Microsoft-Windows-DistributedCOM
69 events across 2 channels
Event ID 10000: Unable to start a DCOM Server: param3.
#Event ID 10001: Unable to start a DCOM Server: param3 as param4/param5.
#Description
Unable to start a DCOM Server: param3 as param4/param5. The error.
Message #
Fields #
| Name | Description | Rules |
|---|---|---|
param1 UnicodeString | 1 detection rule | |
param2 UnicodeString | 1 detection rule | |
param3 UnicodeString | 1 detection rule | |
param4 UnicodeString | ||
param5 UnicodeString |
Detection Rules #
View all rules referencing this event →Sigma # view in coverage
Event ID 10002: Access denied attempting to launch a DCOM Server
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 10003: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 10004: DCOM got error "param1" and was unable to logon param2\param3 in order to run the server: param4.
#Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server: param4.
#Event ID 10005: DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server:
#Description
DCOM got error "param1" attempting to start the service param2 with arguments "param3" in order to run the server.
Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "",
"event_id": 10005,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-06-13T05:14:37.1593618+00:00",
"event_record_id": 2166,
"correlation": {
"ActivityID": "{D57A5142-FAF2-0002-275B-7AD5F2FADC01}"
},
"execution": {
"process_id": 660,
"thread_id": 772
},
"channel": "System",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"param1": "1053",
"param2": "GoogleUpdaterService150.0.7863.0",
"param3": "--com-service",
"param4": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
},
"message": "DCOM got error \"1053\" attempting to start the service GoogleUpdaterService150.0.7863.0 with arguments \"--com-service\" in order to run the server:\r\n{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
}
Event ID 10006: DCOM got error "param1" from the computer param2 when attempting to activate the server: param3.
#Description
DCOM got error "param1" from the computer param2 when attempting to activate the server.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "",
"event_id": 10006,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-04-16T22:13:33.9914282+00:00",
"event_record_id": 5408,
"correlation": {
"ActivityID": "{AEA85543-92F4-4400-9B1C-03900CE328AA}"
},
"execution": {
"process_id": 1360,
"thread_id": 20244
},
"channel": "System",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "2148007941",
"param2": "DESKTOP-A8D4L1Z",
"param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
},
"message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to activate the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D}"
}
Event ID 10007: DCOM got error "param1" when attempting to activate the server:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 10008: DCOM got error "param1" from the computer param2 when attempting to the server.
#Description
DCOM got error "param1" from the computer param2 when attempting to the server.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "",
"event_id": 10008,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-04-16T22:36:00.7542779+00:00",
"event_record_id": 5417,
"correlation": {
"ActivityID": "{921232B8-4EE8-402A-A3DA-B0729FF4991D}"
},
"execution": {
"process_id": 1360,
"thread_id": 7504
},
"channel": "System",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "2148007941",
"param2": "DESKTOP-A8D4L1Z",
"param3": "{38FE8DFE-B129-452B-A215-119382B89E3D}",
"param4": "hello.stg"
},
"message": "DCOM got error \"2148007941\" from the computer DESKTOP-A8D4L1Z when attempting to the server:\r\n{38FE8DFE-B129-452B-A215-119382B89E3D} with file hello.stg."
}
Event ID 10009: DCOM was unable to communicate with the computer param1 using any of the configured protocols
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
__binLength UInt32 | |
binary Binary |
Event ID 10010: The server param1 did not register with DCOM within the required timeout.
#Description
The server param1 did not register with DCOM within the required timeout.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"event_id": 10010,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-04-16T20:35:38.5502237+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
}
}
Event ID 10010: The server param1 did not register with DCOM within the required timeout
#Description
The server did not register with DCOM within the required timeout.
Message #
Fields #
| Name | Description |
|---|---|
param1 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "",
"event_id": 10010,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-06-13T05:12:05.5699142+00:00",
"event_record_id": 2143,
"correlation": {
"ActivityID": "{D57A5142-FAF2-0001-8355-7AD5F2FADC01}"
},
"execution": {
"process_id": 1048,
"thread_id": 1084
},
"channel": "System",
"computer": "telemetry-W11-d.cell-d.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"param1": "{8018F647-BF07-55BB-82BE-A2D7049F7CE4}"
},
"message": "The server {8018F647-BF07-55BB-82BE-A2D7049F7CE4} did not register with DCOM within the required timeout."
}
Event ID 10011: The server param1 could not be contacted to establish the connection to the client
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 10012: There is an assertion failure in DCOM
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 10014: The activation for CLSID param1 failed because remote activations for COM+ are disabled.
#Event ID 10015: The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.
#Description
The machine wide limit settings do not grant param1 param2 permission for the COM Server application with CLSID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString | |
param10 UnicodeString |
Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.
#Description
The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString | |
param10 UnicodeString | |
param11 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"event_id": 10016,
"level": "Warning",
"task": null,
"opcode": "Info",
"time_created": "2026-05-24T02:14:10.9499544+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
"param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
"param3": "Activation",
"param6": "ludus",
"param1": "application-specific",
"param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
"param7": "localuser",
"param11": "Unavailable",
"param9": "LocalHost (Using LRPC)",
"param10": "Unavailable",
"param2": "Local"
}
}
Event ID 10016: The param1 permission settings do not grant param2 param3 permission for the COM Server application with CLSID
#Description
The permission settings do not grant permission for the COM Server application with CLSID.
Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "",
"event_id": 10016,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": -9187343239835811840,
"time_created": "2026-05-29T16:33:58.8709146+00:00",
"event_record_id": 6816,
"correlation": {
"ActivityID": "{BE1132E7-6849-4B6C-8578-E3BE57A71713}"
},
"execution": {
"process_id": 848,
"thread_id": 1484
},
"channel": "System",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "application-specific",
"param2": "Local",
"param3": "Launch",
"param4": "{21B896BF-008D-4D01-A27B-26061B960DD7}",
"param5": "{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}",
"param6": "cell-a",
"param7": "domainadmin",
"param8": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"param9": "LocalHost (Using LRPC)",
"param10": "Unavailable",
"param11": "Unavailable"
},
"message": "The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID \r\n{21B896BF-008D-4D01-A27B-26061B960DD7}\r\n and APPID \r\n{03E09F3B-DCE4-44FE-A9CF-82D050827E1C}\r\n to the user cell-a\\domainadmin SID (S-1-5-21-1006758700-2167138679-1475694448-1105) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool."
}
Event ID 10017: The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.
#Description
The param1 permission settings do not grant param2 access permission to the COM Server application param3 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString | |
param10 UnicodeString |
Event ID 10018: The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.
#Description
The application-specific permission settings do not grant param1 access permission to the COM Server application param2 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString |
Event ID 10019: The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.
#Description
The machine wide limit settings do not grant param1 access permission to the COM Server application param2 with APPID.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString |
Event ID 10020: The machine wide param1 param2 security descriptor is invalid.
#Description
The machine wide param1 param2 security descriptor is invalid. It contains Access Control Entries with permissions that are invalid. The requested action was therefore not performed. This security permission can be corrected using the Component Services administrative tool.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 10021: The launch and activation security descriptor for the COM Server application with APPID.
#Event ID 10022: The param1 access security descriptor for the COM Server application param2 with APPID.
#Event ID 10023: The application-specific access security descriptor for the COM Server application param1 with APPID.
#Event ID 10024: The machine wide group policy param1 Limits security descriptor is invalid.
#Description
The machine wide group policy param1 Limits security descriptor is invalid. The security descriptor is defined as an invalid Security Descriptor Definitions Language (SDDL) string. The requested action was therefore not performed. Please contact your administrator to get the security descriptor corrected in the Group Policy settings.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 10026: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 10027: The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the...
#Description
The machine wide limit settings do not grant param1 param2 permission for COM Server applications to the user param3\param4 SID (param5) from address param6 running in the application container param7 SID (param8). This security permission can be modified using the Component Services administrative tool.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString |
Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.
#Description
DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
__binLength UInt32 | |
binary Binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"event_id": 10028,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-03-15T05:14:36.9508994+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
"param2": " 28e0",
"param1": "JD-WIN11-22H2-1",
"param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe"
}
}
Event ID 10028: DCOM was unable to communicate with the computer param1 using any of the configured protocols; requested by PID param2 (param3), while activating CLSID
#Description
DCOM was unable to communicate with the computer using any of the configured protocols; requested by PID (), while activating CLSID .
Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
__binLength | |
binary |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"guid": "{1B562E86-B7AA-4131-BADC-B6F3A001407E}",
"event_source_name": "DCOM",
"event_id": 10028,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9259400833873739776,
"time_created": "2026-03-13T23:06:00.558843+00:00",
"event_record_id": 12279,
"correlation": {
"ActivityID": "2A8C090C-ABB5-42FC-ABDE-C1146B129851"
},
"execution": {
"process_id": 1212,
"thread_id": 6732
},
"channel": "System",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {
"param1": "DC1",
"param2": " 287c",
"param3": "C:\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
"param4": "{8BC3F05E-D86B-11D0-A075-00C04FB68820}",
"Binary": "3C5265636F726423313A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D323B4465746C6F633D313731303B466C6167733D303B506172616D733D313B7B506172616D23303A307D3E3C5265636F726423323A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D313434323B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E3C5265636F726423333A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D313732323B47656E636F6D703D31383B4465746C6F633D3332323B466C6167733D303B506172616D733D303B3E3C5265636F726423343A20436F6D70757465723D286E756C6C293B5069643D313231323B332F31332F323032362032333A363A303A3535383B5374617475733D31313030313B47656E636F6D703D31383B4465746C6F633D3332303B466C6167733D303B506172616D733D313B7B506172616D23303A4443317D3E"
},
"message": ""
}
Event ID 10029: The activation of the CLSID param1 timed out waiting for the service param2 to stop.
#Event ID 10030: Unable to start a COM Server for debugging: param3.
#Event ID 10031: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class param1 was rejected.
#Event ID 10032: An unmarshaling policy check was performed when unmarshaling a custom inproc handler and the class param1 was rejected.
#Event ID 10033: An unmarshaling policy check was performed when unmarshaling a COM+ envoy context property and the class param1 was rejected.
#Event ID 10034: An unmarshaling policy check was performed due to CLSCTX_NO_CUSTOM_MARSHAL and the class param1 was rejected.
#Event ID 10035: The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with hand...
#Description
The COM standard marshaler was unable to fix a mismatch between the IID ProvidedIid provided by the server and the IID RequestedIid requested by the client, with handler CLSID HandlerClsid. The error code was HRESULT.
Message #
Fields #
| Name | Description |
|---|---|
ProvidedIid UnicodeString | |
RequestedIid UnicodeString | |
HandlerClsid UnicodeString | |
HRESULT UnicodeString |
Event ID 10036: The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server.
#Description
The server-side authentication level policy does not allow the user DomainName\UserName SID (SID) from address ClientIPAddress to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.
Message #
Fields #
| Name | Description |
|---|---|
DomainName UnicodeString | |
UserName UnicodeString | |
SID UnicodeString | |
ClientIPAddress UnicodeString |
Event ID 10037: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel.
#Description
Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with explicitly set authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.
Message #
Fields #
| Name | Description |
|---|---|
ApplicationName UnicodeString | |
PID UnicodeString | |
CLSID UnicodeString | |
ComputerName UnicodeString | |
ActivationAuthenticationLevel UnicodeString |
Event ID 10038: Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel.
#Description
Application ApplicationName with PID PID is requesting to activate CLSID CLSID on computer ComputerName with default activation authentication level at ActivationAuthenticationLevel. The lowest activation authentication level required by DCOM is 5(RPC_C_AUTHN_LEVEL_PKT_INTEGRITY). To raise the activation authentication level, please contact the application vendor.
Message #
Fields #
| Name | Description |
|---|---|
ApplicationName UnicodeString | |
PID UnicodeString | |
CLSID UnicodeString | |
ComputerName UnicodeString | |
ActivationAuthenticationLevel UnicodeString |
Event ID 1073751850: The COM sub system is suppressing duplicate event log entries for a duration of param1 seconds.
#Description
The COM sub system is suppressing duplicate event log entries for a duration of seconds. The suppression timeout can be controlled by a REG_DWORD value named under the following registry key: HKLM\.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 3221235472: Unable to start a DCOM Server: {param3}.
#Event ID 3221235473: Unable to start a DCOM Server: {param3} as {param4}/{param5}.
#Event ID 3221235474: Access denied attempting to launch a DCOM Server.
#Event ID 3221235475: Access denied attempting to launch a DCOM Server using DefaultLaunchPermssion.
#Event ID 3221235476: DCOM got error '{param1}' and was unable to logon {param2}\{param3} in order to run the server:{param4}.
#Event ID 3221235477: DCOM got error '{param1}' attempting to start the service {param2} with arguments '{param3}' in order to run the server:{param4}.
#Event ID 3221235478: DCOM got error '{param1}' from the computer {param2} when attempting to activate the server:{param3}.
#Event ID 3221235479: DCOM got error "param1" when attempting to activate the server: param2.
#Event ID 3221235480: DCOM got error '{param1}' from the computer {param2} when attempting to the server:{param3} with file {param4}.
#Event ID 3221235481: DCOM was unable to communicate with the computer param1 using any of the configured protocols.
#Event ID 3221235482: The server {param1} did not register with DCOM within the required timeout.
#Description
The server {param1} did not register with DCOM within the required timeout.
Message #
Fields #
| Name | Description |
|---|---|
param1 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"event_id": 10010,
"level": "Error",
"task": null,
"opcode": "Info",
"time_created": "2026-04-16T20:35:38.5502237+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param1": "{38FE8DFE-B129-452B-A215-119382B89E3D}"
}
}
Event ID 3221235483: The server param1 could not be contacted to establish the connection to the client.
#Event ID 3221235484: There is an assertion failure in DCOM.
#Event ID 3221235486: The activation for CLSID {param1} failed because remote activations for COM+ are disabled.
#Event ID 3221235487: The machine wide limit settings do not grant {param1} {param2} permission for the COM Server application with CLSID {param3} and APPID {param4} to ...
#Event ID 3221235488: The {param1} permission settings do not grant {param2} {param3} permission for the COM Server application with CLSID {param4} and APPID {param5} to...
#Message #
Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-DistributedCOM",
"event_id": 10016,
"level": "Warning",
"task": null,
"opcode": "Info",
"time_created": "2026-05-24T02:14:10.9499544+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "System"
},
"event_data": {
"param5": "{BDBED08B-7FB7-4EEA-AFD0-53DE534CB638}",
"param8": "S-1-5-21-1006758700-2167138679-1475694448-1000",
"param3": "Activation",
"param6": "ludus",
"param1": "application-specific",
"param4": "{0DC1AB8B-A52D-4BA8-BD76-E2819386FB2F}",
"param7": "localuser",
"param11": "Unavailable",
"param9": "LocalHost (Using LRPC)",
"param10": "Unavailable",
"param2": "Local"
}
}
Event ID 3221235489: The {param1} permission settings do not grant {param2} access permission to the COM Server application {param3} with APPID {param4} to the user {pa...
#Event ID 3221235490: The application-specific permission settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to ...
#Event ID 3221235491: The machine wide limit settings do not grant {param1} access permission to the COM Server application {param2} with APPID {param3} to the user {par...
#Event ID 3221235492: The machine wide {param1} {param2} security descriptor is invalid.
#Event ID 3221235493: The launch and activation security descriptor for the COM Server application with APPID {param1} is invalid.
#Event ID 3221235494: The {param1} access security descriptor for the COM Server application {param2} with APPID %3 is invalid.
#Event ID 3221235495: The application-specific access security descriptor for the COM Server application {param1} with APPID %2 is invalid.
#Event ID 3221235496: The machine wide group policy {param1} Limits security descriptor is invalid.
#Event ID 3221235499: The machine wide limit settings do not grant {param1} {param2} permission for COM Server applications to the user {param3}\{param4} SID ({param5}) ...
#Event ID 3221235501: DCOM started the service {param1} with arguments '{param2}' in order to run the server:{param3}.
#Event ID 3221235507: The COM standard marshaler was unable to fix a mismatch between the IID {ProvidedIid} provided by the server and the IID {RequestedIid} requested b...
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1b562e86-b7aa-4131-badc-b6f3a001407e
Defined in combase.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02