Microsoft-Windows-MSMQ

EventTitleChannelSampleRule
1Message with ID MessageIDGUID\MessageIDIdentity was put into queue QueueName.End2EndNN
1Message with ID MessageIDGUID\MessageIDIdentity was put into queueOperationalNN
2Message receivedEnd2End, OperationalNN
3Message sent over networkEnd2End, OperationalNN
4Message came over networkEnd2End, OperationalNN
5Message with ID MessageIDGUID\MessageIDIdentity was sent to queue QueueName.End2EndNN
5Message with ID MessageIDGUID\MessageIDIdentity was sent to queueOperationalNN
2000The Message Queuing service cannot startOperationalNN
2001The Message Queuing service cannot startOperationalNN
2015The Message Queuing service is not online with Active Directory Domain ServicesOperationalNN
2016The Message Queuing service is not online with Active Directory Domain Services, …OperationalNN
2020The Message Queuing service cannot startOperationalNN
2023The Message Queuing service cannot startOperationalNN
2024The Message Queuing serivce performance counter data are not availableOperationalNN
2027A corrupted packet was encountered.ApplicationNY
2028The Message Queuing service startedApplicationYN
2028The Message Queuing service startedOperationalYN
2035The Message Queuing service cannot startOperationalNN
2043The Message Queuing service deleted message 'param1'OperationalNN
2044The Message Queuing service has insufficient privileges to create audit log …OperationalNN
2045The Message Queuing down-level client support service has insufficient …OperationalNN
2047The Message Queuing service cannot startOperationalNN
2048The server cannot support the automatic recognition of sites and connected …OperationalNN
2049A multicast listener received a request with headers size exceeding the …OperationalNN
2050A multicast listener received a request with content-length header size of …OperationalNN
2051The Message Queuing service rejected a request since the deserialization hit the …OperationalNN
2052The request's deserialization led to a stack overflow exception in the Message …OperationalNN
2053The incoming sequences checkpoint file failed to initializeOperationalNN
2054The Message Queuing service rejected an attempt to create a queue because the …OperationalNN
2055The Message Queuing service session cleanup is taking longer than expectedOperationalNN
2059The Message Queuing service cannot communicate with other computers, because the …OperationalNN
2060The Message Queuing service is online with Active Directory Domain Services and …OperationalNN
2061The Message Queuing service cannot startOperationalNN
2064The transactions checkpoint file failed to initializeOperationalNN
2068The list of Message Queuing servers with directory service functionality in the …OperationalNN
2076The logger files cannot be initializedOperationalNN
2078The Message Queuing service cannot startOperationalNN
2079The Message Queuing service cannot startOperationalNN
2083The Message Queuing service cannot startOperationalNN
2084The Message Queuing service cannot start because a queue is in an inconsistent …OperationalNN
2085The message file 'param1' cannot be createdOperationalNN
2086The message file 'param1' was successfully createdOperationalNN
2087The Client Access License (CAL) limit was reachedOperationalNN
2095Since an MSMQ 1OperationalNN
2096The Message Queuing folder cannot be createdOperationalNN
2097The Message Queuing registry values cannot be read (the registry is probably …OperationalNN
2116Message Queuing was unable to create the msmq (MSMQ Configuration) object in …OperationalNN
2117Message Queuing was unable to load MqupgrdOperationalNN
2118Message Queuing was unable to find the address of MqCreateMsmqObj in MqupgrdOperationalNN
2119Message Queuing Setup cannot be completedOperationalNN
2120The Message Queuing service was unable to obtain the properties of the msmq …OperationalNN
2122This domain controller is not trusted for delegationOperationalNN
2123The Message Queuing server cannot determine if the local domain controller is …OperationalNN
2124The Message Queuing service failed to join the computer's domain 'param3'OperationalNN
2125The Message Queuing service successfully joined the computer's domain 'param1'OperationalNN
2126Message Queuing left the domain and is now operating in workgroup modeOperationalNN
2127Message Queuing objects cannot move automatically between domains (param1)OperationalNN
2134Message Queuing successfully moved to the param1 domainOperationalNN
2135The computer belongs to the param1 domainOperationalNN
2139Message Queuing detected a problem with the local domain controllerOperationalNN
2140This server was unable to resolve the IP addresses of other routing serversOperationalNN
2141The properties of the queue param3 cannot be setOperationalNN
2142The properties of the queue param3 cannot be setOperationalNN
2143The Microsoft Distributed Transaction Coordinator (DTC) failedOperationalNN
2144There is an inconsistency between the actual network addresses and the addresses …OperationalNN
2145The computer object for this computer was not found in Active Directory Domain …OperationalNN
2147The service cannot start due to insufficient disk space or memoryOperationalNN
2148The service cannot start due to its failure to connect to its device driverOperationalNN
2149The Message Queuing directory service failed to update the directory service …OperationalNN
2150The Message Queuing directory service failed to update the directory service …OperationalNN
2151Obsolete, kept for backward compatibilityOperationalNN
2152The Message Queuing directory service is not running as a local systemOperationalNN
2153Message Queuing Down-level Client Support cannot startOperationalNN
2154A multicast listener initialization failedOperationalNN
2155The Message Queuing service stopped monitoring the mapping folderOperationalNN
2156The mapping file param3 was ignoredOperationalNN
2157The mapping of the URL param1 to the queue param2 was ignoredOperationalNN
2158The mapping file param1 was ignored because it was improperly formattedOperationalNN
2159Message Queuing Down-level Client Support startedOperationalNN
2160The queue cannot listen/bind to the multicast addressOperationalNN
2161The mapping of the URL param1 to the queue param2 is ignoredOperationalNN
2162Message Queuing Down-level Client Support failed to create the MSMQ …OperationalNN
2163The Message Queuing service stoppedOperationalNN
2164The Message Queuing service will not join the param1 domainOperationalNN
2165The sites where the computer resides cannot be resolvedOperationalNN
2166The Message Queuing service cannot join the 'param1' Windows NT 4OperationalNN
2167Message Queuing is operating in Hardened modeOperationalNN
2168The Message Queuing service resource cannot bind to the cluster IP addressOperationalNN
2169The local computer is a Message Queuing routing server that formerly belonged to …OperationalNN
2170Message Queuing failed to bind to port 1801OperationalNN
2171Message Queuing cannot bind to UDP port 3527OperationalNN
2172The MsmqServices object is configured with weakened security to support MSMQ 1OperationalNN
2173The MsmqServices object is configured with default securityOperationalNN
2174Message Queuing Down-level Client Support cannot operate in mixed modeOperationalNN
2175Message Queuing will use an encryption key with an effective length of 40 bits …OperationalNN
2176Message Queuing found multiple IP addresses for the local computerOperationalNN
2177The Message Queuing service rejects incoming messages when it is unable to check …OperationalNN
2181Message Queuing cannot establish new connections to this computer because …OperationalNN
2182Storage quota exceeded for MSMQ queueOperationalNN
2183Machine MSMQ storage quota was exceeded or there is insufficient disk spaceOperationalNN
2184Message Queuing could not resolve the name 'param1' to an IP addressOperationalNN
2185A socket operation failed with errorOperationalNN
2186Message Queuing could not establish connection to param1, because the connection …OperationalNN
2187Message Queuing could not establish connection to param1, because connection was …OperationalNN
2188Message Queuing could not access Active Directory Domain Services and failed to …OperationalNN
2189Message Queuing failed to send a message due to low memoryOperationalNN
2190Message Queuing could not complete SSL negotiation with the remote computerOperationalNN
2191Message Queuing could not validate server certificate in HTTPS scenario because …OperationalNN
2192Message Queuing could not establish SSL connection with the recipient computer …OperationalNN
2193Message Queuing could not establish SSL connection with the recipient computer …OperationalNN
2194The Message Queuing service cannot communicate with other computers, because the …OperationalNN
2195Message Queuing could not authenticate a message sent to queueOperationalNN
2196Message Queuing failed to verify digital signature of a message sent to queueOperationalNN
2197Message Queuing failed to listen on the IPv6 protocolOperationalNN
2198Message Queuing failed to listen on the IPv4 protocolOperationalNN
2199Message Queuing Service failed to listen on both IPv4 and IPv6 protocolOperationalNN
2220The IP address param1 specified in the …OperationalNN
2221Message Queuing will use the IP addressOperationalNN
2224The MSMQ VSS Writer object cannot be createdOperationalNN
2225The MSMQ VSS Writer failed to register with the VSSOperationalNN
2226The MSMQ VSS Writer failed to identify itselfOperationalNN
2227Backup failed during eventOperationalNN
2228Restore failed during eventOperationalNN
2229The MSMQ VSS Writer failed to handle the restore located at 'param3'OperationalNN
2230A backup (components: param1) was completed successfullyOperationalNN
2231A restore was completed successfullyOperationalNN
2232The restore located at 'param1' was handled successfullyOperationalNN
2233The MSMQ VSS Writer is disabled through the registry settingOperationalNN
2234The restore located at 'param1' is invalidOperationalNN
2250Message Queuing will not be able to accept messages temporarily because system …OperationalNN
2251Message Queuing will not be able to accept messages temporarily because system …OperationalNN
2252Message Queuing is resuming accepting messages because the system memory usage …OperationalNN
2253The message could not be moved to deadletter queueOperationalNN
2254The message could not be moved to deadletter queueOperationalNN
2255The message could not be moved to deadletter queueOperationalNN
2256The message could not be moved to deadletter queueOperationalNN
1073743848The Message Queuing serivce performance counter data are not available.OperationalNN
1073743852The Message Queuing service started.OperationalYN
1073743884The Message Queuing service is online with Active Directory Domain Services and …OperationalNN
1073743910The message file 'param1' was successfully created.OperationalNN
1073743949The Message Queuing service successfully joined the computer's domain 'param1'.OperationalNN
1073743950Message Queuing left the domain and is now operating in workgroup mode.OperationalNN
1073743958Message Queuing successfully moved to the param1 domain.OperationalNN
1073743959The computer belongs to the param1 domain.OperationalNN
1073743983Message Queuing Down-level Client Support started.OperationalNN
1073743987The Message Queuing service stopped.OperationalNN
1073743991Message Queuing is operating in Hardened mode.OperationalNN
1073743996The MsmqServices object is configured with weakened security to support MSMQ 1.OperationalNN
1073743997The MsmqServices object is configured with default security.OperationalNN
1073744000Message Queuing found multiple IP addresses for the local computer.OperationalNN
1073744045Message Queuing will use the IP address param1.OperationalNN
1073744054A backup (components: param1) was completed successfully.OperationalNN
1073744055A restore was completed successfully.OperationalNN
1073744056The restore located at 'param1' was handled successfully.OperationalNN
1073744057The MSMQ VSS Writer is disabled through the registry setting.OperationalNN
1073744076Message Queuing is resuming accepting messages because the system memory usage …OperationalNN
2147485691The Message Queuing service deleted message 'param1'.OperationalNN
2147485692The Message Queuing service has insufficient privileges to create audit log …OperationalNN
2147485693The Message Queuing down-level client support service has insufficient …OperationalNN
2147485703The Message Queuing service session cleanup is taking longer than expected.OperationalNN
2147485707The Message Queuing service cannot communicate with other computers, because the …OperationalNN
2147485735The Client Access License (CAL) limit was reached.OperationalNN
2147485771The Message Queuing server cannot determine if the local domain controller is …OperationalNN
2147485787Message Queuing detected a problem with the local domain controller.OperationalNN
2147485788This server was unable to resolve the IP addresses of other routing servers.OperationalNN
2147485792There is an inconsistency between the actual network addresses and the addresses …OperationalNN
2147485800The Message Queuing directory service is not running as a local system.OperationalNN
2147485801Message Queuing Down-level Client Support cannot start.OperationalNN
2147485805The mapping of the URL param1 to the queue param2 was ignored.OperationalNN
2147485809The mapping of the URL param1 to the queue param2 is ignored.OperationalNN
2147485810Message Queuing Down-level Client Support failed to create the MSMQ …OperationalNN
2147485813The sites where the computer resides cannot be resolved.OperationalNN
2147485819Message Queuing cannot bind to UDP port 3527.OperationalNN
2147485823Message Queuing will use an encryption key with an effective length of 40 bits …OperationalNN
2147485829Message Queuing cannot establish new connections to this computer because …OperationalNN
2147485830Storage quota exceeded for MSMQ queue param1.OperationalNN
2147485831Machine MSMQ storage quota was exceeded or there is insufficient disk space.OperationalNN
2147485832Message Queuing could not resolve the name 'param1' to an IP address.OperationalNN
2147485833A socket operation failed with error param1.OperationalNN
2147485834Message Queuing could not establish connection to param1, because the connection …OperationalNN
2147485835Message Queuing could not establish connection to param1, because connection was …OperationalNN
2147485836Message Queuing could not access Active Directory Domain Services and failed to …OperationalNN
2147485837Message Queuing failed to send a message due to low memory.OperationalNN
2147485838Message Queuing could not complete SSL negotiation with the remote computer.OperationalNN
2147485839Message Queuing could not validate server certificate in HTTPS scenario because …OperationalNN
2147485840Message Queuing could not establish SSL connection with the recipient computer …OperationalNN
2147485841Message Queuing could not establish SSL connection with the recipient computer …OperationalNN
2147485843Message Queuing could not authenticate a message sent to queue param1.OperationalNN
2147485844Message Queuing failed to verify digital signature of a message sent to queue …OperationalNN
2147485845Message Queuing failed to listen on the IPv6 protocol.OperationalNN
2147485846Message Queuing failed to listen on the IPv4 protocol.OperationalNN
2147485872The MSMQ VSS Writer object cannot be created.OperationalNN
2147485873The MSMQ VSS Writer failed to register with the VSS.OperationalNN
2147485898Message Queuing will not be able to accept messages temporarily because system …OperationalNN
2147485899Message Queuing will not be able to accept messages temporarily because system …OperationalNN
2147485901The message could not be moved to deadletter queue param3.OperationalNN
2147485902The message could not be moved to deadletter queue param1.OperationalNN
2147485903The message could not be moved to deadletter queue param1.OperationalNN
2147485904The message could not be moved to deadletter queue param1.OperationalNN
3221227472The Message Queuing service cannot start.OperationalNN
3221227473The Message Queuing service cannot start.OperationalNN
3221227487The Message Queuing service is not online with Active Directory Domain Services.OperationalNN
3221227488The Message Queuing service is not online with Active Directory Domain Services, …OperationalNN
3221227492The Message Queuing service cannot start.OperationalNN
3221227495The Message Queuing service cannot start.OperationalNN
3221227507The Message Queuing service cannot start.OperationalNN
3221227519The Message Queuing service cannot start.OperationalNN
3221227520The server cannot support the automatic recognition of sites and connected …OperationalNN
3221227521A multicast listener received a request with headers size exceeding the …OperationalNN
3221227522A multicast listener received a request with content-length header size of '%1' …OperationalNN
3221227523The Message Queuing service rejected a request since the deserialization hit the …OperationalNN
3221227524The request's deserialization led to a stack overflow exception in the Message …OperationalNN
3221227525The incoming sequences checkpoint file failed to initialize.OperationalNN
3221227526The Message Queuing service rejected an attempt to create a queue because the …OperationalNN
3221227533The Message Queuing service cannot start.OperationalNN
3221227536The transactions checkpoint file failed to initialize.OperationalNN
3221227540The list of Message Queuing servers with directory service functionality in the …OperationalNN
3221227548The logger files cannot be initialized.OperationalNN
3221227550The Message Queuing service cannot start.OperationalNN
3221227551The Message Queuing service cannot start.OperationalNN
3221227555The Message Queuing service cannot start.OperationalNN
3221227556The Message Queuing service cannot start because a queue is in an inconsistent …OperationalNN
3221227557The message file 'param1' cannot be created.OperationalNN
3221227567Since an MSMQ 1.OperationalNN
3221227568The Message Queuing folder cannot be created.OperationalNN
3221227569The Message Queuing registry values cannot be read (the registry is probably …OperationalNN
3221227588Message Queuing was unable to create the msmq (MSMQ Configuration) object in …OperationalNN
3221227589Message Queuing was unable to load Mqupgrd.OperationalNN
3221227590Message Queuing was unable to find the address of MqCreateMsmqObj in Mqupgrd.OperationalNN
3221227591Message Queuing Setup cannot be completed.OperationalNN
3221227592The Message Queuing service was unable to obtain the properties of the msmq …OperationalNN
3221227594This domain controller is not trusted for delegation.OperationalNN
3221227596The Message Queuing service failed to join the computer's domain 'param3'.OperationalNN
3221227599Message Queuing objects cannot move automatically between domains.OperationalNN
3221227613The properties of the queue param3 cannot be set.OperationalNN
3221227614The properties of the queue param3 cannot be set.OperationalNN
3221227615The Microsoft Distributed Transaction Coordinator (DTC) failed.OperationalNN
3221227617The computer object for this computer was not found in Active Directory Domain …OperationalNN
3221227619The service cannot start due to insufficient disk space or memory.OperationalNN
3221227620The service cannot start due to its failure to connect to its device driver.OperationalNN
3221227621The Message Queuing directory service failed to update the directory service …OperationalNN
3221227622The Message Queuing directory service failed to update the directory service …OperationalNN
3221227623Obsolete, kept for backward compatibilityOperationalNN
3221227626A multicast listener initialization failed.OperationalNN
3221227627The Message Queuing service stopped monitoring the mapping folder param3.OperationalNN
3221227628The mapping file param3 was ignored.OperationalNN
3221227630The mapping file param1 was ignored because it was improperly formatted.OperationalNN
3221227632The queue cannot listen/bind to the multicast address param3.OperationalNN
3221227636The Message Queuing service will not join the param1 domain.OperationalNN
3221227638The Message Queuing service cannot join the 'param1' Windows NT 4.OperationalNN
3221227640The Message Queuing service resource cannot bind to the cluster IP address.OperationalNN
3221227641The local computer is a Message Queuing routing server that formerly belonged to …OperationalNN
3221227642Message Queuing failed to bind to port 1801.OperationalNN
3221227646Message Queuing Down-level Client Support cannot operate in mixed mode.OperationalNN
3221227649The Message Queuing service rejects incoming messages when it is unable to check …OperationalNN
3221227666The Message Queuing service cannot communicate with other computers, because the …OperationalNN
3221227671Message Queuing Service failed to listen on both IPv4 and IPv6 protocol.OperationalNN
3221227692The IP address param1 specified in the …OperationalNN
3221227698The MSMQ VSS Writer failed to identify itself.OperationalNN
3221227699Backup failed during event param3.OperationalNN
3221227700Restore failed during event param3.OperationalNN
3221227701The MSMQ VSS Writer failed to handle the restore located at 'param3'.OperationalNN
3221227706The restore located at 'param1' is invalid.OperationalNN

Event ID 1: Message with ID MessageIDGUID\MessageIDIdentity was put into queue QueueName.

#
Channel
End2End
Opcode
Info

Message #

Message with ID %1\%2 was put into queue %3

Fields #

NameDescription
MessageIDGUID GUID
MessageIDIdentity UInt32
QueueName UnicodeString

Event ID 1: Message with ID MessageIDGUID\MessageIDIdentity was put into queue

#
Channel
Operational
Opcode
Info

Description

Message with ID \ was put into queue.

Fields #

NameDescription
MessageIDGUID GUID
MessageIDIdentity UInt32
QueueName UnicodeString

Event ID 2: Message received

#
Channel
End2End, Operational
Opcode
Info

Event ID 3: Message sent over network

#
Channel
End2End, Operational
Opcode
Info

Event ID 4: Message came over network

#
Channel
End2End, Operational
Opcode
Info

Event ID 5: Message with ID MessageIDGUID\MessageIDIdentity was sent to queue QueueName.

#
Channel
End2End
Opcode
Info

Message #

Message with ID %1\%2 was sent to queue %3

Fields #

NameDescription
MessageIDGUID GUID
MessageIDIdentity UInt32
QueueName UnicodeString

Event ID 5: Message with ID MessageIDGUID\MessageIDIdentity was sent to queue

#
Channel
Operational
Opcode
Info

Description

Message with ID \ was sent to queue.

Fields #

NameDescription
MessageIDGUID GUID
MessageIDIdentity UInt32
QueueName UnicodeString

Event ID 2000: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2001: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2015: The Message Queuing service is not online with Active Directory Domain Services

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2016: The Message Queuing service is not online with Active Directory Domain Services, since the service properties cannot be retrieved or set

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2020: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2023: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2024: The Message Queuing serivce performance counter data are not available

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2027: A corrupted packet was encountered.

#
Channel
Application

Description

Logged (Level 2, Error) by the Message Queuing service when it parses a malformed MSMQ wire-protocol packet. Observed on systems patched against CVE-2023-21554 (QueueJumper): the post-patch validation rejects the malformed packet and logs this event instead of the pre-patch out-of-bounds-write crash.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Leveleq21 rulesigma

Community Notes #

Matched by the SigmaHQ 'MSMQ Corrupted Packet Encountered' rule (Provider MSMQ, Level 2). Provenance is vendor-verified, not Microsoft-documented: the Randori / IBM X-Force team screenshotted this exact event from the MSMQ source while testing the CVE-2023-21554 patch. Note a historical id collision: the legacy KB810318 (MSMQ 1.0 on Windows NT4) assigned 2027 to an unrelated IPX-address message; that IPX message catalog predates the modern MSMQ rewrites and does not describe this event.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 2028: The Message Queuing service started

#
Channel
Application
Level
Informational

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-MSMQ",
    "guid": "{ce18af71-5efd-4f5a-9bd5-635e34632f69}",
    "event_source_name": "MSMQ",
    "event_id": 2028,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 36028797018963968,
    "time_created": "2026-03-13T20:00:50.493281+00:00",
    "event_record_id": 3678,
    "correlation": {},
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Application",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 2028: The Message Queuing service started

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-MSMQ",
    "event_id": 2028,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T20:00:50.4932819+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 2035: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2043: The Message Queuing service deleted message 'param1'

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2044: The Message Queuing service has insufficient privileges to create audit log messages

#
Channel
Operational

Event ID 2045: The Message Queuing down-level client support service has insufficient privileges to create audit log messages

#
Channel
Operational

Event ID 2047: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2048: The server cannot support the automatic recognition of sites and connected networks for down-level clients

#
Channel
Operational

Event ID 2049: A multicast listener received a request with headers size exceeding the configured max size of 'MaxHeaderSize'

#
Channel
Operational

Fields #

NameDescription
MaxHeaderSize UnicodeString
Frequency UnicodeString

Event ID 2050: A multicast listener received a request with content-length header size of 'ReqBodySize' that exceeds the configured max size of 'MaxBodySize'

#
Channel
Operational

Fields #

NameDescription
ReqBodySize UnicodeString
MaxBodySize UnicodeString
Frequency UnicodeString

Event ID 2051: The Message Queuing service rejected a request since the deserialization hit the maximum allowed xml depth of 'MaxXmlDepth'

#
Channel
Operational

Fields #

NameDescription
MaxXmlDepth UnicodeString
Frequency UnicodeString

Event ID 2052: The request's deserialization led to a stack overflow exception in the Message Queuing service

#
Channel
Operational

Fields #

NameDescription
MaxXmlDepth UnicodeString

Event ID 2053: The incoming sequences checkpoint file failed to initialize

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2054: The Message Queuing service rejected an attempt to create a queue because the total number of queues has reached the maximum allowed limit of 'QueueCountLimit' This limit can be increased by creati...

#
Channel
Operational

Fields #

NameDescription
QueueCountLimit UnicodeString

Event ID 2055: The Message Queuing service session cleanup is taking longer than expected

#
Channel
Operational

Fields #

NameDescription
QueueCountLimit UnicodeString

Event ID 2059: The Message Queuing service cannot communicate with other computers, because the RPC interface cannot use the TCP/IP protocol

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2060: The Message Queuing service is online with Active Directory Domain Services and fully operational

#
Channel
Operational

Event ID 2061: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2064: The transactions checkpoint file failed to initialize

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2068: The list of Message Queuing servers with directory service functionality in the Windows registry is empty

#
Channel
Operational

Event ID 2076: The logger files cannot be initialized

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2078: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2079: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2083: The Message Queuing service cannot start

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 2084: The Message Queuing service cannot start because a queue is in an inconsistent state

#
Channel
Operational

Event ID 2085: The message file 'param1' cannot be created

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2086: The message file 'param1' was successfully created

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2087: The Client Access License (CAL) limit was reached

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2095: Since an MSMQ 1

#
Channel
Operational

Event ID 2096: The Message Queuing folder cannot be created

#
Channel
Operational

Event ID 2097: The Message Queuing registry values cannot be read (the registry is probably corrupted)

#
Channel
Operational

Event ID 2116: Message Queuing was unable to create the msmq (MSMQ Configuration) object in Active Directory Domain Services

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2117: Message Queuing was unable to load Mqupgrd

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2118: Message Queuing was unable to find the address of MqCreateMsmqObj in Mqupgrd

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2119: Message Queuing Setup cannot be completed

#
Channel
Operational

Event ID 2120: The Message Queuing service was unable to obtain the properties of the msmq (MSMQ Configuration) object from Active Directory Domain Services

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2122: This domain controller is not trusted for delegation

#
Channel
Operational

Event ID 2123: The Message Queuing server cannot determine if the local domain controller is trusted for delegation

#
Channel
Operational

Event ID 2124: The Message Queuing service failed to join the computer's domain 'param3'

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2125: The Message Queuing service successfully joined the computer's domain 'param1'

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2126: Message Queuing left the domain and is now operating in workgroup mode

#
Channel
Operational

Event ID 2127: Message Queuing objects cannot move automatically between domains (param1)

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2134: Message Queuing successfully moved to the param1 domain

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2135: The computer belongs to the param1 domain

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2139: Message Queuing detected a problem with the local domain controller

#
Channel
Operational

Event ID 2140: This server was unable to resolve the IP addresses of other routing servers

#
Channel
Operational

Event ID 2141: The properties of the queue param3 cannot be set

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 2142: The properties of the queue param3 cannot be set

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 2143: The Microsoft Distributed Transaction Coordinator (DTC) failed

#
Channel
Operational

Event ID 2144: There is an inconsistency between the actual network addresses and the addresses that are listed on other Message Queuing servers for this computer

#
Channel
Operational

Event ID 2145: The computer object for this computer was not found in Active Directory Domain Services, possibly because of Active Directory Domain Services replication delays

#
Channel
Operational

Event ID 2147: The service cannot start due to insufficient disk space or memory

#
Channel
Operational

Event ID 2148: The service cannot start due to its failure to connect to its device driver

#
Channel
Operational

Event ID 2149: The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services at the end of the domain controller demotion process

#
Channel
Operational

Event ID 2150: The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services during the domain controller promotion process

#
Channel
Operational

Event ID 2151: Obsolete, kept for backward compatibility

#
Channel
Operational

Event ID 2152: The Message Queuing directory service is not running as a local system

#
Channel
Operational

Event ID 2153: Message Queuing Down-level Client Support cannot start

#
Channel
Operational

Event ID 2154: A multicast listener initialization failed

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2155: The Message Queuing service stopped monitoring the mapping folder

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2156: The mapping file param3 was ignored

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2157: The mapping of the URL param1 to the queue param2 was ignored

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2158: The mapping file param1 was ignored because it was improperly formatted

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2159: Message Queuing Down-level Client Support started

#
Channel
Operational

Event ID 2160: The queue cannot listen/bind to the multicast address

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2161: The mapping of the URL param1 to the queue param2 is ignored

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2162: Message Queuing Down-level Client Support failed to create the MSMQ Configuration (msmq) object with a given GUID for computer

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2163: The Message Queuing service stopped

#
Channel
Operational

Event ID 2164: The Message Queuing service will not join the param1 domain

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2165: The sites where the computer resides cannot be resolved

#
Channel
Operational

Event ID 2166: The Message Queuing service cannot join the 'param1' Windows NT 4

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2167: Message Queuing is operating in Hardened mode

#
Channel
Operational

Event ID 2168: The Message Queuing service resource cannot bind to the cluster IP address

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2169: The local computer is a Message Queuing routing server that formerly belonged to the 'param1' domain and is now operating in workgroup mode

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2170: Message Queuing failed to bind to port 1801

#
Channel
Operational

Event ID 2171: Message Queuing cannot bind to UDP port 3527

#
Channel
Operational

Event ID 2172: The MsmqServices object is configured with weakened security to support MSMQ 1

#
Channel
Operational

Event ID 2173: The MsmqServices object is configured with default security

#
Channel
Operational

Event ID 2174: Message Queuing Down-level Client Support cannot operate in mixed mode

#
Channel
Operational

Event ID 2175: Message Queuing will use an encryption key with an effective length of 40 bits when sending messages encrypted with the RC2 encryption algorithm

#
Channel
Operational

Event ID 2176: Message Queuing found multiple IP addresses for the local computer

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2177: The Message Queuing service rejects incoming messages when it is unable to check whether the sender is allowed access to the queue for sending messages

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2181: Message Queuing cannot establish new connections to this computer because connection limit was reached

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2182: Storage quota exceeded for MSMQ queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2183: Machine MSMQ storage quota was exceeded or there is insufficient disk space

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2184: Message Queuing could not resolve the name 'param1' to an IP address

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2185: A socket operation failed with error

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2186: Message Queuing could not establish connection to param1, because the connection limit for this computer was reached

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2187: Message Queuing could not establish connection to param1, because connection was refused by the recipient computer

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2188: Message Queuing could not access Active Directory Domain Services and failed to compute routing path for messages sent to queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 2189: Message Queuing failed to send a message due to low memory

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2190: Message Queuing could not complete SSL negotiation with the remote computer

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2191: Message Queuing could not validate server certificate in HTTPS scenario because the certificate was found in disallowed store

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2192: Message Queuing could not establish SSL connection with the recipient computer because a trust chain from the server certificate to a trusted Certificate Authority certificate could not be established

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2193: Message Queuing could not establish SSL connection with the recipient computer because the computer name specified in the HTTP queue format name does not match the name of the recipient server cert...

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2194: The Message Queuing service cannot communicate with other computers, because the select API for socket failed

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2195: Message Queuing could not authenticate a message sent to queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2196: Message Queuing failed to verify digital signature of a message sent to queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2197: Message Queuing failed to listen on the IPv6 protocol

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2198: Message Queuing failed to listen on the IPv4 protocol

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2199: Message Queuing Service failed to listen on both IPv4 and IPv6 protocol

#
Channel
Operational

Event ID 2220: The IP address param1 specified in the \HKLM\Software\Microsoft\MSMQ\Parameters\param2 registry value is not a valid IP address for this computer

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 2221: Message Queuing will use the IP address

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2224: The MSMQ VSS Writer object cannot be created

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2225: The MSMQ VSS Writer failed to register with the VSS

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2226: The MSMQ VSS Writer failed to identify itself

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2227: Backup failed during event

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2228: Restore failed during event

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2229: The MSMQ VSS Writer failed to handle the restore located at 'param3'

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 2230: A backup (components: param1) was completed successfully

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString

Event ID 2231: A restore was completed successfully

#
Channel
Operational

Event ID 2232: The restore located at 'param1' was handled successfully

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2233: The MSMQ VSS Writer is disabled through the registry setting

#
Channel
Operational

Event ID 2234: The restore located at 'param1' is invalid

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2250: Message Queuing will not be able to accept messages temporarily because system paged pool is low

#
Channel
Operational

Event ID 2251: Message Queuing will not be able to accept messages temporarily because system commit is low

#
Channel
Operational

Event ID 2252: Message Queuing is resuming accepting messages because the system memory usage has normalized

#
Channel
Operational

Event ID 2253: The message could not be moved to deadletter queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Event ID 2254: The message could not be moved to deadletter queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2255: The message could not be moved to deadletter queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 2256: The message could not be moved to deadletter queue

#
Channel
Operational

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 1073743848: The Message Queuing serivce performance counter data are not available.

#
Channel
Operational

Description

The Message Queuing serivce performance counter data are not available. The performance counter module failed to initialize. Please run 'lodctr.exe mqperf.ini' from the command console and restart the service, or contact Microsoft support. Error param1: param2

Message #

The Message Queuing serivce performance counter data are not available. The performance counter module failed to initialize. Please run 'lodctr.exe mqperf.ini' from the command console and restart the service, or contact Microsoft support. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 1073743852: The Message Queuing service started.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-MSMQ",
    "event_id": 2028,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-03-13T20:00:50.4932819+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Application"
  },
  "event_data": {}
}

Event ID 1073743884: The Message Queuing service is online with Active Directory Domain Services and fully operational.

#
Channel
Operational

Event ID 1073743910: The message file 'param1' was successfully created.

#
Channel
Operational

Message #

The message file '%1' was successfully created.

Fields #

NameDescription
param1

Event ID 1073743949: The Message Queuing service successfully joined the computer's domain 'param1'.

#
Channel
Operational

Message #

The Message Queuing service successfully joined the computer's domain '%1'.

Fields #

NameDescription
param1

Event ID 1073743950: Message Queuing left the domain and is now operating in workgroup mode.

#
Channel
Operational

Event ID 1073743958: Message Queuing successfully moved to the param1 domain.

#
Channel
Operational

Description

Message Queuing successfully moved to the domain.

Message #

Message Queuing successfully moved to the %1 domain.

Fields #

NameDescription
param1

Event ID 1073743959: The computer belongs to the param1 domain.

#
Channel
Operational

Description

The computer belongs to the param1 domain. It is recommended that you use the MoveTree utility to move the msmq (MSMQ Configuration) object of this computer from the param2 domain (its previous domain) to the current domain.

Message #

The computer belongs to the %1 domain. It is recommended that you use the MoveTree utility to move the msmq (MSMQ Configuration) object of this computer from the %2 domain (its previous domain) to the current domain.

Fields #

NameDescription
param1
param2

Event ID 1073743983: Message Queuing Down-level Client Support started.

#
Channel
Operational

Event ID 1073743987: The Message Queuing service stopped.

#
Channel
Operational

Event ID 1073743991: Message Queuing is operating in Hardened mode.

#
Channel
Operational

Event ID 1073743996: The MsmqServices object is configured with weakened security to support MSMQ 1.

#
Channel
Operational

Description

The MsmqServices object is configured with weakened security to support MSMQ 1.0 clients. With weakened security, the Message Queuing Down-level Client Support service will use its own rights (under the LocalSystem account on a domain controller) to view object properties, but it will not bypass the security restrictions on creating Message Queuing objects and setting their properties.

Message #

The MsmqServices object is configured with weakened security to support MSMQ 1.0 clients. With weakened security, the Message Queuing Down-level Client Support service will use its own rights (under the LocalSystem account on a domain controller) to view object properties, but it will not bypass the security restrictions on creating Message Queuing objects and setting their properties.

Event ID 1073743997: The MsmqServices object is configured with default security.

#
Channel
Operational

Description

The MsmqServices object is configured with default security. MSMQ 1.0 clients will not be able to query Active Directory Domain Services in this configuration.

Message #

The MsmqServices object is configured with default security. MSMQ 1.0 clients will not be able to query Active Directory Domain Services in this configuration.

Event ID 1073744000: Message Queuing found multiple IP addresses for the local computer.

#
Channel
Operational

Description

Message Queuing found multiple IP addresses for the local computer. Message Queuing will use the default IP address determined by the PGM driver for multicast messages. To use a different IP address, set the \HKLM\Software\Microsoft\MSMQ\Parameters\param1 registry value to one of the following valid IP addresses: param2.

Message #

Message Queuing found multiple IP addresses for the local computer. Message Queuing will use the default IP address determined by the PGM driver for multicast messages. To use a different IP address, set the \HKLM\Software\Microsoft\MSMQ\Parameters\%1 registry value to one of the following valid IP addresses: %2!S!.

Fields #

NameDescription
param1
param2

Event ID 1073744045: Message Queuing will use the IP address param1.

#
Channel
Operational

Description

Message Queuing will use the IP address . To use a different IP address, set the \HKLM\Software\Microsoft\MSMQ\Parameters\ registry value to one of the following valid IP addresses: !S!.

Message #

Message Queuing will use the IP address %1. To use a different IP address, set the \HKLM\Software\Microsoft\MSMQ\Parameters\%2 registry value to one of the following valid IP addresses: %3!S!.

Fields #

NameDescription
param1
param2
param3

Event ID 1073744054: A backup (components: param1) was completed successfully.

#
Channel
Operational

Description

A backup (components: ) was completed successfully.

Message #

A backup (components: %1) was completed successfully.

Fields #

NameDescription
param1

Event ID 1073744055: A restore was completed successfully.

#
Channel
Operational

Event ID 1073744056: The restore located at 'param1' was handled successfully.

#
Channel
Operational

Description

The restore located at 'param1' was handled successfully. Restored components are param2.

Message #

The restore located at '%1' was handled successfully. Restored components are %2.

Fields #

NameDescription
param1
param2

Event ID 1073744057: The MSMQ VSS Writer is disabled through the registry setting.

#
Channel
Operational

Description

The MSMQ VSS Writer is disabled through the registry setting. Backup and restore support is not available. To enable the writer, please delete registry value DisableMsmqVSSWriter or set it to 0.

Message #

The MSMQ VSS Writer is disabled through the registry setting. Backup and restore support is not available. To enable the writer, please delete registry value DisableMsmqVSSWriter or set it to 0.

Event ID 1073744076: Message Queuing is resuming accepting messages because the system memory usage has normalized.

#
Channel
Operational

Event ID 2147485691: The Message Queuing service deleted message 'param1'.

#
Channel
Operational

Description

The Message Queuing service deleted message 'param1'. The message cannot be restored because the queue 'param2' does not exist.

Message #

The Message Queuing service deleted message '%1'. The message cannot be restored because the queue '%2' does not exist.

Fields #

NameDescription
param1
param2

Event ID 2147485692: The Message Queuing service has insufficient privileges to create audit log messages.

#
Channel
Operational

Event ID 2147485693: The Message Queuing down-level client support service has insufficient privileges to create audit log messages.

#
Channel
Operational

Event ID 2147485703: The Message Queuing service session cleanup is taking longer than expected.

#
Channel
Operational

Message #

The Message Queuing service session cleanup is taking longer than expected. This indicates a potential DoS attack and an excessively high value configured for the QueueCountLimit DWORD registry value at HKLM\Software\Microsoft\MSMQ\Parameters\QueueCountLimit. The current value set for QueueCountLimit is '%1'. Consider setting it to a lower value to protect the service from DoS attacks.

Event ID 2147485707: The Message Queuing service cannot communicate with other computers, because the RPC interface cannot use the TCP/IP protocol.

#
Channel
Operational

Description

The Message Queuing service cannot communicate with other computers, because the RPC interface cannot use the TCP/IP protocol. Error.

Message #

The Message Queuing service cannot communicate with other computers, because the RPC interface cannot use the TCP/IP protocol. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 2147485735: The Client Access License (CAL) limit was reached.

#
Channel
Operational

Description

The Client Access License (CAL) limit was reached. This server is unable to serve more clients. This may lead to messaging performance degradation. See the Windows documentation for information on how to increase your client license limit. This event is logged no more than once per param1 seconds.

Message #

The Client Access License (CAL) limit was reached. This server is unable to serve more clients. This may lead to messaging performance degradation. See the Windows documentation for information on how to increase your client license limit. This event is logged no more than once per %1 seconds.

Fields #

NameDescription
param1

Event ID 2147485771: The Message Queuing server cannot determine if the local domain controller is trusted for delegation.

#
Channel
Operational

Description

The Message Queuing server cannot determine if the local domain controller is trusted for delegation. This may indicate a serious problem. For more information, see Help and Support Center.

Message #

The Message Queuing server cannot determine if the local domain controller is trusted for delegation. This may indicate a serious problem. For more information, see Help and Support Center.

Event ID 2147485787: Message Queuing detected a problem with the local domain controller.

#
Channel
Operational

Description

Message Queuing detected a problem with the local domain controller. Until the problem is resolved, Message Queuing will function unpredictably. Using Event Viewer, inspect the directory service, File Replication Service, and system logs to help identify the problem.

Message #

Message Queuing detected a problem with the local domain controller. Until the problem is resolved, Message Queuing will function unpredictably. Using Event Viewer, inspect the directory service, File Replication Service, and system logs to help identify the problem.

Event ID 2147485788: This server was unable to resolve the IP addresses of other routing servers.

#
Channel
Operational

Description

This server was unable to resolve the IP addresses of other routing servers. Please check that all computers are registered in DNS.

Message #

This server was unable to resolve the IP addresses of other routing servers. Please check that all computers are registered in DNS.

Event ID 2147485792: There is an inconsistency between the actual network addresses and the addresses that are listed on other Message Queuing servers for this computer.

#
Channel
Operational

Description

There is an inconsistency between the actual network addresses and the addresses that are listed on other Message Queuing servers for this computer. If this computer belongs to an MSMQ 1.0 site, you should use MSMQ Explorer on the local primary site controller (PSC) to manually update the addresses listed for this computer.

Message #

There is an inconsistency between the actual network addresses and the addresses that are listed on other Message Queuing servers for this computer. If this computer belongs to an MSMQ 1.0 site, you should use MSMQ Explorer on the local primary site controller (PSC) to manually update the addresses listed for this computer.

Event ID 2147485800: The Message Queuing directory service is not running as a local system.

#
Channel
Operational

Description

The Message Queuing directory service is not running as a local system. To get the directory service functionality, you need to run as a local system.

Message #

The Message Queuing directory service is not running as a local system. To get the directory service functionality, you need to run as a local system.

Event ID 2147485801: Message Queuing Down-level Client Support cannot start.

#
Channel
Operational

Description

Message Queuing Down-level Client Support cannot start. This service can operate only on a domain controller. The service can be disabled by using Computer Management to change its startup type in the Properties dialog box from Automatic to Manual or Disabled.

Message #

Message Queuing Down-level Client Support cannot start. This service can operate only on a domain controller. The service can be disabled by using Computer Management to change its startup type in the Properties dialog box from Automatic to Manual or Disabled.

Event ID 2147485805: The mapping of the URL param1 to the queue param2 was ignored.

#
Channel
Operational

Description

The mapping of the URL to the queue was ignored. This URL is already mapped to another queue.

Message #

The mapping of the URL %1 to the queue %2 was ignored. This URL is already mapped to another queue.

Fields #

NameDescription
param1
param2

Event ID 2147485809: The mapping of the URL param1 to the queue param2 is ignored.

#
Channel
Operational

Description

The mapping of the URL to the queue is ignored. This queue name is not a valid URL-style queue name.

Message #

The mapping of the URL %1 to the queue %2 is ignored. This queue name is not a valid URL-style queue name.

Fields #

NameDescription
param1
param2

Event ID 2147485810: Message Queuing Down-level Client Support failed to create the MSMQ Configuration (msmq) object with a given GUID for computer param1.

#
Channel
Operational

Description

Message Queuing Down-level Client Support failed to create the MSMQ Configuration (msmq) object with a given GUID for computer param1. Creating MSMQ Configuration objects with given GUIDs may be required for Message Queuing clients during the setup of Windows NT 4.0 or Windows 9x computers and when a Windows 2000 computer joins a Windows Server 2003 (or later) domain. By default, an Active Directory Domain Services forest does not support adding an object with a supplied GUID. You can solve this problem by upgrading Message Queuing on the client computer to a version that does not require creating an object with a given GUID. There are also alternative solutions.

Message #

Message Queuing Down-level Client Support failed to create the MSMQ Configuration (msmq) object with a given GUID for computer %1. Creating MSMQ Configuration objects with given GUIDs may be required for Message Queuing clients during the setup of Windows NT 4.0 or Windows 9x computers and when a Windows 2000 computer joins a Windows Server 2003 (or later) domain. By default, an Active Directory Domain Services forest does not support adding an object with a supplied GUID. You can solve this problem by upgrading Message Queuing on the client computer to a version that does not require creating an object with a given GUID. There are also alternative solutions.

Fields #

NameDescription
param1

Event ID 2147485813: The sites where the computer resides cannot be resolved.

#
Channel
Operational

Description

The sites where the computer resides cannot be resolved. Check that the subnets in your network are configured correctly in Active Directory Domain Services and that each site is configured with the appropriate subnet.

Message #

The sites where the computer resides cannot be resolved. Check that the subnets in your network are configured correctly in Active Directory Domain Services and that each site is configured with the appropriate subnet.

Event ID 2147485819: Message Queuing cannot bind to UDP port 3527.

#
Channel
Operational

Description

Message Queuing cannot bind to UDP port 3527. Message Queuing's internal ping mechanism uses this port to establish network connections. Another process may be using this port. Message Queuing can continue to operate without using this port, but connection times will not be optimal. To optimize the establishment of connections, free this port and restart Message Queuing.

Message #

Message Queuing cannot bind to UDP port 3527. Message Queuing's internal ping mechanism uses this port to establish network connections. Another process may be using this port. Message Queuing can continue to operate without using this port, but connection times will not be optimal. To optimize the establishment of connections, free this port and restart Message Queuing.

Event ID 2147485823: Message Queuing will use an encryption key with an effective length of 40 bits when sending messages encrypted with the RC2 encryption algorithm.

#
Channel
Operational

Description

Message Queuing will use an encryption key with an effective length of 40 bits when sending messages encrypted with the RC2 encryption algorithm. To restore strong encryption, remove the registry value HKLM\Software\Microsoft\MSMQ\Parameters\Security\SendEnhRC2With40.

Message #

Message Queuing will use an encryption key with an effective length of 40 bits when sending messages encrypted with the RC2 encryption algorithm. To restore strong encryption, remove the registry value HKLM\Software\Microsoft\MSMQ\Parameters\Security\SendEnhRC2With40.

Event ID 2147485829: Message Queuing cannot establish new connections to this computer because connection limit was reached.

#
Channel
Operational

Description

Message Queuing cannot establish new connections to this computer because connection limit was reached. There are too many computers attempting to send messages to or receive from this computer. This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2181 registry value to desired time in seconds.

Message #

Message Queuing cannot establish new connections to this computer because connection limit was reached.  There are too many computers attempting to send messages to or receive from this computer. This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2181 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485830: Storage quota exceeded for MSMQ queue param1.

#
Channel
Operational

Description

Storage quota exceeded for MSMQ queue param1. No more messages can be stored in the queue. You can increase a queue's storage quota by editing queue properties in Computer Management console. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2182 registry value to desired time in seconds.

Message #

Storage quota exceeded for MSMQ queue %1. No more messages can be stored in the queue.  You can increase a queue's storage quota by editing queue properties in Computer Management console. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2182 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485831: Machine MSMQ storage quota was exceeded or there is insufficient disk space.

#
Channel
Operational

Description

Machine MSMQ storage quota was exceeded or there is insufficient disk space. No more messages can be stored in user queues. You can increase Message Queuing storage quota or purge unneeded messages by using Computer Management console. This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2183 registry value to desired time in seconds.

Message #

Machine MSMQ storage quota was exceeded or there is insufficient disk space. No more messages can be stored in user queues.  You can increase Message Queuing storage quota or purge unneeded messages by using Computer Management console. This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2183 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485832: Message Queuing could not resolve the name 'param1' to an IP address.

#
Channel
Operational

Description

Message Queuing could not resolve the name 'param1' to an IP address. Try to ping the recipient computer, and check this computer's DNS settings. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2184 registry value to desired time in seconds.

Message #

Message Queuing could not resolve the name '%1' to an IP address. Try to ping the recipient computer, and check this computer's DNS settings.  This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2184 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485833: A socket operation failed with error param1.

#
Channel
Operational

Description

A socket operation failed with error param1. Next hop address is param2. Message Queuing cannot send the message now, but it will retry to send the message. This event is logged at most once per param3 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2185 registry value to desired time in seconds.

Message #

A socket operation failed with error %1. Next hop address is %2!S!. Message Queuing cannot send the message now, but it will retry to send the message. This event is logged at most once per %3 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2185 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2
param3

Event ID 2147485834: Message Queuing could not establish connection to param1, because the connection limit for this computer was reached.

#
Channel
Operational

Description

Message Queuing could not establish connection to param1, because the connection limit for this computer was reached. There too many computers trying to send to or receive messages from this computer. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2186 registry value to desired time in seconds.

Message #

Message Queuing could not establish connection to %1, because the connection limit for this computer was reached. There too many computers trying to send to or receive messages from this computer. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2186 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485835: Message Queuing could not establish connection to param1, because connection was refused by the recipient computer.

#
Channel
Operational

Description

Message Queuing could not establish connection to param1, because connection was refused by the recipient computer. It is possible that Client Access Licenses (CALs) are exhausted (if the recipient is a Windows Server), or connection limit has been reached (if the recipient is a Windows workstation). This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2187 registry value to desired time in seconds.

Message #

Message Queuing could not establish connection to %1, because connection was refused by the recipient computer.  It is possible that Client Access Licenses (CALs) are exhausted (if the recipient is a Windows Server), or connection limit has been reached (if the recipient is a Windows workstation). This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2187 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485836: Message Queuing could not access Active Directory Domain Services and failed to compute routing path for messages sent to queue param3.

#
Channel
Operational

Description

Message Queuing could not access Active Directory Domain Services and failed to compute routing path for messages sent to queue param3. Messages will wait in the outgoing queue until connection with Active Directory Domain Services is restored. This event is logged at most once per param4 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2188 registry value to desired time in seconds. Error param1: param2

Message #

Message Queuing could not access Active Directory Domain Services and failed to compute routing path for messages sent to queue %3. Messages will wait in the outgoing queue until connection with Active Directory Domain Services is restored.  This event is logged at most once per %4 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2188 registry value to desired time in seconds. Error %1: %2

Fields #

NameDescription
param1
param2
param3
param4

Event ID 2147485837: Message Queuing failed to send a message due to low memory.

#
Channel
Operational

Description

Message Queuing failed to send a message due to low memory. Message Queuing will retry to send the message. This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2189 registry value to desired time in seconds.

Message #

Message Queuing failed to send a message due to low memory. Message Queuing will retry to send the message. This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2189 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485838: Message Queuing could not complete SSL negotiation with the remote computer.

#
Channel
Operational

Description

Message Queuing could not complete SSL negotiation with the remote computer. It is possible that the server certificate is not properly installed, or that remote computer is not listening on port 443 (SSL). This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2190 registry value to desired time in seconds.

Message #

Message Queuing could not complete SSL negotiation with the remote computer. It is possible that the server certificate is not properly installed, or that remote computer is not listening on port 443 (SSL). This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2190 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485839: Message Queuing could not validate server certificate in HTTPS scenario because the certificate was found in disallowed store.

#
Channel
Operational

Description

Message Queuing could not validate server certificate in HTTPS scenario because the certificate was found in disallowed store. This means the certificate cannot be trusted. This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2191 registry value to desired time in seconds.

Message #

Message Queuing could not validate server certificate in HTTPS scenario because the certificate was found in disallowed store. This means the certificate cannot be trusted. This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2191 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485840: Message Queuing could not establish SSL connection with the recipient computer because a trust chain from the server certificate to a trusted Certi...

#
Channel
Operational

Description

Message Queuing could not establish SSL connection with the recipient computer because a trust chain from the server certificate to a trusted Certificate Authority certificate could not be established. This event is logged at most once per param3 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2192 registry value to desired time in seconds. Error param1: param2

Message #

Message Queuing could not establish SSL connection with the recipient computer because a trust chain from the server certificate to a trusted Certificate Authority certificate could not be established. This event is logged at most once per %3 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2192 registry value to desired time in seconds. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 2147485841: Message Queuing could not establish SSL connection with the recipient computer because the computer name specified in the HTTP queue format name do...

#
Channel
Operational

Description

Message Queuing could not establish SSL connection with the recipient computer because the computer name specified in the HTTP queue format name does not match the name of the recipient server certificate. This event is logged at most once per param1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2193 registry value to desired time in seconds.

Message #

Message Queuing could not establish SSL connection with the recipient computer because the computer name specified in the HTTP queue format name does not match the name of the recipient server certificate. This event is logged at most once per %1 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2193 registry value to desired time in seconds.

Fields #

NameDescription
param1

Event ID 2147485843: Message Queuing could not authenticate a message sent to queue param1.

#
Channel
Operational

Description

Message Queuing could not authenticate a message sent to queue param1. The message was rejected because the queue only accepts authenticated messages. It is possible that sender did not sign the message, or signed it with a self-signed certificate. A negative arrival acknowledgement will be sent if requested by the sender. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2195 registry value to desired time in seconds.

Message #

Message Queuing could not authenticate a message sent to queue %1. The message was rejected because the queue only accepts authenticated messages. It is possible that sender did not sign the message, or signed it with a self-signed certificate. A negative arrival acknowledgement will be sent if requested by the sender. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2195 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485844: Message Queuing failed to verify digital signature of a message sent to queue param1.

#
Channel
Operational

Description

Message Queuing failed to verify digital signature of a message sent to queue param1. The message was rejected. A negative arrival acknowledgement will be sent if requested by the sender. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2196 registry value to desired time in seconds.

Message #

Message Queuing failed to verify digital signature of a message sent to queue %1. The message was rejected. A negative arrival acknowledgement will be sent if requested by the sender. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2196 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485845: Message Queuing failed to listen on the IPv6 protocol.

#
Channel
Operational

Description

Message Queuing failed to listen on the IPv6 protocol. Messages will not be accepted on IPv6. If you want Message Queuing to accept messages on IPv6 protocol, please verify that the IPv6 protocol is installed and operational (Restarting the machine is required). Error param1: param2

Message #

Message Queuing failed to listen on the IPv6 protocol. Messages will not be accepted on IPv6.  If you want Message Queuing to accept messages on IPv6 protocol, please verify that the IPv6 protocol is installed and operational (Restarting the machine is required). Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 2147485846: Message Queuing failed to listen on the IPv4 protocol.

#
Channel
Operational

Description

Message Queuing failed to listen on the IPv4 protocol. Messages will not be accepted on IPv4. If you want Message Queuing to accept messages on IPv4 protocol, please verify that the IPv4 protocol is installed and operational (Restarting the machine is required). Error param1: param2

Message #

Message Queuing failed to listen on the IPv4 protocol. Messages will not be accepted on IPv4.  If you want Message Queuing to accept messages on IPv4 protocol, please verify that the IPv4 protocol is installed and operational (Restarting the machine is required). Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 2147485872: The MSMQ VSS Writer object cannot be created.

#
Channel
Operational

Description

The MSMQ VSS Writer object cannot be created. Error : .

Message #

The MSMQ VSS Writer object cannot be created. Error %1: %2.

Fields #

NameDescription
param1
param2

Event ID 2147485873: The MSMQ VSS Writer failed to register with the VSS.

#
Channel
Operational

Description

The MSMQ VSS Writer failed to register with the VSS. Please make sure that the VSS is running. Error : .

Message #

The MSMQ VSS Writer failed to register with the VSS. Please make sure that the VSS is running. Error %1: %2.

Fields #

NameDescription
param1
param2

Event ID 2147485898: Message Queuing will not be able to accept messages temporarily because system paged pool is low.

#
Channel
Operational

Description

Message Queuing will not be able to accept messages temporarily because system paged pool is low. During this period, machine quota will be set to 0. No manual intervention is required at this stage. Once memory utilization has normalized, Message Queuing will automatically resume accepting messages.

Message #

Message Queuing will not be able to accept messages temporarily because system paged pool is low. During this period, machine quota will be set to 0. No manual intervention is required at this stage. Once memory utilization has normalized, Message Queuing will automatically resume accepting messages.

Event ID 2147485899: Message Queuing will not be able to accept messages temporarily because system commit is low.

#
Channel
Operational

Description

Message Queuing will not be able to accept messages temporarily because system commit is low. During this period, machine quota will be set to 0. No manual intervention is required at this stage. Once memory utilization has normalized, Message Queuing will automatically resume accepting messages.

Message #

Message Queuing will not be able to accept messages temporarily because system commit is low. During this period, machine quota will be set to 0. No manual intervention is required at this stage. Once memory utilization has normalized, Message Queuing will automatically resume accepting messages.

Event ID 2147485901: The message could not be moved to deadletter queue param3.

#
Channel
Operational

Description

The message could not be moved to deadletter queue param3. Check that queue exists and users have permissions to send. The message was moved to the system transactional dead letter queue. This event is logged at most once per param4 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2253 registry value to desired time in seconds. Error param1: param2

Message #

The message could not be moved to deadletter queue %3. Check that queue exists and users have permissions to send. The message was moved to the system transactional dead letter queue. This event is logged at most once per %4 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2253 registry value to desired time in seconds. Error %1: %2

Fields #

NameDescription
param1
param2
param3
param4

Event ID 2147485902: The message could not be moved to deadletter queue param1.

#
Channel
Operational

Description

The message could not be moved to deadletter queue param1. The deadletter queue is authenticated and the authenticity of the message could not be verified. The message will be moved to the system transactional dead letter queue. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2254 registry value to desired time in seconds.

Message #

The message could not be moved to deadletter queue %1. The deadletter queue is authenticated and the authenticity of the message could not be verified. The message will be moved to the system transactional dead letter queue. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2254 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485903: The message could not be moved to deadletter queue param1.

#
Channel
Operational

Description

The message could not be moved to deadletter queue param1. Deadletter queues should not require privacy of messages. The message will be moved to the system transactional dead letter queue. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2255 registry value to desired time in seconds.

Message #

The message could not be moved to deadletter queue %1. Deadletter queues should not require privacy of messages. The message will be moved to the system transactional dead letter queue. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2255 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 2147485904: The message could not be moved to deadletter queue param1.

#
Channel
Operational

Description

The message could not be moved to deadletter queue param1. The deadletter queue needs to be transactional. The message will be moved to the system transactional dead letter queue. This event is logged at most once per param2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2256 registry value to desired time in seconds.

Message #

The message could not be moved to deadletter queue %1. The deadletter queue needs to be transactional. The message will be moved to the system transactional dead letter queue. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2256 registry value to desired time in seconds.

Fields #

NameDescription
param1
param2

Event ID 3221227472: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\' cannot be retrieved from the local Windows Registry. Error.

Message #

The Message Queuing service cannot start. The registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\%3' cannot be retrieved from the local Windows Registry. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227473: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\' cannot be written to the local Windows Registry. Error.

Message #

The Message Queuing service cannot start. The registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\%3' cannot be written to the local Windows Registry. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227487: The Message Queuing service is not online with Active Directory Domain Services.

#
Channel
Operational

Description

The Message Queuing service is not online with Active Directory Domain Services. The MSMQ Configuration object (msmq) ID stored in the registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\MachineCache\QMId' was found under the computer name 'param1' in Active Directory Domain Services. Please relocate this MSMQ Configuration object under the local computer name in Active Directory Domain Services. The service attempts to locate a matching MSMQ Configuration object every few minutes.

Message #

The Message Queuing service is not online with Active Directory Domain Services. The MSMQ Configuration object (msmq) ID stored in the registry value '\HKLM\SOFTWARE\Microsoft\MSMQ\Parameters\MachineCache\QMId' was found under the computer name '%1' in Active Directory Domain Services. Please relocate this MSMQ Configuration object under the local computer name in Active Directory Domain Services. The service attempts to locate a matching MSMQ Configuration object every few minutes.

Fields #

NameDescription
param1

Event ID 3221227488: The Message Queuing service is not online with Active Directory Domain Services, since the service properties cannot be retrieved or set.

#
Channel
Operational

Description

The Message Queuing service is not online with Active Directory Domain Services, since the service properties cannot be retrieved or set. The service will attempt to retrieve and set its properties in a few minutes. Error param1: param2

Message #

The Message Queuing service is not online with Active Directory Domain Services, since the service properties cannot be retrieved or set. The service will attempt to retrieve and set its properties in a few minutes. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227492: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The internal private queue 'param3' cannot be initialized. If the problem persists, reinstall Message Queuing. Error param1: param2.

Message #

The Message Queuing service cannot start. The internal private queue '%3' cannot be initialized. If the problem persists, reinstall Message Queuing. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227495: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The message store cannot be reloaded. Error.

Message #

The Message Queuing service cannot start. The message store cannot be reloaded. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227507: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The Active Directory Domain Services interface cannot be initialized. Error.

Message #

The Message Queuing service cannot start. The Active Directory Domain Services interface cannot be initialized. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227519: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. A connection with the Distributed Transaction Coordinator cannot be established. Error.

Message #

The Message Queuing service cannot start. A connection with the Distributed Transaction Coordinator cannot be established. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227520: The server cannot support the automatic recognition of sites and connected networks for down-level clients.

#
Channel
Operational

Description

The server cannot support the automatic recognition of sites and connected networks for down-level clients. The problem might be caused by Active Directory Domain Services replication delay. Please restart MQDS service after replication completed.

Message #

The server cannot support the automatic recognition of sites and connected networks for down-level clients.  The problem might be caused by Active Directory Domain Services replication delay. Please restart MQDS service after replication completed.

Event ID 3221227521: A multicast listener received a request with headers size exceeding the configured max size of '%1'.

#
Channel
Operational

Message #

A multicast listener received a request with headers size exceeding the configured max size of '%1'. As a result, the request has been rejected. If this is a legitimate request, increase the default limit by creating a DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\MaxSRMPHeaderSize and setting it to a higher value. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2049 registry value to desired time in seconds.

Event ID 3221227522: A multicast listener received a request with content-length header size of '%1' that exceeds the configured max size of '%2'.

#
Channel
Operational

Message #

A multicast listener received a request with content-length header size of '%1' that exceeds the configured max size of '%2'. As a result, the request has been rejected. If this is a legitimate request, increase the default limit by creating a DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\MaxSRMPBodySize and setting it to a higher value. This event is logged at most once per %3 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2050 registry value to desired time in seconds.

Event ID 3221227523: The Message Queuing service rejected a request since the deserialization hit the maximum allowed xml depth of '%1'.

#
Channel
Operational

Message #

The Message Queuing service rejected a request since the deserialization hit the maximum allowed xml depth of '%1'. This limit can be increased by creating a DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\MaxXmlDepth and setting it to a higher value. Note that increasing the value could expose the service to potential DoS attacks. Watch for event ID 2052 as a sign of such attacks. This event is logged at most once per %2 seconds. To change this setting, set \HKLM\Software\Microsoft\MSMQ\Parameters\Event2051 registry value to desired time in seconds.

Event ID 3221227524: The request's deserialization led to a stack overflow exception in the Message Queuing service.

#
Channel
Operational

Message #

The request's deserialization led to a stack overflow exception in the Message Queuing service. This indicates a potential DoS attack and an excessively high value configured for the MaxXmlDepth DWORD registry value at HKLM\Software\Microsoft\MSMQ\Parameters\MaxXmlDepth. The current value set for MaxXmlDepth is '%1'. Consider setting it to a lower value to prevent the service from consuming excessive memory.

Event ID 3221227525: The incoming sequences checkpoint file failed to initialize.

#
Channel
Operational

Description

The incoming sequences checkpoint file failed to initialize. The file MQInSeqs.lg1 or MQInSeqs.lg2 in the Msmq\Storage folder is corrupted or absent. Error.

Message #

The incoming sequences checkpoint file failed to initialize. The file MQInSeqs.lg1 or MQInSeqs.lg2 in the Msmq\Storage folder is corrupted or absent. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227526: The Message Queuing service rejected an attempt to create a queue because the total number of queues has reached the maximum allowed limit of '%1' ...

#
Channel
Operational

Message #

The Message Queuing service rejected an attempt to create a queue because the total number of queues has reached the maximum allowed limit of '%1' This limit can be increased by creating a DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\QueueCountLimit and setting it to a higher value. Note that increasing the value could expose the service to potential DoS attacks. Watch for event ID 2055 as a sign of such attacks.

Event ID 3221227533: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The local RPC interface cannot be initialized. Error.

Message #

The Message Queuing service cannot start. The local RPC interface cannot be initialized. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227536: The transactions checkpoint file failed to initialize.

#
Channel
Operational

Description

The transactions checkpoint file failed to initialize. The file MQTrans.lg1 or MQTrans.lg2 in the Msmq\Storage folder are corrupted or absent. Error.

Message #

The transactions checkpoint file failed to initialize. The file MQTrans.lg1 or MQTrans.lg2 in the Msmq\Storage folder are corrupted or absent. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227540: The list of Message Queuing servers with directory service functionality in the Windows registry is empty.

#
Channel
Operational

Event ID 3221227548: The logger files cannot be initialized.

#
Channel
Operational

Description

The logger files cannot be initialized. The file QMLog in the Msmq\Storage folder is corrupted or absent. Error.

Message #

The logger files cannot be initialized. The file QMLog in the Msmq\Storage folder is corrupted or absent. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227550: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The checkpoint files cannot be recovered. To start the Message Queuing service without losing consistency, you must correct or recover corrupted checkpoint and log files. To start the service for emergency use (with a potential loss of data consistency), delete the files QMLog, MQTrans.lg1, MQTrans.lg2, MQInSeqs.lg1, and MQInSeqs.lg2 from the Msmq\Storage folder and add the DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\LogDataCreated with a value of 0. Error param1: param2

Message #

The Message Queuing service cannot start. The checkpoint files cannot be recovered. To start the Message Queuing service without losing consistency, you must correct or recover corrupted checkpoint and log files. To start the service for emergency use (with a potential loss of data consistency), delete the files QMLog, MQTrans.lg1, MQTrans.lg2, MQInSeqs.lg1, and MQInSeqs.lg2 from the Msmq\Storage folder and add the DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\LogDataCreated with a value of 0. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227551: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The log file cannot be recovered. To start the Message Queuing service without losing consistency, you must correct or recover corrupted checkpoint and log files. To start the service for emergency use (with a potential loss of data consistency), delete the files QMLog, MQTrans.lg1, MQTrans.lg2, MQInSeqs.lg1, and MQInSeqs.lg2 from the Msmq\Storage folder and add the DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\LogDataCreated with a value of 0. Error param1: param2

Message #

The Message Queuing service cannot start. The log file cannot be recovered. To start the Message Queuing service without losing consistency, you must correct or recover corrupted checkpoint and log files. To start the service for emergency use (with a potential loss of data consistency), delete the files QMLog, MQTrans.lg1, MQTrans.lg2, MQInSeqs.lg1, and MQInSeqs.lg2 from the Msmq\Storage folder and add the DWORD registry key HKLM\Software\Microsoft\MSMQ\Parameters\LogDataCreated with a value of 0. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227555: The Message Queuing service cannot start.

#
Channel
Operational

Description

The Message Queuing service cannot start. The message file 'param3' and the log file 'param4' cannot be reloaded. Error param1: param2.

Message #

The Message Queuing service cannot start. The message file '%3' and the log file '%4' cannot be reloaded. Error %1: %2

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221227556: The Message Queuing service cannot start because a queue is in an inconsistent state.

#
Channel
Operational

Description

The Message Queuing service cannot start because a queue is in an inconsistent state. For more information, see Microsoft Knowledge Base article 827493 at support.microsoft.com.

Message #

The Message Queuing service cannot start because a queue is in an inconsistent state. For more information, see Microsoft Knowledge Base article 827493 at support.microsoft.com.

Event ID 3221227557: The message file 'param1' cannot be created.

#
Channel
Operational

Description

The message file 'param1' cannot be created. There is insufficient disk space or memory.

Message #

The message file '%1' cannot be created. There is insufficient disk space or memory.

Fields #

NameDescription
param1

Event ID 3221227567: Since an MSMQ 1.

#
Channel
Operational

Description

Since an MSMQ 1.0 primary site controller owns the queue, you must manually delete the queue from the MSMQ 1.0 site (use MSMQ Explorer running on an applicable the site controller).

Message #

Since an MSMQ 1.0 primary site controller owns the queue, you must manually delete the queue from the MSMQ 1.0 site (use MSMQ Explorer running on an applicable the site controller).

Event ID 3221227568: The Message Queuing folder cannot be created.

#
Channel
Operational

Event ID 3221227569: The Message Queuing registry values cannot be read (the registry is probably corrupted).

#
Channel
Operational

Event ID 3221227588: Message Queuing was unable to create the msmq (MSMQ Configuration) object in Active Directory Domain Services.

#
Channel
Operational

Description

Message Queuing was unable to create the msmq (MSMQ Configuration) object in Active Directory Domain Services. Error.

Message #

Message Queuing was unable to create the msmq (MSMQ Configuration) object in Active Directory Domain Services. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227589: Message Queuing was unable to load Mqupgrd.

#
Channel
Operational

Description

Message Queuing was unable to load Mqupgrd.dll. Error.

Message #

Message Queuing was unable to load Mqupgrd.dll. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227590: Message Queuing was unable to find the address of MqCreateMsmqObj in Mqupgrd.

#
Channel
Operational

Description

Message Queuing was unable to find the address of MqCreateMsmqObj in Mqupgrd.dll. Error.

Message #

Message Queuing was unable to find the address of MqCreateMsmqObj in Mqupgrd.dll. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227591: Message Queuing Setup cannot be completed.

#
Channel
Operational

Event ID 3221227592: The Message Queuing service was unable to obtain the properties of the msmq (MSMQ Configuration) object from Active Directory Domain Services.

#
Channel
Operational

Description

The Message Queuing service was unable to obtain the properties of the msmq (MSMQ Configuration) object from Active Directory Domain Services. This may be caused by an Active Directory Domain Services replication delay. Please wait several minutes and then restart the Message Queuing service. Error param1: param2

Message #

The Message Queuing service was unable to obtain the properties of the msmq (MSMQ Configuration) object from Active Directory Domain Services. This may be caused by an Active Directory Domain Services replication delay. Please wait several minutes and then restart the Message Queuing service. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227594: This domain controller is not trusted for delegation.

#
Channel
Operational

Description

This domain controller is not trusted for delegation. Therefore, the Message Queuing server cannot run. See Help and Support Center for information about how to enable the "This computer is trusted for delegation" property.

Message #

This domain controller is not trusted for delegation. Therefore, the Message Queuing server cannot run. See Help and Support Center for information about how to enable the "This computer is trusted for delegation" property.

Event ID 3221227596: The Message Queuing service failed to join the computer's domain 'param3'.

#
Channel
Operational

Description

The Message Queuing service failed to join the computer's domain 'param3'. Error param1: param2.

Message #

The Message Queuing service failed to join the computer's domain '%3'. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227599: Message Queuing objects cannot move automatically between domains.

#
Channel
Operational

Description

Message Queuing objects cannot move automatically between domains (). You must either run the MoveTree utility or first uninstall Message Queuing and then reinstall it in the new domain.

Message #

Message Queuing objects cannot move automatically between domains (%1). You must either run the MoveTree utility or first uninstall Message Queuing and then reinstall it in the new domain.

Fields #

NameDescription
param1

Event ID 3221227613: The properties of the queue param3 cannot be set.

#
Channel
Operational

Description

The properties of the queue cannot be set. Copying the queue file to the temporary file returned error.

Message #

The properties of the queue %3 cannot be set. Copying the queue file %4 to the temporary file %5 returned error %1: %2

Fields #

NameDescription
param1
param2
param3
param4
param5

Event ID 3221227614: The properties of the queue param3 cannot be set.

#
Channel
Operational

Description

The properties of the queue cannot be set. Replacing the queue file with the temporary file returned error.

Message #

The properties of the queue %3 cannot be set. Replacing the queue file %4 with the temporary file %5 returned error %1: %2

Fields #

NameDescription
param1
param2
param3
param4
param5

Event ID 3221227615: The Microsoft Distributed Transaction Coordinator (DTC) failed.

#
Channel
Operational

Description

The Microsoft Distributed Transaction Coordinator (DTC) failed. The Message Queuing service cannot continue. Please restart the DTC and the Message Queuing service.

Message #

The Microsoft Distributed Transaction Coordinator (DTC) failed. The Message Queuing service cannot continue. Please restart the DTC and the Message Queuing service.

Event ID 3221227617: The computer object for this computer was not found in Active Directory Domain Services, possibly because of Active Directory Domain Services repli...

#
Channel
Operational

Description

The computer object for this computer was not found in Active Directory Domain Services, possibly because of Active Directory Domain Services replication delays.

Message #

The computer object for this computer was not found in Active Directory Domain Services, possibly because of Active Directory Domain Services replication delays.

Event ID 3221227619: The service cannot start due to insufficient disk space or memory.

#
Channel
Operational

Event ID 3221227620: The service cannot start due to its failure to connect to its device driver.

#
Channel
Operational

Event ID 3221227621: The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services at the end of the domain cont...

#
Channel
Operational

Description

The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services at the end of the domain controller demotion process.

Message #

The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services at the end of the domain controller demotion process.

Event ID 3221227622: The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services during the domain controller ...

#
Channel
Operational

Description

The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services during the domain controller promotion process.

Message #

The Message Queuing directory service failed to update the directory service flag in Active Directory Domain Services during the domain controller promotion process.

Event ID 3221227623: Obsolete, kept for backward compatibility

#
Channel
Operational

Event ID 3221227626: A multicast listener initialization failed.

#
Channel
Operational

Description

A multicast listener initialization failed. The file 'param3' may be corrupted. Error param1: param2.

Message #

A multicast listener initialization failed. The file '%3' may be corrupted. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227627: The Message Queuing service stopped monitoring the mapping folder param3.

#
Channel
Operational

Description

The Message Queuing service stopped monitoring the mapping folder . Error.

Message #

The Message Queuing service stopped monitoring the mapping folder %3. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227628: The mapping file param3 was ignored.

#
Channel
Operational

Description

The mapping file was ignored. Its content cannot be read. Error.

Message #

The mapping file %3 was ignored. Its content cannot be read. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227630: The mapping file param1 was ignored because it was improperly formatted.

#
Channel
Operational

Description

The mapping file was ignored because it was improperly formatted.

Message #

The mapping file %1 was ignored because it was improperly formatted.

Fields #

NameDescription
param1

Event ID 3221227632: The queue cannot listen/bind to the multicast address param3.

#
Channel
Operational

Description

The queue cannot listen/bind to the multicast address . Error.

Message #

The queue cannot listen/bind to the multicast address %3. Error %1: %2

Fields #

NameDescription
param1
param2
param3

Event ID 3221227636: The Message Queuing service will not join the param1 domain.

#
Channel
Operational

Description

The Message Queuing service will not join the param1 domain. An MSMQ Configuration (msmq) object exists in the new domain with an ID differing from the service ID. Please delete the MSMQ Configuration object in the new domain, restart the Message Queuing service, and log on again.

Message #

The Message Queuing service will not join the %1 domain. An MSMQ Configuration (msmq) object exists in the new domain with an ID differing from the service ID. Please delete the MSMQ Configuration object in the new domain, restart the Message Queuing service, and log on again.

Fields #

NameDescription
param1

Event ID 3221227638: The Message Queuing service cannot join the 'param1' Windows NT 4.

#
Channel
Operational

Description

The Message Queuing service cannot join the 'param1' Windows NT 4.0 domain. The Active Directory Domain Services Integration subcomponent was therefore removed.

Message #

The Message Queuing service cannot join the '%1' Windows NT 4.0 domain. The Active Directory Domain Services Integration subcomponent was therefore removed.

Fields #

NameDescription
param1

Event ID 3221227640: The Message Queuing service resource cannot bind to the cluster IP address.

#
Channel
Operational

Description

The Message Queuing service resource cannot bind to the cluster IP address. This prevents the Message Queuing resource from coming online on this node. One possible reason is that the Message Queuing service running on the physical node was started before the computer became a member of the server cluster. As a result, the Message Queuing service running on the physical node listens on all IP addresses of the computer and prevents the Message Queuing resource from listening on the cluster IP address. To solve this problem, restart the Message Queuing service on the physical node. Error param1: param2

Message #

The Message Queuing service resource cannot bind to the cluster IP address. This prevents the Message Queuing resource from coming online on this node. One possible reason is that the Message Queuing service running on the physical node was started before the computer became a member of the server cluster. As a result, the Message Queuing service running on the physical node listens on all IP addresses of the computer and prevents the Message Queuing resource from listening on the cluster IP address. To solve this problem, restart the Message Queuing service on the physical node. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227641: The local computer is a Message Queuing routing server that formerly belonged to the 'param1' domain and is now operating in workgroup mode.

#
Channel
Operational

Description

The local computer is a Message Queuing routing server that formerly belonged to the 'param1' domain and is now operating in workgroup mode. Other Message Queuing clients still regard this computer as a routing server and will try to route messages through this computer. To solve this problem, you need to manually delete the Message Queuing objects for this computer in Active Directory Domain Services. Please delete the following two objects: 1) The msmq object under the computer object of this computer in the Computers container in the Active Directory Users and Computers snap-in: 'CN=msmq,CN=param2,CN=computers,DC=param1,DC=...' 2) The MSMQ Settings object under the server object for this computer in the Active Directory Sites and Services snap-in: 'CN=MSMQ Settings,CN=param2,CN=Servers,CN=<SiteName>,CN=Sites,CN=Configuration,DC=...' You also need to uninstall Routing Support and Down-level Client Support by using Server Role Manager.

Message #

The local computer is a Message Queuing routing server that formerly belonged to the '%1' domain and is now operating in workgroup mode. Other Message Queuing clients still regard this computer as a routing server and will try to route messages through this computer. To solve this problem, you need to manually delete the Message Queuing objects for this computer in Active Directory Domain Services. Please delete the following two objects: 1) The msmq object under the computer object of this computer in the Computers container in the Active Directory Users and Computers snap-in: 'CN=msmq,CN=%2,CN=computers,DC=%1,DC=...' 2) The MSMQ Settings object under the server object for this computer in the Active Directory Sites and Services snap-in: 'CN=MSMQ Settings,CN=%2,CN=Servers,CN=<SiteName>,CN=Sites,CN=Configuration,DC=...' You also need to uninstall Routing Support and Down-level Client Support by using Server Role Manager.

Fields #

NameDescription
param1
param2

Event ID 3221227642: Message Queuing failed to bind to port 1801.

#
Channel
Operational

Description

Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Message #

Message Queuing failed to bind to port 1801. The port may already be bound to another process. Make sure that the port is free and try to start Message Queuing again. If this problem arises during setup, you must free the port and run setup again.

Event ID 3221227646: Message Queuing Down-level Client Support cannot operate in mixed mode.

#
Channel
Operational

Description

Message Queuing Down-level Client Support cannot operate in mixed mode. Mixed mode is a transient mode in which Message Queuing deployment is in the middle of migration from MQIS (for MSMQ 1.0) to Active Directory Domain Services. In this mode, some sites are still Windows NT 4.0 sites and are mastered by the PEC and PSCs. Mixed mode might require creating/deleting/updating objects that belong to Windows NT 4.0 sites. These operations are not supported by Message Queuing Down-level Client Support. After completing the migration of all Windows NT 4.0 sites to Active Directory Domain Services (migration of the PEC and all PSCs in Windows NT 4.0 sites), Message Queuing will no longer be in mixed mode.

Message #

Message Queuing Down-level Client Support cannot operate in mixed mode. Mixed mode is a transient mode in which Message Queuing deployment is in the middle of migration from MQIS (for MSMQ 1.0) to Active Directory Domain Services. In this mode, some sites are still Windows NT 4.0 sites and are mastered by the PEC and PSCs. Mixed mode might require creating/deleting/updating objects that belong to Windows NT 4.0 sites. These operations are not supported by Message Queuing Down-level Client Support. After completing the migration of all Windows NT 4.0 sites to Active Directory Domain Services (migration of the PEC and all PSCs in Windows NT 4.0 sites), Message Queuing will no longer be in mixed mode.

Event ID 3221227649: The Message Queuing service rejects incoming messages when it is unable to check whether the sender is allowed access to the queue for sending mess...

#
Channel
Operational

Description

The Message Queuing service rejects incoming messages when it is unable to check whether the sender is allowed access to the queue for sending messages. In this case, the queue affected is param1, but note that an event might not be issued every time this problem occurs. To perform this access check, Message Queuing needs access to the TokenGroupsGlobalAndUniversal attribute of the sender's user object. Only users with domain administration permissions can add members to the Windows Authorization Access Group, which is allowed access to the TokenGroupsGlobalAndUniversal attribute, in one of two ways: 1) For best security practice, add only the computer accounts that need access to the TokenGroupsGlobalAndUniversal attribute to the Windows Authorization Access Group. The domain administrator will repeat this operation for other Message Queuing computers that require the permission, manually adding the relevant accounts to the Windows Authorization Access Group. 2) As a less secure practice, add the Authenticated Users group to the Windows Authorization Access group. This grants every authenticated user, including the Message Queuing service on any computer, access to the TokenGroupsGlobalAndUniversal attribute for all users, and requires no further manual administration.

Message #

The Message Queuing service rejects incoming messages when it is unable to check whether the sender is allowed access to the queue for sending messages. In this case, the queue affected is %1, but note that an event might not be issued every time this problem occurs.
 To perform this access check, Message Queuing needs access to the TokenGroupsGlobalAndUniversal attribute of the sender's user object. Only users with domain administration permissions can add members to the Windows Authorization Access Group, which is allowed access to the TokenGroupsGlobalAndUniversal attribute, in one of two ways:
 1) For best security practice, add only the computer accounts that need access to the TokenGroupsGlobalAndUniversal attribute to the Windows Authorization Access Group. The domain administrator will repeat this operation for other Message Queuing computers that require the permission, manually adding the relevant accounts to the Windows Authorization Access Group.
 2) As a less secure practice, add the Authenticated Users group to the Windows Authorization Access group. This grants every authenticated user, including the Message Queuing service on any computer, access to the TokenGroupsGlobalAndUniversal attribute for all users, and requires no further manual administration.

Fields #

NameDescription
param1

Event ID 3221227666: The Message Queuing service cannot communicate with other computers, because the select API for socket failed.

#
Channel
Operational

Description

The Message Queuing service cannot communicate with other computers, because the select API for socket failed. Error.

Message #

The Message Queuing service cannot communicate with other computers, because the select API for socket failed. Error %1: %2

Fields #

NameDescription
param1
param2

Event ID 3221227671: Message Queuing Service failed to listen on both IPv4 and IPv6 protocol.

#
Channel
Operational

Description

Message Queuing Service failed to listen on both IPv4 and IPv6 protocol. Messages will not be accepted from the network through TCP/IP protocols. Messages addressed to this machine using TCP/IP protocols will not arrive but will accumulate in sender's outgoing queues. Please fix the TCP/IP protocols issue and restart the computer.

Message #

Message Queuing Service failed to listen on both IPv4 and IPv6 protocol. Messages will not be accepted from the network through TCP/IP protocols.  Messages addressed to this machine using TCP/IP protocols will not arrive but will accumulate in sender's outgoing queues.   Please fix the TCP/IP protocols issue and restart the computer.

Event ID 3221227692: The IP address param1 specified in the \HKLM\Software\Microsoft\MSMQ\Parameters\param2 registry value is not a valid IP address for this computer.

#
Channel
Operational

Description

The IP address param1 specified in the \HKLM\Software\Microsoft\MSMQ\Parameters\param2 registry value is not a valid IP address for this computer. The Message Queuing service will use the IP address param3 instead. Please remove this registry value or set it to one of the following valid IP addresses: param4.

Message #

The IP address %1 specified in the \HKLM\Software\Microsoft\MSMQ\Parameters\%2 registry value is not a valid IP address for this computer. The Message Queuing service will use the IP address %3!S! instead. Please remove this registry value or set it to one of the following valid IP addresses: %4!S!.

Fields #

NameDescription
param1
param2
param3
param4

Event ID 3221227698: The MSMQ VSS Writer failed to identify itself.

#
Channel
Operational

Description

The MSMQ VSS Writer failed to identify itself. Error : .

Message #

The MSMQ VSS Writer failed to identify itself. Error %1: %2.

Fields #

NameDescription
param1
param2

Event ID 3221227699: Backup failed during event param3.

#
Channel
Operational

Description

Backup failed during event . Error : .

Message #

Backup failed during event %3. Error %1: %2.

Fields #

NameDescription
param1
param2
param3

Event ID 3221227700: Restore failed during event param3.

#
Channel
Operational

Description

Restore failed during event . Error : . This can happen if the restore directories under the MSMQ root directory cannot be created, or the restore root directory cannot be written in registry.

Message #

Restore failed during event %3. Error %1: %2. This can happen if the restore directories under the MSMQ root directory cannot be created, or the restore root directory cannot be written in registry.

Fields #

NameDescription
param1
param2
param3

Event ID 3221227701: The MSMQ VSS Writer failed to handle the restore located at 'param3'.

#
Channel
Operational

Description

The MSMQ VSS Writer failed to handle the restore located at 'param3'. Error param1: param2.

Message #

The MSMQ VSS Writer failed to handle the restore located at '%3'. Error %1: %2.

Fields #

NameDescription
param1
param2
param3

Event ID 3221227706: The restore located at 'param1' is invalid.

#
Channel
Operational

Description

The restore located at 'param1' is invalid. Invalid components are param2. Please verify all required files are present in the correct directory.

Message #

The restore located at '%1' is invalid. Invalid components are %2. Please verify all required files are present in the correct directory.

Fields #

NameDescription
param1
param2

Provenance

ETW provider GUID ce18af71-5efd-4f5a-9bd5-635e34632f69

Defined in mqutil.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3207, captured 2026-06-02 — Manifest XML pack, 1.9 MB