Microsoft-Windows-MiStreamProvider
49 events across 2 channels
Event ID 1011: Collect error.
#Event ID 1014: Collect pipeline error.
#Event ID 1015: Collect pipeline OnComplete started.
#Description
Collect pipeline OnComplete started.
Message #
Event ID 1016: Collect pipeline OnComplete stopped.
#Description
Collect pipeline OnComplete stopped.
Message #
Event ID 1017: Collect pipeline OnNext started.
#Description
Collect pipeline OnNext started.
Message #
Event ID 1018: Collect pipeline OnNext stopped.
#Description
Collect pipeline OnNext stopped.
Message #
Event ID 1019: Collect pipeline release started.
#Description
Collect pipeline release started.
Message #
Event ID 1020: Collect pipeline release stopped.
#Description
Collect pipeline release stopped.
Message #
Event ID 1031: Push error.
#Event ID 1034: Push pipeline error.
#Event ID 1041: Flush error.
#Event ID 1052: Connection info.
#Event ID 1053: Getting filename for KVP write.
#Event ID 1054: Filename for KVP write: message.
#Event ID 1055: Cleaning up cached files older than result days.
#Event ID 1056: Deleting cached file: message.
#Event ID 1057: Data is being collected locally because the Target URI and/or Certificate Thumbprint is not set.
#Description
Data is being collected locally because the Target URI and/or Certificate Thumbprint is not set.
Message #
Event ID 1060: Creating pipeline from .
#Event ID 1504: Failed to enumerate directory to upload.
#Description
Failed to enumerate directory to upload.
Message #
Event ID 1505: Failed to read file.
#Event ID 1506: Failed to add headers to HTTP request.
#Event ID 1507: Failed to load certificates.
#Event ID 1508: Failed to send Http request.
#Event ID 1509: Failed to delete file.
#Event ID 1510: Invalid status received from server.
#Event ID 1511: callback status request error.
#Event ID 1512: Failed to write file stream.
#Event ID 1513: Cannot use the client certificate specified.
#Description
Cannot use the client certificate specified. Error: Certificate expired.
Message #
Event ID 1514: One or more errors were found in the Secure Sockets Layer (SSL) certificate sent by the server.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 018c05b7-0e3b-4c5a-9ab2-553ba1489332
Defined in mistreamprov.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02