Microsoft-Windows-Ncasvc

EventTitleChannelSampleRule
1NCA service status changed.OperationalNN
2NCA status update.OperationalNN
3NCA API Activity Start, function: (ApiFunction).OperationalNN
4NCA API Activity End, function: (ApiFunction), error: (Error).OperationalNN
5NCA Evidence Collector Update, evcoll: (EvColl), old: (Old), new: (New).OperationalNN
6NCA Probe Start, type: (Type), resource: (Resource).OperationalNN
7NCA Probe End, type: (Type), resource: (Resource), result: (Result).OperationalNN
8NCA Probe Callback, type: (Type), code: (Code), error: (Error).OperationalNN
9NCA Source Configuration Update started.OperationalNN
10NCA Source Configuration Update complete.OperationalNN
11NCA Module ModuleName Initialization started.OperationalNN
12NCA Module ModuleName Initialization complete with error Error.OperationalNN
13NCA Module ModuleName Shutdown started.OperationalNN
14NCA Module ModuleName Shutdown complete.OperationalNN
15NCA Trigger Source.OperationalNN
10001NCA PerfTrack Scenario Event.OperationalNN
10002NCA PerfTrack Scenario Event.OperationalNN
10003NCA PerfTrack Scenario Event.OperationalNN
10004NCA PerfTrack Scenario Event.OperationalNN
10005NCA PerfTrack Scenario Event.OperationalNN
10006NCA PerfTrack Scenario Event.OperationalNN
10007NCA PerfTrack Scenario Event.OperationalNN
10008NCA PerfTrack Scenario Event.OperationalNN
10009NCA PerfTrack Scenario Event.OperationalNN
10010NCA PerfTrack Scenario Event.OperationalNN
10011NCA PerfTrack Scenario Event.OperationalNN
10012NCA PerfTrack Scenario Event.OperationalNN
10013NCA PerfTrack Scenario Event.OperationalNN
10014NCA PerfTrack Scenario Event.OperationalNN

Event ID 1: NCA service status changed.

#
Channel
Operational

Description

NCA service status changed. New Status: (Status).

Message #

NCA service status changed. New Status: (%1).

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 2: NCA status update.

#
Channel
Operational

Description

NCA status update. New Status: (Status, Substatus).

Message #

NCA status update. New Status: (%1, %2).

Fields #

NameDescription
Status UInt32NTSTATUS reference
Substatus UInt32NTSTATUS reference

Event ID 3: NCA API Activity Start, function: (ApiFunction).

#
Channel
Operational

Message #

NCA API Activity Start, function: (%1).

Fields #

NameDescription
ApiFunction UnicodeString

Event ID 4: NCA API Activity End, function: (ApiFunction), error: (Error).

#
Channel
Operational

Message #

NCA API Activity End, function: (%1), error: (%2).

Fields #

NameDescription
ApiFunction UnicodeString
Error UInt64

Event ID 5: NCA Evidence Collector Update, evcoll: (EvColl), old: (Old), new: (New).

#
Channel
Operational

Description

NCA Evidence Collector Update, evcoll: (EvColl), old: (Old), new: (New). User:(UserId).

Message #

NCA Evidence Collector Update, evcoll: (%1), old: (%2), new: (%3). User:(%4)

Fields #

NameDescription
EvColl UInt32
Old Boolean
New Boolean
UserId UInt64

Event ID 6: NCA Probe Start, type: (Type), resource: (Resource).

#
Channel
Operational

Message #

NCA Probe Start, type: (%1), resource: (%2)

Fields #

NameDescription
Type UInt32
Resource UnicodeString

Event ID 7: NCA Probe End, type: (Type), resource: (Resource), result: (Result).

#
Channel
Operational

Message #

NCA Probe End, type: (%1), resource: (%2), result: (%3)

Fields #

NameDescription
Type UInt32
Resource UnicodeString
Result UInt32

Event ID 8: NCA Probe Callback, type: (Type), code: (Code), error: (Error).

#
Channel
Operational

Message #

NCA Probe Callback, type: (%1), code: (%2), error: (%3)

Fields #

NameDescription
Type UInt32
Code UInt64
Error UInt64

Event ID 9: NCA Source Configuration Update started.

#
Channel
Operational

Message #

NCA %1 Configuration Update started.

Fields #

NameDescription
Source UnicodeString

Event ID 10: NCA Source Configuration Update complete.

#
Channel
Operational

Message #

NCA %1 Configuration Update complete.

Fields #

NameDescription
Source UnicodeString

Event ID 11: NCA Module ModuleName Initialization started.

#
Channel
Operational

Message #

NCA Module %1 Initialization started.

Fields #

NameDescription
ModuleName UnicodeString

Event ID 12: NCA Module ModuleName Initialization complete with error Error.

#
Channel
Operational

Message #

NCA Module %1 Initialization complete with error %2.

Fields #

NameDescription
ModuleName UnicodeString
Error UInt64

Event ID 13: NCA Module ModuleName Shutdown started.

#
Channel
Operational

Message #

NCA Module %1 Shutdown started.

Fields #

NameDescription
ModuleName UnicodeString

Event ID 14: NCA Module ModuleName Shutdown complete.

#
Channel
Operational

Message #

NCA Module %1 Shutdown complete.

Fields #

NameDescription
ModuleName UnicodeString

Event ID 15: NCA Trigger Source.

#
Channel
Operational

Description

NCA Trigger Source. Details: (Info).

Message #

NCA Trigger %1. Details: (%2).

Fields #

NameDescription
Source UnicodeString
Info UnicodeString

Event ID 10001: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_ActionableState
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10002: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_ActionableState
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10003: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_ResolveName
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10004: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_ResolveName
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10005: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_DAConnected
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10006: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_DAConnected
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10007: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_SmartcardRequired_SmartcardEntered
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10008: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_SmartcardRequired_SmartcardEntered
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10009: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_SmartcardEntered_DAConnected
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10010: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_SmartcardEntered_DAConnected
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10011: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_NAPRequired_DAConnected
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10012: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_NAPRequired_DAConnected
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10013: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_DTESucceeded
Opcode
Start

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Event ID 10014: NCA PerfTrack Scenario Event.

#
Channel
Operational
Task
NcaSvc_PerfTrack_InternetConnected_DTESucceeded
Opcode
Stop

Description

NCA PerfTrack Scenario Event. MachineId: NCA_PerfTrack_Scenario_Event_MachineId, SessionId: SessionId, DeploymentId: DeploymentId, StopState: StopState.

Message #

NCA PerfTrack Scenario Event. MachineId: %1, SessionId: %2, DeploymentId: %3, StopState: %4.

Fields #

NameDescription
MachineIdentifier UInt32
SessionIdentifier UInt32
DeploymentIdentifier UInt32
StopState UInt32

Provenance

ETW provider GUID 126ded58-a28d-4113-8e7a-59d7444b2af1

Defined in ncasvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB