Microsoft-Windows-MSDTC 2
66 events across 2 channels
Event ID 4097: Failed to clean up the default DTC cluster resource setting
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4098: Contact = param1 was deleted successfully
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4099: Failed to create DTC cluster resource
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4100: Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4101: Attempting to change the DTC cluster resource's log file path to param1 has failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4102: Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4104: Failed trying to get the state of the cluster node:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4202: MSDTC started with the following settings:
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 | |
param4 | |
param5 | |
param6 | |
param7 | |
param8 | |
param9 | |
param10 | |
param11 | |
param12 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC 2",
"guid": "{5D9E0020-3761-4f36-90C8-38CE6511BD12}",
"event_source_name": "MSDTC 2",
"event_id": 4202,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-06T06:25:51.684453+00:00",
"event_record_id": 1448,
"correlation": {},
"execution": {
"process_id": 4912,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "0",
"param2": "0",
"param3": "0",
"param4": "0",
"param5": "0",
"param6": "0",
"param7": "1",
"param8": "Mutual Authentication Required",
"param9": "NT AUTHORITY\\NetworkService",
"param10": "0",
"param11": "0",
"param12": "1"
},
"message": ""
}
Event ID 4202: MSDTC started with the following settings:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString | |
param10 UnicodeString | |
param11 UnicodeString | |
param12 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC 2",
"guid": "{5D9E0020-3761-4F36-90C8-38CE6511BD12}",
"event_source_name": "",
"event_id": 4202,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-05-29T16:35:27.5896683+00:00",
"event_record_id": 724,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "0",
"param2": "0",
"param3": "0",
"param4": "0",
"param5": "0",
"param6": "0",
"param7": "1",
"param8": "Mutual Authentication Required",
"param9": "NT AUTHORITY\\NetworkService",
"param10": "0",
"param11": "0",
"param12": "1"
},
"message": "MSDTC started with the following settings:\r\r Security Configuration (OFF = 0 and ON = 1):\r Allow Remote Administrator = 0,\r Network Clients = 0,\r Transaction Manager Communication: \r Allow Inbound Transactions = 0,\r Allow Outbound Transactions = 0,\r Transaction Internet Protocol (TIP) = 0,\r Enable XA Transactions = 0,\r Enable SNA LU 6.2 Transactions = 1,\r MSDTC Communications Security = Mutual Authentication Required,\r Account = NT AUTHORITY\\NetworkService,\r Firewall Exclusion Detected = 0\r\r Transaction Bridge Installed = 0\r Filtering Duplicate Events = 1\r"
}
Event ID 4350: Cluster API call failed with error code:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4872: A caller has attempted to register an XA resource while XA transactions are disabled
#Event ID 4875: A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager communication on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4876: A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager communication on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4878: MSDTC encountered an error (HR=0xparam1) while attempting to authenticate an incoming connection from system 'param2'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4879: MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4880: MS DTC encountered an error while attempting to process a message from a connection with system 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 53323: The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53324: The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53325: The MSDTC XA Transaction Manager called the xa_open function for XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53327: The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53328: The MSDTC XA Transaction Manager attempted to perform recovery with the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 53329: The MSDTC XA Transaction Manager called the xa_open function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53330: The MSDTC XA Transaction Manager called the xa_close function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53331: The MSDTC XA Transaction Manager called the xa_recover function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53332: The MSDTC XA Transaction Manager called the xa_commit function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53333: The MSDTC XA Transaction Manager called the xa_rollback function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53334: The MSDTC XA Transaction Manager called the xa_prepare function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53335: The MSDTC XA Transaction Manager called the GetXaSwitch function in the XA resource manager DLL 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 53336: The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53337: The MSDTC XA Transaction Manager called the xa_commit function with the TMONEPHASE flag set for the XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53338: The MSDTC XA Transaction Manager attempted to locate the 'GetXaSwitch' function in the XA resource manager DLL
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 53339: The MS DTC XA Transaction Manager called the xa_close function for XA resource manager 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 1073745921: Failed to clean up the default DTC cluster resource setting.
#Event ID 1073745922: Contact = param1 was deleted successfully.
#Event ID 1073745923: Failed to create DTC cluster resource.
#Event ID 1073745924: Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed.
#Description
Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed. If the dependent disk resource does not support Volume Guid information, please configure at least one dependent disk partition with a drive letter. The error code returned: param1
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 1073745925: Attempting to change the DTC cluster resource's log file path to param1 has failed.
#Event ID 1073745926: Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned.
#Event ID 1073745927: Service: Service is still running.
#Event ID 1073745928: Failed trying to get the state of the cluster node: param1.
#Event ID 1073746026: MSDTC started with the following settings.
#Description
MSDTC started with the following settings.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString | |
param5 UnicodeString | |
param6 UnicodeString | |
param7 UnicodeString | |
param8 UnicodeString | |
param9 UnicodeString | |
param10 UnicodeString | |
param11 UnicodeString | |
param12 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC 2",
"event_id": 4202,
"level": 4,
"task": 2,
"opcode": 0,
"time_created": "2026-04-21T17:12:40.4959884+00:00",
"computer": "DESKTOP-FF3N5XK.ludus.domain",
"channel": "Application"
},
"event_data": {
"param5": "0",
"param8": "Mutual Authentication Required",
"param3": "0",
"param6": "0",
"param1": "0",
"param4": "0",
"param7": "1",
"param11": "0",
"param12": "1",
"param9": "NT AUTHORITY\\NetworkService",
"param10": "0",
"param2": "0"
}
}
Event ID 1073746174: Cluster API call failed with error code: param1.
#Event ID 1073746185: Cluster API call failed with error code: {param1}.
#Event ID 2147488520: A caller has attempted to register an XA resource while XA transactions are disabled.
#Description
A caller has attempted to register an XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.
Message #
Event ID 2147488523: A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager comm...
#Event ID 2147488524: A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager commu...
#Event ID 2147488526: MSDTC encountered an error (HR=0xparam1) while attempting to authenticate an incoming connection from system 'param2'.
#Event ID 2147488527: MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system param2.
#Event ID 2147488528: MS DTC encountered an error while attempting to process a message from a connection with system 'param1'.
#Description
MS DTC encountered an error while attempting to process a message from a connection with system 'param1'. The incoming message should be from another MSDTC, but has not been authenticated as such. The principal name is 'param2'.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 2147536971: The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager 'param1'.
#Description
The MSDTC XA Transaction Manager called the xa_rollback function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536972: The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager 'param1'.
#Description
The MSDTC XA Transaction Manager called the xa_commit function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536973: The MSDTC XA Transaction Manager called the xa_open function for XA resource manager 'param1'.
#Description
The MSDTC XA Transaction Manager called the xa_open function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536975: The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL 'param1'.
#Description
The MSDTC XA Transaction Manager called the 'GetXaSwitch' function in the XA resource manager DLL 'param1'. The call to the 'GetXaSwitch' function failed with error param2: File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536976: The MSDTC XA Transaction Manager attempted to perform recovery with the XA resource manager DLL 'param1'.
#Event ID 2147536977: The MSDTC XA Transaction Manager called the xa_open function in the XA resource manager DLL 'param1'.
#Event ID 2147536978: The MSDTC XA Transaction Manager called the xa_close function in the XA resource manager DLL 'param1'.
#Event ID 2147536979: The MSDTC XA Transaction Manager called the xa_recover function in the XA resource manager DLL 'param1'.
#Event ID 2147536980: The MSDTC XA Transaction Manager called the xa_commit function in the XA resource manager DLL 'param1'.
#Event ID 2147536981: The MSDTC XA Transaction Manager called the xa_rollback function in the XA resource manager DLL 'param1'.
#Event ID 2147536982: The MSDTC XA Transaction Manager called the xa_prepare function in the XA resource manager DLL 'param1'.
#Event ID 2147536983: The MSDTC XA Transaction Manager called the GetXaSwitch function in the XA resource manager DLL 'param1'.
#Event ID 2147536984: The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager 'param1'.
#Description
The MSDTC XA Transaction Manager called the xa_prepare function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536985: The MSDTC XA Transaction Manager called the xa_commit function with the TMONEPHASE flag set for the XA resource manager 'param1'.
#Description
The MSDTC XA Transaction Manager called the xa_commit function with the TMONEPHASE flag set for the XA resource manager 'param1'. The call to the xa_commit function failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536986: The MSDTC XA Transaction Manager attempted to locate the 'GetXaSwitch' function in the XA resource manager DLL.
#Description
The MSDTC XA Transaction Manager attempted to locate the 'GetXaSwitch' function in the XA resource manager DLL. The 'GetXaSwitch' function is missing from the XA resource manager DLL param1 : Error=param2 File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Event ID 2147536987: The MS DTC XA Transaction Manager called the xa_close function for XA resource manager 'param1'.
#Description
The MS DTC XA Transaction Manager called the xa_close function for XA resource manager 'param1'. This call failed with an unexpected return code (param2): File=param3 Line=param4.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString | |
param4 UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 5d9e0020-3761-4f36-90c8-38ce6511bd12
Defined in msdtcVSp1res.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02