Microsoft-Windows-NlaSvc
52 events across 2 channels
Event ID 4001: Entered State: Entered_State Interface Guid: Interface_Guid.
#Event ID 4002: Transitioning to State: CurrentOrNextState Interface Guid: InterfaceGuid.
#Event ID 4101: Received WMI Media Connect Notification for 'AdapterName' InterfaceGuid.
#Event ID 4102: Received WMI Media Disconnect Notification for 'AdapterName' InterfaceGuid.
#Event ID 4103: Route change has occurred for interface InterfaceGuid (MibNotificationType).
#Event ID 4104: Address change has occurred for interface InterfaceGuid (MibNotificationType).
#Event ID 4203: Start gateway resolution on interface InterfaceGuid for GatewayIpAddress.
#Event ID 4204: Stop gateway resolution on interface NlnsState for MAC.
#Event ID 4205: Gateway resolution failed on interface InterfaceGuid for GatewayIpAddress with error: ErrorCode.
#Description
Gateway resolution failed on interface InterfaceGuid for GatewayIpAddress with error: ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceGuid GUID | |
GatewayIpAddress UnicodeString | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-NlaSvc",
"guid": "63B530F8-29C9-4880-A5B4-B8179096E7B8",
"event_source_name": "",
"event_id": 4205,
"version": 0,
"level": 2,
"task": 3,
"opcode": 21,
"keywords": 4611686018427387938,
"time_created": "2026-03-15T05:30:49.223016+00:00",
"event_record_id": 1,
"correlation": {
"ActivityID": "6FDE36A2-B353-0009-B736-DE6F53B3DC01"
},
"execution": {
"process_id": 1992,
"thread_id": 12780
},
"channel": "Microsoft-Windows-NlaSvc/Operational",
"computer": "LAB-WIN11.ludus.domain",
"security": {
"user_id": "S-1-5-20"
}
},
"event_data": {
"InterfaceGuid": "8A1760B6-DC99-4B90-9C4A-029698E5AE27",
"GatewayIpAddress": "10.2.10.1",
"ErrorCode": 67
},
"message": ""
}
Event ID 4251: Plug-in data indicated from PluginName for entity EntityName (IndicatedRowCount rows).
#Event ID 4261: DHCP has stabilized for InterfaceGuid (NlaState).
#Event ID 4311: Start DsGetDcName(DnsSuffix,Flags) for DnsSuffix.
#Event ID 4312: Stop DsGetDcName(DnsSuffix,Flags) for DnsSuffix returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
#Event ID 4313: DsGetDcName(DnsSuffix,Flags) for DnsSuffix failed with error ErrorCode.
#Event ID 4321: Start DsGetDcName(Flags) for DS info.
#Event ID 4322: Stop DsGetDcName(Flags) for DS info returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
#Event ID 4323: DsGetDcName(Flags) for DS info failed with error ErrorCode.
#Event ID 4331: Start DsGetDcName(Flags) for root domain GUID.
#Event ID 4332: Stop DsGetDcName(Flags) for root domain GUID returned error ErrorCode (domain=RetrievedDomain, forest=RetrievedForest).
#Event ID 4333: DsGetDcName(Flags) for root domain GUID failed with error ErrorCode.
#Event ID 4341: Start LDAP authentication on interface Interface Name (Addresses) (Try Count tries).
#Event ID 4342: Stop LDAP authentication on interface Interface Name (Addresses).
#Event ID 4343: LDAP authentication on interface Interface Name (Addresses) failed with error ErrorCode.
#Description
LDAP authentication on interface Interface Name (Addresses) failed with error ErrorCode.
Message #
Fields #
| Name | Description |
|---|---|
InterfaceName UnicodeString | |
Addresses UnicodeString | |
TryCount UInt32 | |
ErrorCode UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-NlaSvc",
"event_id": 4343,
"level": "Error",
"task": "Ldap Authentication",
"opcode": null,
"time_created": "2026-03-29T23:39:11.7779321+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-NlaSvc/Operational"
},
"event_data": {
"Addresses": "10.2.10.11",
"Try Count": "3",
"Interface Name": "{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
"ErrorCode": "81"
}
}
Event ID 4351: Start ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries).
#Event ID 4352: Stop ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries).
#Event ID 4353: ldap_connect(Addresses) for DC=DcName (Try Number of Try Count tries) failed with ErrorCode.
#Event ID 4354: Start ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries).
#Event ID 4355: Stop ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries).
#Event ID 4356: ldap_bind(Addresses) for DC=DcName (Try Number of Try Count tries) failed with ErrorCode.
#Event ID 4401: Inserting identifying signature for interface InterfaceGuid.
#Event ID 4402: Inserting identified signature for interface InterfaceGuid.
#Event ID 4403: Removing identified signature for interface InterfaceGuid.
#Event ID 4404: Inserting identified signature for interface InterfaceGuid.
#Event ID 4405: Inserting identified signature for interface InterfaceGuid.
#Event ID 4407: Adding interface 'AdapterName' InterfaceGuid.
#Event ID 4408: Removing interface 'AdapterName' InterfaceGuid.
#Event ID 4409: Adding interface 'AdapterName' InterfaceGuid.
#Event ID 4410: Inserting identified signature for interface InterfaceGuid.
#Event ID 4411: Inserting identified signature for interface InterfaceGuid.
#Event ID 4451: Network on Reason is unlikely to be authentication-capable; authentication will continue in the background.
#Event ID 5002: Inserting identified signature for interface InterfaceGuid.
#Event ID 6101: Perftrack cancel event for interface 'AdapterName' InterfaceGuid.
#Event ID 6102: Perftrack cancel event for interface 'AdapterName' InterfaceGuid.
#Event ID 6103: Perftrack cancel event for interface 'AdapterName' InterfaceGuid.
#Event ID 6104: Perftrack cancel event for interface 'AdapterName' InterfaceGuid.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 63b530f8-29c9-4880-a5b4-b8179096e7b8
Defined in nlasvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02