Microsoft-Windows-OneX
75 events across 2 channels
Event ID 1: OneXDestroySupplicantPort
#Event ID 2: OneXStartAuthentication
#Event ID 3: OneXStopAuthentication
#Event ID 4: Port(PortId): EAP error WinError=WinError, ReasonCode=ReasonCode, EapMethod(Type=EAPMethodType), RootCause is RootCauseString.
#Event ID 5: Port(PortId): Account is disabled and user is non-domain joined.
#Event ID 6: Port(PortId): EAP failure indication with error code WinError and reason code ReasonCode.
#Event ID 7: Port(PortId): Saving updated user data of size (UserDataSize).
#Event ID 8: Port(PortId): Saving updated connection data of size (UserDataSize).
#Event ID 9: Port(PortId): Successfully received UI Response.
#Event ID 10: Port(PortId): EapProcessPacketValidityAndGetResult returned action Response.
#Event ID 11: Port(PortId): EAP requested authentication restart.
#Event ID 12: Port(Context): EapHostPeerInitialize failed, error ErrorCode.
#Event ID 13: Port(Context): EapHostPeerEndSession failed, error ErrorCode.
#Event ID 14: Port(Context): OneXGeneratePacketEvent failed, error ErrorCode.
#Event ID 15: Port(Context): OneXGeneratePeerAuthRestartedEvent failed, error ErrorCode.
#Event ID 16: Port(Context): EapHostPeerGetAuthStatus failed, error ErrorCode.
#Event ID 17: Port(Context): MSMUIRequest failed, error ErrorCode.
#Event ID 18: Port(Context): CompareSessionUserWithOwner failed, error ErrorCode.
#Event ID 19: Port(Context): ProcessEapHostTLV failed, error ErrorCode.
#Event ID 20: Port(PortId): Cannot send UI Request (code=UIRequestCode) to MSM since UI is disabled for the port.
#Event ID 21: Port(Context): Error ErrorCode in calling WTSQueryUserToken.
#Event ID 22: Port(Context): SupplicantGetUserTokenFromRuntimeState failed, error ErrorCode.
#Event ID 23: Port(PortId): The auth mode is User only but an appropriate user can't be found.
#Event ID 24: Port(Context): CompareOneXCredentials failed, error ErrorCode.
#Event ID 25: Port(Context): Failed to conditionally send Eapol start packet.
#Event ID 26: Port(Context): OneXGenerateForceAuthenticatedEvent failed, error ErrorCode.
#Event ID 27: OneXValidateProfile failed, error ErrorCode, reason code Context.
#Event ID 28: EAP dll requested to show UI, but the UI for the port is not allowed with current credentials
#Event ID 29: The EAP method does not support key derivation and will not be used for discovery
#Event ID 30: The EAP method does not support mutual authentication and will not be used for discovery
#Event ID 31: Done with creating discovery profiles.
#Event ID 32: Created a 1X profile for discovery with eapType=EAPMethodType and AuthMode=AuthMode.
#Event ID 33: The EAP method EAPMethodType is not allowed for media type MediaType and will not be used for discovery.
#Event ID 34: Port(PortId): Successfully sent UI Request (code=UIRequestCode) to MSM.
#Event ID 35: Received a session change event (ChangeType).
#Event ID 36: Finished initializing a new port with id=PortId and friendly name=FriendlyName.
#Event ID 37: Port(PortId): MPPE-Send/Recv-Keys have been derived by supplicant.
#Event ID 38: Port(PortId): Sending UI Request (code=UIRequestCode) to MSM.
#Event ID 39: Port(PortId): Asking MSM to delete user data for user token.
#Event ID 40: Port(PortId): Received an EAP packet length=PacketLength, type=PacketType, identifier=Identifier, eapType=EapMethodType.
#Event ID 41: Port(PortId): Sent an Eapol start packet.
#Event ID 42: Port(PortId): The supplicant is configured to not send an Eapol start packet.
#Event ID 43: Port(PortId): Restarting authentication due to reason = Reason.
#Event ID 44: Port(PortId): Authentication Starting.
#Event ID 45: Port(PortId): Authentication Completed.
#Event ID 46: Port(PortId): Time taken for this authentication = TimeTaken ms.
#Event ID 47: Port(PortId): 802.
#Event ID 48: Port(PortId): Stopping the current 802.
#Event ID 49: Port(PortId): Starting a new 802.
#Event ID 50: Port(PortId): Alternate credentials will be used for this profile.
#Event ID 51: Port(PortId): This is a discovery profile being attempted.
#Event ID 52: Port(PortId): Trying timely configuration.
#Event ID 53: Port(PortId): Completed the 802.
#Event ID 54: Port(PortId): Completed the 802.
#Event ID 55: Port(PortId): The session id (SessionId) received with the UI response is different than the session id for which the request was sent (UIRequestSessionId).
#Event ID 56: Port(PortId): A pending UI request exists size=Size, sessionId=SessionId.
#Event ID 57: Port(PortId): User auth proposed for sessionId=SessionId (Reason).
#Event ID 58: Port(PortId): The machine is in app server mode.
#Event ID 59: EapHostPeerInvokeInteractiveUI failed, Error = WinError Reason = ReasonCode.
#Event ID 60: No EAP Cred fields to display
#Event ID 61: Creds conversion failed (error=ErrorCode).
#Event ID 62: EapHostPeerQueryInteractiveUIInputFields failed (error=ErrorCode).
#Event ID 63: Displaying the change password dialog - Result.
#Event ID 64: Port(PortId): Sending an EAP packet length=PacketLength, type=PacketType, identifier=Identifier, eapType=EapMethodType.
#Event ID 65: Port(PortId): Identity being sent in the ResponseId packet is Identity.
#Event ID 66: Port:(PortId): Saving/Updating master copy of user data.
#Event ID 68: Port(PortId): Flushing User Data from Persistent Store.
#Event ID 70: Port(PortId):OneX Auth Timeout.
#Description
Port(PortId):OneX Auth Timeout.
Message #
Fields #
| Name | Description |
|---|---|
PortId UInt32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-OneX",
"guid": "{AB0D8EF9-866D-4D39-B83F-453F3B8F6325}",
"event_source_name": "",
"event_id": 70,
"version": 0,
"level": 4,
"task": 2,
"opcode": 0,
"keywords": 4611686155866341378,
"time_created": "2026-05-30T04:20:18.1198556+00:00",
"event_record_id": 9,
"correlation": {},
"execution": {
"process_id": 3516,
"thread_id": 7064
},
"channel": "Microsoft-Windows-OneX/Operational",
"computer": "JD-WIN11-22H2-1.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"PortId": "3"
},
"message": "Port(3):OneX Auth Timeout"
}
Event ID 60001: Error: Error Location: Location Context: Context.
#Event ID 60002: Warning: Warning Location: Location Context: Context.
#Event ID 60003: Transitioned to State: NextState Context: Context.
#Event ID 60004: Updated Context: Updated_Context Update Reason: Update_Reason.
#Event ID 60101: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.
#Description
SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress UInt32 | |
SourcePort UInt32 | |
DestinationAddress UInt32 | |
DestinationPort UInt32 | |
Protocol UInt32 | Known values
|
ReferenceContext UInt32 |
Event ID 60102: SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.
#Description
SourceAddress: SourceAddress SourcePort: SourcePort DestinationAddress: DestinationAddress DestinationPort: DestinationPort Protocol: Protocol ReferenceContext: ReferenceContext.
Message #
Fields #
| Name | Description |
|---|---|
SourceAddress Binary | |
SourcePort UInt32 | |
DestinationAddress Binary | |
DestinationPort UInt32 | |
Protocol UInt32 | Known values
|
ReferenceContext UInt32 |
Event ID 60103: Interface Guid: Interface_Guid IfIndex: IfIndex Interface Luid: Interface_Luid ReferenceContext: ReferenceContext.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ab0d8ef9-866d-4d39-b83f-453f3b8f6325
Defined in onex.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02