Microsoft-Windows-EQoS

18 events across 2 channels

Event ID 1: PolicyType QoS policies successfully refreshed.

#
Provider
Microsoft-Windows-EQoS
Channel
Operational

Description

PolicyType QoS policies successfully refreshed. No changes detected.

Message #

%1 QoS policies successfully refreshed. No changes detected.

Fields #

NameDescription
PolicyType UInt32

Event ID 2: PolicyType QoS policies successfully refreshed.

#
Provider
Microsoft-Windows-EQoS
Channel
Operational

Description

PolicyType QoS policies successfully refreshed. Policy changes detected.

Message #

%1 QoS policies successfully refreshed. Policy changes detected.

Fields #

NameDescription
PolicyType UInt32

Event ID 4: The Advanced QoS Setting for inbound TCP throughput level successfully refreshed.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

The Advanced QoS Setting for inbound TCP throughput level successfully refreshed. Level.

Message #

The Advanced QoS Setting for inbound TCP throughput level successfully refreshed. %1

Fields #

NameDescription
Level HexInt32

Event ID 9: The Advanced QoS Setting for DSCP marking overrides successfully refreshed.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

The Advanced QoS Setting for DSCP marking overrides successfully refreshed. Setting.

Message #

The Advanced QoS Setting for DSCP marking overrides successfully refreshed. %1

Fields #

NameDescription
Setting HexInt32

Event ID 12: Selective application of legacy QoS policies based on domain or non-domain network category has been disabled on this machine.

#
Provider
Microsoft-Windows-EQoS
Channel
Operational

Description

Selective application of legacy QoS policies based on domain or non-domain network category has been disabled on this machine. QoS policies will be applied to all network interfaces.

Message #

Selective application of legacy QoS policies based on domain or non-domain network category has been disabled on this machine. QoS policies will be applied to all network interfaces.

Event ID 13: In the past Hours hour(s) and Minutes minute(s), Collisions HTTP.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

In the past Hours hour(s) and Minutes minute(s), Collisions HTTP.SYS responses have had their application requested QoS conflict with URL QoS policies.

Message #

In the past %1 hour(s) and %2 minute(s), %3 HTTP.SYS responses have had their application requested QoS conflict with URL QoS policies.

Fields #

NameDescription
Hours UInt32
Minutes UInt32
Collisions UInt32

Event ID 100: There is at least one policy containing minimum bandwidth specification and at least one other policy that does not.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

There is at least one policy containing minimum bandwidth specification and at least one other policy that does not. It is generally not a good idea to mix these two classes of policies on the same system.

Message #

There is at least one policy containing minimum bandwidth specification and at least one other policy that does not. It is generally not a good idea to mix these two classes of policies on the same system.

Event ID 102: A PolicyType QoS policy "PolicyName" has an invalid version number.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy "PolicyName" has an invalid version number. This policy will not be applied.

Message #

A %1 QoS policy "%2" has an invalid version number. This policy will not be applied.

Fields #

NameDescription
PolicyType UInt32
PolicyName UnicodeString

Event ID 104: A PolicyType QoS policy "PolicyName" does not specify a QoS parameter.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy "PolicyName" does not specify a QoS parameter (e.g. DSCP value, throttle rate, etc.) This policy will not be applied.

Message #

A %1 QoS policy "%2" does not specify a QoS parameter (e.g. DSCP value, throttle rate, etc.) This policy will not be applied.

Fields #

NameDescription
PolicyType UInt32
PolicyName UnicodeString

Event ID 108: A PolicyType QoS policy "PolicyName" potentially conflicts with other QoS policies.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy "PolicyName" potentially conflicts with other QoS policies. See documentation for rules about which policy will be applied at packet send time.

Message #

A %1 QoS policy "%2" potentially conflicts with other QoS policies. See documentation for rules about which policy will be applied at packet send time.

Fields #

NameDescription
PolicyType UInt32
PolicyName UnicodeString

Event ID 110: A PolicyType QoS policy "PolicyName" was ignored because the application path could not be processed.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy "PolicyName" was ignored because the application path could not be processed. The application path may be totally invalid, or has an invalid drive letter, or contains network-mapped drive letter.

Message #

A %1 QoS policy "%2" was ignored because the application path could not be processed. The application path may be totally invalid, or has an invalid drive letter, or contains network-mapped drive letter.

Fields #

NameDescription
PolicyType UInt32
PolicyName UnicodeString

Event ID 200: PolicyType QoS policies failed to refresh.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

PolicyType QoS policies failed to refresh. Error code: NtStatus.

Message #

%1 QoS policies failed to refresh. Error code: %2

Fields #

NameDescription
PolicyType UInt32
NtStatus UInt32

Event ID 204: A PolicyType QoS policy exceeds the maximum allowed name length.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy exceeds the maximum allowed name length. The offending policy is listed under the relevant policy root key with index Index.

Message #

A %1 QoS policy exceeds the maximum allowed name length. The offending policy is listed under the relevant policy root key with index %2.

Fields #

NameDescription
PolicyType UInt32
Index UInt32

Event ID 206: A PolicyType QoS policy has a zero length name.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

A PolicyType QoS policy has a zero length name. The offending policy is listed under the relevant policy root key with index Index.

Message #

A %1 QoS policy has a zero length name. The offending policy is listed under the relevant policy root key with index %2.

Fields #

NameDescription
PolicyType UInt32
Index UInt32

Event ID 208: Failed to open the registry subkey for a PolicyType QoS policy.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

Failed to open the registry subkey for a PolicyType QoS policy. The policy is listed under the relevant policy root key with index Index.

Message #

Failed to open the registry subkey for a %1 QoS policy. The policy is listed under the relevant policy root key with index %2.

Fields #

NameDescription
PolicyType UInt32
Index UInt32

Event ID 210: Failed to read or validate the "PolicyFieldName" field for PolicyType QoS policy named "PolicyName".

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

Failed to read or validate the "PolicyFieldName" field for PolicyType QoS policy named "PolicyName".

Message #

Failed to read or validate the "%2" field for %1 QoS policy named "%3".

Fields #

NameDescription
PolicyType UInt32
PolicyFieldName UnicodeString
PolicyName UnicodeString

Event ID 212: Failed to read or set inbound TCP throughput level.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

Failed to read or set inbound TCP throughput level. Error code: NtStatus.

Message #

Failed to read or set inbound TCP throughput level. Error code: %1

Fields #

NameDescription
NtStatus UInt32

Event ID 213: Failed to read or set the DSCP marking override setting.

#
Provider
Microsoft-Windows-EQoS
Channel
Analytic

Description

Failed to read or set the DSCP marking override setting. Error code: NtStatus.

Message #

Failed to read or set the DSCP marking override setting. Error code: %1

Fields #

NameDescription
NtStatus UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 54cb22ff-26b4-4393-a8c2-6b0715912c5f

Defined in eqossnap.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads