Microsoft-Windows-DfsSvc

EventTitleChannelSampleRule
14318Dfs received a referral request for "path"OperationalNN
14500NetrDfsEnum received an enumerationOperationalNN
14501NetrDfsEnumEx received an enumerationOperationalNN
14503Dfs could not create reparse point for directory childDirectory under directoryOperationalNN
14504Share share mapped to path does not support reparse pointsOperationalNN
14505Share share mapped to directory directory overlaps an existing rootOperationalNN
14508DFS re-established a connection to the PDC to initiate Domain DFS operationsOperationalNN
14509Root share has too many errorsOperationalNN
14510DFS could not initialize winsock libraryOperationalNN
14511DFS could not initialize security libraryOperationalNN
14512DFS could not create DFS support threadOperationalNN
14513DFS could not initialize IP site cacheOperationalNN
14514DFS could not synchronize all DFS rootsOperationalNN
14515DFS could not create event handleOperationalNN
14516DFS could not get required computer informationOperationalNN
14517DFS could not get required cluster informationOperationalNN
14518DFS could not get required DC informationOperationalNN
14519DFS could not initialize prefix tableOperationalNN
14520DFS could not initialize DFS namespaceOperationalNN
14521DFS could not Register DFS NamespacesOperationalNN
14522DFS could not initialize User/kernel communication packageOperationalNN
14523DFS could not contact any DC for Domain DFS operationsOperationalNN
14524DFS could not initialize site support tableOperationalNN
14526DFS could not contact the dc Active DirectoryOperationalNN
14529DFS has connected to the dc Active DirectoryOperationalNN
14530DFS could not access its private data from the Active DirectoryOperationalNN
14531DFS server has finished initializingOperationalYN
14531DFS server has finished initializingSystemYN
14532DFS has recovered from an error and is able to read its private data from the …OperationalNN
14533DFS has finished building all namespacesOperationalYN
14533DFS has finished building all namespacesSystemYN
14534DFS Root share failed during initializationOperationalNN
14535DFS does not support multiple roots on Standard server SKUOperationalNN
14536DFS is unable to return the entire list of trusted domains to the clientOperationalNN
14537DFS is requesting the client for a larger buffer for trusted domain informationOperationalNN
14538DFS was unable to move all matching links of root: share for path oldPath to new …OperationalNN
14539DFS was unable to resynchronize this root target for root:OperationalNN
14540DFS was unable to delete link: share for root: path during a link move …OperationalNN
14541DFS link DFSLink was marked incorrectly as a DFS rootOperationalNN
14542DFS metadata object DFSLink is empty in the metadata for DFS rootOperationalNN
14543The list of folder targets for the following Distributed File System (DFS) …OperationalNN
14544A Distributed File System (DFS) folder with folder targets was created that …OperationalNN
14545A Distributed File System (DFS) folder with folder targets was created that …OperationalNN
14546Dfs successfully created the reparse point for directory childDirectory under …OperationalNN
14547A Distributed File System (DFS) folder was created with conflicting descriptionsOperationalNN
14548The DFS Namespace service could not initialize the trusted domain information on …OperationalNN
14549The DFS Namespace service successfully initialized the trusted domain …OperationalNN
14550The DFS Namespace service could not initialize cross forest trust information on …OperationalNN
14551The DFS Namespace service successfully initialized cross forest trust …OperationalNN
14552The DFS Namespaces service has successfully initialized the following namespace:OperationalNN
14553The DFS Namespaces service failed to initialize the shared folder that hosts the …OperationalNN
14554The DFS Namespaces service has successfully initialized the shared folder that …OperationalNN
1073756142Dfs received a referral request for "path".OperationalNN
1073756324NetrDfsEnum received an enumeration.OperationalNN
1073756325NetrDfsEnumEx received an enumeration.OperationalNN
1073756332DFS re-established a connection to the PDC to initiate Domain DFS operations.OperationalNN
1073756353DFS has connected to the dc Active Directory.OperationalNN
1073756355DFS server has finished initializing.OperationalYN
1073756356DFS has recovered from an error and is able to read its private data from the …OperationalNN
1073756357DFS has finished building all namespaces.OperationalYN
1073756361DFS is requesting the client for a larger buffer for trusted domain information.OperationalNN
1073756373The DFS Namespace service successfully initialized the trusted domain …OperationalNN
1073756375The DFS Namespace service successfully initialized cross forest trust …OperationalNN
1073756376The DFS Namespaces service has successfully initialized the following namespace: …OperationalNN
1073756378The DFS Namespaces service has successfully initialized the shared folder that …OperationalNN
2147498174DFS could not contact the dc Active Directory.OperationalNN
2147498182DFS Root share failed during initialization.OperationalNN
2147498184DFS is unable to return the entire list of trusted domains to the client.OperationalNN
2147498186DFS was unable to move all matching links of root: share for path oldPath to new …OperationalNN
2147498189DFS link DFSLink was marked incorrectly as a DFS root.OperationalNN
2147498190DFS metadata object DFSLink is empty in the metadata for DFS root DFSRoot.OperationalNN
2147498201The DFS Namespaces service failed to initialize the shared folder that hosts the …OperationalNN
3221239975Dfs could not create reparse point for directory childDirectory under directory …OperationalNN
3221239976Share share mapped to path does not support reparse points.OperationalNN
3221239977Share share mapped to directory directory overlaps an existing root.OperationalNN
3221239981Root share has too many errors.OperationalNN
3221239982DFS could not initialize winsock library.OperationalNN
3221239983DFS could not initialize security library.OperationalNN
3221239984DFS could not create DFS support thread.OperationalNN
3221239985DFS could not initialize IP site cache.OperationalNN
3221239986DFS could not synchronize all DFS roots.OperationalNN
3221239987DFS could not create event handle.OperationalNN
3221239988DFS could not get required computer information.OperationalNN
3221239989DFS could not get required cluster information.OperationalNN
3221239990DFS could not get required DC information.OperationalNN
3221239991DFS could not initialize prefix table.OperationalNN
3221239992DFS could not initialize DFS namespace.OperationalNN
3221239993DFS could not Register DFS Namespaces.OperationalNN
3221239994DFS could not initialize User/kernel communication package.OperationalNN
3221239995DFS could not contact any DC for Domain DFS operations.OperationalNN
3221239996DFS could not initialize site support table.OperationalNN
3221240002DFS could not access its private data from the Active Directory.OperationalNN
3221240007DFS does not support multiple roots on Standard server SKU.OperationalNN
3221240011DFS was unable to resynchronize this root target for root.OperationalNN
3221240012DFS was unable to delete link: share for root: path during a link move …OperationalNN
3221240015The list of folder targets for the following Distributed File System (DFS) …OperationalNN
3221240016A Distributed File System (DFS) folder with folder targets was created that …OperationalNN
3221240017A Distributed File System (DFS) folder with folder targets was created that …OperationalNN
3221240018Dfs successfully created the reparse point for directory childDirectory under …OperationalNN
3221240019A Distributed File System (DFS) folder was created with conflicting …OperationalNN
3221240020The DFS Namespace service could not initialize the trusted domain information on …OperationalNN
3221240022The DFS Namespace service could not initialize cross forest trust information on …OperationalNN

Event ID 14318: Dfs received a referral request for "path"

#
Channel
Operational

Fields #

NameDescription
unused UnicodeString
path UnicodeString
__binLength UInt32
binary Binary

Event ID 14500: NetrDfsEnum received an enumeration

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14501: NetrDfsEnumEx received an enumeration

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14503: Dfs could not create reparse point for directory childDirectory under directory

#
Channel
Operational

Fields #

NameDescription
childDirectory UnicodeString
parentDirectory UnicodeString
__binLength UInt32
binary Binary

Event ID 14504: Share share mapped to path does not support reparse points

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
path UnicodeString

Event ID 14505: Share share mapped to directory directory overlaps an existing root

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
directory UnicodeString

Event ID 14508: DFS re-established a connection to the PDC to initiate Domain DFS operations

#
Channel
Operational

Event ID 14509: Root share has too many errors

#
Channel
Operational

Fields #

NameDescription
share UnicodeString

Event ID 14510: DFS could not initialize winsock library

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14511: DFS could not initialize security library

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14512: DFS could not create DFS support thread

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14513: DFS could not initialize IP site cache

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14514: DFS could not synchronize all DFS roots

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14515: DFS could not create event handle

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14516: DFS could not get required computer information

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14517: DFS could not get required cluster information

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14518: DFS could not get required DC information

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14519: DFS could not initialize prefix table

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14520: DFS could not initialize DFS namespace

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14521: DFS could not Register DFS Namespaces

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14522: DFS could not initialize User/kernel communication package

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14523: DFS could not contact any DC for Domain DFS operations

#
Channel
Operational

Event ID 14524: DFS could not initialize site support table

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14526: DFS could not contact the dc Active Directory

#
Channel
Operational

Fields #

NameDescription
dc UnicodeString
__binLength UInt32
binary Binary

Event ID 14529: DFS has connected to the dc Active Directory

#
Channel
Operational

Fields #

NameDescription
dc UnicodeString

Event ID 14530: DFS could not access its private data from the Active Directory

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
__binLength UInt32
binary Binary

Event ID 14531: DFS server has finished initializing

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "event_id": 14531,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-29T21:20:36.5156459+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 14531: DFS server has finished initializing

#
Channel
System
Level
Informational

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "guid": "{7DA4FE0E-FD42-4708-9AA5-89B77A224885}",
    "event_source_name": "",
    "event_id": 14531,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:04.4334246+00:00",
    "event_record_id": 6762,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "DFS server has finished initializing."
}

Event ID 14532: DFS has recovered from an error and is able to read its private data from the Active Directory

#
Channel
Operational

Fields #

NameDescription
share UnicodeString

Event ID 14533: DFS has finished building all namespaces

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "event_id": 14533,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-29T21:20:36.5000098+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 14533: DFS has finished building all namespaces

#
Channel
System
Level
Informational

Fields #

NameDescription
Name

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "guid": "{7DA4FE0E-FD42-4708-9AA5-89B77A224885}",
    "event_source_name": "",
    "event_id": 14533,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-05-29T16:33:04.3240408+00:00",
    "event_record_id": 6761,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": "DFS has finished building all namespaces."
}

Event ID 14534: DFS Root share failed during initialization

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
__binLength UInt32
binary Binary

Event ID 14535: DFS does not support multiple roots on Standard server SKU

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14536: DFS is unable to return the entire list of trusted domains to the client

#
Channel
Operational

Event ID 14537: DFS is requesting the client for a larger buffer for trusted domain information

#
Channel
Operational

Event ID 14538: DFS was unable to move all matching links of root: share for path oldPath to new path

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
oldPath UnicodeString
newPath UnicodeString
__binLength UInt32
binary Binary

Event ID 14539: DFS was unable to resynchronize this root target for root:

#
Channel
Operational

Fields #

NameDescription
share UnicodeString
__binLength UInt32
binary Binary

Event ID 14540: DFS was unable to delete link: share for root: path during a link move operation

#
Channel
Operational

Fields #

NameDescription
path UnicodeString
share UnicodeString
__binLength UInt32
binary Binary

Event ID 14541: DFS link DFSLink was marked incorrectly as a DFS root

#
Channel
Operational

Fields #

NameDescription
DFSLink UnicodeString
__binLength UInt32
binary Binary

Event ID 14542: DFS metadata object DFSLink is empty in the metadata for DFS root

#
Channel
Operational

Fields #

NameDescription
DFSLink UnicodeString
DFSRoot UnicodeString
__binLength UInt32
binary Binary

Event ID 14543: The list of folder targets for the following Distributed File System (DFS) folder is corrupt

#
Channel
Operational

Fields #

NameDescription
DFSLinkDN UnicodeString

Event ID 14544: A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders

#
Channel
Operational

Fields #

NameDescription
DFSNamespace UnicodeString
DFSLink1 UnicodeString
DFSLink2 UnicodeString

Event ID 14545: A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders

#
Channel
Operational

Fields #

NameDescription
DFSNamespace UnicodeString
DFSLink1 UnicodeString

Event ID 14546: Dfs successfully created the reparse point for directory childDirectory under directory

#
Channel
Operational

Fields #

NameDescription
childDirectory UnicodeString
parentDirectory UnicodeString
__binLength UInt32
binary Binary

Event ID 14547: A Distributed File System (DFS) folder was created with conflicting descriptions

#
Channel
Operational

Fields #

NameDescription
DFSNamespace UnicodeString
DFSFolderPath UnicodeString
DFSLinkDN1 UnicodeString
DFSLinkDN2 UnicodeString

Event ID 14548: The DFS Namespace service could not initialize the trusted domain information on this domain controller, but it will periodically retry the operation

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14549: The DFS Namespace service successfully initialized the trusted domain information on this domain controller

#
Channel
Operational

Event ID 14550: The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation

#
Channel
Operational

Fields #

NameDescription
__binLength UInt32
binary Binary

Event ID 14551: The DFS Namespace service successfully initialized cross forest trust information on this domain controller

#
Channel
Operational

Event ID 14552: The DFS Namespaces service has successfully initialized the following namespace:

#
Channel
Operational

Fields #

NameDescription
DFSRoot UnicodeString

Event ID 14553: The DFS Namespaces service failed to initialize the shared folder that hosts the namespace root

#
Channel
Operational

Fields #

NameDescription
SMBShare UnicodeString
__binLength UInt32
binary Binary

Event ID 14554: The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root

#
Channel
Operational

Fields #

NameDescription
SMBShare UnicodeString

Event ID 1073756142: Dfs received a referral request for "path".

#
Channel
Operational

Description

Dfs received a referral request for "path". The return code is in the data.

Message #

Dfs received a referral request for "%2".  The return code is in the data.

Fields #

NameDescription
unused UnicodeString
path UnicodeStringDfs received a referral request for "
binary Binary

Event ID 1073756324: NetrDfsEnum received an enumeration.

#
Channel
Operational

Description

NetrDfsEnum received an enumeration. The return code is in the record data.

Message #

NetrDfsEnum received an enumeration.  The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 1073756325: NetrDfsEnumEx received an enumeration.

#
Channel
Operational

Description

NetrDfsEnumEx received an enumeration. The return code is in the record data.

Message #

NetrDfsEnumEx received an enumeration.  The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 1073756332: DFS re-established a connection to the PDC to initiate Domain DFS operations.

#
Channel
Operational

Event ID 1073756353: DFS has connected to the dc Active Directory.

#
Channel
Operational

Message #

DFS has connected to the %1 Active Directory.

Fields #

NameDescription
dc UnicodeString

Event ID 1073756355: DFS server has finished initializing.

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "event_id": 14531,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-29T21:20:36.5156459+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 1073756356: DFS has recovered from an error and is able to read its private data from the Active Directory.

#
Channel
Operational

Description

DFS has recovered from an error and is able to read its private data from the Active Directory. Root share is now able to read information from the Active Directory.

Message #

DFS has recovered from an error and is able to read its private data from the Active Directory. Root %1 is now able to read information from the Active Directory.

Fields #

NameDescription
share UnicodeString

Event ID 1073756357: DFS has finished building all namespaces.

#
Channel
Operational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DfsSvc",
    "event_id": 14533,
    "level": "Information",
    "task": null,
    "opcode": null,
    "time_created": "2026-03-29T21:20:36.5000098+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "System"
  },
  "event_data": {}
}

Event ID 1073756361: DFS is requesting the client for a larger buffer for trusted domain information.

#
Channel
Operational

Description

DFS is requesting the client for a larger buffer for trusted domain information. Some Win98 clients may not be able to access DFS namespaces.

Message #

DFS is requesting the client for a larger buffer for trusted domain information. Some Win98 clients may not be able to access DFS namespaces.

Event ID 1073756373: The DFS Namespace service successfully initialized the trusted domain information on this domain controller.

#
Channel
Operational

Event ID 1073756375: The DFS Namespace service successfully initialized cross forest trust information on this domain controller.

#
Channel
Operational

Event ID 1073756376: The DFS Namespaces service has successfully initialized the following namespace: DFSRoot.

#
Channel
Operational

Message #

The DFS Namespaces service has successfully initialized the following namespace: %1

Fields #

NameDescription
DFSRoot UnicodeString

Event ID 1073756378: The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root.

#
Channel
Operational

Description

The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root. Shared folder: SMBShare.

Message #

The DFS Namespaces service has successfully initialized the shared folder that hosts the namespace root. Shared folder: %1

Fields #

NameDescription
SMBShare UnicodeString

Event ID 2147498174: DFS could not contact the dc Active Directory.

#
Channel
Operational

Description

DFS could not contact the dc Active Directory. DFS will be using cached data. The return code is in the record data.

Message #

DFS could not contact the %1 Active Directory. DFS will be using cached data. The return code is in the record data.

Fields #

NameDescription
dc UnicodeString
binary Binary

Event ID 2147498182: DFS Root share failed during initialization.

#
Channel
Operational

Description

DFS Root share failed during initialization. The root will not be available.

Message #

DFS Root %1 failed during initialization. The root will not be available.

Fields #

NameDescription
share UnicodeString
binary Binary

Event ID 2147498184: DFS is unable to return the entire list of trusted domains to the client.

#
Channel
Operational

Description

DFS is unable to return the entire list of trusted domains to the client. There are too many trusted domains.

Message #

DFS is unable to return the entire list of trusted domains to the client. There are too many trusted domains.

Event ID 2147498186: DFS was unable to move all matching links of root: share for path oldPath to new path newPath.

#
Channel
Operational

Message #

DFS was unable to move all matching links of root: %1 for path %2 to new path %3

Fields #

NameDescription
share UnicodeString
oldPath UnicodeString
newPath UnicodeString
binary Binary

Event ID 2147498189: DFS link DFSLink was marked incorrectly as a DFS root.

#
Channel
Operational

Description

DFS link DFSLink was marked incorrectly as a DFS root. The DFS namespace is operational on this server. If this namespace is hosted on servers running Windows Server 2003 prior to Service Pack 2 (SP2), or if the server is running Windows 2000 Server, the namespace might not be fully functional on those servers. Please consult the Microsoft Knowledge Base for more information on correcting this issue.

Message #

DFS link %1 was marked incorrectly as a DFS root. The DFS namespace is operational on this server. If this namespace is hosted on servers running Windows Server 2003 prior to Service Pack 2 (SP2), or if the server is running Windows 2000 Server, the namespace might not be fully functional on those servers.  Please consult the Microsoft Knowledge Base for more information on correcting this issue.

Fields #

NameDescription
DFSLink UnicodeString
binary Binary

Event ID 2147498190: DFS metadata object DFSLink is empty in the metadata for DFS root DFSRoot.

#
Channel
Operational

Description

DFS metadata object DFSLink is empty in the metadata for DFS root DFSRoot. The DFS namespace is operational on this server. If this namespace is hosted on servers running Windows Server 2003 prior to Service Pack 2 (SP2), or if the server is running Windows 2000 Server, the namespace might not be fully functional on those servers. Please consult the Microsoft Knowledge Base for more information on correcting this issue.

Message #

DFS metadata object %1 is empty in the metadata for DFS root %2. The DFS namespace is operational on this server. If this namespace is hosted on servers running Windows Server 2003 prior to Service Pack 2 (SP2), or if the server is running Windows 2000 Server, the namespace might not be fully functional on those servers.  Please consult the Microsoft Knowledge Base for more information on correcting this issue.

Fields #

NameDescription
DFSLink UnicodeString
DFSRoot UnicodeString
binary Binary

Event ID 2147498201: The DFS Namespaces service failed to initialize the shared folder that hosts the namespace root.

#
Channel
Operational

Description

The DFS Namespaces service failed to initialize the shared folder that hosts the namespace root. Shared folder: SMBShare.

Message #

The DFS Namespaces service failed to initialize the shared folder that hosts the namespace root. Shared folder: %1

Fields #

NameDescription
SMBShare UnicodeString
binary Binary

Event ID 3221239975: Dfs could not create reparse point for directory childDirectory under directory parentDirectory.

#
Channel
Operational

Description

Dfs could not create reparse point for directory childDirectory under directory parentDirectory. The return code is in the record data.

Message #

Dfs could not create reparse point for directory %1 under directory %2. The return code is in the record data.

Fields #

NameDescription
childDirectory UnicodeString
parentDirectory UnicodeString
binary Binary

Event ID 3221239976: Share share mapped to path does not support reparse points.

#
Channel
Operational

Description

Share share mapped to path does not support reparse points. Upgrade Filesystem and retry.

Message #

Share %1 mapped to %2 does not support reparse points. Upgrade Filesystem and retry.

Fields #

NameDescription
share UnicodeString
path UnicodeString

Event ID 3221239977: Share share mapped to directory directory overlaps an existing root.

#
Channel
Operational

Description

Share share mapped to directory directory overlaps an existing root. The DFS Root will not be created.

Message #

Share %1 mapped to %2 directory overlaps an existing root. The DFS Root will not be created.

Fields #

NameDescription
share UnicodeString
directory UnicodeString

Event ID 3221239981: Root share has too many errors.

#
Channel
Operational

Description

Root share has too many errors. No further eventlogs will be logged on this root.

Message #

Root %1 has too many errors. No further eventlogs will be logged on this root.

Fields #

NameDescription
share UnicodeString

Event ID 3221239982: DFS could not initialize winsock library.

#
Channel
Operational

Description

DFS could not initialize winsock library. The return code is in the record data.

Message #

DFS could not initialize winsock library. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239983: DFS could not initialize security library.

#
Channel
Operational

Description

DFS could not initialize security library. The return code is in the record data.

Message #

DFS could not initialize security library. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239984: DFS could not create DFS support thread.

#
Channel
Operational

Description

DFS could not create DFS support thread. The return code is in the record data.

Message #

DFS could not create DFS support thread. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239985: DFS could not initialize IP site cache.

#
Channel
Operational

Description

DFS could not initialize IP site cache. The return code is in the record data.

Message #

DFS could not initialize IP site cache. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239986: DFS could not synchronize all DFS roots.

#
Channel
Operational

Description

DFS could not synchronize all DFS roots. The return code is in the record data.

Message #

DFS could not synchronize all DFS roots. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239987: DFS could not create event handle.

#
Channel
Operational

Description

DFS could not create event handle. The return code is in the record data.

Message #

DFS could not create event handle. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239988: DFS could not get required computer information.

#
Channel
Operational

Description

DFS could not get required computer information. The return code is in the record data.

Message #

DFS could not get required computer information. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239989: DFS could not get required cluster information.

#
Channel
Operational

Description

DFS could not get required cluster information. The return code is in the record data.

Message #

DFS could not get required cluster information. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239990: DFS could not get required DC information.

#
Channel
Operational

Description

DFS could not get required DC information. The return code is in the record data.

Message #

DFS could not get required DC information. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239991: DFS could not initialize prefix table.

#
Channel
Operational

Description

DFS could not initialize prefix table. The return code is in the record data.

Message #

DFS could not initialize prefix table. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239992: DFS could not initialize DFS namespace.

#
Channel
Operational

Description

DFS could not initialize DFS namespace.The return code is in the record data.

Message #

DFS could not initialize DFS namespace.The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239993: DFS could not Register DFS Namespaces.

#
Channel
Operational

Description

DFS could not Register DFS Namespaces. The return code is in the record data.

Message #

DFS could not Register DFS Namespaces. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239994: DFS could not initialize User/kernel communication package.

#
Channel
Operational

Description

DFS could not initialize User/kernel communication package. The return code is in the record data.

Message #

DFS could not initialize User/kernel communication package. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221239995: DFS could not contact any DC for Domain DFS operations.

#
Channel
Operational

Description

DFS could not contact any DC for Domain DFS operations. This operation will be retried periodically.

Message #

DFS could not contact any DC for Domain DFS operations. This operation will be retried periodically.

Event ID 3221239996: DFS could not initialize site support table.

#
Channel
Operational

Description

DFS could not initialize site support table. The return code is in the record data.

Message #

DFS could not initialize site support table. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221240002: DFS could not access its private data from the Active Directory.

#
Channel
Operational

Description

DFS could not access its private data from the Active Directory. Please manually check network connectivity, security access, and/or consistency of DFS information in the Active Directory. This error occurred on root share.

Message #

DFS could not access its private data from the Active Directory. Please manually check network connectivity, security access, and/or consistency of DFS information in the Active Directory. This error occurred on root %1.

Fields #

NameDescription
share UnicodeString
binary Binary

Event ID 3221240007: DFS does not support multiple roots on Standard server SKU.

#
Channel
Operational

Description

DFS does not support multiple roots on Standard server SKU. Please cleanup the roots or upgrade.

Message #

DFS does not support multiple roots on Standard server SKU. Please cleanup the roots or upgrade.

Fields #

NameDescription
binary Binary

Event ID 3221240011: DFS was unable to resynchronize this root target for root.

#
Channel
Operational

Description

DFS was unable to resynchronize this root target for root: share. This may lead to inaccessability of portions of the DFS namespace. Please verify the share share has all the link directories created for the DFS links. This error may occur if there are directories on this share that may be preventing creation of links.

Message #

DFS was unable to resynchronize this root target for root: %1. This may lead to inaccessability of portions of the DFS namespace.  Please verify the share %1 has all the link directories created for the DFS links. This error may occur if there are directories  on this share that may be preventing creation of links.

Fields #

NameDescription
share UnicodeString
binary Binary

Event ID 3221240012: DFS was unable to delete link: share for root: path during a link move operation.

#
Channel
Operational

Message #

DFS was unable to delete link: %2  for root: %1 during a link move operation.

Fields #

NameDescription
path UnicodeString
share UnicodeString
binary Binary

Event ID 3221240015: The list of folder targets for the following Distributed File System (DFS) folder is corrupt.

#
Channel
Operational

Description

The list of folder targets for the following Distributed File System (DFS) folder is corrupt. DFS folder: DFSLinkDN.

Message #

The list of folder targets for the following Distributed File System (DFS) folder is corrupt. DFS folder: %1

Fields #

NameDescription
DFSLinkDN UnicodeString

Event ID 3221240016: A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders.

#
Channel
Operational

Description

A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: DFSNamespace DFS folder 1: DFSLink1 DFS folder 2: DFSLink2

Message #

A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: %1 DFS folder 1: %2 DFS folder 2: %3

Fields #

NameDescription
DFSNamespace UnicodeString
DFSLink1 UnicodeString
DFSLink2 UnicodeString

Event ID 3221240017: A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders.

#
Channel
Operational

Description

A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: DFSNamespace DFS folder: DFSLink1

Message #

A Distributed File System (DFS) folder with folder targets was created that contains other DFS folders. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: %1 DFS folder: %2

Fields #

NameDescription
DFSNamespace UnicodeString
DFSLink1 UnicodeString

Event ID 3221240018: Dfs successfully created the reparse point for directory childDirectory under directory parentDirectory.

#
Channel
Operational

Description

Dfs successfully created the reparse point for directory childDirectory under directory parentDirectory. This operation had previously failed.

Message #

Dfs successfully created the reparse point for directory %1 under directory %2. This operation had previously failed.

Fields #

NameDescription
childDirectory UnicodeString
parentDirectory UnicodeString
binary Binary

Event ID 3221240019: A Distributed File System (DFS) folder was created with conflicting descriptions.

#
Channel
Operational

Description

A Distributed File System (DFS) folder was created with conflicting descriptions. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: DFSNamespace DFS folder path: DFSFolderPath DFS folder 1: DFSLinkDN1 DFS folder 2: DFSLinkDN2

Message #

A Distributed File System (DFS) folder was created with conflicting descriptions. This can occur if two administrators on different namespace servers create conflicting folder structures at approximately the same time. Namespace: %1 DFS folder path: %2 DFS folder 1: %3 DFS folder 2: %4

Fields #

NameDescription
DFSNamespace UnicodeString
DFSFolderPath UnicodeString
DFSLinkDN1 UnicodeString
DFSLinkDN2 UnicodeString

Event ID 3221240020: The DFS Namespace service could not initialize the trusted domain information on this domain controller, but it will periodically retry the operation.

#
Channel
Operational

Description

The DFS Namespace service could not initialize the trusted domain information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

Message #

The DFS Namespace service could not initialize the trusted domain information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

Fields #

NameDescription
binary Binary

Event ID 3221240022: The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation.

#
Channel
Operational

Description

The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

Message #

The DFS Namespace service could not initialize cross forest trust information on this domain controller, but it will periodically retry the operation. The return code is in the record data.

Fields #

NameDescription
binary Binary

Provenance

ETW provider GUID 7da4fe0e-fd42-4708-9aa5-89b77a224885

Defined in netevent.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB