Microsoft-Windows-IIS-Configuration
Event ID 3: A cache node for 'ConfigPath' has been added to cache
#Event ID 7: Configuration cache is handling change notification for 'ConfigPath'
#Event ID 8: Configuration cache is polling for changes at 'ConfigPath'
#Event ID 9: Configuration cache is discarding all config files whose configuration path is equal to or a subpath of 'ConfigPath'
#Event ID 10: An error has occurred: Message.
#Message #
Fields #
| Name | Description |
|---|---|
HRESULT HexInt32 | |
PhysicalPath UnicodeString | |
Type UInt32 | |
Message UnicodeString | |
LineNumber UInt32 | |
PreviousLine UnicodeString | |
ErrorLine UnicodeString | |
NextLine UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"guid": "DC0B8E51-4863-407A-BC3C-1B479B2978AC",
"event_source_name": "",
"event_id": 10,
"version": 0,
"level": 2,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:16:52.684481+00:00",
"event_record_id": 1197,
"correlation": {},
"execution": {
"process_id": 8424,
"thread_id": 2136
},
"channel": "Microsoft-IIS-Configuration/Administrative",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"HRESULT": "0x800700b7",
"PhysicalPath": "",
"Type": 3,
"Message": "Cannot add duplicate collection entry of type 'add' with unique key attribute 'name' set to 'SecurityCertificate'\r\n",
"LineNumber": 0,
"PreviousLine": "",
"ErrorLine": "",
"NextLine": ""
},
"message": ""
}
Event ID 10: An error has occurred:
#Description
An error has occurred.
Fields #
| Name | Description |
|---|---|
HRESULT HexInt32 | |
PhysicalPath UnicodeString | |
Type UInt32 | |
Message UnicodeString | |
LineNumber UInt32 | |
PreviousLine UnicodeString | |
ErrorLine UnicodeString | |
NextLine UnicodeString |
Event ID 12: Unable to find schema for config section 'SectionPath'.
#Description
Unable to find schema for config section 'SectionPath'. This section will be ignored.
Message #
Fields #
| Name | Description |
|---|---|
PhysicalPath UnicodeString | |
FileConfigPath UnicodeString | |
EffectiveLocationPath UnicodeString | |
SectionPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"guid": "DC0B8E51-4863-407A-BC3C-1B479B2978AC",
"event_source_name": "",
"event_id": 12,
"version": 0,
"level": 3,
"task": 0,
"opcode": 0,
"keywords": 9223372036854775808,
"time_created": "2026-03-13T20:00:13.509827+00:00",
"event_record_id": 1,
"correlation": {},
"execution": {
"process_id": 8484,
"thread_id": 8704
},
"channel": "Microsoft-IIS-Configuration/Administrative",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PhysicalPath": "\\\\?\\C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\CONFIG\\machine.config",
"FileConfigPath": "MACHINE",
"EffectiveLocationPath": "",
"SectionPath": "system.serviceModel/extensions"
},
"message": ""
}
Event ID 12: Unable to find schema for config section 'SectionPath'
#Description
Unable to find schema for config section 'SectionPath'. This section will be ignored.
Fields #
| Name | Description |
|---|---|
PhysicalPath UnicodeString | |
FileConfigPath UnicodeString | |
EffectiveLocationPath UnicodeString | |
SectionPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"event_id": 12,
"level": "Warning",
"task": null,
"opcode": "Info",
"time_created": "2026-05-25T00:18:28.9958981+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-IIS-Configuration/Administrative"
},
"event_data": {
"EffectiveLocationPath": null,
"SectionPath": "system.xaml.hosting/httpHandlers",
"PhysicalPath": "\\\\?\\C:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\CONFIG\\web.config",
"FileConfigPath": "MACHINE/WEBROOT"
}
}
Event ID 13: Parsing config file 'PhysicalPath'
#Event ID 14: MACHINE/WEBROOT/APPHOST configuration redirection has been enabled
#Event ID 15: Attempting to open file or directory 'lpFileName'
#Event ID 16: An impersonation token with handle 'TokenHandle' for the credentials of 'Domain\User' has been created
#Event ID 17: File change notification monitor that watches for changes in 'Directory' has been created
#Event ID 18: File change notification monitor that watches for changes in 'Directory' has blocked waiting for file changes
#Event ID 19: File change notification monitor that watches for changes in 'Directory' received a change notification
#Event ID 20: File change notification monitor that watches for changes in 'Directory' is processing notified changes
#Event ID 21: File change notification monitor that watches for changes in 'Directory' has been destroyed
#Event ID 23: A change listener of type 'TargetType' is being informed about a configuration change at 'ConfigPath'
#Event ID 24: During schema file enumeration, the file 'PhysicalPath' was detected in the schema directory
#Event ID 25: The virtual path 'ConfigPath' has been mapped to the physical path 'PhysicalPath'
#Event ID 27: The 'MetadataName' metadata of a configuration system object was set to 'Value'
#Event ID 28: Thread is impersonating an access token belonging to handle 'ImpersonationTokenHandle'
#Event ID 29: Changes to 'Configuration' at 'ConfigPath' have successfully been committed.
#Message #
Fields #
| Name | Description | Rules |
|---|---|---|
PhysicalPath UnicodeString | ||
ConfigPath UnicodeString | ||
EffectiveLocationPath UnicodeString | ||
Configuration UnicodeString | 4 detection rules | |
EditOperationType UInt32 | ||
OldValue UnicodeString | 1 detection rule | |
NewValue UnicodeString | 15 detection rules |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"guid": "DC0B8E51-4863-407A-BC3C-1B479B2978AC",
"event_source_name": "",
"event_id": 29,
"version": 0,
"level": 5,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:06:38.758372+00:00",
"event_record_id": 2219,
"correlation": {},
"execution": {
"process_id": 2732,
"thread_id": 1444
},
"channel": "Microsoft-IIS-Configuration/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PhysicalPath": "\\\\?\\C:\\Windows\\system32\\inetsrv\\config\\applicationHost.config",
"ConfigPath": "MACHINE/WEBROOT/APPHOST",
"EffectiveLocationPath": "",
"Configuration": "/system.webServer/handlers/add[@name=\"HttpRemotingHandlerFactory-rem-Integrated-4.0\"]/@type",
"EditOperationType": 1,
"OldValue": "",
"NewValue": "System.Runtime.Remoting.Channels.Http.HttpRemotingHandlerFactory, System.Runtime.Remoting, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089"
},
"message": ""
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma # view in coverage
T1505, T1505.004, T1685, T1685.001T1505, T1505.004, T1685, T1685.001T1505, T1505.004, T1685, T1685.001Splunk # view in coverage
T1505, T1505.004
Event ID 29: Changes to 'Configuration' at 'ConfigPath' have successfully been committed
#Fields #
| Name | Description | Rules |
|---|---|---|
PhysicalPath UnicodeString | ||
ConfigPath UnicodeString | ||
EffectiveLocationPath UnicodeString | ||
Configuration UnicodeString | 4 detection rules | |
EditOperationType UInt32 | ||
OldValue UnicodeString | 1 detection rule | |
NewValue UnicodeString | 15 detection rules |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"event_id": 29,
"level": "Verbose",
"task": null,
"opcode": "Info",
"time_created": "2026-03-17T19:25:10.4723631+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-IIS-Configuration/Operational"
},
"event_data": {
"PhysicalPath": "\\\\?\\C:\\Windows\\system32\\inetsrv\\config\\applicationHost.config",
"EditOperationType": "1",
"EffectiveLocationPath": null,
"Configuration": "/system.webServer/staticContent/mimeMap[@fileExtension=\".wim\"]/@mimeType",
"ConfigPath": "MACHINE/WEBROOT/APPHOST",
"OldValue": null,
"NewValue": "application/x-ms-wim"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma # view in coverage
T1505, T1505.004, T1685, T1685.001T1505, T1505.004, T1685, T1685.001T1505, T1505.004, T1685, T1685.001Splunk # view in coverage
T1505, T1505.004
Event ID 30: Failed to commit changes to 'Configuration' at 'ConfigPath'
#Event ID 33: Unable to locate IIS_Schema
#Event ID 36: Handle 'hSourceHandle' duplicated to 'hTargetHandle'
#Event ID 37: Unable to locate a site with SiteName 'SiteName'
#Event ID 39: The SiteId 'Id' has been assigned to more than one site
#Event ID 40: The SiteName 'SiteName' has been assigned to more than one site
#Event ID 41: Failed to instantiate 'ProgId' when attempting to populate dynamic configuration for 'Configuration'
#Event ID 42: Failed to initialize the 'ProviderName' encryption provider in 'PhysicalPath'
#Description
Failed to initialize the 'ProviderName' encryption provider in 'PhysicalPath'. Please check your configuration.
Message #
Fields #
| Name | Description |
|---|---|
PhysicalPath UnicodeString | |
FileConfigPath UnicodeString | |
ProviderName UnicodeString | |
ProviderType UnicodeString | |
Blob UnicodeString | |
ErrorType UInt32 | |
HRESULT HexInt32 |
Event ID 43: Failed to encrypt attribute 'ProviderType'
#Event ID 44: Failed to decrypt attribute 'ProviderType'
#Event ID 45: Unable to map 'ConfigPath' to the subpath of any known virtual directory
#Event ID 46: Virtual directory mapping from 'RelativeVirtualPath' to 'PhysicalPath' created
#Event ID 47: The location of the configuration file whose config path is 'ConfigPath' was mapped to 'Directory'
#Event ID 49: Config/child source file for configuration 'ConfigSourceFilePath' specified in 'PhysicalPath' is being loaded
#Event ID 50: Changes have successfully been committed to 'ConfigPath'.
#Message #
Fields #
| Name | Description |
|---|---|
ConfigPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"guid": "DC0B8E51-4863-407A-BC3C-1B479B2978AC",
"event_source_name": "",
"event_id": 50,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387904,
"time_created": "2026-03-13T20:06:38.758521+00:00",
"event_record_id": 2281,
"correlation": {},
"execution": {
"process_id": 2732,
"thread_id": 1444
},
"channel": "Microsoft-IIS-Configuration/Operational",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"ConfigPath": "MACHINE/WEBROOT/APPHOST"
},
"message": ""
}
Event ID 50: Changes have successfully been committed to 'ConfigPath'
#Fields #
| Name | Description |
|---|---|
ConfigPath UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-IIS-Configuration",
"event_id": 50,
"level": "Information",
"task": null,
"opcode": "Info",
"time_created": "2026-03-17T19:25:10.4723748+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-IIS-Configuration/Operational"
},
"event_data": {
"ConfigPath": "MACHINE/WEBROOT/APPHOST"
}
}
Event ID 51: Failed to commit changes to 'PhysicalPath' because file on the disk has been changed
#Event ID 52: Checking whether file 'PhysicalPath' has changed on the disk returned 'IsInMemoryViewOfFileRecent'
#Event ID 53: Unable to create a path mapping for the virtual directory, /system
#Description
Unable to create a path mapping for the virtual directory, /system.applicationHost/sites/site[@name='SiteName']/application[@path='ApplicationPath']/virtualDirectory[@path='VirtualDirectoryPath'] because the mapping with the relative virtual path, 'PhysicalPath' was already created for another virtual directory.
Message #
Fields #
| Name | Description |
|---|---|
SiteName UnicodeString | |
ApplicationPath UnicodeString | |
VirtualDirectoryPath UnicodeString | |
RelativeVirtualPath UnicodeString | |
PhysicalPath UnicodeString |
Event ID 54: A commit operation has been initiated
#Event ID 55: A commit operation has completed
#Event ID 56: A kernel transaction for a commit operation has been created
#Fields #
| Name | Description |
|---|---|
Handle Pointer | |
HRESULT HexInt32 |
Event ID 57: Failed to create a kernel transaction for the commit operation
#Event ID 60: A file write operation in a commit operation has been initiated
#Event ID 61: The contents of the file 'PhysicalPath' could not be erased
#Event ID 62: The contents of the file 'PhysicalPath' have successfully been erased
#Event ID 63: The new contents of the file 'PhysicalPath' could not be written to
#Event ID 64: A file write operation in a commit operation has completed
#Provenance
ETW provider GUID dc0b8e51-4863-407a-bc3c-1b479b2978ac
Defined in iisres.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB