Microsoft-Windows-PrintService

EventTitleChannelSampleRule
1The print spooler failed to import the printer driver that was downloaded from …OperationalNN
22Failed to upgrade printer settings for printer <PrinterName> driver …OperationalNN
23Printer <PrinterName> failed to initialize because a suitable <DriverName> …OperationalNN
99The print spooler encountered a fatal error while executing a critical operation …AdminNN
100Printer PrinterName successfully added.DebugNN
101Failed to add printer PrinterName, error code ErrorCode.DebugNN
104Deleting printer PrinterName succeeded.DebugNN
105Deleting printer PrinterName failed, error code ErrorCode.DebugNN
106Starting document job JobID for printer PrinterName succeeded.DebugNN
107Starting document job JobID for printer PrinterName failed, error code …DebugNN
110Ending document job JobID for printer PrinterName succeeded.DebugNN
111Ending document job JobID for printer PrinterName failed, error code ErrorCode.DebugNN
114Adding printer driver ObjectName succeeded.DebugNN
115Adding printer driver ObjectName failed, error code ErrorCode.DebugNN
118Opening printer ObjectName succeeded.DebugNN
119Opening printer ObjectName failed, error code ErrorCode.DebugNN
122Starting page job JobID at printer PrinterName succeeded.DebugNN
123Starting page failed at printer JobID, error code ErrorCode.DebugNN
124Ending page job JobID at printer PrinterName succeeded.DebugNN
125Ending page job JobID at printer PrinterName failed, error code ErrorCode.DebugNN
131Setting printer PrinterName failed, error code ErrorCode.DebugNN
200Adding CSR printer connection ObjectName succeeded.DebugNN
201Adding CSR printer connection ObjectName failed, error code ErrorCode.DebugNN
204Deleting CSR printer connection ObjectName succeeded.DebugNN
205Deleting CSR printer connection ObjectName failed, error code ErrorCode.DebugNN
207Opening CSR printer ObjectName failed, error code ErrorCode.DebugNN
210Closing CSR printer ObjectName succeeded.DebugNN
211Closing CSR printer ObjectName failed, error code ErrorCode.DebugNN
212Parsing inf (InfPath) for printer driver DriverName succeeded (processor …DebugNN
213Parsing inf (InfPath) for printer driver DriverName failed (processor …OperationalYN
214Installing printer driver DriverName succeeded.DebugNN
215Installing printer driver DriverName failed, error code LastError, HRESULT …AdminYN
216A printer setup operation succeeded during the installation process.DebugNN
217A printer setup operation failed during the installation process, error code …OperationalNN
218Copying printer driver package InfPath succeeded.OperationalNN
219Copying printer driver package InfPath failed, error code LastError, HRESULT …OperationalNN
220Retrieving CSR cache information for printer ObjectName succeeded.OperationalNN
221Retrieving CSR cache information for printer ObjectName failed, error code …OperationalNN
222Message.DebugNN
223Message.DebugNN
224A remote print driver package operation Function failed with error code Error, …OperationalNN
225An error occurred while installing printer driver 'DriverName'.AdminNN
226An error occurred while installing printer driver 'DriverName'.AdminNN
227An error occurred while installing printer driver 'DriverName'.AdminNN
228An error occurred while installing printer driver 'DriverName'.AdminNN
229An error occurred while installing printer driver 'DriverName'.OperationalNN
230A problem was encountered while installing printer driver 'DriverName'.AdminNN
231An attempt was made to upgrade installed class driver 'DriverName' to a …OperationalNN
232An attempt was made to upgrade installed printer driver 'DriverName' to an older …AdminNN
233An attempt was made to upgrade installed printer driver 'DriverName' to a …AdminNN
234A problem was encountered while deleting printer driver 'DriverName'.OperationalNN
235An error occurred while installing printer driver 'DriverName'.OperationalNN
236An error occurred while installing printer driver 'DriverName'.OperationalNN
237An error occurred while installing printer driver 'DriverName'.OperationalNN
238An error occurred while installing printer driver 'DriverName'.OperationalNN
239An error occurred while installing printer driver 'DriverName'.OperationalNN
240An error occurred while installing printer driver 'DriverName'.OperationalNN
241An attempt was made to upgrade installed printer driver 'DriverName' to a driver …AdminNN
242An error occurred while configuring print queue 'PrinterName'.AdminNN
300Printer param1 was created.OperationalYN
301Printer param1 was deleted, and users will no longer be able to print to this …OperationalYN
302Printer param1 will be deleted.OperationalYN
303Printer param1 was paused.OperationalYN
304Printer param1 was resumed.OperationalYN
305The jobs in the print queue for printer param1 were deleted.OperationalNN
306Settings for printer param1 were changed.OperationalYN
307Document param1, param2 owned by param3 on param4 was printed on param5 through …OperationalYN
308Document param1, param2 owned by param3 was paused on param4.OperationalYN
309Document param1, param2 owned by param3 was resumed on param4.OperationalYN
310Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by …OperationalYN
311An administrator moved document param1, param2 owned by param3 to position …OperationalNN
312Form param1 was added.OperationalNN
313Form param1 was removed.OperationalNN
314Document param1, param2 owned by param3 timed out while printing on param4.AdminNN
315The print spooler failed to share printer param2 with shared resource name …AdminNN
316Printer driver param1 for param2 param3 was added or updated.OperationalYY
317Printer driver param1 was deleted.OperationalYN
318Failed to upgrade printer settings for printer param1 driver param2.AdminNN
319Printer param1 failed to initialize because a suitable param2 driver could not …AdminNN
320Printer param1 failed to initialize because none of its ports (param2) could be …AdminNN
321File(s) param1 associated with printer param2 were added or updated.OperationalYY
322While attempting to publish the printer to the Active Directory directory …AdminNN
323While attempting to publish the printer to the Active Directory directory …AdminNN
325While attempting to remove the printer from the Active Directory directory …AdminNN
326While attempting to publish the printer to the Active Directory directory …AdminNN
327While attempting to publish the printer to the Active Directory directory …AdminNN
328While attempting to publish the printer to the Active Directory directory …AdminNN
329While attempting to publish the printer to the Active Directory directory …AdminNN
331While attempting to publish the printer to the Active Directory directory …AdminNN
332The printer was successfully published to the Active Directory directory …OperationalNN
333While attempting to publish the printer to the Active Directory directory …AdminNN
334The printer was successfully removed from the Active Directory directory …OperationalNN
335While attempting to remove the printer from the Active Directory directory …AdminNN
336Print queue param1 was successfully updated in the Active Directory directory …OperationalNN
337The print queue could not be found on domain param1.AdminNN
338Printer param1 was successfully removed from the Active Directory directory …OperationalNN
342The print spooler removed print queue param1 from the Active Directory directory …OperationalNN
343The print spooler was unable to connect to print queue param1 based on the …OperationalNN
344The print spooler removed print queue param1 from the Active Directory directory …OperationalNN
345The print spooler removed print queue param1 from the Active Directory directory …OperationalNN
346The print spooler removed print queue param1 from the Active Directory directory …OperationalNN
347Print queue param1 could not be deleted (pruned) from the Active Directory …AdminNN
348This version of param1 is incompatible with this version of Windows.AdminNN
349The print spooler failed to create a symbolic link between …AdminNN
350Document param1 failed to print and was deleted because of corruption in the …AdminNN
351The attempt for param1 to use a Windows NT 4.AdminNN
352The priority of document param1, param2 owned by param3 was changed to param4 on …OperationalNN
353The document failed to print because the user did not have the necessary …AdminNN
354param1 initialization failed at param2.AdminYY
356Failed to install or update driver param1 on cluster spooler resource param2.AdminNN
359The attempt to install printer param1 into an offline operating system image …AdminNN
360Updating the color profile failed for printer param1 with Win32 error code …AdminNN
361Printer param1 failed to initialize its ports.AdminNN
362The print spooler could not initialize because resolving the local machine name …AdminNN
363The print spooler param1 failed to start.AdminNN
364Windows could not load print processor param1 because EnumDatatypes did not …AdminNN
365Windows could not load print processor param1 because EnumDatatypes failed.AdminNN
366The print server security descriptor for param1 is invalid.AdminNN
367Windows could not initialize printer param1 because the print processor param2 …AdminNN
368The print spooler failed to verify printer driver package param1 for environment …OperationalYN
369The print spooler failed to verify printer driver package for environment …AdminNN
370The print spooler failed to regenerate the printer driver information for driver …AdminNN
371The print spooler failed to unshare printer param2 which is shared as param3.AdminNN
372The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, …AdminYN
373The spooler has detected that a component has an unusually large number of open …AdminNN
502The print spooler failed to get the computer name.AdminNN
503The system failed to initialize the local print provider: Error Error.AdminNN
504Failed to initialize the router work crew: Error Error.AdminNN
505Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error.AdminNN
507The system failed to initialize the name cache: Error Error.AdminNN
508Failed to initialize the router cache: Error Error.AdminNN
509The print spooler cannot start because the PrinterBusEnumerator could not start.AdminNN
510InitializeProvider cannot allocate memory for Name.AdminNN
511The print spooler failed to load print provider Name.AdminNN
512InitializePrintProvider failed for provider Name.AdminNN
513Group Policy was unable to add per computer connection Name.AdminNN
514Group Policy was unable to delete per computer connection Name.AdminNN
515Group Policy was unable to delete per computer printer connection Name.AdminNN
516Group Policy was unable to deploy per computer printer connection Name.AdminNN
517Group Policy was unable to update per computer printer connection Name.AdminNN
518Group Policy was unable to delete the per user printer connection Name.AdminNN
519Group Policy was unable to deploy per user printer connection Name.AdminNN
520Group Policy was unable to update per user printer connection Name.AdminNN
600The print spooler failed to import the printer driver that was downloaded from …AdminNN
601The print spooler failed to download and import the printer driver from …AdminNN
602The print spooler failed to reopen an existing printer connection because it …AdminNN
603The print spooler failed to reopen an existing printer connection because it …OperationalYN
604The print spooler encountered an unknown driver type while saving Name cache …AdminNN
701The print filter pipeline host cannot initialize with the Component Object Model …OperationalNN
702The print filter pipeline host is shutting down due to the following error: …OperationalNN
703The print filter pipeline host is shutting down due to an error in signaling the …OperationalNN
704The print filter pipeline host is shutting down because the query interface for …OperationalNN
800Spooling job JobDiag.JobId.OperationalYN
801Printing job JobDiag.JobId.OperationalYN
802Deleting job DeleteJobDiag.JobId.OperationalYN
805Rendering job RenderJobDiag.JobId.OperationalYN
806Pausing job JobId.DebugNN
807Resuming job JobId.DebugNN
808The print spooler failed to load a plug-in module PluginDllName, error code …AdminYY
809The print spooler failed to recursively delete the directory DirectoryName, …OperationalNN
810The print spooler failed to delete the directory DirectoryName and the contained …OperationalNN
811The print spooler failed to move the file Source to Destination, error code …OperationalNN
812The print spooler failed to delete the file Source, error code ErrorCode.OperationalNN
813The print spooler failed to copy the file Source to Destination, error code …OperationalNN
814The print spooler failed to install the print processor Processor Environment …OperationalNN
815The print spooler service failed to register the RPC server protocol sequence …OperationalNN
816The print spooler service detected an invalid RPC protocol sequence …OperationalNN
817The RPC end-point policy for the print spooler service is disabled.OperationalNN
818The print spooler RPC server failed to start, error code ErrorCode.OperationalNN
819Client Side Rendering is currently disabled by policy (Policy).OperationalNN
820Client side rendering to PrintProcessor failed, error code ErrorCode.OperationalNN
821The print spooler Client Side Rendering is attempting to render the job JobId on …OperationalNN
822Unknown print processor (LocalPrintProcessor) or invalid data type …OperationalNN
823The default printer was changed to NewDefaultPrinter.AdminYN
824A fatal error occurred while printing job DocumentName, id JobId on the print …OperationalNN
825Client side rendering to PrintProcessor failed, error code ErrorCode.OperationalNN
826Force Client Side Rendering policy was successfully set on printer PrinterName, …OperationalNN
827The specified print queue QueueName is invalid.OperationalNN
828The print job JobId failed with error code ErrorCode.OperationalNN
829XPS API call Name (Context) started.DebugNN
830XPS API call Name (Context) ended, status StatusCode.DebugNN
831XPS API dependency Name (Context) started.DebugNN
832XPS API dependency Name (Context) ended, status StatusCode.DebugNN
833Print spooler operation Name (Context) started.DebugNN
834Print spooler operation Name (Context) ended, status StatusCode.DebugNN
842The print job PrintDriverSandboxJobPrintProc.JobId was sent through the print …OperationalYN
843The print spooler service recorded SucceededRpcCalls successful and …DebugNN
844The print spooler selected the isolation mode IsolationMode (0 - loaded in the …DebugNN
845Attempted to load module Module for printer Printer, printer driver Driver.DebugNN
846Cached printer PrinterName has been scavenged and deleted.OperationalNN
847Cached printer PrinterName has been scheduled for deletion due to a logon …OperationalNN
848Printer PrinterName was shared by the print spooler as ShareName.OperationalYN
849Printer PrinterName shared as ShareName was unshared by the print spooler.OperationalYN
850The print spooler called the function Function in print driver module Driver.OperationalNN
851Point and Print not allowed by policy for queue PrintQueue.OperationalNN
852Driver OriginalDriver could not be installed for printer connection PrinterName.AdminNN
853Print Client Side Rendering synchronization for print job cache completed with …DebugNN
854Print Client Side Rendering synchronization for printer information cache …DebugNN
855OpenPrinter cache entry added for printer PrinterName with access code …DebugNN
856Connection 'ConnectionName' has been reconfigured for normal operation because …OperationalNN
857Connection 'ConnectionName' has been reconfigured for normal operation because …OperationalNN
858Connection 'ConnectionName' has been reconfigured for normal operation because …AdminNN
859Connection 'ConnectionName' has been reconfigured for normal operation because …OperationalNN
860Connection 'ConnectionName' has been reconfigured for normal operation because …OperationalNN
861Connection 'ConnectionName' has been reconfigured for normal operation because …OperationalNN
862Connection 'ConnectionName' has been reconfigured for normal operation because …AdminNN
863Connection 'ConnectionName' has been reconfigured for normal operation due to an …OperationalNN
864The Windows Fax and Scan servicing operation failed, HRESULT HResult.OperationalNN
865There were Failures print job failures out of Jobs jobs sent to printer …AdminNN
866The print spooler failed to create a Plug and Play printer device object for the …AdminNN
867The WS-Print Port Monitor failed to initialize correctly.AdminNN
868The Offline EventLog on machine 'MachineName' exceeded the allow maximum size.AdminNN
869In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code …AdminNN
870The print spooler failed to download package for driver Driver.AdminNN
871The current print job was rejected due to Device Control Print Restrictions.AdminNN
1111Driver <DriverName> required for printer <PrinterName> is unknown.OperationalNN
4098The computer <ComputerName or IP> preference item in the '{GUID}' Group Policy …OperationalNN
4909Print Service event 4909 (manifest stub).OperationalNY
8192The user <UserName> preference item in the '{GUID}' Group Policy object did not …OperationalNN

Event ID 1: The print spooler failed to import the printer driver that was downloaded from <ServerName> into the driver store for driver <DriverName>.

#
Channel
Operational

Event ID 22: Failed to upgrade printer settings for printer <PrinterName> driver <DriverName>.

#
Channel
Operational

Event ID 23: Printer <PrinterName> failed to initialize because a suitable <DriverName> driver could not be found.

#
Channel
Operational

Event ID 99: The print spooler encountered a fatal error while executing a critical operation (OperationCode, error Error) and must immediately terminate.

#
Channel
Admin
Task
Processterminationduetocriticalfailure
Opcode
Unexpectedprocesstermination

Description

The print spooler encountered a fatal error while executing a critical operation (OperationCode, error Error) and must immediately terminate. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Message #

The print spooler encountered a fatal error while executing a critical operation (%1, error %2) and must immediately terminate. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Fields #

NameDescription
OperationCode UInt32
Error HexInt32

Event ID 100: Printer PrinterName successfully added.

#
Channel
Debug
Task
Addingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer PrinterName successfully added. See the event user data for context information.

Message #

Printer %3 successfully added. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 101: Failed to add printer PrinterName, error code ErrorCode.

#
Channel
Debug
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

Failed to add printer PrinterName, error code ErrorCode. See the event user data for context information.

Message #

Failed to add printer %3, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 104: Deleting printer PrinterName succeeded.

#
Channel
Debug
Task
Deletingaprinter
Opcode
SpoolerOperationSucceeded

Description

Deleting printer PrinterName succeeded. See the event user data for context information.

Message #

Deleting printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 105: Deleting printer PrinterName failed, error code ErrorCode.

#
Channel
Debug
Task
Deletingaprinter
Opcode
SpoolerOperationFailed

Description

Deleting printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Deleting printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 106: Starting document job JobID for printer PrinterName succeeded.

#
Channel
Debug
Task
Startingadocumentprintjob
Opcode
SpoolerOperationSucceeded

Description

Starting document job JobID for printer PrinterName succeeded. See the event user data for context information.

Message #

Starting document job %3 for printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 107: Starting document job JobID for printer PrinterName failed, error code ErrorCode.

#
Channel
Debug
Task
Startingadocumentprintjob
Opcode
SpoolerOperationFailed

Description

Starting document job JobID for printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Starting document job %3 for printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 110: Ending document job JobID for printer PrinterName succeeded.

#
Channel
Debug
Task
Endingadocumentprintjob
Opcode
SpoolerOperationSucceeded

Description

Ending document job JobID for printer PrinterName succeeded. See the event user data for context information.

Message #

Ending document job %3 for printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 111: Ending document job JobID for printer PrinterName failed, error code ErrorCode.

#
Channel
Debug
Task
Endingadocumentprintjob
Opcode
SpoolerOperationFailed

Description

Ending document job JobID for printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Ending document job %3 for printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 114: Adding printer driver ObjectName succeeded.

#
Channel
Debug
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Adding printer driver ObjectName succeeded. See the event user data for context information.

Message #

Adding printer driver %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 115: Adding printer driver ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Adding printer driver ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Adding printer driver %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 118: Opening printer ObjectName succeeded.

#
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationSucceeded

Description

Opening printer ObjectName succeeded. See the event user data for context information.

Message #

Opening printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 119: Opening printer ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Opening printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Opening printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 122: Starting page job JobID at printer PrinterName succeeded.

#
Channel
Debug
Task
Startinganewdocumentpage
Opcode
SpoolerOperationSucceeded

Description

Starting page job JobID at printer PrinterName succeeded. See the event user data for context information.

Message #

Starting page job %3 at printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 123: Starting page failed at printer JobID, error code ErrorCode.

#
Channel
Debug
Task
Startinganewdocumentpage
Opcode
SpoolerOperationFailed

Description

Starting page failed at printer JobID, error code ErrorCode. See the event user data for context information.

Message #

Starting page failed at printer %3, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 124: Ending page job JobID at printer PrinterName succeeded.

#
Channel
Debug
Task
Endingadocumentpage
Opcode
SpoolerOperationSucceeded

Description

Ending page job JobID at printer PrinterName succeeded. See the event user data for context information.

Message #

Ending page job %3 at printer %4 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 125: Ending page job JobID at printer PrinterName failed, error code ErrorCode.

#
Channel
Debug
Task
Endingadocumentpage
Opcode
SpoolerOperationFailed

Description

Ending page job JobID at printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Ending page job %3 at printer %4 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
JobID UInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 131: Setting printer PrinterName failed, error code ErrorCode.

#
Channel
Debug
Task
Settingprinterconfiguration
Opcode
SpoolerOperationFailed

Description

Setting printer PrinterName failed, error code ErrorCode. See the event user data for context information.

Message #

Setting printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
PrinterName UnicodeString
Status HexInt32NTSTATUS reference

Event ID 200: Adding CSR printer connection ObjectName succeeded.

#
Channel
Debug
Task
Addingaprinterconnection
Opcode
SpoolerOperationSucceeded

Description

Adding CSR printer connection ObjectName succeeded. See the event user data for context information.

Message #

Adding CSR printer connection %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 201: Adding CSR printer connection ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Addingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Adding CSR printer connection ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Adding CSR printer connection %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 204: Deleting CSR printer connection ObjectName succeeded.

#
Channel
Debug
Task
Deletingaprinterconnection
Opcode
SpoolerOperationSucceeded

Description

Deleting CSR printer connection ObjectName succeeded. See the event user data for context information.

Message #

Deleting CSR printer connection %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 205: Deleting CSR printer connection ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Deletingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Deleting CSR printer connection ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Deleting CSR printer connection %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 207: Opening CSR printer ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Openingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Opening CSR printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Opening CSR printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 210: Closing CSR printer ObjectName succeeded.

#
Channel
Debug
Task
Closingaprinterhandle
Opcode
SpoolerOperationSucceeded

Description

Closing CSR printer ObjectName succeeded. See the event user data for context information.

Message #

Closing CSR printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 211: Closing CSR printer ObjectName failed, error code ErrorCode.

#
Channel
Debug
Task
Closingaprinterhandle
Opcode
SpoolerOperationFailed

Description

Closing CSR printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Closing CSR printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 212: Parsing inf (InfPath) for printer driver DriverName succeeded (processor architecture ProcessorArchitecture).

#
Channel
Debug
Task
Parsingaprinterdriverinf
Opcode
SpoolerOperationSucceeded

Description

Parsing inf (InfPath) for printer driver DriverName succeeded (processor architecture ProcessorArchitecture). See the event user data for context information.

Message #

Parsing inf (%4) for printer driver %5 succeeded (processor architecture %7). See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 213: Parsing inf (InfPath) for printer driver DriverName failed (processor architecture ProcessorArchitecture), error code LastError, HRESULT HResult.

#
Channel
Operational
Level
Error
Task
Parsingaprinterdriverinf
Opcode
SpoolerOperationFailed

Description

Parsing inf (InfPath) for printer driver DriverName failed (processor architecture ProcessorArchitecture), error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Parsing inf (%4) for printer driver %5 failed (processor architecture %7), error code %8, HRESULT %9. See the event user data for context information.

Fields #

NameDescription
SetupParseInf.Label UnicodeString
SetupParseInf.Message UnicodeString
SetupParseInf.AdditionalInfo UnicodeString
SetupParseInf.InfPath UnicodeString
SetupParseInf.DriverName UnicodeString
SetupParseInf.InstallSection UnicodeString
SetupParseInf.ProcessorArchitecture UnicodeString
SetupParseInf.LastError HexInt32
SetupParseInf.HResult HexInt32
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 213,
    "version": 0,
    "level": 2,
    "task": 18,
    "opcode": 12,
    "keywords": 4611686018427388448,
    "time_created": "2026-05-30T01:50:56.6850617+00:00",
    "event_record_id": 73,
    "correlation": {
      "ActivityID": "{6C4AD011-B2EA-447E-ABE8-CBD1BBC806BE}"
    },
    "execution": {
      "process_id": 3872,
      "thread_id": 10128
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "SetupParseInf": {
      "Label": "ParseInfAndCommitFileQueue",
      "Message": "PreSelectDriverEx failed",
      "AdditionalInfo": "-",
      "InfPath": "-",
      "DriverName": "Microsoft XPS Document Writer",
      "InstallSection": "-",
      "ProcessorArchitecture": "Windows x64",
      "LastError": "0x705",
      "HResult": "0x80070705"
    }
  },
  "message": "Parsing inf (-) for printer driver Microsoft XPS Document Writer failed (processor architecture Windows x64), error code 0x705, HRESULT 0x80070705. See the event user data for context information."
}

Event ID 214: Installing printer driver DriverName succeeded.

#
Channel
Debug
Task
Installingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Installing printer driver DriverName succeeded. See the event user data for context information.

Message #

Installing printer driver %5 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
PackageAware UnicodeString
CoreDriverDependencies UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 215: Installing printer driver DriverName failed, error code LastError, HRESULT HResult.

#
Channel
Admin
Level
Error
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Installing printer driver DriverName failed, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Installing printer driver %5 failed, error code %10, HRESULT %11. See the event user data for context information.

Fields #

NameDescription
SetupInstallPrinterDriver.Label UnicodeString
SetupInstallPrinterDriver.Message UnicodeString
SetupInstallPrinterDriver.AdditionalInfo UnicodeString
SetupInstallPrinterDriver.InfPath UnicodeString
SetupInstallPrinterDriver.DriverName UnicodeString
SetupInstallPrinterDriver.InstallSection UnicodeString
SetupInstallPrinterDriver.ProcessorArchitecture UnicodeString
SetupInstallPrinterDriver.PackageAware UnicodeString
SetupInstallPrinterDriver.CoreDriverDependencies UnicodeString
SetupInstallPrinterDriver.LastError HexInt32
SetupInstallPrinterDriver.HResult HexInt32
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
InfPath UnicodeString
DriverName UnicodeString
InstallSection UnicodeString
ProcessorArchitecture UnicodeString
PackageAware UnicodeString
CoreDriverDependencies UnicodeString
LastError HexInt32
HResult HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 215,
    "version": 0,
    "level": 2,
    "task": 19,
    "opcode": 12,
    "keywords": -9223372036854775264,
    "time_created": "2026-05-30T01:50:56.6852684+00:00",
    "event_record_id": 50,
    "correlation": {
      "ActivityID": "{6C4AD011-B2EA-447E-ABE8-CBD1BBC806BE}"
    },
    "execution": {
      "process_id": 3872,
      "thread_id": 10128
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "SetupInstallPrinterDriver": {
      "Label": "InternalInstallPrinterDriverFromPackage",
      "Message": "pfnPSetupParseInfAndCommitFileQueue failed",
      "AdditionalInfo": "-",
      "InfPath": "-",
      "DriverName": "Microsoft XPS Document Writer",
      "InstallSection": "-",
      "ProcessorArchitecture": "Windows x64",
      "PackageAware": "Not package aware",
      "CoreDriverDependencies": "-",
      "LastError": "0x0",
      "HResult": "0x80070705"
    }
  },
  "message": "Installing printer driver Microsoft XPS Document Writer failed, error code 0x0, HRESULT 0x80070705. See the event user data for context information."
}

Event ID 216: A printer setup operation succeeded during the installation process.

#
Channel
Debug
Task
Installingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

A printer setup operation succeeded during the installation process. See the event user data for context information.

Message #

A printer setup operation succeeded during the installation process. See the event user data for context information.

Fields #

NameDescription
Context UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 217: A printer setup operation failed during the installation process, error code LastError, HRESULT HResult.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

A printer setup operation failed during the installation process, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

A printer setup operation failed during the installation process, error code %5, HRESULT %6. See the event user data for context information.

Fields #

NameDescription
Context UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 218: Copying printer driver package InfPath succeeded.

#
Channel
Operational
Task
Copyingaprinterdriverpackage
Opcode
SpoolerOperationSucceeded

Description

Copying printer driver package InfPath succeeded. See the event user data for context information.

Message #

Copying printer driver package %5 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
Server UnicodeString
InfPath UnicodeString
DestInfPath UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 219: Copying printer driver package InfPath failed, error code LastError, HRESULT HResult.

#
Channel
Operational
Task
Copyingaprinterdriverpackage
Opcode
SpoolerOperationFailed

Description

Copying printer driver package InfPath failed, error code LastError, HRESULT HResult. See the event user data for context information.

Message #

Copying printer driver package %5 failed, error code %8, HRESULT %9. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
Message UnicodeString
AdditionalInfo UnicodeString
Server UnicodeString
InfPath UnicodeString
DestInfPath UnicodeString
ProcessorArchitecture UnicodeString
LastError HexInt32
HResult HexInt32

Event ID 220: Retrieving CSR cache information for printer ObjectName succeeded.

#
Channel
Operational
Task
Enumeratingprinters
Opcode
SpoolerOperationSucceeded

Description

Retrieving CSR cache information for printer ObjectName succeeded. See the event user data for context information.

Message #

Retrieving CSR cache information for printer %3 succeeded. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 221: Retrieving CSR cache information for printer ObjectName failed, error code ErrorCode.

#
Channel
Operational
Task
Enumeratingprinters
Opcode
SpoolerOperationFailed

Description

Retrieving CSR cache information for printer ObjectName failed, error code ErrorCode. See the event user data for context information.

Message #

Retrieving CSR cache information for printer %3 failed, error code %2. See the event user data for context information.

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 222: Message.

#
Channel
Debug
Task
Tracingaspoolermessage
Opcode
SpoolerTrace

Message #

%1

Fields #

NameDescription
Message UnicodeString
LastError HexInt32

Event ID 223: Message.

#
Channel
Debug
Task
Tracingaspoolermessage
Opcode
SpoolerOperationFailed

Message #

%1

Fields #

NameDescription
Message UnicodeString
LastError HexInt32

Event ID 224: A remote print driver package operation Function failed with error code Error, server name Server.

#
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

A remote print driver package operation failed with error code , server name . This was most likely caused by an unexpected error in the protocol communication between the client and the print server.

Message #

A remote print driver package operation %1 failed with error code %2, server name %3. This was most likely caused by an unexpected error in the protocol communication between the client and the print server.

Fields #

NameDescription
Function UnicodeString
Error HexInt32
Server UnicodeString

Event ID 225: An error occurred while installing printer driver 'DriverName'.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. Error code: HResult. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

An error occurred while installing printer driver '%1'. Error code: %4. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 226: An error occurred while installing printer driver 'DriverName'.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The driver being installed is incompatible with this version of Windows. Please obtain and install a compatible version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. The driver being installed is incompatible with this version of Windows. Please obtain and install a compatible version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
DriverModelVersion UInt32

Event ID 227: An error occurred while installing printer driver 'DriverName'.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. Error code: HResult. The driver being installed relies on class driver 'RequiredClassDriver', which is not present on this computer. The class driver may be available on Windows Update. Please ensure that Windows Update is enabled in Device Installation Settings and that a connection can be established, and try again, or choose an alternate driver that works with this print device.

Message #

An error occurred while installing printer driver '%1'. Error code: %4. The driver being installed relies on class driver '%3', which is not present on this computer. The class driver may be available on Windows Update. Please ensure that Windows Update is enabled in Device Installation Settings and that a connection can be established, and try again, or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 228: An error occurred while installing printer driver 'DriverName'.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The driver being installed relies on class driver 'RequiredClassDriver', which failed to install. Error code: HResult. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

An error occurred while installing printer driver '%1'. The driver being installed relies on class driver '%3', which failed to install. Error code: %4. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 229: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The driver must contain a pipelineconfig.xml file.

Message #

An error occurred while installing printer driver '%1'. The driver must contain a pipelineconfig.xml file.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 230: A problem was encountered while installing printer driver 'DriverName'.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Description

A problem was encountered while installing printer driver 'DriverName'. A printer extension bundled with the driver failed to register, and will be unavailable. Error code: HResult. The driver will still be functional. Please obtain and install a new version of the printer extension or printer driver from the manufacturer (if available).

Message #

A problem was encountered while installing printer driver '%1'. A printer extension bundled with the driver failed to register, and will be unavailable. Error code: %4. The driver will still be functional. Please obtain and install a new version of the printer extension or printer driver from the manufacturer (if available).

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 231: An attempt was made to upgrade installed class driver 'DriverName' to a non-class driver.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Description

An attempt was made to upgrade installed class driver 'DriverName' to a non-class driver. Doing so will prevent any driver that relies on the class driver to stop functioning. The class driver will remain installed.

Message #

An attempt was made to upgrade installed class driver '%1' to a non-class driver. Doing so will prevent any driver that relies on the class driver to stop functioning. The class driver will remain installed.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 232: An attempt was made to upgrade installed printer driver 'DriverName' to an older version of the driver, which is unsupported.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Description

An attempt was made to upgrade installed printer driver 'DriverName' to an older version of the driver, which is unsupported. If the older version of the driver is required, please delete the current version (via Print Management or Print Server Properties) and try again.

Message #

An attempt was made to upgrade installed printer driver '%1' to an older version of the driver, which is unsupported. If the older version of the driver is required, please delete the current version (via Print Management or Print Server Properties) and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 233: An attempt was made to upgrade installed printer driver 'DriverName' to a version that does not support printer sharing, or may cause compatibility problem...

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Description

An attempt was made to upgrade installed printer driver 'DriverName' to a version that does not support printer sharing, or may cause compatibility problems when sharing to some computers. In order to use the new driver, please disable sharing for all print queues that are using this driver (via Print Management or the Sharing tab in Printer Properties) and try again.

Message #

An attempt was made to upgrade installed printer driver '%1' to a version that does not support printer sharing, or may cause compatibility problems when sharing to some computers. In order to use the new driver, please disable sharing for all print queues that are using this driver (via Print Management or the Sharing tab in Printer Properties) and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 234: A problem was encountered while deleting printer driver 'DriverName'.

#
Channel
Operational
Task
Deletingaprinterdriver
Opcode
SpoolerWarning

Description

A problem was encountered while deleting printer driver 'DriverName'. A printer extension bundled with the driver failed to unregister. Error code: HResult. The driver will still be deleted.

Message #

A problem was encountered while deleting printer driver '%1'. A printer extension bundled with the driver failed to unregister. Error code: %4. The driver will still be deleted.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 235: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The file 'Value' referenced by the Directive directive could not be found.

Message #

An error occurred while installing printer driver '%1'. The file '%5' referenced by the %4 directive could not be found.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 236: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive directive is not allowed for this type of driver. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. The %4 directive is not allowed for this type of driver. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
ClassDriverOnly Boolean
NonClassDriverOnly Boolean

Event ID 237: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver ''. The directive is malformed, by having either an empty token or an incorrect number of tokens. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. The %4 directive is malformed, by having either an empty token or an incorrect number of tokens. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
EmptyToken Boolean
IncorrectNumberOfTokens Boolean

Event ID 238: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive must be a GUID, but 'Value' was provided.

Message #

An error occurred while installing printer driver '%1'. The %4 must be a GUID, but '%5' was provided.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 239: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. The Directive directive must be present in the manifest.

Message #

An error occurred while installing printer driver '%1'. The %4 directive must be present in the manifest.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
Directive UnicodeString
Value UnicodeString

Event ID 240: An error occurred while installing printer driver 'DriverName'.

#
Channel
Operational
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

An error occurred while installing printer driver 'DriverName'. There must be only one manifest per driver. Either no manifest was found, or too many manifests were found. See the event user data for context information.

Message #

An error occurred while installing printer driver '%1'. There must be only one manifest per driver. Either no manifest was found, or too many manifests were found. See the event user data for context information.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
MissingManifest Boolean
MultipleManifests Boolean

Event ID 241: An attempt was made to upgrade installed printer driver 'DriverName' to a driver that does not support non-inbox port monitors.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerWarning

Description

An attempt was made to upgrade installed printer driver 'DriverName' to a driver that does not support non-inbox port monitors. In order to use the new driver, please remove or reconfigure all print queues that are using this driver and try again.

Message #

An attempt was made to upgrade installed printer driver '%1' to a driver that does not support non-inbox port monitors. In order to use the new driver, please remove or reconfigure all print queues that are using this driver and try again.

Fields #

NameDescription
DriverName UnicodeString
InfPath UnicodeString
RequiredClassDriver UnicodeString
HResult HexInt32

Event ID 242: An error occurred while configuring print queue 'PrinterName'.

#
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

An error occurred while configuring print queue 'PrinterName'. Printer driver 'DriverName' may not be used in conjunction with a non-inbox port monitor.

Message #

An error occurred while configuring print queue '%1'. Printer driver '%2' may not be used in conjunction with a non-inbox port monitor.

Fields #

NameDescription
PrinterName UnicodeString
DriverName UnicodeString

Event ID 300: Printer param1 was created.

#
Channel
Operational
Level
Informational
Task
Addingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was created. No user action is required.

Message #

Printer %1 was created. No user action is required.

Fields #

NameDescription
PrinterCreated.Param1
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 300,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2026-06-13T15:13:09.6513266+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 8552,
      "thread_id": 4996
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrinterCreated": {
      "Param1": "evtgen-printer"
    }
  },
  "message": "Printer evtgen-printer was created. No user action is required."
}

Event ID 301: Printer param1 was deleted, and users will no longer be able to print to this printer.

#
Channel
Operational
Level
Informational
Task
Deletingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was deleted, and users will no longer be able to print to this printer. No user action is required.

Message #

Printer %1 was deleted, and users will no longer be able to print to this printer. No user action is required.

Fields #

NameDescription
PrinterDeleted.Param1
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 301,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2026-06-13T15:13:18.2273480+00:00",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 9060,
      "thread_id": 7024
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterDeleted": {
      "Param1": "evtgen-printer"
    }
  },
  "message": "Printer evtgen-printer was deleted, and users will no longer be able to print to this printer. No user action is required."
}

Event ID 302: Printer param1 will be deleted.

#
Channel
Operational
Level
Informational
Task
Deletingaprinter
Opcode
SpoolerOperationStarted

Description

Printer param1 will be deleted. No user action is required.

Message #

Printer %1 will be deleted. No user action is required.

Fields #

NameDescription
PrinterDeletionPending.Param1
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 302,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 10,
    "keywords": 4611686018427389984,
    "time_created": "2026-06-13T15:13:18.1778725+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 9060,
      "thread_id": 6148
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrinterDeletionPending": {
      "Param1": "evtgen-printer"
    }
  },
  "message": "Printer evtgen-printer will be deleted. No user action is required."
}

Event ID 303: Printer param1 was paused.

#
Channel
Operational
Level
Informational
Task
Pausingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was paused. No user action is required.

Message #

Printer %1 was paused. No user action is required.

Fields #

NameDescription
PrinterPaused.Param1
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 303,
    "version": 0,
    "level": 4,
    "task": 23,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2026-05-30T01:51:11.2092102+00:00",
    "event_record_id": 98,
    "correlation": {
      "ActivityID": "{5EF3D886-AF92-402B-AAF8-5AC4C18D93B9}"
    },
    "execution": {
      "process_id": 3872,
      "thread_id": 10128
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrinterPaused": {
      "Param1": "PrintLab-PDF"
    }
  },
  "message": "Printer PrintLab-PDF was paused. No user action is required."
}

Event ID 304: Printer param1 was resumed.

#
Channel
Operational
Level
Informational
Task
Resumingaprinter
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was resumed. No user action is required.

Message #

Printer %1 was resumed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 304,
    "version": 0,
    "level": 4,
    "task": 24,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2021-10-27T10:28:26.229212Z",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3836
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "PrinterUnPaused": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "{BABBC1A0-F75A-44B0-92BC-57E20CEDA1D8}"
    }
  }
}

References #

Event ID 305: The jobs in the print queue for printer param1 were deleted.

#
Channel
Operational
Task
Purgingjobsfromprinterqueue
Opcode
SpoolerOperationSucceeded

Description

The jobs in the print queue for printer param1 were deleted. No user action is required.

Message #

The jobs in the print queue for printer %1 were deleted. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 306: Settings for printer param1 were changed.

#
Channel
Operational
Level
Informational
Task
Settingprinterconfiguration
Opcode
SpoolerOperationSucceeded

Description

Settings for printer param1 were changed. No user action is required.

Message #

Settings for printer %1 were changed. No user action is required.

Fields #

NameDescription
PrinterSet.Param1
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 306,
    "version": 0,
    "level": 4,
    "task": 17,
    "opcode": 11,
    "keywords": 4611686018427389984,
    "time_created": "2026-06-13T15:13:10.0553491+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 8552,
      "thread_id": 1836
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrinterSet": {
      "Param1": "evtgen-printer"
    }
  },
  "message": "Settings for printer evtgen-printer were changed. No user action is required."
}

Event ID 307: Document param1, param2 owned by param3 on param4 was printed on param5 through port param6.

#
Channel
Operational
Level
Informational
Collection Priority
Recommended (NSA)
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 on param4 was printed on param5 through port param6. Size in bytes: SizeInBytes. Pages printed: PagesPrinted. No user action is required.

Message #

Document %1, %2 owned by %3 on %4 was printed on %5 through port %6.  Size in bytes: %7. Pages printed: %8. No user action is required.

Fields #

NameDescription
DocumentPrinted.Param1
DocumentPrinted.Param2
DocumentPrinted.Param3
DocumentPrinted.Param4
DocumentPrinted.Param5
DocumentPrinted.Param6
DocumentPrinted.Param7
DocumentPrinted.Param8
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 307,
    "version": 0,
    "level": 4,
    "task": 26,
    "opcode": 11,
    "keywords": 4611686018427390016,
    "time_created": "2026-05-30T01:51:30.3741444+00:00",
    "event_record_id": 114,
    "correlation": {},
    "execution": {
      "process_id": 12596,
      "thread_id": 4296
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "DocumentPrinted": {
      "Param1": "2",
      "Param2": "document",
      "Param3": "domainadmin",
      "Param4": "\\\\JD-DC01-2022",
      "Param5": "PrintLab-PDF",
      "Param6": "C:\\PrintLab\\pdflab_output.pdf",
      "Param7": "53851",
      "Param8": "1"
    }
  },
  "message": "Document 2, document owned by domainadmin on \\\\JD-DC01-2022 was printed on PrintLab-PDF through port C:\\PrintLab\\pdflab_output.pdf.  Size in bytes: 53851. Pages printed: 1. No user action is required."
}

References #

Event ID 308: Document param1, param2 owned by param3 was paused on param4.

#
Channel
Operational
Level
Informational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 was paused on param4. This document will not print until the document owner resumes the print job. No user action is required.

Message #

Document %1, %2 owned by %3 was paused on %4. This document will not print until the document owner resumes the print job. No user action is required.

Fields #

NameDescription
DocumentPaused.Param1
DocumentPaused.Param2
DocumentPaused.Param3
DocumentPaused.Param4
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 308,
    "version": 0,
    "level": 4,
    "task": 26,
    "opcode": 11,
    "keywords": 4611686018427390016,
    "time_created": "2026-05-30T01:51:14.6869907+00:00",
    "event_record_id": 102,
    "correlation": {
      "ActivityID": "{A1E5D082-A57A-42F4-A80D-125F5E1EFB3F}"
    },
    "execution": {
      "process_id": 3872,
      "thread_id": 7704
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "DocumentPaused": {
      "Param1": "7",
      "Param2": "document",
      "Param3": "domainadmin",
      "Param4": "PrintLab-PDF"
    }
  },
  "message": "Document 7, document owned by domainadmin was paused on PrintLab-PDF. This document will not print until the document owner resumes the print job. No user action is required."
}

Event ID 309: Document param1, param2 owned by param3 was resumed on param4.

#
Channel
Operational
Level
Informational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

Document param1, param2 owned by param3 was resumed on param4. No user action is required.

Message #

Document %1, %2 owned by %3 was resumed on %4. No user action is required.

Fields #

NameDescription
DocumentResumed.Param1
DocumentResumed.Param2
DocumentResumed.Param3
DocumentResumed.Param4
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "{747EF6FD-E535-4D16-B510-42C90F6873A1}",
    "event_source_name": "",
    "event_id": 309,
    "version": 0,
    "level": 4,
    "task": 26,
    "opcode": 11,
    "keywords": 4611686018427390016,
    "time_created": "2026-05-30T01:51:15.7044064+00:00",
    "event_record_id": 103,
    "correlation": {
      "ActivityID": "{F1F9D0C4-D7F6-44F1-9BA0-F0367025EA0C}"
    },
    "execution": {
      "process_id": 3872,
      "thread_id": 7704
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "DocumentResumed": {
      "Param1": "6",
      "Param2": "document",
      "Param3": "domainadmin",
      "Param4": "PrintLab-PDF"
    }
  },
  "message": "Document 6, document owned by domainadmin was resumed on PrintLab-PDF. No user action is required."
}

Event ID 310: Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by DocumentDeleted.Param3 was deleted on DocumentDeleted.Param4.

#
Channel
Operational
Level
Informational
Task
Deletingadocument
Opcode
SpoolerOperationSucceeded

Description

Document DocumentDeleted.Param1, DocumentDeleted.Param2 owned by DocumentDeleted.Param3 was deleted on DocumentDeleted.Param4. No user action is required.

Message #

Document %1, %2 owned by %3 was deleted on %4. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 310,
    "version": 0,
    "level": 4,
    "task": 27,
    "opcode": 11,
    "keywords": 4611686018427390016,
    "time_created": "2026-03-13T20:25:33.325281+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DocumentDeleted": {
      "Param1": "2",
      "Param2": "Print Document",
      "Param3": "domainadmin",
      "Param4": "TestPrinter_EventGen"
    }
  },
  "message": ""
}

Event ID 311: An administrator moved document param1, param2 owned by param3 to position param4 on param5.

#
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

An administrator moved document param1, param2 owned by param3 to position param4 on param5. This changes when the document will print. No user action is required.

Message #

An administrator moved document %1, %2 owned by %3 to position %4 on %5. This changes when the document will print. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 312: Form param1 was added.

#
Channel
Operational
Task
Addingaprintform
Opcode
SpoolerOperationSucceeded

Description

Form param1 was added. No user action is required.

Message #

Form %1 was added. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 313: Form param1 was removed.

#
Channel
Operational
Task
Deletingaprintform
Opcode
SpoolerOperationSucceeded

Description

Form param1 was removed. No user action is required.

Message #

Form %1 was removed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 314: Document param1, param2 owned by param3 timed out while printing on param4.

#
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

Document param1, param2 owned by param3 timed out while printing on param4. The spooler waited for param5 milliseconds and no data was received.

Message #

Document %1, %2 owned by %3 timed out while printing on %4. The spooler waited for %5 milliseconds and no data was received.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 315: The print spooler failed to share printer param2 with shared resource name param3.

#
Channel
Admin
Task
Sharingaprinter
Opcode
SpoolerOperationFailed

Description

The print spooler failed to share printer param2 with shared resource name param3. Error param1. The printer cannot be used by others on the network.

Message #

The print spooler failed to share printer %2 with shared resource name %3. Error %1. The printer cannot be used by others on the network.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 316: Printer driver param1 for param2 param3 was added or updated.

#
Channel
Operational
Level
Informational
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Printer driver param1 for param2 param3 was added or updated. Files:- param4. No user action is required.

Message #

Printer driver %1 for %2 %3 was added or updated. Files:- %4. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 316,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 11,
    "keywords": 4611686018427390208,
    "time_created": "2021-10-27T10:14:27.309949Z",
    "event_record_id": 153,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DriverAdded": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Generic / Text Only",
      "Param2": "Windows x64",
      "Param3": "Version-3",
      "Param4": "UNIDRV.DLL, UNIDRVUI.DLL, TTY.GPD, UNIDRV.HLP, TTYRES.DLL, TTY.INI, TTY.DLL, TTYUI.DLL, TTYUI.HLP, UNIRES.DLL, STDNAMES.GPD, STDDTYPE.GDL, STDSCHEM.GDL, STDSCHMX.GDL"
    }
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Splunk # view in coverage

References #

Event ID 317: Printer driver param1 was deleted.

#
Channel
Operational
Level
Informational
Task
Deletingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

Printer driver param1 was deleted. No user action is required.

Message #

Printer driver %1 was deleted. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 317,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 11,
    "keywords": 4611686018427390208,
    "time_created": "2021-10-27T10:28:26.494838Z",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3768
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "DriverDeleted": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "Generic / Text Only"
    }
  }
}

References #

Event ID 318: Failed to upgrade printer settings for printer param1 driver param2.

#
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Failed to upgrade printer settings for printer param1 driver param2. Error: Error. The device settings for the printer are set to those configured by the manufacturer.

Message #

Failed to upgrade printer settings for printer %1 driver %2. Error: %3. The device settings for the printer are set to those configured by the manufacturer.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 319: Printer param1 failed to initialize because a suitable param2 driver could not be found.

#
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Printer param1 failed to initialize because a suitable param2 driver could not be found. The new printer settings that you specified have not taken effect. Install or reinstall the printer driver. You might need to contact the vendor for an updated driver.

Message #

Printer %1 failed to initialize because a suitable %2 driver could not be found. The new printer settings that you specified have not taken effect. Install or reinstall the printer driver. You might need to contact the vendor for an updated driver.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 320: Printer param1 failed to initialize because none of its ports (param2) could be found.

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

Printer param1 failed to initialize because none of its ports (param2) could be found. This can occur if the ports were deleted or the port information is invalid.

Message #

Printer %1 failed to initialize because none of its ports (%2) could be found. This can occur if the ports were deleted or the port information is invalid.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 321: File(s) param1 associated with printer param2 were added or updated.

#
Channel
Operational
Task
Addingaprinterdriver
Opcode
SpoolerOperationSucceeded

Description

File(s) param1 associated with printer param2 were added or updated. No user action is required.

Message #

File(s) %1 associated with printer %2 were added or updated. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "event_id": 321,
    "level": "Information",
    "task": "Adding a printer driver",
    "opcode": "Spooler Operation Succeeded",
    "time_created": "2026-03-17T19:25:13.9297980+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-PrintService/Operational"
  },
  "event_data": {}
}

Detection Patterns #

Event ID 322: While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property param1 at param2.

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property param1 at param2. Error: Error.

Message #

While attempting to publish the printer to the Active Directory directory service, Windows failed to publish property %1 at %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 323: While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue bec...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue because Windows failed to bind to container: param1. Error: param2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue because Windows failed to bind to container: %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 325: While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue param1 at param2.

#
Channel
Admin
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue param1 at param2. Error: Error.

Message #

While attempting to remove the printer from the Active Directory directory service, Windows failed to delete print queue %1 at %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 326: While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue und...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue under container param1. Error: param2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create or update the print queue under container %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 327: While attempting to publish the printer to the Active Directory directory service, the print spooler could not create print queue param1 under containe...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create print queue param1 under container param2 because Mandatory properties could not be set. Error: param3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not create print queue %1 under container %2 because Mandatory properties could not be set.  Error: %3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 328: While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the primary domain query failed. Error: param1. This can occur if Domain Name System (DNS) cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the primary domain query failed. Error: %1. This can occur if Domain Name System (DNS) cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString

Event ID 329: While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the Domain Name System (DNS) domain name could not be retrieved. Error: param1. This can occur if DNS cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container because the Domain Name System (DNS) domain name could not be retrieved. Error: %1. This can occur if DNS cannot resolve the domain controller IP address, or if the domain controller or directory service is not functioning correctly. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString

Event ID 331: While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue con...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container on domain param1. Error: param2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler could not find the appropriate print queue container on domain %1.  Error: %2. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 332: The printer was successfully published to the Active Directory directory service.

#
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

The printer was successfully published to the Active Directory directory service. The print queue param1 was successfully created in container param2. No user action is required.

Message #

The printer was successfully published to the Active Directory directory service. The print queue %1 was successfully created in container %2. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 333: While attempting to publish the printer to the Active Directory directory service, the print spooler failed to create or update print queue param1 in c...

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to publish the printer to the Active Directory directory service, the print spooler failed to create or update print queue param1 in container param2. Error: param3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Message #

While attempting to publish the printer to the Active Directory directory service, the print spooler failed to create or update print queue %1 in container %2.  Error: %3. The printer is not published in Active Directory and cannot be located by searching Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 334: The printer was successfully removed from the Active Directory directory service.

#
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

The printer was successfully removed from the Active Directory directory service. Print queue param1 was successfully deleted from container param2. The printer can no longer be located by searching Active Directory. No user action is required.

Message #

The printer was successfully removed from the Active Directory directory service. Print queue %1 was successfully deleted from container %2. The printer can no longer be located by searching Active Directory. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 335: While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue param1 from containe...

#
Channel
Admin
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationFailed

Description

While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue param1 from container param2. Error: Error.

Message #

While attempting to remove the printer from the Active Directory directory service, the print spooler failed to delete print queue %1 from container %2.  Error: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 336: Print queue param1 was successfully updated in the Active Directory directory service container param2.

#
Channel
Operational
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

Print queue param1 was successfully updated in the Active Directory directory service container param2. No user action is required.

Message #

Print queue %1 was successfully updated in the Active Directory directory service container %2. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 337: The print queue could not be found on domain param1.

#
Channel
Admin
Task
PublishingaprinterintheActiveDirectory
Opcode
SpoolerOperationFailed

Description

The print queue could not be found on domain param1. It may have been deleted from the Active Directory directory service. Windows will attempt to republish the print queue. Error: Error.

Message #

The print queue could not be found on domain %1.  It may have been deleted from the Active Directory directory service. Windows will attempt to republish the print queue.  Error: %2

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 338: Printer param1 was successfully removed from the Active Directory directory service.

#
Channel
Operational
Task
RemovingaprinterfromtheActiveDirectory
Opcode
SpoolerOperationSucceeded

Description

Printer param1 was successfully removed from the Active Directory directory service. The printer can no longer be located by searching Active Directory. No user action is required.

Message #

Printer %1 was successfully removed from the Active Directory directory service. The printer can no longer be located by searching Active Directory. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 342: The print spooler removed print queue param1 from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) n...

#
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) name or server name listed. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service because it does not have a Universal Naming Convention (UNC) name or server name listed. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 343: The print spooler was unable to connect to print queue param1 based on the information published in the Active Directory.

#
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler was unable to connect to print queue param1 based on the information published in the Active Directory. Error param2. No user action is required. If this print queue continues to be unreachable it may be removed from Active Directory.

Message #

The print spooler was unable to connect to print queue %1 based on the information published in the Active Directory. Error %2. No user action is required. If this print queue continues to be unreachable it may be removed from Active Directory.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 344: The print spooler removed print queue param1 from the Active Directory directory service.

#
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 345: The print spooler removed print queue param1 from the Active Directory directory service because it is a duplicate of another print queue.

#
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service because it is a duplicate of another print queue. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service because it is a duplicate of another print queue. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 346: The print spooler removed print queue param1 from the Active Directory directory service.

#
Channel
Operational
Task
Pruningaprinter
Opcode
SpoolerOperationSucceeded

Description

The print spooler removed print queue param1 from the Active Directory directory service. No user action is required.

Message #

The print spooler removed print queue %1 from the Active Directory directory service. No user action is required.

Fields #

NameDescription
param1 UnicodeString

Event ID 347: Print queue param1 could not be deleted (pruned) from the Active Directory directory service.

#
Channel
Admin
Task
Pruningaprinter
Opcode
SpoolerOperationFailed

Description

Print queue param1 could not be deleted (pruned) from the Active Directory directory service. Error: param2. The spooler will periodically try to remove the entry until it is successful. Continued failures may indicate an Active Directory problem, a basic network problem, or a communication problem between the domain controller and the print server.

Message #

Print queue %1 could not be deleted (pruned) from the Active Directory directory service.  Error: %2. The spooler will periodically try to remove the entry until it is successful. Continued failures may indicate an Active Directory problem, a basic network problem, or a communication problem between the domain controller and the print server.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 348: This version of param1 is incompatible with this version of Windows.

#
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerWarning

Description

This version of param1 is incompatible with this version of Windows. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

This version of %1 is incompatible with this version of Windows. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString

Event ID 349: The print spooler failed to create a symbolic link between HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Print\\Printers and HKEY_LOCAL_M...

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print spooler failed to create a symbolic link between HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Print\\Printers and HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers. Error param1. This only affects older applications, but is probably a sign that the system itself is in a poor condition or that the print spooler does not have the proper registry permissions.

Message #

The print spooler failed to create a symbolic link between HKEY_LOCAL_MACHINE\\System\\CurrentControlSet\\Control\\Print\\Printers and HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Print\\Printers. Error %1. This only affects older applications, but is probably a sign that the system itself is in a poor condition or that the print spooler does not have the proper registry permissions.

Fields #

NameDescription
param1 UnicodeString

Event ID 350: Document param1 failed to print and was deleted because of corruption in the spooled file.

#
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

Document param1 failed to print and was deleted because of corruption in the spooled file. The associated driver is: param2. Try printing the document again.

Message #

Document %1 failed to print and was deleted because of corruption in the spooled file. The associated driver is: %2. Try printing the document again.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 351: The attempt for param1 to use a Windows NT 4.

#
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

The attempt for param1 to use a Windows NT 4.0 (kernel mode) driver failed because this version of Windows does not support Windows NT 4.0 printer drivers. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

The attempt for %1 to use a Windows NT 4.0 (kernel mode) driver failed because this version of Windows does not support Windows NT 4.0 printer drivers. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString

Event ID 352: The priority of document param1, param2 owned by param3 was changed to param4 on param5.

#
Channel
Operational
Task
Printingadocument
Opcode
SpoolerOperationSucceeded

Description

The priority of document param1, param2 owned by param3 was changed to param4 on param5. Windows prints the document with the highest priority number before other print jobs with lower priority numbers. Documents that are currently printing are unaffected by changes in priority. No user action is required.

Message #

The priority of document %1, %2 owned by %3 was changed to %4 on %5. Windows prints the document with the highest priority number before other print jobs with lower priority numbers. Documents that are currently printing are unaffected by changes in priority. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString

Event ID 353: The document failed to print because the user did not have the necessary privileges.

#
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Event ID 354: param1 initialization failed at param2.

#
Channel
Admin
Level
Error
Task
Initializing
Opcode
SpoolerOperationFailed

Description

param1 initialization failed at param2. Error: Error. This can occur because of system instability or a lack of system resources.

Message #

%1 initialization failed at %2. Error: %3. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 354,
    "version": 0,
    "level": 2,
    "task": 36,
    "opcode": 12,
    "keywords": 9223372036854777856,
    "time_created": "2021-10-27T10:28:26.260460Z",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 1048,
      "thread_id": 3836
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "InitFailed": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "Param1": "\\\\fs03vuln\\Kiwi Legit Printer",
      "Param2": "\\\\fs03vuln\\print$\\W32X86\\3\\mimispool.dll",
      "Param3": "2. The system cannot find the file specified.\r\n"
    }
  }
}

Detection Patterns #

References #

Event ID 356: Failed to install or update driver param1 on cluster spooler resource param2.

#
Channel
Admin
Task
Addingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Failed to install or update driver param1 on cluster spooler resource param2. Win32 error: param3. The printer driver is different from the driver in use on other computers (nodes) in the cluster. This can occur because of a transient failure in replication between nodes.

Message #

Failed to install or update driver %1 on cluster spooler resource %2. Win32 error: %3. The printer driver is different from the driver in use on other computers (nodes) in the cluster. This can occur because of a transient failure in replication between nodes.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 359: The attempt to install printer param1 into an offline operating system image failed with Win32 error code param2.

#
Channel
Admin
Task
Addingaprinter
Opcode
SpoolerOperationFailed

Description

The attempt to install printer param1 into an offline operating system image failed with Win32 error code param2. This can occur if the printer driver requires user input or displays a user interface (UI) during installation.

Message #

The attempt to install printer %1 into an offline operating system image failed with Win32 error code %2. This can occur if the printer driver requires user input or displays a user interface (UI) during installation.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 360: Updating the color profile failed for printer param1 with Win32 error code param2.

#
Channel
Admin
Task
Settingprinterconfiguration
Opcode
SpoolerOperationFailed

Description

Updating the color profile failed for printer param1 with Win32 error code param2. The colors printed may not be correctly matched to the colors in the document being printed.

Message #

Updating the color profile failed for printer %1 with Win32 error code %2. The colors printed may not be correctly matched to the colors in the document being printed.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 361: Printer param1 failed to initialize its ports.

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

Printer param1 failed to initialize its ports. Win32 error: param2. This error usually occurs because of a problem with the port monitor. Try recreating the port using a standard TCP/IP printer port, if possible. This problem does not affect other printers.

Message #

Printer %1 failed to initialize its ports. Win32 error: %2. This error usually occurs because of a problem with the port monitor. Try recreating the port using a standard TCP/IP printer port, if possible. This problem does not affect other printers.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 362: The print spooler could not initialize because resolving the local machine name to IP addresses failed with error code param1.

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print spooler could not initialize because resolving the local machine name to IP addresses failed with error code param1. This may be a transient error. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Message #

The print spooler could not initialize because resolving the local machine name to IP addresses failed with error code %1. This may be a transient error. Try to manually restart the print spooler service (from Control Panel | Administrative Tools | Services or from an elevated command prompt running: net start spooler).

Fields #

NameDescription
param1 UnicodeString

Event ID 363: The print spooler param1 failed to start.

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print spooler param1 failed to start. To determine the cause of this error, examine the preceding events in the Event Log.

Message #

The print spooler %1 failed to start. To determine the cause of this error, examine the preceding events in the Event Log.

Fields #

NameDescription
param1 UnicodeString

Event ID 364: Windows could not load print processor param1 because EnumDatatypes did not return any data.

#
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Description

Windows could not load print processor param1 because EnumDatatypes did not return any data. Module: param2. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

Windows could not load print processor %1 because EnumDatatypes did not return any data. Module: %2. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 365: Windows could not load print processor param1 because EnumDatatypes failed.

#
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Description

Windows could not load print processor param1 because EnumDatatypes failed. Error code param2. Module: param3. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

Windows could not load print processor %1 because EnumDatatypes failed. Error code %2. Module: %3. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 366: The print server security descriptor for param1 is invalid.

#
Channel
Admin
Task
Initializingtheprintspooler
Opcode
SpoolerOperationFailed

Description

The print server security descriptor for param1 is invalid. The default print server security descriptor will be used.

Message #

The print server security descriptor for %1 is invalid. The default print server security descriptor will be used.

Fields #

NameDescription
param1 UnicodeString

Event ID 367: Windows could not initialize printer param1 because the print processor param2 could not be found.

#
Channel
Admin
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Description

Windows could not initialize printer param1 because the print processor param2 could not be found. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Message #

Windows could not initialize printer %1 because the print processor %2 could not be found. Please obtain and install a new version of the driver from the manufacturer (if available), or choose an alternate driver that works with this print device.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 368: The print spooler failed to verify printer driver package param1 for environment param2.

#
Channel
Operational
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Description

The print spooler failed to verify printer driver package param1 for environment param2. Win32 system error code param3. This can occur after an operating system upgrade or because of data loss on the hard drive. The print spooler will try to regenerate the driver information from the driver store, which is where drivers are saved before they are installed. No user action is required.

Message #

The print spooler failed to verify printer driver package %1 for environment %2. Win32 system error code %3. This can occur after an operating system upgrade or because of data loss on the hard drive. The print spooler will try to regenerate the driver information from the driver store, which is where drivers are saved before they are installed. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "event_id": 368,
    "level": "Error",
    "task": "Verifying or regenerating a print driver package",
    "opcode": "Spooler Operation Failed",
    "time_created": "2026-03-17T19:25:14.8986873+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-PrintService/Operational"
  },
  "event_data": {
    "Param2": "Windows x64",
    "Param1": "Remote Desktop Easy Print",
    "Param3": "2 (0x2)"
  }
}

Example keys not documented in the fields table: Param1, Param2, Param3

Event ID 369: The print spooler failed to verify printer driver package for environment param1.

#
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Description

The print spooler failed to verify printer driver package for environment param1. Win32 system error code param2. This can occur because of insufficient memory or other system failures. No user action is required.

Message #

The print spooler failed to verify printer driver package for environment %1. Win32 system error code %2. This can occur because of insufficient memory or other system failures. No user action is required.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 370: The print spooler failed to regenerate the printer driver information for driver param1 for environment param2.

#
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Description

The print spooler failed to regenerate the printer driver information for driver param1 for environment param2. Win32 system error code param3. This can occur after an operating system upgrade or because of data loss on the hard drive.

Message #

The print spooler failed to regenerate the printer driver information for driver %1 for environment %2. Win32 system error code %3. This can occur after an operating system upgrade or because of data loss on the hard drive.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 371: The print spooler failed to unshare printer param2 which is shared as param3.

#
Channel
Admin
Task
Unsharingaprinter
Opcode
SpoolerOperationFailed

Description

The print spooler failed to unshare printer param2 which is shared as param3. Error param1.

Message #

The print spooler failed to unshare printer %2 which is shared as %3. Error %1.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString

Event ID 372: The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, failed to print on printer PrintOnProcFailedEd.Param3.

#
Channel
Admin
Level
Error
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

The document PrintOnProcFailedEd.Param1, owned by PrintOnProcFailedEd.Param2, failed to print on printer PrintOnProcFailedEd.Param3. Try to print the document again, or restart the print spooler.

Message #

The document %1, owned by %2, failed to print on printer %3. Try to print the document again, or restart the print spooler. 
Data type: %4. Size of the spool file in bytes: %5. Number of bytes printed: %6. Total number of pages in the document: %7. Number of pages printed: %8. Client computer: %9. Win32 error code returned by the print processor: %10. %11

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UnicodeString
param4 UnicodeString
param5 UnicodeString
param6 UnicodeString
param7 UnicodeString
param8 UnicodeString
param9 UnicodeString
param10 UnicodeString
param11 UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 372,
    "version": 0,
    "level": 2,
    "task": 26,
    "opcode": 12,
    "keywords": 9223372036854777920,
    "time_created": "2026-03-13T18:26:33.122143+00:00",
    "event_record_id": 24,
    "correlation": {},
    "execution": {
      "process_id": 3664,
      "thread_id": 14104
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrintOnProcFailedEd": {
      "Param1": "Print Document",
      "Param2": "domainadmin",
      "Param3": "HP LaserJet Pro M148f-M149f 2 (redirected 1)",
      "Param4": "RAW",
      "Param5": "0",
      "Param6": "0",
      "Param7": "0",
      "Param8": "0",
      "Param9": "\\\\LAB-DC01",
      "Param10": "2152796161",
      "Param11": null
    }
  },
  "message": ""
}

Event ID 373: The spooler has detected that a component has an unusually large number of open Graphical Device Interface (GDI) objects.

#
Channel
Admin
Task
Printingadocument
Opcode
SpoolerOperationFailed

Description

The spooler has detected that a component has an unusually large number of open Graphical Device Interface (GDI) objects. As a result, some enhanced metafile (EMF) print jobs might not print until the spooler is restarted.

Message #

The spooler has detected that a component has an unusually large number of open Graphical Device Interface (GDI) objects. As a result, some enhanced metafile (EMF) print jobs might not print until the spooler is restarted.

Event ID 502: The print spooler failed to get the computer name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The print spooler failed to get the computer name. Error Error. This can occur due to system instability or a lack of system resources.

Message #

The print spooler failed to get the computer name. Error %2. This can occur due to system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 503: The system failed to initialize the local print provider: Error Error.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The system failed to initialize the local print provider: Error Error. This can occur because of system instability or a lack of system resources.

Message #

The system failed to initialize the local print provider: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 504: Failed to initialize the router work crew: Error Error.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to initialize the router work crew: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to initialize the router work crew: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 505: Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to create Phase2Init event in WaitForSpoolerInitialization: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to create Phase2Init event in WaitForSpoolerInitialization: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 507: The system failed to initialize the name cache: Error Error.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The system failed to initialize the name cache: Error Error. This can occur because of system instability or a lack of system resources.

Message #

The system failed to initialize the name cache: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 508: Failed to initialize the router cache: Error Error.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Failed to initialize the router cache: Error Error. This can occur because of system instability or a lack of system resources.

Message #

Failed to initialize the router cache: Error %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 509: The print spooler cannot start because the PrinterBusEnumerator could not start.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

The print spooler cannot start because the PrinterBusEnumerator could not start. Error code Error. This can occur because of system instability or a lack of system resources.

Message #

The print spooler cannot start because the PrinterBusEnumerator could not start. Error code %2. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 510: InitializeProvider cannot allocate memory for Name.

#
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

InitializeProvider cannot allocate memory for Name. This can occur because of system instability or a lack of system resources.

Message #

InitializeProvider cannot allocate memory for %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 511: The print spooler failed to load print provider Name.

#
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

The print spooler failed to load print provider Name. This can occur because of system instability or a lack of system resources.

Message #

The print spooler failed to load print provider %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 512: InitializePrintProvider failed for provider Name.

#
Channel
Admin
Task
Initializingaprintprovider
Opcode
SpoolerOperationFailed

Description

InitializePrintProvider failed for provider Name. This can occur because of system instability or a lack of system resources.

Message #

InitializePrintProvider failed for provider %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 513: Group Policy was unable to add per computer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to add per computer connection Name. Error code Error. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Message #

Group Policy was unable to add per computer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 514: Group Policy was unable to delete per computer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to delete per computer connection Name. Error Error. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Message #

Group Policy was unable to delete per computer connection %1. Error %2. This can occur if the name of the printer connection is incorrect, or if the print spooler cannot contact the print server.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 515: Group Policy was unable to delete per computer printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to delete per computer printer connection Name. Error Error. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Message #

Group Policy was unable to delete per computer printer connection %1. Error %2. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 516: Group Policy was unable to deploy per computer printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to deploy per computer printer connection Name. Error Error. The printer connection is not available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Message #

Group Policy was unable to deploy per computer printer connection %1. Error %2. The printer connection is not available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 517: Group Policy was unable to update per computer printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to update per computer printer connection Name. Error code Error. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Message #

Group Policy was unable to update per computer printer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 518: Group Policy was unable to delete the per user printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to delete the per user printer connection Name. Error code Error. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Message #

Group Policy was unable to delete the per user printer connection %1. Error code %2. The printer connection is still available to users on this computer. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry deleting the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 519: Group Policy was unable to deploy per user printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to deploy per user printer connection Name. Error code Error. The printer connection is not available to the users on this computer to which the Group Policy object applies. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Message #

Group Policy was unable to deploy per user printer connection %1. Error code %2. The printer connection is not available to the users on this computer to which the Group Policy object applies. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry adding the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 520: Group Policy was unable to update per user printer connection Name.

#
Channel
Admin
Task
Routingprintspoolercommand(s)
Opcode
SpoolerOperationFailed

Description

Group Policy was unable to update per user printer connection Name. Error code Error. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Message #

Group Policy was unable to update per user printer connection %1. Error code %2. This can occur if the name of the printer connection is incorrect, if there is a Group Policy problem, or if the print spooler cannot contact the print server. Group Policy will periodically retry updating the printer connection.

Fields #

NameDescription
Name UnicodeString
Error HexInt32

Event ID 600: The print spooler failed to import the printer driver that was downloaded from DriverSource into the driver store for driver Driver.

#
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to import the printer driver that was downloaded from DriverSource into the driver store for driver Driver. Error code= Error. This can occur if there is a problem with the driver or the digital signature of the driver.

Message #

The print spooler failed to import the printer driver that was downloaded from %1 into the driver store for driver %2. Error code= %3. This can occur if there is a problem with the driver or the digital signature of the driver.

Fields #

NameDescription
DriverSource UnicodeString
Driver UnicodeString
Error UnicodeString

Event ID 601: The print spooler failed to download and import the printer driver from DriverSource into the driver store for driver Driver.

#
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to download and import the printer driver from DriverSource into the driver store for driver Driver. Error code= Error.

Message #

The print spooler failed to download and import the printer driver from %1 into the driver store for driver %2. Error code= %3.

Fields #

NameDescription
DriverSource UnicodeString
Driver UnicodeString
Error UnicodeString

Event ID 602: The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey1\RegistryKey2.

#
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey1\RegistryKey2. This can occur if the key name or values are malformed or missing.

Message #

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key %1\%2. This can occur if the key name or values are malformed or missing.

Fields #

NameDescription
RegistryKey1 UnicodeString
RegistryKey2 UnicodeString

Event ID 603: The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey.

#
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key RegistryKey. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Message #

The print spooler failed to reopen an existing printer connection because it could not read the configuration information from the registry key %1. The print spooler could not open the registry key. This can occur if the registry key is corrupt or missing, or if the registry recently became unavailable.

Fields #

NameDescription
RegistryKey UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "event_id": 603,
    "level": "Error",
    "task": "Client-side rendering",
    "opcode": "Spooler Operation Failed",
    "time_created": "2026-03-18T22:31:39.5383820+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-PrintService/Operational"
  },
  "event_data": {
    "RegistryKey": "S-1-5-21-1006758700-2167138679-1475694448-1000\\Printers\\Connections"
  }
}

Event ID 604: The print spooler encountered an unknown driver type while saving Name cache information.

#
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler encountered an unknown driver type while saving Name cache information. This can occur because of a protocol or network error.

Message #

The print spooler encountered an unknown driver type while saving %1 cache information. This can occur because of a protocol or network error.

Fields #

NameDescription
Name UnicodeString

Event ID 701: The print filter pipeline host cannot initialize with the Component Object Model (COM) system.

#
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host cannot initialize with the Component Object Model (COM) system. Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host cannot initialize with the Component Object Model (COM) system. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 702: The print filter pipeline host is shutting down due to the following error: Error HResult.

#
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host is shutting down due to the following error: Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host is shutting down due to the following error: Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 703: The print filter pipeline host is shutting down due to an error in signaling the Component Object Model (COM) proxy in the spooler.

#
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host is shutting down due to an error in signaling the Component Object Model (COM) proxy in the spooler. Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host is shutting down due to an error in signaling the Component Object Model (COM) proxy in the spooler. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 704: The print filter pipeline host is shutting down because the query interface for ISignal in the Component Object Model (COM) proxy in the spooler fa...

#
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

The print filter pipeline host is shutting down because the query interface for ISignal in the Component Object Model (COM) proxy in the spooler failed. Error HResult. This can occur because of system instability or a lack of system resources.

Message #

The print filter pipeline host is shutting down because the query interface for ISignal in the Component Object Model (COM) proxy in the spooler failed. Error %1. This can occur because of system instability or a lack of system resources.

Fields #

NameDescription
HResult HexInt32

Event ID 800: Spooling job JobDiag.JobId.

#
Channel
Operational
Level
Informational
Task
Printjobdiagnostics
Opcode
Start

Message #

Spooling job %1.

Fields #

NameDescription
JobId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 800,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 1,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:11.317144+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 10520
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "JobDiag": {
      "JobId": 2
    }
  },
  "message": ""
}

Event ID 801: Printing job JobDiag.JobId.

#
Channel
Operational
Level
Informational
Task
Printjobdiagnostics

Message #

Printing job %1.

Fields #

NameDescription
JobId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 801,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 0,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:11.789801+00:00",
    "event_record_id": 3,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "JobDiag": {
      "JobId": 2
    }
  },
  "message": ""
}

Event ID 802: Deleting job DeleteJobDiag.JobId.

#
Channel
Operational
Level
Informational
Task
Printjobdiagnostics
Opcode
Stop

Message #

Deleting job %1.

Fields #

NameDescription
JobId UInt32
JobSize UInt32
DataType UInt32
Pages UInt32
PagesPerSide UInt32
FilesOpened Int16
JobSizeHigh UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 802,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 2,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:33.325147+00:00",
    "event_record_id": 9,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "DeleteJobDiag": {
      "JobId": 2,
      "JobSize": 53408,
      "DataType": 1,
      "Pages": 1,
      "PagesPerSide": 0,
      "FilesOpened": 3,
      "JobSizeHigh": 0
    }
  },
  "message": ""
}

Event ID 805: Rendering job RenderJobDiag.JobId.

#
Channel
Operational
Level
Informational
Task
Printjobdiagnostics

Message #

Rendering job %1.

Fields #

NameDescription
JobId UInt32
GdiJobSize UInt32
ICMMethod UInt32
Color Int16
XRes Int16
YRes Int16
Quality Int16
Copies Int16
TTOption Int16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 805,
    "version": 0,
    "level": 4,
    "task": 43,
    "opcode": 0,
    "keywords": 4612811918334230528,
    "time_created": "2026-03-13T20:25:33.323370+00:00",
    "event_record_id": 8,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "RenderJobDiag": {
      "JobId": 2,
      "GdiJobSize": 53408,
      "ICMMethod": 0,
      "Color": 2,
      "XRes": 600,
      "YRes": 600,
      "Quality": 600,
      "Copies": 1,
      "TTOption": 0
    }
  },
  "message": ""
}

References #

Event ID 806: Pausing job JobId.

#
Channel
Debug
Task
Printjobdiagnostics

Message #

Pausing job %1.

Fields #

NameDescription
JobId UInt32

Event ID 807: Resuming job JobId.

#
Channel
Debug
Task
Printjobdiagnostics

Message #

Resuming job %1.

Fields #

NameDescription
JobId UInt32

Event ID 808: The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode.

#
Channel
Admin
Level
Error
Task
Initializing
Opcode
SpoolerOperationFailed

Description

The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to load a plug-in module %1, error code %2. See the event user data for context information.

Fields #

NameDescriptionRules
PluginDllName UnicodeString1 detection rule
ErrorCode HexInt324 detection rules
Context Int16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 808,
    "version": 0,
    "level": 2,
    "task": 36,
    "opcode": 12,
    "keywords": 9223372036854906880,
    "time_created": "2021-10-27T10:28:26.322960Z",
    "event_record_id": 12,
    "correlation": {
      "#attributes": {
        "ActivityID": "8811EC75-6F9C-4103-BB8A-EEED31FA139D"
      }
    },
    "execution": {
      "process_id": 1656,
      "thread_id": 1572
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "FS03.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "LoadPluginFailed": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PluginDllName": "C:\\Windows\\system32\\spool\\DRIVERS\\x64\\3mimispool.dll",
      "ErrorCode": "0x7e",
      "Context": 110
    }
  }
}

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCodeeq0x45a2 rulessigma, splunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

References #

Event ID 809: The print spooler failed to recursively delete the directory DirectoryName, error code WaitForReboot.

#
Channel
Operational
Task
Deletingadirectory
Opcode
SpoolerOperationFailed

Description

The print spooler failed to recursively delete the directory DirectoryName, error code WaitForReboot. See the event user data for context information.

Message #

The print spooler failed to recursively delete the directory %1, error code %2. See the event user data for context information.

Fields #

NameDescription
DirectoryName UnicodeString
WaitForReboot HexInt32
ErrorCode HexInt32
Context Int16

Event ID 810: The print spooler failed to delete the directory DirectoryName and the contained files, error code WaitForReboot.

#
Channel
Operational
Task
Deletingadirectory
Opcode
SpoolerOperationFailed

Description

The print spooler failed to delete the directory DirectoryName and the contained files, error code WaitForReboot. See the event user data for context information.

Message #

The print spooler failed to delete the directory %1 and the contained files, error code %2. See the event user data for context information.

Fields #

NameDescription
DirectoryName UnicodeString
WaitForReboot HexInt32
ErrorCode HexInt32
Context Int16

Event ID 811: The print spooler failed to move the file Source to Destination, error code ErrorCode.

#
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to move the file Source to Destination, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to move the file %1 to %2, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

Event ID 812: The print spooler failed to delete the file Source, error code ErrorCode.

#
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to delete the file Source, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to delete the file %1, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

References #

Event ID 813: The print spooler failed to copy the file Source to Destination, error code ErrorCode.

#
Channel
Operational
Task
Executingafileoperation
Opcode
SpoolerOperationFailed

Description

The print spooler failed to copy the file Source to Destination, error code ErrorCode. See the event user data for context information.

Message #

The print spooler failed to copy the file %1 to %2, error code %4. See the event user data for context information.

Fields #

NameDescription
Source UnicodeString
Destination UnicodeString
Flags HexInt32
ErrorCode HexInt32
Context Int16

Event ID 814: The print spooler failed to install the print processor Processor Environment Path, error code ErrorCode.

#
Channel
Operational
Task
Initializingaprintprocessor
Opcode
SpoolerOperationFailed

Message #

The print spooler failed to install the print processor %1 %2 %3, error code %4.

Fields #

NameDescription
Processor UnicodeString
Environment UnicodeString
Path UnicodeString
ErrorCode HexInt32

Event ID 815: The print spooler service failed to register the RPC server protocol sequence ProtocolSequence, error code ErrorCode.

#
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The print spooler service failed to register the RPC server protocol sequence ProtocolSequence, error code ErrorCode. See the event user data for context information.

Message #

The print spooler service failed to register the RPC server protocol sequence %1, error code %3. See the event user data for context information.

Fields #

NameDescription
ProtocolSequence UnicodeString
EndPoint UnicodeString
ErrorCode HexInt32
Context Int16

Event ID 816: The print spooler service detected an invalid RPC protocol sequence ValidatedProtocolSequence, expecting ExpectedProtocolSequence, error code ErrorCode.

#
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Message #

The print spooler service detected an invalid RPC protocol sequence %1, expecting %2, error code %3.

Fields #

NameDescription
ValidatedProtocolSequence UnicodeString
ExpectedProtocolSequence UnicodeString
ErrorCode HexInt32

Event ID 817: The RPC end-point policy for the print spooler service is disabled.

#
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The RPC end-point policy for the print spooler service is disabled. See the event user data for context information.

Message #

The RPC end-point policy for the print spooler service is disabled. See the event user data for context information.

Fields #

NameDescription
WindowsStarterEdition HexInt32
SuiteStorageServer HexInt32
SystemPrintingDisabled HexInt32
SuiteBlade HexInt32
SuiteEmbeddedRestricted HexInt32
SuiteComputerServer HexInt32

Event ID 818: The print spooler RPC server failed to start, error code ErrorCode.

#
Channel
Operational
Task
EnablingspoolerRPCendpoints
Opcode
SpoolerOperationFailed

Description

The print spooler RPC server failed to start, error code ErrorCode. See the event user data for context information.

Message #

The print spooler RPC server failed to start, error code %1. See the event user data for context information.

Fields #

NameDescription
ErrorCode HexInt32
Context Int16

Event ID 819: Client Side Rendering is currently disabled by policy (Policy).

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerTrace

Message #

Client Side Rendering is currently disabled by policy (%1).

Fields #

NameDescription
Policy UnicodeString

Event ID 820: Client side rendering to PrintProcessor failed, error code ErrorCode.

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Client side rendering to PrintProcessor failed, error code ErrorCode. The print spooler service will retry server side rendering. See the event user data for more context information.

Message #

Client side rendering to %1 failed, error code %4. The print spooler service will retry server side rendering. See the event user data for more context information.

Fields #

NameDescription
PrintProcessor UnicodeString
Connection UnicodeString
IsXpsPrinter HexInt32
ErrorCode HexInt32

Event ID 821: The print spooler Client Side Rendering is attempting to render the job JobId on the server (Server Side Rendering), status Status.

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerTrace

Description

The print spooler Client Side Rendering is attempting to render the job JobId on the server (Server Side Rendering), status Status. See the event user data for context information.

Message #

The print spooler Client Side Rendering is attempting to render the job %1 on the server (Server Side Rendering), status %3. See the event user data for context information.

Fields #

NameDescription
JobId UInt32
Level HexInt32
Status HexInt32NTSTATUS reference

Event ID 822: Unknown print processor (LocalPrintProcessor) or invalid data type (LocalDataType), error ErrorCode, Client Side Rendering is disabled.

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Unknown print processor (LocalPrintProcessor) or invalid data type (LocalDataType), error ErrorCode, Client Side Rendering is disabled. See the event user data for more context information.

Message #

Unknown print processor (%1) or invalid data type (%4), error %7, Client Side Rendering is disabled. See the event user data for more context information.

Fields #

NameDescription
LocalPrintProcessor UnicodeString
RemotePrintProcessor UnicodeString
DefaultPrintProcessor UnicodeString
LocalDataType UnicodeString
RemoteDataType UnicodeString
DefaultDataType UnicodeString
ErrorCode HexInt32

Event ID 823: The default printer was changed to NewDefaultPrinter.

#
Channel
Admin
Level
Informational
Task
Changingthedefaultprinter
Opcode
SpoolerOperationSucceeded

Description

The default printer was changed to NewDefaultPrinter. See the event user data for context information.

Message #

The default printer was changed to %3. See the event user data for context information.

Fields #

NameDescription
DefaultPrinterSelectedBySpooler UInt32
OldDefaultPrinter UnicodeString
NewDefaultPrinter UnicodeString
Status HexInt32NTSTATUS reference
Module UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 823,
    "version": 0,
    "level": 4,
    "task": 49,
    "opcode": 11,
    "keywords": 9223372036854906880,
    "time_created": "2021-10-27T10:09:16.280929Z",
    "event_record_id": 4,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4012
    },
    "channel": "Microsoft-Windows-PrintService/Admin",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-21-4230534742-2542757381-3142984815-1111"
    }
  },
  "user_data": {
    "ChangingDefaultPrinter": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "DefaultPrinterSelectedBySpooler": 1,
      "OldDefaultPrinter": "-",
      "NewDefaultPrinter": "Kiwi Legit Printer",
      "Status": "0x0",
      "Module": "spoolsv.exe"
    }
  }
}

References #

Event ID 824: A fatal error occurred while printing job DocumentName, id JobId on the print queue PrintQueue.

#
Channel
Operational
Task
Executingprintfiltersinthespoolerpipeline
Opcode
SpoolerOperationFailed

Description

A fatal error occurred while printing job DocumentName, id JobId on the print queue PrintQueue. The print filter pipeline process was terminated. Error information: ErrorInfo.

Message #

A fatal error occurred while printing job %1, id %2 on the print queue %3. The print filter pipeline process was terminated. Error information: %4.

Fields #

NameDescription
DocumentName UnicodeString
JobId UInt32
PrintQueue UnicodeString
ErrorInfo UnicodeString

Event ID 825: Client side rendering to PrintProcessor failed, error code ErrorCode.

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationFailed

Description

Client side rendering to PrintProcessor failed, error code ErrorCode. The print spooler service will not retry server side rendering. See the event user data for more context information.

Message #

Client side rendering to %1 failed, error code %4. The print spooler service will not retry server side rendering. See the event user data for more context information.

Fields #

NameDescription
PrintProcessor UnicodeString
Connection UnicodeString
IsXpsPrinter HexInt32
ErrorCode HexInt32

Event ID 826: Force Client Side Rendering policy was successfully set on printer PrinterName, path PrinterPath, port PortName.

#
Channel
Operational
Task
ClientSideRenderingrevertingtoServerSideRendering
Opcode
SpoolerOperationSucceeded

Message #

Force Client Side Rendering policy was successfully set on printer %1, path %2, port %3.

Fields #

NameDescription
PrinterName UnicodeString
PrinterPath UnicodeString
PortName UnicodeString

Event ID 827: The specified print queue QueueName is invalid.

#
Channel
Operational
Task
ExecutingXPSPrintAPIcalls
Opcode
XPSPrintAPIfailure

Message #

The specified print queue %1 is invalid.

Fields #

NameDescription
QueueName UnicodeString

Event ID 828: The print job JobId failed with error code ErrorCode.

#
Channel
Operational
Task
ExecutingXPSPrintAPIcalls
Opcode
XPSPrintAPIfailure

Message #

The print job %1 failed with error code %2.

Fields #

NameDescription
JobId UInt32
ErrorCode HexInt32

Event ID 829: XPS API call Name (Context) started.

#
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Start

Message #

XPS API call %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 830: XPS API call Name (Context) ended, status StatusCode.

#
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Stop

Message #

XPS API call %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 831: XPS API dependency Name (Context) started.

#
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Start

Message #

XPS API dependency %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 832: XPS API dependency Name (Context) ended, status StatusCode.

#
Channel
Debug
Task
XPSPrintAPIperformancetracking
Opcode
Stop

Message #

XPS API dependency %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 833: Print spooler operation Name (Context) started.

#
Channel
Debug
Task
Generalprintspoolerperformancetracking
Opcode
Start

Message #

Print spooler operation %1 (%2) started.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 834: Print spooler operation Name (Context) ended, status StatusCode.

#
Channel
Debug
Task
Generalprintspoolerperformancetracking
Opcode
Stop

Message #

Print spooler operation %1 (%2) ended, status %3.

Fields #

NameDescription
Name UnicodeString
Context UnicodeString
StatusCode HexInt32NTSTATUS reference

Event ID 842: The print job PrintDriverSandboxJobPrintProc.JobId was sent through the print processor PrintDriverSandboxJobPrintProc.Processor on printer PrintDriverSandboxJobPrintProc.Printer, driver PrintDrive...

#
Channel
Operational
Level
Informational
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

The print job JobId was sent through the print processor Processor on printer Printer, driver Driver, in the isolation mode IsolationMode (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox). Win32 error code returned by the print processor: Error.

Message #

The print job %1 was sent through the print processor %2 on printer %3, driver %4, in the isolation mode %5 (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox). Win32 error code returned by the print processor: %6.

Fields #

NameDescription
JobId UInt32
Processor UnicodeString
Printer UnicodeString
Driver UnicodeString
IsolationMode UInt32
Error HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 842,
    "version": 0,
    "level": 4,
    "task": 50,
    "opcode": 11,
    "keywords": 4611686018427650048,
    "time_created": "2026-03-13T20:25:33.321078+00:00",
    "event_record_id": 7,
    "correlation": {},
    "execution": {
      "process_id": 3692,
      "thread_id": 11700
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "user_data": {
    "PrintDriverSandboxJobPrintProc": {
      "JobId": 2,
      "Processor": "MS_XPS_PROC",
      "Printer": "TestPrinter_EventGen",
      "Driver": "Microsoft Print To PDF",
      "IsolationMode": 0,
      "ErrorCode": "0x0"
    }
  },
  "message": ""
}

References #

Event ID 843: The print spooler service recorded SucceededRpcCalls successful and FailedRpcCalls failed RPC requests for all active print driver sandbox hosts.

#
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Message #

The print spooler service recorded %1 successful and %2 failed RPC requests for all active print driver sandbox hosts.

Fields #

NameDescription
SucceededRpcCalls UInt32
FailedRpcCalls UInt32

Event ID 844: The print spooler selected the isolation mode IsolationMode (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for prin...

#
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

The print spooler selected the isolation mode IsolationMode (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for printer Printer, printer driver Driver.

Message #

The print spooler selected the isolation mode %1 (0 - loaded in the spooler, 1 - loaded in shared sandbox, 2 - loaded in isolated sandbox) for printer %2, printer driver %3.

Fields #

NameDescription
IsolationMode UInt32
Printer UnicodeString
Driver UnicodeString

Event ID 845: Attempted to load module Module for printer Printer, printer driver Driver.

#
Channel
Debug
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

Attempted to load module Module for printer Printer, printer driver Driver. Win32 error code Error.

Message #

Attempted to load module %1 for printer %2, printer driver %3. Win32 error code %4.

Fields #

NameDescription
Module UnicodeString
Printer UnicodeString
Driver UnicodeString
Error HexInt32

Event ID 846: Cached printer PrinterName has been scavenged and deleted.

#
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationSucceeded

Description

Cached printer PrinterName has been scavenged and deleted. This printer's age (PrinterAge seconds) has surpassed the expiry age of ExpiryAge seconds.

Message #

Cached printer %1 has been scavenged and deleted. This printer's age (%2 seconds) has surpassed the expiry age of %3 seconds.

Fields #

NameDescription
PrinterName UnicodeString
PrinterAge UInt32
ExpiryAge UInt32

Event ID 847: Cached printer PrinterName has been scheduled for deletion due to a logon scavenging operation.

#
Channel
Operational
Task
Client_siderendering
Opcode
SpoolerOperationSucceeded

Description

Cached printer PrinterName has been scheduled for deletion due to a logon scavenging operation. This printer is no longer referenced in the registry.

Message #

Cached printer %1 has been scheduled for deletion due to a logon scavenging operation. This printer is no longer referenced in the registry.

Fields #

NameDescription
PrinterName UnicodeString

Event ID 848: Printer PrinterName was shared by the print spooler as ShareName.

#
Channel
Operational
Level
Informational
Task
Sharingaprinter
Opcode
SpoolerOperationSucceeded

Message #

Printer %1 was shared by the print spooler as %2.

Fields #

NameDescription
PrinterName UnicodeString
ShareName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 848,
    "version": 0,
    "level": 4,
    "task": 30,
    "opcode": 11,
    "keywords": 4611686018427387936,
    "time_created": "2021-10-27T10:14:27.466200Z",
    "event_record_id": 154,
    "correlation": {},
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterSharing": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PrinterName": "Kiwi Legit Printer",
      "ShareName": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 849: Printer PrinterName shared as ShareName was unshared by the print spooler.

#
Channel
Operational
Level
Informational
Task
Unsharingaprinter
Opcode
SpoolerOperationSucceeded

Message #

Printer %1 shared as %2 was unshared by the print spooler.

Fields #

NameDescription
PrinterName UnicodeString
ShareName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PrintService",
    "guid": "747EF6FD-E535-4D16-B510-42C90F6873A1",
    "event_source_name": "",
    "event_id": 849,
    "version": 0,
    "level": 4,
    "task": 31,
    "opcode": 11,
    "keywords": 4611686018427387936,
    "time_created": "2021-10-27T10:14:21.369976Z",
    "event_record_id": 151,
    "correlation": {
      "#attributes": {
        "ActivityID": "C43202E9-CB0F-0000-D030-32C40FCBD701"
      }
    },
    "execution": {
      "process_id": 2552,
      "thread_id": 4028
    },
    "channel": "Microsoft-Windows-PrintService/Operational",
    "computer": "fs03vuln.offsec.lan",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "PrinterSharing": {
      "#attributes": {
        "xmlns": "http://manifests.microsoft.com/win/2005/08/windows/printing/spooler/core/events"
      },
      "PrinterName": "Kiwi Legit Printer",
      "ShareName": "Kiwi Legit Printer"
    }
  }
}

References #

Event ID 850: The print spooler called the function Function in print driver module Driver.

#
Channel
Operational
Task
Printdriveroperation
Opcode
SpoolerOperationFailed

Description

The print spooler called the function Function in print driver module Driver. This call initialized the Component Object Model (COM) system without properly un-initializing it.

Message #

The print spooler called the function %2 in print driver module %1. This call initialized the Component Object Model (COM) system without properly un-initializing it.

Fields #

NameDescription
Driver UnicodeString
Function UnicodeString

Event ID 851: Point and Print not allowed by policy for queue PrintQueue.

#
Channel
Operational
Task
Addingaprinterconnection
Opcode
SpoolerOperationFailed

Description

Point and Print not allowed by policy for queue PrintQueue. Cannot make a Point and Print connection to this queue. Error Error.

Message #

Point and Print not allowed by policy for queue %1. Cannot make a Point and Print connection to this queue. Error %2.

Fields #

NameDescription
PrintQueue UnicodeString
Error HexInt32

Event ID 852: Driver OriginalDriver could not be installed for printer connection PrinterName.

#
Channel
Admin
Task
Installingaprinterdriver
Opcode
SpoolerOperationFailed

Description

Driver OriginalDriver could not be installed for printer connection PrinterName. The print system selected the replacement driver NewDriver for the printer connection. No user action is required.

Message #

Driver %1 could not be installed for printer connection %3. The print system selected the replacement driver %2 for the printer connection. No user action is required.

Fields #

NameDescription
OriginalDriver UnicodeString
NewDriver UnicodeString
PrinterName UnicodeString

Event ID 853: Print Client Side Rendering synchronization for print job cache completed with code Error for printer PrinterName.

#
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

Print Client Side Rendering synchronization for print job cache completed with code %1 for printer %2.

Fields #

NameDescription
Error HexInt32
PrinterName UnicodeString

Event ID 854: Print Client Side Rendering synchronization for printer information cache completed with code Error for printer PrinterName.

#
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

Print Client Side Rendering synchronization for printer information cache completed with code %1 for printer %2.

Fields #

NameDescription
Error HexInt32
PrinterName UnicodeString

Event ID 855: OpenPrinter cache entry added for printer PrinterName with access code AccessCode.

#
Channel
Debug
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Message #

OpenPrinter cache entry added for printer %1 with access code %2.

Fields #

NameDescription
PrinterName UnicodeString
AccessCode UInt32

Event ID 856: Connection 'ConnectionName' has been reconfigured for normal operation because branch office printing has been disabled.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because branch office printing has been disabled.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 857: Connection 'ConnectionName' has been reconfigured for normal operation because the queue is incompatible with branch office printing.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the queue is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 858: Connection 'ConnectionName' has been reconfigured for normal operation because the queue has been configured for Server Side Rendering.

#
Channel
Admin
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the queue has been configured for Server Side Rendering. To re-enable Branch Office Printing, enable the 'Render Jobs On Client' setting on the server queue.

Message #

Connection '%1' has been reconfigured for normal operation because the queue has been configured for Server Side Rendering. To re-enable Branch Office Printing, enable the 'Render Jobs On Client' setting on the server queue.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 859: Connection 'ConnectionName' has been reconfigured for normal operation because the client is incompatible with branch office printing.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the client is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 860: Connection 'ConnectionName' has been reconfigured for normal operation because the server is incompatible with branch office printing.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the server is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 861: Connection 'ConnectionName' has been reconfigured for normal operation because the remote port is incompatible with branch office printing.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation because the remote port is incompatible with branch office printing.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 862: Connection 'ConnectionName' has been reconfigured for normal operation because the 'Keep Printed Jobs' setting is enabled on the queue.

#
Channel
Admin
Task
Connectionreconfigured
Opcode
SpoolerTrace

Description

Connection 'ConnectionName' has been reconfigured for normal operation because the 'Keep Printed Jobs' setting is enabled on the queue. To re-enable Branch Office Printing, disable the 'Keep Printed Jobs' setting on the server queue.

Message #

Connection '%1' has been reconfigured for normal operation because the 'Keep Printed Jobs' setting is enabled on the queue. To re-enable Branch Office Printing, disable the 'Keep Printed Jobs' setting on the server queue.

Fields #

NameDescription
ConnectionName UnicodeString

Event ID 863: Connection 'ConnectionName' has been reconfigured for normal operation due to an internal error, Error.

#
Channel
Operational
Task
Connectionreconfigured
Opcode
SpoolerTrace

Message #

Connection '%1' has been reconfigured for normal operation due to an internal error, %2.

Fields #

NameDescription
ConnectionName UnicodeString
Error HexInt32

Event ID 864: The Windows Fax and Scan servicing operation failed, HRESULT HResult.

#
Channel
Operational
Task
ServicingWindowsFaxandScan
Opcode
SpoolerOperationFailed

Message #

The Windows Fax and Scan servicing operation failed, HRESULT %1.

Fields #

NameDescription
HResult HexInt32

Event ID 865: There were Failures print job failures out of Jobs jobs sent to printer 'PrinterName' using driver 'DriverName'.

#
Channel
Admin
Task
Isolatingprinterdriversandotherplug_ins
Opcode
SpoolerOperationSucceeded

Description

There were Failures print job failures out of Jobs jobs sent to printer 'PrinterName' using driver 'DriverName'. The printer driver isolation setting was updated to load the printer driver inside the print spooler process. No user action is required.

Message #

There were %1 print job failures out of %2 jobs sent to printer '%3' using driver '%4'. The printer driver isolation setting was updated to load the printer driver inside the print spooler process. No user action is required.

Fields #

NameDescription
Failures UInt32
Jobs UInt32
PrinterName UnicodeString
DriverName UnicodeString

Event ID 866: The print spooler failed to create a Plug and Play printer device object for the printer 'PrinterName'.

#
Channel
Admin
Task
CreatingaPlugandPlaydeviceobjectinstanceforaprinter
Opcode
SpoolerOperationFailed

Description

The print spooler failed to create a Plug and Play printer device object for the printer 'PrinterName'. Print object instance identifier 'DeviceObjectInstanceIdentifier'. Error code HResultErrorCode. This printer will not be fully functional until the print spooler service is restarted and the Plug and Play printer device object is successfully created.

Message #

The print spooler failed to create a Plug and Play printer device object for the printer '%1'. Print object instance identifier '%2'. Error code %3. This printer will not be fully functional until the print spooler service is restarted and the Plug and Play printer device object is successfully created.

Fields #

NameDescription
PrinterName UnicodeString
DeviceObjectInstanceIdentifier UnicodeString
HResultErrorCode HexInt32

Event ID 867: The WS-Print Port Monitor failed to initialize correctly.

#
Channel
Admin
Task
InitializingtheWS_PrintPortMonitor
Opcode
SpoolerOperationFailed

Description

The WS-Print Port Monitor failed to initialize correctly. Creating the Device Association listener failed with the following error code: HResultErrorCode.

Message #

The WS-Print Port Monitor failed to initialize correctly. Creating the Device Association listener failed with the following error code: %1.

Fields #

NameDescription
HResultErrorCode HexInt32

Event ID 868: The Offline EventLog on machine 'MachineName' exceeded the allow maximum size.

#
Channel
Admin
Task
BOPEventOfflineArchiveFull
Opcode
SpoolerTrace

Description

The Offline EventLog on machine 'MachineName' exceeded the allow maximum size. Some job events may have been lost.

Message #

The Offline EventLog on machine '%1' exceeded the allow maximum size. Some job events may have been lost.

Fields #

NameDescription
MachineName UnicodeString

Event ID 869: In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code ErrorCode.

#
Channel
Admin
Task
Verifyingorregeneratingaprintdriverpackage
Opcode
SpoolerOperationFailed

Description

In VALIDATINGDRVINFO, Adding printer driver ObjectName failed, error code ErrorCode. See the event user data for context information. Driver has no valid catalog.

Message #

In VALIDATINGDRVINFO, Adding printer driver %3 failed, error code %2. See the event user data for context information. Driver has no valid catalog

Fields #

NameDescription
Label UnicodeString
ErrorCode HexInt32
ObjectName UnicodeString

Event ID 870: The print spooler failed to download package for driver Driver.

#
Channel
Admin
Task
Client_siderendering
Opcode
SpoolerOperationFailed

Description

The print spooler failed to download package for driver Driver. Error code= Error. Blocking driver as there could be a possibility of potential tampering.

Message #

The print spooler failed to download package for driver %1. Error code= %2. Blocking driver as there could be a possibility of potential tampering.

Fields #

NameDescription
Driver UnicodeString
Error UnicodeString

Event ID 871: The current print job was rejected due to Device Control Print Restrictions.

#
Channel
Admin
Task
DeviceControlPrinting
Opcode
SpoolerOperationFailed

Description

The current print job was rejected due to Device Control Print Restrictions. Rejection Reason: RestrictionReason, Printer: PrinterName, Job or Document Name: JobOrDocumentName, User Name: UserName, Port Name: PortName.

Message #

The current print job was rejected due to Device Control Print Restrictions. Rejection Reason: %1, Printer: %2, Job or Document Name: %3, User Name: %4, Port Name: %5

Fields #

NameDescription
RestrictionReason UnicodeString
PrinterName UnicodeString
JobOrDocumentName UnicodeString
UserName UnicodeString
PortName UnicodeString

Event ID 1111: Driver <DriverName> required for printer <PrinterName> is unknown.

#
Channel
Operational

Event ID 4098: The computer <ComputerName or IP> preference item in the '{GUID}' Group Policy object did not apply because it failed with error code '0x80070bcb The specified printer driver was not found on the s...

#
Channel
Operational

Event ID 4909: Print Service event 4909 (manifest stub).

#
Channel
Operational

Detection Patterns #

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCodeeq0x45a1 rulesplunk

Event ID 8192: The user <UserName> preference item in the '{GUID}' Group Policy object did not apply because it failed with error code '0x80070bcb The specified printer driver was not found on the system and need...

#
Channel
Operational

Provenance

ETW provider GUID 747ef6fd-e535-4d16-b510-42c90f6873a1

Defined in ntprint.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB