Microsoft-Windows-DFSN-Server

EventTitleChannelSampleRule
1A referral request has been receivedAnalytic, OperationalNN
2A DC referral request has been processedAnalytic, OperationalNN
3A root referral request has been processedAnalytic, OperationalNN
4A normal referral request has been processedAnalytic, OperationalNN
5A referral response has been generatedAnalytic, OperationalNN
6A referral response has been postedAnalytic, OperationalNN
7IP address IpAddress resolved to site SiteName.AnalyticNN
7IP address IpAddress resolved to siteOperationalNN
11NetrDfsAdd arrivedAnalytic, OperationalNN
21NetrDfsRemove arrivedAnalytic, OperationalNN
31NetrDfsSetInfo arrivedAnalytic, OperationalNN
41NetrDfsGetInfo arrivedAnalytic, OperationalNN
61NetrDfsMove arrivedAnalytic, OperationalNN
71NetrDfsAddFtRoot arrivedAnalytic, OperationalNN
81NetrDfsRemoveFtRoot arrivedAnalytic, OperationalNN
91NetrDfsAddStdRoot arrivedAnalytic, OperationalNN
101NetrDfsRemoveStdRoot arrivedAnalytic, OperationalNN
112LockAcquiredDomainInfoAnalytic, OperationalNN
121LookupRootFolderDoneAnalytic, OperationalNN
131LookupLinkFolderDoneAnalytic, OperationalNN
191NetrDfsEnum arrivedAnalytic, OperationalNN
501Referral request received for dfspath DfsPath from client with IPAddress …OperationalYN
502DFS has resolved server ServerName to IPAddress ServerIpAddress and site …OperationalYN
503Failed to obtain IPAddress for server ServerName.OperationalNN
504Failed to resolve IPAddress IpAddress to site name.OperationalNN
505Referral generated for DFS path DfsPath and client whose site is ClientSite.OperationalYN
506Request for creating new folder or adding target to existing folder completed …OperationalYN
507Request for deleting a link or removing target of existing link completed with …OperationalNN
508Request to modify properties of DfsPath completed with status Status.OperationalNN
509Request to retrieve properties of DfsPath completed with status Status.AnalyticNN
509Request to retrieve properties of DfsPath completed with statusOperationalNN
510Request to enumerate contents of \\DfsPath completed with status Status.AnalyticNN
510Request to enumerate contents of \\DfsPath completed with statusOperationalNN
511Request to move dfs folders from DfsPath to NewDfsPath completed with status …OperationalNN
512Request to create a new dfs namespace or add target to existing namespace …AdminNN
512Request to create a new dfs namespace or add target to existing namespace …OperationalNN
513Request to remove a dfs namespace or remove target from existing namespace …AdminNN
513Request to remove a dfs namespace or remove target from existing namespace …OperationalNN
514Request to create a new standalone or clustered dfs namespace completed with …AdminNN
514Request to create a new standalone or clustered dfs namespace completed with …OperationalNN
515Request to remove standalone or clustered dfs namespace completed with status …AdminNN
515Request to remove standalone or clustered dfs namespace completed with statusOperationalNN
516DFSN service has started performing complete refresh of metadata for namespace …AdminNN
516DFSN service has started performing complete refresh of metadata for namespaceOperationalNN
517DFSN service completed performing refresh of metadata for namespace DfsNamespace …AdminNN
517DFSN service completed performing refresh of metadata for namespace DfsNamespace …OperationalNN
518DFSN service has successfully deleted DFS reparse point DfsReparsepoint on …AdminNN
518DFSN service has successfully deleted DFS reparse point DfsReparsepoint on …OperationalNN
519DFSN service has failed to deleted DFS reparse point DfsReparsepoint on volume …AdminNN
519DFSN service has failed to deleted DFS reparse point DfsReparsepoint on volume …OperationalNN
520The DFS Namespace service could not obtain site costs for the following Active …OperationalNN
521The DFS Namespace service is unable to contact Active Directory Domain ServicesAdmin, OperationalNN
522A DFS folder has incorrect metadata in the registryAdmin, OperationalNN

Event ID 1: A referral request has been received

#
Channel
Analytic, Operational
Task
Referral
Opcode
RequestReceived

Fields #

NameDescription
RequestBuffer Pointer
RequestBufferLength UInt16

Event ID 2: A DC referral request has been processed

#
Channel
Analytic, Operational
Task
Referral
Opcode
DcRequestProcessed

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 3: A root referral request has been processed

#
Channel
Analytic, Operational
Task
Referral
Opcode
RootRequestProcessed

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4: A normal referral request has been processed

#
Channel
Analytic, Operational
Task
Referral
Opcode
NormalRequestProcessed

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 5: A referral response has been generated

#
Channel
Analytic, Operational
Task
Referral
Opcode
ResponseGenerated

Fields #

NameDescription
Request Pointer
Response Pointer
Status UInt32NTSTATUS reference
ResponseLength UInt16

Event ID 6: A referral response has been posted

#
Channel
Analytic, Operational
Task
Referral
Opcode
ResponsePosted

Fields #

NameDescription
Response Pointer
Status UInt32NTSTATUS reference

Event ID 7: IP address IpAddress resolved to site SiteName.

#
Channel
Analytic
Task
Referral
Opcode
ResponsePosted

Message #

IP address %1 resolved to site %2.

Fields #

NameDescription
IpAddress UnicodeString
SiteName UnicodeString
TimeConsumedToResolveInMilliSeconds UInt64

Event ID 7: IP address IpAddress resolved to site

#
Channel
Operational
Task
Referral
Opcode
ResponsePosted

Description

IP address resolved to site .

Fields #

NameDescription
IpAddress UnicodeString
SiteName UnicodeString
TimeConsumedToResolveInMilliSeconds UInt64

Event ID 11: NetrDfsAdd arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
AddArrived

Event ID 21: NetrDfsRemove arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
RemoveArrived

Event ID 31: NetrDfsSetInfo arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
SetInfoArrived

Event ID 41: NetrDfsGetInfo arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
GetInfoArrived

Event ID 61: NetrDfsMove arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
MoveArrived

Event ID 71: NetrDfsAddFtRoot arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
AddFtRootArrived

Event ID 81: NetrDfsRemoveFtRoot arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
RemoveFtRootArrived

Event ID 91: NetrDfsAddStdRoot arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
AddStdRootArrived

Event ID 101: NetrDfsRemoveStdRoot arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
RemoveStdRootArrived

Event ID 112: LockAcquiredDomainInfo

#
Channel
Analytic, Operational
Task
Lock
Opcode
LockAcquiredDomainInfo

Event ID 121: LookupRootFolderDone

#
Channel
Analytic, Operational
Task
Lookup
Opcode
LookupRootFolderDone

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 131: LookupLinkFolderDone

#
Channel
Analytic, Operational
Task
Lookup
Opcode
LookupLinkFolderDone

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 191: NetrDfsEnum arrived

#
Channel
Analytic, Operational
Task
NetrDfs
Opcode
EnumArrived

Event ID 501: Referral request received for dfspath DfsPath from client with IPAddress ClientIpAddress and site ClientSite.

#
Channel
Operational
Level
Informational
Task
Referral

Message #

Referral request received for dfspath %1 from client with IPAddress %2 and site %3.

Fields #

NameDescription
DfsPath UnicodeString
ClientIpAddress UnicodeString
ClientSite UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DFSN-Server",
    "guid": "B6C4E17A-2CAC-4273-A390-6F6B8C8C9F01",
    "event_source_name": "",
    "event_id": 501,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 1152921504606846977,
    "time_created": "2026-03-13T20:05:06.467486+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "8B83AF9E-B321-000B-87F7-838B21B3DC01"
    },
    "execution": {
      "process_id": 4148,
      "thread_id": 4796
    },
    "channel": "Microsoft-Windows-DFSN-Server/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DfsPath": "",
    "ClientIpAddress": "10.2.10.21",
    "ClientSite": "Default-First-Site-Name"
  },
  "message": ""
}

Event ID 502: DFS has resolved server ServerName to IPAddress ServerIpAddress and site ServerSite.

#
Channel
Operational
Task
Referral

Message #

DFS has resolved server %1 to IPAddress %2 and site %3.

Fields #

NameDescription
ServerName UnicodeString
ServerIpAddress UnicodeString
ServerSite UnicodeString
TimeConsumedToResolveInMilliSeconds UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DFSN-Server",
    "event_id": 502,
    "level": "Information",
    "task": "Referral",
    "opcode": "Info",
    "time_created": "2026-04-18T22:00:41.1486364+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-DFSN-Server/Operational"
  },
  "event_data": {
    "ServerIpAddress": "::1",
    "ServerName": "JD-DC01-2022.ludus.domain",
    "ServerSite": "Default-First-Site-Name",
    "TimeConsumedToResolveInMilliSeconds": "0"
  }
}

Event ID 503: Failed to obtain IPAddress for server ServerName.

#
Channel
Operational
Task
Referral

Description

Failed to obtain IPAddress for server ServerName. This may cause the client to access high-cost or out-of-site targets.

Message #

Failed to obtain IPAddress for server %1. This may cause the client to access high-cost or out-of-site targets.

Fields #

NameDescription
ServerName UnicodeString
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 504: Failed to resolve IPAddress IpAddress to site name.

#
Channel
Operational
Task
Referral

Description

Failed to resolve IPAddress IpAddress to site name. This may cause the client to access high-cost or out-of-site targets.

Message #

Failed to resolve IPAddress %1 to site name. This may cause the client to access high-cost or out-of-site targets.

Fields #

NameDescription
IpAddress UnicodeString
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 505: Referral generated for DFS path DfsPath and client whose site is ClientSite.

#
Channel
Operational
Task
Referral

Description

Referral generated for DFS path DfsPath and client whose site is ClientSite. Targets information can be found in the event payload.

Message #

Referral generated for DFS path %2 and client whose site is %3. Targets information can be found in the event payload.

Fields #

NameDescription
DfsPathLength UInt16
DfsPath UnicodeString
ClientSite UnicodeString
TargetCount UInt32
DfsTarget Int16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DFSN-Server",
    "event_id": 505,
    "level": "Information",
    "task": "Referral",
    "opcode": "Info",
    "time_created": "2026-04-18T22:00:41.1499001+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-DFSN-Server/Operational"
  },
  "event_data": {}
}

Event ID 506: Request for creating new folder or adding target to existing folder completed with status:Status.

#
Channel
Operational
Level
Informational
Task
NetrDfs
Opcode
AddCompleted

Description

Request for creating new folder or adding target to existing folder completed with status:Status. DfsFolder:DfsPath TargetServer:ServerName TargetShare:ShareName.

Message #

Request for creating new folder or adding target to existing folder completed with status:%6. DfsFolder:%1 TargetServer:%2 TargetShare:%3

Fields #

NameDescription
DfsPath UnicodeString
ServerName UnicodeString
ShareName UnicodeString
Comment UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DFSN-Server",
    "guid": "B6C4E17A-2CAC-4273-A390-6F6B8C8C9F01",
    "event_source_name": "",
    "event_id": 506,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 41,
    "keywords": 1152921504606846978,
    "time_created": "2026-03-13T20:45:53.834051+00:00",
    "event_record_id": 296,
    "correlation": {},
    "execution": {
      "process_id": 4148,
      "thread_id": 3744
    },
    "channel": "Microsoft-Windows-DFSN-Server/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DfsPath": "\\ludus.domain\\TestDFS\\Folder1",
    "ServerName": "LAB-DC01",
    "ShareName": "TestDFS\\Folder1",
    "Comment": "NULL",
    "Flags": 1,
    "Status": 1168,
    "TimeConsumedInMilliSeconds": 0
  },
  "message": ""
}

Event ID 507: Request for deleting a link or removing target of existing link completed with status:Status.

#
Channel
Operational
Task
NetrDfs
Opcode
RemoveCompleted

Description

Request for deleting a link or removing target of existing link completed with status:Status. DfsFolder:DfsPath TargetServer:ServerName TargetShare:ShareName.

Message #

Request for deleting a link or removing target of existing link completed with status:%4. DfsFolder:%1 TargetServer:%2 TargetShare:%3

Fields #

NameDescription
DfsPath UnicodeString
ServerName UnicodeString
ShareName UnicodeString
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 508: Request to modify properties of DfsPath completed with status Status.

#
Channel
Operational
Task
NetrDfs
Opcode
SetInfoCompleted

Message #

Request to modify properties of %1 completed with status %5.

Fields #

NameDescription
DfsPath UnicodeString
ServerName UnicodeString
ShareName UnicodeString
Level UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 509: Request to retrieve properties of DfsPath completed with status Status.

#
Channel
Analytic
Task
NetrDfs
Opcode
GetInfoCompleted

Message #

Request to retrieve properties of %1 completed with status %5.

Fields #

NameDescription
DfsPath UnicodeString
ServerName UnicodeString
ShareName UnicodeString
Level UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 509: Request to retrieve properties of DfsPath completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
GetInfoCompleted

Description

Request to retrieve properties of completed with status .

Fields #

NameDescription
DfsPath UnicodeString
ServerName UnicodeString
ShareName UnicodeString
Level UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 510: Request to enumerate contents of \\DfsPath completed with status Status.

#
Channel
Analytic
Task
NetrDfs
Opcode
EnumCompleted

Message #

Request to enumerate contents of \\%1 completed with status %4.

Fields #

NameDescription
DfsPath UnicodeString
Level UInt32
PreferredMaxLength UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 510: Request to enumerate contents of \\DfsPath completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
EnumCompleted

Description

Request to enumerate contents of \\ completed with status .

Fields #

NameDescription
DfsPath UnicodeString
Level UInt32
PreferredMaxLength UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 511: Request to move dfs folders from DfsPath to NewDfsPath completed with status Status.

#
Channel
Operational
Task
NetrDfs
Opcode
MoveCompleted

Message #

Request to move dfs folders from %1 to %2 completed with status %4.

Fields #

NameDescription
DfsPath UnicodeString
NewDfsPath UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 512: Request to create a new dfs namespace or add target to existing namespace completed with status Status.

#
Channel
Admin
Task
NetrDfs
Opcode
AddFtRootCompleted

Description

Request to create a new dfs namespace or add target to existing namespace completed with status Status. The namespace server and share name are DfsServer:ServerName Share:RootShare.

Message #

Request to create a new dfs namespace or add target to existing namespace completed with status %6. The namespace server and share name are DfsServer:%1 Share:%2.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
FtDfsName UnicodeString
Comment UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 512: Request to create a new dfs namespace or add target to existing namespace completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
AddFtRootCompleted

Description

Request to create a new dfs namespace or add target to existing namespace completed with status . The namespace server and share name are DfsServer: Share:.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
FtDfsName UnicodeString
Comment UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 513: Request to remove a dfs namespace or remove target from existing namespace completed with status Status.

#
Channel
Admin
Task
NetrDfs
Opcode
RemoveFtRootCompleted

Description

Request to remove a dfs namespace or remove target from existing namespace completed with status Status. The namespace server and share name are DfsServer:ServerName Share:RootShare.

Message #

Request to remove a dfs namespace or remove target from existing namespace completed with status %5. The namespace server and share name are DfsServer:%1 Share:%2.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
FtDfsName UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 513: Request to remove a dfs namespace or remove target from existing namespace completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
RemoveFtRootCompleted

Description

Request to remove a dfs namespace or remove target from existing namespace completed with status . The namespace server and share name are DfsServer: Share:.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
FtDfsName UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 514: Request to create a new standalone or clustered dfs namespace completed with status Status.

#
Channel
Admin
Task
NetrDfs
Opcode
AddStdRootCompleted

Description

Request to create a new standalone or clustered dfs namespace completed with status Status. The namespace server and share name are DfsServer:ServerName Share:RootShare.

Message #

Request to create a new standalone or clustered dfs namespace completed with status %5. The namespace server and share name are DfsServer:%1 Share:%2.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
Comment UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 514: Request to create a new standalone or clustered dfs namespace completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
AddStdRootCompleted

Description

Request to create a new standalone or clustered dfs namespace completed with status . The namespace server and share name are DfsServer: Share:.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
Comment UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 515: Request to remove standalone or clustered dfs namespace completed with status Status.

#
Channel
Admin
Task
NetrDfs
Opcode
RemoveStdRootCompleted

Description

Request to remove standalone or clustered dfs namespace completed with status Status. The namespace server and share name are DfsServer:ServerName Share:RootShare.

Message #

Request to remove standalone or clustered dfs namespace completed with status %4. The namespace server and share name are DfsServer:%1 Share:%2.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 515: Request to remove standalone or clustered dfs namespace completed with status

#
Channel
Operational
Task
NetrDfs
Opcode
RemoveStdRootCompleted

Description

Request to remove standalone or clustered dfs namespace completed with status . The namespace server and share name are DfsServer: Share:.

Fields #

NameDescription
ServerName UnicodeString
RootShare UnicodeString
Flags UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 516: DFSN service has started performing complete refresh of metadata for namespace DfsNamespace.

#
Channel
Admin

Description

DFSN service has started performing complete refresh of metadata for namespace . This task can take time if the namespace has large number of folders and may delay namespace administration operations.

Message #

DFSN service has started performing complete refresh of metadata for namespace %1. This task can take time if the namespace has large number of folders and may delay namespace administration operations.

Fields #

NameDescription
DfsNamespace UnicodeString
SyncFromPDC Boolean
SyncType UInt32

Event ID 516: DFSN service has started performing complete refresh of metadata for namespace

#
Channel
Operational

Description

DFSN service has started performing complete refresh of metadata for namespace . This task can take time if the namespace has large number of folders and may delay namespace administration operations.

Fields #

NameDescription
DfsNamespace UnicodeString
SyncFromPDC Boolean
SyncType UInt32

Event ID 517: DFSN service completed performing refresh of metadata for namespace DfsNamespace with status Status.

#
Channel
Admin

Description

DFSN service completed performing refresh of metadata for namespace DfsNamespace with status Status. Time taken to perform this operation TimeConsumedInMilliSeconds milliseconds.

Message #

DFSN service completed performing refresh of metadata for namespace %1 with status %4. Time taken to perform this operation %5 milliseconds.

Fields #

NameDescription
DfsNamespace UnicodeString
SyncFromPDC Boolean
SyncType UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 517: DFSN service completed performing refresh of metadata for namespace DfsNamespace with status

#
Channel
Operational

Description

DFSN service completed performing refresh of metadata for namespace with status . Time taken to perform this operation milliseconds.

Fields #

NameDescription
DfsNamespace UnicodeString
SyncFromPDC Boolean
SyncType UInt32
Status UInt32NTSTATUS reference
TimeConsumedInMilliSeconds UInt64

Event ID 518: DFSN service has successfully deleted DFS reparse point DfsReparsepoint on volume VolumeName.

#
Channel
Admin

Description

DFSN service has successfully deleted DFS reparse point DfsReparsepoint on volume VolumeName. The reparse point was deleted because it was not belonging to any of the namespaces on this server.

Message #

DFSN service has successfully deleted DFS reparse point %1 on volume %3. The reparse point was deleted because it was not belonging to any of the namespaces on this server.

Fields #

NameDescription
DfsReparsepoint UnicodeString
VolumeNameLength UInt16
VolumeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 518: DFSN service has successfully deleted DFS reparse point DfsReparsepoint on volume

#
Channel
Operational

Description

DFSN service has successfully deleted DFS reparse point on volume . The reparse point was deleted because it was not belonging to any of the namespaces on this server.

Fields #

NameDescription
DfsReparsepoint UnicodeString
VolumeNameLength UInt16
VolumeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 519: DFSN service has failed to deleted DFS reparse point DfsReparsepoint on volume VolumeName with status Status.

#
Channel
Admin

Description

DFSN service has failed to deleted DFS reparse point DfsReparsepoint on volume VolumeName with status Status. The service attempted to delete this reparse point as it does not belong to any of the namespaces on this server.

Message #

DFSN service has failed to deleted DFS reparse point %1 on volume %3 with status %4. The service attempted to delete this reparse point as it does not belong to any of the namespaces on this server.

Fields #

NameDescription
DfsReparsepoint UnicodeString
VolumeNameLength UInt16
VolumeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 519: DFSN service has failed to deleted DFS reparse point DfsReparsepoint on volume VolumeName with status

#
Channel
Operational

Description

DFSN service has failed to deleted DFS reparse point on volume with status . The service attempted to delete this reparse point as it does not belong to any of the namespaces on this server.

Fields #

NameDescription
DfsReparsepoint UnicodeString
VolumeNameLength UInt16
VolumeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 520: The DFS Namespace service could not obtain site costs for the following Active Directory Domain Services site: ADSite.

#
Channel
Operational
Task
Referral

Description

The DFS Namespace service could not obtain site costs for the following Active Directory Domain Services site: ADSite. This might cause clients to access folder targets in other sites. Error code: Status.

Message #

The DFS Namespace service could not obtain site costs for the following Active Directory Domain Services site: %1. This might cause clients to access folder targets in other sites. Error code: %2.

Fields #

NameDescription
ADSite UnicodeString
Status UInt32NTSTATUS reference

Event ID 521: The DFS Namespace service is unable to contact Active Directory Domain Services

#
Channel
Admin, Operational
Task
NetrDfs

Message #

The DFS Namespace service is unable to contact Active Directory Domain Services. 

Domain: %1 
Domain Controller: %2 
LDAP Error: %3

Fields #

NameDescription
DomainName UnicodeString
DomainControllerName UnicodeString
LdapError UInt32

Event ID 522: A DFS folder has incorrect metadata in the registry

#
Channel
Admin, Operational

Description

A DFS folder has incorrect metadata in the registry. The standalone namespace that contains this DFS folder is offline.

Message #

A DFS folder has incorrect metadata in the registry. The standalone namespace that contains this DFS folder is offline.
To bring the namespace back online, delete the following registry entry and then restart the DFS Namespace service. After the namespace is online, recreate the missing DFS folder or restore the DFS folder from a backup of the DFS namespace.

Registry Path: %1 
Status: %2

Fields #

NameDescription
DfsFolderMetadataRegistryPath UnicodeString
Status UInt32NTSTATUS reference

Provenance

ETW provider GUID b6c4e17a-2cac-4273-a390-6f6b8c8c9f01

Defined in dfssvc.exe, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB