Microsoft-Windows-EQoS
18 events across 2 channels
Event ID 1: PolicyType QoS policies successfully refreshed.
#Event ID 2: PolicyType QoS policies successfully refreshed.
#Event ID 4: The Advanced QoS Setting for inbound TCP throughput level successfully refreshed.
#Event ID 9: The Advanced QoS Setting for DSCP marking overrides successfully refreshed.
#Event ID 12: Selective application of legacy QoS policies based on domain or non-domain network category has been disabled on this machine.
#Description
Selective application of legacy QoS policies based on domain or non-domain network category has been disabled on this machine. QoS policies will be applied to all network interfaces.
Message #
Event ID 13: In the past Hours hour(s) and Minutes minute(s), Collisions HTTP.
#Event ID 100: There is at least one policy containing minimum bandwidth specification and at least one other policy that does not.
#Description
There is at least one policy containing minimum bandwidth specification and at least one other policy that does not. It is generally not a good idea to mix these two classes of policies on the same system.
Message #
Event ID 102: A PolicyType QoS policy "PolicyName" has an invalid version number.
#Event ID 104: A PolicyType QoS policy "PolicyName" does not specify a QoS parameter.
#Event ID 108: A PolicyType QoS policy "PolicyName" potentially conflicts with other QoS policies.
#Event ID 110: A PolicyType QoS policy "PolicyName" was ignored because the application path could not be processed.
#Description
A PolicyType QoS policy "PolicyName" was ignored because the application path could not be processed. The application path may be totally invalid, or has an invalid drive letter, or contains network-mapped drive letter.
Message #
Fields #
| Name | Description |
|---|---|
PolicyType UInt32 | |
PolicyName UnicodeString |
Event ID 200: PolicyType QoS policies failed to refresh.
#Event ID 204: A PolicyType QoS policy exceeds the maximum allowed name length.
#Event ID 206: A PolicyType QoS policy has a zero length name.
#Event ID 208: Failed to open the registry subkey for a PolicyType QoS policy.
#Event ID 210: Failed to read or validate the "PolicyFieldName" field for PolicyType QoS policy named "PolicyName".
#Event ID 212: Failed to read or set inbound TCP throughput level.
#Event ID 213: Failed to read or set the DSCP marking override setting.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 54cb22ff-26b4-4393-a8c2-6b0715912c5f
Defined in eqossnap.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02