Microsoft-Windows-MPS-SRV
277 events across 1 channel
Event ID 101: StartServiceStart
#Event ID 102: StartServiceStop
#Event ID 103: StopServiceStart
#Event ID 104: StopServiceStop
#Event ID 105: Audit_InitializeStart
#Event ID 106: Audit_InitializeStop
#Event ID 107: Audit_ShutdownStart
#Event ID 108: Audit_ShutdownStop
#Event ID 113: AuthApps_InitializeStart
#Event ID 114: AuthApps_InitializeStop
#Event ID 115: AuthApps_ShutdownStart
#Event ID 116: AuthApps_ShutdownStop
#Event ID 117: Notify_InitializeStart
#Event ID 118: Notify_InitializeStop
#Event ID 119: Notify_ShutdownStart
#Event ID 120: Notify_ShutdownStop
#Event ID 121: DynPorts_InitializeStart
#Event ID 122: DynPorts_InitializeStop
#Event ID 123: DynPorts_ShutdownStart
#Event ID 124: DynPorts_ShutdownStop
#Event ID 125: ChangeSource_InitializeStart
#Event ID 126: ChangeSource_InitializeStop
#Event ID 127: ChangeSource_ShutdownStart
#Event ID 128: ChangeSource_ShutdownStop
#Event ID 129: Writer_InitializeStart
#Event ID 130: Writer_InitializeStop
#Event ID 131: Writer_ShutdownStart
#Event ID 132: Writer_ShutdownStop
#Event ID 133: Logger_InitializeStart
#Event ID 134: Logger_InitializeStop
#Event ID 135: Logger_ShutdownStart
#Event ID 136: Logger_ShutdownStop
#Event ID 137: DynDataNLA1stPhase_InitializeStart
#Event ID 138: DynDataNLA1stPhase_InitializeStop
#Event ID 139: DynDataNLA1stPhase_ShutdownStart
#Event ID 140: DynDataNLA1stPhase_ShutdownStop
#Event ID 141: ProfileMgr_InitializeStart
#Event ID 142: ProfileMgr_InitializeStop
#Event ID 143: ProfileMgr_ShutdownStart
#Event ID 144: ProfileMgr_ShutdownStop
#Event ID 145: Upcall2ndPhase_InitializeStart
#Event ID 146: Upcall2ndPhase_InitializeStop
#Event ID 147: Upcall2ndPhase_ShutdownStart
#Event ID 148: Upcall2ndPhase_ShutdownStop
#Event ID 149: RpcAPIs_InitializeStart
#Event ID 150: RpcAPIs_InitializeStop
#Event ID 151: RpcAPIs_ShutdownStart
#Event ID 152: RpcAPIs_ShutdownStop
#Event ID 153: ResrcIndicationAPIs_InitializeStart
#Event ID 154: ResrcIndicationAPIs_InitializeStop
#Event ID 155: ResrcIndicationAPIs_ShutdownStart
#Event ID 156: ResrcIndicationAPIs_ShutdownStop
#Event ID 157: GPMon_InitializeStart
#Event ID 158: GPMon_InitializeStop
#Event ID 159: GPMon_ShutdownStart
#Event ID 160: GPMon_ShutdownStop
#Event ID 161: DynDataNLA2ndPhase_InitializeStart
#Event ID 162: DynDataNLA2ndPhase_InitializeStop
#Event ID 163: DynDataNLA2ndPhase_ShutdownStart
#Event ID 164: DynDataNLA2ndPhase_ShutdownStop
#Event ID 165: ServiceSignalReadyStart
#Event ID 166: ServiceSignalReadyStop
#Event ID 167: Empty_ShutdownStart
#Event ID 168: Empty_ShutdownStop
#Event ID 169: Products_InitializeStart
#Event ID 170: Products_InitializeStop
#Event ID 171: Products_ShutdownStart
#Event ID 172: Products_ShutdownStop
#Event ID 173: HttpProxy_InitializeStart
#Event ID 174: HttpProxy_InitializeStop
#Event ID 175: HttpProxy_ShutdownStart
#Event ID 176: HttpProxy_ShutdownStop
#Event ID 177: AdhSitesSubnets_InitializeStart
#Event ID 178: AdhSitesSubnets_InitializeStop
#Event ID 179: AdhSitesSubnets_ShutdownStart
#Event ID 180: AdhSitesSubnets_ShutdownStop
#Event ID 181: Moneis_InitializeStart
#Event ID 182: Moneis_InitializeStop
#Event ID 183: Moneis_ShutdownStart
#Event ID 184: Moneis_ShutdownStop
#Event ID 185: MoneisRegistrationApiPhase2_InitializeStart
#Event ID 186: MoneisRegistrationApiPhase2_InitializeStop
#Event ID 187: MoneisRegistrationApiPhase2_ShutdownStart
#Event ID 188: MoneisRegistrationApiPhase2_ShutdownStop
#Event ID 189: DynDataNLA0thPhase_InitializeStart
#Event ID 190: DynDataNLA0thPhase_InitializeStop
#Event ID 191: DynDataNLA0thPhase_ShutdownStart
#Event ID 192: DynDataNLA0thPhase_ShutdownStop
#Event ID 193: CallbacksFromBfe_InitializeStart
#Event ID 194: CallbacksFromBfe_InitializeStop
#Event ID 195: CallbacksFromBfe_ShutdownStart
#Event ID 196: CallbacksFromBfe_ShutdownStop
#Event ID 200: MPS_SVC_API_RestoreDefaultsStart
#Event ID 201: MPS_SVC_API_RestoreDefaultsStop
#Event ID 202: MPS_SVC_API_EnumFirewallRulesStart
#Event ID 203: MPS_SVC_API_EnumFirewallRulesStop
#Event ID 204: MPS_SVC_API_DeleteFirewallRuleStart
#Event ID 205: MPS_SVC_API_DeleteFirewallRuleStop
#Event ID 206: MPS_SVC_API_DeleteAllFirewallRulesStart
#Event ID 207: MPS_SVC_API_DeleteAllFirewallRulesStop
#Event ID 208: MPS_SVC_API_AddFirewallRuleStart
#Event ID 209: MPS_SVC_API_AddFirewallRuleStop
#Event ID 210: MPS_SVC_API_SetFirewallRuleStart
#Event ID 211: MPS_SVC_API_SetFirewallRuleStop
#Event ID 212: MPS_SVC_API_GetConfigStart
#Event ID 213: MPS_SVC_API_GetConfigStop
#Event ID 214: MPS_SVC_API_SetConfigStart
#Event ID 215: MPS_SVC_API_SetConfigStop
#Event ID 216: MPS_SVC_API_GetGlobalConfigStart
#Event ID 217: MPS_SVC_API_GetGlobalConfigStop
#Event ID 218: MPS_SVC_API_SetGlobalConfigStart
#Event ID 219: MPS_SVC_API_SetGlobalConfigStop
#Event ID 220: MPS_SVC_API_OpenPolicyStoreStart
#Event ID 221: MPS_SVC_API_OpenPolicyStoreStop
#Event ID 222: MPS_SVC_API_ClosePolicyStoreStart
#Event ID 223: MPS_SVC_API_ClosePolicyStoreStop
#Event ID 224: MPS_SVC_API_AddConnectionSecurityRuleStart
#Event ID 225: MPS_SVC_API_AddConnectionSecurityRuleStop
#Event ID 226: MPS_SVC_API_SetConnectionSecurityRuleStart
#Event ID 227: MPS_SVC_API_SetConnectionSecurityRuleStop
#Event ID 228: MPS_SVC_API_DeleteConnectionSecurityRuleStart
#Event ID 229: MPS_SVC_API_DeleteConnectionSecurityRuleStop
#Event ID 230: MPS_SVC_API_DeleteAllConnectionSecurityRulesStart
#Event ID 231: MPS_SVC_API_DeleteAllConnectionSecurityRulesStop
#Event ID 232: MPS_SVC_API_EnumConnectionSecurityRulesStart
#Event ID 233: MPS_SVC_API_EnumConnectionSecurityRulesStop
#Event ID 234: MPS_SVC_API_AddAuthenticationSetStart
#Event ID 235: MPS_SVC_API_AddAuthenticationSetStop
#Event ID 236: MPS_SVC_API_DeleteAuthenticationSetStart
#Event ID 237: MPS_SVC_API_DeleteAuthenticationSetStop
#Event ID 238: MPS_SVC_API_SetAuthenticationSetStart
#Event ID 239: MPS_SVC_API_SetAuthenticationSetStop
#Event ID 240: MPS_SVC_API_DeleteAllAuthenticationSetsStart
#Event ID 241: MPS_SVC_API_DeleteAllAuthenticationSetsStop
#Event ID 242: MPS_SVC_API_EnumAuthenticationSetsStart
#Event ID 243: MPS_SVC_API_EnumAuthenticationSetsStop
#Event ID 244: MPS_SVC_API_AddCryptoSetStart
#Event ID 245: MPS_SVC_API_AddCryptoSetStop
#Event ID 246: MPS_SVC_API_SetCryptoSetStart
#Event ID 247: MPS_SVC_API_SetCryptoSetStop
#Event ID 248: MPS_SVC_API_DeleteCryptoSetStart
#Event ID 249: MPS_SVC_API_DeleteCryptoSetStop
#Event ID 250: MPS_SVC_API_DeleteAllCryptoSetsStart
#Event ID 251: MPS_SVC_API_DeleteAllCryptoSetsStop
#Event ID 252: MPS_SVC_API_EnumCryptoSetsStart
#Event ID 253: MPS_SVC_API_EnumCryptoSetsStop
#Event ID 254: MPS_SVC_API_EnumPhase1SAsStart
#Event ID 255: MPS_SVC_API_EnumPhase1SAsStop
#Event ID 256: MPS_SVC_API_DeletePhase1SAsStart
#Event ID 257: MPS_SVC_API_DeletePhase1SAsStop
#Event ID 258: MPS_SVC_API_EnumPhase2SAsStart
#Event ID 259: MPS_SVC_API_EnumPhase2SAsStop
#Event ID 260: MPS_SVC_API_DeletePhase2SAsStart
#Event ID 261: MPS_SVC_API_DeletePhase2SAsStop
#Event ID 262: MPS_SVC_API_NotifyUnsupportedAttemptStart
#Event ID 263: MPS_SVC_API_NotifyUnsupportedAttemptStop
#Event ID 264: MPS_SVC_API_RegisterProductStart
#Event ID 265: MPS_SVC_API_RegisterProductStop
#Event ID 266: MPS_SVC_API_UnregisterProductStart
#Event ID 267: MPS_SVC_API_UnregisterProductStop
#Event ID 268: MPS_SVC_API_EnumProductsStart
#Event ID 269: MPS_SVC_API_EnumProductsStop
#Event ID 270: MPS_SVC_API_AddMainModeRuleStart
#Event ID 271: MPS_SVC_API_AddMainModeRuleStop
#Event ID 272: MPS_SVC_API_SetMainModeRuleStart
#Event ID 273: MPS_SVC_API_SetMainModeRuleStop
#Event ID 274: MPS_SVC_API_DeleteMainModeRuleStart
#Event ID 275: MPS_SVC_API_DeleteMainModeRuleStop
#Event ID 276: MPS_SVC_API_DeleteAllMainModeRulesStart
#Event ID 277: MPS_SVC_API_DeleteAllMainModeRulesStop
#Event ID 278: MPS_SVC_API_EnumMainModeRulesStart
#Event ID 279: MPS_SVC_API_EnumMainModeRulesStop
#Event ID 280: MPS_SVC_API_QueryFirewallRulesStart
#Event ID 281: MPS_SVC_API_QueryFirewallRules
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-MPS-SRV",
"guid": "{5444519F-2484-45A2-991E-953E4B54C8E0}",
"event_source_name": "",
"event_id": 281,
"version": 0,
"level": 4,
"task": 279,
"opcode": 2,
"keywords": "0x0000000000010000",
"time_created": "2026-06-02T05:58:43.577+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 1520,
"thread_id": 13852
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "MPS_SVC_API_QueryFirewallRules"
}
Event ID 282: MPS_SVC_API_QueryConnectionSecurityRulesStart
#Event ID 283: MPS_SVC_API_QueryConnectionSecurityRulesStop
#Event ID 284: MPS_SVC_API_QueryMainModeRulesStart
#Event ID 285: MPS_SVC_API_QueryMainModeRulesStop
#Event ID 286: MPS_SVC_API_QueryAuthenticationSetsStart
#Event ID 287: MPS_SVC_API_QueryAuthenticationSetsStop
#Event ID 288: MPS_SVC_API_QueryCryptoSetsStart
#Event ID 289: MPS_SVC_API_QueryCryptoSetsStop
#Event ID 290: DynamicKeywordMgr_InitializeStart
#Event ID 291: DynamicKeywordMgr_InitializeStop
#Event ID 292: DynamicKeywordMgr_ShutdownStart
#Event ID 293: DynamicKeywordMgr_ShutdownStop
#Event ID 294: TenantRestrictions_InitializeStart
#Event ID 295: TenantRestrictions_InitializeStop
#Event ID 296: TenantRestrictions_ShutdownStart
#Event ID 297: TenantRestrictions_ShutdownStop
#Event ID 301: MPS_SVC_BFE_EngineOpenStart
#Event ID 302: MPS_SVC_BFE_EngineOpenStop
#Event ID 303: MPS_SVC_BFE_EngineCloseStart
#Event ID 304: MPS_SVC_BFE_EngineCloseStop
#Event ID 305: MPS_SVC_BFE_TransactionBeginStart
#Event ID 306: MPS_SVC_BFE_TransactionBeginStop
#Event ID 307: MPS_SVC_BFE_TransactionAbortStart
#Event ID 308: MPS_SVC_BFE_TransactionAbortStop
#Event ID 309: MPS_SVC_BFE_TransactionCommitStart
#Event ID 310: MPS_SVC_BFE_TransactionCommitStop
#Event ID 311: MPS_SVC_BFE_ProviderAddStart
#Event ID 312: MPS_SVC_BFE_ProviderAddStop
#Event ID 313: MPS_SVC_BFE_SublayerAddStart
#Event ID 314: MPS_SVC_BFE_SublayerAddStop
#Event ID 315: MPS_SVC_BFE_FilterAddStart
#Event ID 316: MPS_SVC_BFE_FilterAddStop
#Event ID 317: MPS_SVC_BFE_FilterDeleteByKeyStart
#Event ID 318: MPS_SVC_BFE_FilterDeleteByKeyStop
#Event ID 319: MPS_SVC_BFE_FilterDeleteByIdStart
#Event ID 320: MPS_SVC_BFE_FilterDeleteByIdStop
#Event ID 400: GPPolicyUpdateStart
#Event ID 401: GPPolicyUpdateStop
#Event ID 501: PlumberPolicyBeginStart
#Event ID 502: PlumberPolicyCommitStop
#Event ID 503: PlumberPolicyAbortStop
#Event ID 504: MPS_SVC_API_AddDynamicKeywordAddressStop
#Event ID 505: MPS_SVC_API_AddDynamicKeywordAddressStop505
#Event ID 506: MPS_SVC_API_DeleteDynamicKeywordAddressStop
#Event ID 507: MPS_SVC_API_DeleteDynamicKeywordAddressStop507
#Event ID 508: MPS_SVC_API_EnumDynamicKeywordAddressesStop
#Event ID 509: MPS_SVC_API_EnumDynamicKeywordAddressesStop509
#Event ID 510: MPS_CLNT_API_FreeDynamicKeywordAddressesStop
#Event ID 511: MPS_CLNT_API_FreeDynamicKeywordAddressesStop511
#Event ID 512: MPS_SVC_API_UpdateDynamicKeywordAddressStop
#Event ID 513: MPS_SVC_API_UpdateDynamicKeywordAddressStop513
#Event ID 514: MPS_SVC_API_GetRulePlumbStatusFromRuleIDStop
#Event ID 515: MPS_SVC_API_GetRulePlumbStatusFromRuleIDStop515
#Event ID 516: HyperVMgr_InitializeStart
#Event ID 517: HyperVMgr_InitializeStop
#Event ID 518: HyperVMgr_ShutdownStart
#Event ID 519: HyperVMgr_ShutdownStop
#Event ID 520: MPS_SVC_API_CreateHyperVPort0Start
#Event ID 521: MPS_SVC_API_CreateHyperVPort0Stop
#Event ID 522: MPS_SVC_API_SetHyperVPort0Start
#Event ID 523: MPS_SVC_API_SetHyperVPort0Stop
#Event ID 524: MPS_SVC_API_DeleteHyperVPort0Start
#Event ID 525: MPS_SVC_API_DeleteHyperVPort0Stop
#Event ID 526: MPS_SVC_API_EnumHyperVPorts0Start
#Event ID 527: MPS_SVC_API_EnumHyperVPorts0Stop
#Event ID 528: MPS_SVC_API_GetHyperVVMConfig0Start
#Event ID 529: MPS_SVC_API_GetHyperVVMConfig0Stop
#Event ID 530: MPS_SVC_API_SetHyperVVMConfig0Start
#Event ID 531: MPS_SVC_API_SetHyperVVMConfig0Stop
#Event ID 532: MPS_SVC_API_AddHyperVRule0Start
#Event ID 533: MPS_SVC_API_AddHyperVRule0Stop
#Event ID 534: MPS_SVC_API_SetHyperVRule0Start
#Event ID 535: MPS_SVC_API_SetHyperVRule0Stop
#Event ID 536: MPS_SVC_API_DeleteHyperVRule0Start
#Event ID 537: MPS_SVC_API_DeleteHyperVRule0Stop
#Event ID 538: MPS_SVC_API_EnumHyperVRules0Start
#Event ID 539: MPS_SVC_API_EnumHyperVRules0Stop
#Event ID 540: MPS_SVC_API_RegisterHyperVVMCreator0Start
#Event ID 541: MPS_SVC_API_RegisterHyperVVMCreator0Stop
#Event ID 542: MPS_SVC_API_UnregisterHyperVVMCreator0Start
#Event ID 543: MPS_SVC_API_UnregisterHyperVVMCreator0Stop
#Event ID 544: MPS_SVC_API_EnumHyperVVMCreators0Start
#Event ID 545: MPS_SVC_API_EnumHyperVVMCreators0Stop
#Event ID 546: MPS_SVC_API_GetHyperVProfileConfig0Start
#Event ID 547: MPS_SVC_API_GetHyperVProfileConfig0Stop
#Event ID 548: MPS_SVC_API_SetHyperVProfileConfig0Start
#Event ID 549: MPS_SVC_API_SetHyperVProfileConfig0Stop
#Event ID 550: MPS_SVC_API_CreateHyperVPort1Start
#Event ID 551: MPS_SVC_API_CreateHyperVPort1Stop
#Event ID 552: MPS_SVC_API_SetHyperVPort1Start
#Event ID 553: MPS_SVC_API_SetHyperVPort1Stop
#Event ID 554: MPS_SVC_API_EnumHyperVPorts1Start
#Event ID 555: MPS_SVC_API_EnumHyperVPorts1Stop
#Event ID 556: MPS_SVC_API_AddHyperVRule1Start
#Event ID 557: MPS_SVC_API_AddHyperVRule1Stop
#Event ID 558: MPS_SVC_API_SetHyperVRule1Start
#Event ID 559: MPS_SVC_API_SetHyperVRule1Stop
#Event ID 560: MPS_SVC_API_EnumHyperVRules1Start
#Event ID 561: MPS_SVC_API_EnumHyperVRules1Stop
#Event ID 562: HyperVMgrPhase0_InitializeStart
#Event ID 563: HyperVMgrPhase0_InitializeStop
#Event ID 564: HyperVMgrPhase0_ShutdownStart
#Event ID 565: HyperVMgrPhase0_ShutdownStop
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {5444519F-2484-45A2-991E-953E4B54C8E0}
Defined in mpssvc.dll, which carries the event manifest.
Observed on:
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.4768, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3328, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02