Microsoft-Windows-CoreSystem-InitMachineConfig

6 events across 1 channel

Event ID 1: An error with reference Id=evtErrorId was encountered while processing the hive 'evtHiveName'.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

An error with reference Id=evtErrorId was encountered while processing the hive 'evtHiveName'. The status was: evtStatus. The additional information was evtAdditionalInfo.

Message #

An error with reference Id=%1 was encountered while processing the hive '%3'. The status was: %4.  The additional information was %5.

Fields #

NameDescription
evtErrorId UInt64
evtHiveNameLength UInt16
evtHiveName UnicodeString
evtStatus HexInt32
evtAdditionalInfo HexInt64

Event ID 2: Initial Machine Configuration processing of hive 'evtHiveName' has completed.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

Initial Machine Configuration processing of hive 'evtHiveName' has completed.

Message #

Initial Machine Configuration processing of hive '%2' has completed.

Fields #

NameDescription
evtHiveNameLength UInt16
evtHiveName UnicodeString

Event ID 3: Initial Machine Configuration was unable to unload the IMC hive once processing was completed.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

Initial Machine Configuration was unable to unload the IMC hive once processing was completed. The status was evtStatus.

Message #

Initial Machine Configuration was unable to unload the IMC hive once processing was completed.  The status was %1.

Fields #

NameDescription
evtStatus HexInt32

Event ID 4: Initial Machine Configuration was unable to update the system BCD to prevent future execution.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

Initial Machine Configuration was unable to update the system BCD to prevent future execution. The status was evtStatus.

Message #

Initial Machine Configuration was unable to update the system BCD to prevent future execution.  The status was %1.

Fields #

NameDescription
evtStatus HexInt32

Event ID 5: Value blocked: evtValueNameLength under the key, evtKeyPathLength, was NOT set after failing validation.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

Value blocked: evtValueNameLength under the key, evtKeyPathLength, was NOT set after failing validation.

Message #

Value blocked: %4 under the key, %2, was NOT set after failing validation.

Fields #

NameDescription
evtKeyPathLength UInt16
evtKeyPath UnicodeString
evtValueNameLength UInt16
evtValueName UnicodeString

Event ID 6: Value set: evtValueNameLength under the key, evtKeyPathLength, was set after passing validation.

#
Provider
Microsoft-Windows-CoreSystem-InitMachineConfig
Channel
System

Description

Value set: evtValueNameLength under the key, evtKeyPathLength, was set after passing validation.

Message #

Value set: %4 under the key, %2, was set after passing validation.

Fields #

NameDescription
evtKeyPathLength UInt16
evtKeyPath UnicodeString
evtValueNameLength UInt16
evtValueName UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 0b886108-1899-4d3a-9c0d-42d8fc4b9108

Defined in cmimcext.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3089, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3323, captured 2026-06-02

Downloads