Microsoft-Windows-HttpService

EventTitleChannelSampleRule
1Request received (request ID RequestId) on connection (connection ID …TraceYN
2Parsed request (request pointer RequestObj, method HttpVerb) with URI Url.TraceYN
3Delivered request to server application (request pointer RequestObj, request ID …TraceYN
4Server application passed response (request ID RequestId, connection ID …TraceYN
5Server application passed the last response (corresponding to request ID …TraceYN
6Server application passed entity body for request ID RequestId (connection ID …TraceNN
7Server application passed the last entity body for request ID RequestId.TraceNN
8Server application passed response (request ID RequestId, connection ID …TraceYN
9Server application passed the last response (corresponding to request ID …TraceYN
10Response ready for send (corresponding to request ID RequestId) with status code …TraceYN
11Cached the response (corresponding to request ID RequestId) with status code …TraceNN
12Queued last response (corresponding to request ID RequestId) for sending.TraceYN
13Response sent (corresponding to request ID RequestId) with status code …TraceNN
14Error occurred while sending the last response (corresponding to request ID …TraceNN
15Error Status occurred while sending (corresponding to request ID RequestId).TraceNN
16Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) …TraceNN
17Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) …TraceNN
18Attempted to reserve URL (Url).TraceNN
19Successfully read the IP listen list for IP address IpAddrLength.TraceNN
20SSL credentials for IP address and port CertHashLength successfully created.TraceNN
21New connection created (local IP address LocalAddr and remote address …TraceYN
22Connection ID (ConnectionId) assigned to connection and request (request ID …TraceYN
23Client closed the connection (connection pointer ConnectionObj).TraceNN
24Connection (connection pointer ConnectionObj) cleanup started due to either the …TraceYN
25Successfully added entry (URI Uri) to cache.TraceNN
26Failed to add an entry (URI UrlBuffer) to the cache.TraceNN
27Flushed entry (URI Uri) from the cache.TraceNN
28Attempted to set URL group property: Property.TraceYN
29Attempted to set server session property: Property.TraceNN
30Attempted to set request queue property: Property.TraceNN
31Attempted to add URL (Url) to URL group (UrlGroupId).TraceYN
32Removed URL (Url) from URL group (UrlGroupId).TraceYN
33Removed all URLs from URL group UrlGroupId.TraceNN
34Initiating SSL connection.TraceNN
35Initiating SSL handshake.TraceNN
36SSL handshake completed with status: Status.TraceNN
37Server application is attempting to receive the SSL client certificate, which …TraceNN
38Attempt by server application to receive client certificate failed with status: …TraceNN
39Raw SSL data is available for processing.TraceYN
40Decrypted SSL data is available for processing.TraceYN
41Passed plaintext data for encryption.TraceYN
43Attempt (on connection ID ConnectionId) to authenticate client completed.TraceNN
44Attempted to add entry to the AuthCacheType authentication cache.TraceNN
45Entry successfully removed from the authentication cache.TraceNN
46Successfully associated QoS flow with connection (connection ID ConnectionId).TraceNN
47Failed to configure the Type logging (directory Directory), Status: Status.TraceNN
48Successfully configured Type logging (directory Directory).TraceNN
49Failed to create Type log file Filename.TraceNN
50Successfully created new Type log file Filename.TraceNN
51Entry has been written to Type log file.TraceNN
52Parsing of request (request ID RequestId) failed due to reason: Reason.TraceNN
53HTTP timer Timer expired.TraceNN
56Failed to acquire handle for SSL credentials.TraceNN
57SSL connection will be disconnected as initiated by the client.TraceNN
58SSL connection will be disconnected as initiated by the server application.TraceNN
59Attempt to decrypt SSL data failed.TraceNN
60Query for SSL connection parameters failed.TraceNN
61Cannot find SSL endpoint for inbound connection for local IP address and port …TraceNN
62Attempt to perform SSL handshake failed.TraceNN
63Attempt to encrypt SSL data failed.TraceNN
64Request (request ID RequestId) rejected due to reason: Reason.TraceNN
65Server application canceled the processing of its request (request ID …TraceNN
66Http.TraceNN
67Hot-add information: Current UxNumberOfProcessors: …TraceNN
68Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth …TraceNN
69Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth …TraceNN
70QoS flow initialization failed: bandwidth Bandwidth, peak bandwidth …TraceNN
71Setting flow: Connection Connection, FlowHandle FlowHandle.TraceNN
72Assign to Configuration QoS Flow: FlowHandle FlowHandle.TraceNN
73[re]Setting QoS Flow failed: Connection Connection, FlowHandle FlowHandle, …TraceNN
74Response range processing done.TraceNN
75Begin building slices.TraceNN
76Send cached slices.TraceNN
77Cached slices match content.TraceNN
78Merge slices to cache.TraceNN
79Sending range from flat cache entry.TraceNN
80Channel bind ASC parameters: connection ConnectionId, buffers NoBindBuffers, …TraceNN
81Service bind check done.TraceNN
82Captured channel bind config.TraceNN
83Channel bind response config overwrites ReplaceConfigOf.TraceNN
84Policy-Based QoS: Connection Connection, FlowHandle FlowHandle.TraceNN
85Thread pool extension.TraceNN
86Thread ready.TraceNN
87Thread pool trim.TraceNN
88Thread gone.TraceNN
89SNI parsed for connection: ConnectionObj with status: Status.TraceNN
90Request RequestId has initated opaque mode.TraceNN
91Endpoint auto-generated for EndpointName.TraceNN
92Deleted auto-generated endpoint for EndpointName.TraceNN
93Inbound connection for IP: IpAddress, SNI: SniHostname.TraceNN
94SSL connection with local IP address and port Address rejected due to …TraceNN
95Parsing of response (response ID ResponseId) failed due to reason: Reason.TraceNN
96SSL handshake failed.SystemNN
97HTTP error response sent.SystemNN
98SSL renegotiate timed out.SystemNN
99HTTP 11 Required.SystemNN
100Version: Version Counts: Counts.SystemNN
101Version: Version Counts: Counts.SystemNN
105QUIC Connection.TraceNN
106QUIC Connection Callback.TraceNN
107QUIC Stream.TraceNN
108QUIC Stream Callback.TraceNN
109QUIC Registration Failed.SystemNN
110Correlation ID for request RequestId: CorrelationId.TraceYN
111Create URL group UrlGroupId.SystemYN
112Attempted to reserve URL Url.SystemYN
113Attempted to add URL (Url) to URL group (UrlGroupId).SystemYN
114Removed URL (Url) from URL group (UrlGroupId).SystemYN
115Removed all URLs from URL group UrlGroupId.SystemNN
116Attempted to set URL group UrlGroupId property Property.TraceYN
117Delete URL group UrlGroupId.SystemYN
118Status Status.SystemNN
119SSL Certificate Settings deleted for endpoint : Endpoint.SystemYN
120SSL Certificate Settings created by an admin process for endpoint : Endpoint.SystemYN
121SSL Certificate Settings updated by an admin process for endpoint : Endpoint, …SystemNN
122Set the IP address to the listen only list IpList.SystemNN
123QUIC certificate load failed with status Status and was ignored due to disabled …SystemNN
124Request (request ID RequestId) rejected due to request queue overflow.TraceNN
125Connection Connection, Connection Id ConnectionId: Stream Created, StreamId …TraceNN
126Connection Connection, Connection Id ConnectionId: Stream Aborted, StreamId …TraceNN
127Connection Connection, Connection Id ConnectionId: Send StreamId StreamId, …TraceNN
128Connection Connection, Connection Id ConnectionId: Data Indincation, StreamId …TraceNN
129Connection Connection, Connection Id ConnectionId: Header Indincation, StreamId …TraceNN
130Connection Connection, Connection Id ConnectionId: Go Away, StreamId StreamId, …TraceNN
131Http2 fault.TraceNN
132Connection Connection, Connection Id ConnectionId: Create.TraceNN
133Connection Connection, Connection Id ConnectionId: Detach.TraceNN
134task_0OperationalYN
135task_0135OperationalYN
136task_0136OperationalYN
137Query for SSL connection cipher info failedOperational, TraceNN

Event ID 1: Request received (request ID RequestId) on connection (connection ID ConnectionId) from remote address RemoteAddr.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
RecvReq

Message #

Request received (request ID %1) on connection (connection ID %2) from remote address %4.

Fields #

NameDescription
RequestId UInt64
ConnectionId UInt64
RemoteAddrLength UInt32
RemoteAddr Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 11,
    "keywords": "0x0000000000000102",
    "time_created": "2026-06-02T05:24:39.889+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{877F78A1-F053-0006-6514-818753F0DC01}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 7864
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionId": 18230571322465845394,
    "RemoteAddr": "02008900C00002FE0000000000000000",
    "RemoteAddrLength": 16,
    "RequestId": 18230571322734281270
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 2: Parsed request (request pointer RequestObj, method HttpVerb) with URI Url.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
Parse

Message #

Parsed request (request pointer %1, method %2) with URI %3.

Fields #

NameDescription
RequestObj Pointer
HttpVerb UInt32
Url UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 12,
    "keywords": "0x0000000000000002",
    "time_created": "2026-06-02T05:24:39.889+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{40000236-0007-FD00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 7864
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HttpVerb": 6,
    "RequestObj": "0xFFFF878DC1B4B0D0",
    "Url": "http://10.2.10.11:5985/wsman"
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 3: Delivered request to server application (request pointer RequestObj, request ID RequestId, site ID SiteId) from request queue RequestQueueName for URI Url with status Status.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
Deliver

Message #

Delivered request to server application (request pointer %1, request ID %2, site ID %3) from request queue %4 for URI %5 with status %6.

Fields #

NameDescription
RequestObj Pointer
RequestId UInt64
SiteId UInt32
RequestQueueName UnicodeString
Url UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 13,
    "keywords": "0x0000000000000102",
    "time_created": "2026-06-02T05:24:39.889+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{40000236-0007-FD00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 7864
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "RequestId": 18230571322734281270,
    "RequestObj": "0xFFFF878DC1B4B0D0",
    "RequestQueueName": "<<unnamed>>",
    "SiteId": 0,
    "Status": 0,
    "Url": "http://10.2.10.11:5985/wsman"
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 4: Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) wi...

#
Channel
Trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
RecvResp

Description

Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) with status code StatusCode.

Message #

Server application passed response (request ID %1, connection ID %2, method %4, header length %5, number of entity chunks %6, cache policy %7) with status code %3.

Fields #

NameDescription
RequestId UInt64
ConnectionId UInt64
StatusCode UInt16NTSTATUS reference
Verb AnsiString
HeaderLength UInt32
EntityChunkCount UInt16
CachePolicy UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 4,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 7400,
      "thread_id": 12520
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 14,
    "provider": "Microsoft-Windows-HttpService",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:09:43.728Z",
    "version": 0
  },
  "event_data": {
    "CachePolicy": 0,
    "ConnectionId": 18374686519131639270,
    "EntityChunkCount": 1,
    "HeaderLength": 96,
    "RequestId": 18374686519400076832,
    "StatusCode": 200,
    "Verb": "POST"
  },
  "message": ""
}

Event ID 5: Server application passed the last response (corresponding to request ID RequestId).

#
Channel
Trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
RecvRespLast

Message #

Server application passed the last response (corresponding to request ID %1).

Fields #

NameDescription
RequestId UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 5,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 15,
    "keywords": "0x8000000000000006",
    "time_created": "2026-07-19T03:39:42.964394700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "4000010F-0007-FF00-B63F-84710C7967BB"
    },
    "execution": {
      "process_id": 7308,
      "thread_id": 13268
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "RequestId": "0xFF0000074000010F"
  },
  "message": "Server application passed the last response (corresponding to request ID 0xFF0000074000010F)."
}

Event ID 6: Server application passed entity body for request ID RequestId (connection ID ConnectionId).

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
RecvBody

Message #

Server application passed entity body for request ID %1 (connection ID %2).

Fields #

NameDescription
RequestId UInt64
ConnectionId UInt64

Event ID 7: Server application passed the last entity body for request ID RequestId.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
RecvBodyLast

Message #

Server application passed the last entity body for request ID %1.

Fields #

NameDescription
RequestId UInt64

Event ID 8: Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) wi...

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
FastResp

Description

Server application passed response (request ID RequestId, connection ID ConnectionId, method Verb, header length HeaderLength, number of entity chunks EntityChunkCount, cache policy CachePolicy) with status code StatusCode.

Message #

Server application passed response (request ID %1, connection ID %2, method %4, header length %5, number of entity chunks %6, cache policy %7) with status code %3.

Fields #

NameDescription
RequestId UInt64
ConnectionId UInt64
StatusCode UInt16NTSTATUS reference
Verb AnsiString
HeaderLength UInt32
EntityChunkCount UInt16
CachePolicy UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 19,
    "keywords": "0x0000000000000006",
    "time_created": "2026-06-02T05:24:39.884+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{40000235-0007-FD00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 16560
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CachePolicy": 0,
    "ConnectionId": 18230571322465845394,
    "EntityChunkCount": 1,
    "HeaderLength": 0,
    "RequestId": 18230571322734281269,
    "StatusCode": 200,
    "Verb": "POST"
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 9: Server application passed the last response (corresponding to request ID RequestId).

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
FastRespLast

Message #

Server application passed the last response (corresponding to request ID %1).

Fields #

NameDescription
RequestId UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 9,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 18,
    "keywords": "0x0000000000000006",
    "time_created": "2026-06-02T05:24:39.884+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{40000235-0007-FD00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 16560
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "RequestId": 18230571322734281269
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 10: Response ready for send (corresponding to request ID RequestId) with status code HttpStatus.

#
Channel
Trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
SendComplete

Message #

Response ready for send (corresponding to request ID %1) with status code %2.

Fields #

NameDescription
RequestId UInt64
HttpStatus UInt16

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 10,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 7400,
      "thread_id": 12520
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 51,
    "provider": "Microsoft-Windows-HttpService",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 08:09:43.728Z",
    "version": 0
  },
  "event_data": {
    "HttpStatus": 200,
    "RequestId": 18374686519400076832
  },
  "message": ""
}

Event ID 11: Cached the response (corresponding to request ID RequestId) with status code HttpStatus.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
CachedAndSend

Description

Cached the response (corresponding to request ID RequestId) with status code HttpStatus. Response to be sent.

Message #

Cached the response (corresponding to request ID %1) with status code %2. Response to be sent.

Fields #

NameDescription
RequestId UInt64
HttpStatus UInt16

Event ID 12: Queued last response (corresponding to request ID RequestId) for sending.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
FastSend

Description

Queued last response (corresponding to request ID RequestId) for sending. Status code is HttpStatus.

Message #

Queued last response (corresponding to request ID %1) for sending. Status code is %2.

Fields #

NameDescription
RequestId UInt64
HttpStatus UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 12,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 21,
    "keywords": "0x0000000000000006",
    "time_created": "2026-06-02T05:24:39.884+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{40000235-0007-FD00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4672,
      "thread_id": 16560
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HttpStatus": 200,
    "RequestId": 18230571322734281269
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 13: Response sent (corresponding to request ID RequestId) with status code HttpStatus.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
ZeroSend

Description

Response sent (corresponding to request ID RequestId) with status code HttpStatus. If disconnect is required, a TCP FIN has been sent.

Message #

Response sent (corresponding to request ID %1) with status code %2. If disconnect is required, a TCP FIN has been sent.

Fields #

NameDescription
RequestId UInt64
HttpStatus UInt16

Event ID 14: Error occurred while sending the last response (corresponding to request ID RequestId) with status code HttpStatus.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
LastSndError

Description

Error occurred while sending the last response (corresponding to request ID RequestId) with status code HttpStatus. A TCP Reset has been sent.

Message #

Error occurred while sending the last response (corresponding to request ID %1) with status code %2. A TCP Reset has been sent.

Fields #

NameDescription
RequestId UInt64
HttpStatus UInt16

Event ID 15: Error Status occurred while sending (corresponding to request ID RequestId).

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
SndError

Description

Error Status occurred while sending (corresponding to request ID RequestId). A TCP Reset will be sent.

Message #

Error %3 occurred while sending (corresponding to request ID %1). A TCP Reset will be sent.

Fields #

NameDescription
RequestId UInt64
Reason AnsiString
Status UInt32NTSTATUS reference

Event ID 16: Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) queued for sending from the cache.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
SrvdFrmCache

Message #

Response (request pointer %1, site ID %2, number of bytes %3) queued for sending from the cache.

Fields #

NameDescription
RequestObj Pointer
SiteId UInt32
BytesSent UInt32
RequestId UInt64
Encoding AnsiString

Event ID 17: Response (request pointer RequestObj, site ID SiteId, number of bytes BytesSent) queued for sending with status code 304 (cache not modified).

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
CachedNotModified

Message #

Response (request pointer %1, site ID %2, number of bytes %3) queued for sending with status code 304 (cache not modified).

Fields #

NameDescription
RequestObj Pointer
SiteId UInt32
BytesSent UInt32
RequestId UInt64
Encoding AnsiString

Event ID 18: Attempted to reserve URL (Url).

#
Channel
Trace
Task
HTTPSetupTraceTask
Opcode
ResvUrl

Description

Attempted to reserve URL (Url). Status ReserveStatus.

Message #

Attempted to reserve URL (%1). Status %2.

Fields #

NameDescription
Url UnicodeString
ReserveStatus UInt32

Event ID 19: Successfully read the IP listen list for IP address IpAddrLength.

#
Channel
Trace
Task
HTTPSetupTraceTask
Opcode
ReadIpListEntry

Message #

Successfully read the IP listen list for IP address %1.

Fields #

NameDescription
IpAddrLength UInt32
IpAddress Binary

Event ID 20: SSL credentials for IP address and port CertHashLength successfully created.

#
Channel
Trace
Task
HTTPSetupTraceTask
Opcode
CreatedSslCred

Message #

SSL credentials for IP address and port %3 successfully created.

Fields #

NameDescription
EndpointConfigObj Pointer
Endpoint UnicodeString
CertHashLength UInt32
CertHash Binary
CertStoreName UnicodeString
CertCheckMode UInt32
RevokeFreshnessTime UInt32
RevokeRetrievalTime UInt32
Flags UInt32
CtlId UnicodeString
CtlStoreName UnicodeString
CertificateLoadTimems UInt32

Event ID 21: New connection created (local IP address LocalAddr and remote address RemoteAddr).

#
Channel
Trace
Level
Informational
Task
HTTPConnectionTraceTask
Opcode
ConnConnect

Message #

New connection created (local IP address %3 and remote address %5).

Fields #

NameDescription
ConnectionObj Pointer
LocalAddrLength UInt32
LocalAddr Binary
RemoteAddrLength UInt32
RemoteAddr Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 21,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 28,
    "keywords": "0x8000000000000010",
    "time_created": "2026-07-19T03:39:42.410446000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0007-011C-4DBFF10BDD01"
    },
    "execution": {
      "process_id": 8676,
      "thread_id": 8016
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionObj": "0xFFFF800A058E6670",
    "LocalAddrLength": "16",
    "LocalAddr": "127.0.0.1:18083",
    "RemoteAddrLength": "16",
    "RemoteAddr": "127.0.0.1:57018"
  },
  "message": "New connection created (local IP address 127.0.0.1:18083 and remote address 127.0.0.1:57018)."
}

Event ID 22: Connection ID (ConnectionId) assigned to connection and request (request ID RequestId) will be parsed.

#
Channel
Trace
Level
Informational
Task
HTTPConnectionTraceTask
Opcode
ConnIdAssgn

Message #

Connection ID (%2) assigned to connection and request (request ID %1) will be parsed.

Fields #

NameDescription
RequestId UInt64
ConnectionId UInt64
ConnectionObj Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 22,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 55,
    "keywords": "0x8000000000000012",
    "time_created": "2026-07-19T03:39:42.412102300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0007-011C-4DBFF10BDD01"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 4488
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "RequestId": "0xFF00000240000101",
    "ConnectionId": "0xFF00000230000100",
    "ConnectionObj": "0xFFFF800A0EAA9B20"
  },
  "message": "Connection ID (0xFF00000230000100) assigned to connection and request (request ID 0xFF00000240000101) will be parsed."
}

Event ID 23: Client closed the connection (connection pointer ConnectionObj).

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
ConnClose

Description

Client closed the connection (connection pointer ConnectionObj). Status of whether closed by TCP Reset: Abortive.

Message #

Client closed the connection (connection pointer %1). Status of whether closed by TCP Reset: %2.

Fields #

NameDescription
ConnectionObj Pointer
Abortive UInt32

Event ID 24: Connection (connection pointer ConnectionObj) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange...

#
Channel
Trace
Level
Informational
Task
HTTPConnectionTraceTask
Opcode
ConnCleanup

Description

Connection (connection pointer ConnectionObj) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange of TCP Fins.

Message #

Connection (connection pointer %1) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange of TCP Fins.

Fields #

NameDescription
ConnectionObj Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 24,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 30,
    "keywords": "0x8000000000000010",
    "time_created": "2026-07-19T03:39:42.454680800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "BF440000-0BF1-0007-011C-4DBFF10BDD01"
    },
    "execution": {
      "process_id": 13436,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionObj": "0xFFFF800A058E6670"
  },
  "message": "Connection (connection pointer 0xFFFF800A058E6670) cleanup started due to either the sending of a TCP Reset, receiving of a TCP Reset, or after the mutual exchange of TCP Fins."
}

Event ID 25: Successfully added entry (URI Uri) to cache.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
AddedCacheEntry

Message #

Successfully added entry (URI %1) to cache.

Fields #

NameDescription
Uri UnicodeString
StatusCode UInt16NTSTATUS reference
Verb AnsiString
HeaderLength UInt32
ContentLength UInt32
ExpirationTime UInt64
Encoding AnsiString

Event ID 26: Failed to add an entry (URI UrlBuffer) to the cache.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
AddCacheEntryFailed

Description

Failed to add an entry (URI UrlBuffer) to the cache. Status: ErrorStatus.

Message #

Failed to add an entry (URI %1) to the cache. Status: %2.

Fields #

NameDescription
UrlBuffer UnicodeString
ErrorStatus UInt32
Encoding AnsiString

Event ID 27: Flushed entry (URI Uri) from the cache.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
FlushedCache

Message #

Flushed entry (URI %1) from the cache.

Fields #

NameDescription
Uri UnicodeString
StatusCode UInt16NTSTATUS reference
Verb AnsiString
HeaderLength UInt32
ContentLength UInt32
ExpirationTime UInt64

Event ID 28: Attempted to set URL group property: Property.

#
Channel
Trace
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
ChgUrlGrpProp

Description

Attempted to set URL group property: Property. Status: Status.

Message #

Attempted to set URL group property: %1. Status: %2.

Fields #

NameDescription
Property UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 28,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 31,
    "keywords": "0x8000000000000040",
    "time_created": "2026-07-19T03:39:42.236190300+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 13436,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Property": "7",
    "Status": "0x0"
  },
  "message": "Attempted to set URL group property: 7. Status: 0x0."
}

Event ID 29: Attempted to set server session property: Property.

#
Channel
Trace
Task
HTTPConfigurationPropertyTraceTask
Opcode
ChgSrvSesProp

Description

Attempted to set server session property: Property. Status: Status.

Message #

Attempted to set server session property: %1. Status: %2.

Fields #

NameDescription
Property UInt32
Status UInt32NTSTATUS reference

Event ID 30: Attempted to set request queue property: Property.

#
Channel
Trace
Task
HTTPConfigurationPropertyTraceTask
Opcode
ChgReqQueueProp

Description

Attempted to set request queue property: Property. Status: Status.

Message #

Attempted to set request queue property: %1. Status: %2.

Fields #

NameDescription
Property UInt32
Status UInt32NTSTATUS reference

Event ID 31: Attempted to add URL (Url) to URL group (UrlGroupId).

#
Channel
Trace
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
AddUrl

Description

Attempted to add URL (Url) to URL group (UrlGroupId). Status: Status.

Message #

Attempted to add URL (%2) to URL group (%1). Status: %3.

Fields #

NameDescription
UrlGroupId UInt64
Url UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 31,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 34,
    "keywords": "0x8000000000000040",
    "time_created": "2026-07-19T03:39:42.236841600+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 13436,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UrlGroupId": "0xFE00000020000001",
    "Url": "http://127.0.0.1:18083:127.0.0.1/",
    "Status": "0x0"
  },
  "message": "Attempted to add URL (http://127.0.0.1:18083:127.0.0.1/) to URL group (0xFE00000020000001). Status: 0x0."
}

Event ID 32: Removed URL (Url) from URL group (UrlGroupId).

#
Channel
Trace
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
RemUrl

Message #

Removed URL (%2) from URL group (%1).

Fields #

NameDescription
UrlGroupId UInt64
Url UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 32,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 35,
    "keywords": "0x8000000000000040",
    "time_created": "2026-07-19T03:39:42.454744200+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 13436,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UrlGroupId": "0xFE00000020000001",
    "Url": "http://127.0.0.1:18083:127.0.0.1/"
  },
  "message": "Removed URL (http://127.0.0.1:18083:127.0.0.1/) from URL group (0xFE00000020000001)."
}

Event ID 33: Removed all URLs from URL group UrlGroupId.

#
Channel
Trace
Task
HTTPConfigurationPropertyTraceTask
Opcode
RemAllUrls

Message #

Removed all URLs from URL group %1.

Fields #

NameDescription
UrlGroupId UInt64

Event ID 34: Initiating SSL connection.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslConnEvent

Fields #

NameDescription
ConnectionObj Pointer

Event ID 35: Initiating SSL handshake.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslInitiateHandshake

Fields #

NameDescription
ConnectionObj Pointer

Event ID 36: SSL handshake completed with status: Status.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslHandshakeComplete

Message #

SSL handshake completed with status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
ConnectionObj Pointer

Event ID 37: Server application is attempting to receive the SSL client certificate, which will be provided if available.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslInititateSslRcvClientCert

Description

Server application is attempting to receive the SSL client certificate, which will be provided if available. If the client certificate is not available, a renegotiation will be initiated.

Message #

Server application is attempting to receive the SSL client certificate, which will be provided if available. If the client certificate is not available, a renegotiation will be initiated.

Fields #

NameDescription
ConnectionObj Pointer

Event ID 38: Attempt by server application to receive client certificate failed with status: Status.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslRcvClientCertFailed

Message #

Attempt by server application to receive client certificate failed with status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
ConnectionObj Pointer

Event ID 39: Raw SSL data is available for processing.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPSSLTraceTask
Opcode
SslRcvdRawData

Fields #

NameDescription
DataLength UInt32
ConnectionObj Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 39,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 45,
    "keywords": "0x0000000000000212",
    "time_created": "2026-06-02T05:52:20.869+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-2CC6-83720FEEDC01}"
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionObj": "0xFFFFBD09ED73B010",
    "DataLength": 4874
  },
  "message": "HTTP_TASK_SSL"
}

Event ID 40: Decrypted SSL data is available for processing.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPSSLTraceTask
Opcode
SslDlvrdStreamData

Fields #

NameDescription
DataLength UInt32
ConnectionObj Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 40,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 46,
    "keywords": "0x0000000000000202",
    "time_created": "2026-06-02T05:52:20.869+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-2CC6-83720FEEDC01}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 13660
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionObj": "0xFFFFBD09ED73B010",
    "DataLength": 216
  },
  "message": "HTTP_TASK_SSL"
}

Event ID 41: Passed plaintext data for encryption.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPSSLTraceTask
Opcode
SslAcceptStreamData

Fields #

NameDescription
DataLength UInt32
ConnectionObj Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 41,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 47,
    "keywords": "0x0000000000000206",
    "time_created": "2026-06-02T05:52:20.863+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{72529F65-EE0F-0002-2CC6-83720FEEDC01}"
    },
    "execution": {
      "process_id": 2940,
      "thread_id": 14072
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ConnectionObj": "0xFFFFBD09ED73B010",
    "DataLength": 1542
  },
  "message": "HTTP_TASK_SSL"
}

Event ID 43: Attempt (on connection ID ConnectionId) to authenticate client completed.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
SspiCall

Description

Attempt (on connection ID ConnectionId) to authenticate client completed. Authentication type AuthType. Security status: SecStatus.

Message #

Attempt (on connection ID %1) to authenticate client completed. Authentication type %2. Security status: %3.

Fields #

NameDescription
ConnectionId UInt64
AuthType AnsiString
SecStatus UInt32
AuthStatus UInt32
ContextAttributes UInt32

Event ID 44: Attempted to add entry to the AuthCacheType authentication cache.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
AuthCacheEntryAdded

Description

Attempted to add entry to the AuthCacheType authentication cache. Status: Status.

Message #

Attempted to add entry to the %2 authentication cache. Status: %4.

Fields #

NameDescription
ConnectionId UInt64
AuthCacheType AnsiString
AccessTokenOrHandle Pointer
Status UInt32NTSTATUS reference

Event ID 45: Entry successfully removed from the authentication cache.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
AuthCacheEntryFreed

Fields #

NameDescription
AccessTokenOrHandle Pointer
Status UInt32NTSTATUS reference

Event ID 46: Successfully associated QoS flow with connection (connection ID ConnectionId).

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
QosFlowSetReset

Description

Successfully associated QoS flow with connection (connection ID ConnectionId). Bandwidth throttled to: Bandwidth Bytes per second.

Message #

Successfully associated QoS flow with connection (connection ID %1). Bandwidth throttled to: %2 Bytes per second.

Fields #

NameDescription
ConnectionId UInt64
Bandwidth UInt32
Status UInt32NTSTATUS reference

Event ID 47: Failed to configure the Type logging (directory Directory), Status: Status.

#
Channel
Trace
Task
HTTPLoggingTraceTask
Opcode
LoggingConfigFailed

Message #

Failed to configure the %2 logging (directory %4), Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
Type UInt32
Group UInt32
Directory UnicodeString
Software UnicodeString
SiteId UInt32

Event ID 48: Successfully configured Type logging (directory Directory).

#
Channel
Trace
Task
HTTPLoggingTraceTask
Opcode
LoggingConfig

Message #

Successfully configured %2 logging (directory %5).

Fields #

NameDescription
Present UInt32
Type UInt32
Group UInt32
Format UInt32
Directory UnicodeString
Software UnicodeString
SiteId UInt32

Event ID 49: Failed to create Type log file Filename.

#
Channel
Trace
Task
HTTPLoggingTraceTask
Opcode
LogFileCreateFailed

Description

Failed to create Type log file Filename. Status: Status.

Message #

Failed to create %2 log file %5. Status: %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
Type UInt32
Group UInt32
Format UInt32
Filename UnicodeString
SiteId UInt32

Event ID 50: Successfully created new Type log file Filename.

#
Channel
Trace
Task
HTTPLoggingTraceTask
Opcode
LogFileCreate

Message #

Successfully created new %2 log file %5.

Fields #

NameDescription
Handle Pointer
Type UInt32
Group UInt32
Format UInt32
Filename UnicodeString
SiteId UInt32

Event ID 51: Entry has been written to Type log file.

#
Channel
Trace
Task
HTTPLoggingTraceTask
Opcode
LogFileWrite

Message #

Entry has been written to %3 log file.

Fields #

NameDescription
Status UInt32NTSTATUS reference
Handle Pointer
Type UInt32
Group UInt32
Format UInt32
ResType AnsiString
SiteId UInt32

Event ID 52: Parsing of request (request ID RequestId) failed due to reason: Reason.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
ParseRequestFailed

Description

Parsing of request (request ID RequestId) failed due to reason: Reason. Request may not be compliant with HTTP/1.1.

Message #

Parsing of request (request ID %2) failed due to reason: %3. Request may not be compliant with HTTP/1.1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
RequestId UInt64
Reason AnsiString
ErrorCode UInt32
HintLength UInt32
HintData Binary

Event ID 53: HTTP timer Timer expired.

#
Channel
Trace
Task
HTTPTimeoutTraceTask
Opcode
ConnTimedOut

Description

HTTP timer Timer expired. The connection will be reset.

Message #

HTTP timer %3 expired. The connection will be reset.

Fields #

NameDescription
ConnectionId UInt64
ConnectionObj Pointer
Timer AnsiString

Event ID 56: Failed to acquire handle for SSL credentials.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslEndpointCreationFailed

Description

Failed to acquire handle for SSL credentials. Failure will be event logged. Security status: SecStatus.

Message #

Failed to acquire handle for SSL credentials. Failure will be event logged. Security status: %2.

Fields #

NameDescription
EndpointConfigObj Pointer
SecStatus UInt32
Detail AnsiString

Event ID 57: SSL connection will be disconnected as initiated by the client.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslDisconnEvent

Fields #

NameDescription
ConnectionObj Pointer

Event ID 58: SSL connection will be disconnected as initiated by the server application.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslDisconnReq

Description

SSL connection will be disconnected as initiated by the server application. Status: Status.

Message #

SSL connection will be disconnected as initiated by the server application. Status: %2.

Fields #

NameDescription
ConnectionObj Pointer
Status UInt32NTSTATUS reference

Event ID 59: Attempt to decrypt SSL data failed.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslUnsealMsg

Description

Attempt to decrypt SSL data failed. Security status: SecStatus.

Message #

Attempt to decrypt SSL data failed. Security status: %2.

Fields #

NameDescription
ConnectionObj Pointer
SecStatus UInt32

Event ID 60: Query for SSL connection parameters failed.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslQueryConnInfoFailed

Description

Query for SSL connection parameters failed. Security status: SecStatus. Connection will be reset.

Message #

Query for SSL connection parameters failed. Security status: %2. Connection will be reset.

Fields #

NameDescription
ConnectionObj Pointer
SecStatus UInt32
Detail AnsiString

Event ID 61: Cannot find SSL endpoint for inbound connection for local IP address and port Address.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslEndpointConfigNotFound

Message #

Cannot find SSL endpoint for inbound connection for local IP address and port %3.

Fields #

NameDescription
ConnectionObj Pointer
AddressLength UInt32
Address Binary

Event ID 62: Attempt to perform SSL handshake failed.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslAsc

Description

Attempt to perform SSL handshake failed. Security status: SecStatus.

Message #

Attempt to perform SSL handshake failed. Security status: %2.

Fields #

NameDescription
ConnectionObj Pointer
SecStatus UInt32

Event ID 63: Attempt to encrypt SSL data failed.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslSealMsg

Description

Attempt to encrypt SSL data failed. Security status: SecStatus.

Message #

Attempt to encrypt SSL data failed. Security status: %2.

Fields #

NameDescription
ConnectionObj Pointer
SecStatus UInt32

Event ID 64: Request (request ID RequestId) rejected due to reason: Reason.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
RequestRejected

Message #

Request (request ID %1) rejected due to reason: %2.

Fields #

NameDescription
RequestId UInt64
Reason AnsiString
RequestQueueName UnicodeString

Event ID 65: Server application canceled the processing of its request (request ID RequestId).

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
RequestCancelled

Message #

Server application canceled the processing of its request (request ID %1).

Fields #

NameDescription
RequestId UInt64
Reason AnsiString
RequestQueueName UnicodeString

Event ID 66: Http.

#
Channel
Trace
Task
HTTPDriverGlobalSettingsTask
Opcode
HotAddProcFailed

Description

Http.sys failed to process CPU hot-add. Processor number: NewProcNumber, reason: ReasonString, status: Status.

Message #

Http.sys failed to process CPU hot-add. Processor number: %1, reason: %2, status: %3.

Fields #

NameDescription
NewProcNumber UInt8
ReasonString AnsiString
Status UInt32NTSTATUS reference

Event ID 67: Hot-add information: Current UxNumberOfProcessors: Hotadd_information_Current_UxNumberOfProcessors, comment: comment.

#
Channel
Trace
Task
HTTPDriverGlobalSettingsTask
Opcode
HotAddProcSucceeded

Message #

Hot-add information: Current UxNumberOfProcessors: %1, comment: %2.

Fields #

NameDescription
NewProcNumber UInt8
Comment AnsiString

Event ID 68: Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
UserResponseFlowInit

Message #

Initialized QoS flow: FlowHandle %1, bandwidth %2, peak bandwidth %3, burst size %4

Fields #

NameDescription
FlowHandle Pointer
Bandwidth UInt32
PeakBandwidth UInt32
BurstSize UInt32

Event ID 69: Initialized QoS flow: FlowHandle FlowHandle, bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
CachedResponseFlowInit

Message #

Initialized QoS flow: FlowHandle %1, bandwidth %2, peak bandwidth %3, burst size %4

Fields #

NameDescription
FlowHandle Pointer
Bandwidth UInt32
PeakBandwidth UInt32
BurstSize UInt32

Event ID 70: QoS flow initialization failed: bandwidth Bandwidth, peak bandwidth PeakBandwidth, burst size BurstSize, status Status.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
FlowInitFailed

Message #

QoS flow initialization failed: bandwidth %1, peak bandwidth %2, burst size %3, status %4

Fields #

NameDescription
Bandwidth UInt32
PeakBandwidth UInt32
BurstSize UInt32
Status UInt32NTSTATUS reference

Event ID 71: Setting flow: Connection Connection, FlowHandle FlowHandle.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
SetConnectionFlow

Message #

Setting flow: Connection %1, FlowHandle %2

Fields #

NameDescription
Connection Pointer
FlowHandle Pointer

Event ID 72: Assign to Configuration QoS Flow: FlowHandle FlowHandle.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
RequestAssociatedToConfigurationFlow

Message #

Assign to Configuration QoS Flow: FlowHandle %1

Fields #

NameDescription
FlowHandle Pointer

Event ID 73: [re]Setting QoS Flow failed: Connection Connection, FlowHandle FlowHandle, status Status.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
ConnectionFlowFailed

Message #

[re]Setting QoS Flow failed: Connection %1, FlowHandle %2, status %3

Fields #

NameDescription
Connection Pointer
FlowHandle Pointer
Status UInt32NTSTATUS reference

Event ID 74: Response range processing done.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
ResponseRangeProcessingOK

Description

Response range processing done. Req. RequestId, response content size ContentBytes, ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).

Message #

Response range processing done. Req. %1, response content size %2, ranges %3 (%4-%5, %6-%7,...)

Fields #

NameDescription
RequestId UInt64
ContentBytes UInt64
NumberOfRanges UInt32
Range1Start UInt64
Range1End UInt64
Range2Start UInt64
Range2End UInt64

Event ID 75: Begin building slices.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
BeginBuildingSlices

Description

Begin building slices. Req. RequestId, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).

Message #

Begin building slices. Req. %1, slices %2 (%3,%4,...), ranges %5 (%6-%7, %8-%9,...)

Fields #

NameDescription
RequestId UInt64
NumberOfSlices UInt32
SliceIndex1 UInt32
SliceIndex2 UInt32
NumberOfRanges UInt32
Range1Start UInt64
Range1End UInt64
Range2Start UInt64
Range2End UInt64

Event ID 76: Send cached slices.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
SendSliceCacheContent

Description

Send cached slices. Req. RequestId, CacheEntry CacheEntryPtr, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).

Message #

Send cached slices. Req. %1, CacheEntry %2, slices %3 (%4,%5,...), ranges %6 (%7-%8, %9-%10,...)

Fields #

NameDescription
RequestId UInt64
CacheEntryPtr Pointer
NumberOfSlices UInt32
SliceIndex1 UInt32
SliceIndex2 UInt32
NumberOfRanges UInt32
Range1Start UInt64
Range1End UInt64
Range2Start UInt64
Range2End UInt64

Event ID 77: Cached slices match content.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
CachedSlicesMatchContent

Description

Cached slices match content. Req. RequestId, CacheEntry CacheEntryPtr, slices NumberOfSlices (SliceIndex1,SliceIndex2,...), ranges NumberOfRanges (Range1Start-Range1End, Range2Start-Range2End,...).

Message #

Cached slices match content. Req. %1, CacheEntry %2, slices %3 (%4,%5,...), ranges %6 (%7-%8, %9-%10,...)

Fields #

NameDescription
RequestId UInt64
CacheEntryPtr Pointer
NumberOfSlices UInt32
SliceIndex1 UInt32
SliceIndex2 UInt32
NumberOfRanges UInt32
Range1Start UInt64
Range1End UInt64
Range2Start UInt64
Range2End UInt64

Event ID 78: Merge slices to cache.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
MergeSlicesToCache

Description

Merge slices to cache. CacheEntry CacheEntryPtr, slices to merge NofSlicesToMerge, slices to cache NofSlicesInCache.

Message #

Merge slices to cache. CacheEntry %1, slices to merge %2, slices to cache %3

Fields #

NameDescription
CacheEntryPtr Pointer
NofSlicesToMerge UInt32
NofSlicesInCache UInt32

Event ID 79: Sending range from flat cache entry.

#
Channel
Trace
Task
HTTPCacheTraceTask
Opcode
FlatCacheRangeSend

Description

Sending range from flat cache entry. CacheEntry CacheEntryPtr, range Range1Start-Range1End.

Message #

Sending range from flat cache entry. CacheEntry %1, range %2-%3

Fields #

NameDescription
CacheEntryPtr Pointer
Range1Start UInt64
Range1End UInt64

Event ID 80: Channel bind ASC parameters: connection ConnectionId, buffers NoBindBuffers, flags SecFlags.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
ChannelBindAscParams

Message #

Channel bind ASC parameters: connection %1, buffers %2, flags %3

Fields #

NameDescription
ConnectionId UInt64
NoBindBuffers UInt32
SecFlags UInt32

Event ID 81: Service bind check done.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
ServiceBindCheckComplete

Description

Service bind check done. Connection ConnectionId, Context SecContextL-SecContextH, status SecStatus, target Target.

Message #

Service bind check done. Connection %1, Context %2-%3, status %4, target %5

Fields #

NameDescription
ConnectionId UInt64
SecContextL Pointer
SecContextH Pointer
SecStatus UInt32
Target UnicodeString

Event ID 82: Captured channel bind config.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
ChannelBindConfigCapture

Description

Captured channel bind config. Hardening Hardening, flags Flags, service count ServiceNameCount.

Message #

Captured channel bind config. Hardening %1, flags %2, service count %3

Fields #

NameDescription
Hardening UInt8
Flags UInt32
ServiceNameCount UInt32

Event ID 83: Channel bind response config overwrites ReplaceConfigOf.

#
Channel
Trace
Task
HTTPAuthenticationTraceTask
Opcode
ChannelBindPerResponseConfig

Message #

Channel bind response config overwrites %1

Fields #

NameDescription
ReplaceConfigOf AnsiString

Event ID 84: Policy-Based QoS: Connection Connection, FlowHandle FlowHandle.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
UsePolicyBasedQoSFlow

Message #

Policy-Based QoS: Connection %1, FlowHandle %2

Fields #

NameDescription
Connection Pointer
FlowHandle Pointer

Event ID 85: Thread pool extension.

#
Channel
Trace
Task
HTTPThreadPool
Opcode
ThreadPoolExtension

Description

Thread pool extension. Pool type: Thread_pool_extension_Pool_type, active pools: active_pools.

Message #

Thread pool extension. Pool type: %1, active pools: %2.

Fields #

NameDescription
PoolType AnsiString
ActivePools UInt16

Event ID 86: Thread ready.

#
Channel
Trace
Task
HTTPThreadPool
Opcode
ThreadReady

Description

Thread ready. Pool type: Thread_ready_Pool_type, active pools: active_pools, thread count: thread_count.

Message #

Thread ready. Pool type: %1, active pools: %2, thread count: %3

Fields #

NameDescription
PoolType AnsiString
ActivePools UInt16
ThreadCount UInt8

Event ID 87: Thread pool trim.

#
Channel
Trace
Task
HTTPThreadPool
Opcode
ThreadPoolTrim

Description

Thread pool trim. Pool type: Thread_pool_trim_Pool_type, active pools: active_pools.

Message #

Thread pool trim. Pool type: %1, active pools: %2.

Fields #

NameDescription
PoolType AnsiString
ActivePools UInt16

Event ID 88: Thread gone.

#
Channel
Trace
Task
HTTPThreadPool
Opcode
ThreadGone

Description

Thread gone. Pool type: Thread_gone_Pool_type, active pools: active_pools, thread count: thread_count.

Message #

Thread gone. Pool type: %1, active pools: %2, thread count: %3

Fields #

NameDescription
PoolType AnsiString
ActivePools UInt16
ThreadCount UInt8

Event ID 89: SNI parsed for connection: ConnectionObj with status: Status.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SniParsed

Message #

SNI parsed for connection: %1 with status: %2

Fields #

NameDescription
ConnectionObj Pointer
Status UInt32NTSTATUS reference
SniLength UInt32
SniHost Binary
NormalizedHost UnicodeString

Event ID 90: Request RequestId has initated opaque mode.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
InitiateOpaqueMode

Message #

Request %1 has initated opaque mode

Fields #

NameDescription
RequestId UInt64

Event ID 91: Endpoint auto-generated for EndpointName.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
EndpointAutoGenerated

Message #

Endpoint auto-generated for %2

Fields #

NameDescription
EndpointConfigObj Pointer
EndpointName UnicodeString

Event ID 92: Deleted auto-generated endpoint for EndpointName.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
AutoGeneratedEndpointDeleted

Message #

Deleted auto-generated endpoint for %2

Fields #

NameDescription
EndpointConfigObj Pointer
EndpointName UnicodeString

Event ID 93: Inbound connection for IP: IpAddress, SNI: SniHostname.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslEndpointConfigFound

Description

Inbound connection for IP: IpAddress, SNI: SniHostname. SSL endpoint found: MatchingEndpointName.

Message #

Inbound connection for IP: %3, SNI: %4. SSL endpoint found: %5

Fields #

NameDescription
EndpointConfigObj Pointer
IpAddrLength UInt32
IpAddress Binary
SniHostname UnicodeString
MatchingEndpointName UnicodeString
AutoGeneratedEndpoint Boolean

Event ID 94: SSL connection with local IP address and port Address rejected due to configuration policy.

#
Channel
Trace
Task
HTTPSSLTraceTask
Opcode
SslEndpointConfigRejected

Message #

SSL connection with local IP address and port %2 rejected due to configuration policy.

Fields #

NameDescription
AddressLength UInt32
Address Binary

Event ID 95: Parsing of response (response ID ResponseId) failed due to reason: Reason.

#
Channel
Trace
Task
HTTPResponseTraceTask
Opcode
ParseRequestFailed

Description

Parsing of response (response ID ResponseId) failed due to reason: Reason. Request may not be compliant with HTTP/1.1.

Message #

Parsing of response (response ID %2) failed due to reason: %3. Request may not be compliant with HTTP/1.1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
ResponseId UInt64
Reason AnsiString
ErrorCode UInt32
HintLength UInt32
HintData Binary

Event ID 96: SSL handshake failed.

#
Channel
System
Task
HTTPSSLTraceTask
Opcode
SslHandshakeFailure

Description

SSL handshake failed. Local IP: Remote_IP, Remote IP: Thumbprint, SNI: Client_Initiated_Disconnect, Thumbprint: Connection_Status, Client Initiated Disconnect: LocalAddressLength, Abortive Disconnect: LocalAddress, Connection Status: RemoteAddressLength.

Message #

SSL handshake failed. Local IP: %2, Remote IP: %4, SNI: %5, Thumbprint: %7, Client Initiated Disconnect: %8, Abortive Disconnect: %9, Connection Status: %10

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
SniHostname UnicodeString
ThumbprintLength UInt16
Thumbprint Binary
ClientDisconnect Boolean
AbortiveDisconnect Boolean
Status UInt32NTSTATUS reference

Event ID 97: HTTP error response sent.

#
Channel
System
Task
HTTPRequestTraceTask
Opcode
HttpErrorResponseSent

Description

HTTP error response sent. Url: Url, Verb: Verb, Status Code: StatusCode, Cache Send: CacheSend, Request Queue: RequestQueue, PID: ProcessId, TID: ThreadId, Image Name: ImageFileName, Working Set(Bytes): WorkingSetSize, Send Status: SendStatus, Thread Count: ThreadCount, Reason Phrase: ReasonPhrase, Error Cause: ErrorCause, Verbosity: Verbosity

Message #

HTTP error response sent. Url: %1, Verb: %2, Status Code: %3, Cache Send: %4, Request Queue: %5, PID: %6, TID: %7, Image Name: %8, Working Set(Bytes): %9, Send Status: %10, Thread Count: %11, Reason Phrase: %12, Error Cause: %13, Verbosity: %14

Fields #

NameDescription
Url UnicodeString
Verb UInt32
StatusCode UInt16NTSTATUS reference
CacheSend Boolean
RequestQueue UnicodeString
ProcessId UInt32
ThreadId UInt32
ImageFileName AnsiString
WorkingSetSize UInt64
SendStatus UInt32
ThreadCount UInt32
ReasonPhrase AnsiString
ErrorCause AnsiString
Verbosity UInt32

Event ID 98: SSL renegotiate timed out.

#
Channel
System
Task
HTTPSSLTraceTask
Opcode
SslRenegotiateTimedOut

Description

SSL renegotiate timed out. Local IP: Remote_IP, Remote IP: Thumbprint, SNI: Connection_Buffer_Full, Thumbprint: LocalAddress, Connection Buffer Full: RemoteAddressLength.

Message #

SSL renegotiate timed out. Local IP: %2, Remote IP: %4, SNI: %5, Thumbprint: %7, Connection Buffer Full: %8

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
SniHostname UnicodeString
ThumbprintLength UInt16
Thumbprint Binary
ConnectionBufferFull Boolean

Event ID 99: HTTP 11 Required.

#
Channel
System
Task
HTTPRequestTraceTask
Opcode
Http11Required

Description

HTTP 11 Required. Verb: HTTP_11_Required_Verb, Fault Code: Fault_Code.

Message #

HTTP 11 Required. Verb: %1, Fault Code: %2

Fields #

NameDescription
Verb UInt32
FaultCode UInt32

Event ID 100: Version: Version Counts: Counts.

#
Channel
System
Task
HTTPConnectionTraceTask
Opcode
QuicCounts

Message #

Version: %1 Counts: %2

Fields #

NameDescription
Version UInt32
CountsLength UInt32
Counts Binary

Event ID 101: Version: Version Counts: Counts.

#
Channel
System
Task
HTTPConnectionTraceTask
Opcode
WskCounts

Message #

Version: %1 Counts: %2

Fields #

NameDescription
Version UInt32
CountsLength UInt32
Counts Binary

Event ID 105: QUIC Connection.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
QuicConnection

Description

QUIC Connection. QuicConnectionId: QUIC_Connection_QuicConnectionId, Connection: Connection, Local IP: Remote_IP, Remote IP: ErrorCode, SNI: QuicConnectionId, ErrorCode: LocalAddressLength, Status: LocalAddress.

Message #

QUIC Connection. QuicConnectionId: %1, Connection: %2, Local IP: %4, Remote IP: %6, SNI: %8, ErrorCode: %9, Status: %10

Fields #

NameDescription
QuicConnectionId UInt64
Connection Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
SniLength UInt32
SniHost Binary
ErrorLogCode UInt32
Status UInt32NTSTATUS reference

Event ID 106: QUIC Connection Callback.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
QuicConnectionCallback

Description

QUIC Connection Callback. Connection: QUIC_Connection_Callback_Connection, Event: Event, EventParam: EventParam.

Message #

QUIC Connection Callback. Connection: %1, Event: %2, EventParam: %3

Fields #

NameDescription
Connection Pointer
Event UInt8
EventParam UInt64

Event ID 107: QUIC Stream.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
QuicStream

Description

QUIC Stream. QuicStreamId: QUIC_Stream_QuicStreamId, Connection: Connection, Stream: Stream.

Message #

QUIC Stream. QuicStreamId: %1, Connection: %2, Stream: %3

Fields #

NameDescription
QuicStreamId UInt64
Connection Pointer
Stream Pointer

Event ID 108: QUIC Stream Callback.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
QuicStreamCallback

Description

QUIC Stream Callback. Stream: QUIC_Stream_Callback_Stream, Connection: Connection, StreamType: StreamType, Event: Event, EventParam: EventParam.

Message #

QUIC Stream Callback. Stream: %1, Connection: %2, StreamType: %3, Event: %4, EventParam: %5

Fields #

NameDescription
Stream Pointer
Connection Pointer
StreamType AnsiString
Event UInt8
EventParam UInt64

Event ID 109: QUIC Registration Failed.

#
Channel
System
Task
HTTPDriverGlobalSettingsTask
Opcode
QuicRegistration

Description

QUIC Registration Failed. Status: QUIC_Registration_Failed_Status.

Message #

QUIC Registration Failed. Status: %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 110: Correlation ID for request RequestId: CorrelationId.

#
Channel
Trace
Also via
realtime ETW trace
Level
Informational
Task
HTTPRequestTraceTask
Opcode
ClientCorrelation

Message #

Correlation ID for request %1: %2

Fields #

NameDescription
RequestId UInt64
CorrelationId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 110,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 120,
    "keywords": "0x0000000000000002",
    "time_created": "2026-06-02T05:52:20.869+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{4000072C-0001-FE00-B63F-84710C7967BB}"
    },
    "execution": {
      "process_id": 4,
      "thread_id": 12180
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CorrelationId": "{DBC7C805-5E45-11F1-A6BE-010101010000}",
    "RequestId": 18302628891002406700
  },
  "message": "HTTP_TASK_REQUEST"
}

Event ID 111: Create URL group UrlGroupId.

#
Channel
System
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
CreateUrlGroup

Description

Create URL group UrlGroupId. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Create URL group %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
UrlGroupId UInt64
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
    "event_source_name": "",
    "event_id": 111,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 125,
    "keywords": 4611686018427387968,
    "time_created": "2026-03-13T20:06:22.592017+00:00",
    "event_record_id": 2069,
    "correlation": {},
    "execution": {
      "process_id": 4260,
      "thread_id": 4596
    },
    "channel": "System",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "UrlGroupId": 18302628890465533953,
    "Status": 0,
    "ProcessId": 4260,
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-18"
  },
  "message": ""
}

Event ID 112: Attempted to reserve URL Url.

#
Channel
System
Level
Informational
Task
HTTPSetupTraceTask
Opcode
ResvUrlV2

Description

Attempted to reserve URL Url. Status ReserveStatus. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Attempted to reserve URL %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
Url UnicodeString
ReserveStatus UInt32
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 112,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 121,
    "keywords": 4611686018427387905,
    "time_created": "2026-06-13T13:53:53.8268372+00:00",
    "event_record_id": 2699,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 160
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Url": "http://+:47001/wsman/",
    "ReserveStatus": "0",
    "ProcessId": "4",
    "ExecutablePath": "",
    "UserSid": "S-1-5-18"
  },
  "message": "Attempted to reserve URL http://+:47001/wsman/. Status 0x0. Process Id 0x4 Executable path , User S-1-5-18"
}

Event ID 113: Attempted to add URL (Url) to URL group (UrlGroupId).

#
Channel
System
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
AddUrl_5_122

Description

Attempted to add URL (Url) to URL group (UrlGroupId). Status: Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Attempted to add URL (%2) to URL group (%1). Status: %3. Process Id %4 Executable path %5, User %6

Fields #

NameDescription
UrlGroupId UInt64
Url UnicodeString
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
    "event_source_name": "",
    "event_id": 113,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 122,
    "keywords": 4611686018427387968,
    "time_created": "2026-03-11T06:29:35.510270+00:00",
    "event_record_id": 2802,
    "correlation": {},
    "execution": {
      "process_id": 1608,
      "thread_id": 1656
    },
    "channel": "System",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "UrlGroupId": 18302628907645403137,
    "Url": "https://+:5986/wsman/",
    "Status": 0,
    "ProcessId": 1608,
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-20"
  },
  "message": ""
}

Event ID 114: Removed URL (Url) from URL group (UrlGroupId).

#
Channel
System
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
RemUrl_5_123

Description

Removed URL (Url) from URL group (UrlGroupId). Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Removed URL (%2) from URL group (%1). Process Id %3 Executable path %4, User %5

Fields #

NameDescription
UrlGroupId UInt64
Url UnicodeString
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 114,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 123,
    "keywords": 4611686018427387968,
    "time_created": "2026-06-13T13:53:22.9529441+00:00",
    "event_record_id": 2602,
    "correlation": {},
    "execution": {
      "process_id": 7116,
      "thread_id": 9664
    },
    "channel": "System",
    "computer": "telemetry-W11-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "UrlGroupId": "18302628894760501249",
    "Url": "https://+:5986/wsman/",
    "ProcessId": "7116",
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-20"
  },
  "message": "Removed URL (https://+:5986/wsman/) from URL group (0xFE00000220000001). Process Id 0x1BCC Executable path \\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe, User S-1-5-20"
}

Event ID 115: Removed all URLs from URL group UrlGroupId.

#
Channel
System
Task
HTTPConfigurationPropertyTraceTask
Opcode
RemAllUrls_5_124

Description

Removed all URLs from URL group UrlGroupId. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Removed all URLs from URL group %1. Process Id %2 Executable path %3, User %4

Fields #

NameDescription
UrlGroupId UInt64
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Event ID 116: Attempted to set URL group UrlGroupId property Property.

#
Channel
Trace
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
ChgUrlGrpProp_5_127

Description

Attempted to set URL group UrlGroupId property Property. Status: Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Attempted to set URL group %1 property %2. Status: %3. Process Id %4 Executable path %5, User %6

Fields #

NameDescription
UrlGroupId UInt64
Property UInt32
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{dd5ef90a-6398-47a4-ad34-4dcecdef795f}",
    "event_source_name": "",
    "event_id": 116,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 127,
    "keywords": "0x8000000000000040",
    "time_created": "2026-07-19T03:39:42.236207000+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 13436,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-HttpService/Trace",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UrlGroupId": "0xFE00000020000001",
    "Property": "7",
    "Status": "0x0",
    "ProcessId": "0x347C",
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe",
    "UserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105"
  },
  "message": "Attempted to set URL group 0xFE00000020000001 property 7. Status: 0x0. Process Id 0x347C Executable path \\Device\\HarddiskVolume4\\Windows\\System32\\WindowsPowerShell\\v1.0\\powershell.exe, User S-1-5-21-1006758700-2167138679-1475694448-1105"
}

Event ID 117: Delete URL group UrlGroupId.

#
Channel
System
Level
Informational
Task
HTTPConfigurationPropertyTraceTask
Opcode
DeleteUrlGroup

Description

Delete URL group UrlGroupId. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Delete URL group %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
UrlGroupId UInt64
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
    "event_source_name": "",
    "event_id": 117,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 126,
    "keywords": 4611686018427387968,
    "time_created": "2023-10-25T22:56:15.387403+00:00",
    "event_record_id": 1478,
    "correlation": {},
    "execution": {
      "process_id": 3840,
      "thread_id": 3904
    },
    "channel": "System",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-19"
    }
  },
  "event_data": {
    "UrlGroupId": 18302628886170566657,
    "Status": 0,
    "ProcessId": 3840,
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-19"
  },
  "message": ""
}

References #

Event ID 118: Status Status.

#
Channel
System
Task
HTTPConfigurationPropertyTraceTask
Opcode
FlushResponseCache

Description

Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Status %1. Process Id %2 Executable path %3, User %4

Fields #

NameDescription
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Event ID 119: SSL Certificate Settings deleted for endpoint : Endpoint.

#
Channel
System
Level
Informational
Task
HTTPSSLTraceTask
Opcode
SslCertSettingsDeleted

Description

SSL Certificate Settings deleted for endpoint : Endpoint. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

SSL Certificate Settings deleted for endpoint : %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
Endpoint UnicodeString
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
    "event_source_name": "",
    "event_id": 119,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 129,
    "keywords": 4611686018427388416,
    "time_created": "2025-12-31T19:35:47.939697+00:00",
    "event_record_id": 419,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 5100
    },
    "channel": "System",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Endpoint": "NULL",
    "Status": 3221225524,
    "ProcessId": 7104,
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-21-3407486967-1585450050-1838039599-1000"
  },
  "message": ""
}

Event ID 120: SSL Certificate Settings created by an admin process for endpoint : Endpoint.

#
Channel
System
Level
Informational
Task
HTTPSSLTraceTask
Opcode
SslCertSettingsCreated

Description

SSL Certificate Settings created by an admin process for endpoint : Endpoint. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

SSL Certificate Settings created by an admin process for endpoint : %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
Endpoint UnicodeString
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "DD5EF90A-6398-47A4-AD34-4DCECDEF795F",
    "event_source_name": "",
    "event_id": 120,
    "version": 0,
    "level": 4,
    "task": 7,
    "opcode": 130,
    "keywords": 4611686018427388416,
    "time_created": "2025-12-31T19:35:47.964183+00:00",
    "event_record_id": 420,
    "correlation": {},
    "execution": {
      "process_id": 7104,
      "thread_id": 5100
    },
    "channel": "System",
    "computer": "WIN11-22H2-X64",
    "security": {
      "user_id": "S-1-5-21-3407486967-1585450050-1838039599-1000"
    }
  },
  "event_data": {
    "Endpoint": "0.0.0.0:5986",
    "Status": 0,
    "ProcessId": 7104,
    "ExecutablePath": "\\Device\\HarddiskVolume4\\Windows\\System32\\svchost.exe",
    "UserSid": "S-1-5-21-3407486967-1585450050-1838039599-1000"
  },
  "message": ""
}

Event ID 121: SSL Certificate Settings updated by an admin process for endpoint : Endpoint, Extended Param Type ExtendedParamType.

#
Channel
System
Task
HTTPSSLTraceTask
Opcode
SslCertSettingsUpdeted

Description

SSL Certificate Settings updated by an admin process for endpoint : Endpoint, Extended Param Type ExtendedParamType. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

SSL Certificate Settings updated by an admin process for endpoint : %1, Extended Param Type %2. Status %3. Process Id %4 Executable path %5, User %6

Fields #

NameDescription
Endpoint UnicodeString
ExtendedParamType UInt32
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Event ID 122: Set the IP address to the listen only list IpList.

#
Channel
System
Task
HTTPSetupTraceTask
Opcode
SetIpListenList

Description

Set the IP address to the listen only list IpList. Status Status. Process Id ProcessId Executable path ExecutablePath, User UserSid.

Message #

Set the IP address to the listen only list %1. Status %2. Process Id %3 Executable path %4, User %5

Fields #

NameDescription
IpList UnicodeString
Status UInt32NTSTATUS reference
ProcessId UInt64
ExecutablePath UnicodeString
UserSid SID

Event ID 123: QUIC certificate load failed with status Status and was ignored due to disabled TLS 1.

#
Channel
System
Task
HTTPSSLTraceTask
Opcode
QuicTls13Disabled

Description

QUIC certificate load failed with status Status and was ignored due to disabled TLS 1.3 (status Tls13Status).

Message #

QUIC certificate load failed with status %1 and was ignored due to disabled TLS 1.3 (status %2).

Fields #

NameDescription
Status UInt32NTSTATUS reference
Tls13Status UInt32

Event ID 124: Request (request ID RequestId) rejected due to request queue overflow.

#
Channel
Trace
Task
HTTPRequestTraceTask
Opcode
RequestQueueOverflow

Message #

Request (request ID %1) rejected due to request queue overflow

Fields #

NameDescription
RequestId UInt64
RequestQueueName UnicodeString
LastPendingReceiveRequest FILETIME
LastSucceededReceiveRequest FILETIME
LastFailedReceiveRequest FILETIME

Event ID 125: Connection Connection, Connection Id ConnectionId: Stream Created, StreamId StreamId.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
CreatHttp2Stream

Message #

Connection %1, Connection Id %2: Stream Created, StreamId %3

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32

Event ID 126: Connection Connection, Connection Id ConnectionId: Stream Aborted, StreamId StreamId, HRESULT error Error, Reset Code ResetCode.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
AbortHttp2Stream

Message #

Connection %1, Connection Id %2: Stream Aborted, StreamId %3, HRESULT error %4, Reset Code %5

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
Error Int32
ResetCode UInt32

Event ID 127: Connection Connection, Connection Id ConnectionId: Send StreamId StreamId, Length Length.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
SendHttp2Stream

Message #

Connection %1, Connection Id %2: Send StreamId %3, Length %4

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
Length UInt64

Event ID 128: Connection Connection, Connection Id ConnectionId: Data Indincation, StreamId StreamId, BytesIndicated BytesIndicated, BytesAccepted BytesAccepted, Status Status.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
Http2DataIndicate

Message #

Connection %1, Connection Id %2: Data Indincation, StreamId %3, BytesIndicated %4, BytesAccepted %5, Status %6

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
BytesIndicated UInt32
BytesAccepted UInt32
Status Int32NTSTATUS reference

Event ID 129: Connection Connection, Connection Id ConnectionId: Header Indincation, StreamId StreamId, Headers indicated Headers, Status Status.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
Http2HeaderIndicate

Message #

Connection %1, Connection Id %2: Header Indincation, StreamId %3, Headers indicated %4, Status %5

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
Headers UInt32
Status Int32NTSTATUS reference

Event ID 130: Connection Connection, Connection Id ConnectionId: Go Away, StreamId StreamId, ErrorCode ErrorCode, FaultCode FaultCode.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
Http2GoAway

Message #

Connection %1, Connection Id %2: Go Away, StreamId %3, ErrorCode %4, FaultCode %5

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
ErrorCode UInt32
FaultCode UInt32

Event ID 131: Http2 fault.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
Http2Fault

Description

Http2 fault. Connection Connection, Connection Id ConnectionId:, StreamId StreamId, Code FaultCode, Status Status.

Message #

Http2 fault. Connection %1, Connection Id %2:, StreamId %3, Code %4, Status %5

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64
StreamId UInt32
FaultCode UInt32
Status Int32NTSTATUS reference

Event ID 132: Connection Connection, Connection Id ConnectionId: Create.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
CreatHttp2Connection

Message #

Connection %1, Connection Id %2: Create

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64

Event ID 133: Connection Connection, Connection Id ConnectionId: Detach.

#
Channel
Trace
Task
HTTPConnectionTraceTask
Opcode
CreatHttp2Detach

Message #

Connection %1, Connection Id %2: Detach

Fields #

NameDescription
Connection Pointer
ConnectionId UInt64

Event ID 134: task_0

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
RequestId UInt64
ReceiveStart UInt64
ReceiveHeadersEnd UInt64
ResponseStart UInt64
ResponseEnd UInt64
BufferedSend Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 134,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000010000",
    "time_created": "2026-06-02T05:52:20.875+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2284
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "BufferedSend": false,
    "ReceiveHeadersEnd": 1227505232003,
    "ReceiveStart": 1214802420460,
    "RequestId": 18302628891002406700,
    "ResponseEnd": 1227505280233,
    "ResponseStart": 1227505257772
  },
  "message": ""
}

Event ID 135: task_0135

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
PerfCounterPeriod UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 135,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000010000",
    "time_created": "2026-06-02T05:52:19.190+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 15468,
      "thread_id": 14180
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PerfCounterPeriod": 10000000
  },
  "message": ""
}

Event ID 136: task_0136

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Opcode
win:Info

Fields #

NameDescription
RequestId UInt64
StatsType UInt32
StatsLength UInt32
StatsData Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-HttpService",
    "guid": "{DD5EF90A-6398-47A4-AD34-4DCECDEF795F}",
    "event_source_name": "",
    "event_id": 136,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000010000",
    "time_created": "2026-06-02T05:52:20.875+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2284
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "RequestId": 18302628891002406700,
    "StatsData": "04000000B405000018621300000000000000000021090000A601000000000000801C0400801C0400FFFF0000FFFF000020FC130000000000EAEC3000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000001962130022FC13000000000000000000000000000000000000000000",
    "StatsLength": 152,
    "StatsType": 0
  },
  "message": ""
}

Event ID 137: Query for SSL connection cipher info failed

#
Channel
Operational, Trace
Task
HTTPSSLTraceTask
Opcode
SslQueryCipherInfoFailed

Description

Query for SSL connection cipher info failed. Security status: . Connection will be reset.

Fields #

NameDescription
ConnectionObj Pointer
SecStatus UInt32
Detail AnsiString

Provenance

ETW provider GUID {DD5EF90A-6398-47A4-AD34-4DCECDEF795F}

Defined in HTTP.SYS, the binary that emits these events.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.3451, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.4202, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3451, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4202, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • JD-WIN11-22H2-1-native-20260719, sample captured from a live trace, binary version 10.0.22621.1, captured 2026-07-19

    Native ETL capture of a controlled loopback HttpListener request.