Microsoft-Windows-Dhcp-Client

EventTitleChannelSampleRule
1000Your computer has lost the lease to its IP address Address on the Network Card …AdminNN
1001Your computer was not assigned an address from the network (by the DHCP Server) …AdminYN
1002The IP address lease Address1 for the Network Card with network address …AdminYN
1003Your computer was not able to renew its address from the network (from the DHCP …AdminNN
1004Error occurred in stopping the Dhcpv4 Client service.SystemNN
1005Your computer has detected that the IP address Address for the Network Card with …AdminNN
1006Your computer was unable to automatically configure the IP parameters for the …AdminNN
1007Your computer has automatically configured the IP address for the Network Card …AdminNN
1008Your computer was unable to initialize a Network Interface attached to the …AdminNN
1018Dhcpv6 Initialization has failed on the computer with the error code StatusCode.SystemNN
1019Unplumbing OLD Config for the adapter: AdapterName.OperationalYN
1020Stack Media Connect: AdapterName.OperationalYN
1021MEDIA DISCONNECT: Someone still using context.OperationalYN
1022Updating Stack with CACHED config Address on AdapterName.OperationalNN
1023Updating Stack at address Address on AdapterName.OperationalNN
1024Handling ip conflct on AdapterName.OperationalNN
1025Waiting for Offer on AdapterName.OperationalYN
1026Receiving a DHCP message on AdapterName.OperationalYN
1027Received DHCP message on AdapterName is NOT Offer.OperationalNN
1028Waiting for ACK on AdapterName.OperationalNN
1029Waiting for Renew ACK on AdapterName.OperationalNN
1030OBTAIN LEASE - AdapterName: AdapterName Interface LUID: InterfaceLUID.OperationalYN
1031DhcpRenewState: DhcpRenewState.OperationalNN
1032InitRebootState: InitRebootState.OperationalNN
1033DhcpSetGatewaysAndStaticRoutes for the adapter: AdapterName, Error: ErrorCode.OperationalNN
1034DhcpDeleteGatewaysAndStaticRoutes for the adapter: AdapterName, Error: …OperationalNN
1035Route is added with the values Dest = Address1, DestMask = Address2, NextHop = …OperationalNN
1036Route is deleted with the values Dest = Address1, DestMask = Address2, NextHop = …OperationalNN
1037Locking Dhcp Context: [AdapterName].OperationalYN
1038Unlocking Dhcp Context: [AdapterName].OperationalYN
1039Destroying Dhcp Context: [AdapterName].OperationalYN
1040Successfully Plumbed the address: Address.OperationalNN
1041Successfully Deleted the address: Address.OperationalNN
1042Successfully Plumbed the CACHED address using network identifier (Network Hint): …OperationalNN
1043DhcpRegReadOptionCache returned ErrorCode.OperationalNN
1044RegOpenKeyEx returned ErrorCode.OperationalNN
1045Fallback Params Read Fail.OperationalNN
1046Successfully read fallback configurationOperationalYN
1047RegQueryValueEx returned ErrorCode, Fallback config name type ConfigNameType.OperationalYN
1048Registering AdapterName: Registering_AdapterName Address: Address Flags : …OperationalNN
1049Deregistering AdapterName: Deregistering_AdapterName.OperationalNN
1050Deregistering AdapterName: [Dynamic DNS disabled].OperationalNN
1051Failed to Acquire Wcm in Disconnected Standby.OperationalNN
50001Media Connect notification received on interface InterfaceId.OperationalYN
50002Media Disconnect notification received on interface InterfaceId.OperationalYN
50003Media Reconnect notification received on interface InterfaceId.OperationalNN
50004DHCP is enabled on the interface with Interface Id InterfaceId.OperationalYN
50005DHCP is disabled on the interface with Interface Id InterfaceId.OperationalYN
50006Request-Ack is initiated on the interface with Interface Id InterfaceId.OperationalNN
50007Discover-Offer-Request-Ack is initiated on the interface with Interface Id …OperationalYN
50008Interface is converted from static to DHCP on the interface with Interface Id …OperationalNN
50009Discover is sent from the interface InterfaceId.OperationalYN
50010Offer is accepted on the interface InterfaceId.OperationalNN
50011Offer is discarded on the interface InterfaceId.OperationalNN
50012Request is sent from the interface InterfaceId.OperationalNN
50013Ack is accepted on the interface InterfaceId.OperationalNN
50014Ack is discarded on the interface InterfaceId.OperationalNN
50015Nack is received on the interface InterfaceId.AdminNN
50016Unknown message is discarded on the interface InterfaceId.OperationalNN
50017Decline is sent on the interface InterfaceId.OperationalNN
50018Inform is sent on the interface InterfaceId.OperationalNN
50019Release is sent on the interface InterfaceId.OperationalNN
50020The broadcast bit was toggled on the interface InterfaceId.OperationalYN
50021Error occurred in extracting the options on the interface InterfaceId.OperationalNN
50022Setting up a Fallback configuration on interface InterfaceId.OperationalNN
50023Offer Receive Timeout has happened on the interface InterfaceId.OperationalYN
50024Ack Receive Timeout has happened on the interface InterfaceId.OperationalNN
50025Cancelling pending renewals on the interface with the Interface Id InterfaceId.OperationalYN
50028Address Address is plumbed on the interface InterfaceId.OperationalNN
50029Address Address is unplumbed on the interface InterfaceId.OperationalNN
50030Plumbing error has occurred on the interface InterfaceId.OperationalNN
50032Lease is expired on the interface InterfaceId.OperationalNN
50033An interface is added whose interface index is InterfaceId and Status Code is …OperationalYN
50034An error has occurred in initializing the interface InterfaceId.AdminNN
50035Routes are updated on the interface InterfaceId.OperationalNN
50036DHCPv4 client service is startedSystemYN
50037DHCPv4 client service is stopped.SystemYN
50038An error occurred in initializing DHCPv4.SystemNN
50039An error has occurred in opening the socket on the interface InterfaceId.OperationalNN
50040An error has occurred in closing the socket on the interface InterfaceId.OperationalNN
50041Domain change notification is received from DNSAdminYN
50042DNS registration has happened for the interface InterfaceId.OperationalNN
50043DNS Deregistration has happened for the interface InterfaceId.OperationalNN
50044Inform ack is received on the interface InterfaceId.OperationalNN
50053A network error occurred when trying to send a message on interface InterfaceId.OperationalNN
50055Gateway address Address is reachable on the interface InterfaceId.OperationalNN
50056Gateway is not reachable on the interface InterfaceId.OperationalNN
50058Your computer was successfully assigned an address from the network, and it can …OperationalNN
50059Route is added with the values Dest = Str1, DestMask = Str2, NextHop = Str3, …OperationalNN
50060Route is deleted with the values Dest = Str1, DestMask = Str2, NextHop = Str3, …OperationalNN
50061An offer is received for the dummy discovers that are sent for Diagnostics on …OperationalNN
50062Checking reachability of gateway Address on the the interface InterfaceId.OperationalNN
50063DHCP has notified NLA for the configuration changes for the interface …OperationalYN
50064DHCP has run the cache scavenger for the interface InterfaceId.OperationalNN
50065DHCP has found a match in the cache for Service Set Identifier(SSID) …AdminNN
50066DHCP has plumbed an address using Service Set Identifier(SSID) …AdminNN
50067DHCP has received a Service Set Identifier(SSID) NetworkHintString(Hexadecimal …AdminNN
50068Address Address being plumbed for adapter InterfaceId already exists.AdminNN
50069The broadcast bit BoolFlag was successfully set and cached on the interface …OperationalYN
50070DHCP has not received a Service Set Identifier(SSID) for the interface …OperationalYN
50071DHCP has not found a match in the cache for Service Set Identifier(SSID) …OperationalNN
50072Network Diagnostics Framework(NDF) discovery is being initiated on interface …OperationalNN
50073Network Diagnostics Framework(NDF) discovery failed to discover a DHCP server on …OperationalNN
50074Firewall port DwordVal is exempted on interface InterfaceId.OperationalYN
50075Firewall port DwordVal is closed on interface InterfaceId.OperationalYN
50076DHCP has not plumbed an address using Service Set Identifier(SSID) …AdminNN
50077Regular address acquisition will be done on interface InterfaceId because …OperationalNN
50081DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER …OperationalNN
50083Attempting to acquire a reference for interface InterfaceId.OperationalNN
50084Attempting to release the reference for interface InterfaceId.OperationalNN
50085Registered duplicate address detection on interface InterfaceId for IP address …OperationalNN
50086Completed duplicate address detection on interface InterfaceId for IP address …OperationalNN
50087Duplicate address detection on interface InterfaceId for IP address Address …OperationalNN
50088Parameter change request registered for process ProcID with descriptor UniqueID.OperationalNN
50089Parameter change request unregistered for process ProcID with descriptor …OperationalNN
50090Parameter change request notified for process ProcID with descriptor UniqueID.OperationalNN
50091Parameter request received on interface with LUID InterfaceLUID.OperationalYN
50092Parameter request unblocked on interface with LUID InterfaceLUID and index …OperationalYN
50093Parameter request completed on interface with LUID InterfaceLUID and index …OperationalYN
50094Firewall port DwordVal1 exemption triggered on interface InterfaceId.OperationalYN
50095Firewall port DwordVal1 close triggered on interface InterfaceId.OperationalYN
50096DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER …OperationalNN
50097DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER …OperationalNN
50098DHCP will not try regular IPv4 address acquisition on interface InterfaceId …OperationalNN
50099DHCP will try regular IPv4 address acquisition on interface InterfaceId even …OperationalNN
50100DHCP will try regular IPv4 address acquisition on interface InterfaceId due to …OperationalNN
50101The DHCPv4 client received connected standby entry notification.OperationalNN
50102The DHCPv4 client received connected standby exit notification.OperationalYN
50103DHCPv4 client registered for shutdown notificationSystemYN
50104DHCPv4 client received shutdown notificationSystemYN
50105DHCPv4 client ProcessDHCPRequestForever received TERMINATE_EVENTSystemYN
50106DHCPv4 is waiting on DHCPv6 service to stopSystemYN
50107Firewall port exemption is in progress but incomplete.OperationalNN
60000PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId.OperationalNN
60001PERFTRACK (DORA): Offer is accepted on the interface InterfaceId.OperationalNN
60002PERFTRACK: Gateway is reachable on the interface InterfaceId.OperationalNN
60003PERFTRACK: DHCP is not enabled on the interface InterfaceId.OperationalYN
60004PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since …OperationalNN
60005PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after …OperationalNN
60006PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId …OperationalNN
60007PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after …OperationalNN
60010PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId.OperationalNN
60011PERFTRACK (DORA): Offer is accepted on the interface InterfaceId.OperationalNN
60012PERFTRACK: Gateway is reachable on the interface InterfaceId.OperationalNN
60013PERFTRACK: DHCP is not enabled on the interface InterfaceId.OperationalYN
60014PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since …OperationalNN
60015PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after …OperationalNN
60016PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId …OperationalNN
60017PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after …OperationalNN
60018PERFTRACK (DHCPv4): Media Connect on interface InterfaceId.OperationalYN
60019PERFTRACK (DHCPv4): End of Media Connect on interface InterfaceId.OperationalYN
60020PERFTRACK (Media Reconnect): Media reconnect notification was received on …OperationalNN
60021PERFTRACK (Discover-DelayedResponse): Offer/Ack is not received for first …OperationalNN
60022PERFTRACK (Discover-Timeout): No response is received for all 8 discovers on …OperationalYN
60023PERFTRACK (Request-DelayedAck): Ack is not received for first request on …OperationalNN
60024PERFTRACK (Request-NoResponse): There is no response for INIT-REBOOT Request on …OperationalNN
60025PERFTRACK: Fallback address Address is plumbed on interface InterfaceId after …OperationalNN
60026Entered ProcessDhcpRequestForever.OperationalYN
60027ProcessDhcpRequestForever Timed out.OperationalYN
60028CreateRenewalSignalHandle failed with error StatusCode.OperationalNN
60029DeleteRenewTimer failed with error StatusCode.OperationalNN
60030ResetRenewalSignalHandle failed with error StatusCode.OperationalNN
60031CreateRenewTimer failed with error StatusCode.OperationalNN
60032ProcessDhcpRequestForever failed with error StatusCode.OperationalNN

Event ID 1000: Your computer has lost the lease to its IP address Address on the Network Card with network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
LostIpAddress

Message #

Your computer has lost the lease to its IP address %1 on the Network Card with network address %3.

Fields #

NameDescription
Address UInt32
HWLength UInt32
HWAddress Binary

Event ID 1001: Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address HWAddress.

#
Channel
Admin
Level
Error
Task
AddressConfigurationStateEvent
Opcode
IpAddressNotAssigned

Description

Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address HWAddress. The following error occurred: StatusCode. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Message #

Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address %2.  The following error occurred: %3. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Fields #

NameDescription
HWLength UInt32
HWAddress Binary
StatusCode UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 2,
    "task": 3,
    "opcode": 75,
    "keywords": 4611686018427387905,
    "time_created": "2026-03-13T20:26:34.536116+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Admin",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "HWLength": 6,
    "HWAddress": "00155D0A1500",
    "StatusCode": 121
  },
  "message": ""
}

Event ID 1002: The IP address lease Address1 for the Network Card with network address HWAddress has been denied by the DHCP server Address2 (The DHCP Server sent a DHCPNACK message).

#
Channel
Admin
Level
Error
Task
AddressConfigurationStateEvent
Opcode
IpLeaseDenied

Message #

The IP address lease %1 for the Network Card with network address %3 has been denied by the DHCP server %4 (The DHCP Server sent a DHCPNACK message).

Fields #

NameDescription
Address1 UInt32
HWLength UInt32
HWAddress Binary
Address2 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1002,
    "version": 0,
    "level": 2,
    "task": 3,
    "opcode": 76,
    "keywords": 4611686018427387905,
    "time_created": "2023-10-25T22:48:31.191302+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 2076,
      "thread_id": 2312
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Admin",
    "computer": "WinDevEval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "Address1": 2182457536,
    "HWLength": 6,
    "HWAddress": "000C29B19818",
    "Address2": 0
  },
  "message": ""
}

References #

Event ID 1003: Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
IpLeaseRenewalFailed

Description

Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address HWAddress. The following error occurred: StatusCode. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Message #

Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address %2.  The following error occurred: %3. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Fields #

NameDescription
HWLength UInt32
HWAddress Binary
StatusCode UInt32NTSTATUS reference

Event ID 1004: Error occurred in stopping the Dhcpv4 Client service.

#
Channel
System
Task
ServiceStateEvent
Opcode
ErrorServiceStop

Description

Error occurred in stopping the Dhcpv4 Client service. Error code is StatusCode. ShutDown Flag value is DwordVal.

Message #

Error occurred in stopping the Dhcpv4 Client service. Error code is %1. ShutDown Flag value is %2

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference
DwordVal UInt32

Event ID 1005: Your computer has detected that the IP address Address for the Network Card with network address HWAddress is already in use on the network.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
IPConflict

Description

Your computer has detected that the IP address Address for the Network Card with network address HWAddress is already in use on the network. Your computer will automatically attempt to obtain a different address.

Message #

Your computer has detected that the IP address %1 for the Network Card with network address %3 is already in use on the network. Your computer will automatically attempt to obtain a different address.

Fields #

NameDescription
Address UInt32
HWLength UInt32
HWAddress Binary

Event ID 1006: Your computer was unable to automatically configure the IP parameters for the Network Card with the network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
AutoconfigurationFailed

Description

Your computer was unable to automatically configure the IP parameters for the Network Card with the network address HWAddress. The following error occurred during configuration: StatusCode.

Message #

Your computer was unable to automatically configure the IP parameters for the Network Card with the network address %2.  The following error occurred during configuration: %3.

Fields #

NameDescription
HWLength UInt32
HWAddress Binary
StatusCode UInt32NTSTATUS reference

Event ID 1007: Your computer has automatically configured the IP address for the Network Card with network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
AutoconfigurationSuccess

Description

Your computer has automatically configured the IP address for the Network Card with network address HWAddress. The IP address being used is Address.

Message #

Your computer has automatically configured the IP address for the Network Card with network address %2.  The IP address being used is %3.

Fields #

NameDescription
HWLength UInt32
HWAddress Binary
Address UInt32

Event ID 1008: Your computer was unable to initialize a Network Interface attached to the system.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
InitNetworkInterfaceFailed

Description

Your computer was unable to initialize a Network Interface attached to the system. The error code is: StatusCode.

Message #

Your computer was unable to initialize a Network Interface attached to the system. The error code is: %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 1018: Dhcpv6 Initialization has failed on the computer with the error code StatusCode.

#
Channel
System
Task
AddressConfigurationStateEvent
Opcode
Dhcpv6InitFailed

Description

Dhcpv6 Initialization has failed on the computer with the error code StatusCode. Dhcp service will start with IPv4 only.

Message #

Dhcpv6 Initialization has failed on the computer with the error code %1. Dhcp service will start with IPv4 only.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 1019: Unplumbing OLD Config for the adapter: AdapterName.

#
Channel
Operational
Level
Informational

Message #

Unplumbing OLD Config for the adapter: %1

Fields #

NameDescription
AdapterName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1019,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.762822+00:00",
    "event_record_id": 45,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 10916
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{b009ef7d-3a19-47a7-aee7-9535aba6a145}"
  },
  "message": ""
}

Event ID 1020: Stack Media Connect: AdapterName.

#
Channel
Operational
Level
Informational

Description

Stack Media Connect: AdapterName. Creating new context.

Message #

Stack Media Connect: %1. Creating new context

Fields #

NameDescription
AdapterName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1020,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.399292+00:00",
    "event_record_id": 13,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}"
  },
  "message": ""
}

Event ID 1021: MEDIA DISCONNECT: Someone still using context.

#
Channel
Operational
Level
Informational

Description

MEDIA DISCONNECT: Someone still using context. So not destroying the context.

Message #

MEDIA DISCONNECT: Someone still using context. So not destroying the context

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:26:50.955986+00:00",
    "event_record_id": 103,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 7364
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1022: Updating Stack with CACHED config Address on AdapterName.

#
Channel
Operational

Description

Updating Stack with CACHED config Address on AdapterName. Error code is ErrorCode.

Message #

Updating Stack with CACHED config %1 on %2. Error code is %3.

Fields #

NameDescription
Address UInt32
AdapterName UnicodeString
ErrorCode UInt32

Event ID 1023: Updating Stack at address Address on AdapterName.

#
Channel
Operational

Description

Updating Stack at address Address on AdapterName. Error code is ErrorCode.

Message #

Updating Stack at address %1 on %2. Error code is %3.

Fields #

NameDescription
Address UInt32
AdapterName UnicodeString
ErrorCode UInt32

Event ID 1024: Handling ip conflct on AdapterName.

#
Channel
Operational

Message #

Handling ip conflct on %1.

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1025: Waiting for Offer on AdapterName.

#
Channel
Operational
Level
Informational

Description

Waiting for Offer on AdapterName. Wait time is TimeToWaitLeft milliseconds.

Message #

Waiting for Offer on %1. Wait time is %2 milliseconds

Fields #

NameDescription
AdapterName UnicodeString
TimeToWaitLeft UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.800432+00:00",
    "event_record_id": 53,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{b009ef7d-3a19-47a7-aee7-9535aba6a145}",
    "TimeToWaitLeft": 4984
  },
  "message": ""
}

Event ID 1026: Receiving a DHCP message on AdapterName.

#
Channel
Operational
Level
Informational

Description

Receiving a DHCP message on AdapterName. Error code is ErrorCode.

Message #

Receiving a DHCP message on %1. Error code is %2

Fields #

NameDescription
AdapterName UnicodeString
ErrorCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1026,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:34.785631+00:00",
    "event_record_id": 55,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{b009ef7d-3a19-47a7-aee7-9535aba6a145}",
    "ErrorCode": 121
  },
  "message": ""
}

Event ID 1027: Received DHCP message on AdapterName is NOT Offer.

#
Channel
Operational

Message #

Received DHCP message on %1 is NOT Offer.

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1028: Waiting for ACK on AdapterName.

#
Channel
Operational

Message #

Waiting for ACK on %1.

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1029: Waiting for Renew ACK on AdapterName.

#
Channel
Operational

Message #

Waiting for Renew ACK on %1.

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1030: OBTAIN LEASE - AdapterName: AdapterName Interface LUID: InterfaceLUID.

#
Channel
Operational
Level
Informational

Message #

OBTAIN LEASE - AdapterName: %1 Interface LUID: %2

Fields #

NameDescription
AdapterName UnicodeString
InterfaceLUID HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1030,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.777549+00:00",
    "event_record_id": 49,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{b009ef7d-3a19-47a7-aee7-9535aba6a145}",
    "InterfaceLUID": "0x6008005000000"
  },
  "message": ""
}

Event ID 1031: DhcpRenewState: DhcpRenewState.

#
Channel
Operational

Message #

DhcpRenewState: %1

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1032: InitRebootState: InitRebootState.

#
Channel
Operational

Message #

InitRebootState: %1

Fields #

NameDescription
AdapterName UnicodeString

Event ID 1033: DhcpSetGatewaysAndStaticRoutes for the adapter: AdapterName, Error: ErrorCode.

#
Channel
Operational

Message #

DhcpSetGatewaysAndStaticRoutes for the adapter: %1,  Error: %2

Fields #

NameDescription
AdapterName UnicodeString
ErrorCode UInt32

Event ID 1034: DhcpDeleteGatewaysAndStaticRoutes for the adapter: AdapterName, Error: ErrorCode.

#
Channel
Operational

Message #

DhcpDeleteGatewaysAndStaticRoutes for the adapter: %1,  Error: %2

Fields #

NameDescription
AdapterName UnicodeString
ErrorCode UInt32

Event ID 1035: Route is added with the values Dest = Address1, DestMask = Address2, NextHop = Address3, Address = Address4.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
RouteAdded

Message #

Route is added with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4

Fields #

NameDescription
Address1 UInt32
Address2 UInt32
Address3 UInt32
Address4 UInt32

Event ID 1036: Route is deleted with the values Dest = Address1, DestMask = Address2, NextHop = Address3, Address = Address4.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
RouteDeleted

Message #

Route is deleted with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4

Fields #

NameDescription
Address1 UInt32
Address2 UInt32
Address3 UInt32
Address4 UInt32

Event ID 1037: Locking Dhcp Context: [AdapterName].

#
Channel
Operational
Level
Informational

Message #

Locking Dhcp Context: [%1]

Fields #

NameDescription
AdapterName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1037,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:51.250466+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}"
  },
  "message": ""
}

Event ID 1038: Unlocking Dhcp Context: [AdapterName].

#
Channel
Operational
Level
Informational

Message #

Unlocking Dhcp Context: [%1]

Fields #

NameDescription
AdapterName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1038,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:51.250524+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}"
  },
  "message": ""
}

Event ID 1039: Destroying Dhcp Context: [AdapterName].

#
Channel
Operational
Level
Informational

Message #

Destroying Dhcp Context: [%1]

Fields #

NameDescription
AdapterName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1039,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:51.250530+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "AdapterName": "{2a7bd48e-ddc6-4641-9f41-682f29f1d76c}"
  },
  "message": ""
}

Event ID 1040: Successfully Plumbed the address: Address.

#
Channel
Operational

Message #

Successfully Plumbed the address: %1

Fields #

NameDescription
Address UInt32

Event ID 1041: Successfully Deleted the address: Address.

#
Channel
Operational

Message #

Successfully Deleted the address: %1

Fields #

NameDescription
Address UInt32

Event ID 1042: Successfully Plumbed the CACHED address using network identifier (Network Hint): Address.

#
Channel
Operational

Message #

Successfully Plumbed the CACHED address using network identifier (Network Hint): %1

Fields #

NameDescription
Address UInt32

Event ID 1043: DhcpRegReadOptionCache returned ErrorCode.

#
Channel
Operational

Message #

DhcpRegReadOptionCache returned %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1044: RegOpenKeyEx returned ErrorCode.

#
Channel
Operational

Message #

RegOpenKeyEx returned %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1045: Fallback Params Read Fail.

#
Channel
Operational

Description

Fallback Params Read Fail. Error returned is ErrorCode.

Message #

Fallback Params Read Fail. Error returned is %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1046: Successfully read fallback configuration

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1046,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.397815+00:00",
    "event_record_id": 11,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1047: RegQueryValueEx returned ErrorCode, Fallback config name type ConfigNameType.

#
Channel
Operational
Level
Informational

Message #

RegQueryValueEx returned %1, Fallback config name type %2

Fields #

NameDescription
ErrorCode UInt32
ConfigNameType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 1047,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.397810+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "ErrorCode": 2,
    "ConfigNameType": 0
  },
  "message": ""
}

Event ID 1048: Registering AdapterName: Registering_AdapterName Address: Address Flags : [AdapterName] Error : Flags.

#
Channel
Operational

Message #

Registering AdapterName: %1 Address: %2 Flags : [%3] Error : %4

Fields #

NameDescription
AdapterName UnicodeString
Address UInt32
Flags UInt32
ErrorCode UInt32

Event ID 1049: Deregistering AdapterName: Deregistering_AdapterName.

#
Channel
Operational

Description

Deregistering AdapterName: Deregistering_AdapterName. Errorcode is AdapterName.

Message #

Deregistering AdapterName: %1. Errorcode is %2

Fields #

NameDescription
AdapterName UnicodeString
ErrorCode UInt32

Event ID 1050: Deregistering AdapterName: [Dynamic DNS disabled].

#
Channel
Operational

Description

Deregistering AdapterName: [Dynamic DNS disabled]. Error is ErrorCode.

Message #

Deregistering AdapterName: [Dynamic DNS disabled]. Error is %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1051: Failed to Acquire Wcm in Disconnected Standby.

#
Channel
Operational

Description

Failed to Acquire Wcm in Disconnected Standby. Error is ErrorCode.

Message #

Failed to Acquire Wcm in Disconnected Standby. Error is %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 50001: Media Connect notification received on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
MediaStateEvent
Opcode
MediaConnect

Message #

Media Connect notification received on interface %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50001,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 11,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.397033+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 50002: Media Disconnect notification received on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
MediaStateEvent
Opcode
MediaDisconnect

Message #

Media Disconnect notification received on interface %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50002,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 12,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:51.250425+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 50003: Media Reconnect notification received on interface InterfaceId.

#
Channel
Operational
Task
MediaStateEvent
Opcode
MediaReconnect

Message #

Media Reconnect notification received on interface %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50004: DHCP is enabled on the interface with Interface Id InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
DhcpEnabled

Message #

DHCP is enabled on the interface with Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50004,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 35,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:07:47.871464+00:00",
    "event_record_id": 20,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 7584
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 12
  },
  "message": ""
}

Event ID 50005: DHCP is disabled on the interface with Interface Id InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
DhcpDisabled

Message #

DHCP is disabled on the interface with Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50005,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 36,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.397793+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 50006: Request-Ack is initiated on the interface with Interface Id InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
InitRequestAck

Message #

Request-Ack is initiated on the interface with Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50007: Discover-Offer-Request-Ack is initiated on the interface with Interface Id InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
InitDORA

Message #

Discover-Offer-Request-Ack is initiated on the interface with Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50007,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 17,
    "keywords": 9223372036854775809,
    "time_created": "2026-03-13T20:24:29.781267+00:00",
    "event_record_id": 51,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 50008: Interface is converted from static to DHCP on the interface with Interface Id InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
StaticToDhcp

Message #

Interface is converted from static to DHCP on the interface with Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50009: Discover is sent from the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
DiscoverSent

Description

Discover is sent from the interface InterfaceId. Status code is StatusCode.

Message #

Discover is sent from the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50009,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 18,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.800418+00:00",
    "event_record_id": 52,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18,
    "StatusCode": 0
  },
  "message": ""
}

Event ID 50010: Offer is accepted on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
OfferReceived

Description

Offer is accepted on the interface InterfaceId. Offered Address is Address1. Server address is Address2.

Message #

Offer is accepted on the interface %1. Offered Address is %2. Server address is %3

Fields #

NameDescription
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 50011: Offer is discarded on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
OfferDiscarded

Description

Offer is discarded on the interface InterfaceId. Error code is StatusCode.

Message #

Offer is discarded on the interface %1. Error code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50012: Request is sent from the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
RequestSent

Description

Request is sent from the interface InterfaceId. Status code is StatusCode.

Message #

Request is sent from the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50013: Ack is accepted on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AckReceived

Description

Ack is accepted on the interface InterfaceId. Received Address is Address1. Server address is Address2.

Message #

Ack is accepted on the interface %1. Received Address is %2. Server address is %3

Fields #

NameDescription
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 50014: Ack is discarded on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AckDiscarded

Description

Ack is discarded on the interface InterfaceId. Error code is StatusCode.

Message #

Ack is discarded on the interface %1. Error code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50015: Nack is received on the interface InterfaceId.

#
Channel
Admin
Task
ProtocolStateEvent
Opcode
NackReceived

Message #

Nack is received on the interface %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50016: Unknown message is discarded on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
UnknownMessageDiscarded

Message #

Unknown message is discarded on the interface %1.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50017: Decline is sent on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
DeclineSent

Description

Decline is sent on the interface InterfaceId. Status code is StatusCode.

Message #

Decline is sent on the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50018: Inform is sent on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
InformSent

Description

Inform is sent on the interface InterfaceId. Status code is StatusCode.

Message #

Inform is sent on the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50019: Release is sent on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
ReleaseSent

Description

Release is sent on the interface InterfaceId. Status code is StatusCode.

Message #

Release is sent on the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50020: The broadcast bit was toggled on the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
BroadcastbitToggled

Description

The broadcast bit was toggled on the interface InterfaceId. The broadcast bit after toggling is BoolFlag.

Message #

The broadcast bit was toggled on the interface %1. The broadcast bit after toggling is %2

Fields #

NameDescription
InterfaceId UInt32
BoolFlag Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50020,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 29,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:25:34.446170+00:00",
    "event_record_id": 74,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18,
    "BoolFlag": true
  },
  "message": ""
}

Event ID 50021: Error occurred in extracting the options on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
ErrorExtractingOptions

Description

Error occurred in extracting the options on the interface InterfaceId. Status code is StatusCode.

Message #

Error occurred in extracting the options on the interface %1. Status code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50022: Setting up a Fallback configuration on interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
FallbackConfigSet

Description

Setting up a Fallback configuration on interface InterfaceId. The Fallback address Address is set. The status code is StatusCode.

Message #

Setting up a Fallback configuration on interface %1. The Fallback address %2 is set. The status code is %3

Fields #

NameDescription
InterfaceId UInt32
Address UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50023: Offer Receive Timeout has happened on the interface InterfaceId.

#
Channel
Operational
Level
Warning
Task
ProtocolStateEvent
Opcode
OfferReceiveTimeout

Message #

Offer Receive Timeout has happened on the interface %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50023,
    "version": 0,
    "level": 3,
    "task": 2,
    "opcode": 31,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:34.785664+00:00",
    "event_record_id": 56,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 50024: Ack Receive Timeout has happened on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AckReceiveTimeout

Message #

Ack Receive Timeout has happened on the interface %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50025: Cancelling pending renewals on the interface with the Interface Id InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
CancelRenewal

Message #

Cancelling pending renewals on the interface with the Interface Id %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50025,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 33,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:51.250447+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 50028: Address Address is plumbed on the interface InterfaceId.

#
Channel
Operational
Collection Priority
Recommended (JSCU-NL)
Task
AddressConfigurationStateEvent
Opcode
AddressPlumbed

Description

Address Address is plumbed on the interface InterfaceId. Status code is StatusCode.

Message #

Address %1 is plumbed on the interface %2. Status code is %3

Fields #

NameDescription
Address UInt32
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50029: Address Address is unplumbed on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
AddressUnplumbed

Description

Address Address is unplumbed on the interface InterfaceId. Status code is StatusCode.

Message #

Address %1 is unplumbed on the interface %2. Status code is %3

Fields #

NameDescription
Address UInt32
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50030: Plumbing error has occurred on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PlumbingError

Description

Plumbing error has occurred on the interface InterfaceId. Status Code is StatusCode.

Message #

Plumbing error has occurred on the interface %1. Status Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50032: Lease is expired on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
LeaseExpired

Description

Lease is expired on the interface InterfaceId. Expired address is Address.

Message #

Lease is expired on the interface %1. Expired address is %2

Fields #

NameDescription
InterfaceId UInt32
Address UInt32

Event ID 50033: An interface is added whose interface index is InterfaceId and Status Code is StatusCode.

#
Channel
Operational
Level
Informational
Task
MediaStateEvent
Opcode
InterfaceAdded

Message #

An interface is added whose interface index is %1 and Status Code is %2.

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50033,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 46,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:18:54.399285+00:00",
    "event_record_id": 12,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 4,
    "StatusCode": 0
  },
  "message": ""
}

Event ID 50034: An error has occurred in initializing the interface InterfaceId.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
ErrorInitializeInterface

Description

An error has occurred in initializing the interface InterfaceId. Error Code is StatusCode.

Message #

An error has occurred in initializing the interface %1. Error Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50035: Routes are updated on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
RouteUpdated

Description

Routes are updated on the interface InterfaceId. Status Code is StatusCode.

Message #

Routes are updated on the interface %1. Status Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50036: DHCPv4 client service is started

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceStart

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50036,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 68,
    "keywords": 2305843009213693952,
    "time_created": "2026-05-29T16:32:53.8773248+00:00",
    "event_record_id": 6716,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1640
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "DHCPv4 client service is started"
}

Event ID 50037: DHCPv4 client service is stopped.

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceStop

Description

DHCPv4 client service is stopped. ShutDown Flag value is DwordVal.

Message #

DHCPv4 client service is stopped. ShutDown Flag value is %1

Fields #

NameDescription
DwordVal UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50037,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 69,
    "keywords": 2305843009213693952,
    "time_created": "2026-06-13T05:22:34.5361905+00:00",
    "event_record_id": 7391,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1640
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "DwordVal": "1"
  },
  "message": "DHCPv4 client service is stopped. ShutDown Flag value is 1"
}

Event ID 50038: An error occurred in initializing DHCPv4.

#
Channel
System
Task
ServiceStateEvent
Opcode
ErrorInitService

Description

An error occurred in initializing DHCPv4. Error Code is StatusCode.

Message #

An error occurred in initializing DHCPv4. Error Code is %1

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 50039: An error has occurred in opening the socket on the interface InterfaceId.

#
Channel
Operational
Task
WinsockStateEvent
Opcode
ErrorOpeningSocket

Description

An error has occurred in opening the socket on the interface InterfaceId. Error Code is StatusCode.

Message #

An error has occurred in opening the socket on the interface %1. Error Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50040: An error has occurred in closing the socket on the interface InterfaceId.

#
Channel
Operational
Task
WinsockStateEvent
Opcode
ErrorClosingSocket

Description

An error has occurred in closing the socket on the interface InterfaceId. Error Code is StatusCode.

Message #

An error has occurred in closing the socket on the interface %1. Error Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50041: Domain change notification is received from DNS

#
Channel
Admin
Level
Informational
Task
DNSStateEvent
Opcode
DomainChangeNotification

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50041,
    "version": 0,
    "level": 4,
    "task": 6,
    "opcode": 71,
    "keywords": 4611686018427387904,
    "time_created": "2023-10-26T04:17:38.252255+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 2228,
      "thread_id": 2320
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Admin",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 50042: DNS registration has happened for the interface InterfaceId.

#
Channel
Operational
Task
DNSStateEvent
Opcode
DnsRegistrationDone

Description

DNS registration has happened for the interface InterfaceId. Status Code is StatusCode. DNS Flag settings is Dword.

Message #

DNS registration has happened for the interface %1. Status Code is %2. DNS Flag settings is %3.

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference
Dword UInt32

Event ID 50043: DNS Deregistration has happened for the interface InterfaceId.

#
Channel
Operational
Task
DNSStateEvent
Opcode
DnsDeregistrationDone

Description

DNS Deregistration has happened for the interface InterfaceId. Status Code is StatusCode.

Message #

DNS Deregistration has happened for the interface %1. Status Code is %2

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50044: Inform ack is received on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
InformAckReceived

Message #

Inform ack is received on the interface %1.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50053: A network error occurred when trying to send a message on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
NetworkError

Description

A network error occurred when trying to send a message on interface InterfaceId. The error code is: StatusCode.

Message #

A network error occurred when trying to send a message on interface %1. The error code is: %2.

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50055: Gateway address Address is reachable on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
GatewayReachable

Message #

Gateway address %1 is reachable on the interface %2

Fields #

NameDescription
Address UInt32
InterfaceId UInt32

Event ID 50056: Gateway is not reachable on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
GatewayUnreachable

Message #

Gateway is not reachable on the interface %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50058: Your computer was successfully assigned an address from the network, and it can now connect to other computers.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
SuccessfulLease

Event ID 50059: Route is added with the values Dest = Str1, DestMask = Str2, NextHop = Str3, Address = Str4.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
RouteAdded

Message #

Route is added with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4

Fields #

NameDescription
Str1 UnicodeString
Str2 UnicodeString
Str3 UnicodeString
Str4 UnicodeString

Event ID 50060: Route is deleted with the values Dest = Str1, DestMask = Str2, NextHop = Str3, Address = Str4.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
RouteDeleted

Message #

Route is deleted with the values Dest = %1, DestMask = %2, NextHop = %3, Address = %4

Fields #

NameDescription
Str1 UnicodeString
Str2 UnicodeString
Str3 UnicodeString
Str4 UnicodeString

Event ID 50061: An offer is received for the dummy discovers that are sent for Diagnostics on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
OfferReceivedForDiagnostics

Message #

An offer is received for the dummy discovers that are sent for Diagnostics on the interface %1.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50062: Checking reachability of gateway Address on the the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
StartGatewayReachabilityTest

Message #

Checking reachability of gateway %1 on the the interface %2

Fields #

NameDescription
Address UInt32
InterfaceId UInt32

Event ID 50063: DHCP has notified NLA for the configuration changes for the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
NLANotified

Message #

DHCP has notified NLA for the configuration changes for the interface %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50063,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 53,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:25:34.446138+00:00",
    "event_record_id": 73,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 50064: DHCP has run the cache scavenger for the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
CacheScavengerRun

Message #

DHCP has run the cache scavenger for the interface %1

Fields #

NameDescription
InterfaceId UInt32

Event ID 50065: DHCP has found a match in the cache for Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network addres...

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
NetworkHintMatchFound

Description

DHCP has found a match in the cache for Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network address HWAddress.

Message #

DHCP has found a match in the cache for Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4

Fields #

NameDescription
NetworkHintString UnicodeString
NetworkHint UnicodeString
HWLength UInt32
HWAddress Binary

Event ID 50066: DHCP has plumbed an address using Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
MatchedAddressPlumbed

Message #

DHCP has plumbed an address using Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4

Fields #

NameDescription
NetworkHintString UnicodeString
NetworkHint UnicodeString
HWLength UInt32
HWAddress Binary

Event ID 50067: DHCP has received a Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network address HWAddress.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
NetworkHintReceived

Message #

DHCP has received a Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4

Fields #

NameDescription
NetworkHintString UnicodeString
NetworkHint UnicodeString
HWLength UInt32
HWAddress Binary

Event ID 50068: Address Address being plumbed for adapter InterfaceId already exists.

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
AddressAlreadyExists

Message #

Address %1 being plumbed for adapter %2 already exists

Fields #

NameDescription
Address UInt32
InterfaceId UInt32

Event ID 50069: The broadcast bit BoolFlag was successfully set and cached on the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
BroadcastbitCached

Message #

The broadcast bit %1 was successfully set and cached on the interface %2

Fields #

NameDescription
BoolFlag Boolean
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50069,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 87,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:26:34.536775+00:00",
    "event_record_id": 94,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "BoolFlag": false,
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 50070: DHCP has not received a Service Set Identifier(SSID) for the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
NetworkHintNotReceived

Message #

DHCP has not received a Service Set Identifier(SSID) for the interface %1

Fields #

NameDescription
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50070,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 88,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.762788+00:00",
    "event_record_id": 44,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 10916
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 50071: DHCP has not found a match in the cache for Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
NetworkHintMatchNotFound

Message #

DHCP has not found a match in the cache for Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the interface %3

Fields #

NameDescription
NetworkHintString UnicodeString
NetworkHint UnicodeString
InterfaceId UInt32

Event ID 50072: Network Diagnostics Framework(NDF) discovery is being initiated on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
DiagnosticsInitiated

Message #

Network Diagnostics Framework(NDF) discovery is being initiated on interface %1.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50073: Network Diagnostics Framework(NDF) discovery failed to discover a DHCP server on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
DiagnosticsFailed

Message #

Network Diagnostics Framework(NDF) discovery failed to discover a DHCP server on interface %1.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50074: Firewall port DwordVal is exempted on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
FirewallPortExempted

Description

Firewall port DwordVal is exempted on interface InterfaceId. Error code is DwordVal1.

Message #

Firewall port %1 is exempted on interface %2. Error code is %3.

Fields #

NameDescription
DwordVal UInt32
InterfaceId UInt32
DwordVal1 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50074,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 92,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.809876+00:00",
    "event_record_id": 54,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3664
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "DwordVal": 68,
    "InterfaceId": 18,
    "DwordVal1": 0
  },
  "message": ""
}

Event ID 50075: Firewall port DwordVal is closed on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
FirewallPortClosed

Description

Firewall port DwordVal is closed on interface InterfaceId. Error code is DwordVal1.

Message #

Firewall port %1 is closed on interface %2. Error code is %3.

Fields #

NameDescription
DwordVal UInt32
InterfaceId UInt32
DwordVal1 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50075,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 93,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:26:34.580885+00:00",
    "event_record_id": 97,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3664
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "DwordVal": 68,
    "InterfaceId": 18,
    "DwordVal1": 0
  },
  "message": ""
}

Event ID 50076: DHCP has not plumbed an address using Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network address ...

#
Channel
Admin
Task
AddressConfigurationStateEvent
Opcode
MatchedAddressNotPlumbed

Description

DHCP has not plumbed an address using Service Set Identifier(SSID) NetworkHintString(Hexadecimal value of SSID: NetworkHint) for the Network Card with the network address HWAddress since the lease has expired.

Message #

DHCP has not plumbed an address using Service Set Identifier(SSID) %1(Hexadecimal value of SSID: %2) for the Network Card with the network address %4 since the lease has expired

Fields #

NameDescription
NetworkHintString UnicodeString
NetworkHint UnicodeString
HWLength UInt32
HWAddress Binary

Event ID 50077: Regular address acquisition will be done on interface InterfaceId because aggressive address acquisition is turned ON.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AggressiveRetryOn

Message #

Regular address acquisition will be done on interface %1 because aggressive address acquisition is turned ON.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50081: DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AbandonDiscovInCSSinceDhcp

Description

DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state and the interface has the DHCP IPv6 address Address.

Message #

DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state and the interface has the DHCP IPv6 address %3.

Fields #

NameDescription
DwordVal1 UInt32
InterfaceId UInt32
Address Binary

Event ID 50083: Attempting to acquire a reference for interface InterfaceId.

#
Channel
Operational
Task
MediaStateEvent
Opcode
AcquireNICReference

Description

Attempting to acquire a reference for interface InterfaceId. Error code is StatusCode.

Message #

Attempting to acquire a reference for interface %1. Error code is %2.

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50084: Attempting to release the reference for interface InterfaceId.

#
Channel
Operational
Task
MediaStateEvent
Opcode
ReleaseNICReference

Description

Attempting to release the reference for interface InterfaceId. Error code is StatusCode.

Message #

Attempting to release the reference for interface %1. Error code is %2.

Fields #

NameDescription
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50085: Registered duplicate address detection on interface InterfaceId for IP address Address.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
RegisterConflictDetectionNotification

Message #

Registered duplicate address detection on interface %1 for IP address %2.

Fields #

NameDescription
InterfaceId UInt32
Address UInt32

Event ID 50086: Completed duplicate address detection on interface InterfaceId for IP address Address.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
ConflictDetectionComplete

Description

Completed duplicate address detection on interface InterfaceId for IP address Address. Error code is StatusCode.

Message #

Completed duplicate address detection on interface %1 for IP address %2. Error code is %3.

Fields #

NameDescription
InterfaceId UInt32
Address UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50087: Duplicate address detection on interface InterfaceId for IP address Address timed out - reattempting.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
ConflictDetectionTentative

Message #

Duplicate address detection on interface %1 for IP address %2 timed out - reattempting.

Fields #

NameDescription
InterfaceId UInt32
Address UInt32

Event ID 50088: Parameter change request registered for process ProcID with descriptor UniqueID.

#
Channel
Operational
Task
NetworkParameterStateEvent
Opcode
ParamChangeRegister

Message #

Parameter change request registered for process %1 with descriptor %2.

Fields #

NameDescription
ProcID UInt32
UniqueID UInt32
EventPath AnsiString
ClassIDSize UInt32
ClassID Binary
OptListSize UInt32
OptList Binary
IsVendor Boolean

Event ID 50089: Parameter change request unregistered for process ProcID with descriptor UniqueID.

#
Channel
Operational
Task
NetworkParameterStateEvent
Opcode
ParamChangeUnregister

Message #

Parameter change request unregistered for process %1 with descriptor %2.

Fields #

NameDescription
ProcID UInt32
UniqueID UInt32

Event ID 50090: Parameter change request notified for process ProcID with descriptor UniqueID.

#
Channel
Operational
Task
NetworkParameterStateEvent
Opcode
ParamChangeNotification

Description

Parameter change request notified for process ProcID with descriptor UniqueID. The status of the operation was StatusCode.

Message #

Parameter change request notified for process %1 with descriptor %2. The status of the operation was %3.

Fields #

NameDescription
ProcID UInt32
UniqueID UInt32
StatusCode UInt32NTSTATUS reference

Event ID 50091: Parameter request received on interface with LUID InterfaceLUID.

#
Channel
Operational
Level
Informational
Task
NetworkParameterStateEvent
Opcode
ParamRequest

Description

Parameter request received on interface with LUID InterfaceLUID. Attempting to acquire the interface context.

Message #

Parameter request received on interface with LUID %1. Attempting to acquire the interface context.

Fields #

NameDescription
InterfaceLUID HexInt64
ClassIDSize UInt32
ClassID Binary
StandardOptListSize UInt32
StandardOptList Binary
VendorOptListSize UInt32
VendorOptList Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50091,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 114,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T05:29:24.468880+00:00",
    "event_record_id": 311,
    "correlation": {
      "ActivityID": "016B2C13-AC33-4F64-8DD0-EF124435F040"
    },
    "execution": {
      "process_id": 1944,
      "thread_id": 2972
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceLUID": "0x6008004000000",
    "ClassIDSize": 0,
    "ClassID": "",
    "StandardOptListSize": 1,
    "StandardOptList": "FC",
    "VendorOptListSize": 0,
    "VendorOptList": ""
  },
  "message": ""
}

Event ID 50092: Parameter request unblocked on interface with LUID InterfaceLUID and index InterfaceId.

#
Channel
Operational
Level
Informational
Task
NetworkParameterStateEvent
Opcode
ParamRequestUnblocked

Message #

Parameter request unblocked on interface with LUID %1 and index %2.

Fields #

NameDescription
InterfaceLUID HexInt64
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50092,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 115,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T05:30:52.676651+00:00",
    "event_record_id": 371,
    "correlation": {
      "ActivityID": "016B2C13-AC33-4F64-8DD0-EF124435F040"
    },
    "execution": {
      "process_id": 1944,
      "thread_id": 2972
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceLUID": "0x6008004000000",
    "InterfaceId": 14
  },
  "message": ""
}

Event ID 50093: Parameter request completed on interface with LUID InterfaceLUID and index InterfaceId.

#
Channel
Operational
Level
Informational
Task
NetworkParameterStateEvent
Opcode
ParamRequestComplete

Description

Parameter request completed on interface with LUID InterfaceLUID and index InterfaceId. The status of the operation was StatusCode.

Message #

Parameter request completed on interface with LUID %1 and index %2. The status of the operation was %3.

Fields #

NameDescription
InterfaceLUID HexInt64
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference
OptDataSize UInt32
OptData Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50093,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 116,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-15T05:30:52.676769+00:00",
    "event_record_id": 374,
    "correlation": {
      "ActivityID": "016B2C13-AC33-4F64-8DD0-EF124435F040"
    },
    "execution": {
      "process_id": 1944,
      "thread_id": 2972
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceLUID": "0x6008004000000",
    "InterfaceId": 14,
    "StatusCode": 0,
    "OptDataSize": 0,
    "OptData": ""
  },
  "message": ""
}

Event ID 50094: Firewall port DwordVal1 exemption triggered on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
FirewallPortExemptionTriggered

Message #

Firewall port %2 exemption triggered on interface %1.

Fields #

NameDescription
InterfaceId UInt32
DwordVal1 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50094,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 117,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:24:29.781248+00:00",
    "event_record_id": 50,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18,
    "DwordVal1": 68
  },
  "message": ""
}

Event ID 50095: Firewall port DwordVal1 close triggered on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
FirewallPortCloseTriggered

Message #

Firewall port %2 close triggered on interface %1.

Fields #

NameDescription
InterfaceId UInt32
DwordVal1 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50095,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 118,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:26:34.535918+00:00",
    "event_record_id": 91,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceId": 18,
    "DwordVal1": 68
  },
  "message": ""
}

Event ID 50096: DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AbandonDiscovInCSSinceStateless

Description

DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state and the interface has the stateless IPv6 address Address.

Message #

DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state and the interface has the stateless IPv6 address %3.

Fields #

NameDescription
DwordVal1 UInt32
InterfaceId UInt32
Address Binary

Event ID 50097: DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
AbandonDiscovInCSSinceStatic

Description

DHCP has cancelled IPv4 address acquisition cycle after DwordVal1 DISCOVER transmissions on interface InterfaceId because the machine is in Connected Standby state and the interface has the static IPv6 address Address.

Message #

DHCP has cancelled IPv4 address acquisition cycle after %1 DISCOVER transmissions on interface %2 because the machine is in Connected Standby state and the interface has the static IPv6 address %3.

Fields #

NameDescription
DwordVal1 UInt32
InterfaceId UInt32
Address Binary

Event ID 50098: DHCP will not try regular IPv4 address acquisition on interface InterfaceId since the machine is in Connected Standby state and the interface has the IPv6 a...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
DontStartDiscovInCSSinceV6Plumbed

Description

DHCP will not try regular IPv4 address acquisition on interface InterfaceId since the machine is in Connected Standby state and the interface has the IPv6 address Address.

Message #

DHCP will not try regular IPv4 address acquisition on interface %1 since the machine is in Connected Standby state and the interface has the IPv6 address %2.

Fields #

NameDescription
InterfaceId UInt32
Address Binary

Event ID 50099: DHCP will try regular IPv4 address acquisition on interface InterfaceId even though the machine is in Connected Standby state since the interface has no IPv...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
StartDiscovInCSSinceV6Unplumbed

Description

DHCP will try regular IPv4 address acquisition on interface InterfaceId even though the machine is in Connected Standby state since the interface has no IPv6 address.

Message #

DHCP will try regular IPv4 address acquisition on interface %1 even though the machine is in Connected Standby state since the interface has no IPv6 address.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50100: DHCP will try regular IPv4 address acquisition on interface InterfaceId due to registry settings even though the machine is in Connected Standby state and t...

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
StartDiscovInCSAtCompulsoryTime

Description

DHCP will try regular IPv4 address acquisition on interface InterfaceId due to registry settings even though the machine is in Connected Standby state and the interface has an IPv6 address.

Message #

DHCP will try regular IPv4 address acquisition on interface %1 due to registry settings even though the machine is in Connected Standby state and the interface has an IPv6 address.

Fields #

NameDescription
InterfaceId UInt32

Event ID 50101: The DHCPv4 client received connected standby entry notification.

#
Channel
Operational
Task
NetworkParameterStateEvent
Opcode
NotifyCSEntry

Event ID 50102: The DHCPv4 client received connected standby exit notification.

#
Channel
Operational
Level
Informational
Task
NetworkParameterStateEvent
Opcode
NotifyCSExit

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 50102,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 120,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:05:03.977367+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 1988
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 50103: DHCPv4 client registered for shutdown notification

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50103,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 129,
    "keywords": 2305843009213693952,
    "time_created": "2026-05-29T16:32:53.8771660+00:00",
    "event_record_id": 6715,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1640
    },
    "channel": "System",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "DHCPv4 client registered for shutdown notification"
}

Event ID 50104: DHCPv4 client received shutdown notification

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50104,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 129,
    "keywords": 2305843009213693952,
    "time_created": "2026-06-13T05:22:34.5305711+00:00",
    "event_record_id": 7384,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1552
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "DHCPv4 client received shutdown notification"
}

Event ID 50105: DHCPv4 client ProcessDHCPRequestForever received TERMINATE_EVENT

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50105,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 129,
    "keywords": 2305843009213693952,
    "time_created": "2026-06-13T05:22:34.5306539+00:00",
    "event_record_id": 7385,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1640
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "DHCPv4 client ProcessDHCPRequestForever received TERMINATE_EVENT"
}

Event ID 50106: DHCPv4 is waiting on DHCPv6 service to stop

#
Channel
System
Level
Informational
Task
ServiceStateEvent
Opcode
ServiceShutdown

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "{15A7A4F8-0072-4EAB-ABAD-F98A4D666AED}",
    "event_source_name": "",
    "event_id": 50106,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 129,
    "keywords": 2305843009213693952,
    "time_created": "2026-06-13T05:22:34.5361065+00:00",
    "event_record_id": 7390,
    "correlation": {},
    "execution": {
      "process_id": 1548,
      "thread_id": 1640
    },
    "channel": "System",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": "DHCPv4 is waiting on DHCPv6 service to stop"
}

Event ID 50107: Firewall port exemption is in progress but incomplete.

#
Channel
Operational
Task
ServiceStateEvent
Opcode
FirewallExemptionDelayed

Description

Firewall port exemption is in progress but incomplete. Error code is DwordVal.

Message #

Firewall port exemption is in progress but incomplete. Error code is %1.

Fields #

NameDescription
DwordVal UInt32

Event ID 60000: PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackAckConfirm

Description

PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId. Confirmed Address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Ack): Address confirmed for the interface %2. Confirmed Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60001: PERFTRACK (DORA): Offer is accepted on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackAckDORA

Description

PERFTRACK (DORA): Offer is accepted on the interface InterfaceId. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (DORA): Offer is accepted on the interface %2. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60002: PERFTRACK: Gateway is reachable on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackGatewayReachable

Message #

PERFTRACK: Gateway is reachable on the interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60003: PERFTRACK: DHCP is not enabled on the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackStatic

Message #

PERFTRACK: DHCP is not enabled on the interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60003,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 61,
    "keywords": 9223653511831486464,
    "time_created": "2026-03-13T20:18:54.399323+00:00",
    "event_record_id": 19,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 60004: PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since no response is received for request.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackFallbackAddressSet

Description

PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since no response is received for request. Status code is StatusCode.

Message #

PERFTRACK: Setting up Fallback configuration on the interface %2 since no response is received for request. Status code is %3

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 60005: PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleRequestAck

Description

PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT. Confirmed address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Ack): Address confirmed for the interface %2 after toggling the broadcast bit in INIT-REBOOT. Confirmed address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60006: PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleDORAAck

Description

PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT-REBOOT. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60007: PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleInitDORA

Description

PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (Init-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60010: PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackAckConfirm

Description

PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId. Confirmed Address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Ack): Address confirmed for the interface %2. Confirmed Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60011: PERFTRACK (DORA): Offer is accepted on the interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackAckDORA

Description

PERFTRACK (DORA): Offer is accepted on the interface InterfaceId. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (DORA): Offer is accepted on the interface %2. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60012: PERFTRACK: Gateway is reachable on the interface InterfaceId.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackGatewayReachable

Message #

PERFTRACK: Gateway is reachable on the interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60013: PERFTRACK: DHCP is not enabled on the interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackStatic

Message #

PERFTRACK: DHCP is not enabled on the interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60013,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 61,
    "keywords": 9223653511831486464,
    "time_created": "2026-03-13T20:18:54.399322+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 60014: PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since no response is received for request.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackFallbackAddressSet

Description

PERFTRACK: Setting up Fallback configuration on the interface InterfaceId since no response is received for request. Status code is StatusCode.

Message #

PERFTRACK: Setting up Fallback configuration on the interface %2 since no response is received for request. Status code is %3

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
StatusCode UInt32NTSTATUS reference

Event ID 60015: PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleRequestAck

Description

PERFTRACK (Request-Ack): Address confirmed for the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT. Confirmed address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Ack): Address confirmed for the interface %2 after toggling the broadcast bit in INIT-REBOOT. Confirmed address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60016: PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleDORAAck

Description

PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT-REBOOT. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (Request-Nack-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT-REBOOT. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60017: PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackToggleInitDORA

Description

PERFTRACK (Init-Dora): Offer is accepted on the interface InterfaceId after toggling the broadcast bit in INIT. Offered Address is Address1. Server address is Address2.

Message #

PERFTRACK (Init-Dora): Offer is accepted on the interface %2 after toggling the broadcast bit in INIT. Offered Address is %3. Server address is %4

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32
Address1 UInt32
Address2 UInt32

Event ID 60018: PERFTRACK (DHCPv4): Media Connect on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
MediaStateEvent
Opcode
PerfTrackMediaConnect

Message #

PERFTRACK (DHCPv4): Media Connect on interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60018,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 14,
    "keywords": 9223653511831486464,
    "time_created": "2026-03-13T20:18:54.399313+00:00",
    "event_record_id": 17,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 60019: PERFTRACK (DHCPv4): End of Media Connect on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
MediaStateEvent
Opcode
PerfTrackMediaConnectEnd

Message #

PERFTRACK (DHCPv4): End of Media Connect on interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60019,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 15,
    "keywords": 9223653511831486464,
    "time_created": "2026-03-13T20:18:51.250436+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 1772,
      "thread_id": 8220
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "2A7BD48E-DDC6-4641-9F41-682F29F1D76C",
    "InterfaceId": 4
  },
  "message": ""
}

Event ID 60020: PERFTRACK (Media Reconnect): Media reconnect notification was received on interface InterfaceId.

#
Channel
Operational
Task
MediaStateEvent
Opcode
PerfTrackMediaReconnect

Message #

PERFTRACK (Media Reconnect): Media reconnect notification was received on interface %2

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60021: PERFTRACK (Discover-DelayedResponse): Offer/Ack is not received for first discover/request on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackDiscoverNetworkLatency

Message #

PERFTRACK (Discover-DelayedResponse): Offer/Ack is not received for first discover/request on interface %2.

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60022: PERFTRACK (Discover-Timeout): No response is received for all 8 discovers on interface InterfaceId.

#
Channel
Operational
Level
Informational
Task
ProtocolStateEvent
Opcode
PerfTrackDiscoverTimeout

Description

PERFTRACK (Discover-Timeout): No response is received for all 8 discovers on interface InterfaceId. Fallback address is not set.

Message #

PERFTRACK (Discover-Timeout): No response is received for all 8 discovers on interface %2. Fallback address is not set.

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60022,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 96,
    "keywords": 9223653511831486464,
    "time_created": "2026-03-13T20:26:34.536149+00:00",
    "event_record_id": 93,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 3428
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "InterfaceGuid": "B009EF7D-3A19-47A7-AEE7-9535ABA6A145",
    "InterfaceId": 18
  },
  "message": ""
}

Event ID 60023: PERFTRACK (Request-DelayedAck): Ack is not received for first request on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackRequestNetworkLatency

Message #

PERFTRACK (Request-DelayedAck): Ack is not received for first request on interface %2.

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60024: PERFTRACK (Request-NoResponse): There is no response for INIT-REBOOT Request on interface InterfaceId.

#
Channel
Operational
Task
ProtocolStateEvent
Opcode
PerfTrackRequestNoResponse

Description

PERFTRACK (Request-NoResponse): There is no response for INIT-REBOOT Request on interface InterfaceId. Gateway is not reachable and fallback address is not set.

Message #

PERFTRACK (Request-NoResponse): There is no response for INIT-REBOOT Request on interface %2. Gateway is not reachable and fallback address is not set.

Fields #

NameDescription
InterfaceGuid GUID
InterfaceId UInt32

Event ID 60025: PERFTRACK: Fallback address Address is plumbed on interface InterfaceId after DHCP did not get response for discover.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
PerfTrackFallbackAfterDiscover

Message #

PERFTRACK: Fallback address %2 is plumbed on interface %3 after DHCP did not get response for discover.

Fields #

NameDescription
InterfaceGuid GUID
Address UInt32
InterfaceId UInt32

Event ID 60026: Entered ProcessDhcpRequestForever.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
ProcessDHCPRequestForeverEntered

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60026,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 122,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:05:04.005177+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 1964
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 60027: ProcessDhcpRequestForever Timed out.

#
Channel
Operational
Level
Informational
Task
AddressConfigurationStateEvent
Opcode
ProcessDHCPRequestForeverTimedout

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Dhcp-Client",
    "guid": "15A7A4F8-0072-4EAB-ABAD-F98A4D666AED",
    "event_source_name": "",
    "event_id": 60027,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 123,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:05:04.014289+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 1868,
      "thread_id": 1964
    },
    "channel": "Microsoft-Windows-Dhcp-Client/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 60028: CreateRenewalSignalHandle failed with error StatusCode.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
CreateRenewalSignalHandleFailed

Message #

CreateRenewalSignalHandle failed with error %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 60029: DeleteRenewTimer failed with error StatusCode.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
DeleteRenewTimerFailed

Message #

DeleteRenewTimer failed with error %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 60030: ResetRenewalSignalHandle failed with error StatusCode.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
ResetRenewalSignalHandleFailed

Message #

ResetRenewalSignalHandle failed with error %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 60031: CreateRenewTimer failed with error StatusCode.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
CreateRenewTimerFailed

Message #

CreateRenewTimer failed with error %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Event ID 60032: ProcessDhcpRequestForever failed with error StatusCode.

#
Channel
Operational
Task
AddressConfigurationStateEvent
Opcode
ProcessDHCPRequestForeverFailed

Message #

ProcessDhcpRequestForever failed with error %1.

Fields #

NameDescription
StatusCode UInt32NTSTATUS reference

Provenance

ETW provider GUID 15a7a4f8-0072-4eab-abad-f98a4d666aed

Defined in dhcpcore.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB