Microsoft-Windows-IIS-IisMetabaseAudit

13 events across 1 channel

EventTitleChannelSample
4500Metabase Add Key.OperationalN
4501Metabase Delete Key.OperationalN
4502Metabase Delete Child Keys.OperationalN
4503Metabase Copy Key.OperationalN
4504Metabase Rename Key.OperationalN
4505Metabase Set Data.OperationalN
4506Metabase Delete Data.OperationalN
4507Metabase Delete All Data.OperationalN
4508Metabase Copy Data.OperationalN
4509Metabase Set Last Change Time.OperationalN
4510Metabase Restore.OperationalN
4511Metabase Delete Backup.OperationalN
4512Metabase Import.OperationalN

Event ID 4500: Metabase Add Key.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Add Key.

Message #

Metabase Add Key.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4501: Metabase Delete Key.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Delete Key.

Message #

Metabase Delete Key.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4502: Metabase Delete Child Keys.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Delete Child Keys.

Message #

Metabase Delete Child Keys.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4503: Metabase Copy Key.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Copy Key.

Message #

Metabase Copy Key.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Source Path: %4
 Destination Path: %5
 Caller PID: %6
 Caller Image Path: %7
 Result: %8

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabaseSourcePath UnicodeString
MetabaseDestinationPath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4504: Metabase Rename Key.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Rename Key.

Message #

Metabase Rename Key.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Source Path: %4
 New Key Name: %5
 Caller PID: %6
 Caller Image Path: %7
 Result: %8

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabaseSourcePath UnicodeString
NewKeyName UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4505: Metabase Set Data.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Set Data.

Message #

Metabase Set Data.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Property ID: %5
 Property Name: %6
 Old Value: %7
 New Value: %8
 Caller PID: %9
 Caller Image Path: %10
 Result: %11

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
PropertyID UnicodeString
PropertyName UnicodeString
OldValue UnicodeString
NewValue UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4506: Metabase Delete Data.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Delete Data.

Message #

Metabase Delete Data.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Property ID: %5
 Property Name: %6
 Old Value: %7
 Caller PID: %8
 Caller Image Path: %9
 Result: %10

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
PropertyID UnicodeString
PropertyName UnicodeString
OldValue UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4507: Metabase Delete All Data.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Delete All Data.

Message #

Metabase Delete All Data.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4508: Metabase Copy Data.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Copy Data.

Message #

Metabase Copy Data.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Source Path: %4
 Destination Path: %5
 Caller PID: %6
 Caller Image Path: %7
 Result: %8

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabaseSourcePath UnicodeString
MetabaseDestinationPath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4509: Metabase Set Last Change Time.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Set Last Change Time.

Message #

Metabase Set Last Change Time.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Path: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabasePath UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4510: Metabase Restore.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Restore.

Message #

Metabase Restore.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Name of Backup: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
BackupName UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4511: Metabase Delete Backup.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Delete Backup.

Message #

Metabase Delete Backup.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Name of Backup: %4
 Caller PID: %5
 Caller Image Path: %6
 Result: %7

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
BackupName UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Event ID 4512: Metabase Import.

#
Provider
Microsoft-Windows-IIS-IisMetabaseAudit
Channel
Operational

Description

Metabase Import.

Message #

Metabase Import.
 
 Primary User Name: %1
 Primary User Domain: %2
 Primary Logon ID: %3
 Source Path: %4
 Destination Path: %5
 Filename: %6
 Caller PID: %7
 Caller Image Path: %8
 Result: %9

Fields #

NameDescription
UserName UnicodeString
Domain UnicodeString
LogonID UnicodeString
MetabaseSourcePath UnicodeString
MetabaseDestinationPath UnicodeString
ImportFileName UnicodeString
CallerPID UnicodeString
CallerImagePath UnicodeString
Result UnicodeString

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID bbb924b8-f415-4f57-aa45-1007f704c9b1

Defined in iisres.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02

Downloads