Microsoft-Windows-LinkLayerDiscoveryProtocol
Event ID 10000: The Link Layer Discovery Protocol driver (LLDP) is starting
#Event ID 10001: The Link Layer Discovery Protocol driver (LLDP) is stopping
#Event ID 10020: The local MIB on interface IfIndex has been updated.
#Event ID 10021: An update to the local MIB on interface IfIndex was rejected.
#Event ID 10030: The parameter AdminParameter on interface IfIndex has been changed.
#Event ID 10040: An LLDP frame was transmitted on interface IfIndex.
#Event ID 10041: An LLDP frame was received on interface IfIndex.
#Event ID 10042: An LLDP frame received on interface IfIndex was rejected.
#Event ID 10043: An LLDP frame was successfully validated on interface IfIndex.
#Event ID 10050: A new neighbor was discovered on interface Neighbor_ID.
#Event ID 10051: The neighbor on interface Neighbor_ID has updated its MIB.
#Event ID 10052: The neighbor on interface Neighbor_ID was removed because no message has been received within the timeout interval.
#Event ID 10053: The neighbor on interface Neighbor_ID was removed because a shutdown message was received.
#Event ID 10060: The system has detected that there are multiple neighbors sending LLDP packets to the network interface IfIndex.
#Event ID 10062: A message was received on interface Existing_Neighbor_ID from an unknown neighbor, while the previously-detected neighbor is still active.
#Description
A message was received on interface Existing_Neighbor_ID from an unknown neighbor, while the previously-detected neighbor is still active. This will prolong the "tooManyNeighbors" state.
Message #
Fields #
| Name | Description |
|---|---|
IfIndex UInt32 | |
ExistingMsapIdLength UInt32 | |
ExistingMsapId Binary | |
ReceivedMsapIdLength UInt32 | |
ReceivedMsapId Binary |
Event ID 60001: Error: {ErrorCode} Location: {Location} Context: {Context}.
#Fields #
| Name | Description |
|---|---|
ErrorCode | |
Location | |
Context |
Event ID 60002: Warning: {WarningCode} Location: {Location} Context: {Context}.
#Fields #
| Name | Description |
|---|---|
WarningCode | |
Location | |
Context |
Event ID 60003: Transitioned to State: {NextState} Context: {Context}.
#Fields #
| Name | Description |
|---|---|
NextState | |
Context |
Event ID 60004: Updated Context: {Context} Update Reason: {UpdateReasonCode}.
#Fields #
| Name | Description |
|---|---|
Context | |
UpdateReasonCode |
Event ID 60101: SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Prot...
#Description
SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress | |
SourcePort | |
DestinationAddress | |
DestinationPort | |
Protocol | Known values
|
ReferenceContext |
Event ID 60102: SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Prot...
#Description
SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress | |
SourcePort | |
DestinationAddress | |
DestinationPort | |
Protocol | Known values
|
ReferenceContext |
Provenance
ETW provider GUID dcbfb8f0-cd19-4f1c-a27d-23ac706ded72
Defined in mslldp.sys, the binary that emits these events.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB