Microsoft-Windows-EmbeddedAppLauncher

EventTitleChannelSampleRule
10001Failed to get the current process handle: {num2}.AdminNN
10002Failed to get process token: {num2}.AdminNN
10003Failed to get privilege ({str1}) luid: {num2}.AdminNN
10004Failed to set elevated privilege: {num2}.AdminNN
10005Failed to exit system ({num1}): {num2}.AdminNN
10006System exit successful ({num1}).AdminNN
10007CurrentProcess running in an elevated context: {str1}.AdminNN
10008Failed to get token information ({str1}) for current process: {num2}.AdminNN
10009Failed to get the current process tokenAdminNN
10010Failed to create ApplicationActivationManager {num2}.AdminNN
10011Failed to enable launcher to set foreground window: {num2}.AdminNN
10012Failed to activate application ({str1}): {num2}.AdminNN
10013Failed to get ApplicationActivationManager: {num2}.AdminNN
10014Failed to get opened application process ({num1}): {num2}.AdminNN
10015Failed to wait for application to exit: {num2}.AdminNN
10016Elevated context detected; calling Activation Manager surrogate server in …AdminNN
10017Key ({str1}) was not opened: {num2}.AdminNN
10018Key ({str1}\{str2}) was not opened: {num2}.AdminNN
10019Key ({str1}\{str2}) was longer than maximum allowed ({num1}): {num2}.AdminNN
10020Key ({str1}) was not opened for enumeration: {num2}.AdminNN
10021AppId was retrieved from registry: {str1}.AdminNN
10022Return code ({num1}) was mapped to action code ({num2}).AdminNN
10023Failed to retrieve application ({num1}) return code: {num2}.AdminNN
10024Failed to set process shutdown parameters: {num1}.AdminNN
10025Failed to create the launcher: {num1}.AdminNN
10026Launcher exit code: {num1}.AdminNN
10027GetExitCodeProcess for processs id {num1} failed with error code: {num2}.AdminNN
10028Unable to create HSTRING using WindowsCreateString API for processs id {num1}.AdminNN
10029Cannot get package family name for process id:{num1} error code: {num2}.AdminNN
10030Cannot get application data manager for the package family name {str1} .AdminNN
10031Process id {num1} exited with exit code {num2}.AdminNN
10032Process id {num1} exited with a custom exit code {num2}.AdminNN
10033Process id {num1} crashed.AdminNN
10034Return code string found in registry is invalid: {str1}.AdminNN
10035SID for account ({str1}) was not found: {num2}.AdminNN
10036Failed to get current user name: {num2}.AdminNN
10037Read settings for SID: {str1}.AdminNN
10038Read global settingsAdminNN
10039Failed to get SID (Group #: {num1}): {num2}.AdminNN
10040The current user is a member of Administrators.AdminNN
10041Failed to get Administrators SID: {num2}.AdminNN
10042Failed to check token membership ({str1}): {num2}.AdminNN
10043Default Strategy was retrieved from registry: {num2}.AdminNN
10044Skipping the Custom Exit Code Logic.AdminNN
10045Default Strategy found in registry ({num1}) was not valid: {num2}.AdminNN
10046Valid configuration not found in registry.AdminNN
10047Failed to register for session change messages: {num1}.AdminNN
10048Failed to prepare the foreground for application launch ({str1}): {num2}.AdminNN
10049Non-configured users cannot run the Embedded App Launcher.AdminNN
10050Settings were read from override (Application: {str1}; Default return code …AdminNN
10051App launcher is disabled.AdminNN
10052Failed to override appkey ({num1}) in registry ({str1}).AdminNN
10053Timed out waiting for ShellReadyEvent.AdminNN
10054Failed to wait for ShellReadyEvent: {num1}.AdminNN
10055Could not open ShellReadyEvent: {num1}.AdminNN
10056ShellReadyEvent in launcher succeeded.AdminNN
10057Session change notification window closed.AdminNN
10058Could not get the event that waits for the session change notification window to …AdminNN
10059Timed out waiting for session change notification window to close.AdminNN
10060Could not lock work station: {num1}.AdminNN
10061The current user isn't allowed for assigned access scenarios.AdminNN

Event ID 10001: Failed to get the current process handle: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10002: Failed to get process token: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10003: Failed to get privilege ({str1}) luid: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10004: Failed to set elevated privilege: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10005: Failed to exit system ({num1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10006: System exit successful ({num1}).

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10007: CurrentProcess running in an elevated context: {str1}.

#
Channel
Admin

Fields #

NameDescription
str1

Event ID 10008: Failed to get token information ({str1}) for current process: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10009: Failed to get the current process token

#
Channel
Admin

Event ID 10010: Failed to create ApplicationActivationManager {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10011: Failed to enable launcher to set foreground window: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10012: Failed to activate application ({str1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10013: Failed to get ApplicationActivationManager: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10014: Failed to get opened application process ({num1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10015: Failed to wait for application to exit: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10016: Elevated context detected; calling Activation Manager surrogate server in DllHost to launch the app from Medium-IL

#
Channel
Admin

Event ID 10017: Key ({str1}) was not opened: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10018: Key ({str1}\{str2}) was not opened: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
str2
num2

Event ID 10019: Key ({str1}\{str2}) was longer than maximum allowed ({num1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
str2
num1
num2

Event ID 10020: Key ({str1}) was not opened for enumeration: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10021: AppId was retrieved from registry: {str1}.

#
Channel
Admin

Fields #

NameDescription
str1

Event ID 10022: Return code ({num1}) was mapped to action code ({num2}).

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10023: Failed to retrieve application ({num1}) return code: {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10024: Failed to set process shutdown parameters: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10025: Failed to create the launcher: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10026: Launcher exit code: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10027: GetExitCodeProcess for processs id {num1} failed with error code: {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10028: Unable to create HSTRING using WindowsCreateString API for processs id {num1}.

#
Channel
Admin

Description

Unable to create HSTRING using WindowsCreateString API for processs id {num1}. API failed with error code: {num2}.

Message #

Unable to create HSTRING using WindowsCreateString API for processs id {num1}. API failed with error code: {num2}

Fields #

NameDescription
num1
num2

Event ID 10029: Cannot get package family name for process id:{num1} error code: {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10030: Cannot get application data manager for the package family name {str1} .

#
Channel
Admin

Description

Cannot get application data manager for the package family name {str1} . Process id:{num1} Error code: {num2}.

Message #

Cannot get application data manager for the package family name {str1} . Process id:{num1} Error code: {num2}

Fields #

NameDescription
str1
num1
num2

Event ID 10031: Process id {num1} exited with exit code {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10032: Process id {num1} exited with a custom exit code {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10033: Process id {num1} crashed.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10034: Return code string found in registry is invalid: {str1}.

#
Channel
Admin

Fields #

NameDescription
str1

Event ID 10035: SID for account ({str1}) was not found: {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10036: Failed to get current user name: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10037: Read settings for SID: {str1}.

#
Channel
Admin

Fields #

NameDescription
str1

Event ID 10038: Read global settings

#
Channel
Admin

Event ID 10039: Failed to get SID (Group #: {num1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10040: The current user is a member of Administrators.

#
Channel
Admin

Description

The current user is a member of Administrators. Exiting app launcher.

Message #

The current user is a member of Administrators.  Exiting app launcher.

Event ID 10041: Failed to get Administrators SID: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10042: Failed to check token membership ({str1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10043: Default Strategy was retrieved from registry: {num2}.

#
Channel
Admin

Fields #

NameDescription
num2

Event ID 10044: Skipping the Custom Exit Code Logic.

#
Channel
Admin

Description

Skipping the Custom Exit Code Logic. Cannot get package family name for Process id {num1}. API Return Code {num2}.

Message #

Skipping the Custom Exit Code Logic. Cannot get package family name for Process id {num1}. API Return Code {num2}.

Fields #

NameDescription
num1
num2

Event ID 10045: Default Strategy found in registry ({num1}) was not valid: {num2}.

#
Channel
Admin

Fields #

NameDescription
num1
num2

Event ID 10046: Valid configuration not found in registry.

#
Channel
Admin

Description

Valid configuration not found in registry. Check registry settings ({str1}) : {num2}.

Message #

Valid configuration not found in registry.  Check registry settings ({str1}) : {num2}

Fields #

NameDescription
str1
num2

Event ID 10047: Failed to register for session change messages: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10048: Failed to prepare the foreground for application launch ({str1}): {num2}.

#
Channel
Admin

Fields #

NameDescription
str1
num2

Event ID 10049: Non-configured users cannot run the Embedded App Launcher.

#
Channel
Admin

Event ID 10050: Settings were read from override (Application: {str1}; Default return code action {num1}).

#
Channel
Admin

Fields #

NameDescription
str1
num1

Event ID 10051: App launcher is disabled.

#
Channel
Admin

Event ID 10052: Failed to override appkey ({num1}) in registry ({str1}).

#
Channel
Admin

Fields #

NameDescription
num1
str1

Event ID 10053: Timed out waiting for ShellReadyEvent.

#
Channel
Admin

Event ID 10054: Failed to wait for ShellReadyEvent: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10055: Could not open ShellReadyEvent: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10056: ShellReadyEvent in launcher succeeded.

#
Channel
Admin

Event ID 10057: Session change notification window closed.

#
Channel
Admin

Event ID 10058: Could not get the event that waits for the session change notification window to close.

#
Channel
Admin

Event ID 10059: Timed out waiting for session change notification window to close.

#
Channel
Admin

Event ID 10060: Could not lock work station: {num1}.

#
Channel
Admin

Fields #

NameDescription
num1

Event ID 10061: The current user isn't allowed for assigned access scenarios.

#
Channel
Admin