Microsoft-Windows-Kerberos-KdcProxy
26 events across 1 channel
Event ID 1: Service stopped with a failure: error code ErrorCode.
#Event ID 2: Failed to initialize Group Policy: error code ErrorCode.
#Event ID 3: Failed to read Group Policy: error code ErrorCode.
#Event ID 4: Failed to start the HTTP service: error code ErrorCode.
#Event ID 5: Service failed to register UrlPrefix UrlPrefix: error code ErrorCode.
#Event ID 6: Service failed to start because system is not domain-joined: error code ErrorCode.
#Event ID 100: HttpReceiveHttpRequest API failed to receive an HTTP request from the network: error code ErrorCode.
#Event ID 101: Service failed to create a new IO object to service an HTTP request from the network: error code ErrorCode.
#Event ID 102: Failed to unpack PduType: error code ErrorCode.
#Event ID 103: Failed to locate a domain controller in domain TargetDomain with locator flags Flags: error code ErrorCode.
#Event ID 200: Retry (RetryNumber) connection to KDC in TargetDomain.
#Event ID 302: Initialized Group Policy successfully
#Description
Initialized Group Policy successfully.
Message #
Event ID 304: HTTP service started successfully
#Description
HTTP service started successfully.
Message #
Event ID 306: Rediscover KDC for domain TargetDomain.
#Event ID 307: Hash table was expanded from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
#Description
Hash table was expanded from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
BeginNonEmptyBuckets UInt32 | |
BeginTotalBuckets UInt32 | |
BeginTotalEntries UInt32 | |
NonEmptyBuckets UInt32 | |
TotalBuckets UInt32 | |
TotalEntries UInt32 | |
TimeSpent UInt32 |
Event ID 308: Hash table was contracted from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
#Description
Hash table was contracted from (BeginNonEmptyBuckets/BeginTotalBuckets buckets, BeginTotalEntries entries) to (NonEmptyBuckets/TotalBuckets buckets, TotalEntries entries) in TimeSpent milliseconds.
Message #
Fields #
| Name | Description |
|---|---|
BeginNonEmptyBuckets UInt32 | |
BeginTotalBuckets UInt32 | |
BeginTotalEntries UInt32 | |
NonEmptyBuckets UInt32 | |
TotalBuckets UInt32 | |
TotalEntries UInt32 | |
TimeSpent UInt32 |
Event ID 309: Rediscovered KDC KDCAddress(KDCName) for domain TargetDomain.
#Event ID 401: Client certificate is required to establish an HTTP connection
#Description
Client certificate is required to establish an HTTP connection.
Message #
Event ID 402: Client certificate is not valid to establish an HTTP connection: trust status TrustStatus.
#Event ID 403: The account (Domain: DomainName, User: UserName) has NumerOfFailures password failures.
#Event ID 404: The account (Domain: DomainName, User: UserName) is rejected due to the usage of an unarmored Kerberos message.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID d3f8787e-656f-4876-9ebd-6f5e3cb0a45b
Defined in kpssvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3807, captured 2026-06-02