Microsoft-Windows-Diagnosis-Scripted
25 events across 4 channels
Event ID 1: The scripted diagnostic engine executed a diagnostic package located at PackagePath with ID PackageId.
#Description
The scripted diagnostic engine executed a diagnostic package located at PackagePath with ID PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackagePath UnicodeString | |
PackageId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"guid": "{E1DD7E52-621D-44E3-A1AD-0370C2B25946}",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": -9223372019674906624,
"time_created": "2026-06-13T05:39:32.6573395+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 5480,
"thread_id": 5084
},
"channel": "Microsoft-Windows-Diagnosis-Scripted/Admin",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance",
"PackageId": "MaintenanceDiagnostic"
},
"message": "The scripted diagnostic engine executed a diagnostic package located at C:\\Windows\\diagnostics\\scheduled\\Maintenance with ID MaintenanceDiagnostic."
}
Event ID 101: The scripted diagnostic engine started initializing a diagnostic package located at PackagePath.
#Description
The scripted diagnostic engine started initializing a diagnostic package located at PackagePath.
Message #
Fields #
| Name | Description | Rules |
|---|---|---|
PackagePath UnicodeString | 1 detection rule |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"guid": "{E1DD7E52-621D-44E3-A1AD-0370C2B25946}",
"event_source_name": "",
"event_id": 101,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686052787126272,
"time_created": "2026-06-13T05:39:32.0639362+00:00",
"event_record_id": 13,
"correlation": {},
"execution": {
"process_id": 5480,
"thread_id": 5084
},
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance"
},
"message": "The scripted diagnostic engine started initializing a diagnostic package located at C:\\Windows\\diagnostics\\scheduled\\Maintenance."
}
Detection Rules #
View all rules referencing this event →Sigma # view in coverage
Event ID 102: The scripted diagnostic engine completed initializing a diagnostic package located at PackagePath.
#Description
The scripted diagnostic engine completed initializing a diagnostic package located at PackagePath.
Message #
Fields #
| Name | Description |
|---|---|
PackagePath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"guid": "{E1DD7E52-621D-44E3-A1AD-0370C2B25946}",
"event_source_name": "",
"event_id": 102,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686052787126272,
"time_created": "2026-06-13T05:39:32.6573381+00:00",
"event_record_id": 14,
"correlation": {},
"execution": {
"process_id": 5480,
"thread_id": 5084
},
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"PackagePath": "C:\\Windows\\diagnostics\\scheduled\\Maintenance"
},
"message": "The scripted diagnostic engine completed initializing a diagnostic package located at C:\\Windows\\diagnostics\\scheduled\\Maintenance."
}
Event ID 103: The scripted diagnostic engine started diagnosing the diagnostic package PackageId.
#Description
The scripted diagnostic engine started diagnosing the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"guid": "{E1DD7E52-621D-44E3-A1AD-0370C2B25946}",
"event_source_name": "",
"event_id": 103,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686052787126272,
"time_created": "2026-06-13T05:39:32.6595348+00:00",
"event_record_id": 15,
"correlation": {},
"execution": {
"process_id": 5480,
"thread_id": 5084
},
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"PackageId": "MaintenanceDiagnostic"
},
"message": "The scripted diagnostic engine started diagnosing the diagnostic package MaintenanceDiagnostic."
}
Event ID 104: The scripted diagnostic engine completed diagnosing the diagnostic package PackageId.
#Description
The scripted diagnostic engine completed diagnosing the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"guid": "{E1DD7E52-621D-44E3-A1AD-0370C2B25946}",
"event_source_name": "",
"event_id": 104,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686052787126272,
"time_created": "2026-06-13T05:39:36.5124770+00:00",
"event_record_id": 16,
"correlation": {},
"execution": {
"process_id": 5480,
"thread_id": 5084
},
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"PackageId": "MaintenanceDiagnostic"
},
"message": "The scripted diagnostic engine completed diagnosing the diagnostic package MaintenanceDiagnostic."
}
Event ID 105: The scripted diagnostic engine started running the resolution ResolutionId in the diagnostic package PackageId.
#Description
The scripted diagnostic engine started running the resolution ResolutionId in the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString | |
ResolutionId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 105,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:41.8700085+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"ResolutionId": "RC_DiagnosticHistory/DefaultInstanceId/RS_AdminDiagnosticHistory",
"PackageId": "MaintenanceDiagnostic"
}
}
Event ID 106: The scripted diagnostic engine completed running the resolution ResolutionId in the diagnostic package PackageId.
#Description
The scripted diagnostic engine completed running the resolution ResolutionId in the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString | |
ResolutionId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 106,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:42.0121583+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"ResolutionId": "RC_DiagnosticHistory/DefaultInstanceId/RS_AdminDiagnosticHistory",
"PackageId": "MaintenanceDiagnostic"
}
}
Event ID 107: The scripted diagnostic engine started verifying the diagnostic package PackageId.
#Description
The scripted diagnostic engine started verifying the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 107,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:42.0123013+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"PackageId": "MaintenanceDiagnostic"
}
}
Event ID 108: The scripted diagnostic engine completed verifying the diagnostic package PackageId.
#Description
The scripted diagnostic engine completed verifying the diagnostic package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 108,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:42.0905970+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"PackageId": "MaintenanceDiagnostic"
}
}
Event ID 201: The scripted diagnostic engine has encountered an error Status.
#Description
The scripted diagnostic engine has encountered an error Status.
Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 301: The scripted diagnostic engine has encountered an error in function FunctionName, line LineNumber: ErrorCode.
#Event ID 401: Rootcause RootCauseId was detected in package PackageId.
#Description
Rootcause RootCauseId was detected in package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString | |
RootCauseId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 401,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:41.5895729+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"PackageId": "MaintenanceDiagnostic",
"RootCauseId": "RC_DiagnosticHistory/DefaultInstanceId"
}
}
Event ID 402: Rootcause RootCauseId was resolved in package PackageId.
#Description
Rootcause RootCauseId was resolved in package PackageId.
Message #
Fields #
| Name | Description |
|---|---|
PackageId UnicodeString | |
RootCauseId UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Diagnosis-Scripted",
"event_id": 402,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-04-20T21:20:42.0908422+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Diagnosis-Scripted/Operational"
},
"event_data": {
"PackageId": "MaintenanceDiagnostic",
"RootCauseId": "RC_DiagnosticHistory/DefaultInstanceId"
}
}
Event ID 1000: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1002: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Event ID 1004: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1006: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Event ID 1008: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1010: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Event ID 1012: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1014: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Event ID 1016: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1018: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Event ID 1020: The scripted diagnostic engine has entered a performance tracing section.
#Description
The scripted diagnostic engine has entered a performance tracing section.
Message #
Event ID 1022: The scripted diagnostic engine has exited a performance tracing section.
#Description
The scripted diagnostic engine has exited a performance tracing section..
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID e1dd7e52-621d-44e3-a1ad-0370c2b25946
Defined in sdiageng.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02