Microsoft-Windows-Mprddm
| Event | Title | Channel | Sample | Rule |
|---|---|---|---|---|
| 0 | Used for debugging purposes | Operational | N | N |
| 1 | Connect Notification for a VPN connection | Operational | N | N |
| 2 | Disconnect Notification for a VPN connection | Operational | N | N |
| 1001 | Unable to get DHCP address | Operational | N | N |
| 1002 | Able to get DHCP address | Operational | N | N |
| 1003 | No static IP address available | Operational | N | N |
| 1004 | Very few static IP addresses available | Operational | N | N |
| 1005 | Static IP addresses available | Operational | N | N |
| 1006 | WAN Miniports not available | Operational | N | N |
| 1007 | WAN Miniports available | Operational | N | N |
| 1008 | All ports exhausted | Operational | N | N |
| 1009 | Very few ports available | Operational | N | N |
| 1010 | Ports available | Operational | N | N |
Event ID 1: Connect Notification for a VPN connection
#Fields #
| Name | Description |
|---|---|
connectionID Pointer | |
userName UnicodeString | |
remoteIPv4Address UnicodeString | |
remoteIPv6Address UnicodeString | |
ispAddress UnicodeString | |
deviceType UInt32 | |
tunnelType UnicodeString | |
portName UnicodeString | |
authenticationProtocol UInt32 | |
authenticationData UInt32 | |
eapTypeId UInt32 | |
embeddedEapTypeId UInt32 | |
quarantineState UInt32 | |
connectionStartTime FILETIME | |
isS2SConnection UInt32 | |
routingDomainId GUID |
Event ID 2: Disconnect Notification for a VPN connection
#Fields #
| Name | Description |
|---|---|
connectionID Pointer | |
userName UnicodeString | |
remoteIPv4Address UnicodeString | |
remoteIPv6Address UnicodeString | |
ispAddress UnicodeString | |
portName UnicodeString | |
bytesIn UInt64 | |
bytesOut UInt64 | |
disconnectTime FILETIME | |
isS2SConnection UInt32 |
Event ID 1001: Unable to get DHCP address
#Event ID 1002: Able to get DHCP address
#Event ID 1003: No static IP address available
#Event ID 1004: Very few static IP addresses available
#Event ID 1005: Static IP addresses available
#Event ID 1006: WAN Miniports not available
#Event ID 1007: WAN Miniports available
#Event ID 1008: All ports exhausted
#Event ID 1009: Very few ports available
#Event ID 1010: Ports available
#Provenance
ETW provider GUID 3a5bef13-d0f7-4e7f-9ec8-5e707df711d0
Defined in mprddm.dll, which carries the event manifest.
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB