Microsoft-Windows-DSC

EventTitleChannelSampleRule
4097Job <JobId>: This event indicates that failure happens when <ComponentName> is …OperationalNN
4098Job <JobId>: Displaying messages from built-in DSC resources: WMI channel …AnalyticNN
4099Job <JobId>: Method <MethodName> started.DebugNN
4100Job <JobId>: Displaying messages from the engine: WMI channel …AnalyticNN
4101Job <JobId>: From <ClassName>, message is <MessageBody>.AnalyticNN
4102Job <JobId>: Operation <Operation> started by user sid <UserSid> from computer …OperationalYN
4103Job <JobId>: This event indicates that a non-terminating error was thrown when …OperationalNN
4104Job <JobId>: This event indicates that failure happens when <ComponentName> is …OperationalNN
4105Job <JobId>: Attempting to get the configuration from pull server using Download …OperationalNN
4106Job <JobId>: Attempting to get the modules from pull server using Download …OperationalNN
4107Job <JobId>: Attempting to get the action from pull server using Download …OperationalNN
4108Job <JobId>: Successfully got the configuration from pull server using Download …OperationalNN
4109Job <JobId>: Successfully got the modules from pull server using Download …OperationalNN
4110Job <JobId>: Successfully got the action <ActionStatus> from pull server using …OperationalNN
4111Job <JobId>: Successfully installed the certificate <Thumbprint> from <Path>.OperationalNN
4112Job <JobId>: Skipping installing certificate <Thumbprint> as it is already …OperationalNN
4113Job <JobId>: Successfully deleted certificate file <Path>.OperationalNN
4114Job <JobId>: Running consistency engine.OperationalYN
4115Job <JobId>: Consistency engine was run successfully.OperationalYN
4116Job <JobId>: This event indicates that failure happened while trying to run …OperationalNN
4117Job <JobId>: Displaying verbose messages from Powershell DSC resource: …AnalyticNN
4118Job <JobId>: Displaying debug messages from Powershell DSC resource: ResourceID: …DebugNN
4119Job <JobId>: Method <MethodName> started with parameters Class name: <ClassName> …DebugNN
4120Job <JobId>: Method <MethodName> ended successfully.DebugNN
4121Job <JobId>: Current configuration is cancelled.OperationalNN
4128Job <JobId>: Configuration is stopped when Powershell DSC resource is executing.OperationalNN
4129Job <JobId>: Write progress failed with error code <ErrorCode>.OperationalNN
4130Job <JobId>: Current configuration is forcely stopped.OperationalNN
4131Job <JobId>: DSC Engine Error: Error Message: <ErrorMessage> Error Code: …OperationalNN
4132Job <JobId>: Getting a registration instance for <param1>.DebugNN
4133Job <JobId>: Module manager is loading instance document from location <param1>.DebugNN
4134Job <JobId>: Validating instance document.DebugNN
4135Job <JobId>: Deleting instance document from location <param1> since it is …AnalyticNN
4136Job <JobId>: Parsing the configuration to apply.AnalyticNN
4137Job <JobId>: Resolving Dependencies inside the configuration document.DebugNN
4144Job <JobId>: Setting resources in order.DebugNN
4145Job <JobId>: Processing resource index <param1>, name <param2>.AnalyticNN
4146Job <JobId>: Getting Metaconfiguration details.DebugNN
4147Job <JobId>: Moving the resource <param1> of class <param2> to desired state.DebugNN
4148Job <JobId>: Setting Metaconfiguration instance.AnalyticNN
4149Job <JobId>: Saving configuration instance into <param1>.DebugNN
4150Job <JobId>: Copying configuration file from <param1> to <param2>.AnalyticNN
4151Job <JobId>: Applying configuration from <param1>.AnalyticNN
4152Job <JobId>: Waiting for the current configuration to stop.AnalyticNN
4153Job <JobId>: Deleting file from <param1>.AnalyticNN
4160Job <JobId>: Registering the task with task scheduler after rebooting the …OperationalNN
4161Job <JobId>: Scheduling a restart of the machine.OperationalNN
4162Job <JobId>: Executing operations for PS DSC resource <param1> with resource …AnalyticNN
4163Job <JobId>: Executing operations for WMIv2 DSC resource <param1>s with resource …AnalyticNN
4164Job <JobId>: Executing GET for PS DSC resource <param1> with resource name …AnalyticNN
4165Job <JobId>: Executing GET for WMIv2 DSC resource <param1> with resource name …AnalyticNN
4166Job <JobId>: Invoking session and getting result for namespace <param1>, …AnalyticNN
4167Job <JobId>: Getting PS DSC resource schema path and registration information.DebugNN
4168Job <JobId>: Function <FunctionName> started with parameters Class name: …DebugNN
4169Job <JobId>: Function <MethodName> started with parameters DataSize: <DataSize> …DebugNN
4176Job <JobId>: Validating infrastructure schema.DebugNN
4177Job <JobId>: Validating DSC resource registration against schema Number of …DebugNN
4178Job <JobId>: Validating DSC resource schema against a class array of size …DebugNN
4179Job <JobId>: Validating Schema of class <param1> which is class index <param2> …DebugNN
4180Job <JobId>: Validating DSC Document instance with instance array size of …DebugNN
4181Job <JobId>: Validating DSC resource registration instance for class: <param1>.DebugNN
4182Job <JobId>: Validating Class property <param1> for class <param2>.DebugNN
4183Job JobId : Failed attempt number ParamNumber : Couldn't delete file ParamText .AnalyticNN
4184Job <JobId>: The current metaconfiguration is not registered for Pull …AnalyticNN
4185Job <JobId>: Failed to register the Pull Server Task for the current …OperationalNN
4192Job <JobId>: Failed to register the Consistency Task for the current …OperationalNN
4193Job <JobId>: Failed to copy the configuration from location <param1> to location …OperationalNN
4194Job <JobId>: Failed to delete the current configuration file.OperationalNN
4195Job <JobId>: Machine was restarted as needed by one or more DSC resources.OperationalNN
4196Job <JobId>: Restoring the configuration to previous configuration.OperationalNN
4197Job <JobId>: Reading the file content from <param1>.DebugNN
4198Job <JobId>: Consistency Engine did not find a current or pending configuration …OperationalNN
4199Job <JobId>: The checksum validation for module <param1> completed with status …OperationalNN
4200Job <JobId>: The content validation for module <param1> completed with status …OperationalNN
4201Job <JobId>: The modules <param1> were downloaded to the location <param2>.OperationalNN
4208Job <JobId>: The modules <param1> were installed at the location <param2>.OperationalNN
4209Job <JobId>: Attempting to get the modules <param1> from pull server with Server …OperationalNN
4210Job <JobId>: Attempting to get the configuration <param1> from pull server with …OperationalNN
4211Job <JobId>: The checksum validation for configuration <param1> completed with …OperationalNN
4212Job <JobId>: The configuration <param1> has an invalid format.OperationalNN
4213Job <JobId>: The module <param1> has an invalid version format <param2>.OperationalNN
4214Job <JobId>: Skipping pulling module <param1> with version <param2> as it …OperationalNN
4215Job <JobId>: Extraction for module <param1> failed since module path <param2> …OperationalNN
4216Job <JobId>: Skipping pulling of modules since all modules specified in …OperationalNN
4217Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument …OperationalNN
4224Job <JobId>: WebDownloadManager processed certificate: <param1> <param2>.OperationalNN
4225Job <JobId>: WebDownloadManager for configuration s Get-DscDocument command, …OperationalNN
4226Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument …OperationalNN
4227Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument …OperationalNN
4228Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument …OperationalNN
4229Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument …OperationalNN
4230Job <JobId>: WebDownloadManager Get-DscModule command, module <param1> using …OperationalNN
4231Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, Http …OperationalNN
4232Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, GET Url: …OperationalNN
4233Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, GET call …OperationalNN
4240Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, Checksum …OperationalNN
4241Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, File …OperationalNN
4242Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command …OperationalNN
4243Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command …OperationalNN
4244Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, …OperationalNN
4245Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, …OperationalNN
4246Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, …OperationalNN
4247Job <JobId>: Module <param1> is over written with the downloaded module …OperationalNN
4248Job <JobId>: Cannot download configuration from <param1>.OperationalNN
4249Job <JobId>: From <ClassName>, message is <MessageBody>.OperationalYN
4250Job <JobId>: Message <Message> HResult <HResult> StackTrack <StackTrace>.OperationalNN
4251Job <JobId>: Operation <Operation> completed successfully.OperationalYN
4252Job <JobId>: MIResult: <MIResult> Error Message: <ErrorMessage> Message ID: …OperationalNN
4253Job <JobId>: WarningMessage <WarningMessage>.OperationalNN
4254Job <JobId>: DebugMessage <DebugMessage>.DebugNN
4255Job <JobId>: Activity <activity> CurrentOperation <currentOperation> …DebugNN
4256Job <JobId>: PromptMessage <PromptMessage>.DebugNN
4257Job <JobId>: Job runs under the following LCM setting.OperationalYN
4258Job <JobId>: Cannot register at <param1>.OperationalNN
4260Job <JobId>: Http Client <param1> failed for WebReportManager for configuration …OperationalNN
4261Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command with …OperationalNN
4262Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command, POST …OperationalNN
4263Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command using …OperationalNN
4264Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command …OperationalNN
4265Job <JobId>: Attempting to send the status report using Report Manager …OperationalNN
4266Job <JobId>: Successfully sent the status report using Report Manager …OperationalNN
4267Job <JobId>: Partial Configuration <PartialConfigurationName> not available on …OperationalNN
4268Job <JobId>: LCM has resized the resource state cache.DebugNN
4269Job <JobId>: Restore default value due to corrupted MOF file <FileName>.OperationalNN
4270The local configuration manager was shut down.OperationalYN
4271The local configuration manager started.OperationalYN
4272One of the input streams to the local configuration manager unexpectedly …OperationalNN
4273One of the input streams to the local configuration manager unexpectedly failed.OperationalNN
4274Job <JobId>: Pulling partial configuration <param1> from the server.OperationalNN
4275Job <JobId>: Starting to apply partial configuration <param1>.OperationalNN
4276Job <JobId>: Handling application of configurations in partial configuration …AnalyticNN
4277Job <JobId>: Looking into the partial configuration store to merge any present …AnalyticNN
4278Job <JobId>: Merging partial configuration <param1> into pending.AnalyticNN
4279Job <JobId>: Validating the partial configuration <param1> for consistency in …AnalyticNN
4280Job <JobId>: Validating the document got from merging all partial …DebugNN
4281Job <JobId>: Validating the partial configuration definition blocks inside the …DebugNN
4282Job <JobId>: Validating that the name of the partial configuration …DebugNN
4283Job <JobId>: Validating that the configuration source defined in each partial …DebugNN
4284Job <JobId>: Validating that the exclusive resources are not conflicting in the …DebugNN
4285Job <JobId>: Validating if the exclusive resource <exclusiveResource> is written …DebugNN
4286Job <JobId>: The local configuration manager has applied the configuration …AnalyticNN
4287A crash has occured in Local Configuration Manager.OperationalNN
4288Job <JobId>: The local configuration manager did not find any current …OperationalNN
4289Job <JobId>: The local configuration manager failed to remove the current …OperationalNN
4290Job <JobId>: The local configuration manager was able to successfully remove the …OperationalNN
4291Job <JobId>: The local configuration manager is attempting to remove the pending …OperationalNN
4292Job <JobId>: The local configuration manager did not find any pending …OperationalNN
4293Job <JobId>: The local configuration manager failed to remove the pending …OperationalNN
4294Job <JobId>: The local configuration manager was able to successfully remove the …OperationalNN
4295Job <JobId>: The local configuration manager is attempting to remove the …OperationalNN
4296Job <JobId>: The local configuration manager did not find any previous …OperationalNN
4297Job <JobId>: The local configuration manager failed to remove the previous …OperationalNN
4298Job <JobId>: The local configuration manager was able to successfully remove the …OperationalNN
4299Job <JobId>: Could not wait for the stopping event.OperationalNN
4300Job <JobId>: The local configuration manager is attempting to remove the current …OperationalNN
4301Job <JobId>: The local configuration manager is attempting to remove partial …OperationalNN
4302Job <JobId>: The local configuration manager was able to successfully remove …OperationalNN
4303Job <JobId>: The local configuration manager failed to remove partial …OperationalNN
4304Job <JobId>: The local configuration manager did not find any partial …OperationalNN
4305Job <JobId>: The DownloadManager <Name> is invalid.OperationalNN
4306Job <JobId>: The ReportManager <Name> is invalid.OperationalNN
4307The DscTimer is going to start the consistency timer for the first time with …OperationalYN
4308The DscTimer is going to start the refresh timer for the first time with value …OperationalYN
4309The DScTimer is updating the consistency timer to the value …OperationalNN
4310The DscTimer is updating the refresh timer to the value RefreshTimerValue …OperationalNN
4311The DscTimer is going to invoke the consistency check for task of type REBOOT.OperationalYN
4312The DscTimer is running LCM method PerformRequiredConfigurationChecks with the …OperationalYN
4313The DscTimer successfully created the consistency timer.OperationalYN
4314The DscTimer successfully created the refresh timer.OperationalYN
4315Job <JobId>: The local configuration manager is attempting to remove the …OperationalNN
4316Job <JobId>: The local configuration manager did not find configuration checksum …OperationalNN
4317Job <JobId>: The local configuration manager failed to remove the configuration …OperationalNN
4318Job <JobId>: The local configuration manager was able to successfully remove the …OperationalNN
4319Job <JobId>: The local configuration manager is updating the PSModulePath to …OperationalYN
4320Job <JobId>: The local configuration manager could not read the system …OperationalNN
4321Job <JobId>: PsDscRunAsCredential has been specified.OperationalNN
4322Job <JobId>: Impersonation successful.OperationalNN
4323Job <JobId>: Impersonation reverted.OperationalNN
4324Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command with …OperationalNN
4325Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command using …OperationalNN
4326Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, Http …OperationalNN
4327Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, GET …OperationalNN
4328Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, GET …OperationalNN
4329Job <JobId>: Register-DscAgent command for AgentId <AgentId>.OperationalNN
4332Job <JobId>: Resource execution sequence:: <ResourceSequence>.OperationalYN
4333Job <JobId>: Attempting to get the configuration from pull server using Download …OperationalNN
4334Job <JobId>: Attempting to get the modules from pull server using Download …OperationalNN
4335Job <JobId>: Checksum Validation failed.OperationalNN
4336Job <JobId>: Server has returned a response of UpdateMetaConfiguration.OperationalNN
4337Job <JobId>: A ServerUrl was not located in the metaconfiguration for AgentId …OperationalNN
4338Job <JobId>: The current pull request-id is <requestId>.DebugNN
4339Job <JobId>: The server response was Header: <header> and Content:<content>.DebugNN
4340The DscTimer is going to start the timer to create task for sending pending …OperationalNN
4341The DScTimer is updating the timer to create task to send pending report to the …OperationalNN
4342The DscTimer successfully created the timer to create task for sending pending …OperationalNN
4343The DscTimer has successfully run LCM method PerformRequiredConfigurationChecks …OperationalYN
4344The DscTimer is already performing operation with flag flag,ignoring new …OperationalNN
4345The DSCStatusHistory.OperationalNN
4346The DSCConfigurationStatus mof file not found at path.OperationalNN
4347Deserializing mof path failed.OperationalNN
4348Failed to process non-terminating error from resource 'resourceName'.OperationalNN
4349Job <JobId>: The local configuration manager is attempting to remove the …OperationalNN
4350Job <JobId>: The local configuration manager did not find any configuration …OperationalNN
4351Job <JobId>: The local configuration manager failed to remove the configuration …OperationalNN
4352Job <JobId>: The local configuration manager was able to successfully remove the …OperationalNN
4353Job <JobId>: LCM has released the resource state cache.DebugNN
4401Job <JobId>: Attempting to register the Dsc agent with AgentId <AgentId> with …OperationalNN
4402Job <JobId>: Successfully registered the Dsc agent with AgentId <AgentId> with …OperationalNN
4403Job <JobId>: Registering Dsc Agent with Agent Id <AgentId>.OperationalNN
4404Job <JobId>: Http Client <AgentId> failed to register Dsc Agent: <error>.OperationalNN
4405Job <JobId>: Register-DscAgent command for AgentId <AgentId> succeeded.OperationalNN
4406Job <JobId>: Register-DscAgent command for AgentId <AgentId> using certificate …OperationalNN
4407Job <JobId>: The Dsc Agent will generate a new AgentId.OperationalYN
4408Job <JobId>: Unable to write AgentId <AgentId> to registry.OperationalNN
4409Job <JobId>: The Dsc Agent with AgentId <AgentId> has already been registered …OperationalNN
4410Job <JobId>: Using Version 1 protocol of Dsc PULL.DebugNN
4411Job <JobId>: Attempt to register the Dsc Agent AgentId <AgentId> with Server URL …OperationalNN
4412Job <JobId>: The Dsc Agent with AgentId <AgentId> failed to create a self-signed …OperationalNN
4413Job <JobId>: The AgentId <AgentId> was written to the registry.OperationalYN
4501Telemetry assembly assemblyName does not successfully load.OperationalNN
4502Cannot get type typeName from loaded Dsc Telemetry assembly.OperationalNN
4503An error occured when initializing event source instance for Dsc Telemetry …OperationalNN
4504Job <JobId>: WebDownloadManager for configuration associated with AgentId …OperationalNN
4505Job <JobId>: WebDownloadManager for configuration associated with AgentId …OperationalNN
4506Job <JobId>: WebDownloadManager for configuration associated with AgentId …OperationalNN
4507Job <JobId>: WebDownloadManager for configuration associated with AgentId …OperationalNN
4508Job <JobId>: Attempting to send the status report using Report Manager …OperationalNN
4509Job <JobId>: Updating PSModulePath with the current value from the registry …DebugNN
4510Job JobId : errorno error writing to job details log logName.OperationalNN
4511Job JobId : errorno error closing job details log logName.OperationalNN
4512Job JobId : Details logging started to logName.OperationalYN
4513Job JobId : Details logging completed for logName.OperationalYN
4514Validating the signer signature chain failed with the status 'signatureStatus'.OperationalNN
4515Failed to open trusted publisher store with the error 'message'.OperationalNN
4516Failed to retrieve signing certificate information from the trusted publisher …OperationalNN
4517Failed to parse trusted publisher store path with the error 'message'.OperationalNN
4518Trusted publisher store path is : 'storeInfo'.OperationalNN
4519Signature validation was successful.OperationalNN
4520Validating the signer signature trust failed.OperationalNN
4521Validating the signer signature hash failed with the status 'signatureStatus'.OperationalNN
4522Validating the signer signature failed with the status 'signatureStatus'.OperationalNN
4523Validating the signature of the configuration document failed.OperationalNN
4524Signature validation skipped becouse machine signature verification policy is …OperationalNN
4525Extracting the downloaded zip file 'zipFileName' failed.OperationalNN
4526The downloaded zip file 'zipFileName' does not contain a catalog file.OperationalNN
4527Catalog signature verification failed for the downloaded zip file 'zipFileName'.OperationalNN
4528Comparing the module catalalog with current contents of the module succeeded for …OperationalNN
4529Comparing the module catalalog file with current contents of the module failed …OperationalNN
4530The Local Configuration Manager could not find the partial configuration block …OperationalNN
4531The uncompressed file size of the downloaded zip file <zipFile>, exceeded the …OperationalNN
4601Job <JobId>: Http Client <AgentId> failed to rotate Dsc Agent registration: …OperationalNN
4602Job <JobId>: Rotating Dsc Agent registration with Agent Id <AgentId>.OperationalNN
4603Job <JobId>: Http Client <AgentId> received an unknown rotate header with the …OperationalNN
4604Job <JobId>: Rotate-DscAgent command for AgentId <AgentId> succeeded.OperationalNN
4605Job <JobId>: Rotate-DscAgent command for AgentId <AgentId> to certificate id: …OperationalNN

Event ID 4097: Job <JobId>: This event indicates that failure happens when <ComponentName> is processing the configuration.

#
Channel
Operational
Task
SendconfigurationscenarioforLocalconfigurationmanager

Description

Job <JobId>: This event indicates that failure happens when <ComponentName> is processing the configuration. Error Id is <ErrorId>. Error Detail is <ErrorDetail>. Resource Id is <ResourceId> and Source Info is <SourceInfo>. Error Message is <ErrorMessage>.

Message #

Job <JobId>: This event indicates that failure happens when <ComponentName> is processing the configuration. Error Id is <ErrorId>. Error Detail is <ErrorDetail>. Resource Id is <ResourceId> and Source Info is <SourceInfo>. Error Message is <ErrorMessage>.

Fields #

NameDescription
JobId UnicodeString
ComponentName UnicodeString
ErrorId HexInt32
ErrorDetail UnicodeString
ResourceId UnicodeString
SourceInfo UnicodeString
ErrorMessage UnicodeString

Event ID 4098: Job <JobId>: Displaying messages from built-in DSC resources: WMI channel <WMIMessageChannel> ResourceID: <ResourceId> Message: <MessageBody>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
WMIMessageChannel UInt32
ResourceId UnicodeString
MessageBody UnicodeString

Event ID 4099: Job <JobId>: Method <MethodName> started.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
MethodName UnicodeString

Event ID 4100: Job <JobId>: Displaying messages from the engine: WMI channel <WMIMessageChannel> ResourceID: <ResourceId> Message: <MessageBody>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
WMIMessageChannel UInt32
ResourceId UnicodeString
MessageBody UnicodeString

Event ID 4101: Job <JobId>: From <ClassName>, message is <MessageBody>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
ClassName UnicodeString
MessageBody UnicodeString

Event ID 4102: Job <JobId>: Operation <Operation> started by user sid <UserSid> from computer <ComputerName>.

#
Channel
Operational
Level
Informational
Task
SendconfigurationscenarioforLocalconfigurationmanager

Fields #

NameDescription
JobId UnicodeString
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
UserSid UnicodeString
ComputerName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4102,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.2131871+00:00",
    "event_record_id": 24,
    "correlation": {
      "ActivityID": "{DC261B5A-AEBD-41EB-ACFE-F2646C1474A8}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "Operation": "Consistency Check or Pull",
    "UserSid": "S-1-5-20",
    "ComputerName": "NULL"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nOperation Consistency Check or Pull started by user sid S-1-5-20 from computer NULL."
}

Event ID 4103: Job <JobId>: This event indicates that a non-terminating error was thrown when <ComponentName> was executing <OperationCmd> on <ProviderName> DSC r...

#
Channel
Operational

Description

Job <JobId>: This event indicates that a non-terminating error was thrown when <ComponentName> was executing <OperationCmd> on <ProviderName> DSC resource. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error Message is <ErrorMessage>.

Message #

Job <JobId>: This event indicates that a non-terminating error was thrown when <ComponentName> was executing <OperationCmd> on <ProviderName> DSC resource. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error Message is <ErrorMessage>.

Fields #

NameDescription
JobId UnicodeString
ComponentName UnicodeString
OperationCmd UnicodeString
ProviderName UnicodeString
FullyQualifiedErrorId UnicodeString
ErrorMessage UnicodeString

Event ID 4104: Job <JobId>: This event indicates that failure happens when <ComponentName> is trying to get the configuration from pull server using download mana...

#
Channel
Operational

Description

Job <JobId>: This event indicates that failure happens when <ComponentName> is trying to get the configuration from pull server using download manager <DownloadManagerName>. ErrorId is <ErrorId>. ErrorDetail is <ErrorDetail>

Message #

Job <JobId>: This event indicates that failure happens when <ComponentName> is trying to get the configuration from pull server using download manager <DownloadManagerName>. ErrorId is <ErrorId>. ErrorDetail is <ErrorDetail>

Fields #

NameDescription
JobId UnicodeString
ComponentName UnicodeString
DownloadManagerName UnicodeString
ErrorId HexInt32
ErrorDetail UnicodeString

Event ID 4105: Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>.Configuration Id is <ConfigurationId>.

Message #

Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>.Configuration Id is <ConfigurationId>.

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString
ConfigurationId UnicodeString

Event ID 4106: Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>. Configuration Id is <ConfigurationId>. Modules are <Modules>.

Message #

Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>. Configuration Id is <ConfigurationId>. Modules are <Modules>.

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString
ConfigurationId UnicodeString
Modules UnicodeString

Event ID 4107: Job <JobId>: Attempting to get the action from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to get the action from pull server using Download Manager <DownloadManagerName>. Configuration Id is <ConfigurationId>. Checksum is <Checksum>. Compliance status is <Compliant>.

Message #

Job <JobId>: Attempting to get the action from pull server using Download Manager <DownloadManagerName>. Configuration Id is <ConfigurationId>. Checksum is <Checksum>. Compliance status is <Compliant>.

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString
ConfigurationId UnicodeString
Checksum UnicodeString
Compliant Boolean

Event ID 4108: Job <JobId>: Successfully got the configuration from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString

Event ID 4109: Job <JobId>: Successfully got the modules from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString

Event ID 4110: Job <JobId>: Successfully got the action <ActionStatus> from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
ActionStatus UnicodeString
DownloadManagerName UnicodeString

Event ID 4111: Job <JobId>: Successfully installed the certificate <Thumbprint> from <Path>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
Thumbprint UnicodeString
Path UnicodeString

Event ID 4112: Job <JobId>: Skipping installing certificate <Thumbprint> as it is already installed.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
Thumbprint UnicodeString

Event ID 4113: Job <JobId>: Successfully deleted certificate file <Path>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
Path UnicodeString

Event ID 4114: Job <JobId>: Running consistency engine.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4114,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.2244131+00:00",
    "event_record_id": 26,
    "correlation": {
      "ActivityID": "{DC261B5A-AEBD-41EB-ACFE-F2646C1474A8}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nRunning consistency engine."
}

Event ID 4115: Job <JobId>: Consistency engine was run successfully.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4115,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4789520+00:00",
    "event_record_id": 29,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-0007-6EE6-13CFFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nConsistency engine was run successfully."
}

Event ID 4116: Job <JobId>: This event indicates that failure happened while trying to run consistency engine.

#
Channel
Operational

Description

Job <JobId>: This event indicates that failure happened while trying to run consistency engine. ErrorId is <ErrorId>. ErrorDetail is <ErrorDetail>

Message #

Job <JobId>: This event indicates that failure happened while trying to run consistency engine. ErrorId is <ErrorId>. ErrorDetail is <ErrorDetail>

Fields #

NameDescription
JobId UnicodeString
ErrorId UInt32
ErrorDetail UnicodeString

Event ID 4117: Job <JobId>: Displaying verbose messages from Powershell DSC resource: ResourceID: <ResourceId> Message: <MessageBody>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
ResourceId UnicodeString
MessageBody UnicodeString

Event ID 4118: Job <JobId>: Displaying debug messages from Powershell DSC resource: ResourceID: <ResourceId> Message: <MessageBody>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
ResourceId UnicodeString
MessageBody UnicodeString

Event ID 4119: Job <JobId>: Method <MethodName> started with parameters Class name: <ClassName> Resource ID: <ResourceID> Flags: <Flags> Execution Mode: <Executio...

#
Channel
Debug

Description

Job <JobId>: Method <MethodName> started with parameters Class name: <ClassName> Resource ID: <ResourceID> Flags: <Flags> Execution Mode: <ExecutionMode> DSC resource Namespace: <ProviderNamespace>

Message #

Job <JobId>: Method <MethodName> started with parameters Class name: <ClassName> Resource ID: <ResourceID> Flags: <Flags> Execution Mode: <ExecutionMode> DSC resource Namespace: <ProviderNamespace>

Fields #

NameDescription
JobId UnicodeString
MethodName UnicodeString
ClassName UnicodeString
ResourceID UnicodeString
Flags UInt32Class name.
ExecutionMode UInt32
ProviderNamespace UnicodeString

Event ID 4120: Job <JobId>: Method <MethodName> ended successfully.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
MethodName UnicodeString

Event ID 4121: Job <JobId>: Current configuration is cancelled.

#
Channel
Operational
Task
SendconfigurationscenarioforLocalconfigurationmanager

Description

Job <JobId>: Current configuration is cancelled. <TotalSize> out of <RemainingSize> resources are not configured.

Message #

Job <JobId>: Current configuration is cancelled. <TotalSize> out of <RemainingSize> resources are not configured.

Fields #

NameDescription
JobId UnicodeString
TotalSize UInt32
RemainingSize UInt32

Event ID 4128: Job <JobId>: Configuration is stopped when Powershell DSC resource is executing.

#
Channel
Operational
Task
SendconfigurationscenarioforLocalconfigurationmanager

Fields #

NameDescription
JobId UnicodeString

Event ID 4129: Job <JobId>: Write progress failed with error code <ErrorCode>.

#
Channel
Operational
Task
SendconfigurationscenarioforLocalconfigurationmanager

Description

Job <JobId>: Write progress failed with error code <ErrorCode>. The current configuration will be stopped.

Message #

Job <JobId>: Write progress failed with error code <ErrorCode>. The current configuration will be stopped.

Fields #

NameDescription
JobId UnicodeString
ErrorCode UInt32

Event ID 4130: Job <JobId>: Current configuration is forcely stopped.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4131: Job <JobId>: DSC Engine Error: Error Message: <ErrorMessage> Error Code: <ErrorCode>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
ErrorMessage UnicodeString
ErrorCode UInt32

Event ID 4132: Job <JobId>: Getting a registration instance for <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4133: Job <JobId>: Module manager is loading instance document from location <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4134: Job <JobId>: Validating instance document.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4135: Job <JobId>: Deleting instance document from location <param1> since it is invalid.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4136: Job <JobId>: Parsing the configuration to apply.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4137: Job <JobId>: Resolving Dependencies inside the configuration document.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4144: Job <JobId>: Setting resources in order.

#
Channel
Debug

Description

Job <JobId>: Setting resources in order. Number of resources: <param1>

Message #

Job <JobId>: Setting resources in order. Number of resources: <param1>

Fields #

NameDescription
JobId UnicodeString
param1 UInt32

Event ID 4145: Job <JobId>: Processing resource index <param1>, name <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UInt32
param2 UnicodeString

Event ID 4146: Job <JobId>: Getting Metaconfiguration details.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4147: Job <JobId>: Moving the resource <param1> of class <param2> to desired state.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4148: Job <JobId>: Setting Metaconfiguration instance.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4149: Job <JobId>: Saving configuration instance into <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4150: Job <JobId>: Copying configuration file from <param1> to <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4151: Job <JobId>: Applying configuration from <param1>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4152: Job <JobId>: Waiting for the current configuration to stop.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4153: Job <JobId>: Deleting file from <param1>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4160: Job <JobId>: Registering the task with task scheduler after rebooting the machine.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4161: Job <JobId>: Scheduling a restart of the machine.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4162: Job <JobId>: Executing operations for PS DSC resource <param1> with resource name <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4163: Job <JobId>: Executing operations for WMIv2 DSC resource <param1>s with resource name <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4164: Job <JobId>: Executing GET for PS DSC resource <param1> with resource name <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4165: Job <JobId>: Executing GET for WMIv2 DSC resource <param1> with resource name <param2>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4166: Job <JobId>: Invoking session and getting result for namespace <param1>, classname <param2> for method <param3>.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 4167: Job <JobId>: Getting PS DSC resource schema path and registration information.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4168: Job <JobId>: Function <FunctionName> started with parameters Class name: <ClassName> Method Name: <MethodName> Namespace: <Namespace>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
FunctionName UnicodeString
ClassName UnicodeString
MethodName UnicodeString
Namespace UnicodeStringClass name.

Event ID 4169: Job <JobId>: Function <MethodName> started with parameters DataSize: <DataSize> Flags: <Flags> Execution Mode: <ExecutionMode>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
MethodName UnicodeString
DataSize UInt32
Flags UInt32
ExecutionMode UInt32

Event ID 4176: Job <JobId>: Validating infrastructure schema.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
paramNumber UInt32

Event ID 4177: Job <JobId>: Validating DSC resource registration against schema Number of classes: <param1> Number of Registrations: <param2>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UInt32
param2 UInt32

Event ID 4178: Job <JobId>: Validating DSC resource schema against a class array of size <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UInt32

Event ID 4179: Job <JobId>: Validating Schema of class <param1> which is class index <param2> in an array of classes of size <param3>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UInt32
param3 UInt32

Event ID 4180: Job <JobId>: Validating DSC Document instance with instance array size of <param1> and flags <param2>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UInt32
param2 UInt32

Event ID 4181: Job <JobId>: Validating DSC resource registration instance for class: <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4182: Job <JobId>: Validating Class property <param1> for class <param2>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4183: Job JobId : Failed attempt number ParamNumber : Couldn't delete file ParamText .

#
Channel
Analytic

Description

Job JobId : Failed attempt number ParamNumber : Couldn't delete file ParamText . The error code is ParamErrorCode. The error message is: ParamErrorMessage.

Message #

Job <JobId>: Failed attempt number <ParamNumber>: Couldn't delete file <ParamText>. The error code is <ParamErrorCode>. The error message is: <ParamErrorMessage>

Fields #

NameDescription
JobId UnicodeString
ParamNumber UInt32
ParamText UnicodeString
ParamErrorCode UInt32
ParamErrorMessage UnicodeString

Event ID 4184: Job <JobId>: The current metaconfiguration is not registered for Pull configuration mode.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4185: Job <JobId>: Failed to register the Pull Server Task for the current metaconfiguration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4192: Job <JobId>: Failed to register the Consistency Task for the current metaconfiguration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4193: Job <JobId>: Failed to copy the configuration from location <param1> to location <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4194: Job <JobId>: Failed to delete the current configuration file.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4195: Job <JobId>: Machine was restarted as needed by one or more DSC resources.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4196: Job <JobId>: Restoring the configuration to previous configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4197: Job <JobId>: Reading the file content from <param1>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4198: Job <JobId>: Consistency Engine did not find a current or pending configuration to apply.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4199: Job <JobId>: The checksum validation for module <param1> completed with status code <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UInt32

Event ID 4200: Job <JobId>: The content validation for module <param1> completed with status code <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UInt32

Event ID 4201: Job <JobId>: The modules <param1> were downloaded to the location <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4208: Job <JobId>: The modules <param1> were installed at the location <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4209: Job <JobId>: Attempting to get the modules <param1> from pull server with Server Url <param2> using Web Download Manager.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4210: Job <JobId>: Attempting to get the configuration <param1> from pull server with Server Url <param2> using Web Download Manager.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4211: Job <JobId>: The checksum validation for configuration <param1> completed with status code <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UInt32

Event ID 4212: Job <JobId>: The configuration <param1> has an invalid format.

#
Channel
Operational

Description

Job <JobId>: The configuration <param1> has an invalid format. The configuration name should be a UUID.

Message #

Job <JobId>: The configuration <param1> has an invalid format. The configuration name should be a UUID.

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4213: Job <JobId>: The module <param1> has an invalid version format <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4214: Job <JobId>: Skipping pulling module <param1> with version <param2> as it already exists in this location <param3>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 4215: Job <JobId>: Extraction for module <param1> failed since module path <param2> already exists.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4216: Job <JobId>: Skipping pulling of modules since all modules specified in configuration <param1> are available.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4217: Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument command using certificate id: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4224: Job <JobId>: WebDownloadManager processed certificate: <param1> <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4225: Job <JobId>: WebDownloadManager for configuration s Get-DscDocument command, Http Client failed: <param1>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4226: Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument command, GET Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4227: Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument command, GET call result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4228: Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument command, Checksum validation failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4229: Job <JobId>: WebDownloadManager for configuration <param1> Get-DscDocument command, File save result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4230: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1> using certificate id: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4231: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, Http Client failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4232: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, GET Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4233: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, GET call result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4240: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, Checksum validation failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4241: Job <JobId>: WebDownloadManager Get-DscModule command, module <param1>, File save result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4242: Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command with server url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4243: Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command using certificate id: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4244: Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, Http Client failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4245: Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, GET Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4246: Job <JobId>: WebDownloadManager for configuration <param1> Do-DscAction command, GET call result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4247: Job <JobId>: Module <param1> is over written with the downloaded module <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4248: Job <JobId>: Cannot download configuration from <param1>.

#
Channel
Operational

Description

Job <JobId>: Cannot download configuration from <param1>. Downloading over HTTP is not allowed.

Message #

Job <JobId>: Cannot download configuration from <param1>. Downloading over HTTP is not allowed.

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4249: Job <JobId>: From <ClassName>, message is <MessageBody>.

#
Channel
Operational
Level
Warning

Fields #

NameDescription
JobId UnicodeString
ClassName UnicodeString
MessageBody UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4249,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4767603+00:00",
    "event_record_id": 28,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-0007-6EE6-13CFFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "ClassName": "LCM",
    "MessageBody": "\n      Completed processing test operation. The operation returned False."
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nFrom LCM, message is \n      Completed processing test operation. The operation returned False."
}

Event ID 4250: Job <JobId>: Message <Message> HResult <HResult> StackTrack <StackTrace>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
Message UnicodeString
HResult Int32
StackTrace UnicodeString

Event ID 4251: Job <JobId>: Operation <Operation> completed successfully.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4251,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4789633+00:00",
    "event_record_id": 31,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-0007-6EE6-13CFFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "Operation": "Consistency Check or Pull"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nOperation Consistency Check or Pull completed successfully."
}

Event ID 4252: Job <JobId>: MIResult: <MIResult> Error Message: <ErrorMessage> Message ID: <MessageID> Error Category: <ErrorCategory> Error Code: <ErrorCode> Err...

#
Channel
Operational

Description

Job <JobId>: MIResult: <MIResult> Error Message: <ErrorMessage> Message ID: <MessageID> Error Category: <ErrorCategory> Error Code: <ErrorCode> Error Type: <ErrorType>

Message #

Job <JobId>: MIResult: <MIResult> Error Message: <ErrorMessage> Message ID: <MessageID> Error Category: <ErrorCategory> Error Code: <ErrorCode> Error Type: <ErrorType>

Fields #

NameDescription
JobId UnicodeString
MIResult UInt32
ErrorMessage UnicodeString
MessageID UnicodeString
ErrorCategory UInt32
ErrorCode UInt32
ErrorType UnicodeString

Event ID 4253: Job <JobId>: WarningMessage <WarningMessage>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
WarningMessage UnicodeString

Event ID 4254: Job <JobId>: DebugMessage <DebugMessage>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
DebugMessage UnicodeString

Event ID 4255: Job <JobId>: Activity <activity> CurrentOperation <currentOperation> StatusDescription <statusDescription> PercentComplete <percentComplete> Second...

#
Channel
Debug

Description

Job <JobId>: Activity <activity> CurrentOperation <currentOperation> StatusDescription <statusDescription> PercentComplete <percentComplete> SecondsRemaining <secondsRemaining>

Message #

Job <JobId>: Activity <activity> CurrentOperation <currentOperation> StatusDescription <statusDescription> PercentComplete <percentComplete> SecondsRemaining <secondsRemaining>

Fields #

NameDescription
JobId UnicodeString
activity UnicodeString
currentOperation UnicodeString
statusDescription UnicodeString
percentComplete UInt32
secondsRemaining UInt32

Event ID 4256: Job <JobId>: PromptMessage <PromptMessage>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
PromptMessage UnicodeString

Event ID 4257: Job <JobId>: Job runs under the following LCM setting.

#
Channel
Operational
Level
Informational

Description

Job <JobId>: Job runs under the following LCM setting. ConfigurationMode: <configurationMode> ConfigurationModeFrequencyMins: <configurationModeFrequencyMins> RefreshMode: <refreshmode> RefreshFrequencyMins: <refreshFrequencyMins> RebootNodeIfNeeded: <rebootNodeIfNeeded> DebugMode: <debugMode>

Message #

Job <JobId>: Job runs under the following LCM setting. ConfigurationMode: <configurationMode> ConfigurationModeFrequencyMins: <configurationModeFrequencyMins> RefreshMode: <refreshmode> RefreshFrequencyMins: <refreshFrequencyMins> RebootNodeIfNeeded: <rebootNodeIfNeeded> DebugMode: <debugMode>

Fields #

NameDescription
JobId UnicodeString
configurationMode UnicodeString
configurationModeFrequencyMins UInt32
refreshmode UnicodeString
refreshFrequencyMins UInt32
rebootNodeIfNeeded UnicodeString
debugMode UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4257,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4789576+00:00",
    "event_record_id": 30,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-0007-6EE6-13CFFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "configurationMode": "ApplyAndMonitor",
    "configurationModeFrequencyMins": "15",
    "refreshmode": "PUSH",
    "refreshFrequencyMins": "30",
    "rebootNodeIfNeeded": "NONE",
    "debugMode": "False"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nJob runs under the following LCM setting. \r\nConfigurationMode: ApplyAndMonitor \r\nConfigurationModeFrequencyMins: 15 \r\nRefreshMode: PUSH \r\nRefreshFrequencyMins: 30 \r\nRebootNodeIfNeeded: NONE \r\nDebugMode: False"
}

Event ID 4258: Job <JobId>: Cannot register at <param1>.

#
Channel
Operational

Description

Job <JobId>: Cannot register at <param1>. Registering over HTTP is not allowed. To ensure security in registration, use an HTTPS address for the ServerUrl in the <param2> of the LocalConfigurationManager resource for this device. If you understand the security implications of using HTTP and want to allow its use on this device, set AllowUnsecureConnection property to true in the <param3> of the LocalConfigurationManager resource for this device.

Message #

Job <JobId>: Cannot register at <param1>. Registering over HTTP is not allowed. To ensure security in registration, use an HTTPS address for the ServerUrl in the <param2> of the LocalConfigurationManager resource for this device. If you understand the security implications of using HTTP and want to allow its use on this device, set AllowUnsecureConnection property to true in the <param3> of the LocalConfigurationManager resource for this device.

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 4260: Job <JobId>: Http Client <param1> failed for WebReportManager for configuration <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4261: Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command with server url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4262: Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command, POST Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4263: Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command using certificate id: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4264: Job <JobId>: WebReportManager for agent <param1> Send-DscStatus command succeeded.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4265: Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>. Configuration Id is <ConfigurationId>.

Message #

Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>. Configuration Id is <ConfigurationId>.

Fields #

NameDescription
JobId UnicodeString
ReportManagerName UnicodeString
ConfigurationId UnicodeString

Event ID 4266: Job <JobId>: Successfully sent the status report using Report Manager <ReportManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
ReportManagerName UnicodeString

Event ID 4267: Job <JobId>: Partial Configuration <PartialConfigurationName> not available on configuration server.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
PartialConfigurationName UnicodeString

Event ID 4268: Job <JobId>: LCM has resized the resource state cache.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4269: Job <JobId>: Restore default value due to corrupted MOF file <FileName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
FileName UnicodeString

Event ID 4270: The local configuration manager was shut down.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4270,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:44:19.1116750+00:00",
    "event_record_id": 48,
    "correlation": {
      "ActivityID": "{C593B7AD-BB71-4D84-8DDF-486161585923}"
    },
    "execution": {
      "process_id": 6940,
      "thread_id": 3036
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The local configuration manager was shut down."
}

Event ID 4271: The local configuration manager started.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4271,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:26.4817259+00:00",
    "event_record_id": 3,
    "correlation": {
      "ActivityID": "{603B392B-5B0C-4D93-A76B-EEADDD96B7E7}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 9864
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The local configuration manager started."
}

Event ID 4272: One of the input streams to the local configuration manager unexpectedly completed.

#
Channel
Operational

Event ID 4273: One of the input streams to the local configuration manager unexpectedly failed.

#
Channel
Operational

Event ID 4274: Job <JobId>: Pulling partial configuration <param1> from the server.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4275: Job <JobId>: Starting to apply partial configuration <param1>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4276: Job <JobId>: Handling application of configurations in partial configuration mode based on the meta configuration definition.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4277: Job <JobId>: Looking into the partial configuration store to merge any present partial configurations.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4278: Job <JobId>: Merging partial configuration <param1> into pending.

#
Channel
Analytic

Description

Job <JobId>: Merging partial configuration <param1> into pending.mof

Message #

Job <JobId>: Merging partial configuration <param1> into pending.mof

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4279: Job <JobId>: Validating the partial configuration <param1> for consistency in configuration Name and exclusive resources.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString

Event ID 4280: Job <JobId>: Validating the document got from merging all partial configurations.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4281: Job <JobId>: Validating the partial configuration definition blocks inside the meta configuration.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4282: Job <JobId>: Validating that the name of the partial configuration <partialConfigName> is consistent across the partial configuration.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
partialConfigName UnicodeString

Event ID 4283: Job <JobId>: Validating that the configuration source defined in each partial configuration inside the meta configuration are defined as configurat...

#
Channel
Debug

Description

Job <JobId>: Validating that the configuration source defined in each partial configuration inside the meta configuration are defined as configuration download managers as well.

Message #

Job <JobId>: Validating that the configuration source defined in each partial configuration inside the meta configuration are defined as configuration download managers as well.

Fields #

NameDescription
JobId UnicodeString

Event ID 4284: Job <JobId>: Validating that the exclusive resources are not conflicting in the meta configuration definition.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4285: Job <JobId>: Validating if the exclusive resource <exclusiveResource> is written in the correct format.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
exclusiveResource UnicodeString

Event ID 4286: Job <JobId>: The local configuration manager has applied the configuration successfully.

#
Channel
Analytic

Fields #

NameDescription
JobId UnicodeString

Event ID 4287: A crash has occured in Local Configuration Manager.

#
Channel
Operational

Event ID 4288: Job <JobId>: The local configuration manager did not find any current configuration to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4289: Job <JobId>: The local configuration manager failed to remove the current configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4290: Job <JobId>: The local configuration manager was able to successfully remove the current configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4291: Job <JobId>: The local configuration manager is attempting to remove the pending configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4292: Job <JobId>: The local configuration manager did not find any pending configuration to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4293: Job <JobId>: The local configuration manager failed to remove the pending configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4294: Job <JobId>: The local configuration manager was able to successfully remove the pending configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4295: Job <JobId>: The local configuration manager is attempting to remove the previous configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4296: Job <JobId>: The local configuration manager did not find any previous configuration to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4297: Job <JobId>: The local configuration manager failed to remove the previous configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4298: Job <JobId>: The local configuration manager was able to successfully remove the previous configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4299: Job <JobId>: Could not wait for the stopping event.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4300: Job <JobId>: The local configuration manager is attempting to remove the current configuration.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4301: Job <JobId>: The local configuration manager is attempting to remove partial configurations.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4302: Job <JobId>: The local configuration manager was able to successfully remove partial configurations.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4303: Job <JobId>: The local configuration manager failed to remove partial configurations.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4304: Job <JobId>: The local configuration manager did not find any partial configurations to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4305: Job <JobId>: The DownloadManager <Name> is invalid.

#
Channel
Operational

Description

Job <JobId>: The DownloadManager <Name> is invalid. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error message is: <ErrorMessage>

Message #

Job <JobId>: The DownloadManager <Name> is invalid. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error message is: <ErrorMessage>

Fields #

NameDescription
JobId UnicodeString
Name UnicodeString
FullyQualifiedErrorId UnicodeString
ErrorMessage UnicodeString

Event ID 4306: Job <JobId>: The ReportManager <Name> is invalid.

#
Channel
Operational

Description

Job <JobId>: The ReportManager <Name> is invalid. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error message is: <ErrorMessage>

Message #

Job <JobId>: The ReportManager <Name> is invalid. FullyQualifiedErrorId is <FullyQualifiedErrorId>. Error message is: <ErrorMessage>

Fields #

NameDescription
JobId UnicodeString
Name UnicodeString
FullyQualifiedErrorId UnicodeString
ErrorMessage UnicodeString

Event ID 4307: The DscTimer is going to start the consistency timer for the first time with value ConsistencyTimerValue minutes.

#
Channel
Operational
Level
Informational

Message #

The DscTimer is going to start the consistency timer for the first time with value <ConsistencyTimerValue> minutes.

Fields #

NameDescription
ConsistencyTimerValue UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4307,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:29.2142403+00:00",
    "event_record_id": 7,
    "correlation": {
      "ActivityID": "{31A12504-2E43-42ED-89C4-F2768523D20E}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConsistencyTimerValue": "15"
  },
  "message": "The DscTimer is going to start the consistency timer for the first time with value 15 minutes."
}

Event ID 4308: The DscTimer is going to start the refresh timer for the first time with value RefreshTimerValue minutes.

#
Channel
Operational
Level
Informational

Message #

The DscTimer is going to start the refresh timer for the first time with value <RefreshTimerValue> minutes.

Fields #

NameDescription
RefreshTimerValue UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4308,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:29.2142548+00:00",
    "event_record_id": 9,
    "correlation": {
      "ActivityID": "{31A12504-2E43-42ED-89C4-F2768523D20E}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "RefreshTimerValue": "30"
  },
  "message": "The DscTimer is going to start the refresh timer for the first time with value 30 minutes."
}

Event ID 4309: The DScTimer is updating the consistency timer to the value ConsistencyTimerValue minutes.

#
Channel
Operational

Message #

The DScTimer is updating the consistency timer to the value <ConsistencyTimerValue> minutes.

Fields #

NameDescription
ConsistencyTimerValue UInt32

Event ID 4310: The DscTimer is updating the refresh timer to the value RefreshTimerValue minutes.

#
Channel
Operational

Message #

The DscTimer is updating the refresh timer to the value <RefreshTimerValue> minutes.

Fields #

NameDescription
RefreshTimerValue UInt32

Event ID 4311: The DscTimer is going to invoke the consistency check for task of type REBOOT.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4311,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.2045292+00:00",
    "event_record_id": 22,
    "correlation": {
      "ActivityID": "{EF441A92-7AB9-4844-8882-700D1A5FFEF3}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The DscTimer is going to invoke the consistency check for task of type REBOOT."
}

Event ID 4312: The DscTimer is running LCM method PerformRequiredConfigurationChecks with the flag set to flag.

#
Channel
Operational
Level
Informational

Message #

The DscTimer is running LCM method PerformRequiredConfigurationChecks with the flag set to <flag>.

Fields #

NameDescription
flag UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4312,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.2075977+00:00",
    "event_record_id": 23,
    "correlation": {
      "ActivityID": "{EF441A92-7AB9-4844-8882-700D1A5FFEF3}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "flag": "2"
  },
  "message": "The DscTimer is running LCM method PerformRequiredConfigurationChecks with the flag set to 2."
}

Event ID 4313: The DscTimer successfully created the consistency timer.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4313,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:29.2142508+00:00",
    "event_record_id": 8,
    "correlation": {
      "ActivityID": "{31A12504-2E43-42ED-89C4-F2768523D20E}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The DscTimer successfully created the consistency timer."
}

Event ID 4314: The DscTimer successfully created the refresh timer.

#
Channel
Operational
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4314,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:29.2142606+00:00",
    "event_record_id": 10,
    "correlation": {
      "ActivityID": "{31A12504-2E43-42ED-89C4-F2768523D20E}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The DscTimer successfully created the refresh timer."
}

Event ID 4315: Job <JobId>: The local configuration manager is attempting to remove the configuration checksum.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4316: Job <JobId>: The local configuration manager did not find configuration checksum to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4317: Job <JobId>: The local configuration manager failed to remove the configuration checksum.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4318: Job <JobId>: The local configuration manager was able to successfully remove the configuration checksum.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4319: Job <JobId>: The local configuration manager is updating the PSModulePath to <PSModulePath>.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString
PSModulePath UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4319,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:43:31.2565900+00:00",
    "event_record_id": 40,
    "correlation": {
      "ActivityID": "{D1FD61BC-C8F6-4EBD-9E0C-1264256DA64F}"
    },
    "execution": {
      "process_id": 6940,
      "thread_id": 3036
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{56B1180A-5BD1-11F1-9661-9BD2E82CF0EE}",
    "PSModulePath": "C:\\Program Files (x86)\\WindowsPowerShell\\Modules;C:\\Program Files\\WindowsPowerShell\\Modules;C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\Modules"
  },
  "message": "Job {56B1180A-5BD1-11F1-9661-9BD2E82CF0EE} : \r\nThe local configuration manager is updating the PSModulePath to C:\\Program Files (x86)\\WindowsPowerShell\\Modules;C:\\Program Files\\WindowsPowerShell\\Modules;C:\\Windows\\system32\\WindowsPowerShell\\v1.0\\Modules."
}

Event ID 4320: Job <JobId>: The local configuration manager could not read the system environment registry for PSModulePath.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4321: Job <JobId>: PsDscRunAsCredential has been specified.

#
Channel
Operational

Description

Job <JobId>: PsDscRunAsCredential has been specified. The user name is <UserName>.

Message #

Job <JobId>: PsDscRunAsCredential has been specified. The user name is <UserName>.

Fields #

NameDescription
JobId UnicodeString
UserName UnicodeString

Event ID 4322: Job <JobId>: Impersonation successful.

#
Channel
Operational

Description

Job <JobId>: Impersonation successful. Thread is running under the context of <UserName>.

Message #

Job <JobId>: Impersonation successful. Thread is running under the context of <UserName>.

Fields #

NameDescription
JobId UnicodeString
UserName UnicodeString

Event ID 4323: Job <JobId>: Impersonation reverted.

#
Channel
Operational

Description

Job <JobId>: Impersonation reverted. Thread is running under the context of <UserName>.

Message #

Job <JobId>: Impersonation reverted. Thread is running under the context of <UserName>.

Fields #

NameDescription
JobId UnicodeString
UserName UnicodeString

Event ID 4324: Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command with server url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4325: Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command using certificate id: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4326: Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, Http Client failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4327: Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, GET Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4328: Job <JobId>: WebDownloadManager for AgentId <param1> Do-DscAction command, GET call result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4329: Job <JobId>: Register-DscAgent command for AgentId <AgentId>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4332: Job <JobId>: Resource execution sequence:: <ResourceSequence>.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString
ResourceSequence UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4332,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.3958000+00:00",
    "event_record_id": 27,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-000B-28AF-FECEFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "ResourceSequence": "[File]EvtGenFile, [Registry]EvtGenReg"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : \r\n Resource execution sequence :: [File]EvtGenFile, [Registry]EvtGenReg."
}

Event ID 4333: Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>. AssignedConfigurationName is <AssignedConfigurationName>.

Message #

Job <JobId>: Attempting to get the configuration from pull server using Download Manager <DownloadManagerName>. AssignedConfigurationName is <AssignedConfigurationName>.

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString
AssignedConfigurationName UnicodeString

Event ID 4334: Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>. Agent Id is <AgentId>. Modules are <Modules>.

Message #

Job <JobId>: Attempting to get the modules from pull server using Download Manager <DownloadManagerName>. Agent Id is <AgentId>. Modules are <Modules>.

Fields #

NameDescription
JobId UnicodeString
DownloadManagerName UnicodeString
AgentId UnicodeString
Modules UnicodeString

Event ID 4335: Job <JobId>: Checksum Validation failed.

#
Channel
Operational

Description

Job <JobId>: Checksum Validation failed. Client computed checksum is <clientChecksum> and Checksum Sent from the server is <checkSumFromServer>.

Message #

Job <JobId>: Checksum Validation failed. Client computed checksum is <clientChecksum> and Checksum Sent from the server is <checkSumFromServer>.

Fields #

NameDescription
JobId UnicodeString
clientChecksum UnicodeString
checkSumFromServer UnicodeString

Event ID 4336: Job <JobId>: Server has returned a response of UpdateMetaConfiguration.

#
Channel
Operational

Description

Job <JobId>: Server has returned a response of UpdateMetaConfiguration. Please update the meta configuration on this node.

Message #

Job <JobId>: Server has returned a response of UpdateMetaConfiguration. Please update the meta configuration on this node.

Fields #

NameDescription
JobId UnicodeString

Event ID 4337: Job <JobId>: A ServerUrl was not located in the metaconfiguration for AgentId <AgentId>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4338: Job <JobId>: The current pull request-id is <requestId>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
requestId UnicodeString

Event ID 4339: Job <JobId>: The server response was Header: <header> and Content:<content>.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString
header UnicodeString
content UnicodeString

Event ID 4340: The DscTimer is going to start the timer to create task for sending pending report for the first time with value ReportingTimerValue minutes.

#
Channel
Operational

Message #

The DscTimer is going to start the timer to create task for sending pending report for the first time with value <ReportingTimerValue> minutes.

Fields #

NameDescription
ReportingTimerValue UInt32

Event ID 4341: The DScTimer is updating the timer to create task to send pending report to the value ConsistencyTimerValue minutes.

#
Channel
Operational

Message #

The DScTimer is updating the timer to create task to send pending report to the value <ConsistencyTimerValue> minutes.

Fields #

NameDescription
ConsistencyTimerValue UInt32

Event ID 4342: The DscTimer successfully created the timer to create task for sending pending report.

#
Channel
Operational

Event ID 4343: The DscTimer has successfully run LCM method PerformRequiredConfigurationChecks with flag flag.

#
Channel
Operational
Level
Informational

Message #

The DscTimer has successfully run LCM method PerformRequiredConfigurationChecks with flag <flag>.

Fields #

NameDescription
flag UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4343,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4834011+00:00",
    "event_record_id": 33,
    "correlation": {
      "ActivityID": "{EF441A92-7AB9-4844-8882-700D1A5FFEF3}"
    },
    "execution": {
      "process_id": 6660,
      "thread_id": 14044
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "flag": "2"
  },
  "message": "The DscTimer has successfully run LCM method PerformRequiredConfigurationChecks with flag 2."
}

Event ID 4344: The DscTimer is already performing operation with flag flag,ignoring new request.

#
Channel
Operational

Message #

The DscTimer is already performing operation with flag <flag>,ignoring new request.

Fields #

NameDescription
flag UInt32

Event ID 4345: The DSCStatusHistory.

#
Channel
Operational

Description

The DSCStatusHistory.mof is not found at path.

Message #

The DSCStatusHistory.mof is not found at <path>.

Fields #

NameDescription
path UnicodeString

Event ID 4346: The DSCConfigurationStatus mof file not found at path.

#
Channel
Operational

Message #

The DSCConfigurationStatus mof file not found at <path>.

Fields #

NameDescription
path UnicodeString

Event ID 4347: Deserializing mof path failed.

#
Channel
Operational

Message #

Deserializing mof <path> failed.

Fields #

NameDescription
path UnicodeString

Event ID 4348: Failed to process non-terminating error from resource 'resourceName'.

#
Channel
Operational

Message #

Failed to process non-terminating error from resource '<resourceName>'.

Fields #

NameDescription
resourceName UnicodeString

Event ID 4349: Job <JobId>: The local configuration manager is attempting to remove the configuration state cache.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4350: Job <JobId>: The local configuration manager did not find any configuration state cache file to remove.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4351: Job <JobId>: The local configuration manager failed to remove the configuration state cache file.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4352: Job <JobId>: The local configuration manager was able to successfully remove the configuration state cache file.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString

Event ID 4353: Job <JobId>: LCM has released the resource state cache.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4401: Job <JobId>: Attempting to register the Dsc agent with AgentId <AgentId> with the server <server> using Download Manager <DownloadManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
server UnicodeString
DownloadManagerName UnicodeString

Event ID 4402: Job <JobId>: Successfully registered the Dsc agent with AgentId <AgentId> with the server <server> using Download Manager <DownloadManagerName>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
server UnicodeString
DownloadManagerName UnicodeString

Event ID 4403: Job <JobId>: Registering Dsc Agent with Agent Id <AgentId>.

#
Channel
Operational

Description

Job <JobId>: Registering Dsc Agent with Agent Id <AgentId>. Register-DscAgent command, PUT Url: <put>.

Message #

Job <JobId>: Registering Dsc Agent with Agent Id <AgentId>. Register-DscAgent command, PUT Url: <put>.

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
put UnicodeString

Event ID 4404: Job <JobId>: Http Client <AgentId> failed to register Dsc Agent: <error>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
error UnicodeString

Event ID 4405: Job <JobId>: Register-DscAgent command for AgentId <AgentId> succeeded.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4406: Job <JobId>: Register-DscAgent command for AgentId <AgentId> using certificate id: <CertId>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
CertId UnicodeString

Event ID 4407: Job <JobId>: The Dsc Agent will generate a new AgentId.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4407,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:26.4687680+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "{603B392B-5B0C-4D93-A76B-EEADDD96B7E7}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 9864
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9839-5BCF-11F1-9661-9BD2E82CF0EE}"
  },
  "message": "Job {3C5F9839-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nThe Dsc Agent will generate a new AgentId."
}

Event ID 4408: Job <JobId>: Unable to write AgentId <AgentId> to registry.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4409: Job <JobId>: The Dsc Agent with AgentId <AgentId> has already been registered for the Server URL <Server>.

#
Channel
Operational

Description

Job <JobId>: The Dsc Agent with AgentId <AgentId> has already been registered for the Server URL <Server>. Registration will be skipped for this Server URL.

Message #

Job <JobId>: The Dsc Agent with AgentId <AgentId> has already been registered for the Server URL <Server>. Registration will be skipped for this Server URL.

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
Server UnicodeString

Event ID 4410: Job <JobId>: Using Version 1 protocol of Dsc PULL.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4411: Job <JobId>: Attempt to register the Dsc Agent AgentId <AgentId> with Server URL <Server> since RegistrationKey was specified.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
Server UnicodeString

Event ID 4412: Job <JobId>: The Dsc Agent with AgentId <AgentId> failed to create a self-signed certificate.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4413: Job <JobId>: The AgentId <AgentId> was written to the registry.

#
Channel
Operational
Level
Informational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4413,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:26.4692240+00:00",
    "event_record_id": 2,
    "correlation": {
      "ActivityID": "{603B392B-5B0C-4D93-A76B-EEADDD96B7E7}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 9864
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9839-5BCF-11F1-9661-9BD2E82CF0EE}",
    "AgentId": "3C5F983A-5BCF-11F1-9661-9BD2E82CF0EE"
  },
  "message": "Job {3C5F9839-5BCF-11F1-9661-9BD2E82CF0EE} : \r\nThe AgentId 3C5F983A-5BCF-11F1-9661-9BD2E82CF0EE was written to the registry."
}

Event ID 4501: Telemetry assembly assemblyName does not successfully load.

#
Channel
Operational

Description

Telemetry assembly assemblyName does not successfully load. Load exception message is: loadExceptionMessage.

Message #

Telemetry assembly <assemblyName> does not successfully load. Load exception message is: <loadExceptionMessage>

Fields #

NameDescription
assemblyName UnicodeString
loadExceptionMessage UnicodeString

Event ID 4502: Cannot get type typeName from loaded Dsc Telemetry assembly.

#
Channel
Operational

Message #

Cannot get type <typeName> from loaded Dsc Telemetry assembly.

Fields #

NameDescription
typeName UnicodeString

Event ID 4503: An error occured when initializing event source instance for Dsc Telemetry assembly.

#
Channel
Operational

Description

An error occured when initializing event source instance for Dsc Telemetry assembly. The exception is: exceptionMessage.

Message #

An error occured when initializing event source instance for Dsc Telemetry assembly. The exception is: <exceptionMessage>

Fields #

NameDescription
exceptionMessage UnicodeString

Event ID 4504: Job <JobId>: WebDownloadManager for configuration associated with AgentId <param1> Get-DscDocument command, File save result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4505: Job <JobId>: WebDownloadManager for configuration associated with AgentId <param1> Get-DscDocument command, Checksum validation failed: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4506: Job <JobId>: WebDownloadManager for configuration associated with AgentId <param1> Get-DscDocument command, GET Url: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4507: Job <JobId>: WebDownloadManager for configuration associated with AgentId <param1> Get-DscDocument command, GET call result: <param2>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
param1 UnicodeString
param2 UnicodeString

Event ID 4508: Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>.

#
Channel
Operational

Description

Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>. AgentId is <ConfigurationId>.

Message #

Job <JobId>: Attempting to send the status report using Report Manager <ReportManagerName>. AgentId is <ConfigurationId>.

Fields #

NameDescription
JobId UnicodeString
ReportManagerName UnicodeString
ConfigurationId UnicodeString

Event ID 4509: Job <JobId>: Updating PSModulePath with the current value from the registry failed.

#
Channel
Debug

Fields #

NameDescription
JobId UnicodeString

Event ID 4510: Job JobId : errorno error writing to job details log logName.

#
Channel
Operational

Message #

Job <JobId>: <errorno> error writing to job details log <logName>.

Fields #

NameDescription
JobId UnicodeString
errorno UInt32
logName UnicodeString

Event ID 4511: Job JobId : errorno error closing job details log logName.

#
Channel
Operational

Message #

Job <JobId>: <errorno> error closing job details log <logName>.

Fields #

NameDescription
JobId UnicodeString
errorno UInt32
logName UnicodeString

Event ID 4512: Job JobId : Details logging started to logName.

#
Channel
Operational
Level
Informational

Message #

Job <JobId>: Details logging started to <logName>.

Fields #

NameDescription
JobId UnicodeString
logName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4512,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.2132300+00:00",
    "event_record_id": 25,
    "correlation": {
      "ActivityID": "{DC261B5A-AEBD-41EB-ACFE-F2646C1474A8}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "logName": "C:\\Windows\\system32\\configuration\\ConfigurationStatus\\{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}-0.details.json"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : Details logging started to C:\\Windows\\system32\\configuration\\ConfigurationStatus\\{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}-0.details.json."
}

Event ID 4513: Job JobId : Details logging completed for logName.

#
Channel
Operational
Level
Informational

Message #

Job <JobId>: Details logging completed for <logName>.

Fields #

NameDescription
JobId UnicodeString
logName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-DSC",
    "guid": "{50DF9E12-A8C4-4939-B281-47E1325BA63E}",
    "event_source_name": "",
    "event_id": 4513,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-30T02:28:34.4794791+00:00",
    "event_record_id": 32,
    "correlation": {
      "ActivityID": "{CEFBC89A-D2FC-0007-6EE6-13CFFCD2DC01}"
    },
    "execution": {
      "process_id": 11004,
      "thread_id": 12916
    },
    "channel": "Microsoft-Windows-DSC/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "JobId": "{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}",
    "logName": "C:\\Windows\\system32\\configuration\\ConfigurationStatus\\{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}-0.details.json"
  },
  "message": "Job {3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE} : Details logging completed for C:\\Windows\\system32\\configuration\\ConfigurationStatus\\{3C5F9840-5BCF-11F1-9661-9BD2E82CF0EE}-0.details.json."
}

Event ID 4514: Validating the signer signature chain failed with the status 'signatureStatus'.

#
Channel
Operational

Description

Validating the signer signature chain failed with the status 'signatureStatus'. A certificate chain could not be built to a trusted root authority.

Message #

Validating the signer signature chain failed with the status '<signatureStatus>'. A certificate chain could not be built to a trusted root authority.

Fields #

NameDescription
signatureStatus UnicodeString

Event ID 4515: Failed to open trusted publisher store with the error 'message'.

#
Channel
Operational

Description

Failed to open trusted publisher store with the error 'message'. The store path is either invalid or does not exist.

Message #

Failed to open trusted publisher store with the error '<message>'. The store path is either invalid or does not exist.

Fields #

NameDescription
message UnicodeString

Event ID 4516: Failed to retrieve signing certificate information from the trusted publisher store with the error 'message'.

#
Channel
Operational

Message #

Failed to retrieve signing certificate information from the trusted publisher store with the error '<message>'.

Fields #

NameDescription
message UnicodeString

Event ID 4517: Failed to parse trusted publisher store path with the error 'message'.

#
Channel
Operational

Message #

Failed to parse trusted publisher store path with the error '<message>'.

Fields #

NameDescription
message UnicodeString

Event ID 4518: Trusted publisher store path is : 'storeInfo'.

#
Channel
Operational

Message #

Trusted publisher store path is: '<storeInfo>'.

Fields #

NameDescription
storeInfo UnicodeString

Event ID 4519: Signature validation was successful.

#
Channel
Operational

Description

Signature validation was successful. Signer certificate is valid and trusted.

Message #

Signature validation was successful. Signer certificate is valid and trusted.

Event ID 4520: Validating the signer signature trust failed.

#
Channel
Operational

Description

Validating the signer signature trust failed. The signer certificate did not match with any valid code signing certificate that is installed on the node.

Message #

Validating the signer signature trust failed. The signer certificate did not match with any valid code signing certificate that is installed on the node.

Event ID 4521: Validating the signer signature hash failed with the status 'signatureStatus'.

#
Channel
Operational

Description

Validating the signer signature hash failed with the status 'signatureStatus'. The content of the configuration document or module has been changed.

Message #

Validating the signer signature hash failed with the status '<signatureStatus>'. The content of the configuration document or module has been changed.

Fields #

NameDescription
signatureStatus UnicodeString

Event ID 4522: Validating the signer signature failed with the status 'signatureStatus'.

#
Channel
Operational

Message #

Validating the signer signature failed with the status '<signatureStatus>'.

Fields #

NameDescription
signatureStatus UnicodeString

Event ID 4523: Validating the signature of the configuration document failed.

#
Channel
Operational

Description

Validating the signature of the configuration document failed. The signature status on the document is 'signatureStatus'.

Message #

Validating the signature of the configuration document failed. The signature status on the document is '<signatureStatus>'.

Fields #

NameDescription
signatureStatus UnicodeString

Event ID 4524: Signature validation skipped becouse machine signature verification policy is set to 'currentMachinSignatureVerificationPolicy'.

#
Channel
Operational

Message #

Signature validation skipped becouse machine signature verification policy is set to '<currentMachinSignatureVerificationPolicy>'

Fields #

NameDescription
currentMachinSignatureVerificationPolicy UnicodeString

Event ID 4525: Extracting the downloaded zip file 'zipFileName' failed.

#
Channel
Operational

Message #

Extracting the downloaded zip file '<zipFileName>' failed.

Fields #

NameDescription
zipFileName UnicodeString

Event ID 4526: The downloaded zip file 'zipFileName' does not contain a catalog file.

#
Channel
Operational

Description

The downloaded zip file 'zipFileName' does not contain a catalog file. Ensure the catalog file for the module exist inside the module folder.

Message #

The downloaded zip file '<zipFileName>' does not contain a catalog file. Ensure the catalog file for the module exist inside the module folder.

Fields #

NameDescription
zipFileName UnicodeString

Event ID 4527: Catalog signature verification failed for the downloaded zip file 'zipFileName'.

#
Channel
Operational

Message #

Catalog signature verification failed for the downloaded zip file '<zipFileName>'.

Fields #

NameDescription
zipFileName UnicodeString

Event ID 4528: Comparing the module catalalog with current contents of the module succeeded for module 'moduleName'.

#
Channel
Operational

Message #

Comparing the module catalalog with current contents of the module succeeded for module '<moduleName>'.

Fields #

NameDescription
moduleName UnicodeString

Event ID 4529: Comparing the module catalalog file with current contents of the module failed for the downloaded zip file '<zipFileName>'.

#
Channel
Operational

Description

Comparing the module catalalog file with current contents of the module failed for the downloaded zip file '<zipFileName>'. Verify using 'Test-FileCatalog' cmdlet that contents of the module on the server has not changed after it is signed.

Message #

Comparing the module catalalog file with current contents of the module failed for the downloaded zip file '<zipFileName>'. Verify using 'Test-FileCatalog' cmdlet that contents of the module on the server has not changed after it is signed.

Fields #

NameDescription
zipFileName UnicodeString

Event ID 4530: The Local Configuration Manager could not find the partial configuration block that matches the server assigned configuration document 'assignedConfigName'.

#
Channel
Operational

Message #

The Local Configuration Manager could not find the partial configuration block that matches the server assigned configuration document '<assignedConfigName>'.

Fields #

NameDescription
assignedConfigName UnicodeString

Event ID 4531: The uncompressed file size of the downloaded zip file <zipFile>, exceeded the 'MaximumDownloadSizeMB' value of <limit> MB provided in the metaconfi...

#
Channel
Operational

Description

The uncompressed file size of the downloaded zip file <zipFile>, exceeded the 'MaximumDownloadSizeMB' value of <limit> MB provided in the metaconfiguration. Please increase this value in the metaconfiguration if you are expecting module size greater than the current limit.

Message #

The uncompressed file size of the downloaded zip file <zipFile>, exceeded the 'MaximumDownloadSizeMB' value of <limit> MB provided in the metaconfiguration. Please increase this value in the metaconfiguration if you are expecting module size greater than the current limit.

Fields #

NameDescription
zipFile UnicodeString
limit UInt32

Event ID 4601: Job <JobId>: Http Client <AgentId> failed to rotate Dsc Agent registration: <error>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
error UnicodeString

Event ID 4602: Job <JobId>: Rotating Dsc Agent registration with Agent Id <AgentId>.

#
Channel
Operational

Description

Job <JobId>: Rotating Dsc Agent registration with Agent Id <AgentId>. Rotate-DscAgent command, PUT Url: <put>.

Message #

Job <JobId>: Rotating Dsc Agent registration with Agent Id <AgentId>. Rotate-DscAgent command, PUT Url: <put>.

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
put UnicodeString

Event ID 4603: Job <JobId>: Http Client <AgentId> received an unknown rotate header with the value: <HeaderValue>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
HeaderValue UnicodeString

Event ID 4604: Job <JobId>: Rotate-DscAgent command for AgentId <AgentId> succeeded.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString

Event ID 4605: Job <JobId>: Rotate-DscAgent command for AgentId <AgentId> to certificate id: <CertId>.

#
Channel
Operational

Fields #

NameDescription
JobId UnicodeString
AgentId UnicodeString
CertId UnicodeString

Provenance

ETW provider GUID 50df9e12-a8c4-4939-b281-47e1325ba63e

Defined in DscCoreR.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB