Microsoft-Windows-IPSEC-SRV
30 events across 1 channel
Event ID 101: StartServiceStart
#Event ID 102: StartServiceStop
#Event ID 103: StopServiceStart
#Event ID 104: StopServiceStop
#Event ID 105: ApplyDomainPolicyStart
#Event ID 106: ApplyDomainPolicyStop
#Event ID 107: IPSEC_BFE_EngineOpenStart
#Event ID 108: IPSEC_BFE_EngineOpenStop
#Event ID 109: IPSEC_BFE_EngineCloseStart
#Event ID 110: IPSEC_BFE_EngineCloseStop
#Event ID 111: IPSEC_BFE_TransactionBeginStart
#Event ID 112: IPSEC_BFE_TransactionBeginStop
#Event ID 113: IPSEC_BFE_TransactionCommitStart
#Event ID 114: IPSEC_BFE_TransactionCommitStop
#Event ID 115: IPSEC_BFE_TransactionAbortStart
#Event ID 116: IPSEC_BFE_TransactionAbortStop
#Event ID 117: IPSEC_BFE_ProviderContextAddStart
#Event ID 118: IPSEC_BFE_ProviderContextAddStop
#Event ID 119: IPSEC_BFE_ProviderContextDeleteByKeyStart
#Event ID 120: IPSEC_BFE_ProviderContextDeleteByKeyStop
#Event ID 121: IPSEC_BFE_FilterAddStart
#Event ID 122: IPSEC_BFE_FilterAddStop
#Event ID 123: IPSEC_BFE_FilterDeleteByKeyStart
#Event ID 124: IPSEC_BFE_FilterDeleteByKeyStop
#Event ID 125: IPSEC_BFE_IPsecTunnelAddStart
#Event ID 126: IPSEC_BFE_IPsecTunnelAddStop
#Event ID 127: ApplyLocalPolicyStart
#Event ID 128: ApplyLocalPolicyStop
#Event ID 129: ApplyCachePolicyStart
#Event ID 130: ApplyCachePolicyStop
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID c91ef675-842f-4fcf-a5c9-6ea93f2e4f8b
Defined in ipsecsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02