Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider

EventTitleChannelSampleRule
1000The Windows Scripted Diagnostic Provider API IDiagnosticProvider …OperationalYN
1001The Windows Scripted Diagnostic Provider API IDiagnosticProvider …OperationalNN
1002The Windows Scripted Diagnostic Provider API IDiagnosticProvider …OperationalNN
1003The Windows Scripted Diagnostic Provider API IDiagnosticProvider …OperationalNN
1004The Windows Scripted Diagnostic Provider API IDiagnosticProvider …OperationalNN
1010The Windows Scripted Diagnostic Provider API IDiagnosticProvider Cancel method …OperationalNN
1011The Windows Scripted Diagnostic Provider API IDiagnosticProvider Cancel method …OperationalNN
1012The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to …OperationalNN
1013The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to …OperationalNN
1015The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property …OperationalNN
1016The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property …OperationalNN
1017The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property …DebugNN
1018The Windows Scripted Diagnostic Provider API IDiagnosticProvider …DebugNN
2000The diagnostic package index information was successfully loaded from IndexPath.OperationalYN
2001Failed to scan diagnostic package index information from IndexPath, with error …OperationalNN
2002Failed to load the resource (Resource;ResourceId) with error code (Error).OperationalNN
3000Sending request to the remote server Hostname at the URL path Url.OperationalNN
3001Failed to connect to the remote server Hostname at the URL path Url due to lack …OperationalNN
3002Failed to connect to the remote server Hostname at the URL path Url with error …OperationalNN
3003Timed out while communicating with the remote server Hostname at the URL path …OperationalNN
3004Timed out waiting for a response from the remote server Hostname at the URL path …OperationalNN
3005Response from the remote server Hostname at the URL path Url returned the …OperationalNN
3006Received response from the remote server Hostname at the URL path Url.OperationalNN
3007Parsed valid response from the remote server Hostname at the URL path Url.OperationalNN
3008Response received from the remote server Hostname at the URL path Url is invalid …OperationalNN
3009Response received from the remote server Hostname at the URL path Url is …OperationalNN
3010Attempting to send data to remote server using the following proxy …DebugNN
3011Failed to send data to remote server using the following proxy configuration: …DebugNN
3012Failed to send data to remote server because list of proxy servers was exhausted …OperationalNN
3013Connection to remote server has been reset or terminated while waiting for a …OperationalNN
3014The following system configuration will be used when querying content providers: …OperationalNN
4000Starting to scan diagnostic package index information from IndexPath.DebugNN
4001Finished scanning diagnostic package index information from IndexPath.DebugNN
4006Starting to query content providers for scripted diagnostic content packages.DebugNN
4007Finished querying content providers for scripted diagnostic content packages …DebugNN
4008Starting to cancel content providers.DebugNN
4009Finished cancelling content providers with error code (Error).DebugNN
4010Starting to cancel local content provider.DebugNN
4011Finished cancelling local content provider with error code (Error).DebugNN
4012Starting to cancel remote content provider.DebugNN
4013Finished cancelling remove content provider with error code (Error).DebugNN
4014Starting to gather system configuration necessary for scripted diagnostic …DebugNN
4015Finished gathering system configuration necessary for scripted diagnostic …DebugNN
4016Started to connect to remote server Hostname using URL path Url.DebugNN
4017Finished connecting to remote server Hostname using URL path Url.DebugNN
4018Sending POST request to the remote server Hostname using the URL path: Url with …DebugNN
4019Response received from remote server.DebugNN
4020Starting to parse response from the remote server Hostname POST request to the …DebugNN
4021Finished parsing response from the remote server Hostname POST request to the …DebugNN
4022Starting to acquire lock in function Method.DebugNN
4023Finished acquiring lock in function Method.DebugNN
4024Starting to add result to Diagnostic Collection.DebugNN
4025Finished adding result to Diagnostic Collection with error code (Error).DebugNN
4026Starting to load resource from Resource.DebugNN
4027Finished loading resource from Resource.DebugNN
5000Method succeeded.DebugNN
5001Method succeeded.DebugNN
5002Method succeeded.DebugNN
5004Method succeeded.DebugNN
5005Method succeeded.DebugNN
5006Method succeeded.DebugNN
5008Method succeeded.DebugNN
5009Method succeeded.DebugNN
5010Method failed because the system ran out of memory.DebugNN
5011Method failed with error (Error) because the input parameter, Parameter, was …DebugNN
5012Method failed with error (Error).DebugNN
5013Method succeeded.DebugNN
5014Method failed with error (Error) because the index, Index, is out of bounds of …DebugNN
5015Method succeeded.DebugNN
5016Method failed with error (Error) because the collection already contains an …DebugNN
5017Method succeeded.DebugNN
5018Method failed with error (Error) because the collection already contains an …OperationalNN
5019Local Content Diagnostic Provider search parameter: Parameter has value: Value.DebugNN
5020Search Result includes a diagnostic with the following identifier Id.DebugNN
5021Deserializing diagnostic from index file IndexPath failed with error code …OperationalNN
5022task_05022DebugNN
5023task_05023DebugNN
5024task_05024DebugNN
5025task_05025DebugNN
5026Deserializing diagnostic failed index file IndexPath with error code (Error) …OperationalNN

Event ID 1000: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method succeeded.

#
Channel
Operational

Description

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method succeeded. The input Culture/Locale was UILanguage. The size of the result set was ResultSize.

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method succeeded.  The input Culture/Locale was %1.  The size of the result set was %2.

Fields #

NameDescription
UILanguage UnicodeString
ResultSize UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider",
    "event_id": 1000,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-03-17T18:45:49.4045989+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational"
  },
  "event_data": {
    "UILanguage": "en-US",
    "ResultSize": "1"
  }
}

Event ID 1001: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed because the system ran out of memory.

#
Channel
Operational

Event ID 1002: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method was canceled by the caller.

#
Channel
Operational

Event ID 1003: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed with error (Error).

#
Channel
Operational

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed with error (%1).

Fields #

NameDescription
Error UInt32

Event ID 1004: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed.

#
Channel
Operational

Description

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed. The input Culture/Locale, UILanguage, is not a valid Language identifier.

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed.  The input Culture/Locale, %1, is not a valid Language identifier.

Fields #

NameDescription
UILanguage UnicodeString

Event ID 1010: The Windows Scripted Diagnostic Provider API IDiagnosticProvider Cancel method succeeded.

#
Channel
Operational

Event ID 1011: The Windows Scripted Diagnostic Provider API IDiagnosticProvider Cancel method failed with error (Error).

#
Channel
Operational

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider Cancel method failed with error (%1).

Fields #

NameDescription
Error UInt32

Event ID 1012: The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to cancel the connected diagnostic provider with error (Error).

#
Channel
Operational

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to cancel the connected diagnostic provider with error (%1).

Fields #

NameDescription
Error UInt32

Event ID 1013: The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to cancel the local diagnostic provider with error (Error).

#
Channel
Operational

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider failed to cancel the local diagnostic provider with error (%1).

Fields #

NameDescription
Error UInt32

Event ID 1015: The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by Group Policy.

#
Channel
Operational

Description

The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by Group Policy. The property will be interpreted as being set to VARIANT_FALSE.

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by Group Policy.  The property will be interpreted as being set to VARIANT_FALSE.

Event ID 1016: The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by the Administrator through...

#
Channel
Operational

Description

The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by the Administrator through a System Wide Preference. The property will be interpreted as being set to VARIANT_FALSE.

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is being overridden by the Administrator through a System Wide Preference.  The property will be interpreted as being set to VARIANT_FALSE.

Event ID 1017: The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is set to QueryRemoteServer.

#
Channel
Debug

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider object property QueryRemoteServer is set to %1.

Fields #

NameDescription
QueryRemoteServer Boolean

Event ID 1018: The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed because the input IDiagnosticMetadat...

#
Channel
Debug

Description

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed because the input IDiagnosticMetadataCollection object was empty.

Message #

The Windows Scripted Diagnostic Provider API IDiagnosticProvider FindDiagnosticsBySearchMetadata method failed because the input IDiagnosticMetadataCollection object was empty.

Event ID 2000: The diagnostic package index information was successfully loaded from IndexPath.

#
Channel
Operational

Message #

The diagnostic package index information was successfully loaded from %1.

Fields #

NameDescription
IndexPath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider",
    "event_id": 2000,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-03-17T18:45:49.4042596+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-Diagnosis-ScriptedDiagnosticsProvider/Operational"
  },
  "event_data": {
    "IndexPath": "C:\\Windows\\Diagnostics\\Index\\WindowsUpdateDiagnostic.xml"
  }
}

Event ID 2001: Failed to scan diagnostic package index information from IndexPath, with error (Error).

#
Channel
Operational

Message #

Failed to scan diagnostic package index information from %2, with error (%1).

Fields #

NameDescription
Error UInt32
IndexPath UnicodeString

Event ID 2002: Failed to load the resource (Resource;ResourceId) with error code (Error).

#
Channel
Operational

Message #

Failed to load the resource (%2;%3) with error code (%1).

Fields #

NameDescription
Error UInt32
Resource UnicodeString
ResourceId Int32

Event ID 3000: Sending request to the remote server Hostname at the URL path Url.

#
Channel
Operational

Description

Sending request to the remote server Hostname at the URL path Url. Contents of the request are: RequestBody.

Message #

Sending request to the remote server %1 at the URL path %2.  Contents of the request are: %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
RequestBody AnsiString

Event ID 3001: Failed to connect to the remote server Hostname at the URL path Url due to lack of network access.

#
Channel
Operational

Message #

Failed to connect to the remote server %1 at the URL path %2 due to lack of network access.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

References #

Event ID 3002: Failed to connect to the remote server Hostname at the URL path Url with error Error.

#
Channel
Operational

Message #

Failed to connect to the remote server %1 at the URL path %2 with error %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
Error UInt32

References #

Event ID 3003: Timed out while communicating with the remote server Hostname at the URL path Url.

#
Channel
Operational

Message #

Timed out while communicating with the remote server %1 at the URL path %2.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

Event ID 3004: Timed out waiting for a response from the remote server Hostname at the URL path Url.

#
Channel
Operational

Message #

Timed out waiting for a response from the remote server %1 at the URL path %2.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

References #

Event ID 3005: Response from the remote server Hostname at the URL path Url returned the following error response code: ResponseCode.

#
Channel
Operational

Message #

Response from the remote server %1 at the URL path %2 returned the following error response code: %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
ResponseCode UInt32

Event ID 3006: Received response from the remote server Hostname at the URL path Url.

#
Channel
Operational

Message #

Received response from the remote server %1 at the URL path %2.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

Event ID 3007: Parsed valid response from the remote server Hostname at the URL path Url.

#
Channel
Operational

Message #

Parsed valid response from the remote server %1 at the URL path %2.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

References #

Event ID 3008: Response received from the remote server Hostname at the URL path Url is invalid for the following reason: Reason.

#
Channel
Operational

Message #

Response received from the remote server %1 at the URL path %2 is invalid for the following reason: %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
Reason UnicodeString

Event ID 3009: Response received from the remote server Hostname at the URL path Url is malformed.

#
Channel
Operational

Message #

Response received from the remote server %1 at the URL path %2 is malformed.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

Event ID 3010: Attempting to send data to remote server using the following proxy configuration: Access Type (AccessType); Proxy Server (Proxy); Proxy Bypass Server (ProxyBypass).

#
Channel
Debug

Message #

Attempting to send data to remote server using the following proxy configuration: Access Type (%1); Proxy Server (%2); Proxy Bypass Server (%3).

Fields #

NameDescription
AccessType Int32
Proxy UnicodeString
ProxyBypass UnicodeString

References #

Event ID 3011: Failed to send data to remote server using the following proxy configuration: Access Type (AccessType); Proxy Server (Proxy); Proxy Bypass Server (ProxyBypass) because...

#
Channel
Debug

Description

Failed to send data to remote server using the following proxy configuration: Access Type (AccessType); Proxy Server (Proxy); Proxy Bypass Server (ProxyBypass) because of proxy failure (Error).

Message #

Failed to send data to remote server using the following proxy configuration: Access Type (%2); Proxy Server (%3); Proxy Bypass Server (%4) because of proxy failure (%1).

Fields #

NameDescription
Error UInt32
AccessType Int32
Proxy UnicodeString
ProxyBypass UnicodeString

References #

Event ID 3012: Failed to send data to remote server because list of proxy servers was exhausted without receiving a response.

#
Channel
Operational

Description

Failed to send data to remote server because list of proxy servers was exhausted without receiving a response. The error code returned to caller is Error.

Message #

Failed to send data to remote server because list of proxy servers was exhausted without receiving a response. The error code returned to caller is %1.

Fields #

NameDescription
Error UInt32

References #

Event ID 3013: Connection to remote server has been reset or terminated while waiting for a response.

#
Channel
Operational

Description

Connection to remote server has been reset or terminated while waiting for a response. The error code returned to the caller is Error.

Message #

Connection to remote server has been reset or terminated while waiting for a response.  The error code returned to the caller is %1.

Fields #

NameDescription
Error UInt32

Event ID 3014: The following system configuration will be used when querying content providers: OS Major Version (OSMajorVersion); OS Minor Version (OSMinorVersion); Service Pack Major.

#
Channel
Operational

Description

The following system configuration will be used when querying content providers: OS Major Version (OSMajorVersion); OS Minor Version (OSMinorVersion); Service Pack Major (ServicePackMajor); Service Pack Minor (ServicePackMinor); Build Number (BuildNumber); Product Type (ProductType); Processor Architecture (ProcessorArchitecture); Culture (Culture); System Type (SystemType); OEM (OEM); Model (Model); IsMobilePc (IsMobilePc); IsInternal (IsInternal); GeoId (GeoId); Family (Family); OEM SKU (OEMSKU); Version (Version); Base Board OEM (BaseBoardOEM); Base Board Model (BaseBoardModel); Base Board Version (BaseBoardVersion); BIOS Vendor (BIOSVendor); BIOS Version (BIOSVersion); BIOS Release Date (BIOSReleaseDate); BIOS Major Release (BIOSMajorRelease); BIOS Minor Release (BIOSMinorRelease); Embedded Controller Firmware Major Release (ECFirmwareMajorRelease); Embedded Controller Firmware Minor Release (ECFirmwareMinorRelease).

Message #

The following system configuration will be used when querying content providers: OS Major Version (%1); OS Minor Version (%2); Service Pack Major (%3); Service Pack Minor (%4); Build Number (%5); Product Type (%6); Processor Architecture (%7); Culture (%8); System Type (%9); OEM (%10); Model (%11); IsMobilePc (%12); IsInternal (%13); GeoId (%14); Family (%15); OEM SKU (%16); Version (%17); Base Board OEM (%18); Base Board Model (%19); Base Board Version (%20); BIOS Vendor (%21); BIOS Version (%22); BIOS Release Date (%23); BIOS Major Release (%24); BIOS Minor Release (%25); Embedded Controller Firmware Major Release (%26); Embedded Controller Firmware Minor Release (%27).

Fields #

NameDescription
OSMajorVersion Int32
OSMinorVersion Int32
ServicePackMajor Int16
ServicePackMinor Int16
BuildNumber Int32
ProductType Int32
ProcessorArchitecture Int16
Culture UnicodeString
SystemType Int8
OEM UnicodeString
Model UnicodeString
IsMobilePc Boolean
IsInternal Boolean
GeoId Int32
Family UnicodeString
OEMSKU UnicodeString
Version UnicodeString
BaseBoardOEM UnicodeString
BaseBoardModel UnicodeString
BaseBoardVersion UnicodeString
BIOSVendor UnicodeString
BIOSVersion UnicodeString
BIOSReleaseDate UnicodeString
BIOSMajorRelease UInt8
BIOSMinorRelease UInt8
ECFirmwareMajorRelease UInt8
ECFirmwareMinorRelease UInt8

Event ID 4000: Starting to scan diagnostic package index information from IndexPath.

#
Channel
Debug
Opcode
Start

Message #

Starting to scan diagnostic package index information from %1.

Fields #

NameDescription
IndexPath UnicodeString

Event ID 4001: Finished scanning diagnostic package index information from IndexPath.

#
Channel
Debug
Opcode
Stop

Message #

Finished scanning diagnostic package index information from %1.

Fields #

NameDescription
IndexPath UnicodeString

Event ID 4006: Starting to query content providers for scripted diagnostic content packages.

#
Channel
Debug
Opcode
Start

Event ID 4007: Finished querying content providers for scripted diagnostic content packages with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished querying content providers for scripted diagnostic content packages with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4008: Starting to cancel content providers.

#
Channel
Debug
Opcode
Start

Event ID 4009: Finished cancelling content providers with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished cancelling content providers with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4010: Starting to cancel local content provider.

#
Channel
Debug
Opcode
Start

Event ID 4011: Finished cancelling local content provider with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished cancelling local content provider with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4012: Starting to cancel remote content provider.

#
Channel
Debug
Opcode
Start

Event ID 4013: Finished cancelling remove content provider with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished cancelling remove content provider with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4014: Starting to gather system configuration necessary for scripted diagnostic content package query.

#
Channel
Debug
Opcode
Start

Event ID 4015: Finished gathering system configuration necessary for scripted diagnostic content package query with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished gathering system configuration necessary for scripted diagnostic content package query with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4016: Started to connect to remote server Hostname using URL path Url.

#
Channel
Debug
Opcode
Start

Message #

Started to connect to remote server %1 using URL path %2.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString

Event ID 4017: Finished connecting to remote server Hostname using URL path Url.

#
Channel
Debug
Opcode
Stop

Description

Finished connecting to remote server Hostname using URL path Url. The operation completed with error Error.

Message #

Finished connecting to remote server %1 using URL path %2.  The operation completed with error %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
Error UInt32

Event ID 4018: Sending POST request to the remote server Hostname using the URL path: Url with request body: RequestBody.

#
Channel
Debug
Opcode
Start

Message #

Sending POST request to the remote server %1 using the URL path: %2 with request body: %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
RequestBody AnsiString

Event ID 4019: Response received from remote server.

#
Channel
Debug
Opcode
Stop

Description

Response received from remote server. The HTTP response was HttpError. The operation completed with error Error.

Message #

Response received from remote server.  The HTTP response was %1.  The operation completed with error %2.

Fields #

NameDescription
HttpError UInt32
Error UInt32

Event ID 4020: Starting to parse response from the remote server Hostname POST request to the URL path: Url with request body: RequestBody.

#
Channel
Debug
Opcode
Start

Message #

Starting to parse response from the remote server %1 POST request to the URL path: %2 with request body: %3.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
RequestBody AnsiString

Event ID 4021: Finished parsing response from the remote server Hostname POST request to the URL path: Url with request body: RequestBody with error Error.

#
Channel
Debug
Opcode
Stop

Message #

Finished parsing response from the remote server %1 POST request to the URL path: %2 with request body: %3 with error %4.

Fields #

NameDescription
Hostname UnicodeString
Url UnicodeString
RequestBody AnsiString
Error UInt32

Event ID 4022: Starting to acquire lock in function Method.

#
Channel
Debug
Opcode
Start

Message #

Starting to acquire lock in function %1.

Fields #

NameDescription
Method AnsiString

Event ID 4023: Finished acquiring lock in function Method.

#
Channel
Debug
Opcode
Stop

Message #

Finished acquiring lock in function %1.

Fields #

NameDescription
Method AnsiString

Event ID 4024: Starting to add result to Diagnostic Collection.

#
Channel
Debug
Opcode
Start

Event ID 4025: Finished adding result to Diagnostic Collection with error code (Error).

#
Channel
Debug
Opcode
Stop

Message #

Finished adding result to Diagnostic Collection with error code (%1).

Fields #

NameDescription
Error UInt32

Event ID 4026: Starting to load resource from Resource.

#
Channel
Debug
Opcode
Start

Message #

Starting to load resource from %1.

Fields #

NameDescription
Resource UnicodeString

Event ID 4027: Finished loading resource from Resource.

#
Channel
Debug
Opcode
Stop

Message #

Finished loading resource from %1.

Fields #

NameDescription
Resource UnicodeString

Event ID 5000: Method succeeded.

#
Channel
Debug

Message #

%1 succeeded.

Fields #

NameDescription
Method AnsiString

Event ID 5001: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The corresponding object property was set to Value.

Message #

%1 succeeded.  The corresponding object property was set to %2.

Fields #

NameDescription
Method AnsiString
Value UnicodeString

Event ID 5002: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The corresponding object property was set to Value.

Message #

%1 succeeded.  The corresponding object property was set to %2.

Fields #

NameDescription
Method AnsiString
Value Boolean

Event ID 5004: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The corresponding object property was set to Value.

Message #

%1 succeeded.  The corresponding object property was set to %2.

Fields #

NameDescription
Method AnsiString
Value Int32

Event ID 5005: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The output parameter was set to Value.

Message #

%1 succeeded.  The output parameter was set to %2.

Fields #

NameDescription
Method AnsiString
Value UnicodeString

Event ID 5006: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The output parameter was set to Value.

Message #

%1 succeeded.  The output parameter was set to %2.

Fields #

NameDescription
Method AnsiString
Value Boolean

Event ID 5008: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The output parameter was set to Value.

Message #

%1 succeeded.  The output parameter was set to %2.

Fields #

NameDescription
Method AnsiString
Value Int32

Event ID 5009: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The output parameter was set to Value.

Message #

%1 succeeded.  The output parameter was set to %2.

Fields #

NameDescription
Method AnsiString
Value UInt64

Event ID 5010: Method failed because the system ran out of memory.

#
Channel
Debug

Message #

%1 failed because the system ran out of memory.

Fields #

NameDescription
Method AnsiString

Event ID 5011: Method failed with error (Error) because the input parameter, Parameter, was NULL.

#
Channel
Debug

Message #

%1 failed with error (%2) because the input parameter, %3, was NULL.

Fields #

NameDescription
Method AnsiString
Error UInt32
Parameter AnsiString

Event ID 5012: Method failed with error (Error).

#
Channel
Debug

Message #

%1 failed with error (%2).

Fields #

NameDescription
Method AnsiString
Error UInt32

Event ID 5013: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The output parameter was set to the item in the collection at index Value.

Message #

%1 succeeded.  The output parameter was set to the item in the collection at index %2.

Fields #

NameDescription
Method AnsiString
Value UInt64

Event ID 5014: Method failed with error (Error) because the index, Index, is out of bounds of the enumeration or the enumeration is empty.

#
Channel
Debug

Message #

%1 failed with error (%2) because the index, %3, is out of bounds of the enumeration or the enumeration is empty.

Fields #

NameDescription
Method AnsiString
Error UInt32
Index UInt64

Event ID 5015: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The object was added to the collection at index Index. The new size of the collection is Count.

Message #

%1 succeeded.  The object was added to the collection at index %2.  The new size of the collection is %3.

Fields #

NameDescription
Method AnsiString
Index UInt64
Count UInt64

Event ID 5016: Method failed with error (Error) because the collection already contains an object of type, Type, with value, Value.

#
Channel
Debug

Message #

%1 failed with error (%2) because the collection already contains an object of type, %3, with value, %4.

Fields #

NameDescription
Method AnsiString
Error UInt32
Type Int32
Value UnicodeString

Event ID 5017: Method succeeded.

#
Channel
Debug

Description

Method succeeded. The size of the collection increased by ItemsAdded object(s). The new size of the collection is Count.

Message #

%1 succeeded.  The size of the collection increased by %2 object(s).  The new size of the collection is %3.

Fields #

NameDescription
Method AnsiString
ItemsAdded UInt64
Count UInt64

Event ID 5018: Method failed with error (Error) because the collection already contains an object of with identifier, Id, and publisher, Publisher, with a greater version (Version).

#
Channel
Operational

Message #

%1 failed with error (%2) because the collection already contains an object of with identifier, %3, and publisher, %4, with a greater version (%5).

Fields #

NameDescription
Method AnsiString
Error UInt32
Id UnicodeString
Publisher UnicodeString
Version UnicodeString

Event ID 5019: Local Content Diagnostic Provider search parameter: Parameter has value: Value.

#
Channel
Debug

Message #

Local Content Diagnostic Provider search parameter: %1 has value: %2.

Fields #

NameDescription
Parameter UInt32
Value UnicodeString

Event ID 5020: Search Result includes a diagnostic with the following identifier Id.

#
Channel
Debug

Description

Search Result includes a diagnostic with the following identifier Id. The publisher of the Diagnostic is Publisher. The version of the Diagnostic is Version. The URL for the diagnostic is: Url.

Message #

Search Result includes a diagnostic with the following identifier %1.  The publisher of the Diagnostic is %2. The version of the Diagnostic is %3.  The URL for the diagnostic is: %4.

Fields #

NameDescription
Id UnicodeString
Publisher UnicodeString
Version UnicodeString
Url UnicodeString

Event ID 5021: Deserializing diagnostic from index file IndexPath failed with error code (Error) because the XML does not represent a valid Diagnostic.

#
Channel
Operational

Message #

Deserializing diagnostic from index file %2 failed with error code (%1) because the XML does not represent a valid Diagnostic.

Fields #

NameDescription
Error UInt32
IndexPath UnicodeString

Event ID 5022: task_05022

#
Channel
Debug

Fields #

NameDescription
Name AnsiString
Address Pointer

Event ID 5023: task_05023

#
Channel
Debug

Fields #

NameDescription
Name AnsiString
Address Pointer

Event ID 5024: task_05024

#
Channel
Debug

Fields #

NameDescription
Name AnsiString
Address Pointer
RefCount UInt32

Event ID 5025: task_05025

#
Channel
Debug

Fields #

NameDescription
Name AnsiString
Address Pointer
RefCount UInt32

Event ID 5026: Deserializing diagnostic failed index file IndexPath with error code (Error) because the XML does not contain valid XML.

#
Channel
Operational

Message #

Deserializing diagnostic failed index file %2 with error code (%1) because the XML does not contain valid XML.

Fields #

NameDescription
Error UInt32
IndexPath UnicodeString

Provenance

ETW provider GUID 9363ccd9-d429-4452-9adb-2501e704b810

Defined in sdiagprv.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB