Microsoft-Windows-Host-Network-Service
Event ID 1000: HNS failed to create vmswitch with error 'Parameter0' and adapter id = 'Parameter1'.
#Message #
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-14T01:40:09.308665+00:00",
"event_record_id": 34,
"correlation": {},
"execution": {
"process_id": 2476,
"thread_id": 2776
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "0x800700b7",
"Parameter1": "C08CB7B8-9B3C-408E-8E30-5E16A3AEB444",
"Parameter2": "Default Switch"
},
"message": ""
}
Event ID 1000
#Description
HNS failed to create vmswitch with error 'Parameter0' and adapter id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "{0C885E0D-6EB6-476C-A048-2457EED3A5C1}",
"event_source_name": "",
"event_id": 1000,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-04-17T20:05:36.0464973+00:00",
"event_record_id": 261,
"correlation": {
"ActivityID": "{3C2340FB-4ED1-45DC-A89D-6438EE3C2BE7}"
},
"execution": {
"process_id": 3180,
"thread_id": 5852
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "0x800700b7",
"Parameter1": "C08CB7B8-9B3C-408E-8E30-5E16A3AEB444",
"Parameter2": "Default Switch"
},
"message": "HNS failed to create vmswitch with error '0x800700B7' and adapter id = 'C08CB7B8-9B3C-408E-8E30-5E16A3AEB444'."
}
Event ID 1001: HNS failed to delete vmswitch with error = 'Parameter0', id = 'Parameter1' and friendly name = 'Parameter2'.
#Event ID 1001
#Description
HNS failed to delete vmswitch with error = 'Parameter0', id = 'Parameter1' and friendly name = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1002: HNS failed to create intenal nic with error = 'Parameter0', id = 'Parameter1' and friendly name = 'Parameter2'.
#Event ID 1002
#Description
HNS failed to create intenal nic with error = 'Parameter0', id = 'Parameter1' and friendly name = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1003: HNS failed to delete internal nic with error = 'HResult' and id = 'Parameter1'.
#Event ID 1003
#Description
HNS failed to delete internal nic with error = 'HResult' and id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1004: HNS failed to create vmswitch port with error 'HResult', switch id = 'SwitchId', port id = 'PortId' and type = 'PortType'.
#Event ID 1004
#Description
HNS failed to create vmswitch port with error 'HResult', switch id = 'SwitchId', port id = 'PortId' and type = 'PortType'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
SwitchId GUID | |
PortId GUID | |
PortType UInt32 |
Event ID 1005: HNS failed to delete vmswitch port with error 'Parameter0', switch id = 'Parameter1' and port id = 'Parameter2'.
#Event ID 1005
#Description
HNS failed to delete vmswitch port with error 'Parameter0', switch id = 'Parameter1' and port id = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1006: HNS failed to connect vmswitch port with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and nic name = 'Parameter4'.
#Event ID 1006
#Description
HNS failed to connect vmswitch port with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and nic name = 'Parameter4'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Paramete3 UnicodeString | |
Parameter4 UnicodeString |
Event ID 1007: HNS failed to disconnect vmswitch port with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and nic name = 'Parameter4'.
#Event ID 1007
#Description
HNS failed to disconnect vmswitch port with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and nic name = 'Parameter4'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Paramete3 UnicodeString | |
Parameter4 UnicodeString |
Event ID 1008: HNS failed to bind external adapter to vswitch with error 'HResult' and adapter id = 'Parameter1'.
#Event ID 1008
#Description
HNS failed to bind external adapter to vswitch with error 'HResult' and adapter id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1009: HNS failed to unbind external adapter to vswitch with error 'HResult' and adapter id = 'Parameter1'.
#Event ID 1009
#Description
HNS failed to unbind external adapter to vswitch with error 'HResult' and adapter id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1010: HNS failed to set vmswitch extension with error 'HResult' on switch id = 'Parameter1'.
#Event ID 1010
#Description
HNS failed to set vmswitch extension with error 'HResult' on switch id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1011: HNS failed to set vmswitch port profile with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and profile id = 'Parameter4'.
#Event ID 1011
#Description
HNS failed to set vmswitch port profile with error 'Parameter0', switch id = 'Parameter1', port id = 'Paramete3' and profile id = 'Parameter4'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Paramete3 UnicodeString | |
Parameter4 UnicodeString |
Event ID 1012: HNS failed to set vmswitch port isolation with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2' and isolation id = 'Parameter3'.
#Event ID 1012
#Description
HNS failed to set vmswitch port isolation with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2' and isolation id = 'Parameter3'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1013: Parameter0 :- Network id = 'Parameter1'.
#Message #
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 UInt32 | |
Parameter3 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1013,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T22:13:59.744236+00:00",
"event_record_id": 28,
"correlation": {},
"execution": {
"process_id": 2364,
"thread_id": 10356
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "HNS-Layer-Create",
"Parameter1": "632711BF-FE3A-4CDE-94A3-B7D4B24574A6",
"Parameter2": 6,
"Parameter3": "0x80070057"
},
"message": ""
}
Event ID 1013
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 UInt32 | |
Parameter3 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "{0C885E0D-6EB6-476C-A048-2457EED3A5C1}",
"event_source_name": "",
"event_id": 1013,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": -9223372036854775808,
"time_created": "2026-04-17T20:05:36.0478828+00:00",
"event_record_id": 263,
"correlation": {
"ActivityID": "{3C2340FB-4ED1-45DC-A89D-6438EE3C2BE7}"
},
"execution": {
"process_id": 3180,
"thread_id": 5852
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "HNS-Network-Create",
"Parameter1": "{c08cb7b8-9b3c-408e-8e30-5e16a3aeb444}",
"Parameter2": "7",
"Parameter3": "0x800700b7"
},
"message": "HNS-Network-Create :- \r\n Network id = '{c08cb7b8-9b3c-408e-8e30-5e16a3aeb444}'.\r\n Network type = 'ICS'.\r\n Result code = '0x800700B7'. "
}
Event ID 1014: Parameter0 :- Network id = 'Parameter1'.
#Message #
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 UInt32 | |
Parameter3 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1014,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-11T06:32:02.402467+00:00",
"event_record_id": 3,
"correlation": {
"ActivityID": "B3C94439-5656-4D26-8052-20033A5181C5"
},
"execution": {
"process_id": 2820,
"thread_id": 6780
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "HNS-Network-Create",
"Parameter1": "B95D0C5E-57D4-412B-B571-18A81A16E005",
"Parameter2": 7,
"Parameter3": "0x0"
},
"message": ""
}
Event ID 1014
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 UInt32 | |
Parameter3 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"event_id": 1014,
"level": 4,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:32:25.0243826+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Host-Network-Service-Admin"
},
"event_data": {
"Parameter0": "HNS-Network-Create",
"Parameter2": "7",
"Parameter1": "{c08cb7b8-9b3c-408e-8e30-5e16a3aeb444}",
"Parameter3": "0x0"
}
}
Event ID 1015: Parameter0 :- Endpoint id = 'Parameter1'.
#Event ID 1015
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 GUID | |
Parameter3 UInt32 | |
Parameter4 HexInt32 |
Event ID 1016: Parameter0':- Endpoint id = 'Parameter1'.
#Message #
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 GUID | |
Parameter3 UInt32 | |
Parameter4 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1016,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-11T06:32:02.417112+00:00",
"event_record_id": 6,
"correlation": {
"ActivityID": "95388E16-C0CB-4191-9FDE-E7B11BC8D046"
},
"execution": {
"process_id": 2820,
"thread_id": 2384
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "HNS-Endpoint-Attach",
"Parameter1": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"Parameter2": "B95D0C5E-57D4-412B-B571-18A81A16E005",
"Parameter3": 7,
"Parameter4": "0x0"
},
"message": ""
}
Event ID 1016
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 GUID | |
Parameter3 UInt32 | |
Parameter4 HexInt32 |
Event ID 1017: HNS failed to configure hostagent traffic managment on vmswitch port with error 'Parameter0', port profile id = 'Paramete1', ip address = 'Paramete2' and isolation id = ...
#Description
HNS failed to configure hostagent traffic managment on vmswitch port with error 'Parameter0', port profile id = 'Paramete1', ip address = 'Paramete2' and isolation id = 'Parameter3'.
Message #
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1017
#Description
HNS failed to configure hostagent traffic managment on vmswitch port with error 'Parameter0', port profile id = 'Paramete1', ip address = 'Paramete2' and isolation id = 'Parameter3'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1018: HNS failed to reset hostagent traffic management on vmswitch port with error 'HResult' and port profile id = 'Parameter1'.
#Event ID 1018
#Description
HNS failed to reset hostagent traffic management on vmswitch port with error 'HResult' and port profile id = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1019: HNS failed to configure hostagent traffic managment on switch with error 'Parameter0', switch id = 'Parameter1', managment ip address = 'Parameter2' and forward all traffi...
#Description
HNS failed to configure hostagent traffic managment on switch with error 'Parameter0', switch id = 'Parameter1', managment ip address = 'Parameter2' and forward all traffic to external network = 'Parameter3'.
Message #
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 Boolean |
Event ID 1019
#Description
HNS failed to configure hostagent traffic managment on switch with error 'Parameter0', switch id = 'Parameter1', managment ip address = 'Parameter2' and forward all traffic to external network = 'Parameter3'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 Boolean |
Event ID 1020: HNS failed to add firewall rules for new container with error 'Parameter0' and unique error string "'Parameter1'".
#Event ID 1020
#Description
HNS failed to add firewall rules for new container with error 'Parameter0' and unique error string "'Parameter1'".
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UInt32 |
Event ID 1021: HNS failed to create winnat instance with error 'Parameter0', external ip prefix = 'Parameter1', internal ip prefix = 'Paramete3' and nat name = 'Parameter4'.
#Event ID 1021
#Description
HNS failed to create winnat instance with error 'Parameter0', external ip prefix = 'Parameter1', internal ip prefix = 'Paramete3' and nat name = 'Parameter4'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Paramete3 UnicodeString | |
Parameter4 UnicodeString |
Event ID 1022: HNS failed to delete winnat instance with error 'Parameter0', class name 'Parameter1' and instance id = 'Parameter2'.
#Event ID 1022
#Description
HNS failed to delete winnat instance with error 'Parameter0', class name 'Parameter1' and instance id = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1023: HNS failed to set interface configuration with error 'Parameter0'.
#Event ID 1023
#Description
HNS failed to set interface configuration with error 'Parameter0'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString | |
Parameter3 UnicodeString | |
Parameter4 Boolean | |
Parameter5 UInt32 |
Event ID 1024: HNS failed to configure ipv4 address with error 'Parameter0'.
#Event ID 1025: HNS failed to configure default route with error 'Parameter0'.
#Event ID 1025
#Description
HNS failed to configure default route with error 'Parameter0'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UInt32 | |
Parameter2 UInt32 | |
Parameter3 UnicodeString |
Event ID 1026: HNS failed to allocate nat port with error 'HResult'.
#Event ID 1026
#Description
HNS failed to allocate nat port with error 'HResult'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter0 UInt32 |
Event ID 1027: HNS failed to restore all configuration from its data file with error HResult.
#Event ID 1027
#Description
HNS failed to restore all configuration from its data file with error.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 |
Event ID 1028: HNS failed to set ethernet adapter MAC address with error = 'Parameter0', adapter guid = 'Parameter1' and MAC address = 'Parameter2'.
#Event ID 1028
#Description
HNS failed to set ethernet adapter MAC address with error = 'Parameter0', adapter guid = 'Parameter1' and MAC address = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1030: '.
#Message #
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
API UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1030,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-11T06:32:02.350163+00:00",
"event_record_id": 2,
"correlation": {
"ActivityID": "B3C94439-5656-4D26-8052-20033A5181C5"
},
"execution": {
"process_id": 2820,
"thread_id": 6780
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"HResult": "0x80070032",
"API": 1
},
"message": ""
}
Event ID 1030
#Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
API UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"event_id": 1030,
"level": 2,
"task": 0,
"opcode": 0,
"time_created": "2026-05-27T19:32:24.5797600+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Microsoft-Windows-Host-Network-Service-Admin"
},
"event_data": {
"API": "1",
"HResult": "0x80070032"
}
}
Event ID 1031: HNS failed to add encryption rules for new container with error 'Parameter0' and unique error string "'Parameter1'".
#Event ID 1031
#Description
HNS failed to add encryption rules for new container with error 'Parameter0' and unique error string "'Parameter1'".
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UInt32 |
Event ID 1033: HNS failed to get vmswitch info with error = 'HResult', switchid = 'Parameter1'.
#Event ID 1033
#Description
HNS failed to get vmswitch info with error = 'HResult', switchid = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1034: HNS failed to enumerate vmswitch ports with error = 'HResult', switchid = 'Parameter1'.
#Event ID 1034
#Description
HNS failed to enumerate vmswitch ports with error = 'HResult', switchid = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1035: HNS failed to get port handle count with error = 'HResult', portname = 'Parameter1'.
#Event ID 1035
#Description
HNS failed to get port handle count with error = 'HResult', portname = 'Parameter1'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
Parameter1 UnicodeString |
Event ID 1036: Mirrored Networking was requested.
#Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter2 UInt32 | |
Parameter3 HexInt32 |
Event ID 1037: HNS failed to update vmswitch port isolation with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2' and isolation id = 'Parameter3'.
#Event ID 1037
#Description
HNS failed to update vmswitch port isolation with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2' and isolation id = 'Parameter3'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1038: HNS failed to set vmswitch MAC spoofing with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2'.
#Event ID 1038
#Description
HNS failed to set vmswitch MAC spoofing with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1039: HNS failed to delete vmswitch port property with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2'.
#Event ID 1039
#Description
HNS failed to delete vmswitch port property with error 'Parameter0', switch id = 'Paramete1', port id = 'Paramete2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Paramete1 UnicodeString | |
Paramete2 UnicodeString | |
Parameter3 UInt64 |
Event ID 1040: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1041: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1042: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1043: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1044: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1045: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1046: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1047: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1048: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1049: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1050: Modified guest 'ResourceType' settings.
#Description
Modified guest 'ResourceType' settings. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1051: Failed to modify guest 'ResourceType' settings with error 'Result'.
#Description
Failed to modify guest 'ResourceType' settings with error 'Result'. Entity: 'EntityType', Id: 'EntityId', Operation: 'OperationType', Settings: 'Settings'.
Message #
Fields #
| Name | Description |
|---|---|
EntityType UInt32 | |
EntityId GUID | |
OperationType UInt32 | Known values
|
ResourceType UInt32 | |
Settings UnicodeString | |
Result HexInt32 |
Event ID 1052: Parameter0 :- GuestNetworkService id = 'Parameter1'.
#Event ID 1053: Parameter0 :- GuestNetworkService id = 'Parameter1'.
#Message #
Fields #
| Name | Description |
|---|---|
Parameter0 UnicodeString | |
Parameter1 GUID | |
Parameter3 HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1053,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-11T06:32:02.416617+00:00",
"event_record_id": 5,
"correlation": {
"ActivityID": "95388E16-C0CB-4191-9FDE-E7B11BC8D046"
},
"execution": {
"process_id": 2820,
"thread_id": 2384
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Parameter0": "HNS-GuestNetworkService-Create",
"Parameter1": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
"Parameter3": "0x0"
},
"message": ""
}
Event ID 1054: Guest Network Service state changed.
#Description
Guest Network Service state changed. Id: 'GnsId', State: 'GnsState'.
Message #
Fields #
| Name | Description |
|---|---|
GnsId GUID | |
GnsState UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1054,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:32:02.416768+00:00",
"event_record_id": 7,
"correlation": {
"ActivityID": "95388E16-C0CB-4191-9FDE-E7B11BC8D046"
},
"execution": {
"process_id": 2820,
"thread_id": 2384
},
"channel": "Microsoft-Windows-Host-Network-Service-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"GnsId": "29A7892D-8743-4A3F-85E3-06FE9D7977B4",
"GnsState": 3
},
"message": ""
}
Event ID 1055: RPC request received.
#Description
RPC request received. Type: 'Data_0', Entity: 'Request', Id: 'Entity', Access Level: 'RpcAccessLevel', Data: 'Id'.
Message #
Fields #
| Name | Description |
|---|---|
Request UnicodeString | |
Entity UnicodeString | |
Id GUID | |
Data UnicodeString | |
RpcAccessLevel UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1055,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-11T06:32:02.422796+00:00",
"event_record_id": 10,
"correlation": {
"ActivityID": "76236D51-D0B4-40EE-96C0-426CDBEB2766"
},
"execution": {
"process_id": 2820,
"thread_id": 10060
},
"channel": "Microsoft-Windows-Host-Network-Service-Operational",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Data_0": {
"ID": "ad2366c4-0be2-4636-8124-f3bddfd27e15",
"Name": "Ethernet",
"Version": 64424509440,
"Health": {
"Extra": {
"Resources": {
"AdditionalParams": {},
"AllocationOrder": 1,
"Allocators": [
{
"AdditionalParams": {},
"AllocationOrder": 0,
"Connected": false,
"EndpointId": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"EndpointPortGuid": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"Flags": 0,
"Health": {
"LastErrorCode": 0,
"LastUpdateTime": 134176843224049781
},
"ID": "14C2D8AC-D409-41E0-873B-AA38FB908377",
"IsPolicy": false,
"IsolationId": 0,
"MacAddress": "00-15-5D-CF-7E-0C",
"ManagementPort": false,
"NetworkId": "B95D0C5E-57D4-412B-B571-18A81A16E005",
"NicId": "29A7892D-8743-4A3F-85E3-06FE9D7977B4--AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"PortFriendlyNamePrefix": "Endpoint Port",
"PreferredPortFriendlyName": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"State": 3,
"SwitchId": "B95D0C5E-57D4-412B-B571-18A81A16E005",
"Tag": "VM Port",
"VmPort": true,
"nonPersistentPort": true
}
],
"CompartmentOperationTime": 0,
"Flags": 0,
"Health": {
"LastErrorCode": 0,
"LastUpdateTime": 134176843223894715
},
"ID": "958DB0CF-E213-4033-99A7-14D3ED54D19C",
"PortOperationTime": 0,
"State": 1,
"SwitchOperationTime": 0,
"VfpOperationTime": 0,
"parentId": "05D7D175-0BA4-482B-A21D-3968B8A854EC"
},
"SharedContainers": [],
"VirtualMachine": "29a7892d-8743-4a3f-85e3-06fe9d7977b4"
}
},
"SchemaVersion": {
"Major": 2,
"Minor": 0
},
"HostComputeNetwork": "b95d0c5e-57d4-412b-b571-18a81a16e005",
"IpConfigurations": [
{
"IpAddress": "172.18.253.78",
"PrefixLength": 20,
"IpSubnetId": "ad36f57c-b3cd-40da-bbd8-3fb22e0dbc19"
}
],
"Dns": {
"ServerList": [
"172.18.240.1"
]
},
"Routes": [
{
"NextHop": "172.18.240.1",
"DestinationPrefix": "0.0.0.0/0"
}
],
"MacAddress": "00-15-5D-CF-7E-0C"
},
"Request": "Query",
"Entity": "Endpoint",
"Id": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"RpcAccessLevel": 1
},
"message": ""
}
Example keys not documented in the fields table: Data_0
Event ID 1056: EventString :- Endpoint id = 'EndpointId'.
#Event ID 1056
#Fields #
| Name | Description |
|---|---|
EventString UnicodeString | |
EndpointId GUID | |
NetworkId GUID | |
PolicyType UInt32 | |
Result HexInt32 |
Event ID 1057: EventString :- Endpoint id = 'EndpointId'.
#Message #
Fields #
| Name | Description |
|---|---|
EventString UnicodeString | |
EndpointId GUID | |
NetworkId GUID | |
PolicyType UInt32 | |
Result HexInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "0C885E0D-6EB6-476C-A048-2457EED3A5C1",
"event_source_name": "",
"event_id": 1057,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-11T06:32:02.482204+00:00",
"event_record_id": 7,
"correlation": {
"ActivityID": "95388E16-C0CB-4191-9FDE-E7B11BC8D046"
},
"execution": {
"process_id": 2820,
"thread_id": 10064
},
"channel": "Microsoft-Windows-Host-Network-Service-Admin",
"computer": "LAB-WIN11",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"EventString": "HNS-Policy-Apply",
"EndpointId": "AD2366C4-0BE2-4636-8124-F3BDDFD27E15",
"NetworkId": "B95D0C5E-57D4-412B-B571-18A81A16E005",
"PolicyType": 3,
"Result": "0x0"
},
"message": ""
}
Event ID 1058
#Description
HNS failed to configure IOV offload on vmswitch port with error 'Parameter0', switch id = 'Parameter1', port id = 'Parameter2'.
Fields #
| Name | Description |
|---|---|
Parameter0 HexInt32 | |
Parameter1 UnicodeString | |
Parameter2 UnicodeString |
Event ID 1060: Action taken to remove orphaned component: 'Action' 'Name' ('Detail'), result='Result'.
#Event ID 1060
#Description
Action taken to remove orphaned component: 'Action' 'Name' ('Detail'), result='Result'.
Fields #
| Name | Description |
|---|---|
Action UnicodeString | |
Name UnicodeString | |
Detail UnicodeString | |
Result HexInt32 |
Event ID 1062: HNS failed to start a service or load a kernel driver.
#Event ID 1062
#Description
HNS failed to start a service or load a kernel driver. Name = 'ServiceOrDriverName' HResult = 'HResult'.
Fields #
| Name | Description |
|---|---|
HResult HexInt32 | |
ServiceOrDriverName UnicodeString |
Event ID entity: Entity
#Fields #
| Name | Description |
|---|---|
Json tlg:UnicodeString | |
Type tlg:UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "{0C885E0D-6EB6-476C-A048-2457EED3A5C1}",
"event_source_name": "",
"event_id": "entity",
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "",
"time_created": "2026-06-02T05:52:19.191+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 2412,
"thread_id": 8112
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"Json": {
"ActivityId": "1323CCF7-1496-4985-97B0-09053E23EC8B",
"AdditionalParams": {},
"Extensions": [
{
"Id": "E7C3B2F0-F3C5-48DF-AF2B-10FED6D72E7A",
"IsEnabled": false,
"Name": "Microsoft Windows Filtering Platform"
},
{
"Id": "430BDADD-BAB0-41AB-A369-94B67FA5BE0A",
"IsEnabled": true,
"Name": "Microsoft NDIS Capture"
}
],
"Flags": 0,
"Health": {
"LastErrorCode": 0,
"LastUpdateTime": 134243839434405480
},
"HostPortPresent": true,
"ID": "02FF6FD7-6AC3-408F-B550-7F2124335698",
"IsFSE": false,
"IsSDN": false,
"MacPools": [
{
"EndMacAddress": "00-15-5D-5C-7F-FF",
"StartMacAddress": "00-15-5D-5C-70-00"
}
],
"Name": "Default Switch",
"Policies": [],
"State": 0,
"SubType": "NAT",
"SupportsIpv6": false,
"Type": "Layered",
"Version": 68719476736
},
"Type": "Layered"
},
"message": "Entity"
}
Event ID on-rundown: OnRundown
#Fields #
| Name | Description |
|---|---|
"Begin Rundown" tlg:AnsiString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Host-Network-Service",
"guid": "{0C885E0D-6EB6-476C-A048-2457EED3A5C1}",
"event_source_name": "",
"event_id": "on-rundown",
"version": 0,
"level": 0,
"task": 0,
"opcode": 0,
"keywords": "",
"time_created": "2026-06-02T05:52:19.191+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 2412,
"thread_id": 8112
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"\"Begin Rundown\"": "Begin Rundown"
},
"message": "OnRundown"
}
Provenance
ETW provider GUID {0C885E0D-6EB6-476C-A048-2457EED3A5C1}
Defined in HostNetSvc.dll, which carries the event manifest.
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB