticYN
290The service is creating the Volume Shadow Copy writer.AnalyticYN
291The service is registering its COM objects.AnalyticYN
301The BITS service has started successfully.AnalyticYN
302The BITS service has started successfully, but it was delayed long enough that …OperationalYN
303The peer-cache client startup phase of startup has completed.OperationalNN
304The service is shutting down.AnalyticYN
305The service shutdown is complete.AnalyticNN
306The BITS service loaded the job list from disk.OperationalYN
307It took number seconds to write a change file to the BITS job list.OperationalYN
308The BITS service shut down successfully, but it was delayed for number seconds.OperationalYN
309The BITS peer cache was unable to find any peers in the network.OperationalNN
310The initialization of the peer helper modules failed with the following error: …OperationalYN
311The BITS peer transfer with the JobId ID for the JobName transfer job resulted …OperationalYN
312The Network List Manager Cost Interface is not available on this system.OperationalNN
313The Network List Manager Cost Interface is reporting no network connectivity.OperationalNN
16384The administrator User canceled job "Title" on behalf of Owner.OperationalNN
16385While canceling job "Title", BITS was unable to remove some temporary files.SystemNN
16386While canceling job "Title", BITS was unable to remove some temporary files.SystemNN
16387The administrator Owner modified the PropertyName property of job "Title".OperationalNN
16388The administrator User took ownership of job "Title" from Owner.OperationalNN
16389Job "Title" owned by Owner was canceled after being inactive for more than …OperationalNN
16390Job "Title" owned by Owner failed to notify its associated application.SystemNN
16391The BITS job list is not in a recognized format.OperationalNN
16392The BITS service failed to start.SystemYN
16393BITS has encountered an error communicating with an Internet Gateway Device.SystemNN
16394BITS Peer-caching protocolOperationalNN
16395Web Services-Discovery protocolOperationalNN
16396Error status occurred when BITS tried to change the state of firewall rule …SystemNN
16397The Per-user job limit specified through Group Policy must be less than or equal …SystemNN
16398A new BITS job could not be created.SystemNN
16400A new BITS job could not be created.SystemNN
16401BITS could not add file(s) to entityName job.SystemNN
16402BITS could not add ranges to entityName file.SystemNN
16403task_016403OperationalYY
16404The BITS service has detected an exception, Function: function, Line: line Error …SystemNN
16405A bandwidth profile is not configured correctly.SystemNN
17005The BITS service is configured to run as string.SystemNN

Event ID 0: task_0Start

#
Channel
Analytic
Opcode
Start

Event ID 1: BITS job "Title" with ID JobGuid has been resumed.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security, others)
Opcode
Resume

Message #

BITS job "%2" with ID %1 has been resumed.

Fields #

NameDescription
JobGuid GUID
Title UnicodeString

Event ID 2: BITS job "Title" with ID JobGuid has been suspended.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Opcode
Suspend

Message #

BITS job "%2" with ID %1 has been suspended.

Fields #

NameDescription
JobGuid GUID
Title UnicodeString

Event ID 3: The BITS service created a new job: jobTitle, with owner jobId.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Message #

The BITS service created a new job: %1, with owner %2

Fields #

NameDescriptionRules
jobTitle UnicodeStringTransfer job.
jobId GUID
jobOwner UnicodeStringOwner.
processPath UnicodeString3 detection rules
processId UInt32
ClientProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 3,
    "version": 3,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T01:45:20.897391+00:00",
    "event_record_id": 432,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-3588-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 17248
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "jobTitle": "Chrome Component Updater",
    "jobId": "9A25D168-24E6-4C66-AC78-5ED0E6007F1A",
    "jobOwner": "WINDEV2310EVAL\\User",
    "processPath": "C:\\Program Files\\WindowsApps\\SpotifyAB.SpotifyMusic_1.222.982.0_x64__zpdnekdrzrea0\\Spotify.exe",
    "processId": 2208,
    "ClientProcessStartKey": 3659174697241209
  },
  "message": ""
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 4: The transfer job is complete.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)

Message #

The transfer job is complete.
User: %1
Transfer job: %2
Job ID: %3
Owner: %4
File count: %5

Fields #

NameDescription
User UnicodeString
jobTitle UnicodeStringTransfer job.
jobId GUID
jobOwner UnicodeStringOwner.
fileCount UInt64
bytesTransferred UInt64
bytesTransferredFromPeer UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 4,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T02:02:24.353689+00:00",
    "event_record_id": 436,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-3588-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 5192
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "User": "WINDEV2310EVAL\\User",
    "jobTitle": "Edge Component Updater",
    "jobId": "3C77FC9E-C30A-4FC3-804B-82E48B3059B6",
    "jobOwner": "WINDEV2310EVAL\\User",
    "fileCount": 1,
    "bytesTransferred": 201001,
    "bytesTransferredFromPeer": 0
  },
  "message": ""
}

References #

Event ID 5: Job cancelled.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Job cancelled. User: User, job: jobTitle, jobID: jobId, owner: jobOwner, filecount: fileCount.

Message #

Job cancelled. User: %1, job: %2, jobID: %3, owner: %4, filecount: %5

Fields #

NameDescription
User UnicodeStringJob cancelled. User.
jobTitle UnicodeString
jobId GUID
jobOwner UnicodeString
fileCount UInt64
processId UInt32
ClientProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 5,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-25T21:23:18.455184+00:00",
    "event_record_id": 20,
    "correlation": {
      "ActivityID": "DE03B784-07C3-0003-32C2-03DEC307DA01"
    },
    "execution": {
      "process_id": 4816,
      "thread_id": 4860
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "User": "NT AUTHORITY\\LOCAL SERVICE",
    "jobTitle": "Font Download",
    "jobId": "BF87B9AA-D285-46CB-89FF-C6C111F0E4CB",
    "jobOwner": "NT AUTHORITY\\LOCAL SERVICE",
    "fileCount": 1,
    "processId": 2948,
    "ClientProcessStartKey": 562949953421373
  },
  "message": ""
}

References #

Event ID 6: Command-line command set for job jobId with owner jobOwner.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Description

Command-line command set for job jobId with owner jobOwner. Program: program Args: parameters.

Message #

Command-line command set for job %1 with owner %2. Program: %3 Args: %4.

Fields #

NameDescription
jobId GUID
jobOwner UnicodeString
program UnicodeString2. Program.
parameters UnicodeStringArgs.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 6,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-25T21:25:55.426533+00:00",
    "event_record_id": 32,
    "correlation": {
      "ActivityID": "DE03B784-07C3-0003-E610-04DEC307DA01"
    },
    "execution": {
      "process_id": 4940,
      "thread_id": 5896
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "jobId": "F36CA3CE-3AEB-4592-B4ED-D23E59938DF9",
    "jobOwner": "NT AUTHORITY\\SYSTEM",
    "program": "C:\\Windows\\system32\\directxdatabaseupdater.exe",
    "parameters": "C:\\Windows\\system32\\directxdatabaseupdater.exe -DatabaseComplete {F36CA3CE-3AEB-4592-B4ED-D23E59938DF9}"
  },
  "message": ""
}

References #

Event ID 10: BITS started listening for peer-client requests.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients
Opcode
Start

Fields #

NameDescription
server)_listeningforclientsStart(

Event ID 11: BITS was not able to listen for peer-client requests.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients
Opcode
Stop

Description

BITS was not able to listen for peer-client requests. The error code was ErrorCode. BITS jobs from other machines will not be able to use this machine as a peer server. To fix this problem, try stopping the BITS service and restarting it.

Message #

BITS was not able to listen for peer-client requests.  The error code was %1.  BITS jobs from other machines will not be able to use this machine as a peer server.  To fix this problem, try stopping the BITS service and restarting it.

Fields #

NameDescription
ErrorCode UInt32

Event ID 12: BITS stopped listening for peer-client requests.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients
Opcode
Stop

Fields #

NameDescription
server)_listeningforclientsStop12(

Event ID 13: BITS started listening for peer-server announcements.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements
Opcode
Start

Event ID 14: BITS was not able to listen for peer-server announcements.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements
Opcode
Stop

Description

BITS was not able to listen for peer-server announcements. The error code was ErrorCode. BITS jobs on this machine will not be able to use peer-caching. To fix this problem, try stopping the BITS service and restarting it.

Message #

BITS was not able to listen for peer-server announcements.  The error code was %1.  BITS jobs on this machine will not be able to use peer-caching.  To fix this problem, try stopping the BITS service and restarting it.

Fields #

NameDescription
ErrorCode UInt32

Event ID 15: BITS stopped listening for peer-server announcements.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements
Opcode
Stop

Event ID 16: BITS has sent an inquiry for peer servers.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements

Event ID 17: BITS has read the policy parameters for peer-caching.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Fields #

NameDescription
peerCacheEnabled Boolean
peerClientEnabled Boolean
peerServerEnabled Boolean
maxPeers UInt32
maxClients UInt32
maxContentAge UInt32
maxCacheSize UInt32
minCacheDiskSize UInt32
cacheDenyUrls UnicodeString
denyUrlCount UInt8
denyUrls UnicodeString

Event ID 18: The peer list rejected an incoming server announcement.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
listenviaWS_Discoveryforserverannouncements
Opcode
denyingorignoringanincomingpacket

Description

The peer list rejected an incoming server announcement. This event is generated if the request is not valid, not if the server is merely in a different Windows domain.

Message #

The peer list rejected an incoming server announcement. This event is generated if the request is not valid, not if the server is merely in a different Windows domain.

Fields #

NameDescription
packet UnicodeString
hr UInt32
fqdn UnicodeString
sourceAddress Binary
addressCount UInt8
addresses UnicodeString

Event ID 19: A new peer was added.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements
Opcode
replyingtoanincomingrequest

Fields #

NameDescription
fqdn UnicodeString
authenticated Boolean
online Boolean
addressCount UInt8
addressLength UInt16

Event ID 20: A peer was updated.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements
Opcode
replyingtoanincomingrequest

Fields #

NameDescription
fqdn UnicodeString
authenticated Boolean
online Boolean
addressCount UInt8
addressLength UInt16

Event ID 21: A peer was removed from the peer list.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements

Fields #

NameDescription
fqdn UnicodeString
authenticated Boolean
online Boolean
addressCount UInt8
addressLength UInt16

Event ID 22: A cached peer was restored from disk.

#
Channel
Analytic
Task
listenviaWS_Discoveryforserverannouncements

Fields #

NameDescription
fqdn UnicodeString
authenticated Boolean
online Boolean
addressCount UInt8
addressLength UInt16

Event ID 23: An application cleared the peer list.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)
Task
listenviaWS_Discoveryforserverannouncements

Fields #

NameDescription
user SID

Event ID 24: BITS has replied to a client's inquiry for peer servers.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients
Opcode
replyingtoanincomingrequest

Fields #

NameDescription
sourceAddress Binary

Event ID 25: The server received a peer inquiry but rejected it.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients
Opcode
denyingorignoringanincomingpacket

Fields #

NameDescription
sourceAddress Binary
packet UnicodeString
hr UInt32

Event ID 27: A peer search for an URL has begun.

#
Channel
Analytic
Task
apeersearchforaparticularURL
Opcode
Start

Fields #

NameDescription
searchId GUID
jobId GUID
url UnicodeString
timestamp FILETIME

Event ID 28: A peer search ended.

#
Channel
Analytic
Task
apeersearchforaparticularURL
Opcode
Stop

Fields #

NameDescription
searchId GUID
jobId GUID

Event ID 29: A search request is being sent.

#
Channel
Analytic
Task
aparticularrequestwithinapeersearch
Opcode
Start

Fields #

NameDescription
requestId GUID
searchId GUID
peer UnicodeString

Event ID 30: A search request has completed.

#
Channel
Analytic
Task
aparticularrequestwithinapeersearch
Opcode
Stop

Fields #

NameDescription
requestId GUID
SearchId GUID
hr UInt32

Event ID 31: A search request has completed unsuccessfully.

#
Channel
Analytic
Task
aparticularrequestwithinapeersearch
Opcode
Stop

Fields #

NameDescription
requestId GUID
SearchId GUID
hr UInt32

Event ID 32: The peer's record id matched the request.

#
Channel
Analytic
Task
aparticularrequestwithinapeersearch

Message #

The peer's record %2 matched the request.

Fields #

NameDescription
requestId GUID
id GUID
url UnicodeString
rangecount UInt16
Range Int16

Event ID 33: BITS updated the set of IP addresses used for peer-caching.

#
Channel
Analytic
Task
peerneighborlist(server)_listeningforclients

Fields #

NameDescription
count UInt8
addresses UnicodeString

Event ID 34: Job cannot be transferred because job transfer cost policy preventing it.

#
Channel
Analytic

Description

Job cannot be transferred because job transfer cost policy preventing it. job: jobName, jobID: jobId, filecount: FileCount, jobs transfer policy: jobTransferPolicy, global transfer policy: globalTransferPolicy.

Message #

Job cannot be transferred because job transfer cost policy preventing it. job: %1, jobID: %2, filecount: %3, jobs transfer policy: %4, global transfer policy: %5.

Fields #

NameDescription
jobName UnicodeString
jobId GUID
FileCount UInt64
jobTransferPolicy UInt32
globalTransferPolicy UInt32

Event ID 37: The cost state has changed.

#
Channel
Analytic

Description

The cost state has changed. NLM reports the following.

Message #

The cost state has changed.  NLM reports the following: 
Cost: %1
 Usage: %2 MB
 Cap: %3 MB
 Throttled: %4
 Overcap: %5
 Roaming: %6

The resultant BITS Cost state is : %7.

Fields #

NameDescription
nlmCost UInt32
usage UInt32
cap UInt32
isThrottled UInt32
isOvercap UInt32
isRoaming UInt32
globalTransferPolicy UInt32

Event ID 59: BITS started the name transfer job that is associated with the url URL.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security, others)
Opcode
Start

Message #

BITS started the %2 transfer job that is associated with the %4 URL.

Fields #

NameDescription
transferId GUID
name UnicodeString
Id GUID
url UnicodeString
peer UnicodeString
fileTime FILETIME
fileLength UInt64
bytesTotal UInt64
bytesTransferred UInt64
bytesTransferredFromPeer UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 59,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 1,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T01:45:21.457190+00:00",
    "event_record_id": 434,
    "correlation": {
      "ActivityID": "837C306A-427B-4022-ABDF-56DD359EB862"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 12700
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "transferId": "837C306A-427B-4022-ABDF-56DD359EB862",
    "name": "Chrome Component Updater",
    "Id": "9A25D168-24E6-4C66-AC78-5ED0E6007F1A",
    "url": "http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3",
    "peer": "",
    "fileTime": "2023-09-22T20:52:50.000000Z",
    "fileLength": 14317402,
    "bytesTotal": 14317402,
    "bytesTransferred": 0,
    "bytesTransferredFromPeer": 0
  },
  "message": ""
}

References #

Event ID 60: BITS stopped transferring the name transfer job that is associated with the url URL.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)
Opcode
Stop

Description

BITS stopped transferring the name transfer job that is associated with the url URL. The status code is hr.

Message #

BITS stopped transferring the %2 transfer job that is associated with the %4 URL. The status code is %6.

Fields #

NameDescriptionRules
transferId GUID
name UnicodeString
Id GUID
url UnicodeString
peer UnicodeString
hr UInt321 detection rule
fileTime FILETIME
fileLength UInt64
bytesTotal UInt64
bytesTransferred UInt64
proxy UnicodeString
peerProtocolFlags UInt64
bytesTransferredFromPeer UInt64
AdditionalInfoHr UInt32
PeerContextInfo UInt32
bandwidthLimit UInt64
ignoreBandwidthLimitsOnLan Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 60,
    "version": 1,
    "level": 4,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T01:45:52.846707+00:00",
    "event_record_id": 435,
    "correlation": {
      "ActivityID": "837C306A-427B-4022-ABDF-56DD359EB862"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 12832
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "transferId": "837C306A-427B-4022-ABDF-56DD359EB862",
    "name": "Chrome Component Updater",
    "Id": "9A25D168-24E6-4C66-AC78-5ED0E6007F1A",
    "url": "http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3",
    "peer": "",
    "hr": 0,
    "fileTime": "2023-09-22T20:52:50.000000Z",
    "fileLength": 14317402,
    "bytesTotal": 14317402,
    "bytesTransferred": 14317402,
    "proxy": "",
    "peerProtocolFlags": 0,
    "bytesTransferredFromPeer": 0,
    "AdditionalInfoHr": 0,
    "PeerContextInfo": 0,
    "bandwidthLimit": 18446744073709551615,
    "ignoreBandwidthLimitsOnLan": false
  },
  "message": ""
}

Community Notes #

Surfaces Background Intelligent Transfer Service misuse for exfil or downloads.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 61: BITS stopped transferring the name transfer job that is associated with the url URL.

#
Channel
Operational
Also via
realtime ETW trace
Level
Warning
Collection Priority
Recommended (Yamato Security)
Opcode
Stop

Description

BITS stopped transferring the name transfer job that is associated with the url URL. The status code is hr.

Message #

BITS stopped transferring the %2 transfer job that is associated with the %4 URL. The status code is %6.

Fields #

NameDescription
transferId GUID
name UnicodeString
Id GUID
url UnicodeString
peer UnicodeString
hr UInt32
fileTime FILETIME
fileLength UInt64
bytesTotal UInt64
bytesTransferred UInt64
proxy UnicodeString
peerProtocolFlags UInt64
bytesTransferredFromPeer UInt64
AdditionalInfoHr UInt32
PeerContextInfo UInt32
bandwidthLimit UInt64
ignoreBandwidthLimitsOnLan Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 61,
    "version": 1,
    "level": 3,
    "task": 0,
    "opcode": 2,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-25T21:23:18.535833+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C"
    },
    "execution": {
      "process_id": 4816,
      "thread_id": 2800
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "transferId": "B93FF5C2-FB5D-428C-88AE-EE3A7EE94E1C",
    "name": "Font Download",
    "Id": "0732C691-11CC-4489-AA3A-006D80128165",
    "url": "https://fs.microsoft.com/fs/windows/fontset-2017-04.json",
    "peer": "",
    "hr": 2149580817,
    "fileTime": "1601-01-01T00:00:00.000000Z",
    "fileLength": 18446744073709551615,
    "bytesTotal": 18446744073709551615,
    "bytesTransferred": 0,
    "proxy": "",
    "peerProtocolFlags": 0,
    "bytesTransferredFromPeer": 0,
    "AdditionalInfoHr": 0,
    "PeerContextInfo": 0,
    "bandwidthLimit": 18446744073709551615,
    "ignoreBandwidthLimitsOnLan": false
  },
  "message": ""
}

References #

Event ID 62: The BITS job named "Title" belonging to user Owner received inconsistent data while downloading.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS job named "Title" belonging to user Owner received inconsistent data while downloading. The URL was "Url". The transfer will continue using a different server. If the problem occurs often, an administrator should scan the peer server for viruses or corruption in its hard drive.

Message #

The BITS job named "%1" belonging to user %2 received inconsistent data while downloading. The URL was "%3". The transfer will continue using a different server.  If the problem occurs often, an administrator should scan the peer server for viruses or corruption in its hard drive.

Fields #

NameDescription
Title UnicodeString
Owner UnicodeString
Url UnicodeString
Id GUID

Event ID 63: The BITS job Job is configured to launch Pgm after transfer of Url.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS job Job is configured to launch Pgm after transfer of Url. The notification program returned error hr, BITS will continue to launch the program periodically until it succeeds.

Message #

The BITS job %1 is configured to launch %3 after transfer of %2. The notification program returned error %4, BITS will continue to launch the program periodically until it succeeds.

Fields #

NameDescription
Job UnicodeString
Url UnicodeString
Pgm UnicodeString
hr UInt32

Event ID 64: The BITS job Job is configured to launch Pgm after transfer of Url.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS job Job is configured to launch Pgm after transfer of Url. The service failed to launch the program with error hr, BITS will continue trying to launch the program periodically until it succeeds.

Message #

The BITS job %1 is configured to launch %3 after transfer of %2. The service failed to launch the program with error %4, BITS will continue trying to launch the program periodically until it succeeds.

Fields #

NameDescription
Job UnicodeString
Url UnicodeString
Pgm UnicodeString
hr UInt32

Event ID 70: BITS received a peer-cache request from a client at address clientAddress.

#
Channel
Analytic
Opcode
Start

Message #

BITS received a peer-cache request from a client at address %1.

Fields #

NameDescription
clientAddress Binary

Event ID 71: The client's search request is for "url" with timestamp timestamp.

#
Channel
Analytic

Message #

The client's search request is for "%1" with timestamp %2.

Fields #

NameDescription
url UnicodeString
timestamp FILETIME

Event ID 72: The cache found a matching cache record with ID id.

#
Channel
Analytic

Message #

The cache found a matching cache record with ID %1.

Fields #

NameDescription
id GUID
url UnicodeString
rangecount UInt16
Range UInt8

Event ID 73: While processing the client's request, BITS encountered error ErrorCode.

#
Channel
Analytic

Message #

While processing the client's request, BITS encountered error %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 74: BITS rejected the client's request with HTTP status status.

#
Channel
Analytic

Message #

BITS rejected the client's request with HTTP status %1.

Fields #

NameDescription
status UInt16NTSTATUS reference

Event ID 75: BITS has finished processing the client request.

#
Channel
Analytic
Opcode
Stop

Event ID 76: The request includes the client's event-log activity ID.

#
Channel
Analytic
Opcode
Send

Event ID 77: BITS search for peer-servers has started.

#
Channel
Analytic
Opcode
Start

Event ID 78: BITS has encountered ErrorCode error while reading the peer-cache information.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

BITS has encountered ErrorCode error while reading the peer-cache information. BITS will now attempt to delete and re-create the peer-cache.

Message #

BITS has encountered %1 error while reading the peer-cache information. BITS will now attempt to delete and re-create the peer-cache.

Fields #

NameDescription
ErrorCode UInt32

Event ID 79: BITS has successfully deleted the peer-cache.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

BITS has successfully deleted the peer-cache. All the files cached until this point have been removed. The peer-cache will be re-created again as needed for handling the future requests.

Message #

BITS has successfully deleted the peer-cache. All the files cached until this point have been removed. The peer-cache will be re-created again as needed for handling the future requests.

Event ID 80: BITS has successfully enabled peer-client and/or peer-server related components.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 81: BITS has encountered ErrorCode error while starting one or more peer-client or peer-server components.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Message #

BITS has encountered %1 error while starting one or more peer-client or peer-server components.

Fields #

NameDescription
ErrorCode UInt32

Event ID 82: BITS accessed group policy value Title : PolicyValue.

#
Channel
Analytic
Level
Informational

Message #

BITS accessed group policy value %1 : %2.

Fields #

NameDescription
Title UnicodeString
PolicyValue UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 82,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.441395+00:00",
    "event_record_id": 17,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Title": "MaxTransferRateOffSchedule",
    "PolicyValue": 4294967295
  },
  "message": ""
}

Event ID 83: BITS defaulted group policy value Title : PolicyValue.

#
Channel
Analytic
Level
Informational

Message #

BITS defaulted group policy value %1 : %2.

Fields #

NameDescription
Title UnicodeString
PolicyValue UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 83,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.345490+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Title": "DisableBranchCache",
    "PolicyValue": 0
  },
  "message": ""
}

Event ID 101: The peer's response to a search was invalid.

#
Channel
Analytic
Task
aparticularrequestwithinapeersearch
Opcode
Stop

Fields #

NameDescription
requestId GUID
responseXml UnicodeString

Event ID 102: The file ranges associated with a transfer attempt

#
Channel
Analytic

Fields #

NameDescription
xferId GUID
count UInt8
ranges Int8

Event ID 200: While transferring URL, BITS encountered error hr using owner as the HTTP proxy server.

#
Channel
Analytic

Description

While transferring url, BITS encountered error hr using proxy as the HTTP proxy server. This may indicate a problem with the proxy server or with the client's network configuration. If this error occurs frequently, then an administrator should investigate. Details: {Job: job}, {owner: owner}, {jobid: jobId}, {URL: url}, {xferId: xferId}, {proxyServerList: proxyServerList}, {hr: hr}.

Message #

While transferring %1, BITS encountered error %2 using %3 as the HTTP proxy server.  This may indicate a problem with the proxy server or with the client's network configuration.  If this error occurs frequently, then an administrator should investigate. Details: {Job: %4}, {owner: %5}, {jobid: %6}, {URL: %1}, {xferId: %7}, {proxyServerList: %8}, {hr: %2}.

Fields #

NameDescription
url UnicodeString
hr UInt32}, {hr.
proxy UnicodeString
job UnicodeString
owner UnicodeString3 as the HTTP proxy server. This may indicate a problem with the proxy server or with the client's network configuration. If this error occurs frequently, then an administrator should investigate. Details: {Job.
jobId GUID
xferId GUID}, {jobid.
proxyServerList UnicodeString}, {xferId.

Event ID 201: The BITS job named "job" was unable to contact any HTTP proxy server in its proxy list.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS job named "job" was unable to contact any HTTP proxy server in its proxy list. This may indicate a problem with the proxy servers or with the client's network configuration. An administrator should verify whether the proxy list is correct. BITS will periodically try to transfer the job. The HTTP proxy list is "proxyServerList". The proxy-bypass list is "proxyBypassList".

Message #

The BITS job named "%1" was unable to contact any HTTP proxy server in its proxy list.  This may indicate a problem with the proxy servers or with the client's network configuration.  An administrator should verify whether the proxy list is correct.  BITS will periodically try to transfer the job.  The HTTP proxy list is "%6".  The proxy-bypass list is "%7".

Fields #

NameDescription
job UnicodeString
jobId GUID
jobOwner UnicodeString
url UnicodeString
transferId GUID
proxyServerList UnicodeString
proxyBypassList UnicodeString
error UInt32

Event ID 202: While transferring owner, BITS encountered error urlContentLength using hr as the HTTP proxy server.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

While transferring jobName, BITS encountered error hr using proxy as the HTTP proxy server. The web server or proxy server does not support an HTTP feature required by BITS. This problem can only be corrected by the administrator of the web server or proxy server. Details: {job: jobName}, {owner: jobOwner}, {jobId: jobId}, {url: url}, {xferId: xferId}, {proxyServer: proxy}, {hr: hr}, {urlContentLength: fileLength}, {urlHttpVersion: HTTPVersion}, {urlRange: URLRange}

Message #

While transferring %1, BITS encountered error %7 using %6 as the HTTP proxy server.  The web server or proxy server does not support an HTTP feature required by BITS.  This problem can only be corrected by the administrator of the web server or proxy server.  Details: {job: %1}, {owner: %2}, {jobId: %3}, {url: %4}, {xferId: %5}, {proxyServer: %6}, {hr: %7}, {urlContentLength: %8}, {urlHttpVersion: %9}, {urlRange: %10}

Fields #

NameDescription
jobName UnicodeString
jobOwner UnicodeString
jobId GUID}, {jobId.
url UnicodeString}, {url.
xferId GUID}, {xferId.
proxy UnicodeString
hr UInt32}, {hr.
fileLength UInt64
HTTPVersion UnicodeString
URLRange UnicodeString

Event ID 203: The BITS service provided job credentials in response to an authentication challenge from the server server for the job transfer job that is associated ...

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS service provided job credentials in response to an authentication challenge from the server server for the job transfer job that is associated with the following URL: url.

Message #

The BITS service provided job credentials in response to an authentication challenge from the %1 server for the %2 transfer job that is associated with the following URL: %3.
The credentials were accepted.

Fields #

NameDescription
server UnicodeString
job UnicodeString
url UnicodeString
scheme UnicodeString
user UnicodeString

Event ID 204: The BITS service provided job credentials in response to an authentication challenge from server for job job, url url.

#
Channel
Operational
Level
Error
Collection Priority
Recommended (Yamato Security)

Description

The BITS service provided job credentials in response to an authentication challenge from server for job job, url url. The credentials were rejected.

Message #

The BITS service provided job credentials in response to an authentication challenge from %1 for job %2, url %3. The credentials were rejected.

Fields #

NameDescription
server UnicodeString
job UnicodeString
url UnicodeString2 transfer job that is associated with the following URL.
scheme UnicodeString
user UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 204,
    "version": 1,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-14T22:56:18.815891+00:00",
    "event_record_id": 443,
    "correlation": {},
    "execution": {
      "process_id": 9052,
      "thread_id": 6016
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "server": "outlook.office365.com",
    "job": "Microsoft Outlook Offline Address Book 9bcc1d66a60a9745b5d797f23d8b2f80",
    "url": "/OAB/1e7ad0fe-e5d2-428b-a1de-bd1a0d0e6cb9/oab.xml",
    "scheme": "UNIDENTIFIED",
    "user": "S-1-5-21-1006758700-2167138679-1475694448-1105"
  },
  "message": ""
}

Event ID 205: A bandwidth slot transition occurred.

#
Channel
Analytic

Fields #

NameDescription
profileType UInt8
currSlotStartTime FILETIME
currSlotBandwidthLimit UInt64
nextSlotStartTime FILETIME
nextSlotBandwidthLimit UInt64

Event ID 206: The URL "url" in BITS job "jobName" does not support the HTTP HEAD verb, which is required for BITS bandwidth throttling.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The URL "url" in BITS job "jobName" does not support the HTTP HEAD verb, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Message #

The URL "%2" in BITS job "%1" does not support the HTTP HEAD verb, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields #

NameDescription
jobName UnicodeString
url UnicodeString

Event ID 207: The URL "url" in BITS job "jobName" does not support the HTTP Content-Length header, which is required for BITS bandwidth throttling.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The URL "url" in BITS job "jobName" does not support the HTTP Content-Length header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Message #

The URL "%2" in BITS job "%1" does not support the HTTP Content-Length header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields #

NameDescription
jobName UnicodeString
url UnicodeString

Event ID 208: A flash-Crowd situation is detected for the URL "url" in BITS job "jobName".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Message #

A flash-Crowd situation is detected for the URL "%2" in BITS job "%1".

Fields #

NameDescription
jobName UnicodeString
url UnicodeString

Event ID 209: High performance property for BITS job "jobName" with ID "jobId" isRoaming.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (Yamato Security)

Message #

High performance property for BITS job "%1" with ID "%2" %3.

Fields #

NameDescription
jobName UnicodeString
jobId GUID
isRoaming UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 209,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-05T22:27:06.012810+00:00",
    "event_record_id": 121,
    "correlation": {
      "ActivityID": "F590C418-1079-0000-98E3-90F57910DA01"
    },
    "execution": {
      "process_id": 5620,
      "thread_id": 4004
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "jobName": "Font Download",
    "jobId": "45827C8A-7310-400E-A51E-179189C5AC76",
    "isRoaming": 1
  },
  "message": ""
}

References #

Event ID 210: The URL "url" in BITS job "jobName" does not support the HTTP Content-Range header, which is required for BITS bandwidth throttling.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The URL "url" in BITS job "jobName" does not support the HTTP Content-Range header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Message #

The URL "%2" in BITS job "%1" does not support the HTTP Content-Range header, which is required for BITS bandwidth throttling. The URL will be downloaded without throttling.

Fields #

NameDescription
jobName UnicodeString
url UnicodeString

Event ID 211: BITS job "Title" with ID "JobGuid" encountered an error ErrorCode.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

BITS job "Title" with ID "JobGuid" encountered an error ErrorCode. Message.

Message #

BITS job "%2" with ID "%1" encountered an error %3. %4

Fields #

NameDescription
JobGuid GUID
Title UnicodeString
ErrorCode UInt32
Message UInt32

Event ID 212: BITS service has detected a 'SystemEvent' system event.

#
Channel
Analytic
Also via
realtime ETW trace
Level
Verbose

Message #

BITS service has detected a '%1' system event

Fields #

NameDescription
SystemEvent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 212,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.656795+00:00",
    "event_record_id": 22,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8132
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "SystemEvent": 7
  },
  "message": ""
}

Event ID 213: Job is not currently transferring because one of its transfer policies conflicts with current system state.

#
Channel
Analytic

Description

Job is not currently transferring because one of its transfer policies conflicts with current system state. job: jobName, jobID: jobId, filecount: FileCount, block reason: BlockReasonErrorCode.

Message #

Job is not currently transferring because one of its transfer policies conflicts with current system state. job: %1, jobID: %2, filecount: %3, block reason: %4.

Fields #

NameDescription
jobName UnicodeString
jobId GUID
FileCount UInt64
BlockReasonErrorCode UInt32

Event ID 281: The service is generating its common global data.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 281,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.303306+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 282: The service is reading its group policy settings.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 282,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.344992+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 283: The service is creating its performance counters.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 283,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.302664+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 284: The service is searching for gateway devices.

#
Channel
Analytic

Event ID 285: The service is starting the peer-caching client.

#
Channel
Analytic

Event ID 286: The service is starting the peer-caching server.

#
Channel
Analytic

Event ID 287: The service is reading the job list from the disk.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 287,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.441546+00:00",
    "event_record_id": 20,
    "correlation": {},
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 288: The service is updating its list of active network connections.

#
Channel
Analytic

Event ID 289: The service is updating its list of logged-in users.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 289,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.584106+00:00",
    "event_record_id": 21,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0005-D06D-848B21B3DC01"
    },
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 290: The service is creating the Volume Shadow Copy writer.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 290,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.701261+00:00",
    "event_record_id": 24,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0005-D06D-848B21B3DC01"
    },
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 291: The service is registering its COM objects.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 291,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.769863+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0005-D06D-848B21B3DC01"
    },
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 301: The BITS service has started successfully.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 301,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:23:56.781430+00:00",
    "event_record_id": 29,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0005-D06D-848B21B3DC01"
    },
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 302: The BITS service has started successfully, but it was delayed long enough that there may be a problem.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)

Description

The BITS service has started successfully, but it was delayed long enough that there may be a problem. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Message #

The BITS service has started successfully, but it was delayed long enough that there may be a problem. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "event_id": 302,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-04-18T00:33:38.2704794+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Microsoft-Windows-Bits-Client"
  },
  "event_data": {}
}

Event ID 303: The peer-cache client startup phase of startup has completed.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 304: The service is shutting down.

#
Channel
Analytic
Level
Verbose

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 304,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213693952,
    "time_created": "2026-03-13T20:25:56.771683+00:00",
    "event_record_id": 30,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-0005-D06D-848B21B3DC01"
    },
    "execution": {
      "process_id": 11028,
      "thread_id": 8440
    },
    "channel": "Microsoft-Windows-Bits-Client/Analytic",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 305: The service shutdown is complete.

#
Channel
Analytic

Event ID 306: The BITS service loaded the job list from disk.

#
Channel
Operational
Level
Verbose
Collection Priority
Recommended (Yamato Security)

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "{EF1CC15B-46C1-414E-BB95-E76B077BD51E}",
    "event_source_name": "",
    "event_id": 306,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T14:33:57.8159482+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 5384,
      "thread_id": 5008
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The BITS service loaded the job list from disk."
}

Event ID 307: It took number seconds to write a change file to the BITS job list.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)

Description

It took number seconds to write a change file to the BITS job list. If this is excessive, the number of BITS jobs may be larger than this machine can handle quickly.

Message #

It took %1 seconds to write a change file to the BITS job list. If this is excessive, the number of BITS jobs may be larger than this machine can handle quickly.

Fields #

NameDescription
number Double

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "{EF1CC15B-46C1-414E-BB95-E76B077BD51E}",
    "event_source_name": "",
    "event_id": 307,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:11:31.8564242+00:00",
    "event_record_id": 62,
    "correlation": {
      "ActivityID": "{208980A3-EFD9-0001-BFB3-8920D9EFDC01}"
    },
    "execution": {
      "process_id": 6468,
      "thread_id": 7980
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WIN11-25H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "number": "16.25"
  },
  "message": "It took 16.25 seconds to write a change file to the BITS job list. If this is excessive, the number of BITS jobs may be larger than this machine can handle quickly."
}

Event ID 308: The BITS service shut down successfully, but it was delayed for number seconds.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)

Description

The BITS service shut down successfully, but it was delayed for number seconds. This might cause delays when you turn off your computer. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Message #

The BITS service shut down successfully, but it was delayed for %1 seconds. This might cause delays when you turn off your computer. For more information on the delay, enable the analytic log for BITS, then stop and restart the BITS service.

Fields #

NameDescription
number Double

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 308,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2021-06-13T06:19:28.351119Z",
    "event_record_id": 17,
    "correlation": {
      "#attributes": {
        "ActivityID": "9E13646C-6014-0001-5C6E-139E1460D701"
      }
    },
    "execution": {
      "process_id": 1140,
      "thread_id": 356
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "sv-dc.hinokabegakure-no-sato.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "number": "3199.234"
  }
}

References #

Event ID 309: The BITS peer cache was unable to find any peers in the network.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 310: The initialization of the peer helper modules failed with the following error: ErrorCode.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)

Message #

The initialization of the peer helper modules failed with the following error: %1.

Fields #

NameDescription
ErrorCode UInt32The initialization of the peer helper modules failed with the following error.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 310,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T00:48:24.805665+00:00",
    "event_record_id": 419,
    "correlation": {},
    "execution": {
      "process_id": 16164,
      "thread_id": 15644
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ErrorCode": 2147942450
  },
  "message": ""
}

References #

Event ID 311: The BITS peer transfer with the JobId ID for the JobName transfer job resulted in the following error: ErrorCode.

#
Channel
Operational
Level
Warning
Collection Priority
Recommended (Yamato Security)

Message #

The BITS peer transfer with the %1 ID for the %2 transfer job resulted in the following error: %4.

Fields #

NameDescription
JobId GUID
JobName UnicodeString
url UnicodeString
ErrorCode UInt32
ErrorContext UInt8
bytesTransferredFromPeer UInt64
PeerProtocolFlags UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "ef1cc15b-46c1-414e-bb95-e76b077bd51e",
    "event_source_name": "",
    "event_id": 311,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-07-19T17:35:03.1768929+00:00",
    "event_record_id": 3671,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 7140,
      "thread_id": 1892
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "JobId": "{3a7080d7-9892-47e6-a76e-3842202c774b}",
    "JobName": "PreSignInSettingsConfigJSON",
    "url": "https://g.live.com/odclientsettings/ProdV2",
    "ErrorCode": "2147745808",
    "ErrorContext": "5",
    "bytesTransferredFromPeer": "0",
    "PeerProtocolFlags": "0"
  },
  "message": "The BITS peer transfer with the {3a7080d7-9892-47e6-a76e-3842202c774b} ID for the PreSignInSettingsConfigJSON transfer job resulted in the following error: 0x80040010."
}

Event ID 312: The Network List Manager Cost Interface is not available on this system.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The Network List Manager Cost Interface is not available on this system. (This is expected on Windows Server.) BITS will not consider Transfer Policy when scheduling jobs.

Message #

The Network List Manager Cost Interface is not available on this system. (This is expected on Windows Server.)  BITS will not consider Transfer Policy when scheduling jobs.

Fields #

NameDescription
ErrorCode UInt32

Event ID 313: The Network List Manager Cost Interface is reporting no network connectivity.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The Network List Manager Cost Interface is reporting no network connectivity. BITS will try to retrieve the network state again at a later time.

Message #

The Network List Manager Cost Interface is reporting no network connectivity. BITS will try to retrieve the network state again at a later time.

Fields #

NameDescription
ErrorCode UInt32

Event ID 16384: The administrator User canceled job "Title" on behalf of Owner.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The administrator User canceled job "Title" on behalf of Owner. The job ID was Id.

Message #

The administrator %4 canceled job "%2" on behalf of %3.  The job ID was %1.

Fields #

NameDescription
Id GUID
Title UnicodeString
Owner UnicodeString
User UnicodeString
processId UInt32
ClientProcessStartKey UInt64

Event ID 16385: While canceling job "Title", BITS was unable to remove some temporary files.

#
Channel
System

Description

While canceling job "Title", BITS was unable to remove some temporary files. To recover disk space, delete the files listed below. The job ID was Id. FileList.

Message #

While canceling job "%2", BITS was unable to remove some temporary files. To recover disk space, delete the files listed below.  The job ID was %1.  %3

Fields #

NameDescription
Id GUID
Title UnicodeString
FileList UnicodeString

Event ID 16386: While canceling job "Title", BITS was unable to remove some temporary files.

#
Channel
System

Description

While canceling job "Title", BITS was unable to remove some temporary files. To recover disk space, delete the temporary files. Note: Due to space limitations, not all files are listed. Check for additional files of the form BITxxx.TMP in the same directory. The job ID was Id. FileList

Message #

While canceling job "%2", BITS was unable to remove some temporary files. To recover disk space, delete the temporary files. Note: Due to space limitations, not all files are listed.  Check for additional files of the form BITxxx.TMP in the same directory.  The job ID was %1.  %3

Fields #

NameDescription
Id GUID
Title UnicodeString
FileList UnicodeString

Event ID 16387: The administrator Owner modified the PropertyName property of job "Title".

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The administrator Owner modified the PropertyName property of job "Title". The job ID was Id.

Message #

The administrator %3 modified the %4 property of job "%2".  The job ID was %1.

Fields #

NameDescription
Id GUID
Title UnicodeString
Owner UnicodeString
PropertyName UnicodeString

Event ID 16388: The administrator User took ownership of job "Title" from Owner.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The administrator User took ownership of job "Title" from Owner. The job ID was Id.

Message #

The administrator %4 took ownership of job "%2" from %3.  The job ID was %1.

Fields #

NameDescription
Id GUID
Title UnicodeString
Owner UnicodeString
User UnicodeString
processId UInt32
ClientProcessStartKey UInt64

Event ID 16389: Job "Title" owned by Owner was canceled after being inactive for more than DayCount days.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

Job "Title" owned by Owner was canceled after being inactive for more than DayCount days. The job ID was Id.

Message #

Job "%2" owned by %3 was canceled after being inactive for more than %4 days.  The job ID was %1.

Fields #

NameDescription
Id GUID
Title UnicodeString
Owner UnicodeString
DayCount UInt32

Event ID 16390: Job "Title" owned by Owner failed to notify its associated application.

#
Channel
System

Description

Job "Title" owned by Owner failed to notify its associated application. BITS will retry in RetryWaitTime minutes. The job ID was Id.

Message #

Job "%2" owned by %3 failed to notify its associated application.  BITS will retry in %4 minutes.  The job ID was %1.

Fields #

NameDescription
Id GUID
Title UnicodeString
Owner UnicodeString
RetryWaitTime UInt32

Event ID 16391: The BITS job list is not in a recognized format.

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Description

The BITS job list is not in a recognized format. It may have been created by a different version of BITS. The job list has been cleared.

Message #

The BITS job list is not in a recognized format.  It may have been created by a different version of BITS.  The job list has been cleared.

Event ID 16392: The BITS service failed to start.

#
Channel
System
Level
Error

Description

The BITS service failed to start. Error ErrorCode.

Message #

The BITS service failed to start.  Error %1.

Fields #

NameDescription
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 16392,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2025-12-31T19:34:50.503454+00:00",
    "event_record_id": 319,
    "correlation": {
      "ActivityID": "159FE9D7-7A73-0001-5538-A015737ADC01"
    },
    "execution": {
      "process_id": 7452,
      "thread_id": 1064
    },
    "channel": "System",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ErrorCode": 2147943515
  },
  "message": ""
}

Event ID 16393: BITS has encountered an error communicating with an Internet Gateway Device.

#
Channel
System

Description

BITS has encountered an error communicating with an Internet Gateway Device. Please check that the device is functioning properly. BITS will not attempt to use this device until the next system reboot. Error code: ErrorCode.

Message #

BITS has encountered an error communicating with an Internet Gateway Device.  Please check that the device is functioning properly. BITS will not attempt to use this device until the next system reboot. Error code: %1.

Fields #

NameDescription
ErrorCode UInt32

Event ID 16394: BITS Peer-caching protocol

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 16395: Web Services-Discovery protocol

#
Channel
Operational
Collection Priority
Recommended (Yamato Security)

Event ID 16396: Error status occurred when BITS tried to change the state of firewall rule "rule" to enabled.

#
Channel
System

Description

Error status occurred when BITS tried to change the state of firewall rule "rule" to enabled. Restarting the BITS service may correct the problem.

Message #

Error %3 occurred when BITS tried to change the state of firewall rule "%1" to %2.  Restarting the BITS service may correct the problem.

Fields #

NameDescription
rule UnicodeString
enabled Boolean
status UInt32NTSTATUS reference

Event ID 16397: The Per-user job limit specified through Group Policy must be less than or equal to Per-computer job Limit.

#
Channel
System

Description

The Per-user job limit (currentSize) specified through Group Policy must be less than or equal to Per-computer job Limit (currentLimit). To correct the problem, modify BITS Group Policy settings and restart the BITS service.

Message #

The Per-user job limit (%2) specified through Group Policy must be less than or equal to Per-computer job Limit (%3).  To correct the problem, modify BITS Group Policy settings and restart the BITS service.

Fields #

NameDescription
entityName UnicodeString
currentSize UInt32
currentLimit UInt32

Event ID 16398: A new BITS job could not be created.

#
Channel
System

Description

A new BITS job could not be created. The current job count for the user entityName (currentSize) is equal to or greater than the job limit (currentLimit) specified through group policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.

Message #

A new BITS job could not be created. The current job count for the user %1 (%2) is equal to or greater than the job limit (%3) specified through group policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error, and restart the BITS service. If this error recurs, contact your system administrator and increate the per-user and per-computer Group Policy job limits.

Fields #

NameDescription
entityName UnicodeString
currentSize UInt32
currentLimit UInt32

Event ID 16400: A new BITS job could not be created.

#
Channel
System

Description

A new BITS job could not be created. The current job count for this computer (currentSize) is equal to or greater than the per-computer job limit (currentLimit) specified through Group Policy. To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error and restarting the BITS service. If this error recurs, contact your system administrator and increase the per-computer Group Policy job limits.

Message #

A new BITS job could not be created. The current job count for this computer (%2) is equal to or greater than the per-computer job limit (%3) specified through Group Policy.  To correct the problem, complete or cancel the BITS jobs that haven't made progress by looking at the error and restarting the BITS service. If this error recurs, contact your system administrator and increase the per-computer Group Policy job limits.

Fields #

NameDescription
entityName UnicodeString
currentSize UInt32
currentLimit UInt32

Event ID 16401: BITS could not add file(s) to entityName job.

#
Channel
System

Description

BITS could not add file(s) to entityName job. The file count for entityName job (currentSize) has exceeded the per-job file limit (currentLimit) specified through Group Policy. To correct the problem, increase the Computer’s per-job file limit Group Policy settings and restart the BITS service.

Message #

BITS could not add file(s) to %1 job. The file count for %1 job (%2) has exceeded the per-job file limit (%3) specified through Group Policy.  To correct the problem, increase the Computer?s per-job file limit Group Policy settings and restart the BITS service.

Fields #

NameDescription
entityName UnicodeString
currentSize UInt32
currentLimit UInt32

Event ID 16402: BITS could not add ranges to entityName file.

#
Channel
System

Description

BITS could not add ranges to entityName file. The range count for entityName file (currentSize) has exceeded the per-file range limit (currentLimit) specified through group policy. To correct the problem, increase the per-file range limit Group Policy setting and restart the BITS service.

Message #

BITS could not add ranges to %1 file. The range count for %1 file (%2) has exceeded the per-file range limit (%3) specified through group policy.  To correct the problem, increase the per-file range limit Group Policy setting and restart the BITS service.

Fields #

NameDescription
entityName UnicodeString
currentSize UInt32
currentLimit UInt32

Event ID 16403: task_016403

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Collection Priority
Recommended (Yamato Security)

Fields #

NameDescriptionRules
User UnicodeString
jobTitle UnicodeString
jobId GUID
jobOwner UnicodeString
fileCount UInt64
RemoteName UnicodeString84 detection rules
LocalName UnicodeString13 detection rules
processId UInt32
ClientProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Bits-Client",
    "guid": "EF1CC15B-46C1-414E-BB95-E76B077BD51E",
    "event_source_name": "",
    "event_id": 16403,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2023-11-06T01:45:21.024078+00:00",
    "event_record_id": 433,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0002-3588-E4E43710DA01"
    },
    "execution": {
      "process_id": 16164,
      "thread_id": 18264
    },
    "channel": "Microsoft-Windows-Bits-Client/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-21-1992711665-1655669231-58201500-1000"
    }
  },
  "event_data": {
    "User": "WINDEV2310EVAL\\User",
    "jobTitle": "Chrome Component Updater",
    "jobId": "9A25D168-24E6-4C66-AC78-5ED0E6007F1A",
    "jobOwner": "WINDEV2310EVAL\\User",
    "fileCount": 1,
    "RemoteName": "http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acwcdm4bj7lx4xbm2ireywxlhvca_4.10.2710.0/oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3",
    "LocalName": "C:\\Users\\User\\AppData\\Local\\Temp\\chrome_BITS_2208_583787314\\oimompecagnajdejgnnjijobebaeigek_4.10.2710.0_win64_adsurwm4gclupf32xdrpgdnapira.crx3",
    "processId": 2208,
    "ClientProcessStartKey": 3659174697241209
  },
  "message": ""
}

Community Notes #

May indicate download/staging. See this Google Cloud post Back in a Bit: Attacker Use of the Windows Background Intelligent Transfer Service

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 16404: The BITS service has detected an exception, Function: function, Line: line Error code: hr.

#
Channel
System

Message #

The BITS service has detected an exception, Function: %1, Line: %2 Error code: %3.

Fields #

NameDescription
function UnicodeString
line UInt32
hr UInt32

Event ID 16405: A bandwidth profile is not configured correctly.

#
Channel
System

Description

A bandwidth profile is not configured correctly. The value of a Group Policy setting is missing or is not within the allowed range. Make sure that you configure the Group Policy settings correctly, and then try again.

Message #

A bandwidth profile is not configured correctly. The value of a Group Policy setting is missing or is not within the allowed range. Make sure that you configure the Group Policy settings correctly, and then try again.

Fields #

NameDescription
Key UnicodeString
SubKeyOrValueName UnicodeString

Event ID 17005: The BITS service is configured to run as string.

#
Channel
System

Description

The BITS service is configured to run as string. BITS works correctly only when configured to run as the system account.

Message #

The BITS service is configured to run as %1. BITS works correctly only when configured to run as the system account.

Fields #

NameDescription
string UnicodeString
string2 UnicodeString
string3 UnicodeString

Provenance

ETW provider GUID {EF1CC15B-46C1-414E-BB95-E76B077BD51E}

Defined in qmgr.dll, which carries the event manifest.

  • WS2022-20348.4893, sample captured from a live trace, binary version 7.8.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 7.8.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 7.8.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB