Microsoft-Windows-PerfNet

EventTitleChannelSampleRule
1000Unable to open the Network Services performance object.ApplicationNN
1001Unable to collect Network Services performance data.ApplicationNN
2000Unable to collect Browser performance data because the NetApi32.ApplicationNN
2001Unable to collect Browser performance data because the Query function was not …ApplicationNN
2002Unable to open the Redirector service performance object.ApplicationNN
2003Unable to read performance data for the Redirector service.ApplicationNN
2004Unable to open the Server service performance object.ApplicationNN
2005Unable to read performance data for the Server service.ApplicationNN
2006Unable to read Server Queue performance data from the Server service.ApplicationNN
2007Unable to allocate memory for TDI Statistics block.ApplicationNN
3000Entered the OpenNbtPerformanceData routine.OperationalNN
3099The OpenNbtPerformanceData routine successfully completed.OperationalNN
3100Entered the CollectNbtPerformanceData routine.OperationalNN
3101Unable to read IO control information from an NBT device.ApplicationNN
3102Successfully read the NBT device IO Control information.OperationalNN
3103The data buffer passed to the collection routine was too small to receive the …OperationalNN
3199The CollectNbtPerformanceData routine successfully completed.OperationalNN
3200Entered the CloseNbtPerformanceData routine.OperationalNN
4000Entered the OpenTcpIpPerformanceData routine.OperationalNN
4001NBT Open failed.OperationalNN
4002NBT Open succeeded.OperationalNN
4010Unable to get the local computer name.ApplicationNN
4099The OpenTcpIpPerformanceData routine successfully completed.OperationalNN
4100Entered the CollectTcpIpPerformanceData routine.OperationalNN
4105The CollectNbtPerformanceData routine returned an error.OperationalNN
4106The OpenTcpIpPerformanceData routine did not establish a SNMP Mgr Session.OperationalNN
4108The SnmpMgrRequest call requesting the TCP, IP, UDP and Interface Counters …OperationalNN
4110The SnmpMgrRequest call requesting ICMP Counters returned an error.OperationalNN
4111Processing NetInterface entries.OperationalNN
4112The buffer is not large enough to store the Network Interface data.OperationalNN
4113The SnmpGet (GETNEXT) request returned an error while processing the Net …OperationalNN
4114Copying data from network requests to the Performance Monitor buffer.OperationalNN
4116The buffer is not large enough to store the Network Protocol (IP, ICMP, TCP & …OperationalNN
4121SNMP returned a NULL buffer in response to a request for network performance …ApplicationNN
4199The CollectTcpIpPerformanceData routine successfully completed.OperationalNN
4200Entered the CloseTcpIpPerformanceData routine.OperationalNN

Event ID 1000: Unable to open the Network Services performance object.

#
Channel
Application

Description

Unable to open the Network Services performance object. Error: Win32Error.

Message #

Unable to open the Network Services performance object. Error: %1

Fields #

NameDescription
Win32Error UInt32

Event ID 1001: Unable to collect Network Services performance data.

#
Channel
Application

Description

Unable to collect Network Services performance data. The DLL failed to load because it cannot successfully communicate with network service devices.

Message #

Unable to collect Network Services performance data. The DLL failed to load because it cannot successfully communicate with network service devices.

Event ID 2000: Unable to collect Browser performance data because the NetApi32.

#
Channel
Application

Description

Unable to collect Browser performance data because the NetApi32.DLL failed to load. Error: Win32Error.

Message #

Unable to collect Browser performance data because the NetApi32.DLL failed to load. Error: %1

Fields #

NameDescription
Win32Error UInt32

Event ID 2001: Unable to collect Browser performance data because the Query function was not found in the NetApi32.

#
Channel
Application

Description

Unable to collect Browser performance data because the Query function was not found in the NetApi32.DLL. Error: NTSTATUS.

Message #

Unable to collect Browser performance data because the Query function was not found in the NetApi32.DLL. Error: %1

Fields #

NameDescription
NTSTATUS UInt32

Event ID 2002: Unable to open the Redirector service performance object.

#
Channel
Application

Description

Unable to open the Redirector service performance object. Error: NTSTATUS.

Message #

Unable to open the Redirector service performance object. Error: %1

Fields #

NameDescription
NTSTATUS UInt32

Event ID 2003: Unable to read performance data for the Redirector service.

#
Channel
Application

Description

Unable to read performance data for the Redirector service. Error: NTSTATUS.

Message #

Unable to read performance data for the Redirector service. Error: %1

Fields #

NameDescription
NTSTATUS UInt32

Event ID 2004: Unable to open the Server service performance object.

#
Channel
Application

Description

Unable to open the Server service performance object. Error: NTSTATUS.

Message #

Unable to open the Server service performance object. Error: %1

Fields #

NameDescription
NTSTATUS UInt32

Event ID 2005: Unable to read performance data for the Server service.

#
Channel
Application

Description

Unable to read performance data for the Server service. Error: NTSTATUS.

Message #

Unable to read performance data for the Server service. Error: %1

Fields #

NameDescription
NTSTATUS UInt32
IOCompletionNTSTATUS UInt32

Event ID 2006: Unable to read Server Queue performance data from the Server service.

#
Channel
Application

Description

Unable to read Server Queue performance data from the Server service. Error: NTSTATUS.

Message #

Unable to read Server Queue performance data from the Server service. Error: %1

Fields #

NameDescription
NTSTATUS UInt32
IOCompletionNTSTATUS UInt32

Event ID 2007: Unable to allocate memory for TDI Statistics block.

#
Channel
Application

Description

Unable to allocate memory for TDI Statistics block. Close one or more applications and retry.

Message #

Unable to allocate memory for TDI Statistics block. Close one or more applications and retry.

Event ID 3000: Entered the OpenNbtPerformanceData routine.

#
Channel
Operational

Event ID 3099: The OpenNbtPerformanceData routine successfully completed.

#
Channel
Operational

Event ID 3100: Entered the CollectNbtPerformanceData routine.

#
Channel
Operational

Fields #

NameDescription
ValueName UnicodeString

Event ID 3101: Unable to read IO control information from an NBT device.

#
Channel
Application

Description

Unable to read IO control information from an NBT device. A network device using the NBT protocol could not be queried.

Message #

Unable to read IO control information from an NBT device. A network device using the NBT protocol could not be queried.

Event ID 3102: Successfully read the NBT device IO Control information.

#
Channel
Operational

Event ID 3103: The data buffer passed to the collection routine was too small to receive the data from the NBT device.

#
Channel
Operational

Description

The data buffer passed to the collection routine was too small to receive the data from the NBT device. No data was returned to the caller. The bytes available and the bytes required are in the message data.

Message #

The data buffer passed to the collection routine was too small to receive the data from the NBT device. No data was returned to the caller. The bytes available and the bytes required are in the message data.

Fields #

NameDescription
Available UInt32
Required UInt32

Event ID 3199: The CollectNbtPerformanceData routine successfully completed.

#
Channel
Operational

Event ID 3200: Entered the CloseNbtPerformanceData routine.

#
Channel
Operational

Event ID 4000: Entered the OpenTcpIpPerformanceData routine.

#
Channel
Operational

Event ID 4001: NBT Open failed.

#
Channel
Operational

Description

NBT Open failed. See NBT error message.

Message #

NBT Open failed. See NBT error message.

Event ID 4002: NBT Open succeeded.

#
Channel
Operational

Event ID 4010: Unable to get the local computer name.

#
Channel
Application

Description

Unable to get the local computer name. The data in the data section contains the error code.

Message #

Unable to get the local computer name. The data in the data section contains the error code.

Fields #

NameDescription
Error UInt32

Event ID 4099: The OpenTcpIpPerformanceData routine successfully completed.

#
Channel
Operational

Event ID 4100: Entered the CollectTcpIpPerformanceData routine.

#
Channel
Operational

Fields #

NameDescription
ValueName UnicodeString

Event ID 4105: The CollectNbtPerformanceData routine returned an error.

#
Channel
Operational

Description

The CollectNbtPerformanceData routine returned an error. The error status is in the data section.

Message #

The CollectNbtPerformanceData routine returned an error. The error status is in the data section.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4106: The OpenTcpIpPerformanceData routine did not establish a SNMP Mgr Session.

#
Channel
Operational

Event ID 4108: The SnmpMgrRequest call requesting the TCP, IP, UDP and Interface Counters returned an error.

#
Channel
Operational

Description

The SnmpMgrRequest call requesting the TCP, IP, UDP and Interface Counters returned an error. The ErrorStatus and ErrorIndex values are shown in Data.

Message #

The SnmpMgrRequest call requesting the TCP, IP, UDP and Interface Counters returned an error. The ErrorStatus and ErrorIndex values are shown in Data.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4110: The SnmpMgrRequest call requesting ICMP Counters returned an error.

#
Channel
Operational

Description

The SnmpMgrRequest call requesting ICMP Counters returned an error. The ErrorStatus and ErrorIndex values are shown in Data.

Message #

The SnmpMgrRequest call requesting ICMP Counters returned an error. The ErrorStatus and ErrorIndex values are shown in Data.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4111: Processing NetInterface entries.

#
Channel
Operational

Event ID 4112: The buffer is not large enough to store the Network Interface data.

#
Channel
Operational

Description

The buffer is not large enough to store the Network Interface data. The returned data contains the available and required buffer size.

Message #

The buffer is not large enough to store the Network Interface data. The returned data contains the available and required buffer size.

Fields #

NameDescription
Available UInt32
Required UInt32

Event ID 4113: The SnmpGet (GETNEXT) request returned an error while processing the Net Interface instances.

#
Channel
Operational

Description

The SnmpGet (GETNEXT) request returned an error while processing the Net Interface instances. The ErrorStatus and ErrorIndex are shown in Data.

Message #

The SnmpGet (GETNEXT) request returned an error while processing the Net Interface instances. The ErrorStatus and ErrorIndex are shown in Data.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 4114: Copying data from network requests to the Performance Monitor buffer.

#
Channel
Operational

Event ID 4116: The buffer is not large enough to store the Network Protocol (IP, ICMP, TCP & UDP) data.

#
Channel
Operational

Description

The buffer is not large enough to store the Network Protocol (IP, ICMP, TCP & UDP) data. The returned data contains the available and required buffer size.

Message #

The buffer is not large enough to store the Network Protocol (IP, ICMP, TCP & UDP) data. The returned data contains the available and required buffer size.

Fields #

NameDescription
Available UInt32
Required UInt32

Event ID 4121: SNMP returned a NULL buffer in response to a request for network performance information.

#
Channel
Application

Description

SNMP returned a NULL buffer in response to a request for network performance information. This error may be caused by a problem with the SNMP service.

Message #

SNMP returned a NULL buffer in response to a request for network performance information. This error may be caused by a problem with the SNMP service.

Event ID 4199: The CollectTcpIpPerformanceData routine successfully completed.

#
Channel
Operational

Event ID 4200: Entered the CloseTcpIpPerformanceData routine.

#
Channel
Operational

Provenance

ETW provider GUID cab2b8a5-49b9-4eec-b1b0-fac21da05a3b

Defined in perfnet.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB