Microsoft-Windows-Push-To-Install-Service
6 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 6001 | Function Error Code: Source Function: Error_Code Source: Message (ErrorCode). | Operational | N |
| 6002 | Source Exception Details: LineNumber Function: Message Source: Exception_Details … | Operational | N |
| 6003 | Message Error Code: Error Code Function: Function Source: Source (Line Number). | Operational | Y |
| 6004 | Message Error Code: Error Code Function: Function Source: Source (Line Number). | Operational | Y |
| 6005 | Function Error Code: Source Function: Error_Code Source: Message (ErrorCode). | Operational | N |
| 6006 | Process Name: Process Name. | Operational | Y |
Event ID 6001: Function Error Code: Source Function: Error_Code Source: Message (ErrorCode).
#Event ID 6002: Source Exception Details: LineNumber Function: Message Source: Exception_Details (Function).
#Event ID 6003: Message Error Code: Error Code Function: Function Source: Source (Line Number).
#Description
Message Error Code: Error Code Function: Function Source: Source (Line Number)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Function AnsiString | |
Error Code | |
Source AnsiString | |
Line Number | |
ErrorCode | |
LineNumber |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Push-To-Install-Service",
"guid": "{3A718A68-6974-4075-ABD3-E8243CAEF398}",
"event_source_name": "",
"event_id": 6003,
"version": 0,
"level": 3,
"task": 6003,
"opcode": 0,
"keywords": -9223372036854775807,
"time_created": "2026-06-13T08:22:02.4005110+00:00",
"event_record_id": 32920,
"correlation": {},
"execution": {
"process_id": 3404,
"thread_id": 2008
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Message": "",
"Function": "",
"Error Code": "-2147012889",
"Source": "onecoreuap\\enduser\\winstore\\servicescommon\\lib\\httpforservices.cpp",
"Line Number": "675"
},
"message": "\r\nError Code: Unknown HResult Error code: 0x80072ee7\r\nFunction: \r\nSource: onecoreuap\\enduser\\winstore\\servicescommon\\lib\\httpforservices.cpp (675)"
}
Event ID 6004: Message Error Code: Error Code Function: Function Source: Source (Line Number).
#Description
Message Error Code: Error Code Function: Function Source: Source (Line Number)
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Function AnsiString | |
Error Code | |
Source AnsiString | |
Line Number | |
ErrorCode | |
LineNumber |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Push-To-Install-Service",
"guid": "{3A718A68-6974-4075-ABD3-E8243CAEF398}",
"event_source_name": "",
"event_id": 6004,
"version": 0,
"level": 4,
"task": 6004,
"opcode": 0,
"keywords": -9223372036854775807,
"time_created": "2026-06-13T08:22:02.4037714+00:00",
"event_record_id": 32921,
"correlation": {},
"execution": {
"process_id": 3404,
"thread_id": 2008
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Message": "onecoreuap\\enduser\\winstore\\servicescommon\\lib\\httpforservices.cpp(675)\\pushtoinstall.dll!00007FFE017EA229: (caller: 00007FFE017EA75F) Exception(1) tid(7d8) 80072EE7 ",
"Function": "",
"Error Code": "-2147012889",
"Source": "onecoreuap\\enduser\\winstore\\pushtoinstall\\lib\\service.cpp",
"Line Number": "294"
},
"message": "onecoreuap\\enduser\\winstore\\servicescommon\\lib\\httpforservices.cpp(675)\\pushtoinstall.dll!00007FFE017EA229: (caller: 00007FFE017EA75F) Exception(1) tid(7d8) 80072EE7 \r\nError Code: Unknown HResult Error code: 0x80072ee7\r\nFunction: \r\nSource: onecoreuap\\enduser\\winstore\\pushtoinstall\\lib\\service.cpp (294)"
}
Event ID 6005: Function Error Code: Source Function: Error_Code Source: Message (ErrorCode).
#Event ID 6006: Process Name: Process Name.
#Description
Process Name: Process Name.
Message #
Fields #
| Name | Description |
|---|---|
Process Name | |
Module Name | |
Build Name | |
ProcessName | |
ModuleName | |
BuildName |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Push-To-Install-Service",
"guid": "{3A718A68-6974-4075-ABD3-E8243CAEF398}",
"event_source_name": "",
"event_id": 6006,
"version": 0,
"level": 4,
"task": 6006,
"opcode": 0,
"keywords": -9223372036854775806,
"time_created": "2026-06-13T08:22:02.0433197+00:00",
"event_record_id": 32915,
"correlation": {},
"execution": {
"process_id": 3404,
"thread_id": 7688
},
"channel": "Microsoft-Windows-Store/Operational",
"computer": "telemetry-W11-a.cell-a.ludus.domain",
"security": {
"user_id": "S-1-5-18"
}
},
"event_data": {
"Process Name": "C:\\WINDOWS\\System32\\svchost.exe",
"Module Name": "c:\\windows\\system32\\pushtoinstall.dll",
"Build Name": "26100.1.amd64fre.ge_release.240331-1435"
},
"message": "Process Name: C:\\WINDOWS\\System32\\svchost.exe\r\nModule Name: c:\\windows\\system32\\pushtoinstall.dll\r\nBuild: 26100.1.amd64fre.ge_release.240331-1435\r\n"
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 3a718a68-6974-4075-abd3-e8243caef398
Defined in PushToInstall.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3037, captured 2026-06-02