Microsoft-Windows-OneX

EventTitleChannelSampleRule
1OneXDestroySupplicantPortDiagnosticNN
2OneXStartAuthenticationDiagnosticNN
3OneXStopAuthenticationDiagnosticNN
4Port(PortId): EAP error WinError=WinError, ReasonCode=ReasonCode, …DiagnosticNN
5Port(PortId): Account is disabled and user is non-domain joined.DiagnosticNN
6Port(PortId): EAP failure indication with error code WinError and reason code …DiagnosticNN
7Port(PortId): Saving updated user data of size (UserDataSize).DiagnosticNN
8Port(PortId): Saving updated connection data of size (UserDataSize).DiagnosticNN
9Port(PortId): Successfully received UI Response.DiagnosticNN
10Port(PortId): EapProcessPacketValidityAndGetResult returned action Response.DiagnosticNN
11Port(PortId): EAP requested authentication restart.DiagnosticNN
12Port(Context): EapHostPeerInitialize failed, error ErrorCode.DiagnosticNN
13Port(Context): EapHostPeerEndSession failed, error ErrorCode.DiagnosticNN
14Port(Context): OneXGeneratePacketEvent failed, error ErrorCode.DiagnosticNN
15Port(Context): OneXGeneratePeerAuthRestartedEvent failed, error ErrorCode.DiagnosticNN
16Port(Context): EapHostPeerGetAuthStatus failed, error ErrorCode.DiagnosticNN
17Port(Context): MSMUIRequest failed, error ErrorCode.DiagnosticNN
18Port(Context): CompareSessionUserWithOwner failed, error ErrorCode.DiagnosticNN
19Port(Context): ProcessEapHostTLV failed, error ErrorCode.DiagnosticNN
20Port(PortId): Cannot send UI Request (code=UIRequestCode) to MSM since UI is …DiagnosticNN
21Port(Context): Error ErrorCode in calling WTSQueryUserToken.DiagnosticNN
22Port(Context): SupplicantGetUserTokenFromRuntimeState failed, error ErrorCode.DiagnosticNN
23Port(PortId): The auth mode is User only but an appropriate user can't be found.DiagnosticNN
24Port(Context): CompareOneXCredentials failed, error ErrorCode.DiagnosticNN
25Port(Context): Failed to conditionally send Eapol start packet.DiagnosticNN
26Port(Context): OneXGenerateForceAuthenticatedEvent failed, error ErrorCode.DiagnosticNN
27OneXValidateProfile failed, error ErrorCode, reason code Context.DiagnosticNN
28EAP dll requested to show UI, but the UI for the port is not allowed with …DiagnosticNN
29The EAP method does not support key derivation and will not be used for …DiagnosticNN
30The EAP method does not support mutual authentication and will not be used for …DiagnosticNN
31Done with creating discovery profiles.DiagnosticNN
32Created a 1X profile for discovery with eapType=EAPMethodType and …DiagnosticNN
33The EAP method EAPMethodType is not allowed for media type MediaType and will …DiagnosticNN
34Port(PortId): Successfully sent UI Request (code=UIRequestCode) to MSM.DiagnosticNN
35Received a session change event (ChangeType).DiagnosticNN
36Finished initializing a new port with id=PortId and friendly name=FriendlyName.DiagnosticNN
37Port(PortId): MPPE-Send/Recv-Keys have been derived by supplicant.DiagnosticNN
38Port(PortId): Sending UI Request (code=UIRequestCode) to MSM.DiagnosticNN
39Port(PortId): Asking MSM to delete user data for user token.DiagnosticNN
40Port(PortId): Received an EAP packet length=PacketLength, type=PacketType, …DiagnosticNN
41Port(PortId): Sent an Eapol start packet.DiagnosticNN
42Port(PortId): The supplicant is configured to not send an Eapol start packet.DiagnosticNN
43Port(PortId): Restarting authentication due to reason = Reason.DiagnosticNN
44Port(PortId): Authentication Starting.DiagnosticNN
45Port(PortId): Authentication Completed.DiagnosticNN
46Port(PortId): Time taken for this authentication = TimeTaken ms.DiagnosticNN
47Port(PortId): 802.DiagnosticNN
48Port(PortId): Stopping the current 802.DiagnosticNN
49Port(PortId): Starting a new 802.DiagnosticNN
50Port(PortId): Alternate credentials will be used for this profile.DiagnosticNN
51Port(PortId): This is a discovery profile being attempted.DiagnosticNN
52Port(PortId): Trying timely configuration.DiagnosticNN
53Port(PortId): Completed the 802.DiagnosticNN
54Port(PortId): Completed the 802.DiagnosticNN
55Port(PortId): The session id (SessionId) received with the UI response is …DiagnosticNN
56Port(PortId): A pending UI request exists size=Size, sessionId=SessionId.DiagnosticNN
57Port(PortId): User auth proposed for sessionId=SessionId (Reason).DiagnosticNN
58Port(PortId): The machine is in app server mode.DiagnosticNN
59EapHostPeerInvokeInteractiveUI failed, Error = WinError Reason = ReasonCode.DiagnosticNN
60No EAP Cred fields to displayDiagnosticNN
61Creds conversion failed (error=ErrorCode).DiagnosticNN
62EapHostPeerQueryInteractiveUIInputFields failed (error=ErrorCode).DiagnosticNN
63Displaying the change password dialog - Result.DiagnosticNN
64Port(PortId): Sending an EAP packet length=PacketLength, type=PacketType, …DiagnosticNN
65Port(PortId): Identity being sent in the ResponseId packet is Identity.DiagnosticNN
66Port:(PortId): Saving/Updating master copy of user data.OperationalNN
68Port(PortId): Flushing User Data from Persistent Store.OperationalNN
70Port(PortId):OneX Auth Timeout.OperationalYN
60001Error: Error Location: Location Context: Context.DiagnosticNN
60002Warning: Warning Location: Location Context: Context.DiagnosticNN
60003Transitioned to State: NextState Context: Context.DiagnosticNN
60004Updated Context: Updated_Context Update Reason: Update_Reason.DiagnosticNN
60101SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: …DiagnosticNN
60102SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: …DiagnosticNN
60103Interface Guid: Interface_Guid IfIndex: IfIndex Interface Luid: Interface_Luid …DiagnosticNN

Event ID 1: OneXDestroySupplicantPort

#
Channel
Diagnostic
Task
API

Fields #

NameDescription
PortId UInt32

Event ID 2: OneXStartAuthentication

#
Channel
Diagnostic
Task
API
Opcode
Start

Fields #

NameDescription
PortId UInt32

Event ID 3: OneXStopAuthentication

#
Channel
Diagnostic
Task
API
Opcode
Stop

Fields #

NameDescription
PortId UInt32

Event ID 4: Port(PortId): EAP error WinError=WinError, ReasonCode=ReasonCode, EapMethod(Type=EAPMethodType), RootCause is RootCauseString.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): EAP error WinError=%2, ReasonCode=%3, EapMethod(Type=%4), RootCause is %5

Fields #

NameDescription
PortId UInt32
WinError UInt32
ReasonCode UInt32
EAPMethodType UInt8
RootCauseString UnicodeString

Event ID 5: Port(PortId): Account is disabled and user is non-domain joined.

#
Channel
Diagnostic
Task
EAP

Description

Port(PortId): Account is disabled and user is non-domain joined. Authentication will be tried with alternate credentials profile.

Message #

Port(%1): Account is disabled and user is non-domain joined. Authentication will be tried with alternate credentials profile.

Fields #

NameDescription
PortId UInt32

Event ID 6: Port(PortId): EAP failure indication with error code WinError and reason code ReasonCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): EAP failure indication with error code %2 and reason code %3

Fields #

NameDescription
PortId UInt32
WinError UInt32
ReasonCode UInt32

Event ID 7: Port(PortId): Saving updated user data of size (UserDataSize).

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Saving updated user data of size (%2)

Fields #

NameDescription
PortId UInt32
UserDataSize UInt32

Event ID 8: Port(PortId): Saving updated connection data of size (UserDataSize).

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Saving updated connection data of size (%2)

Fields #

NameDescription
PortId UInt32
UserDataSize UInt32

Event ID 9: Port(PortId): Successfully received UI Response.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Successfully received UI Response

Fields #

NameDescription
PortId UInt32

Event ID 10: Port(PortId): EapProcessPacketValidityAndGetResult returned action Response.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): EapProcessPacketValidityAndGetResult returned action %2

Fields #

NameDescription
PortId UInt32
Response UInt32

Event ID 11: Port(PortId): EAP requested authentication restart.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): EAP requested authentication restart

Fields #

NameDescription
PortId UInt32

Event ID 12: Port(Context): EapHostPeerInitialize failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): EapHostPeerInitialize failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 13: Port(Context): EapHostPeerEndSession failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): EapHostPeerEndSession failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 14: Port(Context): OneXGeneratePacketEvent failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): OneXGeneratePacketEvent failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 15: Port(Context): OneXGeneratePeerAuthRestartedEvent failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): OneXGeneratePeerAuthRestartedEvent failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 16: Port(Context): EapHostPeerGetAuthStatus failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): EapHostPeerGetAuthStatus failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 17: Port(Context): MSMUIRequest failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): MSMUIRequest failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 18: Port(Context): CompareSessionUserWithOwner failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): CompareSessionUserWithOwner failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 19: Port(Context): ProcessEapHostTLV failed, error ErrorCode.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%3): ProcessEapHostTLV failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 20: Port(PortId): Cannot send UI Request (code=UIRequestCode) to MSM since UI is disabled for the port.

#
Channel
Diagnostic
Task
MSM

Message #

Port(%1): Cannot send UI Request (code=%2) to MSM since UI is disabled for the port

Fields #

NameDescription
PortId UInt32
UIRequestCode UInt32

Event ID 21: Port(Context): Error ErrorCode in calling WTSQueryUserToken.

#
Channel
Diagnostic
Task
User

Description

Port(Context): Error ErrorCode in calling WTSQueryUserToken. Proposing machine authentication.

Message #

Port(%3): Error %1 in calling WTSQueryUserToken. Proposing machine authentication.

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 22: Port(Context): SupplicantGetUserTokenFromRuntimeState failed, error ErrorCode.

#
Channel
Diagnostic
Task
User

Message #

Port(%3): SupplicantGetUserTokenFromRuntimeState failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 23: Port(PortId): The auth mode is User only but an appropriate user can't be found.

#
Channel
Diagnostic
Task
User

Message #

Port(%1): The auth mode is User only but an appropriate user can't be found

Fields #

NameDescription
PortId UInt32

Event ID 24: Port(Context): CompareOneXCredentials failed, error ErrorCode.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%3): CompareOneXCredentials failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 25: Port(Context): Failed to conditionally send Eapol start packet.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(Context): Failed to conditionally send Eapol start packet. Ignoring error WarningCode.

Message #

Port(%3): Failed to conditionally send Eapol start packet. Ignoring error %1

Fields #

NameDescription
WarningCode UInt32
Location UInt32
Context UInt32

Event ID 26: Port(Context): OneXGenerateForceAuthenticatedEvent failed, error ErrorCode.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%3): OneXGenerateForceAuthenticatedEvent failed, error %1

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 27: OneXValidateProfile failed, error ErrorCode, reason code Context.

#
Channel
Diagnostic
Task
Supplicant

Message #

OneXValidateProfile failed, error %1, reason code %3

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 28: EAP dll requested to show UI, but the UI for the port is not allowed with current credentials

#
Channel
Diagnostic
Task
EAP

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 29: The EAP method does not support key derivation and will not be used for discovery

#
Channel
Diagnostic
Task
Profile

Fields #

NameDescription
EAPMethodType UInt8

Event ID 30: The EAP method does not support mutual authentication and will not be used for discovery

#
Channel
Diagnostic
Task
Profile

Fields #

NameDescription
EAPMethodType UInt8

Event ID 31: Done with creating discovery profiles.

#
Channel
Diagnostic
Task
Profile

Description

Done with creating discovery profiles. Created ProfilesCount profiles.

Message #

Done with creating discovery profiles. Created %1 profiles

Fields #

NameDescription
ProfilesCount UInt32

Event ID 32: Created a 1X profile for discovery with eapType=EAPMethodType and AuthMode=AuthMode.

#
Channel
Diagnostic
Task
Profile

Message #

Created a 1X profile for discovery with eapType=%1 and AuthMode=%2

Fields #

NameDescription
EAPMethodType UInt8
AuthMode UnicodeString

Event ID 33: The EAP method EAPMethodType is not allowed for media type MediaType and will not be used for discovery.

#
Channel
Diagnostic
Task
Profile

Message #

The EAP method %1 is not allowed for media type %2 and will not be used for discovery

Fields #

NameDescription
EAPMethodType UInt8
MediaType UInt32

Event ID 34: Port(PortId): Successfully sent UI Request (code=UIRequestCode) to MSM.

#
Channel
Diagnostic
Task
MSM

Message #

Port(%1): Successfully sent UI Request (code=%2) to MSM

Fields #

NameDescription
PortId UInt32
UIRequestCode UInt32

Event ID 35: Received a session change event (ChangeType).

#
Channel
Diagnostic
Task
Supplicant

Message #

Received a session change event (%1)

Fields #

NameDescription
ChangeType UInt32

Event ID 36: Finished initializing a new port with id=PortId and friendly name=FriendlyName.

#
Channel
Diagnostic
Task
Port

Message #

Finished initializing a new port with id=%1 and friendly name=%2

Fields #

NameDescription
PortId UInt32
FriendlyName UnicodeString

Event ID 37: Port(PortId): MPPE-Send/Recv-Keys have been derived by supplicant.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%1): MPPE-Send/Recv-Keys have been derived by supplicant

Fields #

NameDescription
PortId UInt32

Event ID 38: Port(PortId): Sending UI Request (code=UIRequestCode) to MSM.

#
Channel
Diagnostic
Task
MSM

Message #

Port(%1): Sending UI Request (code=%2) to MSM

Fields #

NameDescription
PortId UInt32
UIRequestCode UInt32

Event ID 39: Port(PortId): Asking MSM to delete user data for user token.

#
Channel
Diagnostic
Task
MSM

Message #

Port(%1): Asking MSM to delete user data for user token

Fields #

NameDescription
PortId UInt32

Event ID 40: Port(PortId): Received an EAP packet length=PacketLength, type=PacketType, identifier=Identifier, eapType=EapMethodType.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Received an EAP packet length=%2, type=%3, identifier=%4, eapType=%5

Fields #

NameDescription
PortId UInt32
PacketLength UInt16
PacketType UInt32
Identifier UInt8
EapMethodType UInt32

Event ID 41: Port(PortId): Sent an Eapol start packet.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Sent an Eapol start packet

Fields #

NameDescription
PortId UInt32

Event ID 42: Port(PortId): The supplicant is configured to not send an Eapol start packet.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): The supplicant is configured to not send an Eapol start packet

Fields #

NameDescription
PortId UInt32

Event ID 43: Port(PortId): Restarting authentication due to reason = Reason.

#
Channel
Diagnostic
Task
MSM

Message #

Port(%1): Restarting authentication due to reason = %2

Fields #

NameDescription
PortId UInt32
Reason UInt32

Event ID 44: Port(PortId): Authentication Starting.

#
Channel
Diagnostic
Task
Supplicant
Opcode
Start

Message #

Port(%1): Authentication Starting

Fields #

NameDescription
PortId UInt32

Event ID 45: Port(PortId): Authentication Completed.

#
Channel
Diagnostic
Task
Supplicant
Opcode
Stop

Message #

Port(%1): Authentication Completed

Fields #

NameDescription
PortId UInt32

Event ID 46: Port(PortId): Time taken for this authentication = TimeTaken ms.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%1): Time taken for this authentication = %2 ms

Fields #

NameDescription
PortId UInt32
TimeTaken UInt32

Event ID 47: Port(PortId): 802.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(PortId): 802.1X user identified. auth identity = AuthIdentity, sessionId = SessionId, username=Username, domain=Domain.

Message #

Port(%1): 802.1X user identified. auth identity = %2, sessionId = %3, username=%4, domain=%5

Fields #

NameDescription
PortId UInt32
AuthIdentity UnicodeString
SessionId UInt32
Username UnicodeString
Domain UnicodeString

Event ID 48: Port(PortId): Stopping the current 802.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(PortId): Stopping the current 802.1X authentication.

Message #

Port(%1): Stopping the current 802.1X authentication

Fields #

NameDescription
PortId UInt32

Event ID 49: Port(PortId): Starting a new 802.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(PortId): Starting a new 802.1X authentication (Reason).

Message #

Port(%1): Starting a new 802.1X authentication (%2)

Fields #

NameDescription
PortId UInt32
Reason UInt32

Event ID 50: Port(PortId): Alternate credentials will be used for this profile.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%1): Alternate credentials will be used for this profile

Fields #

NameDescription
PortId UInt32

Event ID 51: Port(PortId): This is a discovery profile being attempted.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%1): This is a discovery profile being attempted

Fields #

NameDescription
PortId UInt32

Event ID 52: Port(PortId): Trying timely configuration.

#
Channel
Diagnostic
Task
Supplicant

Message #

Port(%1): Trying timely configuration

Fields #

NameDescription
PortId UInt32

Event ID 53: Port(PortId): Completed the 802.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(PortId): Completed the 802.1X authentication successfully.

Message #

Port(%1): Completed the 802.1X authentication successfully

Fields #

NameDescription
PortId UInt32

Event ID 54: Port(PortId): Completed the 802.

#
Channel
Diagnostic
Task
Supplicant

Description

Port(PortId): Completed the 802.1X authentication because no authenticator was found.

Message #

Port(%1): Completed the 802.1X authentication because no authenticator was found

Fields #

NameDescription
PortId UInt32

Event ID 55: Port(PortId): The session id (SessionId) received with the UI response is different than the session id for which the request was sent (UIRequestSessionId).

#
Channel
Diagnostic
Task
User

Description

Port(PortId): The session id (SessionId) received with the UI response is different than the session id for which the request was sent (UIRequestSessionId). Discarding this response.

Message #

Port(%1): The session id (%2) received with the UI response is different than the session id for which the request was sent (%3). Discarding this response

Fields #

NameDescription
PortId UInt32
SessionId UInt32
UIRequestSessionId UInt32

Event ID 56: Port(PortId): A pending UI request exists size=Size, sessionId=SessionId.

#
Channel
Diagnostic
Task
User

Message #

Port(%1): A pending UI request exists size=%2, sessionId=%3

Fields #

NameDescription
PortId UInt32
Size UInt32
SessionId UInt32

Event ID 57: Port(PortId): User auth proposed for sessionId=SessionId (Reason).

#
Channel
Diagnostic
Task
User

Message #

Port(%1): User auth proposed for sessionId=%3 (%2)

Fields #

NameDescription
PortId UInt32
Reason UInt32
SessionId UInt32

Event ID 58: Port(PortId): The machine is in app server mode.

#
Channel
Diagnostic
Task
User

Description

Port(PortId): The machine is in app server mode. Proposing machine auth.

Message #

Port(%1): The machine is in app server mode. Proposing machine auth

Fields #

NameDescription
PortId UInt32

Event ID 59: EapHostPeerInvokeInteractiveUI failed, Error = WinError Reason = ReasonCode.

#
Channel
Diagnostic
Task
EAP

Message #

EapHostPeerInvokeInteractiveUI failed, Error = %2 Reason = %3

Fields #

NameDescription
PortId UInt32
WinError UInt32
ReasonCode UInt32

Event ID 60: No EAP Cred fields to display

#
Channel
Diagnostic
Task
EAP

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 61: Creds conversion failed (error=ErrorCode).

#
Channel
Diagnostic
Task
EAP

Message #

Creds conversion failed (error=%1)

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 62: EapHostPeerQueryInteractiveUIInputFields failed (error=ErrorCode).

#
Channel
Diagnostic
Task
EAP

Message #

EapHostPeerQueryInteractiveUIInputFields failed (error=%1)

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 63: Displaying the change password dialog - Result.

#
Channel
Diagnostic
Task
User

Message #

Displaying the change password dialog - %1

Fields #

NameDescription
Result UInt32

Event ID 64: Port(PortId): Sending an EAP packet length=PacketLength, type=PacketType, identifier=Identifier, eapType=EapMethodType.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Sending an EAP packet length=%2, type=%3, identifier=%4, eapType=%5

Fields #

NameDescription
PortId UInt32
PacketLength UInt16
PacketType UInt32
Identifier UInt8
EapMethodType UInt32

Event ID 65: Port(PortId): Identity being sent in the ResponseId packet is Identity.

#
Channel
Diagnostic
Task
EAP

Message #

Port(%1): Identity being sent in the ResponseId packet is %2

Fields #

NameDescription
PortId UInt32
Identity AnsiString

Event ID 66: Port:(PortId): Saving/Updating master copy of user data.

#
Channel
Operational
Task
EAP

Message #

Port:(%1): Saving/Updating master copy of user data
SupplicantIsUsingExplicitCreds:(%2)

Fields #

NameDescription
PortId UInt32
ExplicitCredentials Boolean

Event ID 68: Port(PortId): Flushing User Data from Persistent Store.

#
Channel
Operational
Task
EAP

Message #

Port(%1): Flushing User Data from Persistent Store

SupplicantIsUsingExplicitCreds:(%2)

Fields #

NameDescription
PortId UInt32
ExplicitCredentials Boolean

Event ID 70: Port(PortId):OneX Auth Timeout.

#
Channel
Operational
Level
Informational
Task
EAP

Message #

Port(%1):OneX Auth Timeout

Fields #

NameDescription
PortId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-OneX",
    "guid": "{AB0D8EF9-866D-4D39-B83F-453F3B8F6325}",
    "event_source_name": "",
    "event_id": 70,
    "version": 0,
    "level": 4,
    "task": 2,
    "opcode": 0,
    "keywords": 4611686155866341378,
    "time_created": "2026-05-30T04:20:18.1198556+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 3516,
      "thread_id": 7064
    },
    "channel": "Microsoft-Windows-OneX/Operational",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "PortId": "3"
  },
  "message": "Port(3):OneX Auth Timeout"
}

Event ID 60001: Error: Error Location: Location Context: Context.

#
Channel
Diagnostic

Message #

Error: %1 Location: %2 Context: %3

Fields #

NameDescription
ErrorCode UInt32
Location UInt32
Context UInt32

Event ID 60002: Warning: Warning Location: Location Context: Context.

#
Channel
Diagnostic

Message #

Warning: %1 Location: %2 Context: %3

Fields #

NameDescription
WarningCode UInt32
Location UInt32
Context UInt32

Event ID 60003: Transitioned to State: NextState Context: Context.

#
Channel
Diagnostic

Message #

Transitioned to State: %1 Context: %2

Fields #

NameDescription
NextState UInt8
Context UInt32

Event ID 60004: Updated Context: Updated_Context Update Reason: Update_Reason.

#
Channel
Diagnostic

Message #

Updated Context: %1 Update Reason: %2

Fields #

NameDescription
Context UInt32
UpdateReasonCode UInt32

Event ID 60101: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.

#
Channel
Diagnostic

Message #

SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6

Fields #

NameDescription
SourceAddress UInt32
SourcePort UInt32
DestinationAddress UInt32
DestinationPort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext UInt32

Event ID 60102: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.

#
Channel
Diagnostic

Message #

SourceAddress: %1 SourcePort: %2 DestinationAddress: %3 DestinationPort: %4 Protocol: %5 ReferenceContext: %6

Fields #

NameDescription
SourceAddress Binary
SourcePort UInt32
DestinationAddress Binary
DestinationPort UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
ReferenceContext UInt32

Event ID 60103: Interface Guid: Interface_Guid IfIndex: IfIndex Interface Luid: Interface_Luid ReferenceContext: ReferenceContext.

#
Channel
Diagnostic

Message #

Interface Guid: %1 IfIndex: %2 Interface Luid: %3 ReferenceContext: %4

Fields #

NameDescription
IfGuid GUID
IfIndex UInt32
IfLuid UInt64
ReferenceContext UInt32

Provenance

ETW provider GUID ab0d8ef9-866d-4d39-b83f-453f3b8f6325

Defined in onex.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB