Microsoft-Windows-EventSystem
62 events across 2 channels
Event ID 4354: The COM+ Event System failed to fire the param2 method on event class param3 for publisher param4 and subscriber
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Event ID 4355: The COM+ Event System could not determine the name of the current user
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4356: The COM+ Event System failed to create an instance of the subscriber
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4357: The COM+ Event System could not fire an EventObjectChange event to subscription param2 because the query criteria string "param3" contained an error
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4358: The COM+ Event System could not fire an EventObjectChange event to subscription param2 because a bad HRESULT was detected during filtering
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4359: The type library "param2" specified in EventClass param3 ("param4") could not be loaded, or is not correct for this EventClass
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 4361: The COM+ Event System detected a corrupt IEventClass object
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4362: The COM+ Event System detected a corrupt IEventSubscription object
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4609: The COM+ Event System detected a bad return code during its internal processing
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4610: The COM+ Event System detected a bad return code during its internal processing
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4611: The COM+ Event System detected an unexpected null pointer during its internal processing, at line param2 of
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4612: The COM+ Event System ran out of memory during its internal processing, at line param2 of
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4613: The COM+ Event System detected an unexpected error from a Win32 API call at line param2 of
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4614: The COM+ Event System detected an inconsistency in its internal state
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4615: The COM+ Event System caught an exception param1 at address param2 within method param3 of interface
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4616: The COM+ Event System caught an access violation at address param1 within method param3 of interface
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4619: The COM+ Event System could not store the per-user subscription param2 because the registry key HKEY_USERS\param3 could not be opened
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4620: The COM+ Event System detected an error trying to query an param1 object because the criteria string "param2" contained an error
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 4621: The COM+ Event System could not remove the param2 object
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4622: The COM+ Event System could not marshal the subscriber for subscription
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4623: The COM+ Event System failed to create an instance of the MultiInterfacePublisherFilter param2 defined in event class
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 4624: The COM+ Event System could not apply the filter criteria to subscription param2 with display name "%6" because the criteria string "param3" contained an error
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of param1 seconds
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EventSystem",
"guid": "{899daace-4868-4295-afcd-9eb8fb497561}",
"event_source_name": "EventSystem",
"event_id": 4625,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-06T06:25:40.864290+00:00",
"event_record_id": 1434,
"correlation": {},
"execution": {
"process_id": 2696,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "86400",
"param2": "SuppressDuplicateDuration",
"param3": "Software\\Microsoft\\EventSystem\\EventLog"
},
"message": ""
}
Event ID 4625: The EventSystem sub system is suppressing duplicate event log entries for a duration of param1 seconds
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EventSystem",
"guid": "{899DAACE-4868-4295-AFCD-9EB8FB497561}",
"event_source_name": "",
"event_id": 4625,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-06-13T13:41:23.6511191+00:00",
"event_record_id": 619,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "telemetry-DC-d.cell-d.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "86400",
"param2": "SuppressDuplicateDuration",
"param3": "Software\\Microsoft\\EventSystem\\EventLog"
},
"message": "The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds. The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\\Software\\Microsoft\\EventSystem\\EventLog."
}
Event ID 4626: The COM+ Event System fired the param2 method on event class param3 for publisher param4 and subscriber param5 but the subscriber returned an error
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Event ID 4627: The COM+ Event System timed out attempting to fire the param2 method on event class param3 for publisher param4 and subscriber
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString |
Event ID 4628: The COM+ Event System service blocked the creation of a subscription to the event class with CLSID
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4629: The COM+ Event System did not fire the
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString |
Event ID 1073746449: The EventSystem sub system is suppressing duplicate event log entries for a duration of param1 seconds.
#Description
The EventSystem sub system is suppressing duplicate event log entries for a duration of param1 seconds. The suppression timeout can be controlled by a REG_DWORD value named param2 under the following registry key: HKLM\param3.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-EventSystem",
"event_id": 4625,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:31:58.0707833+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Application"
},
"event_data": {
"param2": "SuppressDuplicateDuration",
"param1": "86400",
"param3": "Software\\Microsoft\\EventSystem\\EventLog"
}
}
Event ID 1073746450: The COM+ Event System fired the param2 method on event class param3 for publisher param4 and subscriber param5 but the subscriber returned an error.
#Description
The COM+ Event System fired the param2 method on event class param3 for publisher param4 and subscriber param5 but the subscriber returned an error. The display name of the subscription is "param6". The subscriber returned HRESULT param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Event ID 2147488002: The COM+ Event System failed to fire the param2 method on event class param3 for publisher param4 and subscriber param5.
#Description
The COM+ Event System failed to fire the param2 method on event class param3 for publisher param4 and subscriber param5. The display name of the subscription is "param6". The HRESULT was param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString |
Event ID 2147488003: The COM+ Event System could not determine the name of the current user.
#Event ID 2147488004: The COM+ Event System failed to create an instance of the subscriber param2.
#Event ID 2147488005: The COM+ Event System could not fire an EventObjectChange event to subscription param2 because the query criteria string "param3" contained an error.
#Description
The COM+ Event System could not fire an EventObjectChange event to subscription param2 because the query criteria string "param3" contained an error. The approximate location of the error in the criteria string is at character index param4; the criteria sub-text at this location is "param5". The HRESULT was param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 2147488006: The COM+ Event System could not fire an EventObjectChange event to subscription param2 because a bad HRESULT was detected during filtering.
#Event ID 2147488007: The type library "param2" specified in EventClass param3 ("param4") could not be loaded, or is not correct for this EventClass.
#Event ID 2147488009: The COM+ Event System detected a corrupt IEventClass object.
#Event ID 2147488010: The COM+ Event System detected a corrupt IEventSubscription object.
#Event ID 2147488257: The COM+ Event System detected a bad return code during its internal processing.
#Description
The COM+ Event System detected a bad return code during its internal processing. HRESULT was param3 from line param2 of param1. This warning may be expected if the computer is low on resources. If the computer is not low on resources, and these warnings persist, it may indicate a problem in the COM+ Event System.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 2147488259: The COM+ Event System detected an unexpected null pointer during its internal processing, at line param2 of param1.
#Description
The COM+ Event System detected an unexpected null pointer during its internal processing, at line param2 of param1. This warning may be expected if the computer is low on resources. If the computer is not low on resources, and these warnings persist, it may indicate a problem in the COM+ Event System.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 2147488261: The COM+ Event System detected an unexpected error from a Win32 API call at line param2 of param1.
#Description
The COM+ Event System detected an unexpected error from a Win32 API call at line param2 of param1. A call to param3 failed with error code param5: "param4" This warning may be expected if the computer is low on resources. If the computer is not low on resources, and these warnings persist, it may indicate a problem in the COM+ Event System.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 2147488262: The COM+ Event System detected an inconsistency in its internal state.
#Description
The COM+ Event System detected an inconsistency in its internal state. The assertion "param3" failed at line param2 of param1. This warning may be expected if the computer is low on resources. If the computer is not low on resources, and these warnings persist, it may indicate a problem in the COM+ Event System.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 2147488275: The COM+ Event System timed out attempting to fire the param2 method on event class param3 for publisher param4 and subscriber param5.
#Description
The COM+ Event System timed out attempting to fire the param2 method on event class param3 for publisher param4 and subscriber param5. The subscriber failed to respond within param7 seconds. The display name of the subscription is "param6". The HRESULT was param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString |
Event ID 2147488276: The COM+ Event System service blocked the creation of a subscription to the event class with CLSID
#Event ID 2147488277: The COM+ Event System did not fire the
#Event ID 3221230081: The COM+ Event System detected a bad return code during its internal processing.
#Event ID 3221230082: The COM+ Event System detected a bad return code during its internal processing.
#Description
The COM+ Event System detected a bad return code during its internal processing. HRESULT was param3 from line param2 of param1. This may indicate that the COM+ Event System is not properly installed. Please try reinstalling the COM+ Event System.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 3221230083: The COM+ Event System detected an unexpected null pointer during its internal processing; at line {param2} of {param1}.
#Event ID 3221230084: The COM+ Event System ran out of memory during its internal processing, at line param2 of param1.
#Event ID 3221230085: The COM+ Event System detected an unexpected error from a Win32 API call at line {param2} of {param1}.
#Event ID 3221230086: The COM+ Event System detected an inconsistency in its internal state.
#Event ID 3221230087: The COM+ Event System caught an exception param1 at address param2 within method param3 of interface param4.
#Event ID 3221230088: The COM+ Event System caught an access violation at address param1 within method param3 of interface param4.
#Description
The COM+ Event System caught an access violation at address param1 within method param3 of interface param4. The method attempted to access address param2.param5.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Event ID 3221230089: The COM+ Event System raised an unexpected exception {param1} at address {param2}.
#Event ID 3221230090: The COM+ Event System raised an unexpected access violation at address {param1}; attempting to access address {param2}.
#Event ID 3221230091: The COM+ Event System could not store the per-user subscription param2 because the registry key HKEY_USERS\param3 could not be opened.
#Event ID 3221230092: The COM+ Event System detected an error trying to query an param1 object because the criteria string "param2" contained an error.
#Description
The COM+ Event System detected an error trying to query an param1 object because the criteria string "param2" contained an error. The approximate location of the error is at character index param3; the criteria sub-text at this location is "param4".
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 3221230093: The COM+ Event System could not remove the param2 object param3.
#Event ID 3221230094: The COM+ Event System could not marshal the subscriber for subscription param2.
#Event ID 3221230095: The COM+ Event System failed to create an instance of the MultiInterfacePublisherFilter param2 defined in event class param3.
#Event ID 3221230096: The COM+ Event System could not apply the filter criteria to subscription param2 with display name "%6" because the criteria string "param3" contained an e...
#Description
The COM+ Event System could not apply the filter criteria to subscription param2 with display name "%6" because the criteria string "param3" contained an error. The approximate location of the error is at character index param4; the criteria sub-text at this location is "param5". The HRESULT was param1.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 899daace-4868-4295-afcd-9eb8fb497561
Defined in comres.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02