Microsoft-Windows-PDC
Event ID 1: Activator Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 2: Activator Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 3: Notification client Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 4: Notification client Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 5: Resiliency client Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 6: Resiliency client Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 7: Notification message ActivityType: Status/Active: Message, ActivityType: StatusActive.
#Message #
Fields #
| Name | Description |
|---|---|
Message Pointer | |
StatusActive UInt32 | |
ActivityType UInt32 | 1: Status/Active. |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 7,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:21.712Z",
"version": 0
},
"event_data": {
"ActivityType": 0,
"Message": "0xFFFFF4890CF27DB0",
"Status/Active": 0
},
"message": ""
}
Example keys not documented in the fields table: Status/Active
Event ID 8: Activators received acknowledgement: Status: Activators_received_acknowledgement_Status, State: State.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
State UInt32 |
Event ID 9: Activator client Client received acknowledgement: Status: State.
#Event ID 10: Notification started: Type: Notification_started_Type, ClientContext:ClientContext, PDC Sequence:PDC_Sequence, Value:Value, WaitTime:WaitTime.
#Event ID 11: Control notification: Type: Control_notification_Type, Flags:Flags.
#Event ID 12: Invalid notification: Client: Invalid_notification_Client, Expected sequence number:Expected_sequence_number, Received sequence number:Received_sequence_number.
#Event ID 13: Notification received: Client: Notification_received_Client, Received sequence number:Received_sequence_number.
#Event ID 14: Notification received from all clients: Status:Status.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 15: Callback activated for type: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 16: Notification message: Client Control, Message: Status, Control: PDC_Sequence, Status: Client; PDC Sequence: Message.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
Message Pointer | |
Control UInt32 | 1, Message. |
Status UInt32 | NTSTATUS reference |
PdcSequence UInt32 |
Event ID 17: Activator Client Client sent a request to PDC.
#Event ID 18: Response from PDC to activator Client Client.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
SendReceive UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 18,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:21.713Z",
"version": 0
},
"event_data": {
"Client": "0xFFFFC807BC631B20",
"Send/Receive": 0
},
"message": ""
}
Example keys not documented in the fields table: Send/Receive
Event ID 19: TransactionId resiliency client: client: Port, Port: ResiliencyType, ResiliencyType: ClientReferences, ClientReferences: Transation_Id, Transation Id: CurrentState, CurrentState: NextState, NextSta...
#Description
TransactionId resiliency client: client: Port, Port: ResiliencyType, ResiliencyType: ClientReferences, ClientReferences: Transation_Id, Transation Id: CurrentState, CurrentState: NextState, NextState: Client.
Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
Port Pointer | |
ResiliencyType UInt32 | |
References UInt64 | |
TransactionId UInt32 | |
CurrentState UInt32 | |
NextState UInt32 | |
PrefixLength UInt32 | |
Prefix UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 19,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:21.712Z",
"version": 0
},
"event_data": {
"Client": "0xFFFFF8016AA0F560",
"CurrentState": 0,
"NextState": 0,
"Port": "0x0",
"Prefix": "Reference",
"PrefixLength": 9,
"References": 2,
"ResiliencyType": 0,
"TransactionId": 0
},
"message": ""
}
Event ID 20: Resiliency Message ClientState, TransactionId: ClientStatus, ClientState: SendMessage, ClientStatus: UserModeMessage, SendMessage: Message, UserModeMessage: TransactionId.
#Event ID 21: PDC recieved message from resiliency client Client.
#Event ID 22: PDC sent message to resiliency client Client.
#Event ID 23: PDC resiliency client Client referenced.
#Message #
Fields #
| Name | Description |
|---|---|
ActivatorToken Pointer | |
Client Pointer | |
ReferenceDereference UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 23,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:21.712Z",
"version": 0
},
"event_data": {
"ActivatorToken": "0xFFFFC807BC631B20",
"Client": "0xFFFFF8016AA0F560",
"Reference/Dereference": 1
},
"message": ""
}
Example keys not documented in the fields table: Reference/Dereference
Event ID 24: PDC resiliency client Client dereferenced.
#Message #
Fields #
| Name | Description |
|---|---|
ActivatorToken Pointer | |
Client Pointer | |
ReferenceDereference UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 24,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:22.256Z",
"version": 0
},
"event_data": {
"ActivatorToken": "0xFFFFC807BC631B20",
"Client": "0xFFFFF8016AA0F6A0",
"Reference/Dereference": 0
},
"message": ""
}
Example keys not documented in the fields table: Reference/Dereference
Event ID 25: PDC is entering Phase phase.
#Message #
Fields #
| Name | Description |
|---|---|
Phase UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 26: PDC is exiting Phase phase with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Phase UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 27: PDC received display notification: PDC_received_display_notification.
#Event ID 28: PDC received monitor request ON/OFF: PDC_received_monitor_request_ONOFF, Console:Console.
#Event ID 29: PDC received monitor request exit at: PDC_received_monitor_request_exit_at, Status:Status.
#Message #
Fields #
| Name | Description |
|---|---|
At UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 30: PDC monitor context - Session Count:ConnectedSessionCount, Console Session:ConsoleSessionId, Session: SessionId, Current On Request: OnRequestCurrent, Processed On Request: OnRequestProcessed, Curr...
#Description
PDC monitor context - Session Count:ConnectedSessionCount, Console Session:ConsoleSessionId, Session: SessionId, Current On Request: OnRequestCurrent, Processed On Request: OnRequestProcessed, Current Off Request: OffRequestCurrent, Processed Off Request: OffRequestProcessed.
Message #
Fields #
| Name | Description |
|---|---|
ConnectedSessionCount UInt32 | |
ConsoleSessionId UInt32 | |
SessionId UInt32 | |
OnRequestCurrent UInt32 | |
OnRequestProcessed UInt32 | |
OffRequestCurrent UInt32 | |
OffRequestProcessed UInt32 | |
BlockingActive Boolean | |
BlockingScenarioCount UInt32 | |
BlockingEscapeCount UInt32 | |
BlockingPowerPressCount UInt32 |
Event ID 31: PDC monitor handler activated at:PDC_monitor_handler_activated_at.
#Event ID 32: PDC monitor control activated.
#Event ID 33: PDC power button handler activated.
#Event ID 34: PDC power button consumed.
#Event ID 35: PDC Display notification handler activated.
#Event ID 36: PDC PdcCsEnterExit handler activated at:PDC_PdcCsEnterExit_handler_activated_at.
#Event ID 37: PDC Enable Input.
#Event ID 38: PDC Disable Input.
#Event ID 39: PDC Suspend/Resume handler activated.
#Event ID 40: PDC Session handler - Session Connected, Console: SessionId, Connected: Console.
#Event ID 41: PDC Connection Event.
#Event ID 42: PDC Initialization - AoAc: PDC_Initialization__AoAc, Status:Status.
#Message #
Fields #
| Name | Description |
|---|---|
AoAc UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 43: Suspend/Resume client in process Process (session:Session) at Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Process Pointer | |
Session UInt32 | |
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 43,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4120,
"thread_id": 1036
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:48:28.514Z",
"version": 0
},
"event_data": {
"Client": "0xFFFFDC84CBFD3D70",
"PdcId": 17,
"Process": "0xFFFFC807B8B470C0",
"Session": 0,
"Status": 0
},
"message": ""
}
Event ID 44: Suspend/Resume client in process Process (session:Session) at Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Process Pointer | |
Session UInt32 | |
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 44,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4120,
"thread_id": 12756
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:48:31.284Z",
"version": 0
},
"event_data": {
"Client": "0xFFFFDC84CBFD3D70",
"PdcId": 17,
"Process": "0xFFFFC807B8B470C0",
"Session": 0,
"Status": 0
},
"message": ""
}
Event ID 45: Suspend/reesume Client Client sent a request to PDC.
#Event ID 46: Response from PDC to suspend/resume client Client.
#Event ID 47: Suspend/resume message PowerEvent: Transaction id: Message, PowerEvent: TransactionId.
#Event ID 48: Suspend Entered
#Event ID 49: Suspend Exited
#Event ID 50: Suspend Entered
#Event ID 51: Suspend Exited
#Event ID 52: Suspend Entered
#Event ID 53: Suspend Exited
#Event ID 54: Suspend Entered
#Event ID 55: Suspend Exited
#Event ID 56: Suspend/Resume callback
#Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 57: Suspend/resume started: Type: Suspendresume_started_Type, Session: Session, IteratioType: IteratioType, ClientContext:ClientContext, PDC Sequence:PDC_Sequence, Power Event:Power_Event, WaitTime:Wai...
#Description
Suspend/resume started: Type: Suspendresume_started_Type, Session: Session, IteratioType: IteratioType, ClientContext:ClientContext, PDC Sequence:PDC_Sequence, Power Event:Power_Event, WaitTime:WaitTime.
Message #
Fields #
| Name | Description |
|---|---|
Type UInt32 | |
Session UInt32 | |
Iteration UInt32 | |
ClientContext Pointer | |
PdcSequence UInt32 | |
Value UInt32 | |
WaitTime UInt32 |
Event ID 58: Notification received: Client: Notification_received_Client, Received sequence number:Received_sequence_number.
#Event ID 59: Invalid notification: Client: Invalid_notification_Client, Expected sequence number:Expected_sequence_number, Received sequence number:Received_sequence_number.
#Event ID 60: Notification received from all clients: Status:Status.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 61: PDC Suspend/Resume event handler activated.
#Event ID 62: Connected standby entered
#Event ID 63: CS entered with times: PLM: DisableInputToPLMEntry, DAM: DisableInputToDAMEntry,Low Power Epoch: DisableInputToLowPowerEpochEntry.
#Event ID 64: Connected standby about the exit
#Event ID 65: CS exited with times: Low Power Epoch: ResiliencyExitToLowPowerEpochEntry, DAM:ResiliencyExitToDAMEntry, PLM:ResiliencyExitToPLMEntry.
#Message #
Fields #
| Name | Description |
|---|---|
ResiliencyExitToLowPowerEpochEntry UInt32 | |
ResiliencyExitToDAMEntry UInt32 | |
ResiliencyExitToPLMEntry UInt32 | |
PhaseTimesResiliencyAndResiliencyNotification UInt32 | |
PhaseTimesLowPowerAndDam UInt32 | |
PhaseTimesPlmAndPresence UInt32 | |
PhaseTimesConnectionAndMaintenanceAndScreenOn UInt32 | |
CsDuration UInt32 | |
ScenarioInstanceId UInt64 |
Event ID 66: Connected standby progression aborted
#Event ID 67: Connected standby exited
#Event ID 68: PDC state changed: new: PDC_state_changed_new, old:old.
#Event ID 69: Console Display Off request status:Console_Display_Off_request_status.
#Message #
Fields #
| Name | Description |
|---|---|
Status UInt32 | NTSTATUS reference |
Event ID 70: Console Display Off is disabled
#Event ID 71: Activator Client (PDC Identifier:PdcId) registered with status: ResiliencyClientCount.
#Event ID 72: Notification client Client (PDC Identifier:PdcId) registered with status: Type.
#Event ID 73: Resiliency client Client (PDC Identifier:ClientReferences) registered with status: CurrentState.
#Event ID 74: PDC Filter Input.
#Event ID 75: Task client Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 76: Task client Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 77: Task message Message: Status/Active: Status/Active.
#Event ID 78: Task Client Client sent a request to PDC.
#Event ID 79: Response from PDC to task client Client.
#Event ID 80: Rundown of PDC task client ReferenceCount - PDC identifier:Status, ReferenceCount:Name, Status:Client, Name:PdcId.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
ReferenceCount UInt32 | 1 - PDC identifier. |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 81: PDC task client TaskClient referenced at csphase At.
#Event ID 82: PDC task client TaskClient dereferenced at csphase At.
#Event ID 84: DisplayOffEnd
#Event ID 86: EnterConnectedStandbyAbort
#Event ID 87: ActivationStatistics
#Fields #
| Name | Description |
|---|---|
TimeActivated UInt32 | |
ConnectedStandbyTimeAndActivationCount UInt32 | |
ClientIdAndFlags UInt32 | |
MaxActivationDuration UInt32 |
Event ID 88: Scenario client Client (PDC Identifier:PdcId) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 89: Scenario client Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 90: Task message PdcMessage: Status/Active: Client.
#Message #
Fields #
| Name | Description |
|---|---|
PdcMessage Pointer | |
Client Pointer | |
PdcId UInt32 | |
OperationStatus UInt32 | NTSTATUS reference |
Active Boolean | |
ReferenceCount UInt32 |
Event ID 91: Scenario Client Client sent a request to PDC.
#Event ID 92: Response from PDC to scenario client Client.
#Event ID 93: Rundown of PDC scenario client Active - PDC identifier:Status, Active:Name, Status:Client, Name:PdcId.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Active Boolean | 1 - PDC identifier. |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 94: SPM scenario Scenario state changed: new NextState, old PreviousState.
#Event ID 95: SPM scenario Scenario has ClientIdCount scenario clients of dependency type Type.
#Event ID 96: SPM scenario client TestClient info - Name:ClientNameLength TestClient:ClientId.
#Event ID 97: Rundown of SPM scenario Flags - GUID:State, Flags:Name, State:Scenario, Name:ScenarioNameLength.
#Event ID 98: Rundown of SPM scenario DripsCount - DripsTime:PlatformIdleTranstions, DripsCount:PlatformIdleCount, PlatformIdleTranstions:Scenario, PlatformIdleCount:DripsTimeInUs.
#Event ID 99: SPM client ID PdcId state changed: old PreviousState, new NextState.
#Event ID 101: PhaseAccounting_V1
#Fields #
| Name | Description |
|---|---|
DataCount UInt32 | |
Data Int8 | |
ScenarioInstanceId UInt64 |
Event ID 102: ClientVerboseRundown
#Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
ClientFlags UInt32 | |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 103: ActivatorActiveTooLong
#Fields #
| Name | Description |
|---|---|
TimeContinuouslyActive UInt32 | |
ClientIdAndActivityTypeAndOnAc UInt32 | |
UserClientProcess UInt32 |
Event ID 104: Rundown of SPM scenario DripsCount - DripsTime:PlatformIdleTranstions, DripsCount:PlatformIdleCount, PlatformIdleTranstions:Scenario, PlatformIdleCount:DripsTimeInUs.
#Event ID 105: SpmScenarioActivityRundown
#Fields #
| Name | Description |
|---|---|
Scenario Pointer | |
ActiveCount UInt64 | |
MaxActiveTime UInt64 | |
MinActiveTime UInt64 | |
TotalActiveTime UInt64 |
Event ID 106: Ppm Profile client Client (PDC Identifier:PdcId, ProfileGuid:ProfileGuid) registered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
ProfileGuid GUID | |
Status UInt32 | NTSTATUS reference |
ClientNameLength UInt32 | |
ClientName UnicodeString |
Event ID 107: PPM profile client Client (PDC Identifier:PdcId) deregistered with status: Status.
#Message #
Fields #
| Name | Description |
|---|---|
Client Pointer | |
PdcId UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 108: PDC PPM profile client Client acquired a referenced.
#Event ID 109: PDC PPM profile client Client released a referenced.
#Event ID 110: PDCV2 ClientRegistered - ClientId=ClientId, status=Status.
#Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
Status UInt32 | NTSTATUS reference |
PdcVersion UInt32 | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString |
Event ID 111: PDCV2 ClientActivated - ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) activationCount=ActivationCount, upCounter=ActivationsUpCounter, maxDuration=ExpectedMaximumDurat...
#Description
PDCV2 ClientActivated - ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) activationCount=ActivationCount, upCounter=ActivationsUpCounter, maxDuration=ExpectedMaximumDuration, status=Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
TaskNameLength UInt32 | |
TaskName UnicodeString | |
SubTaskLength UInt32 | |
SubTaskName UnicodeString | |
ActivationCount UInt32 | |
ActivationsUpCounter UInt32 | |
ExpectedMaximumDuration UInt32 | |
Status UInt32 | NTSTATUS reference |
ActivationHandle Pointer | |
PdcVersion UInt32 | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 111,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:21.713Z",
"version": 0
},
"event_data": {
"ActivationCount": 1,
"ActivationHandle": "0x1CE119FB7C0",
"ActivationsUpCounter": 880,
"ClientId": 77,
"ExpectedMaximumDuration": 300,
"ModuleName": "C:\\Windows\\SYSTEM32\\TelLib.dll",
"ModuleNameLength": 30,
"PdcVersion": 2,
"Status": 0,
"SubTaskLength": 21,
"SubTaskName": "TelLib_AsimovUploader",
"TaskName": "UTC Network Requests",
"TaskNameLength": 20
},
"message": ""
}
Event ID 112: PDCV2 ClientRenewed - ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) expectedMax=ExpectedMaximumDuration, activationCount=ActivationCount, upCounter=ActivationsUpCounte...
#Description
PDCV2 ClientRenewed - ClientId=(, )(activationHandle=) expectedMax=, activationCount=, upCounter=, activationDuration=, renewalUpcount=, errorDetails=, status=.
Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
TaskNameLength UInt32 | |
TaskName UnicodeString | |
SubTaskLength UInt32 | |
SubTaskName UnicodeString | |
ExpectedMaximumDuration UInt32 | |
ActivationCount UInt32 | |
ActivationsUpCounter UInt32 | |
ActivationDuration UInt64 | |
RenewalUpCounter UInt32 | |
ErrorDetail UInt32 | |
Status UInt32 | NTSTATUS reference |
ActivationHandle Pointer | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString | |
BrokeredForPID UInt32 |
Event ID 113: PDCV2 ClientDeactivated - ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) activationCount=ActivationCount, upCounter=ActivationsUpCounter, Status=Status, activationDurat...
#Description
PDCV2 ClientDeactivated - ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) activationCount=ActivationCount, upCounter=ActivationsUpCounter, Status=Status, activationDuration=ActivationDuration.
Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
TaskNameLength UInt32 | |
TaskName UnicodeString | |
SubTaskLength UInt32 | |
SubTaskName UnicodeString | |
ActivationCount UInt32 | |
ActivationsUpCounter UInt32 | |
ActivationDuration UInt64 | |
Status UInt32 | NTSTATUS reference |
ActivationHandle Pointer | |
PdcVersion UInt32 | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString | |
BrokeredForPID UInt32 |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 113,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4236,
"thread_id": 7896
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 05:50:22.257Z",
"version": 0
},
"event_data": {
"ActivationCount": 0,
"ActivationDuration": 532,
"ActivationHandle": "0x1CE119FB7C0",
"ActivationsUpCounter": 880,
"BrokeredForPID": 0,
"ClientId": 77,
"ModuleName": "C:\\Windows\\SYSTEM32\\TelLib.dll",
"ModuleNameLength": 30,
"PdcVersion": 2,
"Status": 0,
"SubTaskLength": 21,
"SubTaskName": "TelLib_AsimovUploader",
"TaskName": "UTC Network Requests",
"TaskNameLength": 20
},
"message": ""
}
Event ID 114: PDCV2 ClientUnregistered - ClientId=ClientId, status=Status.
#Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
Status UInt32 | NTSTATUS reference |
PdcVersion UInt32 | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString |
Event ID 115: PDCV2 ActivationClientCallback ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) was called with reason CallbackReason, activationCount=ActivationCount, upCounter=Activati...
#Description
PDCV2 ActivationClientCallback ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) was called with reason CallbackReason, activationCount=ActivationCount, upCounter=ActivationsUpCounter, duration=ActivationDuration, Status=Status.
Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
TaskNameLength UInt32 | |
TaskName UnicodeString | |
SubTaskLength UInt32 | |
SubTaskName UnicodeString | |
CallbackReason UInt32 | |
ActivationCount UInt32 | |
ActivationsUpCounter UInt32 | |
ActivationDuration UInt64 | |
Status UInt32 | NTSTATUS reference |
ActivationHandle Pointer | |
RenewalUpCounter UInt32 | |
PdcVersion UInt32 | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString | |
BrokeredForPID UInt32 |
Event ID 116: PDCV2 SetBrokeredPID- ClientId=ClientId(TaskName, SubTaskName)(activationHandle=ActivationHandle) PID=BrokeredForPID, expectedMax=ExpectedMaximumDuration, activationCount=ActivationCount, upCounter...
#Description
PDCV2 SetBrokeredPID- ClientId=(, )(activationHandle=) PID=, expectedMax=, activationCount=, upCounter=, activationDuration=, renewalUpcount=, status=.
Message #
Fields #
| Name | Description |
|---|---|
ClientId UInt32 | |
TaskNameLength UInt32 | |
TaskName UnicodeString | |
SubTaskLength UInt32 | |
SubTaskName UnicodeString | |
ExpectedMaximumDuration UInt32 | |
ActivationCount UInt32 | |
ActivationsUpCounter UInt32 | |
ActivationDuration UInt64 | |
RenewalUpCounter UInt32 | |
BrokeredForPID UInt32 | |
Status UInt32 | NTSTATUS reference |
ActivationHandle Pointer | |
ModuleNameLength UInt32 | |
ModuleName UnicodeString |
Event ID 117: Modern Standby exit due to PDC signal client
#Fields #
| Name | Description |
|---|---|
ScenarioInstanceId UInt8 | |
RequestType UInt32 | |
Reason UInt32 | |
ClassId GUID | |
ProviderId GUID | |
DiagStringLength UInt32 | |
DiagString UnicodeString | |
ScenarioInstanceIdV2 UInt64 |
Event ID 118: Modern Standby entry due to PDC signal client
#Fields #
| Name | Description |
|---|---|
ScenarioInstanceId UInt8 | |
RequestType UInt32 | |
Reason UInt32 | |
ClassId GUID | |
ProviderId GUID | |
DiagStringLength UInt32 | |
DiagString UnicodeString | |
ScenarioInstanceIdV2 UInt64 |
Event ID 119: PDC phase Phase was referenced.
#Message #
Fields #
| Name | Description |
|---|---|
Phase UInt8 | |
CountChange Int32 | |
ReferenceCount Int32 | |
WasWorkItemQueued Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-PDC",
"guid": "{A6BF0DEB-3659-40AD-9F81-E25AF62CE3C7}",
"event_source_name": "",
"event_id": 119,
"version": 0,
"level": 0,
"task": 118,
"opcode": 0,
"keywords": "0x0000000000000880",
"time_created": "2026-06-02T05:29:50.513+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 20788
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"CountChange": 1,
"Phase": 0,
"ReferenceCount": 3,
"WasWorkItemQueued": false
},
"message": "PdcPhaseReferenced"
}
Event ID 120: PDC phase Phase was dereferenced.
#Message #
Fields #
| Name | Description |
|---|---|
Phase UInt8 | |
CountChange Int32 | |
ReferenceCount Int32 | |
WasWorkItemQueued Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-PDC",
"guid": "{A6BF0DEB-3659-40AD-9F81-E25AF62CE3C7}",
"event_source_name": "",
"event_id": 120,
"version": 0,
"level": 0,
"task": 119,
"opcode": 0,
"keywords": "0x0000000000000880",
"time_created": "2026-06-02T05:29:50.516+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4,
"thread_id": 20788
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {
"CountChange": 1,
"Phase": 0,
"ReferenceCount": 2,
"WasWorkItemQueued": false
},
"message": "PdcPhaseDereferenced"
}
Event ID 121: PDC phase PreviousTargetPhase was selected as target.
#Event ID 123: PDC phase Phase notifications state changed.
#Event ID 124: PDC phase Phase rundown.
#Event ID 125: PDC phase Phase accounting rundown.
#Event ID 126: PDC phase notification callback
#Fields #
| Name | Description |
|---|---|
CurrentPhase UInt8 | |
CurrentPhaseNotificationsState UInt8 | |
CurrentPhaseNotificationsStatus UInt32 | |
CurrentPhasePdcSequence UInt32 | |
CallbackStatus UInt32 | |
CallbackPdcSequence UInt32 |
Event ID 127: PDC notified system is idle state SystemIdle.
#Message #
Fields #
| Name | Description |
|---|---|
SystemIdle Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 127,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 4,
"thread_id": 12036
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:47:20.607Z",
"version": 0
},
"event_data": {
"SystemIdle": false
},
"message": ""
}
Event ID 128: A function in PDC received an invalid argument
#Fields #
| Name | Description |
|---|---|
FunctionNameLength UInt32 | |
FunctionName UnicodeString | |
ArgumentNameLength UInt32 | |
ArgumentName UnicodeString |
Event ID 129: SpmScenarioCreate
#Fields #
| Name | Description |
|---|---|
Scenario Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 130: SpmScenarioDelete
#Fields #
| Name | Description |
|---|---|
Scenario Pointer | |
Status UInt32 | NTSTATUS reference |
Event ID 132: GroupRequest
#Fields #
| Name | Description |
|---|---|
GroupId UInt32 | |
RequestCount Int32 | |
Updated Boolean |
Example Event #
{
"system": {
"channel": "Microsoft-Windows-Kernel-Pdc/Diagnostic",
"computer": "10.2.10.21",
"correlation": {},
"event_id": 132,
"event_record_id": 0,
"event_source_name": "",
"execution": {
"process_id": 8992,
"thread_id": 8508
},
"guid": "",
"keywords": 0,
"level": 4,
"opcode": 0,
"provider": "Microsoft-Windows-PDC",
"security": {
"user_id": ""
},
"task": 0,
"time_created": "2026-07-22 01:47:30.337Z",
"version": 0
},
"event_data": {
"GroupId": 5,
"RequestCount": 1,
"Updated": true
},
"message": ""
}
Provenance
ETW provider GUID {A6BF0DEB-3659-40AD-9F81-E25AF62CE3C7}
Defined in Microsoft-Windows-Pdc.dll, which carries the event manifest.
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB