Microsoft-Windows-OfflineFiles

EventTitleChannelSampleRule
1The Offline Files service started successfully.OperationalYN
2The Offline Files service is terminating.OperationalYN
3The Offline Files service is waiting for all running tasks to complete.OperationalYN
4The Offline Files service has terminated.OperationalYN
5The Offline Files service received a STOP or SHUTDOWN control from the Service …OperationalNN
6The Offline Files driver.SystemNN
7User logon detected.OperationalYN
8User logoff detected.OperationalYN
9Path disconnected.OperationalNN
10Path reconnected.OperationalNN
11Offline Files configuration is being controlled by Group Policy.OperationalYN
12Offline Files configuration is being controlled by WMI configuration classes …OperationalNN
1000Background agent failed startup, error = Text.OperationalNN
1001Background Synchronization failed on Path.OperationalNN
1002Background Synchronization executed successfully.OperationalNN
1003Background Synchronization has started on Path as client has not synced for …OperationalNN
1004Path Path transitioned to slow link with latency = Latency and bandwidth = …OperationalNN
1005Path Path transitioned to online with latency = Latency.OperationalNN
1006Background Synchronization failed for FailedFileCount files on Path.OperationalNN
1007Path Path transitioned to slow link mode so the user will work offline with …OperationalNN
1008Path Path failed to transition to slow link mode due to an open handle on …OperationalNN
1009Path Path failed to transition to slow link mode due to an open handle.OperationalNN
2000Sync info for Path Only the server copy exists.SyncLogNN
2001Sync info for Path Only the client copy exists.SyncLogNN
2002Sync info for Path Both client and server copies exist.SyncLogNN
2003Sync info for Path Server copy exists, client copy deleted.SyncLogNN
2004Sync info for Path Server copy exists, client copy replaced then deleted.SyncLogNN
2005Sync succeeded.SyncLogNN
2006Sync failed.SyncLogNN
2010Creation of new excluded file type.OperationalNN
2011Rename of file SourcePath to file TargetPath was blocked.OperationalNN

Event ID 1: The Offline Files service started successfully.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387920,
    "time_created": "2026-05-30T04:03:24.6211326+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 9144,
      "thread_id": 6004
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The Offline Files service started successfully."
}

Event ID 2: The Offline Files service is terminating.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387920,
    "time_created": "2026-05-30T04:03:24.2126163+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 11852,
      "thread_id": 932
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The Offline Files service is terminating."
}

Event ID 3: The Offline Files service is waiting for all running tasks to complete.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 3,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387920,
    "time_created": "2026-05-30T04:03:24.2177139+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 11852,
      "thread_id": 12980
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The Offline Files service is waiting for all running tasks to complete."
}

Event ID 4: The Offline Files service has terminated.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387920,
    "time_created": "2026-05-30T04:03:24.2181741+00:00",
    "event_record_id": 5,
    "correlation": {},
    "execution": {
      "process_id": 11852,
      "thread_id": 12980
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "The Offline Files service has terminated."
}

Event ID 5: The Offline Files service received a STOP or SHUTDOWN control from the Service Control Manager.

#
Channel
Operational
Opcode
Info

Description

The Offline Files service received a STOP or SHUTDOWN control from the Service Control Manager. The service will now stop.

Message #

The Offline Files service received a STOP or SHUTDOWN control from the Service Control Manager.  The service will now stop.

Event ID 6: The Offline Files driver.

#
Channel
System
Opcode
Info

Description

The Offline Files driver (csc.sys) is not running.

Message #

The Offline Files driver (csc.sys) is not running.

Event ID 7: User logon detected.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

User logon detected
Account: %1
Session: %2

Fields #

NameDescription
Info.Account UnicodeString
Info.Session UInt32
Account UnicodeString
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "95353826-4fbe-41d4-9c42-f521c6e86360",
    "event_source_name": "",
    "event_id": 7,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387912,
    "time_created": "2026-07-19T17:14:59.2340035+00:00",
    "event_record_id": 75,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 1884,
      "thread_id": 2280
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Info": {
      "Account": "ludus\\domainadmin",
      "Session": "1"
    }
  },
  "message": "User logon detected\r\nAccount: ludus\\domainadmin\r\nSession: 1"
}

Event ID 8: User logoff detected.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

User logoff detected
Account: %1
Session: %2

Fields #

NameDescription
Info.Account UnicodeString
Info.Session UInt32
Account UnicodeString
Session UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387912,
    "time_created": "2026-05-30T04:14:38.6921031+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 9144,
      "thread_id": 3416
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "Info": {
      "Account": "ludus\\domainuser",
      "Session": "2"
    }
  },
  "message": "User logoff detected\r\nAccount: ludus\\domainuser\r\nSession: 2"
}

Event ID 9: Path disconnected.

#
Channel
Operational
Opcode
Info

Message #

Path disconnected.
%1

Fields #

NameDescription
Path UnicodeString

Event ID 10: Path reconnected.

#
Channel
Operational
Opcode
Info

Message #

Path reconnected.
%1

Fields #

NameDescription
Path UnicodeString

Event ID 11: Offline Files configuration is being controlled by Group Policy.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OfflineFiles",
    "guid": "{95353826-4FBE-41D4-9C42-F521C6E86360}",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387936,
    "time_created": "2026-05-30T04:03:24.5587637+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 9144,
      "thread_id": 6004
    },
    "channel": "Microsoft-Windows-OfflineFiles/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": "Offline Files configuration is being controlled by Group Policy."
}

Event ID 12: Offline Files configuration is being controlled by WMI configuration classes Win32_OfflineFilesUserConfiguration and Win32_OfflineFilesMachineConfi...

#
Channel
Operational
Opcode
Info

Description

Offline Files configuration is being controlled by WMI configuration classes Win32_OfflineFilesUserConfiguration and Win32_OfflineFilesMachineConfiguration.

Message #

Offline Files configuration is being controlled by WMI configuration classes Win32_OfflineFilesUserConfiguration and Win32_OfflineFilesMachineConfiguration.

Event ID 1000: Background agent failed startup, error = Text.

#
Channel
Operational
Opcode
Info

Message #

Background agent failed startup, error = %1

Fields #

NameDescription
Text UnicodeString

Event ID 1001: Background Synchronization failed on Path.

#
Channel
Operational
Opcode
Info

Description

Background Synchronization failed on.

Message #

Background Synchronization failed on 

%1

Fields #

NameDescription
Path UnicodeString
ResultCode UnicodeString
Result UnicodeString

Event ID 1002: Background Synchronization executed successfully.

#
Channel
Operational
Opcode
Info

Event ID 1003: Background Synchronization has started on Path as client has not synced for MinutesSinceLastSync minutes.

#
Channel
Operational
Opcode
Info

Description

Background Synchronization has started on.

Message #

Background Synchronization has started on 

%1

 as client has not synced for %2 minutes.

Fields #

NameDescription
Path UnicodeString
MinutesSinceLastSync UInt32

Event ID 1004: Path Path transitioned to slow link with latency = Latency and bandwidth = Bandwidth.

#
Channel
Operational
Opcode
Info

Message #

Path %1 transitioned to slow link with latency = %2 and bandwidth = %3

Fields #

NameDescription
Path UnicodeString
Latency UInt64
Bandwidth UInt64

Event ID 1005: Path Path transitioned to online with latency = Latency.

#
Channel
Operational
Opcode
Info

Message #

Path %1 transitioned to online with latency = %2

Fields #

NameDescription
Path UnicodeString
Latency UInt64

Event ID 1006: Background Synchronization failed for FailedFileCount files on Path.

#
Channel
Operational
Opcode
Info

Description

Background Synchronization failed for FailedFileCount files on.

Message #

Background Synchronization failed for %2 files on 

%1

Fields #

NameDescription
Path UnicodeString
FailedFileCount UInt32

Event ID 1007: Path Path transitioned to slow link mode so the user will work offline with background synchronization of the data to the file server.

#
Channel
Operational
Opcode
Info

Description

Path Path transitioned to slow link mode so the user will work offline with background synchronization of the data to the file server. The administrator has configured this path to work offline regardless of the network performance.

Message #

Path %1 transitioned to slow link mode so the user will work offline with background synchronization of the data to the file server. The administrator has configured this path to work offline regardless of the network performance.

Fields #

NameDescription
Path UnicodeString

Event ID 1008: Path Path failed to transition to slow link mode due to an open handle on FileName.

#
Channel
Operational
Opcode
Info

Message #

Path %1 failed to transition to slow link mode due to an open handle on %2.

Fields #

NameDescription
Path UnicodeString
FileName UnicodeString

Event ID 1009: Path Path failed to transition to slow link mode due to an open handle.

#
Channel
Operational
Opcode
Info

Message #

Path %1 failed to transition to slow link mode due to an open handle.

Fields #

NameDescription
Path UnicodeString

Event ID 2000: Sync info for Path Only the server copy exists.

#
Channel
SyncLog
Opcode
Info

Description

Sync info for Path.

Message #

Sync info for %1
Only the server copy exists.
%10
See details for more information.

Fields #

NameDescription
Path UnicodeString
ServerIsDir Boolean
ClientDeleted Boolean
ServerChanged Boolean
ServerLastWriteTime FILETIME
ServerChangeTime FILETIME
ServerAttributes UInt32
ServerSize UInt64
SyncState UInt32
SyncStateText UnicodeString

Event ID 2001: Sync info for Path Only the client copy exists.

#
Channel
SyncLog
Opcode
Info

Description

Sync info for Path.

Message #

Sync info for %1
Only the client copy exists.
%12
See details for more information.

Fields #

NameDescription
Path UnicodeString
ClientIsDir Boolean
ClientChanged Boolean
ClientIsSparse Boolean
ClientCreatedOffline Boolean
ClientDeletedOffline Boolean
ClientLastWriteTime FILETIME
ClientChangeTime FILETIME
ClientAttributes UInt32
ClientSize UInt64
ServerDeleted Boolean
SyncState UInt32
SyncStateText UnicodeString

Event ID 2002: Sync info for Path Both client and server copies exist.

#
Channel
SyncLog
Opcode
Info

Description

Sync info for Path.

Message #

Sync info for %1
Both client and server copies exist.
%17
See details for more information.

Fields #

NameDescription
Path UnicodeString
ClientIsDir Boolean
ClientChanged Boolean
ClientIsSparse Boolean
ClientCreatedOffline Boolean
ClientLastWriteTime FILETIME
ClientChangeTime FILETIME
ClientAttributes UInt32
ClientSize UInt64
ServerIsDir Boolean
ServerChanged Boolean
ServerLastWriteTime FILETIME
ServerChangeTime FILETIME
ServerAttributes UInt32
ServerSize UInt64
SyncState UInt32
SyncStateText UnicodeString

Event ID 2003: Sync info for Path Server copy exists, client copy deleted.

#
Channel
SyncLog
Opcode
Info

Description

Sync info for Path.

Message #

Sync info for %1
Server copy exists, client copy deleted.
%13
See details for more information.

Fields #

NameDescription
Path UnicodeString
ClientIsDir Boolean
ClientChanged Boolean
ClientIsSparse Boolean
ClientCreatedOffline Boolean
ServerIsDir Boolean
ServerChanged Boolean
ServerLastWriteTime FILETIME
ServerChangeTime FILETIME
ServerAttributes UInt32
ServerSize UInt64
SyncState UInt32
SyncStateText UnicodeString

Event ID 2004: Sync info for Path Server copy exists, client copy replaced then deleted.

#
Channel
SyncLog
Opcode
Info

Description

Sync info for Path.

Message #

Sync info for %1
Server copy exists, client copy replaced then deleted.
%10\
See details for more information.

Fields #

NameDescription
Path UnicodeString
ClientIsDir Boolean
ServerIsDir Boolean
ServerChanged Boolean
ServerLastWriteTime FILETIME
ServerChangeTime FILETIME
ServerAttributes UInt32
ServerSize UInt64
SyncState UInt32
SyncStateText UnicodeString

Event ID 2005: Sync succeeded.

#
Channel
SyncLog
Opcode
Info

Message #

Sync succeeded.

%1

Operation: %2

Fields #

NameDescription
Path UnicodeString
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 2006: Sync failed.

#
Channel
SyncLog
Opcode
Info

Message #

Sync failed.

%1

Operation: %2
Result: %4

Fields #

NameDescription
Path UnicodeString
Operation UnicodeString
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
ResultCode UnicodeString
Result UnicodeString

Event ID 2010: Creation of new excluded file type.

#
Channel
Operational
Opcode
Info

Message #

Creation of new excluded file type 
%1 was blocked.

Fields #

NameDescription
Path UnicodeString

Event ID 2011: Rename of file SourcePath to file TargetPath was blocked.

#
Channel
Operational
Opcode
Info

Description

Rename of file SourcePath to file TargetPath was blocked. The source and/or target file name is an excluded file type.

Message #

Rename of file %1 to file %2 was blocked. The source and/or target file name is an excluded file type.

Fields #

NameDescription
SourcePath UnicodeString
TargetPath UnicodeString

Provenance

ETW provider GUID 95353826-4fbe-41d4-9c42-f521c6e86360

Defined in cscsvc.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB