Microsoft-Windows-LinkLayerDiscoveryProtocol

EventTitleChannelSampleRule
10000The Link Layer Discovery Protocol driver (LLDP) is startingOperationalNN
10001The Link Layer Discovery Protocol driver (LLDP) is stoppingOperationalNN
10010The interface IfIndex is enabled.OperationalNN
10011The interface IfIndex is disabled.OperationalNN
10020The local MIB on interface IfIndex has been updated.DiagnosticNN
10021An update to the local MIB on interface IfIndex was rejected.DiagnosticNN
10030The parameter AdminParameter on interface IfIndex has been changed.DiagnosticNN
10040An LLDP frame was transmitted on interface IfIndex.DiagnosticNN
10041An LLDP frame was received on interface IfIndex.DiagnosticNN
10042An LLDP frame received on interface IfIndex was rejected.DiagnosticNN
10043An LLDP frame was successfully validated on interface IfIndex.DiagnosticNN
10050A new neighbor was discovered on interface Neighbor_ID.OperationalNN
10051The neighbor on interface Neighbor_ID has updated its MIB.DiagnosticNN
10052The neighbor on interface Neighbor_ID was removed because no message has been …OperationalNN
10053The neighbor on interface Neighbor_ID was removed because a shutdown message was …OperationalNN
10060The system has detected that there are multiple neighbors sending LLDP packets …OperationalNN
10061The "tooManyNeighbors" state has been clearedOperationalNN
10062A message was received on interface Existing_Neighbor_ID from an unknown …DiagnosticNN
60001Error: {ErrorCode} Location: {Location} Context: {Context}.DiagnosticNN
60002Warning: {WarningCode} Location: {Location} Context: {Context}.DiagnosticNN
60003Transitioned to State: {NextState} Context: {Context}.DiagnosticNN
60004Updated Context: {Context} Update Reason: {UpdateReasonCode}.DiagnosticNN
60101SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: …DiagnosticNN
60102SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: …DiagnosticNN
60103Interface Guid: {IfGuid} IfIndex: {IfIndex} Interface Luid: {IfLuid} …DiagnosticNN

Event ID 10000: The Link Layer Discovery Protocol driver (LLDP) is starting

#
Channel
Operational

Event ID 10001: The Link Layer Discovery Protocol driver (LLDP) is stopping

#
Channel
Operational

Event ID 10010: The interface IfIndex is enabled.

#
Channel
Operational

Message #

The interface %1 is enabled

Fields #

NameDescription
IfIndex UInt32

Event ID 10011: The interface IfIndex is disabled.

#
Channel
Operational

Message #

The interface %1 is disabled

Fields #

NameDescription
IfIndex UInt32

Event ID 10020: The local MIB on interface IfIndex has been updated.

#
Channel
Diagnostic

Message #

The local MIB on interface %1 has been updated

Fields #

NameDescription
IfIndex UInt32

Event ID 10021: An update to the local MIB on interface IfIndex was rejected.

#
Channel
Diagnostic

Message #

An update to the local MIB on interface %1 was rejected

Fields #

NameDescription
IfIndex UInt32
RejectReason UInt32

Event ID 10030: The parameter AdminParameter on interface IfIndex has been changed.

#
Channel
Diagnostic

Message #

The parameter %2 on interface %1 has been changed

Fields #

NameDescription
IfIndex UInt32
AdminParameter UInt32
OldValue UInt32
NewValue UInt32

Event ID 10040: An LLDP frame was transmitted on interface IfIndex.

#
Channel
Diagnostic

Message #

An LLDP frame was transmitted on interface %1

Fields #

NameDescription
IfIndex UInt32
PacketPayloadLength UInt32
PacketPayload Binary

Event ID 10041: An LLDP frame was received on interface IfIndex.

#
Channel
Diagnostic

Message #

An LLDP frame was received on interface %1

Fields #

NameDescription
IfIndex UInt32
SequenceNumber UInt32
PacketPayloadLength UInt32
PacketPayload Binary

Event ID 10042: An LLDP frame received on interface IfIndex was rejected.

#
Channel
Diagnostic

Message #

An LLDP frame received on interface %1 was rejected.
%2

Fields #

NameDescription
IfIndex UInt32
SequenceNumber UInt32
PacketDiscardReason UInt32

Event ID 10043: An LLDP frame was successfully validated on interface IfIndex.

#
Channel
Diagnostic

Message #

An LLDP frame was successfully validated on interface %1

Fields #

NameDescription
IfIndex UInt32
SequenceNumber UInt32

Event ID 10050: A new neighbor was discovered on interface Neighbor_ID.

#
Channel
Operational

Message #

A new neighbor was discovered on interface %1
Neighbor ID: %3

Fields #

NameDescription
IfIndex UInt32
MsapIdLength UInt32
MsapId Binary

Event ID 10051: The neighbor on interface Neighbor_ID has updated its MIB.

#
Channel
Diagnostic

Message #

The neighbor on interface %1 has updated its MIB
Neighbor ID: %3

Fields #

NameDescription
IfIndex UInt32
MsapIdLength UInt32
MsapId Binary

Event ID 10052: The neighbor on interface Neighbor_ID was removed because no message has been received within the timeout interval.

#
Channel
Operational

Message #

The neighbor on interface %1 was removed because no message has been received within the timeout interval
Neighbor ID: %3

Fields #

NameDescription
IfIndex UInt32
MsapIdLength UInt32
MsapId Binary

Event ID 10053: The neighbor on interface Neighbor_ID was removed because a shutdown message was received.

#
Channel
Operational

Message #

The neighbor on interface %1 was removed because a shutdown message was received
Neighbor ID: %3

Fields #

NameDescription
IfIndex UInt32
MsapIdLength UInt32
MsapId Binary

Event ID 10060: The system has detected that there are multiple neighbors sending LLDP packets to the network interface IfIndex.

#
Channel
Operational

Description

The system has detected that there are multiple neighbors sending LLDP packets to the network interface IfIndex. A "tooManyNeighbors" state has been declared. This may inhibit some network operations.

Message #

The system has detected that there are multiple neighbors sending LLDP packets to the network interface %1.  A "tooManyNeighbors" state has been declared.  This may inhibit some network operations.

Fields #

NameDescription
IfIndex UInt32

Event ID 10061: The "tooManyNeighbors" state has been cleared

#
Channel
Operational

Fields #

NameDescription
IfIndex UInt32

Event ID 10062: A message was received on interface Existing_Neighbor_ID from an unknown neighbor, while the previously-detected neighbor is still active.

#
Channel
Diagnostic

Description

A message was received on interface Existing_Neighbor_ID from an unknown neighbor, while the previously-detected neighbor is still active. This will prolong the "tooManyNeighbors" state.

Message #

A message was received on interface %1 from an unknown neighbor, while the previously-detected neighbor is still active.  This will prolong the "tooManyNeighbors" state.
Existing Neighbor ID: %3
Recived Neighbor ID: %5

Fields #

NameDescription
IfIndex UInt32
ExistingMsapIdLength UInt32
ExistingMsapId Binary
ReceivedMsapIdLength UInt32
ReceivedMsapId Binary

Event ID 60001: Error: {ErrorCode} Location: {Location} Context: {Context}.

#
Channel
Diagnostic

Fields #

NameDescription
ErrorCode
Location
Context

Event ID 60002: Warning: {WarningCode} Location: {Location} Context: {Context}.

#
Channel
Diagnostic

Fields #

NameDescription
WarningCode
Location
Context

Event ID 60003: Transitioned to State: {NextState} Context: {Context}.

#
Channel
Diagnostic

Fields #

NameDescription
NextState
Context

Event ID 60004: Updated Context: {Context} Update Reason: {UpdateReasonCode}.

#
Channel
Diagnostic

Fields #

NameDescription
Context
UpdateReasonCode

Event ID 60101: SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Prot...

#
Channel
Diagnostic

Description

SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}.

Message #

SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}

Fields #

NameDescription
SourceAddress
SourcePort
DestinationAddress
DestinationPort
Protocol
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext

Event ID 60102: SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Prot...

#
Channel
Diagnostic

Description

SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}.

Message #

SourceAddress: {SourceAddress} SourcePort: {SourcePort} DestinationAddress: {DestinationAddress} DestinationPort: {DestinationPort} Protocol: {Protocol} ReferenceContext: {ReferenceContext}

Fields #

NameDescription
SourceAddress
SourcePort
DestinationAddress
DestinationPort
Protocol
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext

Event ID 60103: Interface Guid: {IfGuid} IfIndex: {IfIndex} Interface Luid: {IfLuid} ReferenceContext: {ReferenceContext}.

#
Channel
Diagnostic

Fields #

NameDescription
IfGuid
IfIndex
IfLuid
ReferenceContext

Provenance

ETW provider GUID dcbfb8f0-cd19-4f1c-a27d-23ac706ded72

Defined in mslldp.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB