Microsoft-Windows-Network-Connection-Broker

32 events across 1 channel

EventTitleChannelSample
1001StatusDescription - Status : Status.Microsoft-Windows-Network-Connection-BrokerY
1002Reference: Reference -RefCount : RefCount, file: file line: line.Microsoft-Windows-Network-Connection-BrokerN
1003Dereference: Dereference -RefCount : RefCount, file: file line: line.Microsoft-Windows-Network-Connection-BrokerN
1101Provider registration completed with context Object and status Status.Microsoft-Windows-Network-Connection-BrokerN
1102Provider deregistration completed with context Object and status Status.Microsoft-Windows-Network-Connection-BrokerN
1103Provider rundown completed with context Object and status Status.Microsoft-Windows-Network-Connection-BrokerN
1104Update sample completed for context ContextHandle, provider Provider, value …Microsoft-Windows-Network-Connection-BrokerN
1105Network change occured, new value = Value, new value type = ValueType.Microsoft-Windows-Network-Connection-BrokerY
1106Collecting provider Provider with request holder RequestHolder for notification.Microsoft-Windows-Network-Connection-BrokerY
1107Accepting update request for provider ContextHandle finished with status Status.Microsoft-Windows-Network-Connection-BrokerY
1108Completing update request for provider Provider finished with status Status.Microsoft-Windows-Network-Connection-BrokerY
1109Provider Provider created with refcount RefCount.Microsoft-Windows-Network-Connection-BrokerN
1110Provider Provider destroyed.Microsoft-Windows-Network-Connection-BrokerN
1111Provider Provider referenced, the previous refcount was RefCount.Microsoft-Windows-Network-Connection-BrokerY
1112Provider Provider dereferenced, the previous refcount was RefCount.Microsoft-Windows-Network-Connection-BrokerY
1113Description updated timer values -.Microsoft-Windows-Network-Connection-BrokerY
1114LogMessage.Microsoft-Windows-Network-Connection-BrokerN
1115Reference context: Reference_context -RefCount : RefCount, file: file line: …Microsoft-Windows-Network-Connection-BrokerN
1116Dereference context: Dereference_context -RefCount : RefCount, file: file line: …Microsoft-Windows-Network-Connection-BrokerN
1117CCReset event occurred of type ApplicationRestart for package: PackageName and …Microsoft-Windows-Network-Connection-BrokerN
2001Socket Broker: Registered trigger notifications for event id EventId and …Microsoft-Windows-Network-Connection-BrokerN
2002Socket Broker: De-Registered trigger notifications for event id EventId and …Microsoft-Windows-Network-Connection-BrokerN
2003Socket Broker: Application AppName is transferring ownership of a socket …Microsoft-Windows-Network-Connection-BrokerN
2004Socket Broker: Application AppName is retrieving socket SocketId for event id …Microsoft-Windows-Network-Connection-BrokerN
2005Socket Broker: BICreateEvent is called for event id BrokerEventId and …Microsoft-Windows-Network-Connection-BrokerN
2006Socket Broker: BIEnableEvent is called for event id BrokerEventId, application …Microsoft-Windows-Network-Connection-BrokerN
2007Socket Broker: BIDisableEvent is called for event id BrokerEventId, application …Microsoft-Windows-Network-Connection-BrokerN
2008Socket Broker: BIDeleteEvent is called for event id BrokerEventId, application …Microsoft-Windows-Network-Connection-BrokerN
2009Socket Broker: Notifying background task for event id BrokerEventId, socket id …Microsoft-Windows-Network-Connection-BrokerY
2010Socket Broker: CreatePushEnabledContext for event id BrokerEventId returned …Microsoft-Windows-Network-Connection-BrokerN
2011Socket Broker: RetrieveContext for event id BrokerEventId and socket id SocketId …Microsoft-Windows-Network-Connection-BrokerN
2012Socket Broker: EnumerateSockets for application name AppName returned status …Microsoft-Windows-Network-Connection-BrokerN

Event ID 1001: StatusDescription - Status : Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

StatusDescription - Status : Status

Message #

%1 - Status : %2

Fields #

NameDescription
StatusDescription UnicodeString
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1001,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 12396
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Status": 0,
    "StatusDescription": "Kam: processed network change notification"
  },
  "message": ""
}

Event ID 1002: Reference: Reference -RefCount : RefCount, file: file line: line.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Reference: Reference -RefCount : RefCount, file: file line: line.

Message #

Reference: %1 -RefCount : %2,  file: %3 line: %4

Fields #

NameDescription
StatusDescription UnicodeString
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1003: Dereference: Dereference -RefCount : RefCount, file: file line: line.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Dereference: Dereference -RefCount : RefCount, file: file line: line.

Message #

Dereference: %1 -RefCount : %2,  file: %3 line: %4

Fields #

NameDescription
StatusDescription UnicodeString
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1101: Provider registration completed with context Object and status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Provider registration completed with context Object and status Status.

Message #

Provider registration completed with context %1 and status %2

Fields #

NameDescription
Object Pointer
Status UInt32NTSTATUS reference

Event ID 1102: Provider deregistration completed with context Object and status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Provider deregistration completed with context Object and status Status.

Message #

Provider deregistration completed with context %1 and status %2

Fields #

NameDescription
Object Pointer
Status UInt32NTSTATUS reference

Event ID 1103: Provider rundown completed with context Object and status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Provider rundown completed with context Object and status Status.

Message #

Provider rundown completed with context %1 and status %2

Fields #

NameDescription
Object Pointer
Status UInt32NTSTATUS reference

Event ID 1104: Update sample completed for context ContextHandle, provider Provider, value Value, value type ValueType with status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Update sample completed for context ContextHandle, provider Provider, value Value, value type ValueType with status Status.

Message #

Update sample completed for context %1, provider %2, value %6, value type %7 with status %9

Fields #

NameDescription
ContextHandle Pointer
Provider Pointer
ServiceNlmEpoch UInt64
ServiceNlmSignature Pointer
ClientNlmEpoch UInt64
Value UInt32
ValueType Int32
ScheduleUpdate Boolean
Status UInt32NTSTATUS reference

Event ID 1105: Network change occured, new value = Value, new value type = ValueType.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Network change occured, new value = Value, new value type = ValueType.

Message #

Network change occured, new value = %7, new value type = %8

Fields #

NameDescription
NlmEpochBefore UInt64
NlmSignatureBefore Pointer
NlmSignatureStableBefore Boolean
NlmEpochAfter UInt64
NlmSignatureAfter Pointer
NlmSignatureStableAfter Boolean
Value UInt32
ValueType Int32
ScheduleUpdate Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1105,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 8316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NlmEpochAfter": 2,
    "NlmEpochBefore": 1,
    "NlmSignatureAfter": "0x2445AA7E210",
    "NlmSignatureBefore": "0x2445AA98550",
    "NlmSignatureStableAfter": true,
    "NlmSignatureStableBefore": true,
    "ScheduleUpdate": true,
    "Value": 960,
    "ValueType": 1
  },
  "message": ""
}

Event ID 1106: Collecting provider Provider with request holder RequestHolder for notification.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Collecting provider Provider with request holder RequestHolder for notification.

Message #

Collecting provider %1 with request holder %2 for notification

Fields #

NameDescription
Provider Pointer
RequestHolder Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1106,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 8316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Provider": "0x2445AA98850",
    "RequestHolder": "0x2445AA722F0"
  },
  "message": ""
}

Event ID 1107: Accepting update request for provider ContextHandle finished with status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Accepting update request for provider ContextHandle finished with status Status.

Message #

Accepting update request for provider %1 finished with status %6

Fields #

NameDescription
ContextHandle Pointer
Provider Pointer
RequestHolder Pointer
UpdateRequested Boolean
CompleteCall Boolean
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1107,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.796+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{8BC7C5F0-6A9E-4327-B8D3-F0B6E97F4665}"
    },
    "execution": {
      "process_id": 8,
      "thread_id": 16080
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CompleteCall": false,
    "ContextHandle": "0x2445AA98850",
    "Provider": "0x2445AA98850",
    "RequestHolder": "0x0",
    "Status": 0,
    "UpdateRequested": false
  },
  "message": ""
}

Event ID 1108: Completing update request for provider Provider finished with status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Completing update request for provider Provider finished with status Status.

Message #

Completing update request for provider %1 finished with status %6

Fields #

NameDescription
Provider Pointer
RequestHolder Pointer
Value UInt32
ValueType Int32
NlmEpoch UInt64
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1108,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 8316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NlmEpoch": 2,
    "Provider": "0x2445AA98850",
    "RequestHolder": "0x2445AA722F0",
    "Status": 0,
    "Value": 960,
    "ValueType": 1
  },
  "message": ""
}

Event ID 1109: Provider Provider created with refcount RefCount.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Provider Provider created with refcount RefCount.

Message #

Provider %1 created with refcount %2

Fields #

NameDescription
Provider Pointer
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1110: Provider Provider destroyed.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Provider Provider destroyed.

Message #

Provider %1 destroyed

Fields #

NameDescription
Provider Pointer
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1111: Provider Provider referenced, the previous refcount was RefCount.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Provider Provider referenced, the previous refcount was RefCount.

Message #

Provider %1 referenced, the previous refcount was %2

Fields #

NameDescription
Provider Pointer
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1111,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 8316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FileName": "onecoreuap\\net\\netio\\iphlpsvc\\kaprovider\\kapisrv\\kapisrv.c",
    "LineNumber": 1386,
    "Provider": "0x2445AA98850",
    "RefCount": 1
  },
  "message": ""
}

Event ID 1112: Provider Provider dereferenced, the previous refcount was RefCount.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Provider Provider dereferenced, the previous refcount was RefCount.

Message #

Provider %1 dereferenced, the previous refcount was %2

Fields #

NameDescription
Provider Pointer
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1112,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:07.763+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 8316
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "FileName": "onecoreuap\\net\\netio\\iphlpsvc\\kaprovider\\kapisrv\\kapisrv.c",
    "LineNumber": 1352,
    "Provider": "0x2445AA98850",
    "RefCount": 2
  },
  "message": ""
}

Event ID 1113: Description updated timer values -.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Description updated timer values -.

Message #

%1 updated timer values - 
 app input value %2 current timeout value %3 stored timeout value %4 wns test timeout value %5

Fields #

NameDescription
Description UnicodeString
Appprovidedtime UInt32
Currentkeepalivetime UInt32
Loweredkeepalivetime UInt32
WNStestinputtime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 1113,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000001",
    "time_created": "2026-06-02T05:29:07.769+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 16080
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "App provided time": 33,
    "Current keepalive time": 16,
    "Description": "Kam:KapiUpdateCallback",
    "Lowered keepalive time": 4294967295,
    "WNS test input time": 16
  },
  "message": ""
}

Event ID 1114: LogMessage.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

LogMessage

Message #

%1

Fields #

NameDescription
LogMessage UnicodeString

Event ID 1115: Reference context: Reference_context -RefCount : RefCount, file: file line: line.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Reference context: Reference_context -RefCount : RefCount, file: file line: line.

Message #

Reference context: %1 -RefCount : %2,  file: %3 line: %4

Fields #

NameDescription
StatusDescription UnicodeString
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1116: Dereference context: Dereference_context -RefCount : RefCount, file: file line: line.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Dereference context: Dereference_context -RefCount : RefCount, file: file line: line.

Message #

Dereference context: %1 -RefCount : %2,  file: %3 line: %4

Fields #

NameDescription
StatusDescription UnicodeString
RefCount UInt32
FileName AnsiString
LineNumber UInt32

Event ID 1117: CCReset event occurred of type ApplicationRestart for package: PackageName and fired: Fired.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

CCReset event occurred of type ApplicationRestart for package: PackageName and fired: Fired.

Message #

CCReset event occurred of type ApplicationRestart for package: %1 and fired: %2

Fields #

NameDescription
PackageName UnicodeString
Fired Boolean

Event ID 2001: Socket Broker: Registered trigger notifications for event id EventId and application name AppName.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: Registered trigger notifications for event id EventId and application name AppName.

Message #

Socket Broker: Registered trigger notifications for event id %1 and application name %2

Fields #

NameDescription
EventId GUID
AppName UnicodeString

Event ID 2002: Socket Broker: De-Registered trigger notifications for event id EventId and application name AppName.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: De-Registered trigger notifications for event id EventId and application name AppName.

Message #

Socket Broker: De-Registered trigger notifications for event id %1 and application name %2

Fields #

NameDescription
EventId GUID
AppName UnicodeString

Event ID 2003: Socket Broker: Application AppName is transferring ownership of a socket SocketId with address family AddressFamily, socket type SocketType, protocol Protocol, tcp listener IsTcpListener and eve...

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: Application AppName is transferring ownership of a socket SocketId with address family AddressFamily, socket type SocketType, protocol Protocol, tcp listener IsTcpListener and event id EventId.

Message #

Socket Broker: Application %3 is transferring ownership of a socket %2 with address family %4, socket type %5, protocol %6, tcp listener %7 and event id %1

Fields #

NameDescription
EventId GUID
SocketId UnicodeString
AppName UnicodeString
AddressFamily Int32
SocketType Int32
Protocol Int32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
IsTcpListener Boolean

Event ID 2004: Socket Broker: Application AppName is retrieving socket SocketId for event id EventId.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: Application AppName is retrieving socket SocketId for event id EventId.

Message #

Socket Broker: Application %3 is retrieving socket %2 for event id %1

Fields #

NameDescription
EventId GUID
SocketId UnicodeString
AppName UnicodeString

Event ID 2005: Socket Broker: BICreateEvent is called for event id BrokerEventId and application AppName.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: BICreateEvent is called for event id BrokerEventId and application AppName.

Message #

Socket Broker: BICreateEvent is called for event id %1 and application %2

Fields #

NameDescription
BrokerEventId GUID
AppName UnicodeString

Event ID 2006: Socket Broker: BIEnableEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: BIEnableEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

Message #

Socket Broker: BIEnableEvent is called for event id %1, application %2 and call reason %3

Fields #

NameDescription
BrokerEventId GUID
AppName UnicodeString
CallReason Int32

Event ID 2007: Socket Broker: BIDisableEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: BIDisableEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

Message #

Socket Broker: BIDisableEvent is called for event id %1, application %2 and call reason %3

Fields #

NameDescription
BrokerEventId GUID
AppName UnicodeString
CallReason Int32

Event ID 2008: Socket Broker: BIDeleteEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: BIDeleteEvent is called for event id BrokerEventId, application AppName and call reason CallReason.

Message #

Socket Broker: BIDeleteEvent is called for event id %1, application %2 and call reason %3

Fields #

NameDescription
BrokerEventId GUID
AppName UnicodeString
CallReason Int32

Event ID 2009: Socket Broker: Notifying background task for event id BrokerEventId, socket id SocketId, socket type SocketType, trigger reason TriggerReason and status Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker
Also via
realtime ETW trace
Level
Informational

Description

Socket Broker: Notifying background task for event id BrokerEventId, socket id SocketId, socket type SocketType, trigger reason TriggerReason and status Status.

Message #

Socket Broker: Notifying background task for event id %1, socket id %2, socket type %3, trigger reason %4 and status %5

Fields #

NameDescription
BrokerEventId GUID
SocketId UnicodeString
SocketType Int32
TriggerReason Int32
Status Int32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Network-Connection-Broker",
    "guid": "{3EB875EB-8F4A-4800-A00B-E484C97D7551}",
    "event_source_name": "",
    "event_id": 2009,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": "0x0000000000000000",
    "time_created": "2026-06-02T05:29:08.059+00:00",
    "event_record_id": 0,
    "correlation": {},
    "execution": {
      "process_id": 8,
      "thread_id": 16080
    },
    "channel": "ETW Trace",
    "computer": "JD-DC01-2022",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "BrokerEventId": "{00000000-0000-0000-0000-000000000000}",
    "SocketId": "NULL",
    "SocketType": 0,
    "Status": 0,
    "TriggerReason": 4
  },
  "message": ""
}

Event ID 2010: Socket Broker: CreatePushEnabledContext for event id BrokerEventId returned Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: CreatePushEnabledContext for event id BrokerEventId returned Status.

Message #

Socket Broker: CreatePushEnabledContext for event id %1 returned %2

Fields #

NameDescription
BrokerEventId GUID
Status Int32NTSTATUS reference

Event ID 2011: Socket Broker: RetrieveContext for event id BrokerEventId and socket id SocketId returned Status.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: RetrieveContext for event id BrokerEventId and socket id SocketId returned Status.

Message #

Socket Broker: RetrieveContext for event id %1 and socket id %2 returned %3

Fields #

NameDescription
BrokerEventId GUID
SocketId UnicodeString
Status Int32NTSTATUS reference

Event ID 2012: Socket Broker: EnumerateSockets for application name AppName returned status Status with sockets NumSockets.

#
Provider
Microsoft-Windows-Network-Connection-Broker
Channel
Microsoft-Windows-Network-Connection-Broker

Description

Socket Broker: EnumerateSockets for application name AppName returned status Status with sockets NumSockets.

Message #

Socket Broker: EnumerateSockets for application name %1 returned status %2 with sockets %3

Fields #

NameDescription
AppName UnicodeString
Status Int32NTSTATUS reference
NumSockets Int32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID {3EB875EB-8F4A-4800-A00B-E484C97D7551}

Defined in ncbservice.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads