Microsoft-Windows-ClusterAwareUpdating

EventTitleChannelSampleRule
1000task_0DebugNN
1000Event ID 1000OperationalNN
2000Failover Cluster Updating WMI provider suffered an unclean shutdownAdminNN
2000Event ID 2000OperationalNN
2001Scan for updates succeeded.AdminNN
2001Event ID 2001OperationalNN
2002Scan failed with HRESULT HRESULT.AdminNN
2002Event ID 2002OperationalNN
2003Download for updates succeeded.AdminNN
2003Event ID 2003OperationalNN
2004Download failed with HRESULT HRESULT.AdminNN
2004Event ID 2004OperationalNN
2005Install for updates succeeded.AdminNN
2005Event ID 2005OperationalNN
2006Install failed with HRESULT HRESULT.AdminNN
2006Event ID 2006OperationalNN
2007Cancelling Windows Update Agent operationAdminNN
2007Event ID 2007OperationalNN
2008Update has been skipped as it required user interaction {UpdateTitle UpdateID}.AdminNN
2008Event ID 2008OperationalNN
2009Update has been skipped as it has an unaccepted EULA {UpdateTitle UpdateID}.AdminNN
2009Event ID 2009OperationalNN
2010Ignoring WUA warning Message HRESULT.AdminNN
2010Event ID 2010OperationalNN
2011ObjectName for orchestrator ClientKey has timed out.AdminNN
2011Event ID 2011OperationalNN
2012Orchestrator ClientKey reconnected to WMI provider.AdminNN
2012Event ID 2012OperationalNN
2013Failed to store report with identifier ReportId with HRESULT HRESULT.AdminNN
2013Event ID 2013OperationalNN
2014Activity Transfer eventAdminNN
2014Event ID 2014OperationalNN
2015Failed to retrieve report with identifier ReportId with HRESULT HRESULT.AdminNN
2015Event ID 2015OperationalNN
2016An instance of ObjectName already exists with Guid ExistingGuid.AdminNN
2016Event ID 2016OperationalNN
2017Skipped an optional update {UpdateTitle UpdateID}.AdminNN
2017Event ID 2017OperationalNN
2018Update has been skipped as it is not an important update {UpdateTitle UpdateID}.AdminNN
2018Event ID 2018OperationalNN
2021Failed to start the hotfix installer.AdminNN
2021Event ID 2021OperationalNN

Event ID 1000: task_0

#
Channel
Debug

Message #

%1

Fields #

NameDescription
log AnsiString

Event ID 1000

#
Channel
Operational

Fields #

NameDescription
log AnsiString

Event ID 2000: Failover Cluster Updating WMI provider suffered an unclean shutdown

#
Channel
Admin

Event ID 2000

#
Channel
Operational

Description

Failover Cluster Updating WMI provider suffered an unclean shutdown.

Event ID 2001: Scan for updates succeeded.

#
Channel
Admin

Description

Scan for updates succeeded. Found UpdateCount updates.

Message #

Scan for updates succeeded. Found %1 updates

Fields #

NameDescription
UpdateCount UInt32

Event ID 2001

#
Channel
Operational

Description

Scan for updates succeeded. Found updates.

Fields #

NameDescription
UpdateCount UInt32

Event ID 2002: Scan failed with HRESULT HRESULT.

#
Channel
Admin

Message #

Scan failed with HRESULT %1

Fields #

NameDescription
HRESULT UInt32

Event ID 2002

#
Channel
Operational

Description

Scan failed with HRESULT.

Fields #

NameDescription
HRESULT UInt32

Event ID 2003: Download for updates succeeded.

#
Channel
Admin

Description

Download for updates succeeded. Downloaded UpdateCount updates.

Message #

Download for updates succeeded. Downloaded %1 updates

Fields #

NameDescription
UpdateCount UInt32

Event ID 2003

#
Channel
Operational

Description

Download for updates succeeded. Downloaded updates.

Fields #

NameDescription
UpdateCount UInt32

Event ID 2004: Download failed with HRESULT HRESULT.

#
Channel
Admin

Message #

Download failed with HRESULT %1

Fields #

NameDescription
HRESULT UInt32

Event ID 2004

#
Channel
Operational

Description

Download failed with HRESULT.

Fields #

NameDescription
HRESULT UInt32

Event ID 2005: Install for updates succeeded.

#
Channel
Admin

Description

Install for updates succeeded. Installed UpdateCount updates.

Message #

Install for updates succeeded. Installed %1 updates

Fields #

NameDescription
UpdateCount UInt32

Event ID 2005

#
Channel
Operational

Description

Install for updates succeeded. Installed updates.

Fields #

NameDescription
UpdateCount UInt32

Event ID 2006: Install failed with HRESULT HRESULT.

#
Channel
Admin

Message #

Install failed with HRESULT %1

Fields #

NameDescription
HRESULT UInt32

Event ID 2006

#
Channel
Operational

Description

Install failed with HRESULT.

Fields #

NameDescription
HRESULT UInt32

Event ID 2007: Cancelling Windows Update Agent operation

#
Channel
Admin

Event ID 2007

#
Channel
Operational

Description

Cancelling Windows Update Agent operation.

Event ID 2008: Update has been skipped as it required user interaction {UpdateTitle UpdateID}.

#
Channel
Admin

Message #

Update has been skipped as it required user interaction {%1 %2}

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2008

#
Channel
Operational

Description

Update has been skipped as it required user interaction { }.

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2009: Update has been skipped as it has an unaccepted EULA {UpdateTitle UpdateID}.

#
Channel
Admin

Message #

Update has been skipped as it has an unaccepted EULA {%1 %2}

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2009

#
Channel
Operational

Description

Update has been skipped as it has an unaccepted EULA { }.

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2010: Ignoring WUA warning Message HRESULT.

#
Channel
Admin

Message #

Ignoring WUA warning %1 %2

Fields #

NameDescription
Message UnicodeString
HRESULT UInt32

Event ID 2010

#
Channel
Operational

Description

Ignoring WUA warning.

Fields #

NameDescription
Message UnicodeString
HRESULT UInt32

Event ID 2011: ObjectName for orchestrator ClientKey has timed out.

#
Channel
Admin

Description

ObjectName for orchestrator ClientKey has timed out. Last access time: LastAccessTime.

Message #

%1 for orchestrator %2 has timed out. Last access time: %3

Fields #

NameDescription
ObjectName UnicodeString
ClientKey GUID
LastAccessTime FILETIME

Event ID 2011

#
Channel
Operational

Description

for orchestrator has timed out. Last access time.

Fields #

NameDescription
ObjectName UnicodeString
ClientKey GUID
LastAccessTime FILETIME

Event ID 2012: Orchestrator ClientKey reconnected to WMI provider.

#
Channel
Admin

Message #

Orchestrator %1 reconnected to WMI provider

Fields #

NameDescription
ClientKey GUID

Event ID 2012

#
Channel
Operational

Description

Orchestrator reconnected to WMI provider.

Fields #

NameDescription
ClientKey GUID

Event ID 2013: Failed to store report with identifier ReportId with HRESULT HRESULT.

#
Channel
Admin

Message #

Failed to store report with identifier %1 with HRESULT %2

Fields #

NameDescription
ReportId UnicodeString
HRESULT UInt32

Event ID 2013

#
Channel
Operational

Description

Failed to store report with identifier with HRESULT.

Fields #

NameDescription
ReportId UnicodeString
HRESULT UInt32

Event ID 2014: Activity Transfer event

#
Channel
Admin

Event ID 2014

#
Channel
Operational

Description

Activity Transfer event.

Event ID 2015: Failed to retrieve report with identifier ReportId with HRESULT HRESULT.

#
Channel
Admin

Message #

Failed to retrieve report with identifier %1 with HRESULT %2

Fields #

NameDescription
ReportId UnicodeString
HRESULT UInt32

Event ID 2015

#
Channel
Operational

Description

Failed to retrieve report with identifier with HRESULT.

Fields #

NameDescription
ReportId UnicodeString
HRESULT UInt32

Event ID 2016: An instance of ObjectName already exists with Guid ExistingGuid.

#
Channel
Admin

Description

An instance of ObjectName already exists with Guid ExistingGuid. Failed to create an instance with Guid NewGuid.

Message #

An instance of %1 already exists with Guid %2. Failed to create an instance with Guid %3

Fields #

NameDescription
ObjectName UnicodeString
ExistingGuid GUID
NewGuid GUID

Event ID 2016

#
Channel
Operational

Description

An instance of already exists with Guid . Failed to create an instance with Guid.

Fields #

NameDescription
ObjectName UnicodeString
ExistingGuid GUID
NewGuid GUID

Event ID 2017: Skipped an optional update {UpdateTitle UpdateID}.

#
Channel
Admin

Message #

Skipped an optional update {%1 %2}

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2017

#
Channel
Operational

Description

Skipped an optional update { }.

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2018: Update has been skipped as it is not an important update {UpdateTitle UpdateID}.

#
Channel
Admin

Message #

Update has been skipped as it is not an important update {%1 %2}

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2018

#
Channel
Operational

Description

Update has been skipped as it is not an important update { }.

Fields #

NameDescription
UpdateTitle UnicodeString
UpdateID UnicodeString

Event ID 2021: Failed to start the hotfix installer.

#
Channel
Admin

Description

Failed to start the hotfix installer. Installer path: InstallPath. Parameters: Parameters. Update path: UpdatePath. HRESULT HRESULT, exit code: ExitCode.

Message #

Failed to start the hotfix installer. Installer path: %1. Parameters: %2. Update path: %3. HRESULT %4, exit code: %5.

Fields #

NameDescription
InstallPath UnicodeString
Parameters UnicodeString
UpdatePath UnicodeString
HRESULT UInt32
ExitCode Int32

Event ID 2021

#
Channel
Operational

Description

Failed to start the hotfix installer. Installer path: . Parameters: . Update path: . HRESULT , exit code: .

Fields #

NameDescription
InstallPath UnicodeString
Parameters UnicodeString
UpdatePath UnicodeString
HRESULT UInt32
ExitCode Int32

Provenance

ETW provider GUID 10629806-46f2-4366-9092-53025e067e8c

Defined in cauwmiv2.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02 — Manifest XML pack, 1.9 MB