Microsoft-Windows-MSDTC Client 2
38 events across 2 channels
Event ID 4097: Failed to clean up the default DTC cluster resource setting
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4098: Contact = param1 was deleted successfully
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4099: Failed to create DTC cluster resource
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4100: Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4101: Attempting to change the DTC cluster resource's log file path to param1 has failed
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4102: Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4104: Failed trying to get the state of the cluster node:
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4104,
"version": 0,
"level": 2,
"task": 14,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-11-05T22:27:41.546510+00:00",
"event_record_id": 1466,
"correlation": {},
"execution": {
"process_id": 4608,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDev2310Eval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "",
"param2": "0x8007045B"
},
"message": ""
}
References #
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 4104: Failed trying to get the state of the cluster node:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Event ID 4350: Cluster API call failed with error code:
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 | |
param3 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4350,
"version": 0,
"level": 3,
"task": 14,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-03-13T20:23:52.178949+00:00",
"event_record_id": 3710,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "LAB-DC01.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "0x800706D9",
"param2": "OpenClusterEx",
"param3": "lpszClusterName: (null)"
},
"message": ""
}
Event ID 4350: Cluster API call failed with error code:
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"event_id": 4350,
"level": 3,
"task": 14,
"opcode": 0,
"time_created": "2026-03-13T20:23:52.1789492+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"param2": "OpenClusterEx",
"param1": "0x800706D9",
"param3": "lpszClusterName: (null)"
}
}
Event ID 4872: A caller has attempted to register an XA resource while XA transactions are disabled
#Event ID 4873: An XA transaction manager has attempted to open the MSDTC XA resource while XA transactions are disabled
#Event ID 4874: A caller has attempted to propagate a transaction to a remote system, but MSDTC network DTC access is currently disabled on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4875: A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager communication on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4876: A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager communication on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 4878: MSDTC encountered an error (HR=0xparam1) while attempting to authenticate an incoming connection from system 'param2'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Event ID 4879: MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system
#Fields #
| Name | Description |
|---|---|
param1 | |
param2 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4ff1-B107-DF8AFC3C0363}",
"event_source_name": "MSDTC Client 2",
"event_id": 4879,
"version": 0,
"level": 3,
"task": 3,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2023-10-25T22:53:19.706720+00:00",
"event_record_id": 1415,
"correlation": {},
"execution": {
"process_id": 932,
"thread_id": 0
},
"channel": "Application",
"computer": "WinDevEval",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "80000171",
"param2": "WINDEVEVAL"
},
"message": ""
}
Event ID 4879: MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"guid": "{155CB334-3D7F-4FF1-B107-DF8AFC3C0363}",
"event_source_name": "",
"event_id": 4879,
"version": 0,
"level": 3,
"task": 3,
"opcode": 0,
"keywords": 36028797018963968,
"time_created": "2026-05-29T06:18:33.7428069+00:00",
"event_record_id": 648,
"correlation": {},
"execution": {
"process_id": 0,
"thread_id": 0
},
"channel": "Application",
"computer": "telemetry-DC-a.cell-a.ludus.domain",
"security": {
"user_id": ""
}
},
"event_data": {
"param1": "80000171",
"param2": "TELEMETRY-DC-A"
},
"message": "MSDTC encountered an error (HR=0x80000171) while attempting to establish a secure connection with system TELEMETRY-DC-A."
}
Event ID 4881: A caller has attempted to connect to a remote MSDTC on machine 'param1'
#Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 1073745921: Failed to clean up the default DTC cluster resource setting.
#Event ID 1073745922: Contact = param1 was deleted successfully.
#Event ID 1073745923: Failed to create DTC cluster resource.
#Event ID 1073745924: Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed.
#Description
Attempt to find the drive letter or Volume Guid corresponding to the cluster DTC's dependent disk resource has failed. If the dependent disk resource does not support Volume Guid information, please configure at least one dependent disk partition with a drive letter. The error code returned: param1
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString |
Event ID 1073745925: Attempting to change the DTC cluster resource's log file path to param1 has failed.
#Event ID 1073745926: Application specified a cluster resource ID: param1, but no DTC cluster resource could be returned.
#Event ID 1073745927: Service: Service is still running.
#Event ID 1073745928: Failed trying to get the state of the cluster node: param1.
#Event ID 1073746174: Cluster API call failed with error code: param1.
#Description
Cluster API call failed with error code: param1. Cluster API function: ClusterAPIFunction Arguments: Arguments.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString | |
param3 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"event_id": 4350,
"level": 3,
"task": 14,
"opcode": 0,
"time_created": "2026-03-13T20:23:52.1789492+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"param2": "OpenClusterEx",
"param1": "0x800706D9",
"param3": "lpszClusterName: (null)"
}
}
Event ID 1073746185: Cluster API call failed with error code: {param1}.
#Event ID 2147488520: A caller has attempted to register an XA resource while XA transactions are disabled.
#Description
A caller has attempted to register an XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.
Message #
Event ID 2147488521: An XA transaction manager has attempted to open the MSDTC XA resource while XA transactions are disabled.
#Description
An XA transaction manager has attempted to open the MSDTC XA resource while XA transactions are disabled. Please review the MSDTC configuration settings.
Message #
Event ID 2147488522: A caller has attempted to propagate a transaction to a remote system, but MSDTC network DTC access is currently disabled on machine 'param1'.
#Event ID 2147488523: A caller has attempted to import a transaction from a remote system, but MSDTC is currently configured to disallow inbound transaction manager comm...
#Event ID 2147488524: A caller has attempted to export a transaction to a remote system, but MSDTC is currently configured to disallow outbound transaction manager commu...
#Event ID 2147488526: MSDTC encountered an error (HR=0xparam1) while attempting to authenticate an incoming connection from system 'param2'.
#Event ID 2147488527: MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system param2.
#Description
MSDTC encountered an error (HR=0xparam1) while attempting to establish a secure connection with system param2.
Message #
Fields #
| Name | Description |
|---|---|
param1 UnicodeString | |
param2 UnicodeString |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-MSDTC Client 2",
"event_id": 4879,
"level": 3,
"task": 3,
"opcode": 0,
"time_created": "2026-03-15T04:21:57.0604250+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Application"
},
"event_data": {
"param1": "80000171",
"param2": "JD-DC01-2022"
}
}
Event ID 2147488529: A caller has attempted to connect to a remote MSDTC on machine 'param1'.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 155cb334-3d7f-4ff1-b107-df8afc3c0363
Defined in msdtcVSp1res.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 2001.12.10941.16384, captured 2026-06-02