Microsoft-Windows-OfflineFiles
31 events across 3 channels
Event ID 1: The Offline Files service started successfully.
#Description
The Offline Files service started successfully.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 1,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387920,
"time_created": "2026-05-30T04:03:24.6211326+00:00",
"event_record_id": 7,
"correlation": {},
"execution": {
"process_id": 9144,
"thread_id": 6004
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The Offline Files service started successfully."
}
Event ID 2: The Offline Files service is terminating.
#Description
The Offline Files service is terminating.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 2,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387920,
"time_created": "2026-05-30T04:03:24.2126163+00:00",
"event_record_id": 3,
"correlation": {},
"execution": {
"process_id": 11852,
"thread_id": 932
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The Offline Files service is terminating."
}
Event ID 3: The Offline Files service is waiting for all running tasks to complete.
#Description
The Offline Files service is waiting for all running tasks to complete.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387920,
"time_created": "2026-05-30T04:03:24.2177139+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 11852,
"thread_id": 12980
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The Offline Files service is waiting for all running tasks to complete."
}
Event ID 4: The Offline Files service has terminated.
#Description
The Offline Files service has terminated.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 4,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387920,
"time_created": "2026-05-30T04:03:24.2181741+00:00",
"event_record_id": 5,
"correlation": {},
"execution": {
"process_id": 11852,
"thread_id": 12980
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "The Offline Files service has terminated."
}
Event ID 5: The Offline Files service received a STOP or SHUTDOWN control from the Service Control Manager.
#Description
The Offline Files service received a STOP or SHUTDOWN control from the Service Control Manager. The service will now stop.
Message #
Event ID 6: The Offline Files driver.
#Description
The Offline Files driver (csc.sys) is not running.
Message #
Event ID 7: User logon detected.
#Event ID 8: User logoff detected.
#Description
User logoff detected.
Message #
Fields #
| Name | Description |
|---|---|
Info.Account UnicodeString | |
Info.Session UInt32 | |
Account UnicodeString | |
Session UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 8,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387912,
"time_created": "2026-05-30T04:14:38.6921031+00:00",
"event_record_id": 8,
"correlation": {},
"execution": {
"process_id": 9144,
"thread_id": 3416
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"user_data": {
"Info": {
"Account": "ludus\\domainuser",
"Session": "2"
}
},
"message": "User logoff detected\r\nAccount: ludus\\domainuser\r\nSession: 2"
}
Event ID 9: Path disconnected.
#Event ID 10: Path reconnected.
#Event ID 11: Offline Files configuration is being controlled by Group Policy.
#Description
Offline Files configuration is being controlled by Group Policy.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OfflineFiles",
"guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
"event_source_name": "",
"event_id": 11,
"version": 0,
"level": 4,
"task": 0,
"opcode": 0,
"keywords": 4611686018427387936,
"time_created": "2026-05-30T04:03:24.5587637+00:00",
"event_record_id": 6,
"correlation": {},
"execution": {
"process_id": 9144,
"thread_id": 6004
},
"channel": "Microsoft-Windows-OfflineFiles/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {},
"message": "Offline Files configuration is being controlled by Group Policy."
}
Event ID 12: Offline Files configuration is being controlled by WMI configuration classes Win32_OfflineFilesUserConfiguration and Win32_OfflineFilesMachineConfi...
#Description
Offline Files configuration is being controlled by WMI configuration classes Win32_OfflineFilesUserConfiguration and Win32_OfflineFilesMachineConfiguration.
Message #
Event ID 1000: Background agent failed startup, error = Text.
#Event ID 1001: Background Synchronization failed on Path.
#Event ID 1002: Background Synchronization executed successfully.
#Description
Background Synchronization executed successfully.
Message #
Event ID 1003: Background Synchronization has started on Path as client has not synced for MinutesSinceLastSync minutes.
#Event ID 1004: Path Path transitioned to slow link with latency = Latency and bandwidth = Bandwidth.
#Event ID 1005: Path Path transitioned to online with latency = Latency.
#Event ID 1006: Background Synchronization failed for FailedFileCount files on Path.
#Event ID 1007: Path Path transitioned to slow link mode so the user will work offline with background synchronization of the data to the file server.
#Event ID 1008: Path Path failed to transition to slow link mode due to an open handle on FileName.
#Event ID 1009: Path Path failed to transition to slow link mode due to an open handle.
#Event ID 2000: Sync info for Path Only the server copy exists.
#Event ID 2001: Sync info for Path Only the client copy exists.
#Description
Sync info for Path.
Message #
Fields #
| Name | Description |
|---|---|
Path UnicodeString | |
ClientIsDir Boolean | |
ClientChanged Boolean | |
ClientIsSparse Boolean | |
ClientCreatedOffline Boolean | |
ClientDeletedOffline Boolean | |
ClientLastWriteTime FILETIME | |
ClientChangeTime FILETIME | |
ClientAttributes UInt32 | |
ClientSize UInt64 | |
ServerDeleted Boolean | |
SyncState UInt32 | |
SyncStateText UnicodeString |
Event ID 2002: Sync info for Path Both client and server copies exist.
#Description
Sync info for Path.
Message #
Fields #
| Name | Description |
|---|---|
Path UnicodeString | |
ClientIsDir Boolean | |
ClientChanged Boolean | |
ClientIsSparse Boolean | |
ClientCreatedOffline Boolean | |
ClientLastWriteTime FILETIME | |
ClientChangeTime FILETIME | |
ClientAttributes UInt32 | |
ClientSize UInt64 | |
ServerIsDir Boolean | |
ServerChanged Boolean | |
ServerLastWriteTime FILETIME | |
ServerChangeTime FILETIME | |
ServerAttributes UInt32 | |
ServerSize UInt64 | |
SyncState UInt32 | |
SyncStateText UnicodeString |
Event ID 2003: Sync info for Path Server copy exists, client copy deleted.
#Description
Sync info for Path.
Message #
Fields #
| Name | Description |
|---|---|
Path UnicodeString | |
ClientIsDir Boolean | |
ClientChanged Boolean | |
ClientIsSparse Boolean | |
ClientCreatedOffline Boolean | |
ServerIsDir Boolean | |
ServerChanged Boolean | |
ServerLastWriteTime FILETIME | |
ServerChangeTime FILETIME | |
ServerAttributes UInt32 | |
ServerSize UInt64 | |
SyncState UInt32 | |
SyncStateText UnicodeString |
Event ID 2004: Sync info for Path Server copy exists, client copy replaced then deleted.
#Event ID 2005: Sync succeeded.
#Description
Sync succeeded.
Message #
Fields #
| Name | Description |
|---|---|
Path UnicodeString | |
Operation UnicodeString | Known values
|
Event ID 2006: Sync failed.
#Description
Sync failed.
Message #
Fields #
| Name | Description |
|---|---|
Path UnicodeString | |
Operation UnicodeString | Known values
|
ResultCode UnicodeString | |
Result UnicodeString |
Event ID 2010: Creation of new excluded file type.
#Event ID 2011: Rename of file SourcePath to file TargetPath was blocked.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 95353826-4fbe-41d4-9c42-f521c6e86360
Defined in cscsvc.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02