Microsoft-Windows-Mprddm

13 events across 1 channel

Event ID 0: Used for debugging purposes

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Used for debugging purposes.

Message #

Used for debugging purposes

Fields #

NameDescription
debugString UnicodeString

Event ID 1: Connect Notification for a VPN connection

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Connect Notification for a VPN connection.

Message #

Connect Notification for a VPN connection

Fields #

NameDescription
connectionID Pointer
userName UnicodeString
remoteIPv4Address UnicodeString
remoteIPv6Address UnicodeString
ispAddress UnicodeString
deviceType UInt32
tunnelType UnicodeString
portName UnicodeString
authenticationProtocol UInt32
authenticationData UInt32
eapTypeId UInt32
embeddedEapTypeId UInt32
quarantineState UInt32
connectionStartTime FILETIME
isS2SConnection UInt32
routingDomainId GUID

Event ID 2: Disconnect Notification for a VPN connection

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Disconnect Notification for a VPN connection.

Message #

Disconnect Notification for a VPN connection

Fields #

NameDescription
connectionID Pointer
userName UnicodeString
remoteIPv4Address UnicodeString
remoteIPv6Address UnicodeString
ispAddress UnicodeString
portName UnicodeString
bytesIn UInt64
bytesOut UInt64
disconnectTime FILETIME
isS2SConnection UInt32

Event ID 1001: Unable to get DHCP address

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Unable to get DHCP address.

Message #

Unable to get DHCP address

Event ID 1002: Able to get DHCP address

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Able to get DHCP address.

Message #

Able to get DHCP address

Event ID 1003: No static IP address available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

No static IP address available.

Message #

No static IP address available

Event ID 1004: Very few static IP addresses available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Very few static IP addresses available.

Message #

Very few static IP addresses available

Event ID 1005: Static IP addresses available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Static IP addresses available.

Message #

Static IP addresses available

Event ID 1006: WAN Miniports not available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

WAN Miniports not available.

Message #

WAN Miniports not available

Event ID 1007: WAN Miniports available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

WAN Miniports available.

Message #

WAN Miniports available

Event ID 1008: All ports exhausted

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

All ports exhausted.

Message #

All ports exhausted

Event ID 1009: Very few ports available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Very few ports available.

Message #

Very few ports available

Event ID 1010: Ports available

#
Provider
Microsoft-Windows-Mprddm
Channel
Operational

Description

Ports available.

Message #

Ports available

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 3a5bef13-d0f7-4e7f-9ec8-5e707df711d0

Defined in mprddm.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads