Microsoft-Windows-FileManagerDataModel

EventTitleChannelSampleRule
1Error message: {UnicodeString}.OperationalNN
2Warning message: {UnicodeString}.OperationalNN
3Information message: {UnicodeString}.OperationalNN
4Information message: {UnicodeString}.OperationalNN
5Warning message: {UnicodeString}.OperationalNN
6Error message: {UnicodeString}.OperationalNN
7backtrace from {MethodName}; trace: {Backtrace}.OperationalNN
100RegisterEventHandlers threw {HresultValue}.OperationalNN
104Status while getting the user identity: {HresultValue}.OperationalNN
403Pause state changing: [.OperationalNN
404Pause state changed: {Boolean}.OperationalNN
405Internal Pause state changed: {Boolean}.OperationalNN
407ExecuteSyncPauseRequest status: {HresultValue}.OperationalNN
408Calling Sync Engine {Boolean}.OperationalNN
412Registering SyncEngine callback objectOperationalNN
414Setting selective sync options for rootFolderId=.OperationalNN
415Selective Sync option for ItemId = {ItemId}; state = {State}.OperationalNN
416Cleaning up SyncEngineManager requests list; {Integer} requests.OperationalNN
417EndSetSelectiveSync called; cookie:{Cookie}; result: {Result}.OperationalNN
418Couldn't start the SyncEngine; hr = {HresultValue}.OperationalNN
421BeginRefreshSync stopped: {HresultValue}.OperationalNN
426Sync Engine callback is no longer valid: {HresultValue}.OperationalNN
500FileSyncBlockedReason: {Integer}.OperationalNN
501FileSyncBlocked event fired: {HresultValue}.OperationalNN
503AuthenticationErrorEvent fired: [.OperationalNN
601Retrieve fast properties store.OperationalNN
711In StartGetRunningOperations; _pollingInProgress is {Boolean}.OperationalNN
712Enabling/Disabling toast notificiations: {Boolean}.OperationalNN
713Setting new polling frequency to {HresultValue}.OperationalNN
714Handling interrupt [.OperationalNN
900Location {UnicodeString} is a fastlocation; generating scope.OperationalNN
1004Terminating operation [.OperationalNN
1005Operations are destroyed on {Boolean}.OperationalNN
1006New polling rate: {Integer} milliseconds.OperationalNN
1009Processing {Integer} operations.OperationalNN
1010{Integer} operations were processed.OperationalNN
1100NetworkStatusChanged event received when EventsEnabled = {Boolean}.OperationalNN
1103Setting EventsEnabled: {Boolean}.OperationalNN
1200Sync status from indexer for {Path} is {Status}; hr = {HResult}.OperationalNN
1201Notify change for property {PropertyName} with override property …OperationalNN
1203Global SyncEngineStatus: GlobalErroState [.OperationalNN
1204Global SyncEngineStatus: GlobalErroState [.OperationalNN
1206Could not check whether item is marked for offline availability for {This}; …OperationalNN
1207Erasing entry for property {UnicodeString}.OperationalNN
1208Failed to retrieve IShellItem; hr = {HresultValue}.OperationalNN
1300Listening to shell change status: {Id}; on window id: {HResult}.OperationalNN
1301Stopped listening to shell change notifications; handler=.OperationalNN
1302Updating status to: {Integer}.OperationalNN
1303Stopping timer for window: {Integer}.OperationalNN
1306OnTileAvailabilityCheckTimerTick: Updating tile statusOperationalNN
1401Timer tick with refresh = [.OperationalNN
1402Firing SyncEngineStatus event: currentError: {CurrentError}; currentSyncStatu: …OperationalNN
1501HealthMonitor's GetSyncEngineStatus stopped {HresultValue}.OperationalNN
1503HealthMonitor's GetIndexerStatus stopped {HresultValue}.OperationalNN
1504HealthMonitor will start in {Integer} seconds.OperationalNN
1506HealthMonitor stopped: {HresultValue}.OperationalNN
1600PerformanceTimer::Start failed with hr=.OperationalNN
1601PerformanceTimer::GetDuration failed with hr=.OperationalNN

Event ID 1: Error message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 2: Warning message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 3: Information message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 4: Information message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 5: Warning message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 6: Error message: {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 7: backtrace from {MethodName}; trace: {Backtrace}.

#
Channel
Operational

Fields #

NameDescription
MethodName
Backtrace

Event ID 100: RegisterEventHandlers threw {HresultValue}.

#
Channel
Operational

Description

RegisterEventHandlers threw {HresultValue}. If E_ACCESSDENIED; a Guest account could be a readon of this failure.

Message #

RegisterEventHandlers threw {HresultValue}. If E_ACCESSDENIED; a Guest account could be a readon of this failure.

Fields #

NameDescription
HresultValue

Event ID 104: Status while getting the user identity: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 403: Pause state changing: [.

#
Channel
Operational

Description

Pause state changing: [{CurrentState}] => [{RequestedState}].

Message #

Pause state changing: [{CurrentState}] => [{RequestedState}]

Fields #

NameDescription
CurrentState
RequestedState

Event ID 404: Pause state changed: {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 405: Internal Pause state changed: {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 407: ExecuteSyncPauseRequest status: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 408: Calling Sync Engine {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 412: Registering SyncEngine callback object

#
Channel
Operational

Event ID 414: Setting selective sync options for rootFolderId=.

#
Channel
Operational

Description

Setting selective sync options for rootFolderId={UnicodeString}.

Message #

Setting selective sync options for rootFolderId={UnicodeString}

Fields #

NameDescription
UnicodeString

Event ID 415: Selective Sync option for ItemId = {ItemId}; state = {State}.

#
Channel
Operational

Fields #

NameDescription
ItemId
State

Event ID 416: Cleaning up SyncEngineManager requests list; {Integer} requests.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 417: EndSetSelectiveSync called; cookie:{Cookie}; result: {Result}.

#
Channel
Operational

Fields #

NameDescription
Cookie
Result

Event ID 418: Couldn't start the SyncEngine; hr = {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 421: BeginRefreshSync stopped: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 426: Sync Engine callback is no longer valid: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 500: FileSyncBlockedReason: {Integer}.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 501: FileSyncBlocked event fired: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 503: AuthenticationErrorEvent fired: [.

#
Channel
Operational

Description

AuthenticationErrorEvent fired: [{HresultValue}].

Message #

AuthenticationErrorEvent fired: [{HresultValue}]

Fields #

NameDescription
HresultValue

Event ID 601: Retrieve fast properties store.

#
Channel
Operational

Description

Retrieve fast properties store. Extrinsic property store could not be created; errorCode: {HresultValue}.

Message #

Retrieve fast properties store. Extrinsic property store could not be created; errorCode: {HresultValue}

Fields #

NameDescription
HresultValue

Event ID 711: In StartGetRunningOperations; _pollingInProgress is {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 712: Enabling/Disabling toast notificiations: {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 713: Setting new polling frequency to {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 714: Handling interrupt [.

#
Channel
Operational

Description

Handling interrupt [{Guid}].

Message #

Handling interrupt [{Guid}]

Fields #

NameDescription
Guid

Event ID 900: Location {UnicodeString} is a fastlocation; generating scope.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 1004: Terminating operation [.

#
Channel
Operational

Description

Terminating operation [{Guid}].

Message #

Terminating operation [{Guid}]

Fields #

NameDescription
Guid

Event ID 1005: Operations are destroyed on {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 1006: New polling rate: {Integer} milliseconds.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1009: Processing {Integer} operations.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1010: {Integer} operations were processed.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1100: NetworkStatusChanged event received when EventsEnabled = {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 1103: Setting EventsEnabled: {Boolean}.

#
Channel
Operational

Fields #

NameDescription
Boolean

Event ID 1200: Sync status from indexer for {Path} is {Status}; hr = {HResult}.

#
Channel
Operational

Fields #

NameDescription
Path
StatusNTSTATUS reference
HResult

Event ID 1201: Notify change for property {PropertyName} with override property {OverridePropertyName}.

#
Channel
Operational

Fields #

NameDescription
PropertyName
OverridePropertyName

Event ID 1203: Global SyncEngineStatus: GlobalErroState [.

#
Channel
Operational

Description

Global SyncEngineStatus: GlobalErroState [{GlobalError}] GlobalSyncState[{GlobalSyncState}].

Message #

Global SyncEngineStatus: GlobalErroState [{GlobalError}] GlobalSyncState[{GlobalSyncState}]

Fields #

NameDescription
GlobalError
GlobalSyncState

Event ID 1204: Global SyncEngineStatus: GlobalErroState [.

#
Channel
Operational

Description

Global SyncEngineStatus: GlobalErroState [{GlobalError}] GlobalSyncState[{GlobalSyncState}].

Message #

Global SyncEngineStatus: GlobalErroState [{GlobalError}] GlobalSyncState[{GlobalSyncState}]

Fields #

NameDescription
GlobalError
GlobalSyncState

Event ID 1206: Could not check whether item is marked for offline availability for {This}; result: [{HResult}].

#
Channel
Operational

Fields #

NameDescription
This
HResult

Event ID 1207: Erasing entry for property {UnicodeString}.

#
Channel
Operational

Fields #

NameDescription
UnicodeString

Event ID 1208: Failed to retrieve IShellItem; hr = {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 1300: Listening to shell change status: {Id}; on window id: {HResult}.

#
Channel
Operational

Fields #

NameDescription
Id
HResult

Event ID 1301: Stopped listening to shell change notifications; handler=.

#
Channel
Operational

Description

Stopped listening to shell change notifications; handler={Integer}.

Message #

Stopped listening to shell change notifications; handler={Integer}

Fields #

NameDescription
Integer

Event ID 1302: Updating status to: {Integer}.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1303: Stopping timer for window: {Integer}.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1306: OnTileAvailabilityCheckTimerTick: Updating tile status

#
Channel
Operational

Event ID 1401: Timer tick with refresh = [.

#
Channel
Operational

Description

Timer tick with refresh = [{UnicodeString}].

Message #

Timer tick with refresh = [{UnicodeString}]

Fields #

NameDescription
UnicodeString

Event ID 1402: Firing SyncEngineStatus event: currentError: {CurrentError}; currentSyncStatu: {CurrentSyncStatus}; currentTransferStatus: {CurrentSyncStatus}.

#
Channel
Operational

Fields #

NameDescription
CurrentError
CurrentSyncStatus

Event ID 1501: HealthMonitor's GetSyncEngineStatus stopped {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 1503: HealthMonitor's GetIndexerStatus stopped {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 1504: HealthMonitor will start in {Integer} seconds.

#
Channel
Operational

Fields #

NameDescription
Integer

Event ID 1506: HealthMonitor stopped: {HresultValue}.

#
Channel
Operational

Fields #

NameDescription
HresultValue

Event ID 1600: PerformanceTimer::Start failed with hr=.

#
Channel
Operational

Description

PerformanceTimer::Start failed with hr={HresultValue}.

Message #

PerformanceTimer::Start failed with hr={HresultValue}

Fields #

NameDescription
HresultValue

Event ID 1601: PerformanceTimer::GetDuration failed with hr=.

#
Channel
Operational

Description

PerformanceTimer::GetDuration failed with hr={HresultValue}.

Message #

PerformanceTimer::GetDuration failed with hr={HresultValue}

Fields #

NameDescription
HresultValue