Microsoft-Windows-PushNotifications-Platform

EventTitleChannelSampleRule
1The Windows Push Notification Platform has encountered an error in File: …DebugNN
2The Windows Push Notification Platform has started loading.DebugNN
3The Windows Push Notification Platform has been unloaded.DebugNN
4The Windows Push Notification Platform has been disabled due to Group Policy …DebugNN
5The Windows Push Notification Platform has been loaded.DebugNN
6The Windows Push Notification Platform has started unloading.DebugNN
7The Windows Push Notification Platform has launched as Type with Privilege …DebugNN
8The Windows Push Notification Platform is switching into new NewPrivilege …DebugNN
9The Windows Push Notification Platform has switched with error code Error, and …DebugNN
10The Windows Push Notification Platform has started defragging storage.DebugNN
11The Windows Push Notification Platform has finished defragging storage.DebugNN
12The Windows Push Notification Platform has determined new maximum number of …DebugNN
13The Windows Push Notification Platform has expanded its persistent header …DebugNN
14The Windows Push Notification Platform has switched to using an expanded …DebugNN
15The Windows Push Notification Platform has started loading file data: count …DebugNN
16The Windows Push Notification Platform has created a new memory-mapped file.DebugNN
17The Windows Push Notification Platform has detected that its persistent buffer …DebugNN
18The Windows Push Notification Platform has registered inbox applications.DebugNN
19The Windows Push Notification Platform has encountered an error in File: …OperationalYN
20The Windows Push Notification Platform has encountered error ErrorCode opening …OperationalNN
21The Windows Push Notification Platform has started processing tile update …DebugNN
22The Windows Push Notification Platform has stopped processing tile update …DebugNN
23The Windows Push Notification Platform is setting URI Uri with recurrence …DebugNN
24The Windows Push Notification Platform has initiated a WNS connection.DebugNN
25The Windows Push Notification Platform is disconnecting from WNS.DebugNN
26ThreadPool: [Name] (InstanceId) has been scheduled.DebugNN
27ThreadPool: [Name] (InstanceId) finished with error code [ErrorCode].DebugNN
28ResourceManager has recevied a message: code [MessageCode].DebugYN
29The Windows Push Notification Platform has started scavenging the image cache.DebugNN
30The Windows Push Notification Platform has finished scavenging the image cache.DebugNN
31The Windows Push Notification Platform has TotalSize entries in the image cache.DebugNN
32The Device has entered battery saver state: BATTERY_SAVINGS_ONDebugNN
33The Device has exited battery saver state: BATTERY_SAVINGS_OFFDebugNN
34The DcpProvider has been loaded successfully.DebugNN
35WNS Platform finished TraceLogging registration with code ErrorCode.DebugNN
36WNS Connection Provider finished TraceLogging registration with code ErrorCode.DebugNN
37The Windows Push Notification Platform is required to connect on startup, …OperationalYN
38PDC intialization finished with ErrorCode: ErrorCode.DebugNN
39PDC unintialization finished with ErrorCode: ErrorCode.DebugNN
40PDC activation finished with ErrorCode: ErrorCode, PdcType: PdcType, …DebugNN
41PDC deactivation finished with ErrorCode: ErrorCode, PdcType: PdcType, …DebugNN
42Cloud Notifications must be enabled in GP and MDM to receive push notifications.OperationalYN
1000A Connection Provider is registered with Windows Push Notification Platform …DebugNN
1001The following Connection Provider is enabled with the parameters: CLSID [CLSID] …DebugNN
1002The Connection Provider with CLSID CLSID was instantiated with the following …DebugNN
1003Connect request sent to the Connection Provider.OperationalNN
1004Disconnect request sent the Connection Provider.OperationalNN
1005The Connection Provider status changed to Status.OperationalYN
1006Sending a channel request to the Connection Provider with parameters: …OperationalNN
1007The Connection Provider completed the channel request for transaction id …OperationalNN
1008Sending a channel revoke request to the Connection Provider for channel id …OperationalNN
1010group received for ChannelId action and AppUserModelId NotificationType with …OperationalNN
1011Sending a request to the Connection Provider to renew a channel with parameters: …OperationalNN
1012Setting batching configuration to the following state: BatchingState.DebugNN
1013Configuring notification delivery for AppUserModelId AppUserModelId with channel …OperationalNN
1014The Resource Manager was notified that display state changed to DisplayStatus.DebugNN
1015Configuring notification policy for NotificationType [NotificationType] Enabled …OperationalNN
1016The Resource Manager was notified of an update to the network cost.DebugNN
1017The Resource Manager was notified of an update to the data plan.DebugNN
1018The Resource Manager reset the Mobile Broadband Usage statistics.DebugNN
1019The Resource Manager was notified that user session state changed to Status.DebugNN
1020The Connection Provider status changed to a failure state: {Status}.OperationalNN
1021The Connection Manager has failed to connect: ErrorCode.OperationalNN
1022ConnectWork is requesting ConnectionManager to connect.OperationalYN
1023No internet connection available, WorkItemName is queued for next network status …OperationalYN
1024Internet connection status changed to IsConnected, submitting pending workitems: …OperationalYN
1025A Power event was fired: PowerEventType [PowerEventType] IsEnabled [Enabled].OperationalYN
1100Connecting to the Windows Push Notification Service.DebugNN
1101Windows Push Notification Service connection result: Error.DebugNN
1102Sending Channel WNP Protocol command: Sending_Channel_WNP_Protocol_command …DebugNN
1103Channel WNP Protocol command tracking information: TransactionId [TransactionId] …DebugNN
1104Sending Revoke WNP Protocol command: Sending_Revoke_WNP_Protocol_command …DebugNN
1105Sending Block/Unblock WNP Protocol command: ChannelId [ChannelId] …DebugNN
1106Sending Options WNP Protocol command: Sending_Options_WNP_Protocol_command …DebugNN
1107WNP Protocol command response: WNP_Protocol_command_response [TrID] TrID [Error] …DebugNN
1108WNP Protocol delivered notification: WNP_Protocol_delivered_notification …DebugNN
1109Disconnecting from the Windows Push Notification Service.DebugNN
1110Windows Push Notification Service disconnection result: Error.DebugNN
1112Requesting Device Compact Ticket for the ConnectionType.DebugNN
1113Device Compact Ticket request completed with Device Id DeviceId for the …OperationalYN
1114Sending Filter/Unfilter WNP Protocol command: NotificationType …DebugNN
1115Sending Ack WNP Protocol command: Sending_Ack_WNP_Protocol_command [MsgId] …DebugNN
1116Device Compact Ticket request failed with error Error for the ConnectionType.OperationalNN
1117Windows Push Notification Service was disconnected due to error: Error and will …OperationalYN
1118Sending Challenge Response WNP Protocol command: Nonce [Nonce] Response …DebugNN
1201WNP Transport Layer Connect call initiated for the ConnectionType.DebugNN
1202WNP Transport Layer Connect call completed for the ConnectionType.DebugNN
1203WNP Transport Layer SendCommand call initiated for TrID CommandTrid on the …DebugNN
1204WNP Transport Layer SendCommand call completed for TrID CommandTrid on the …DebugNN
1205WNP Transport Layer Disconnect call initiated for the ConnectionType.OperationalYN
1206WNP Transport Layer Disconnect call completed for the ConnectionType.OperationalYN
1207WNP Transport Layer resolving DNS initiated for host HostName for the …OperationalYN
1208WNP Transport Layer resolving DNS completed for the ConnectionType with code …OperationalYN
1209WNP Transport Layer retrieving proxy information initiated for the …OperationalNN
1210WNP Transport Layer retrieving proxy information completed for the …OperationalNN
1211WNP Transport Layer initial server connection initiated to server HostName on …OperationalYN
1212WNP Transport Layer initial server connection completed to server HostName on …OperationalYN
1213WNP Transport Layer proxy connection initiated for the ConnectionType.OperationalYN
1214WNP Transport Layer proxy connection completed to server HostName for the …OperationalNN
1215WNP Transport Layer proxy negotiation initiated for the ConnectionType.OperationalYN
1216WNP Transport Layer proxy negotiation completed for the ConnectionType.OperationalYN
1217WNP Transport Layer TLS negotiation initiated for the ConnectionType.OperationalYN
1218WNP Transport Layer TLS negotiation completed for the ConnectionType with code …OperationalYN
1219WNP Transport Layer sent Bytes bytes on the ConnectionType.DebugNN
1220WNP Transport Layer received Bytes bytes on the ConnectionType.DebugNN
1223WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: …OperationalYN
1224WNP Transport Layer received Bytes bytes of payload: Payload.OperationalNN
1225WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, …OperationalYN
1226WNP Transport Layer received proxy server response for the ConnectionType of …OperationalNN
1227WNP Transport Layer received command when disconnected with Verb: Verb, Trid: …OperationalNN
1228WNP Keep Alive Detector received OnConnected event from the test connection with …DebugNN
1229WNP Keep Alive Detector received OnReconnecting event from the test connection …DebugNN
1230WNP Keep Alive Detector received OnDisconnected event from the test connection …DebugNN
1231WNP Keep Alive Detector received KA hint from server: ServerKaHint seconds.DebugNN
1232WNP Keep Alive Detector updating cached Ka time with value: KaValue seconds; …DebugNN
1233Fast reconnect triggered for previous WNS session (SessionId) on the …OperationalNN
1234ConnectionType TCP connection established over ProtocolType.DebugNN
1235WNP Keep Alive Detector resetting Idle Failed Interval.DebugNN
1236WNP Keep Alive Detector incrementing Idle-Succeeded count to IdleSucceededCount.DebugNN
1237WNP Keep Alive Detector encountered failed idle interval of IdleFailedInterval …DebugNN
1238WNP Keep Alive Detector starting Test ConnectionOperationalYN
1239WNP Keep Alive Detector starting KA measurement with value: KaValue seconds; …OperationalYN
1240WNP Keep Alive Detector stopping KA measurementOperationalYN
1241WNP Keep Alive Detector lost network over ProtocolType.OperationalNN
1242WNP Transport Layer received Power Management event with type …OperationalNN
1243WNP Transport Layer received Power Management event with type …DebugNN
1244Connection to the Windows Push Notification Service (HostName:Port) failed …OperationalNN
1245Connection to the Windows Push Notification Service (HostName:Port) failed …AdminNN
1246WNP Transport Layer was disconnected from the Windows Push Notification Service …OperationalYN
1247Connection to the Windows Push Notification Service failed because of a failure …AdminNN
1248Connection to the Windows Push Notification Service (HostName:Port) failed …AdminNN
1249StopKeepAliveMeasurement was called from message loop.DebugNN
1250The KA measurement was never started.DebugNN
1251The test connection disconnect failed synchronously due to error: Error.DebugNN
1252The KA value has converged.OperationalYN
1253The test connection will be disconnected due to idle failure.DebugNN
1254WNP Transport Layer for ConnectionType detected preferred interface change.OperationalYN
1255WNP Transport Layer for ConnectionType reacting to preferred interface change, …OperationalNN
1256WNP Transport Layer for ConnectionType reacting to preferred interface change, …OperationalNN
1257WNP Transport Layer for ConnectionType called InitializeSecurityContext and got …OperationalYN
1258WNP Transport Layer for ConnectionType received asynchronous connection error …OperationalYN
1259WNP Transport Layer for the Data Connection sending out of band keep alive (PNG) …OperationalNN
1260WNP Transport Layer for the Data Connection received cellular state change WNF …OperationalNN
1261Adding new user to the Windows Push Notification Service.OperationalYN
1262Removing existing user from the Windows Push Notification Service.OperationalYN
1263Replacing existing user from the Windows Push Notification Service.OperationalNN
1264Adding new user to the Windows Push Notification Service completed.OperationalYN
1265Removing existing user from the Windows Push Notification Service completed.OperationalYN
1266Replacing existing user from the Windows Push Notification Service completed.OperationalNN
1267WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: …OperationalYN
1268WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, …OperationalYN
1300Started tracking connection establishment performance.DebugNN
1301Finished tracking connection establishment performance.DebugNN
1302PDC Intialization finished with error code [ErrorCode] and Initialization Count …DebugNN
1303PDC Unintialization finished with error code [ErrorCode] and Initialization …DebugNN
1304PDC Activation finished with error code [ErrorCode], Initialization Count is …DebugNN
1305PDC Deactivation finished with error code [ErrorCode], Initialization Count is …DebugNN
1306WNP protocol state for Device Id DeviceId is State State for the ConnectionType.DebugNN
1307WNP Connector state for Connector Id ConnectorId is State State for the …DebugNN
1308WNP Transport Layer for Connector Id ConnectorId requested NCSI probe for the …DebugNN
1309WNP Transport Layer for Auth Manager requested NCSI probe for the ConnectionType …DebugNN
1310WNP Transport Layer for ConnectionType detected first fallback interface change.OperationalYN
1311WNP Transport Layer for ConnectionType detected second fallback interface …OperationalNN
1312WNP Transport Layer detected low WIFI signal quality level (value = …OperationalNN
1313WNP Transport Layer detected a significant drop in WIFI signal quality (delta = …OperationalNN
1314WNP Transport Layer detected a change in WIFI interface availability (event …OperationalNN
1315WNP Transport Layer detected a change in WIFI interface connectivity status …OperationalNN
1316WNS delivered notification dropped in CP: ErrorCode [ErrorCode] Namespace …OperationalNN
1317NotificationType associated with ChannelId ChannelId and AppUserModelId …OperationalNN
1318WNP Protocol delivered notification: Namespace [Namespace] UserId [UserId] …OperationalNN
2000The Windows Push Notification Platform has received a channel request with the …DebugNN
2001The channel table has added a valid channel mapping: ChannelId [ChannelId] …OperationalYN
2002The channel table has removed a channel mapping: ChannelId [ChannelId] …OperationalNN
2003The channel table has updated a channel mapping: ChannelId [ChannelId] …OperationalYN
2004The channel table has returned a cached channel mapping: ChannelId [ChannelId] …DebugNN
2005A cloud notification callback was added: AppUserModelId [AppUserModelId].DebugNN
2006A cloud notification callback was removed: AppUserModelId [AppUserModelId].DebugNN
2007A cloud notification could not be delivered to a callback due to an error: …DebugNN
2008A cloud notification was delivered to a callback: AppUserModelId …DebugNN
2009A local notification was submitted to threadpool: AppUserModelId …DebugNN
2010A clear tile message was received from an application endpoint: AppUserModelId …DebugNN
2011A clear badge message was received from an application endpoint: AppUserModelId …DebugNN
2012A cancel toast message was received from an application endpoint: AppUserModelId …DebugNN
2013A clear toast message was received from an application endpoint: AppUserModelId …DebugNN
2014A remove toast message was received from an application endpoint: AppUserModelId …DebugNN
2015A channel request failed due to an error: AppUserModelId [AppUserModelId] …DebugNN
2016A clear mixview message was received from an application endpoint: …DebugNN
2025A toast feedback callback was added: TrackingId [NotificationTrackingId].DebugNN
2026A toast feedback callback was removed: TrackingId [NotificationTrackingId].DebugNN
2027A toast feedback callback was invoked: TrackingId [NotificationTrackingId].DebugNN
2028A scheduled toast was added: PackageFullName [PackageFullName] AppUserModelID …DebugNN
2029A scheduled toast was removed: PackageFullName [PackageFullName] AppUserModelID …DebugNN
2030A scheduled toast is about to be raised: AppUserModelID [AppUserModelID] TimerId …DebugNN
2031A background task to application mapping has been added: AppUserModelID …DebugNN
2032A background task to application mapping has been removed: AppUserModelID …DebugNN
2033A raw notification has activated a background task: AppUserModelID …OperationalNN
2034A raw notification has activated a system task: AppUserModelID [AppUserModelID].DebugNN
2035A scheduled tile was added: PackageFullName [PackageFullName] AppUserModelID …DebugNN
2036A scheduled tile was removed: PackageFullName [PackageFullName] AppUserModelID …DebugNN
2037A scheduled tile is being raised: AppUserModelID [AppUserModelId] TimerId …DebugNN
2038A scheduled tile was removed because the number of scheduled tiles per app …DebugNN
2039A periodic update has been set: PackageFullName [PackageFullName] AppUserModelID …DebugNN
2040A periodic update has been reset: PackageFullName [PackageFullName] …DebugNN
2041A periodic update has started polling URL: AppUserModelID [AppUserModelId] …DebugNN
2042A periodic update has finished polling URL: AppUserModelID [AppUserModelId] …DebugNN
2043A periodic update has rejected polling URL because size of notification exceeded …DebugNN
2044A periodic update has rejected polling URL due to mobile broadband connection …DebugNN
2045A periodic update has failed polling URL.DebugNN
2046A background task application mapping entry has been removed: AppUserModelID …DebugNN
2047Notification API call for AppUserModelId [AppUserModelId] failed.DebugNN
2048A raw notification has failed to activate a background task: AppUserModelID …DebugNN
2049A periodic update has found HTTP Status Code rather than 200: AppUserModelID …DebugNN
2050A periodic update has failed polling URL because X-WNS-TAG header is invalid: …DebugNN
2051A periodic update has failed polling URL because X-WNS-EXPIRY header is invalid: …DebugNN
2052A periodic update of Type NotificationType for AppUserModelId AppUserModelID at …DebugNN
2053A periodic update has failed polling URL because X-WNS-GROUP header is invalid: …OperationalNN
2100A cloud notification was dropped because the following channel is not valid: …DebugNN
2101A notification was dropped because the expiration time was in the past: …DebugNN
2102A notification was dropped because of global settings: RequestFlags …DebugNN
2103A notification was dropped because cloud notifications are disabled globally: …DebugNN
2104A notification was dropped because of application settings: AppUserModelId …DebugNN
2105A notification was dropped because the application does not have the network …DebugNN
2106A notification was dropped because the application does not have the capability …DebugNN
2107A notification was dropped because the current network is costly: AppUserModelId …DebugNN
2108A notification was dropped because the mobile broadband cap has been reached: …DebugNN
2109Network traffic related to notifications was attributed to the following …DebugNN
2110A notification was dropped because cloud notifications are disabled for the …DebugNN
2111A notification was dropped because the application is not registered: …DebugNN
2112A NotificationType notification with trackingid TrackingId is getting posted for …DebugNN
2150An application setting was changed: AppUserModelId [AppUserModelId] SettingType …DebugNN
2151A group policy setting was changed.DebugNN
2152An application setting was queried: AppUserModelId [AppUserModelId] SettingType …DebugNN
2153A global setting was changed: SettingType [SettingType] Enabled [Enabled] …DebugNN
2154A global setting was queried: SettingType [SettingType] Enabled [Enabled] …DebugNN
2155The list of apps with capability: SettingType [SettingType] was requested.DebugNN
2156Callback registered for SettingType [SettingType] with Cookie Cookie [Cookie …DebugNN
2157Callback unregistered : Callback_unregistered [Cookie Value].DebugNN
2158End of clearing Tile Notification Queues and Image Cache.DebugNN
2159Mobile Broadband Tile Cap Queried: Mobile_Broadband_Tile_Cap_Queried [Cap Value …DebugNN
2160Mobile Broadband Tile Cap Changed: Mobile_Broadband_Tile_Cap_Changed [Cap Value …DebugNN
2161Mobile Broadband Tile Usage Queried: Mobile_Broadband_Tile_Usage_Queried [Usage …DebugNN
2162Mobile Broadband Reset Dates Queried.DebugNN
2163The list of apps with capability: SettingType [SettingType] in Package: …DebugNN
2164Start of clearing Tile Notification Queues and Image Cache.DebugNN
2165Mobile Broadband Cap Enforcement Callback invoked: Enabled [Enabled].DebugNN
2166Toasts have been Temporarily Suspended until WakeupTime [UTC FILETIME].DebugNN
2167Toast Temporary Suspend Time was queried: Is Suspended?DebugNN
2168Toast Wakeup Timer has fired.DebugNN
2169The list of Polling apps in Package: PackageFamilyName [PackageFamilyName] was …DebugNN
2170A Setting Sync was scheduled: PackageFamilyName [PackageFamilyName] CollectionId …DebugNN
2171A call to the settings endpoint happened to unblock all channels for all types.OperationalNN
2200A channel request was not allowed because of global settings: RequestFlags …DebugNN
2201A channel request was not allowed because the application does not have the …DebugNN
2202A NotificationType notification with NotificationTrackingId TrackingId was …DebugNN
2203A NotificationType notification with NotificationTrackingId TrackingId is being …DebugNN
2250Notification channels associated with a package are able to receive raw …DebugNN
2300The following application was added to the lock screen: PackageFullName …DebugNN
2301The following application was removed from the lock screen: PackageFullName …DebugNN
2400System application was registered with the following paramaeters: …DebugNN
2401System application was unregistered with the following parameters: …DebugNN
2402task_02402DebugNN
2403task_02403DebugNN
2404Phone VoIP application was registered with the following parameters: …DebugNN
2405Phone VoIP application was unregistered with the following parameters: …DebugNN
2406The Windows Push Notification Platform has received a phone legacy channel …DebugNN
2407PhoneLegacy push notification is being processed: ChannelId [ChannelId], …DebugNN
2408PhoneLegacy voip notification is being processed: ChannelId [ChannelId], …DebugNN
2409A connection status callback was added: AppUserModelId [AppUserModelId].DebugNN
2410A connection status callback was removed: AppUserModelId [AppUserModelId].DebugNN
2411A connection status callback was updated: AppUserModelId [AppUserModelId].DebugNN
2412A connection status was delivered to a callback: AppUserModelId [AppUserModelId] …DebugNN
2413An application was registered with the following parameters: PackageFullName …OperationalYN
2414An application resgistration was updated with the following parameters: …OperationalYN
2415An application was unregistered with the following parameters: AppUserModelId …OperationalYN
2416A local notification was received from AppUserModelId [AppUserModelId] with a …OperationalYN
2416A local notification was received from AppUserModelId [AppUserModelId] with a …OperationalYN
2417A local notification failed to be submitted to threadpool: ErrorCode [HResult]OperationalNN
2418A local notification was submitted to threadpool: AppUserModelId …OperationalYN
2418A local notification was submitted to threadpool: AppUserModelId …OperationalYN
2419A raw notification has activated a system task: AppUserModelID [AppUserModelID]OperationalNN
3000Tile session creation is requested for ProcessName endpoint Object.OperationalYN
3001Tile session creation is finished for ProcessName from endpoint Endpoint with …OperationalYN
3002Tile session SessionId is being updated.DebugNN
3003Tile session SessionId is updated with error code Error.DebugNN
3004Tile session SessionId is being closed.OperationalYN
3005Tile session SessionId is closed with error code Error.OperationalYN
3006Toast session creation is requested for ProcessName from endpoint Object.OperationalYN
3007Toast session creation is finished for ProcessName from endpoint Endpoint with …OperationalYN
3008Toast session SessionId is being closed.OperationalYN
3009Toast session SessionId is closed with error code Error.OperationalYN
3010Started tracking Notification Request performance.DebugNN
3011Finished tracking Notification Request performance.DebugNN
3012Toast with notification tracking id TrackingId is delivered to AppUserModelId on …DebugNN
3013NotificationType with notification tracking id TrackingId is delivered to …DebugNN
3014Tile queue entry is created for AppUserModelId.DebugNN
3015Tile notification id NotificationId for AppUserModelId is stored at QueueIndex …DebugNN
3016Tile notification id OverridingNotificationId overrided existing notification id …DebugNN
3017This is a verbose debug event that dumps Tile Queue information.DebugNN
3018Badge notification id TrackingId is stored for AppUserModelId.DebugNN
3019Tile image request RequestId has started.DebugNN
3020Tile image request RequestId has been canceled due to new request.DebugNN
3021Tile image request for notification NotificationId in AppUserModelId contains …DebugNN
3022Image download request is being processed for first time: resource id …DebugNN
3023Image download is complete for a single URL: notification id [NotificationId], …DebugNN
3024Image download is complete for all URL with notification id [NotificationId].DebugNN
3025Processing initial batch on Image request for toast: AppUserModelId …DebugNN
3026Processing Toast Image request URL: Resource Id [ResourceId], URL [URL].DebugNN
3027Scheduling Image Download Task: [Slot Index] SlotIndex, [Notification Id] …DebugNN
3028Completed Image Download Task: [Notification Id] NotificationId, [IsTile] …DebugNN
3029Download image has failed: [Notification Id] NotificationId [Tile] IsTile …DebugNN
3030Image resource is being processed.DebugNN
3031Image resource has been processed.DebugNN
3032Clearing all tile notifiction is being processed.DebugNN
3033Clearing all tile notifiction has been processed.DebugNN
3034Clearing all images is being processed.DebugNN
3035Clearing all images has been processed.DebugNN
3036Image Download Manager policy is changed to IDM_Enabled.DebugNN
3037Detail event for tile session SessionId update.DebugNN
3038Detail event at start of Notification Request performance tracking.DebugNN
3039Image Download Manager drop request due to newer request arrival.DebugNN
3040Downloading image has failed because protocol is not supported: URL [URL].DebugNN
3041Downloading image has failed because downloaded image it too big over maximum …DebugNN
3042Downloading image has failed because downloaded image is empty: URL [URL].DebugNN
3043The new tile notification was found to be a duplicate of a previous …DebugNN
3044The new badge notification was found to be a duplicate of a previous …DebugNN
3045Started tracking Toast Notification Request performance.DebugNN
3046Finished tracking Toast Notification Request performance.DebugNN
3047The new tile flyout notification was found to be a duplicate of a previous …DebugNN
3048Badge notification id TrackingId is stored for AppUserModelId.DebugNN
3049Endpoint Object is being cleanedup.OperationalYN
3050Toast notification id NotificationId for AppUserModelId is stored at QueueIndex …DebugNN
3051Toast notification id OverridingNotificationId overrided existing notification …DebugNN
3052Toast with notification tracking id TrackingId is being delivered to …OperationalYN
3053NotificationType with notification tracking id TrackingId is being delivered to …OperationalNN
3054Toast with notification tracking id TrackingId is canceled by AppUserModelId - …OperationalNN
3055Some toast notifications have been cleared - informed session SessionId.OperationalYN
3056NotificationType are being cleared for AppUserModelId - informed session …OperationalYN
3057Presentation Endpoint received a call to close session SessionId.OperationalYN
3058Presentation Endpoint ended a call to close session SessionId.OperationalYN
3100Started tracking Clear Toast Notification performance.DebugNN
3101Finished tracking Clear Toast Notification performance.DebugNN
3102Started tracking Clear Toast Notifications performance.DebugNN
3103Finished tracking Clear Toast Notifications performance.DebugNN
3104Toast with notification id [TrackingId] has expired and will be removed from the …DebugNN
3105Started tracking Remove Toast Notifications performance.DebugNN
3106Finished tracking Remove Toast Notifications performance.DebugNN
3107Processing of Push Notification has failed: ChannelId [ChannelId], …DebugNN
3108Started tracking Clear Toast Notification Rollover performance.DebugNN
3109Finished tracking Clear Toast Notification Rollover performance.DebugNN
3110Toast Notification Forwarding Global Settings: isFwToCdpEnabled = …OperationalNN
3111Start Toast Notification Forwarding activityOperationalNN
3112Stop Toast Notification Forwarding activityOperationalNN
3113Toast Notification Forwarding Local Settings: isDeveloperAppMirroringEnabled = …OperationalNN
3114Start Toast Notification Forwarding Do Forward To AFCOperationalNN
3115Stop Toast Notification Forwarding Do Forward To AFCOperationalNN
3116Start Toast Notification Forwarding Make Activity from NotificationOperationalNN
3117Stop Toast Notification Forwarding Make Activity from NotificationOperationalNN
3118Toast Notification Forwarding Finished Decorating PayloadOperationalNN
3119Toast Notification Forwarding Finished Loading Payload onto ActivityOperationalNN
3120Toast Notification Forwarding Finished setting attributes onto activityOperationalNN
3121Start Toast Notification Forwarding Asset ResolutionOperationalNN
3122Toast Notification Forwarding Asset Resolution SuccessfulOperationalNN
3123Toast Notification Forwarding Making Activity TrackingId = TrackingId …OperationalNN
3124Toast Notification Forwarding Published Activity with Result = ErrorCode.OperationalNN
3125VerboseLog.OperationalNN
3126Sync Dismiss: Dismiss Activities for App StartOperationalNN
3127Sync Dismiss: Dismiss Activities for App StopOperationalNN
3128Sync Dismiss: Dismiss Activities StartOperationalNN
3129Sync Dismiss: Dismiss Activities StopOperationalNN
3130Sync Dismiss: Dismiss Activities StartOperationalNN
3131Sync Dismiss: Dismiss Activities StopOperationalNN
3132Sync Dismiss: Remove Notification using Activity StartOperationalNN
3133Sync Dismiss: Remove Notification using Activity StopOperationalNN
3134Sync Dismiss: Get Activities StartOperationalNN
3135Sync Dismiss: Get Activities StopOperationalNN
3136Sync Dismiss: CDPGetPlatformDeviceId StartOperationalNN
3137Sync Dismiss: CDPGetPlatformDeviceId StopOperationalNN
3138VerboseLog.OperationalNN
3139Sync Dismiss Removed Activity with Result = ErrorCode.OperationalNN
3140Sync Dismiss Removed Notification with Result = ErrorCode.OperationalNN
3141SyncDismissRemoveNotificationUsingActivityParams: MatchOnNotificationId = …OperationalNN
3142Sync Dismiss: Matched Activity using Notification!OperationalNN
3143Sync Dismiss: Matched Notification using Activity!OperationalNN
3144Received WNF_CDP_CDPUSERSVC_READYOperationalNN
3145[Sqlite][Informational] Status: SqliteInformational_Status.DebugNN
3146[Sqlite][Warning] Status: SqliteWarning_Status.OperationalNN
3147[Sqlite][Error] Status: SqliteError_Status.OperationalNN
3148[Sqlite][Other] Status: SqliteOther_Status.DebugNN
3149Processing of Push Notification has succeeded: ChannelId [ChannelId], …DebugNN
3149Processing of Push Notification has succeeded: ChannelId [ChannelId], …OperationalNN
3150Processing of Local Notification has failed: NotificationType …OperationalNN
3151Processing of Local Notification has succeeded: NotificationType …Debug, OperationalNN
3152Processing of Push Notification has failed: ChannelId [ChannelId], …OperationalNN
3153Toast with notification tracking id TrackingId is delivered to AppUserModelId on …OperationalYN
3153Toast with notification tracking id TrackingId is delivered to AppUserModelId on …OperationalYN
3154Processing and publishing of Resume Notification has succeeded: TrackingId …DebugNN
3154Event ID 3154OperationalNN
3155Processing and publishing of Resume Notification has failed: TrackingId …OperationalNN
3155Event ID 3155OperationalNN
3156Processing of Resume Response has succeeded: TrackingId [TrackingId].DebugNN
3156Event ID 3156OperationalNN
3157Processing of Resume Response has failed: TrackingId [TrackingId], Location …OperationalNN
3157Event ID 3157OperationalNN
10000DebugTrace: DebugTrace.DebugNN

Event ID 1: The Windows Push Notification Platform has encountered an error in File: FileName, Function FunctionName, Line LineNumber, Error ErrorCode, ErrorMessage ErrorMessage.

#
Channel
Debug
Opcode
Info

Message #

The Windows Push Notification Platform has encountered an error in File: %1, Function %2, Line %3, Error %4, ErrorMessage %5.

Fields #

NameDescription
FileName UnicodeString
FunctionName UnicodeString
LineNumber Int32
ErrorCode UInt32
ErrorMessage UnicodeString

Event ID 2: The Windows Push Notification Platform has started loading.

#
Channel
Debug
Task
PlatformBootUp

Event ID 3: The Windows Push Notification Platform has been unloaded.

#
Channel
Debug
Task
PlatformShutdown

Event ID 4: The Windows Push Notification Platform has been disabled due to Group Policy settings.

#
Channel
Debug
Opcode
Info

Event ID 5: The Windows Push Notification Platform has been loaded.

#
Channel
Debug
Task
PlatformBootUp

Event ID 6: The Windows Push Notification Platform has started unloading.

#
Channel
Debug
Task
PlatformShutdown

Event ID 7: The Windows Push Notification Platform has launched as Type with Privilege privilege.

#
Channel
Debug
Opcode
Info

Message #

The Windows Push Notification Platform has launched as %1 with %2 privilege.

Fields #

NameDescription
Type UInt32
Privilege UInt32

Event ID 8: The Windows Push Notification Platform is switching into new NewPrivilege privilege.

#
Channel
Debug
Task
SwitchPrivilege
Opcode
Start

Message #

The Windows Push Notification Platform is switching into new %1 privilege.

Fields #

NameDescription
NewPrivilege UInt32

Event ID 9: The Windows Push Notification Platform has switched with error code Error, and current privilege is ResultedPrivilege.

#
Channel
Debug
Task
SwitchPrivilege
Opcode
Stop

Message #

The Windows Push Notification Platform has switched with error code %2, and current privilege is %1.

Fields #

NameDescription
ResultedPrivilege UInt32
Error Int32

Event ID 10: The Windows Push Notification Platform has started defragging storage.

#
Channel
Debug
Task
DefragFile
Opcode
Start

Event ID 11: The Windows Push Notification Platform has finished defragging storage.

#
Channel
Debug
Task
DefragFile
Opcode
Stop

Event ID 12: The Windows Push Notification Platform has determined new maximum number of applications MaximumApplication based on count of current applications CountApplication.

#
Channel
Debug
Opcode
Info

Description

The Windows Push Notification Platform has determined new maximum number of applications MaximumApplication based on count of current applications CountApplication. Old maximum number of applications is OldMaximumApplication.

Message #

The Windows Push Notification Platform has determined new maximum number of applications %2 based on count of current applications %1. Old maximum number of applications is %3.

Fields #

NameDescription
CountApplication UInt16
MaximumApplication UInt16
OldMaximumApplication UInt16

Event ID 13: The Windows Push Notification Platform has expanded its persistent header storage to accommodate NewMaximumApplication Applications.

#
Channel
Debug
Opcode
Info

Message #

The Windows Push Notification Platform has expanded its persistent header storage to accommodate %1 Applications.

Fields #

NameDescription
NewMaximumApplication UInt16

Event ID 14: The Windows Push Notification Platform has switched to using an expanded persistence buffer.

#
Channel
Debug
Opcode
Info

Event ID 15: The Windows Push Notification Platform has started loading file data: count applications CountApplication, count allocated entries CountAllocated, max count MaximumApplication.

#
Channel
Debug
Opcode
Info

Message #

The Windows Push Notification Platform has started loading file data: count applications %1, count allocated entries %2, max count %3.

Fields #

NameDescription
CountApplication UInt16
CountAllocated UInt16
MaximumApplication UInt16

Event ID 16: The Windows Push Notification Platform has created a new memory-mapped file.

#
Channel
Debug
Opcode
Info

Event ID 17: The Windows Push Notification Platform has detected that its persistent buffer is out of sync.

#
Channel
Debug
Opcode
Info

Event ID 18: The Windows Push Notification Platform has registered inbox applications.

#
Channel
Debug
Opcode
Info

Event ID 19: The Windows Push Notification Platform has encountered an error in File: FileName, Function FunctionName, Line LineNumber, Error ErrorCode, ErrorMessage ErrorMessage.

#
Channel
Operational
Level
Verbose
Opcode
Info

Message #

The Windows Push Notification Platform has encountered an error in File: %1, Function %2, Line %3, Error %4, ErrorMessage %5.

Fields #

NameDescription
FileName UnicodeStringThe Windows Push Notification Platform has encountered an error in File.
FunctionName UnicodeString
LineNumber Int32
ErrorCode UInt32
ErrorMessage

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 19,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854767616,
    "time_created": "2026-05-29T16:44:57.7229544+00:00",
    "event_record_id": 312,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 3628
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "FileName": "onecoreuap\\base\\diagnosis\\platform\\notifications\\platform\\endpoint\\backgroundapplicationpolicymanager.cpp",
    "FunctionName": "BackgroundApplicationPolicyManager::InitializeWnfCallbacks",
    "LineNumber": "162",
    "ErrorCode": "2147943568"
  },
  "message": "The Windows Push Notification Platform has encountered an error in file: onecoreuap\\base\\diagnosis\\platform\\notifications\\platform\\endpoint\\backgroundapplicationpolicymanager.cpp, function BackgroundApplicationPolicyManager::InitializeWnfCallbacks, line 162: 0x80070490."
}

Event ID 20: The Windows Push Notification Platform has encountered error ErrorCode opening file FilePath.

#
Channel
Operational
Opcode
Info

Message #

The Windows Push Notification Platform has encountered error %2 opening file %1.

Fields #

NameDescription
FilePath UnicodeString
ErrorCode UInt32

Event ID 21: The Windows Push Notification Platform has started processing tile update settings for CountInboxApps inbox and CountPreinstallApps preinstall apps.

#
Channel
Debug
Task
ProcessTileUpdateSettings
Opcode
Start

Message #

The Windows Push Notification Platform has started processing tile update settings for %1 inbox and %2 preinstall apps.

Fields #

NameDescription
CountInboxApps UInt32
CountPreinstallApps UInt32

Event ID 22: The Windows Push Notification Platform has stopped processing tile update settings.

#
Channel
Debug
Task
ProcessTileUpdateSettings
Opcode
Stop

Event ID 23: The Windows Push Notification Platform is setting URI Uri with recurrence WpnRecurrence for AppUserModelId AppUserModelId.

#
Channel
Debug
Task
ProcessTileUpdateSettings

Message #

The Windows Push Notification Platform is setting URI %2 with recurrence %3 for AppUserModelId %1.

Fields #

NameDescription
AppUserModelId UnicodeString
Uri UnicodeString
WpnRecurrence UInt32

Event ID 24: The Windows Push Notification Platform has initiated a WNS connection.

#
Channel
Debug
Task
PlatformBootUp

Event ID 25: The Windows Push Notification Platform is disconnecting from WNS.

#
Channel
Debug
Task
PlatformShutdown

Event ID 26: ThreadPool: [Name] (InstanceId) has been scheduled.

#
Channel
Debug
Opcode
Info

Message #

ThreadPool: [%1] (%2) has been scheduled.

Fields #

NameDescription
Name UnicodeString
InstanceId Pointer

Event ID 27: ThreadPool: [Name] (InstanceId) finished with error code [ErrorCode].

#
Channel
Debug
Opcode
Info

Message #

ThreadPool: [%1] (%2) finished with error code [%3]

Fields #

NameDescription
Name UnicodeString
InstanceId Pointer
ErrorCode Int32

Event ID 28: ResourceManager has recevied a message: code [MessageCode].

#
Channel
Debug
Level
Verbose
Opcode
Info

Message #

ResourceManager has recevied a message: code [%1]

Fields #

NameDescription
MessageCode UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-PushNotification-Platform/Debug",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 28,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4452,
      "thread_id": 5024
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:12:47.065Z",
    "version": 0
  },
  "event_data": {
    "MessageCode": 537
  },
  "message": ""
}

Event ID 29: The Windows Push Notification Platform has started scavenging the image cache.

#
Channel
Debug
Task
DefragFile
Opcode
Start

Event ID 30: The Windows Push Notification Platform has finished scavenging the image cache.

#
Channel
Debug
Task
DefragFile
Opcode
Stop

Event ID 31: The Windows Push Notification Platform has TotalSize entries in the image cache.

#
Channel
Debug
Opcode
Info

Message #

The Windows Push Notification Platform has %1 entries in the image cache.

Fields #

NameDescription
TotalSize UInt64

Event ID 32: The Device has entered battery saver state: BATTERY_SAVINGS_ON

#
Channel
Debug
Task
BatterySaver
Opcode
Start

Event ID 33: The Device has exited battery saver state: BATTERY_SAVINGS_OFF

#
Channel
Debug
Task
BatterySaver
Opcode
Stop

Event ID 34: The DcpProvider has been loaded successfully.

#
Channel
Debug
Opcode
Info

Event ID 35: WNS Platform finished TraceLogging registration with code ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNS Platform finished TraceLogging registration with code %1.

Fields #

NameDescription
ErrorCode Int32

Event ID 36: WNS Connection Provider finished TraceLogging registration with code ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNS Connection Provider finished TraceLogging registration with code %1.

Fields #

NameDescription
ErrorCode Int32

Event ID 37: The Windows Push Notification Platform is required to connect on startup, ValidChannelsExist : ChannelsExist.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

The Windows Push Notification Platform is required to connect on startup, ValidChannelsExist : %1.

Fields #

NameDescription
ChannelsExist BooleanThe Windows Push Notification Platform is required to connect on startup, ValidChannelsExist.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 37,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036896722944,
    "time_created": "2023-11-05T22:41:17.162599+00:00",
    "event_record_id": 2587,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 5040
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ChannelsExist": true
  },
  "message": ""
}

References #

Event ID 38: PDC intialization finished with ErrorCode: ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

PDC intialization finished with ErrorCode: %1.

Fields #

NameDescription
ErrorCode Int32

Event ID 39: PDC unintialization finished with ErrorCode: ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

PDC unintialization finished with ErrorCode: %1.

Fields #

NameDescription
ErrorCode Int32

Event ID 40: PDC activation finished with ErrorCode: ErrorCode, PdcType: PdcType, PdcScenario: PdcScenario, ScenarioData: [ScenarioData].

#
Channel
Debug
Opcode
Info

Message #

PDC activation finished with ErrorCode: %1, PdcType: %2, PdcScenario: %3, ScenarioData: [%4].

Fields #

NameDescription
ErrorCode Int32
PdcType UInt32
PdcScenario UInt32
ScenarioData UnicodeString

Event ID 41: PDC deactivation finished with ErrorCode: ErrorCode, PdcType: PdcType, PdcNetRef: PdcNetRefCount, PdcPlatRef: PdcPlatRefCount.

#
Channel
Debug
Opcode
Info

Message #

PDC deactivation finished with ErrorCode: %1, PdcType: %2, PdcNetRef: %3, PdcPlatRef: %4.

Fields #

NameDescription
ErrorCode Int32
PdcType UInt32
PdcNetRefCount Int64
PdcPlatRefCount Int64

Event ID 42: Cloud Notifications must be enabled in GP and MDM to receive push notifications.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

Cloud Notifications must be enabled in GP and MDM to receive push notifications. GroupPolicyValue: GroupPolicyValue, MDMPolicyValue: MDMPolicyValue.

Message #

Cloud Notifications must be enabled in GP and MDM to receive push notifications. GroupPolicyValue: %1, MDMPolicyValue: %2.

Fields #

NameDescription
GroupPolicyValue BooleanCloud Notifications must be enabled in GP and MDM to receive push notifications. GroupPolicyValue.
MDMPolicyValue Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 42,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036812828672,
    "time_created": "2026-05-29T16:33:58.0859355+00:00",
    "event_record_id": 319,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5428
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "GroupPolicyValue": "true",
    "MDMPolicyValue": "true"
  },
  "message": "Cloud Notifications must be enabled in GP and MDM to receive push notifications. GroupPolicyValue: true, MDMPolicyValue: true."
}

Event ID 1000: A Connection Provider is registered with Windows Push Notification Platform using the following parameters: CLSID [CLSID] Enabled [Enabled] Flags [CLSCTX Flags].

#
Channel
Debug
Opcode
Info

Message #

A Connection Provider is registered with Windows Push Notification Platform using the following parameters: %1 [CLSID] %2 [Enabled] %3 [CLSCTX Flags].

Fields #

NameDescription
CLSID GUID
Enabled Boolean
Flags UInt32

Event ID 1001: The following Connection Provider is enabled with the parameters: CLSID [CLSID] Flags [CLSCTX Flags].

#
Channel
Debug
Opcode
Info

Message #

The following Connection Provider is enabled with the parameters: %1 [CLSID] %2 [CLSCTX Flags].

Fields #

NameDescription
CLSID GUID
Flags UInt32
ErrorCode Int32

Event ID 1002: The Connection Provider with CLSID CLSID was instantiated with the following flags Flags and finished with ErrorCode ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

The Connection Provider with CLSID %1 was instantiated with the following flags %2 and finished with ErrorCode %3.

Fields #

NameDescription
CLSID GUID
Flags UInt32
ErrorCode Int32

Event ID 1003: Connect request sent to the Connection Provider.

#
Channel
Operational
Task
ConnectionEstablishment

Event ID 1004: Disconnect request sent the Connection Provider.

#
Channel
Operational
Opcode
Info

Event ID 1005: The Connection Provider status changed to Status.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment

Message #

The Connection Provider status changed to %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1005,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 0,
    "keywords": 9223372036963926272,
    "time_created": "2023-11-05T22:41:17.244262+00:00",
    "event_record_id": 2601,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 8072
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Status": 4
  },
  "message": ""
}

References #

Event ID 1006: Sending a channel request to the Connection Provider with parameters: PackageFullName [PackageFullName] Properties [Properties] Cookie [Cookie] TransactionId [TransactionId].

#
Channel
Operational
Opcode
Info

Message #

Sending a channel request to the Connection Provider with parameters: %1 [PackageFullName] %2 [Properties] %3 [Cookie] %4 [TransactionId].

Fields #

NameDescription
PackageFullName UnicodeString
Properties UInt32
Cookie UInt32
TransactionId Int32

Event ID 1007: The Connection Provider completed the channel request for transaction id TransactionId.

#
Channel
Operational
Opcode
Info

Description

The Connection Provider completed the channel request for transaction id TransactionId. ChannelId [ChannelId] ChannelUri [ChannelUri] Expiry [Expiry].

Message #

The Connection Provider completed the channel request for transaction id %1. %2 [ChannelId] %3 [ChannelUri] %4 [Expiry].

Fields #

NameDescription
TransactionId Int32
ChannelId UnicodeString
ChannelUri UnicodeString
Expiry Double

Event ID 1008: Sending a channel revoke request to the Connection Provider for channel id ChannelId.

#
Channel
Operational
Opcode
Info

Message #

Sending a channel revoke request to the Connection Provider for channel id %1.

Fields #

NameDescription
ChannelId UnicodeString

Event ID 1010: group received for ChannelId action and AppUserModelId NotificationType with TrackingId ChannelId, X-WNS-MSG-ID AppUserModelId, timestamp TrackingId and expiration MessageId tag: Timestamp, group: ...

#
Channel
Operational
Task
NewCloudNotificationArrival
Opcode
Start

Description

group received for ChannelId action and AppUserModelId NotificationType with TrackingId ChannelId, X-WNS-MSG-ID AppUserModelId, timestamp TrackingId and expiration MessageId tag: Timestamp, group: Expiry, action: Tag, bundle: count=Group;missed=Action;Id=OfflineCacheCount.

Message #

%1 received for ChannelId %2 and AppUserModelId %3 with TrackingId %4, X-WNS-MSG-ID %5, timestamp %6 and expiration %7 tag: %8, group: %9, action: %10, bundle: count=%11;missed=%12;Id=%13.

Fields #

NameDescription
NotificationType UInt32
ChannelId UnicodeString
AppUserModelId UnicodeString
TrackingId UInt32
MessageId UInt64
Timestamp Double
Expiry Double
Tag UnicodeString
Group UnicodeString
Action UInt32
OfflineCacheCount UInt32
CacheRollover Boolean
OfflineBundleId UnicodeString
Priority UnicodeString
Cached UnicodeString

Event ID 1011: Sending a request to the Connection Provider to renew a channel with parameters: ChannelId [ChannelId] PackageFullName [PackageFullName] Properties [Properties] Cookie [Cookie] TransactionId...

#
Channel
Operational
Opcode
Info

Description

Sending a request to the Connection Provider to renew a channel with parameters: ChannelId [ChannelId] PackageFullName [PackageFullName] Properties [Properties] Cookie [Cookie] TransactionId [TransactionId].

Message #

Sending a request to the Connection Provider to renew a channel with parameters: %1 [ChannelId] %2 [PackageFullName] %3 [Properties] %4 [Cookie] %5 [TransactionId].

Fields #

NameDescription
ChannelId UnicodeString
PackageFullName UnicodeString
Properties UInt32
Cookie UInt32
TransactionId Int32

Event ID 1012: Setting batching configuration to the following state: BatchingState.

#
Channel
Debug
Opcode
Info

Message #

Setting batching configuration to the following state: %1.

Fields #

NameDescription
BatchingState UInt32

Event ID 1013: Configuring notification delivery for AppUserModelId AppUserModelId with channel id ChannelId.

#
Channel
Operational
Opcode
Info

Description

Configuring notification delivery for AppUserModelId AppUserModelId with channel id ChannelId. NotificationType [NotificationType] Enabled [Enabled].

Message #

Configuring notification delivery for AppUserModelId %4 with channel id %1.  %2 [NotificationType] %3 [Enabled].

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UInt32
Enabled Boolean
AppUserModelId UnicodeString

Event ID 1014: The Resource Manager was notified that display state changed to DisplayStatus.

#
Channel
Debug
Opcode
Info

Message #

The Resource Manager was notified that display state changed to %1.

Fields #

NameDescription
DisplayStatus UInt32

Event ID 1015: Configuring notification policy for NotificationType [NotificationType] Enabled [Enabled].

#
Channel
Operational
Opcode
Info

Message #

Configuring notification policy for %1 [NotificationType] %2 [Enabled].

Fields #

NameDescription
NotificationType UInt32
Enabled Boolean

Event ID 1016: The Resource Manager was notified of an update to the network cost.

#
Channel
Debug
Opcode
Info

Description

The Resource Manager was notified of an update to the network cost. NetworkCost [Cost] Costly [Costly].

Message #

The Resource Manager was notified of an update to the network cost. %1 [Cost] %2 [Costly].

Fields #

NameDescription
NetworkCost UInt32
Costly Boolean

Event ID 1017: The Resource Manager was notified of an update to the data plan.

#
Channel
Debug
Opcode
Info

Description

The Resource Manager was notified of an update to the data plan. DateSource [Source] BillingCycle [BillingCycle].

Message #

The Resource Manager was notified of an update to the data plan. %1 [Source] %2 [BillingCycle].

Fields #

NameDescription
DateSource UInt32
BillingCycle FILETIME

Event ID 1018: The Resource Manager reset the Mobile Broadband Usage statistics.

#
Channel
Debug
Opcode
Info

Event ID 1019: The Resource Manager was notified that user session state changed to Status.

#
Channel
Debug
Opcode
Info

Message #

The Resource Manager was notified that user session state changed to %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1020: The Connection Provider status changed to a failure state: {Status}.

#
Channel
Operational

Fields #

NameDescription
StatusNTSTATUS reference

Event ID 1021: The Connection Manager has failed to connect: ErrorCode.

#
Channel
Operational
Opcode
Info

Message #

The Connection Manager has failed to connect: %1.

Fields #

NameDescription
ErrorCode Int32

Event ID 1022: ConnectWork is requesting ConnectionManager to connect.

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1022,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036963827968,
    "time_created": "2023-11-05T22:41:17.175463+00:00",
    "event_record_id": 2592,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 5364
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 1023: No internet connection available, WorkItemName is queued for next network status change.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

No internet connection available, %1 is queued for next network status change.

Fields #

NameDescription
WorkItemName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 1023,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036745723648,
    "time_created": "2026-05-30T03:12:54.4585956+00:00",
    "event_record_id": 4560138,
    "correlation": {
      "ActivityID": "{783C80E5-215B-4D9C-8EA0-027A518E0E7D}"
    },
    "execution": {
      "process_id": 4456,
      "thread_id": 10200
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "WorkItemName": "ConnectWork"
  },
  "message": "No internet connection available, ConnectWork is queued for next network status change."
}

Event ID 1024: Internet connection status changed to IsConnected, submitting pending workitems: count = PendingCount.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

Internet connection status changed to %1, submitting pending workitems: count = %2.

Fields #

NameDescription
IsConnected Boolean
PendingCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 1024,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036745723648,
    "time_created": "2026-05-30T02:34:09.7762935+00:00",
    "event_record_id": 4560063,
    "correlation": {},
    "execution": {
      "process_id": 3460,
      "thread_id": 2064
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsConnected": "true",
    "PendingCount": "0"
  },
  "message": "Internet connection status changed to true, submitting pending workitems: count = 0."
}

Event ID 1025: A Power event was fired: PowerEventType [PowerEventType] IsEnabled [Enabled].

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

A Power event was fired: %1 [PowerEventType] %2 [Enabled].

Fields #

NameDescription
PowerEventType UnicodeStringA Power event was fired.
IsEnabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223336852482686720,
    "time_created": "2026-05-29T16:33:58.1124188+00:00",
    "event_record_id": 323,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 1536
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "PowerEventType": "MonitorSettingChange",
    "IsEnabled": "true"
  },
  "message": "A Power event was fired: MonitorSettingChange [PowerEventType] true [Enabled]."
}

Event ID 1100: Connecting to the Windows Push Notification Service.

#
Channel
Debug
Opcode
Info

Description

Connecting to the Windows Push Notification Service. UserId [UserId] UserType [UserType] FeatureSet [FeatureSet] AuthType [AuthType] AuthPayload [AuthPayload] BindPayload [BindPayload].

Message #

Connecting to the Windows Push Notification Service. %1 [UserId] %2 [UserType] %3 [FeatureSet] %4 [AuthType] %6 [AuthPayload] %8 [BindPayload].

Fields #

NameDescription
UserId UInt64
UserType UInt32
FeatureSet AnsiString
AuthType AnsiString
AuthPayloadSize UInt32
AuthPayload Binary
BindPayloadSize UInt32
BindPayload Binary

Event ID 1101: Windows Push Notification Service connection result: Error.

#
Channel
Debug
Opcode
Info

Message #

Windows Push Notification Service connection result: %1.

Fields #

NameDescription
Error UInt32

Event ID 1102: Sending Channel WNP Protocol command: Sending_Channel_WNP_Protocol_command [TransactionId] TransactionId [ChannelId] ChannelId [PackageFullName] PackageFullName [Properties] CommandSize [Command] C...

#
Channel
Debug
Opcode
Info

Description

Sending Channel WNP Protocol command: Sending_Channel_WNP_Protocol_command [TransactionId] TransactionId [ChannelId] ChannelId [PackageFullName] PackageFullName [Properties] CommandSize [Command] Command [Namespace] Namespace [ContextId] PayloadSize [Payload] Payload [UserId].

Message #

Sending Channel WNP Protocol command: %1 [TransactionId] %2 [ChannelId] %3 [PackageFullName] %4 [Properties] %6 [Command] %7 [Namespace] %8 [ContextId] %10 [Payload] %11 [UserId].

Fields #

NameDescription
TransactionId Int32
ChannelId AnsiString
PackageFullName AnsiString
Properties UInt32
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary
UserId UInt64

Event ID 1103: Channel WNP Protocol command tracking information: TransactionId [TransactionId] TrID [TrID].

#
Channel
Debug
Opcode
Info

Message #

Channel WNP Protocol command tracking information: %1 [TransactionId] %2 [TrID].

Fields #

NameDescription
TransactionId Int32
TrID UInt32

Event ID 1104: Sending Revoke WNP Protocol command: Sending_Revoke_WNP_Protocol_command [ChannelId] CommandSize [Command] Command [Namespace] Namespace [ContextId] PayloadSize [Payload] Payload [UserId].

#
Channel
Debug
Opcode
Info

Message #

Sending Revoke WNP Protocol command: %1 [ChannelId] %3 [Command] %4 [Namespace] %5 [ContextId] %7 [Payload] %8 [UserId].

Fields #

NameDescription
ChannelId AnsiString
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary
UserId UInt64

Event ID 1105: Sending Block/Unblock WNP Protocol command: ChannelId [ChannelId] NotificationType [NotificationType] Enabled [Enabled] Command [Command] Namespace [Namespace] ContextId [ContextId] Payload [Payloa...

#
Channel
Debug
Opcode
Info

Description

Sending Block/Unblock WNP Protocol command: ChannelId [ChannelId] NotificationType [NotificationType] Enabled [Enabled] Command [Command] Namespace [Namespace] ContextId [ContextId] Payload [Payload] UserId [UserId].

Message #

Sending Block/Unblock WNP Protocol command: %1 [ChannelId] %2 [NotificationType] %3 [Enabled] %5 [Command] %6 [Namespace] %7 [ContextId] %9 [Payload] %10 [UserId].

Fields #

NameDescription
ChannelId AnsiString
NotificationType UInt32
Enabled Boolean
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary
UserId UInt64

Event ID 1106: Sending Options WNP Protocol command: Sending_Options_WNP_Protocol_command [State] CommandSize [Command] Command [Namespace] Namespace [ContextId] PayloadSize [Payload].

#
Channel
Debug
Opcode
Info

Message #

Sending Options WNP Protocol command: %1 [State] %3 [Command] %4 [Namespace] %5 [ContextId] %7 [Payload].

Fields #

NameDescription
BatchingState UInt32
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary

Event ID 1107: WNP Protocol command response: WNP_Protocol_command_response [TrID] TrID [Error] Error [ContextId] ContextId [UserId].

#
Channel
Debug
Opcode
Info

Message #

WNP Protocol command response: %1 [TrID] %2 [Error] %3 [ContextId] %4 [UserId].

Fields #

NameDescription
TrID UInt32
Error UInt32
ContextId UInt64
UserId UInt64

Event ID 1108: WNP Protocol delivered notification: WNP_Protocol_delivered_notification [Namespace] Namespace [UserId] UserId [PayloadSize] PayloadSize [MsgId] MsgId [Ack].

#
Channel
Debug
Opcode
Info

Message #

WNP Protocol delivered notification: %1 [Namespace] %2 [UserId] %3 [PayloadSize] %4 [MsgId] %5 [Ack].

Fields #

NameDescription
Namespace AnsiString
UserId AnsiString
PayloadSize UInt32
MsgId UInt64
Ack Boolean

Event ID 1109: Disconnecting from the Windows Push Notification Service.

#
Channel
Debug
Opcode
Info

Event ID 1110: Windows Push Notification Service disconnection result: Error.

#
Channel
Debug
Opcode
Info

Message #

Windows Push Notification Service disconnection result: %1.

Fields #

NameDescription
Error UInt32

Event ID 1112: Requesting Device Compact Ticket for the ConnectionType.

#
Channel
Debug
Task
ConnectionEstablishment
Opcode
Start

Message #

Requesting Device Compact Ticket for the %1.

Fields #

NameDescription
ConnectionType UInt32

Event ID 1113: Device Compact Ticket request completed with Device Id DeviceId for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Stop

Message #

Device Compact Ticket request completed with Device Id %1 for the %2.

Fields #

NameDescription
DeviceId AnsiString
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1113,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "keywords": 9223372036854890496,
    "time_created": "2023-11-05T22:36:06.776267+00:00",
    "event_record_id": 2554,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceId": "0018800CFC3A4A31",
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1114: Sending Filter/Unfilter WNP Protocol command: NotificationType [NotificationType] Enabled [Enabled] Command [Command] Namespace [Namespace] ContextId [ContextId] Payload [Payload] UserId [UserId].

#
Channel
Debug
Opcode
Info

Message #

Sending Filter/Unfilter WNP Protocol command: %1 [NotificationType] %2 [Enabled] %4 [Command] %5 [Namespace] %6 [ContextId] %8 [Payload] %9 [UserId].

Fields #

NameDescription
NotificationType UInt32
Enabled Boolean
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary
UserId UInt64

Event ID 1115: Sending Ack WNP Protocol command: Sending_Ack_WNP_Protocol_command [MsgId] CommandSize [Command] Command [Namespace] PayloadSize [Payload].

#
Channel
Debug
Opcode
Info

Message #

Sending Ack WNP Protocol command: %1 [MsgId] %3 [Command] %4 [Namespace] %6 [Payload].

Fields #

NameDescription
MsgId UInt64
CommandSize UInt32
Command Binary
Namespace AnsiString
PayloadSize UInt32
Payload Binary

Event ID 1116: Device Compact Ticket request failed with error Error for the ConnectionType.

#
Channel
Operational
Task
ConnectionEstablishment
Opcode
Stop

Message #

Device Compact Ticket request failed with error %1 for the %2.

Fields #

NameDescription
Error UInt32
ConnectionType UInt32

Event ID 1117: Windows Push Notification Service was disconnected due to error: Error and will now enter reconnect mode.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

Windows Push Notification Service was disconnected due to error: %1 and will now enter reconnect mode.

Fields #

NameDescription
Error UInt32Windows Push Notification Service was disconnected due to error.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1117,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372037022564352,
    "time_created": "2023-11-05T22:36:04.732833+00:00",
    "event_record_id": 2541,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Error": 2147952453
  },
  "message": ""
}

References #

Event ID 1118: Sending Challenge Response WNP Protocol command: Nonce [Nonce] Response [Response] Command [Command] Namespace [Namespace] ContextId [ContextId] Payload [Payload].

#
Channel
Debug
Opcode
Info

Message #

Sending Challenge Response WNP Protocol command: %1 [Nonce] %2 [Response] %4 [Command] %5 [Namespace] %6 [ContextId] %8 [Payload].

Fields #

NameDescription
Nonce AnsiString
Response AnsiString
CommandSize UInt32
Command Binary
Namespace AnsiString
ContextId UInt64
PayloadSize UInt32
Payload Binary

Event ID 1201: WNP Transport Layer Connect call initiated for the ConnectionType.

#
Channel
Debug
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer Connect call initiated for the %1.

Fields #

NameDescription
ConnectionType UInt32

Event ID 1202: WNP Transport Layer Connect call completed for the ConnectionType.

#
Channel
Debug
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer Connect call completed for the %1.

Fields #

NameDescription
ConnectionType UInt32

Event ID 1203: WNP Transport Layer SendCommand call initiated for TrID CommandTrid on the ConnectionType.

#
Channel
Debug
Opcode
Start

Message #

WNP Transport Layer SendCommand call initiated for TrID %1 on the %2.

Fields #

NameDescription
CommandTrid UInt32
ConnectionType UInt32

Event ID 1204: WNP Transport Layer SendCommand call completed for TrID CommandTrid on the ConnectionType.

#
Channel
Debug
Opcode
Stop

Message #

WNP Transport Layer SendCommand call completed for TrID %1 on the %2.

Fields #

NameDescription
CommandTrid UInt32
ConnectionType UInt32
Error UInt32

Event ID 1205: WNP Transport Layer Disconnect call initiated for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
PlatformShutdown
Opcode
Start

Message #

WNP Transport Layer Disconnect call initiated for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1205,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 1,
    "keywords": 9223372036861067264,
    "time_created": "2023-11-06T00:20:42.969404+00:00",
    "event_record_id": 2746,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 0
  },
  "message": ""
}

References #

Event ID 1206: WNP Transport Layer Disconnect call completed for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
PlatformShutdown
Opcode
Stop

Message #

WNP Transport Layer Disconnect call completed for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1206,
    "version": 0,
    "level": 4,
    "task": 8,
    "opcode": 2,
    "keywords": 9223372036861067264,
    "time_created": "2023-11-06T00:20:43.006766+00:00",
    "event_record_id": 2749,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 0
  },
  "message": ""
}

References #

Event ID 1207: WNP Transport Layer resolving DNS initiated for host HostName for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer resolving DNS initiated for host %2 for the %1.

Fields #

NameDescription
ConnectionType UInt32
HostName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1207,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.645586+00:00",
    "event_record_id": 2542,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "HostName": "client.wns.windows.com"
  },
  "message": ""
}

References #

Event ID 1208: WNP Transport Layer resolving DNS completed for the ConnectionType with code ErrorCode.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer resolving DNS completed for the %1 with code %2.

Fields #

NameDescription
ConnectionType UInt32
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1208,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.671837+00:00",
    "event_record_id": 2543,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "ErrorCode": 0
  },
  "message": ""
}

References #

Event ID 1209: WNP Transport Layer retrieving proxy information initiated for the {ConnectionType}.

#
Channel
Operational

Fields #

NameDescription
ConnectionType

Event ID 1210: WNP Transport Layer retrieving proxy information completed for the {ConnectionType}.

#
Channel
Operational

Fields #

NameDescription
ConnectionType

Event ID 1211: WNP Transport Layer initial server connection initiated to server HostName on port Port for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer initial server connection initiated to server %2 on port %3 for the %1.

Fields #

NameDescription
ConnectionType UInt32
HostName AnsiString
Port UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1211,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.672509+00:00",
    "event_record_id": 2544,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "HostName": "client.wns.windows.com",
    "Port": 443
  },
  "message": ""
}

References #

Event ID 1212: WNP Transport Layer initial server connection completed to server HostName on port Port for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer initial server connection completed to server %2 on port %3 for the %1.

Fields #

NameDescription
ConnectionType UInt32
HostName AnsiString
Port UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1212,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.697481+00:00",
    "event_record_id": 2545,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "HostName": "client.wns.windows.com",
    "Port": 443
  },
  "message": ""
}

References #

Event ID 1213: WNP Transport Layer proxy connection initiated for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer proxy connection initiated for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 1213,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "time_created": "2026-04-28T02:37:06.9638909+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "ConnectionType": "1"
  }
}

Event ID 1214: WNP Transport Layer proxy connection completed to server HostName for the ConnectionType.

#
Channel
Operational
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer proxy connection completed to server %2 for the %1.

Fields #

NameDescription
ConnectionType UInt32
HostName UnicodeString

Event ID 1215: WNP Transport Layer proxy negotiation initiated for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer proxy negotiation initiated for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 1215,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "time_created": "2026-04-28T02:37:06.9638928+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "ConnectionType": "1"
  }
}

Event ID 1216: WNP Transport Layer proxy negotiation completed for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer proxy negotiation completed for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 1216,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "time_created": "2026-04-28T02:37:06.9732954+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "ConnectionType": "1"
  }
}

Event ID 1217: WNP Transport Layer TLS negotiation initiated for the ConnectionType.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Start

Message #

WNP Transport Layer TLS negotiation initiated for the %1.

Fields #

NameDescription
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1217,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 1,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.697498+00:00",
    "event_record_id": 2546,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1218: WNP Transport Layer TLS negotiation completed for the ConnectionType with code ErrorCode.

#
Channel
Operational
Level
Informational
Task
ConnectionEstablishment
Opcode
Stop

Message #

WNP Transport Layer TLS negotiation completed for the %1 with code %2.

Fields #

NameDescription
ConnectionType UInt32
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1218,
    "version": 0,
    "level": 4,
    "task": 9,
    "opcode": 2,
    "keywords": 9223372036859068416,
    "time_created": "2023-11-05T22:36:06.766754+00:00",
    "event_record_id": 2553,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "ErrorCode": 0
  },
  "message": ""
}

References #

Event ID 1219: WNP Transport Layer sent Bytes bytes on the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

WNP Transport Layer sent %1 bytes on the %2.

Fields #

NameDescription
Bytes UInt32
ConnectionType UInt32

Event ID 1220: WNP Transport Layer received Bytes bytes on the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

WNP Transport Layer received %1 bytes on the %2.

Fields #

NameDescription
Bytes UInt32
ConnectionType UInt32

Event ID 1223: WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload.

#
Channel
Operational
Level
Verbose
Opcode
Info

Description

WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload. IsLongRunning: ConnectionType.

Message #

WNP Transport Layer sent command: %1, Trid: %2, Namespace: %3, CV: %4 containing %5 bytes of payload: %6. IsLongRunning: %7.

Fields #

NameDescription
Verb AnsiStringWNP Transport Layer sent command.
TrID UInt32
Namespace AnsiString
CorrelationVector AnsiString
Bytes UInt32
Payload Binary5 bytes of payload.
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1223,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036959633408,
    "time_created": "2023-11-06T01:49:11.345596+00:00",
    "event_record_id": 2773,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Verb": "PNG",
    "TrID": 19,
    "Namespace": "CON",
    "CorrelationVector": "vfP4YmNyxkSgHVIt.19",
    "Bytes": 29,
    "Payload": "436F6E746578743A20336635303563336636353833666465640D0A0D0A",
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1224: WNP Transport Layer received Bytes bytes of payload: Payload.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer received %1 bytes of payload: %2.

Fields #

NameDescription
Bytes UInt32
Payload Binary
ConnectionType UInt32

Event ID 1225: WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload.

#
Channel
Operational
Level
Verbose
Opcode
Info

Description

WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload. IsLongRunning: ConnectionType.

Message #

WNP Transport Layer received command: %1, Trid: %2, Namespace: %3, CV: %4 containing %5 bytes of payload: %6. IsLongRunning: %7.

Fields #

NameDescription
Verb AnsiStringWNP Transport Layer received command.
TrID UInt32
Namespace AnsiString
CorrelationVector AnsiString
Bytes UInt32
Payload Binary5 bytes of payload.
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1225,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036959633408,
    "time_created": "2023-11-06T01:49:11.384647+00:00",
    "event_record_id": 2775,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Verb": "PNG",
    "TrID": 19,
    "Namespace": "CON",
    "CorrelationVector": "vfP4YmNyxkSgHVIt.19.0",
    "Bytes": 126,
    "Payload": "4D532D43563A2076665034596D4E79786B5367485649742E31392E300D0A0D0A3C70696E672D726573706F6E73653E3C776169743E34333C2F776169743E3C636F6E6E656374696F6E2D7374617475733E436F6E6E65637465643C2F636F6E6E656374696F6E2D7374617475733E3C2F70696E672D726573706F6E73653E",
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1226: WNP Transport Layer received proxy server response for the ConnectionType of Bytes bytes with payload: Payload.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer received proxy server response for the %3 of %1 bytes with payload: %2.

Fields #

NameDescription
Bytes UInt32
Payload Binary
ConnectionType UInt32

Event ID 1227: WNP Transport Layer received command when disconnected with Verb: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload.

#
Channel
Operational
Opcode
Info

Description

WNP Transport Layer received command when disconnected with Verb: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload: Payload. IsLongRunning: ConnectionType.

Message #

WNP Transport Layer received command when disconnected with Verb: %1, Trid: %2, Namespace: %3, CV: %4 containing %5 bytes of payload: %6. IsLongRunning: %7.

Fields #

NameDescription
Verb AnsiString
TrID UInt32
Namespace AnsiString
CorrelationVector AnsiString
Bytes UInt32
Payload Binary
ConnectionType UInt32

Event ID 1228: WNP Keep Alive Detector received OnConnected event from the test connection with Error: ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector received OnConnected event from the test connection with Error: %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1229: WNP Keep Alive Detector received OnReconnecting event from the test connection with Error: ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector received OnReconnecting event from the test connection with Error: %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1230: WNP Keep Alive Detector received OnDisconnected event from the test connection with Error: ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector received OnDisconnected event from the test connection with Error: %1

Fields #

NameDescription
ErrorCode UInt32

Event ID 1231: WNP Keep Alive Detector received KA hint from server: ServerKaHint seconds.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector received KA hint from server: %1 seconds

Fields #

NameDescription
ServerKaHint UInt32

Event ID 1232: WNP Keep Alive Detector updating cached Ka time with value: KaValue seconds; type: KaValueType.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector updating cached Ka time with value: %2 seconds; type: %1

Fields #

NameDescription
KaValueType UInt32
KaValue UInt32

Event ID 1233: Fast reconnect triggered for previous WNS session (SessionId) on the ConnectionType.

#
Channel
Operational
Opcode
Info

Description

Fast reconnect triggered for previous WNS session (SessionId) on the ConnectionType. It has been SecondsSinceLastSentPacket seconds since last packet.

Message #

Fast reconnect triggered for previous WNS session (%1) on the %3.  It has been %2 seconds since last packet.

Fields #

NameDescription
SessionId AnsiString
SecondsSinceLastSentPacket UInt64
ConnectionType UInt32

Event ID 1234: ConnectionType TCP connection established over ProtocolType.

#
Channel
Debug
Opcode
Info

Message #

%2 TCP connection established over %1.

Fields #

NameDescription
ProtocolType UInt32
ConnectionType UInt32

Event ID 1235: WNP Keep Alive Detector resetting Idle Failed Interval.

#
Channel
Debug
Opcode
Info

Description

WNP Keep Alive Detector resetting Idle Failed Interval. Last Idle-Succeeded interval IdleSucceededInterval seconds is larger than Idle-Failed interval IdleFailedInterval seconds.

Message #

WNP Keep Alive Detector resetting Idle Failed Interval. Last Idle-Succeeded interval %1 seconds is larger than Idle-Failed interval %2 seconds

Fields #

NameDescription
IdleSucceededInterval UInt32
IdleFailedInterval UInt32

Event ID 1236: WNP Keep Alive Detector incrementing Idle-Succeeded count to IdleSucceededCount.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector incrementing Idle-Succeeded count to %1

Fields #

NameDescription
IdleSucceededCount UInt32

Event ID 1237: WNP Keep Alive Detector encountered failed idle interval of IdleFailedInterval seconds.

#
Channel
Debug
Opcode
Info

Message #

WNP Keep Alive Detector encountered failed idle interval of %1 seconds

Fields #

NameDescription
IdleFailedInterval UInt32

Event ID 1238: WNP Keep Alive Detector starting Test Connection

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1238,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:33:26.748563+00:00",
    "event_record_id": 2458,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 1239: WNP Keep Alive Detector starting KA measurement with value: KaValue seconds; type: KaValueType; Min Limit: KaMinLimit seconds.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

WNP Keep Alive Detector starting KA measurement with value: %2 seconds; type: %1; Min Limit: %3 seconds

Fields #

NameDescription
KaValueType UInt32seconds; type.
KaValue UInt32WNP Keep Alive Detector starting KA measurement with value.
KaMinLimit UInt32; Min Limit.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1239,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:33:26.736302+00:00",
    "event_record_id": 2457,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 3672
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "KaValueType": 0,
    "KaValue": 60,
    "KaMinLimit": 60
  },
  "message": ""
}

References #

Event ID 1240: WNP Keep Alive Detector stopping KA measurement

#
Channel
Operational
Level
Informational
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1240,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2026-02-10T04:19:29.950446+00:00",
    "event_record_id": 936,
    "correlation": {},
    "execution": {
      "process_id": 3980,
      "thread_id": 9792
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1241: WNP Keep Alive Detector lost network over ProtocolType.

#
Channel
Operational
Opcode
Info

Message #

WNP Keep Alive Detector lost network over %1.

Fields #

NameDescription
ProtocolType UInt32

Event ID 1242: WNP Transport Layer received Power Management event with type PowerManagementType on the ConnectionType.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer received Power Management event with type %1 on the %2.

Fields #

NameDescription
PowerManagementType UInt32
ConnectionType UInt32

Event ID 1243: WNP Transport Layer received Power Management event with type PowerManagementType on the ConnectionType.

#
Channel
Debug
Opcode
Info

Description

WNP Transport Layer received Power Management event with type PowerManagementType on the ConnectionType. Message is ignored.

Message #

WNP Transport Layer received Power Management event with type %1 on the %2.  Message is ignored

Fields #

NameDescription
PowerManagementType UInt32
ConnectionType UInt32

Event ID 1244: Connection to the Windows Push Notification Service (HostName:Port) failed because proxy host detected (ProxyHostName) could not be used to establish the connection.

#
Channel
Operational
Opcode
Info

Description

Connection to the Windows Push Notification Service (HostName:Port) failed because proxy host detected (ProxyHostName) could not be used to establish the connection. Please check the proxy configuration on the client as well as verify that the proxy host detected is operating correctly.

Message #

Connection to the Windows Push Notification Service (%1:%2) failed because proxy host detected (%3) could not be used to establish the connection.  Please check the proxy configuration on the client as well as verify that the proxy host detected is operating correctly.

Fields #

NameDescription
HostName UnicodeString
Port UInt16
ProxyHostName UnicodeString

Event ID 1245: Connection to the Windows Push Notification Service (HostName:Port) failed because the proxy host detected (ProxyHostName) explicitly requires user authentication.

#
Channel
Admin
Opcode
Info

Description

Connection to the Windows Push Notification Service (HostName:Port) failed because the proxy host detected (ProxyHostName) explicitly requires user authentication. Only proxies configured with NTLM authentication are supported.

Message #

Connection to the Windows Push Notification Service (%1:%2) failed because the proxy host detected (%3) explicitly requires user authentication.  Only proxies configured with NTLM authentication are supported.

Fields #

NameDescription
HostName UnicodeString
Port UInt16
ProxyHostName UnicodeString

Event ID 1246: WNP Transport Layer was disconnected from the Windows Push Notification Service due to a loss of network connectivity.

#
Channel
Operational
Level
Warning
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1246,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372037026742272,
    "time_created": "2026-07-23T22:24:52.002651+00:00",
    "event_record_id": 7429482,
    "correlation": {},
    "execution": {
      "process_id": 4820,
      "thread_id": 12280
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 1247: Connection to the Windows Push Notification Service failed because of a failure to configure the connection to run properly in low-power states.

#
Channel
Admin
Opcode
Info

Description

Connection to the Windows Push Notification Service failed because of a failure to configure the connection to run properly in low-power states. Please ensure all network drivers are up to date.

Message #

Connection to the Windows Push Notification Service failed because of a failure to configure the connection to run properly in low-power states.  Please ensure all network drivers are up to date.

Fields #

NameDescription
ControlChannelTriggerStatus UInt32

Event ID 1248: Connection to the Windows Push Notification Service (HostName:Port) failed because the proxy host detected (ProxyHostName) could not be connected to.

#
Channel
Admin
Opcode
Info

Description

Connection to the Windows Push Notification Service (HostName:Port) failed because the proxy host detected (ProxyHostName) could not be connected to. The HTTP request failed with HTTP Status: HttpStatus.

Message #

Connection to the Windows Push Notification Service (%1:%2) failed because the proxy host detected (%3) could not be connected to. The HTTP request failed with HTTP Status: %4.

Fields #

NameDescription
HostName UnicodeString
Port UInt16
ProxyHostName UnicodeString
HttpStatus UInt32

Event ID 1249: StopKeepAliveMeasurement was called from message loop.

#
Channel
Debug
Opcode
Info

Event ID 1250: The KA measurement was never started.

#
Channel
Debug
Opcode
Info

Event ID 1251: The test connection disconnect failed synchronously due to error: Error.

#
Channel
Debug
Opcode
Info

Message #

The test connection disconnect failed synchronously due to error: %1

Fields #

NameDescription
Error UInt32

Event ID 1252: The KA value has converged.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

The KA value has converged. Now disconnect test connection.

Message #

The KA value has converged.  Now disconnect test connection.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1252,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-06T00:20:42.944747+00:00",
    "event_record_id": 2745,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 1253: The test connection will be disconnected due to idle failure.

#
Channel
Debug
Opcode
Info

Event ID 1254: WNP Transport Layer for ConnectionType detected preferred interface change.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

WNP Transport Layer for ConnectionType detected preferred interface change. Old index OldIndex, old address family OldAddressFamily. New index NewIndex, new address family NewAddressFamily, NDIS_PHYSICAL_MEDIUM NewPhysicalMediumType.

Message #

WNP Transport Layer for %1 detected preferred interface change. Old index %2, old address family %3. New index %4, new address family %5, NDIS_PHYSICAL_MEDIUM %6.

Fields #

NameDescription
ConnectionType UInt32
OldIndex UInt32
OldAddressFamily UInt32
NewIndex UInt32
NewAddressFamily UInt32
NewPhysicalMediumType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1254,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:33:26.761426+00:00",
    "event_record_id": 2462,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 0,
    "OldIndex": 0,
    "OldAddressFamily": 0,
    "NewIndex": 9,
    "NewAddressFamily": 0,
    "NewPhysicalMediumType": 14
  },
  "message": ""
}

References #

Event ID 1255: WNP Transport Layer for ConnectionType reacting to preferred interface change, disconnect and immediately reconnect.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer for %1 reacting to preferred interface change, disconnect and immediately reconnect.

Fields #

NameDescription
ConnectionType UInt32

Event ID 1256: WNP Transport Layer for ConnectionType reacting to preferred interface change, immediately reconnect.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer for %1 reacting to preferred interface change, immediately reconnect.

Fields #

NameDescription
ConnectionType UInt32

Event ID 1257: WNP Transport Layer for ConnectionType called InitializeSecurityContext and got return code Error.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

WNP Transport Layer for %1 called InitializeSecurityContext and got return code %2.

Fields #

NameDescription
ConnectionType UInt32
Error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1257,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:36:06.766744+00:00",
    "event_record_id": 2552,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "Error": 0
  },
  "message": ""
}

References #

Event ID 1258: WNP Transport Layer for ConnectionType received asynchronous connection error SocketError.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

WNP Transport Layer for %1 received asynchronous connection error %2.

Fields #

NameDescription
ConnectionType UInt32
SocketError UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1258,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:36:03.277507+00:00",
    "event_record_id": 2540,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 1,
    "SocketError": 10053
  },
  "message": ""
}

References #

Event ID 1259: WNP Transport Layer for the Data Connection sending out of band keep alive (PNG) request.

#
Channel
Operational
Opcode
Info

Event ID 1260: WNP Transport Layer for the Data Connection received cellular state change WNF event.

#
Channel
Operational
Opcode
Info

Event ID 1261: Adding new user to the Windows Push Notification Service.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

Adding new user to the Windows Push Notification Service. DeviceId [DeviceId] UserId [UserId] UserType [UserType].

Message #

Adding new user to the Windows Push Notification Service. %1 [DeviceId] %2 [UserId] %3 [UserType].

Fields #

NameDescription
DeviceId AnsiString
UserId UInt64
UserType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1261,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:41:17.176465+00:00",
    "event_record_id": 2593,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceId": "0018800CFC3A4A31",
    "UserId": 0,
    "UserType": 1
  },
  "message": ""
}

References #

Event ID 1262: Removing existing user from the Windows Push Notification Service.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

Removing existing user from the Windows Push Notification Service. DeviceId [DeviceId] UserId [UserId] UserType [UserType].

Message #

Removing existing user from the Windows Push Notification Service. %1 [DeviceId] %2 [UserId] %3 [UserType].

Fields #

NameDescription
DeviceId AnsiString
UserId UInt64
UserType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1262,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:31:33.631380+00:00",
    "event_record_id": 2379,
    "correlation": {},
    "execution": {
      "process_id": 3280,
      "thread_id": 1712
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceId": "0018800CFC3A4A31",
    "UserId": 17056889,
    "UserType": 2
  },
  "message": ""
}

References #

Event ID 1263: Replacing existing user from the Windows Push Notification Service.

#
Channel
Operational
Opcode
Info

Description

Replacing existing user from the Windows Push Notification Service. DeviceId [DeviceId] OldUserId [OldUserId] OldUserType [OldUserType] NewUserId [NewUserId] NewUserType [NewUserType].

Message #

Replacing existing user from the Windows Push Notification Service. %1 [DeviceId] %2 [OldUserId] %3 [OldUserType] %4 [NewUserId] %5 [NewUserType].

Fields #

NameDescription
DeviceId AnsiString
OldUserId UInt64
OldUserType UInt32
NewUserId UInt64
NewUserType UInt32

Event ID 1264: Adding new user to the Windows Push Notification Service completed.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

Adding new user to the Windows Push Notification Service completed. DeviceId [DeviceId] UserId [UserId] Error [ErrorCode].

Message #

Adding new user to the Windows Push Notification Service completed. %1 [DeviceId] %2 [UserId] %3 [ErrorCode].

Fields #

NameDescription
DeviceId AnsiString
UserId UInt64
Error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1264,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:41:17.203291+00:00",
    "event_record_id": 2598,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceId": "0018800CFC3A4A31",
    "UserId": 0,
    "Error": 0
  },
  "message": ""
}

References #

Event ID 1265: Removing existing user from the Windows Push Notification Service completed.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

Removing existing user from the Windows Push Notification Service completed. DeviceId [DeviceId] UserId [UserId] Error [ErrorCode].

Message #

Removing existing user from the Windows Push Notification Service completed. %1 [DeviceId] %2 [UserId] %3 [ErrorCode].

Fields #

NameDescription
DeviceId AnsiString
UserId UInt64
Error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1265,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:31:33.659387+00:00",
    "event_record_id": 2384,
    "correlation": {},
    "execution": {
      "process_id": 3280,
      "thread_id": 1712
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "DeviceId": "0018800CFC3A4A31",
    "UserId": 17056889,
    "Error": 0
  },
  "message": ""
}

References #

Event ID 1266: Replacing existing user from the Windows Push Notification Service completed.

#
Channel
Operational
Opcode
Info

Description

Replacing existing user from the Windows Push Notification Service completed. DeviceId [DeviceId] OldUserId [OldUserId] NewUserId [NewUserId] Error [ErrorCode].

Message #

Replacing existing user from the Windows Push Notification Service completed. %1 [DeviceId] %2 [OldUserId] %3 [NewUserId] %4 [ErrorCode].

Fields #

NameDescription
DeviceId AnsiString
OldUserId UInt64
NewUserId UInt64
Error UInt32

Event ID 1267: WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload only.

#
Channel
Operational
Level
Verbose
Opcode
Info

Description

WNP Transport Layer sent command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload only. However, full payload including header is: Payload. IsLongRunning: ConnectionType.

Message #

WNP Transport Layer sent command: %1, Trid: %2, Namespace: %3, CV: %4 containing %5 bytes of payload only. However, full payload including header is: %6. IsLongRunning: %7.

Fields #

NameDescription
Verb AnsiStringWNP Transport Layer sent command.
TrID UInt32
Namespace AnsiString
CorrelationVector AnsiString
Bytes UInt32
Payload Binary5 bytes of payload only. However, full payload including header is.
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1267,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036959633408,
    "time_created": "2023-11-06T01:49:11.345599+00:00",
    "event_record_id": 2774,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Verb": "PNG",
    "TrID": 19,
    "Namespace": "CON",
    "CorrelationVector": "vfP4YmNyxkSgHVIt.19",
    "Bytes": 72,
    "Payload": "504E4720313920434F4E2035370D0A4D532D43563A2076665034596D4E79786B5367485649742E31390D0A436F6E746578743A20336635303563336636353833666465640D0A0D0A",
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1268: WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload only.

#
Channel
Operational
Level
Verbose
Opcode
Info

Description

WNP Transport Layer received command: Verb, Trid: TrID, Namespace: Namespace, CV: CorrelationVector containing Bytes bytes of payload only. However, full payload including header is: Payload. IsLongRunning: ConnectionType.

Message #

WNP Transport Layer received command: %1, Trid: %2, Namespace: %3, CV: %4 containing %5 bytes of payload only. However, full payload including header is: %6. IsLongRunning: %7.

Fields #

NameDescription
Verb AnsiStringWNP Transport Layer received command.
TrID UInt32
Namespace AnsiString
CorrelationVector AnsiString
Bytes UInt32
Payload Binary5 bytes of payload only. However, full payload including header is.
ConnectionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1268,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036959633408,
    "time_created": "2023-11-06T01:49:11.384651+00:00",
    "event_record_id": 2776,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 4140
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Verb": "PNG",
    "TrID": 19,
    "Namespace": "CON",
    "CorrelationVector": "vfP4YmNyxkSgHVIt.19.0",
    "Bytes": 126,
    "Payload": "504E4720313920434F4E003132360D0A4D532D43563A2076665034596D4E79786B5367485649742E31392E300D0A0D0A3C70696E672D726573706F6E73653E3C776169743E34333C2F776169743E3C636F6E6E656374696F6E2D7374617475733E436F6E6E65637465643C2F636F6E6E656374696F6E2D7374617475733E",
    "ConnectionType": 1
  },
  "message": ""
}

References #

Event ID 1300: Started tracking connection establishment performance.

#
Channel
Debug
Opcode
Info

Event ID 1301: Finished tracking connection establishment performance.

#
Channel
Debug
Opcode
Info

Event ID 1302: PDC Intialization finished with error code [ErrorCode] and Initialization Count is [InitCount].

#
Channel
Debug
Opcode
Info

Message #

PDC Intialization finished with error code [%1] and Initialization Count is [%2].

Fields #

NameDescription
ErrorCode Int32
InitCount Int64

Event ID 1303: PDC Unintialization finished with error code [ErrorCode] and Initialization Count is [InitCount].

#
Channel
Debug
Opcode
Info

Message #

PDC Unintialization finished with error code [%1] and Initialization Count is [%2].

Fields #

NameDescription
ErrorCode Int32
InitCount Int64

Event ID 1304: PDC Activation finished with error code [ErrorCode], Initialization Count is [InitCount], and Reason is [PdcReason] for the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

PDC Activation finished with error code [%1], Initialization Count is [%2], and Reason is [%3] for the %4.

Fields #

NameDescription
ErrorCode Int32
InitCount Int64
PdcReason Int64
ConnectionType UInt32

Event ID 1305: PDC Deactivation finished with error code [ErrorCode], Initialization Count is [InitCount], and Reason is [PdcReason] for the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

PDC Deactivation finished with error code [%1], Initialization Count is [%2], and Reason is [%3] for the %4.

Fields #

NameDescription
ErrorCode Int32
InitCount Int64
PdcReason Int64
ConnectionType UInt32

Event ID 1306: WNP protocol state for Device Id DeviceId is State State for the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

WNP protocol state for Device Id %1 is State %2 for the %3.

Fields #

NameDescription
DeviceId AnsiString
State Int64
ConnectionType UInt32

Event ID 1307: WNP Connector state for Connector Id ConnectorId is State State for the ConnectionType.

#
Channel
Debug
Opcode
Info

Message #

WNP Connector state for Connector Id %1 is State %2 for the %3.

Fields #

NameDescription
ConnectorId UInt32
State Int64
ConnectionType UInt32

Event ID 1308: WNP Transport Layer for Connector Id ConnectorId requested NCSI probe for the ConnectionType and got error code ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNP Transport Layer for Connector Id %1 requested NCSI probe for the %2 and got error code %3.

Fields #

NameDescription
ConnectorId UInt32
ConnectionType UInt32
ErrorCode Int32

Event ID 1309: WNP Transport Layer for Auth Manager requested NCSI probe for the ConnectionType and got error code ErrorCode.

#
Channel
Debug
Opcode
Info

Message #

WNP Transport Layer for Auth Manager requested NCSI probe for the %1 and got error code %2.

Fields #

NameDescription
ConnectionType UInt32
ErrorCode Int32

Event ID 1310: WNP Transport Layer for ConnectionType detected first fallback interface change.

#
Channel
Operational
Level
Informational
Opcode
Info

Description

WNP Transport Layer for ConnectionType detected first fallback interface change. Old index OldIndex, old address family OldAddressFamily. New index NewIndex, new address family NewAddressFamily, NDIS_PHYSICAL_MEDIUM NewPhysicalMediumType.

Message #

WNP Transport Layer for %1 detected first fallback interface change. Old index %2, old address family %3. New index %4, new address family %5, NDIS_PHYSICAL_MEDIUM %6.

Fields #

NameDescription
ConnectionType UInt32
OldIndex UInt32
OldAddressFamily UInt32
NewIndex UInt32
NewAddressFamily UInt32
NewPhysicalMediumType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 1310,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036858970112,
    "time_created": "2023-11-05T22:33:26.761428+00:00",
    "event_record_id": 2463,
    "correlation": {
      "ActivityID": "E4DB489E-1037-0003-9850-DBE43710DA01"
    },
    "execution": {
      "process_id": 3380,
      "thread_id": 5052
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ConnectionType": 0,
    "OldIndex": 0,
    "OldAddressFamily": 0,
    "NewIndex": 4,
    "NewAddressFamily": 0,
    "NewPhysicalMediumType": 14
  },
  "message": ""
}

References #

Event ID 1311: WNP Transport Layer for ConnectionType detected second fallback interface change.

#
Channel
Operational
Opcode
Info

Description

WNP Transport Layer for ConnectionType detected second fallback interface change. Old index OldIndex, old address family OldAddressFamily. New index NewIndex, new address family NewAddressFamily, NDIS_PHYSICAL_MEDIUM NewPhysicalMediumType.

Message #

WNP Transport Layer for %1 detected second fallback interface change. Old index %2, old address family %3. New index %4, new address family %5, NDIS_PHYSICAL_MEDIUM %6.

Fields #

NameDescription
ConnectionType UInt32
OldIndex UInt32
OldAddressFamily UInt32
NewIndex UInt32
NewAddressFamily UInt32
NewPhysicalMediumType UInt32

Event ID 1312: WNP Transport Layer detected low WIFI signal quality level (value = TriggerValue); and hence sending out of band keep alive (PNG) request.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer detected low WIFI signal quality level (value = %1); and hence sending out of band keep alive (PNG) request.

Fields #

NameDescription
TriggerValue UInt32

Event ID 1313: WNP Transport Layer detected a significant drop in WIFI signal quality (delta = TriggerValue); and hence sending out of band keep alive (PNG) request.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer detected a significant drop in WIFI signal quality (delta = %1); and hence sending out of band keep alive (PNG) request.

Fields #

NameDescription
TriggerValue UInt32

Event ID 1314: WNP Transport Layer detected a change in WIFI interface availability (event TriggerValue); and hence sending out of band keep alive (PNG) request.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer detected a change in WIFI interface availability (event %1); and hence sending out of band keep alive (PNG) request.

Fields #

NameDescription
TriggerValue UInt32

Event ID 1315: WNP Transport Layer detected a change in WIFI interface connectivity status (event TriggerValue); and hence sending out of band keep alive (PNG) request.

#
Channel
Operational
Opcode
Info

Message #

WNP Transport Layer detected a change in WIFI interface connectivity status (event %1); and hence sending out of band keep alive (PNG) request.

Fields #

NameDescription
TriggerValue UInt32

Event ID 1316: WNS delivered notification dropped in CP: ErrorCode [ErrorCode] Namespace [Namespace] UserId [UserId] PayloadSize [PayloadSize] MsgId [MsgId]

#
Channel
Operational

Message #

WNS delivered notification dropped in CP: %1 [ErrorCode] %2 [Namespace] %3 [UserId] %4 [PayloadSize] %5 [MsgId].

Fields #

NameDescription
ErrorCode UInt32
Namespace AnsiString
UserId AnsiString
PayloadSize UInt32
MsgId UInt64

Event ID 1317: NotificationType associated with ChannelId ChannelId and AppUserModelId AppUserModelId with X-WNS-MSG-ID MessageId failed to be submitted to threadpool

#
Channel
Operational
Task
NewCloudNotificationArrival

Description

NotificationType associated with ChannelId ChannelId and AppUserModelId AppUserModelId with X-WNS-MSG-ID MessageId failed to be submitted to threadpool. ErrorCode ErrorCode.

Message #

%1 associated with ChannelId %2 and AppUserModelId %3 with X-WNS-MSG-ID %4 failed to be submitted to threadpool. ErrorCode %5

Fields #

NameDescription
NotificationType UInt32
ChannelId UnicodeString
AppUserModelId UnicodeString
MessageId UInt64
ErrorCode UInt32

Event ID 1318: WNP Protocol delivered notification: Namespace [Namespace] UserId [UserId] PayloadSize [PayloadSize] MsgId [MsgId] Ack [Ack] CorrelationVector [CorrelationVector]

#
Channel
Operational

Message #

WNP Protocol delivered notification: %1 [Namespace] %2 [UserId] %3 [PayloadSize] %4 [MsgId] %5 [Ack] %6 [CorrelationVector].

Fields #

NameDescription
Namespace AnsiString
UserId AnsiString
PayloadSize UInt32
MsgId UInt64
Ack Boolean
CorrelationVector AnsiString

Event ID 2000: The Windows Push Notification Platform has received a channel request with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId].

#
Channel
Debug
Task
RequestChannel
Opcode
Start

Message #

The Windows Push Notification Platform has received a channel request with the following parameters: %1 [PackageFullName] %2 [AppUserModelId].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelId UnicodeString

Event ID 2001: The channel table has added a valid channel mapping: ChannelId [ChannelId] AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Operational
Level
Informational
Task
RequestChannel
Opcode
Stop

Message #

The channel table has added a valid channel mapping: %1 [ChannelId] %2 [AppUserModelId] %3 [ErrorCode].

Fields #

NameDescription
ChannelId UnicodeStringThe channel table has added a valid channel mapping.
AppUserModelId UnicodeString
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 2001,
    "version": 0,
    "level": 4,
    "task": 17,
    "opcode": 2,
    "keywords": 9223372036863164928,
    "time_created": "2023-11-05T22:41:17.323597+00:00",
    "event_record_id": 2606,
    "correlation": {},
    "execution": {
      "process_id": 3380,
      "thread_id": 5016
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "ChannelId": "1;15334591640917018673",
    "AppUserModelId": "Microsoft.Windows.PushToInstall",
    "ErrorCode": 0
  },
  "message": ""
}

References #

Event ID 2002: The channel table has removed a channel mapping: ChannelId [ChannelId] AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Operational
Opcode
Info

Message #

The channel table has removed a channel mapping: %1 [ChannelId] %2 [AppUserModelId] %3 [ErrorCode].

Fields #

NameDescription
ChannelId UnicodeString
AppUserModelId UnicodeString
ErrorCode Int32

Event ID 2003: The channel table has updated a channel mapping: ChannelId [ChannelId] AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Operational
Level
Informational
Task
RequestChannel
Opcode
Stop

Message #

The channel table has updated a channel mapping: %1 [ChannelId] %2 [AppUserModelId] %3 [ErrorCode].

Fields #

NameDescription
ChannelId UnicodeString
AppUserModelId UnicodeString
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 2003,
    "level": 4,
    "task": 17,
    "opcode": 2,
    "time_created": "2026-05-27T16:17:07.0315908+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "ErrorCode": "0",
    "ChannelId": "1;16799312441015299245",
    "AppUserModelId": "Microsoft.Windows.PushToInstall"
  }
}

Event ID 2004: The channel table has returned a cached channel mapping: ChannelId [ChannelId] AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Debug
Task
RequestChannel
Opcode
Stop

Message #

The channel table has returned a cached channel mapping: %1 [ChannelId] %2 [AppUserModelId] %3 [ErrorCode].

Fields #

NameDescription
ChannelId UnicodeString
AppUserModelId UnicodeString
ErrorCode Int32

Event ID 2005: A cloud notification callback was added: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A cloud notification callback was added: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2006: A cloud notification callback was removed: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A cloud notification callback was removed: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2007: A cloud notification could not be delivered to a callback due to an error: AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Debug
Opcode
Info

Message #

A cloud notification could not be delivered to a callback due to an error: %1 [AppUserModelId] %2 [ErrorCode].

Fields #

NameDescription
AppUserModelId UnicodeString
ErrorCode Int32

Event ID 2008: A cloud notification was delivered to a callback: AppUserModelId [AppUserModelId] NotificationType [NotificationType] TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A cloud notification was delivered to a callback: %1 [AppUserModelId] %2 [NotificationType] %3 [NotificationTrackingId].

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32

Event ID 2009: A local notification was submitted to threadpool: AppUserModelId [AppUserModelId] NotificationType [NotificationType] TrackingId [NotificationTrackingId] NotificationSource [NotificationSource].

#
Channel
Debug
Task
NewLocalNotificationArrival
Opcode
Start

Message #

A local notification was submitted to threadpool: %1 [AppUserModelId] %2 [NotificationType] %3 [NotificationTrackingId] %4 [NotificationSource].

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
NotificationSource UInt32

Event ID 2010: A clear tile message was received from an application endpoint: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A clear tile message was received from an application endpoint: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2011: A clear badge message was received from an application endpoint: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A clear badge message was received from an application endpoint: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2012: A cancel toast message was received from an application endpoint: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A cancel toast message was received from an application endpoint: %1 [AppUserModelId] %2 [NotificationTrackingId].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32

Event ID 2013: A clear toast message was received from an application endpoint: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A clear toast message was received from an application endpoint: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2014: A remove toast message was received from an application endpoint: AppUserModelId [AppUserModelId] for Tag [Tag] and Group [Group].

#
Channel
Debug
Opcode
Info

Message #

A remove toast message was received from an application endpoint: %1 [AppUserModelId] for %2 [Tag] and %3 [Group].

Fields #

NameDescription
AppUserModelId UnicodeString
Tag UnicodeString
Group UnicodeString

Event ID 2015: A channel request failed due to an error: AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Debug
Opcode
Info

Message #

A channel request failed due to an error: %1 [AppUserModelId] %2 [ErrorCode].

Fields #

NameDescription
AppUserModelId UnicodeString
ErrorCode Int32

Event ID 2016: A clear mixview message was received from an application endpoint: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A clear mixview message was received from an application endpoint: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2025: A toast feedback callback was added: TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A toast feedback callback was added: %1 [NotificationTrackingId].

Fields #

NameDescription
TrackingId UInt32

Event ID 2026: A toast feedback callback was removed: TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A toast feedback callback was removed: %1 [NotificationTrackingId].

Fields #

NameDescription
TrackingId UInt32

Event ID 2027: A toast feedback callback was invoked: TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A toast feedback callback was invoked: %1 [NotificationTrackingId].

Fields #

NameDescription
TrackingId UInt32

Event ID 2028: A scheduled toast was added: PackageFullName [PackageFullName] AppUserModelID [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A scheduled toast was added: %1 [PackageFullName] %2 [AppUserModelId].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString
TimerId GUID
Duetime FILETIME

Event ID 2029: A scheduled toast was removed: PackageFullName [PackageFullName] AppUserModelID [AppUserModelID].

#
Channel
Debug
Opcode
Info

Message #

A scheduled toast was removed: %1 [PackageFullName] %2 [AppUserModelID].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString

Event ID 2030: A scheduled toast is about to be raised: AppUserModelID [AppUserModelID] TimerId [TimerId] Duetime [Duetime].

#
Channel
Debug
Opcode
Info

Message #

A scheduled toast is about to be raised: %1 [AppUserModelID] %2 [TimerId] %3 [Duetime].

Fields #

NameDescription
AppUserModelID UnicodeString
TimerId GUID
Duetime FILETIME

Event ID 2031: A background task to application mapping has been added: AppUserModelID [AppUserModelID] EventId [EventId].

#
Channel
Debug
Opcode
Info

Message #

A background task to application mapping has been added: %1 [AppUserModelID]  %2 [EventId].

Fields #

NameDescription
AppUserModelID UnicodeString
EventId GUID

Event ID 2032: A background task to application mapping has been removed: AppUserModelID [AppUserModelID] EventId [EventId].

#
Channel
Debug
Opcode
Info

Message #

A background task to application mapping has been removed: %1 [AppUserModelID]  %2 [EventId].

Fields #

NameDescription
AppUserModelID UnicodeString
EventId GUID

Event ID 2033: A raw notification has activated a background task: AppUserModelID [AppUserModelID] EventId [EventId] NotificationId [NotificationID].

#
Channel
Operational
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

A raw notification has activated a background task: %1 [AppUserModelID] %2 [EventId] %3 [NotificationID].

Fields #

NameDescription
AppUserModelID UnicodeString
EventId GUID
NotificationId UInt32

Event ID 2034: A raw notification has activated a system task: AppUserModelID [AppUserModelID].

#
Channel
Debug
Opcode
Info

Message #

A raw notification has activated a system task: %1 [AppUserModelID].

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 2035: A scheduled tile was added: PackageFullName [PackageFullName] AppUserModelID [AppUserModelId] TimerId [Cookie].

#
Channel
Debug
Opcode
Info

Message #

A scheduled tile was added: %1 [PackageFullName] %2 [AppUserModelId] %3 [Cookie].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString
TimerId GUID
Duetime FILETIME

Event ID 2036: A scheduled tile was removed: PackageFullName [PackageFullName] AppUserModelID [AppUserModelId] TimerId [Cookie].

#
Channel
Debug
Opcode
Info

Message #

A scheduled tile was removed: %1 [PackageFullName] %2 [AppUserModelId] %3 [Cookie].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString
TimerId GUID

Event ID 2037: A scheduled tile is being raised: AppUserModelID [AppUserModelId] TimerId [Cookie].

#
Channel
Debug
Opcode
Info

Message #

A scheduled tile is being raised: %1 [AppUserModelId] %2 [Cookie].

Fields #

NameDescription
AppUserModelID UnicodeString
TimerId GUID
Duetime FILETIME

Event ID 2038: A scheduled tile was removed because the number of scheduled tiles per app exceeded maximum queue size: AppUserModelID [AppUserModelId] TimerId [Cookie].

#
Channel
Debug
Opcode
Info

Message #

A scheduled tile was removed because the number of scheduled tiles per app exceeded maximum queue size: %1 [AppUserModelId] %2 [Cookie].

Fields #

NameDescription
AppUserModelID UnicodeString
TimerId GUID
Duetime FILETIME

Event ID 2039: A periodic update has been set: PackageFullName [PackageFullName] AppUserModelID [AppUserModelId] NotificationType [Type].

#
Channel
Debug
Opcode
Info

Message #

A periodic update has been set: %1 [PackageFullName] %2 [AppUserModelId] %3 [Type].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString
NotificationType UInt32
TimerId GUID
URL UnicodeString

Event ID 2040: A periodic update has been reset: PackageFullName [PackageFullName] AppUserModelID [AppUserModelId] NotificationType [Type].

#
Channel
Debug
Opcode
Info

Message #

A periodic update has been reset: %1 [PackageFullName] %2 [AppUserModelId] %3 [Type].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelID UnicodeString
NotificationType UInt32

Event ID 2041: A periodic update has started polling URL: AppUserModelID [AppUserModelId] NotificationType [Type].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Start

Message #

A periodic update has started polling URL: %1 [AppUserModelId] %2 [Type].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
TimerId GUID

Event ID 2042: A periodic update has finished polling URL: AppUserModelID [AppUserModelId] NotificationType [Type].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has finished polling URL: %1 [AppUserModelId] %2 [Type].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32

Event ID 2043: A periodic update has rejected polling URL because size of notification exceeded maximum: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has rejected polling URL because size of notification exceeded maximum: %1 [AppUserModelId] %2 [Type] %3 [URL].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString

Event ID 2044: A periodic update has rejected polling URL due to mobile broadband connection such as roaming or reaching quota : AppUserModelID [AppUserModelId] NotificationType [Type].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has rejected polling URL due to mobile broadband connection such as roaming or reaching quota : %1 [AppUserModelId] %2 [Type].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32

Event ID 2045: A periodic update has failed polling URL.

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Description

A periodic update has failed polling URL. Please refer error description for detail: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL] Error [Error].

Message #

A periodic update has failed polling URL. Please refer error description for detail: %1 [AppUserModelId] %2 [Type] %3 [URL] %4 [Error].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString
Error Int32

Event ID 2046: A background task application mapping entry has been removed: AppUserModelID [AppUserModelID].

#
Channel
Debug
Opcode
Info

Message #

A background task application mapping entry has been removed: %1 [AppUserModelID].

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 2047: Notification API call for AppUserModelId [AppUserModelId] failed.

#
Channel
Debug
Opcode
Info

Description

Notification API call for AppUserModelId [AppUserModelId] failed. If you are logged into multiple sessions as the same user, please logoff and use a single user session. If you are using the Visual Studio debugging simulator, exit the simulator to resolve this error.

Message #

Notification API call for %1 [AppUserModelId] failed. If you are logged into multiple sessions as the same user, please logoff and use a single user session.  If you are using the Visual Studio debugging simulator, exit the simulator to resolve this error.

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2048: A raw notification has failed to activate a background task: AppUserModelID [AppUserModelID] EventId [EventId] ErrorCode [ErrorCode].

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

A raw notification has failed to activate a background task: %1 [AppUserModelID] %2 [EventId] %3 [ErrorCode].

Fields #

NameDescription
AppUserModelID UnicodeString
EventId GUID
ErrorCode UInt32

Event ID 2049: A periodic update has found HTTP Status Code rather than 200: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL] HttpStatusCode [HTTP Status Code].

#
Channel
Debug
Task
PeriodicPoll

Message #

A periodic update has found HTTP Status Code rather than 200: %1 [AppUserModelId] %2 [Type] %3 [URL] %4 [HTTP Status Code].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString
HttpStatusCode UInt32

Event ID 2050: A periodic update has failed polling URL because X-WNS-TAG header is invalid: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has failed polling URL because X-WNS-TAG header is invalid: %1 [AppUserModelId] %2 [Type] %3 [URL].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString

Event ID 2051: A periodic update has failed polling URL because X-WNS-EXPIRY header is invalid: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL].

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has failed polling URL because X-WNS-EXPIRY header is invalid: %1 [AppUserModelId] %2 [Type] %3 [URL].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString

Event ID 2052: A periodic update of Type NotificationType for AppUserModelId AppUserModelID at URL URL has been skipped due to settings.

#
Channel
Debug
Task
PeriodicPoll
Opcode
Stop

Description

A periodic update of Type NotificationType for AppUserModelId AppUserModelID at URL URL has been skipped due to settings. Error Code: Error.

Message #

A periodic update of Type %2 for AppUserModelId %1  at URL %3 has been skipped due to settings.  Error Code: %4

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString
Error Int32

Event ID 2053: A periodic update has failed polling URL because X-WNS-GROUP header is invalid: AppUserModelID [AppUserModelId] NotificationType [Type] URL [URL].

#
Channel
Operational
Task
PeriodicPoll
Opcode
Stop

Message #

A periodic update has failed polling URL because X-WNS-GROUP header is invalid: %1 [AppUserModelId] %2 [Type] %3 [URL].

Fields #

NameDescription
AppUserModelID UnicodeString
NotificationType UInt32
URL UnicodeString

Event ID 2100: A cloud notification was dropped because the following channel is not valid: ChannelId [ChannelId].

#
Channel
Debug
Opcode
Info

Message #

A cloud notification was dropped because the following channel is not valid: %1 [ChannelId].

Fields #

NameDescription
ChannelId UnicodeString

Event ID 2101: A notification was dropped because the expiration time was in the past: TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because the expiration time was in the past: %1 [NotificationTrackingId].

Fields #

NameDescription
TrackingId UInt32

Event ID 2102: A notification was dropped because of global settings: RequestFlags [PolicyLevel] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because of global settings: %1 [PolicyLevel] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
RequestFlags UInt32
TrackingId UInt32
NotificationType UnicodeString

Event ID 2103: A notification was dropped because cloud notifications are disabled globally: RequestFlags [PolicyLevel] TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because cloud notifications are disabled globally: %1 [PolicyLevel]  %2 [NotificationTrackingId].

Fields #

NameDescription
RequestFlags UInt32
TrackingId UInt32

Event ID 2104: A notification was dropped because of application settings: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because of application settings: %1 [AppUserModelId] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UnicodeString

Event ID 2105: A notification was dropped because the application does not have the network capability: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because the application does not have the network capability: %1 [AppUserModelId] %2 [NotificationTrackingId].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32

Event ID 2106: A notification was dropped because the application does not have the capability for the type: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [N...

#
Channel
Debug
Opcode
Info

Description

A notification was dropped because the application does not have the capability for the type: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

Message #

A notification was dropped because the application does not have the capability for the type: %1 [AppUserModelId] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UnicodeString

Event ID 2107: A notification was dropped because the current network is costly: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because the current network is costly: %1 [AppUserModelId] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UInt32

Event ID 2108: A notification was dropped because the mobile broadband cap has been reached: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because the mobile broadband cap has been reached: %1 [AppUserModelId] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UInt32

Event ID 2109: Network traffic related to notifications was attributed to the following AppUserModelId: AppUserModelId.

#
Channel
Debug
Opcode
Info

Description

Network traffic related to notifications was attributed to the following AppUserModelId: AppUserModelId. NotificationType [NotificationType] Size [Size] NetworkType [NetworkType].

Message #

Network traffic related to notifications was attributed to the following AppUserModelId: %1. %2 [NotificationType] %3 [Size] %4 [NetworkType].

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UInt32
Size UInt64
NetworkType UInt32

Event ID 2110: A notification was dropped because cloud notifications are disabled for the application: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [Notifi...

#
Channel
Debug
Opcode
Info

Description

A notification was dropped because cloud notifications are disabled for the application: AppUserModelId [AppUserModelId] TrackingId [NotificationTrackingId] NotificationType [NotificationType].

Message #

A notification was dropped because cloud notifications are disabled for the application: %1 [AppUserModelId] %2 [NotificationTrackingId] %3 [NotificationType].

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UnicodeString

Event ID 2111: A notification was dropped because the application is not registered: AppUserModelId [AppUserModelId] NotificationType [NotificationType].

#
Channel
Debug
Opcode
Info

Message #

A notification was dropped because the application is not registered: %1 [AppUserModelId] %2 [NotificationType]

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UnicodeString

Event ID 2112: A NotificationType notification with trackingid TrackingId is getting posted for the application AppUserModelId with setting override.

#
Channel
Debug
Opcode
Info

Message #

A %3 notification with trackingid %2 is getting posted for the application %1 with setting override.

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UnicodeString

Event ID 2150: An application setting was changed: AppUserModelId [AppUserModelId] SettingType [SettingType] Enabled [Enabled].

#
Channel
Debug
Opcode
Info

Message #

An application setting was changed: %1 [AppUserModelId] %2 [SettingType] %3 [Enabled].

Fields #

NameDescription
AppUserModelId UnicodeString
SettingType UInt32
Enabled Boolean

Event ID 2151: A group policy setting was changed.

#
Channel
Debug
Opcode
Info

Description

A group policy setting was changed. Notification Service connection was updated: Enabled [Enabled].

Message #

A group policy setting was changed. Notification Service connection was updated: %1 [Enabled].

Fields #

NameDescription
Enabled Boolean

Event ID 2152: An application setting was queried: AppUserModelId [AppUserModelId] SettingType [SettingType] Enabled [Enabled].

#
Channel
Debug
Opcode
Info

Message #

An application setting was queried: %1 [AppUserModelId] %2 [SettingType] %3 [Enabled].

Fields #

NameDescription
AppUserModelId UnicodeString
SettingType UInt32
Enabled Boolean

Event ID 2153: A global setting was changed: SettingType [SettingType] Enabled [Enabled] PolicyLevel [PolicyLevel].

#
Channel
Debug
Opcode
Info

Message #

A global setting was changed: %1 [SettingType] %2 [Enabled] %3 [PolicyLevel].

Fields #

NameDescription
SettingType UInt32
Enabled Boolean
PolicyLevel UInt32

Event ID 2154: A global setting was queried: SettingType [SettingType] Enabled [Enabled] PolicyLevel [PolicyLevel].

#
Channel
Debug
Opcode
Info

Message #

A global setting was queried: %1 [SettingType] %2 [Enabled] %3 [PolicyLevel].

Fields #

NameDescription
SettingType UInt32
Enabled Boolean
PolicyLevel UInt32

Event ID 2155: The list of apps with capability: SettingType [SettingType] was requested.

#
Channel
Debug
Opcode
Info

Message #

The list of apps with capability: %1 [SettingType] was requested.

Fields #

NameDescription
SettingType UInt32

Event ID 2156: Callback registered for SettingType [SettingType] with Cookie Cookie [Cookie Value].

#
Channel
Debug
Opcode
Info

Message #

Callback registered for %1 [SettingType] with Cookie %2 [Cookie Value].

Fields #

NameDescription
SettingType UInt32
Cookie UInt32

Event ID 2157: Callback unregistered : Callback_unregistered [Cookie Value].

#
Channel
Debug
Opcode
Info

Message #

Callback unregistered : %1 [Cookie Value].

Fields #

NameDescription
Cookie UInt32

Event ID 2158: End of clearing Tile Notification Queues and Image Cache.

#
Channel
Debug
Task
ClearAll
Opcode
Stop

Event ID 2159: Mobile Broadband Tile Cap Queried: Mobile_Broadband_Tile_Cap_Queried [Cap Value (Bytes)].

#
Channel
Debug
Opcode
Info

Message #

Mobile Broadband Tile Cap Queried: %1 [Cap Value (Bytes)].

Fields #

NameDescription
SettingsValue UInt64

Event ID 2160: Mobile Broadband Tile Cap Changed: Mobile_Broadband_Tile_Cap_Changed [Cap Value (Bytes)].

#
Channel
Debug
Opcode
Info

Message #

Mobile Broadband Tile Cap Changed: %1 [Cap Value (Bytes)].

Fields #

NameDescription
SettingsValue UInt64

Event ID 2161: Mobile Broadband Tile Usage Queried: Mobile_Broadband_Tile_Usage_Queried [Usage Value (Bytes)].

#
Channel
Debug
Opcode
Info

Message #

Mobile Broadband Tile Usage Queried: %1 [Usage Value (Bytes)].

Fields #

NameDescription
SettingsValue UInt64

Event ID 2162: Mobile Broadband Reset Dates Queried.

#
Channel
Debug
Opcode
Info

Event ID 2163: The list of apps with capability: SettingType [SettingType] in Package: PackageFamilyName [PackageFamilyName] was requested.

#
Channel
Debug
Opcode
Info

Message #

The list of apps with capability: %1 [SettingType] in Package: %2 [PackageFamilyName] was requested.

Fields #

NameDescription
SettingType UInt32
PackageFamilyName UnicodeString

Event ID 2164: Start of clearing Tile Notification Queues and Image Cache.

#
Channel
Debug
Task
ClearAll
Opcode
Start

Event ID 2165: Mobile Broadband Cap Enforcement Callback invoked: Enabled [Enabled].

#
Channel
Debug
Opcode
Info

Message #

Mobile Broadband Cap Enforcement Callback invoked: %1 [Enabled].

Fields #

NameDescription
Enabled Boolean

Event ID 2166: Toasts have been Temporarily Suspended until WakeupTime [UTC FILETIME].

#
Channel
Debug
Opcode
Info

Message #

Toasts have been Temporarily Suspended until %1 [UTC FILETIME].

Fields #

NameDescription
WakeupTime FILETIME
IsValid Boolean

Event ID 2167: Toast Temporary Suspend Time was queried: Is Suspended?

#
Channel
Debug
Opcode
Info

Description

Toast Temporary Suspend Time was queried: Is Suspended? IsValid wakeupTime? WakeupTime [UTC FILETIME].

Message #

Toast Temporary Suspend Time was queried: Is Suspended? %2 wakeupTime? %1 [UTC FILETIME].

Fields #

NameDescription
WakeupTime FILETIME
IsValid Boolean

Event ID 2168: Toast Wakeup Timer has fired.

#
Channel
Debug
Opcode
Info

Event ID 2169: The list of Polling apps in Package: PackageFamilyName [PackageFamilyName] was requested.

#
Channel
Debug
Opcode
Info

Message #

The list of Polling apps in Package: %1 [PackageFamilyName] was requested.

Fields #

NameDescription
PackageFamilyName UnicodeString

Event ID 2170: A Setting Sync was scheduled: PackageFamilyName [PackageFamilyName] CollectionId [Collection ID].

#
Channel
Debug
Opcode
Info

Message #

A Setting Sync was scheduled: %1 [PackageFamilyName] %2 [Collection ID].

Fields #

NameDescription
PackageFamilyName UnicodeString
CollectionId UnicodeString

Event ID 2171: A call to the settings endpoint happened to unblock all channels for all types.

#
Channel
Operational
Opcode
Info

Event ID 2200: A channel request was not allowed because of global settings: RequestFlags [PolicyLevel] AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A channel request was not allowed because of global settings: %1 [PolicyLevel] %2 [AppUserModelId].

Fields #

NameDescription
RequestFlags UInt32
AppUserModelId UnicodeString

Event ID 2201: A channel request was not allowed because the application does not have the network capability: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A channel request was not allowed because the application does not have the network capability: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2202: A NotificationType notification with NotificationTrackingId TrackingId was dropped because appropriate privilege is not held.

#
Channel
Debug
Opcode
Info

Description

A NotificationType notification with NotificationTrackingId TrackingId was dropped because appropriate privilege is not held. Please check out Mosh Debugger is running on your machine.

Message #

A %2 notification with NotificationTrackingId %1 was dropped because appropriate privilege is not held. Please check out Mosh Debugger is running on your machine.

Fields #

NameDescription
TrackingId UInt32
NotificationType UnicodeString

Event ID 2203: A NotificationType notification with NotificationTrackingId TrackingId is being delivered to application AppUserModelId.

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

A %3 notification with NotificationTrackingId %2 is being delivered to application %1.

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32
NotificationType UnicodeString

Event ID 2250: Notification channels associated with a package are able to receive raw notifications: [PackageFullName] PackageFullName.

#
Channel
Debug
Opcode
Info

Message #

Notification channels associated with a package are able to receive raw notifications: [PackageFullName] %1

Fields #

NameDescription
PackageFullName UnicodeString

Event ID 2300: The following application was added to the lock screen: PackageFullName [PackageFullName] PackageRelativeApplicationId [PackageRelativeApplicationId].

#
Channel
Debug
Opcode
Info

Message #

The following application was added to the lock screen: %1 [PackageFullName] %2 [PackageRelativeApplicationId].

Fields #

NameDescription
PackageFullName UnicodeString
PackageRelativeApplicationId UnicodeString

Event ID 2301: The following application was removed from the lock screen: PackageFullName [PackageFullName] PackageRelativeApplicationId [PackageRelativeApplicationId].

#
Channel
Debug
Opcode
Info

Message #

The following application was removed from the lock screen: %1 [PackageFullName] %2 [PackageRelativeApplicationId].

Fields #

NameDescription
PackageFullName UnicodeString
PackageRelativeApplicationId UnicodeString

Event ID 2400: System application was registered with the following paramaeters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId] Capabilities [Settings] WNFEventName [WNFEventName].

#
Channel
Debug
Opcode
Info

Message #

System application was registered with the following paramaeters: %1 [PackageFullName] %2 [AppUserModelId] %3 [Settings] %5 [WNFEventName].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelId UnicodeString
Capabilities UInt32
WNFEventNameLength UInt32
WNFEventName Binary

Event ID 2401: System application was unregistered with the following parameters: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

System application was unregistered with the following parameters: %1 [AppUserModelId]

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2402: task_02402

#
Channel
Debug
Opcode
Info

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2403: task_02403

#
Channel
Debug
Opcode
Info

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2404: Phone VoIP application was registered with the following parameters: AppUserModelId [AppUserModelId] PhoneVoipAgentId [PhoneVoipAgentId].

#
Channel
Debug
Opcode
Info

Message #

Phone VoIP application was registered with the following parameters: %1 [AppUserModelId] %2 [PhoneVoipAgentId].

Fields #

NameDescription
AppUserModelId UnicodeString
PhoneVoipAgentId GUID

Event ID 2405: Phone VoIP application was unregistered with the following parameters: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

Phone VoIP application was unregistered with the following parameters: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2406: The Windows Push Notification Platform has received a phone legacy channel request with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserM...

#
Channel
Debug
Task
RequestChannel
Opcode
Start

Description

The Windows Push Notification Platform has received a phone legacy channel request with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId] ChannelName [ChannelName] ServiceName [ServiceName].

Message #

The Windows Push Notification Platform has received a phone legacy channel request with the following parameters: %1 [PackageFullName] %2 [AppUserModelId] %3 [ChannelName] %4 [ServiceName].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelId UnicodeString
ChannelName UnicodeString
ServiceName UnicodeString

Event ID 2407: PhoneLegacy push notification is being processed: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

PhoneLegacy push notification is being processed: ChannelId [%1], NotificationType [%2], TrackingId [%3] AppId [%4]

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString

Event ID 2408: PhoneLegacy voip notification is being processed: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId], PhoneVoipAgentId [PhoneVoipAgentId].

#
Channel
Debug
Opcode
Info

Message #

PhoneLegacy voip notification is being processed: ChannelId [%1], NotificationType [%2], TrackingId [%3] AppId [%4], PhoneVoipAgentId [%5]

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
PhoneVoipAgentId GUID

Event ID 2409: A connection status callback was added: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A connection status callback was added: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2410: A connection status callback was removed: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A connection status callback was removed: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2411: A connection status callback was updated: AppUserModelId [AppUserModelId].

#
Channel
Debug
Opcode
Info

Message #

A connection status callback was updated: %1 [AppUserModelId].

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 2412: A connection status was delivered to a callback: AppUserModelId [AppUserModelId] IsConnected [IsConnected] ErrorCode [ErrorCode].

#
Channel
Debug
Opcode
Info

Message #

A connection status was delivered to a callback: %1 [AppUserModelId] %2 [IsConnected] %3 [ErrorCode].

Fields #

NameDescription
AppUserModelId UnicodeString
IsConnected Boolean
ErrorCode Int32

Event ID 2413: An application was registered with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId] AppSettings [Settings] AppType [AppType] ErrorCode [ErrorCode].

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

An application was registered with the following parameters: %1 [PackageFullName] %2 [AppUserModelId] %3 [Settings] %4 [AppType] %5 [ErrorCode].

Fields #

NameDescription
PackageFullName UnicodeStringAn application was registered with the following parameters.
AppUserModelId UnicodeString
AppSettings UInt32
AppType UInt32
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 2413,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036846386688,
    "time_created": "2026-05-29T16:34:10.5529680+00:00",
    "event_record_id": 329,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5356
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "PackageFullName": "System",
    "AppUserModelId": "Windows.SystemToast.WindowsTip",
    "AppSettings": "9471",
    "AppType": "1073741824",
    "ErrorCode": "0"
  },
  "message": "An application was registered with the following parameters: System [PackageFullName] Windows.SystemToast.WindowsTip [AppUserModelId] 0x24FF [Settings] 1073741824 [AppType] The operation completed successfully. [ErrorCode]."
}

Event ID 2414: An application resgistration was updated with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId] AppSettings [Settings] AppType [AppType] ErrorCode [Err...

#
Channel
Operational
Level
Informational
Opcode
Info

Description

An application resgistration was updated with the following parameters: PackageFullName [PackageFullName] AppUserModelId [AppUserModelId] AppSettings [Settings] AppType [AppType] ErrorCode [ErrorCode].

Message #

An application resgistration was updated with the following parameters: %1 [PackageFullName] %2 [AppUserModelId] %3 [Settings] %4 [AppType] %5 [ErrorCode].

Fields #

NameDescription
PackageFullName UnicodeString
AppUserModelId UnicodeString
AppSettings UInt32
AppType UInt32
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "88CD9180-4491-4640-B571-E3BEE2527943",
    "event_source_name": "",
    "event_id": 2414,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036863164928,
    "time_created": "2026-02-14T21:02:02.291561+00:00",
    "event_record_id": 1143,
    "correlation": {
      "ActivityID": "EAB545B2-3409-4E30-9F30-BC4AC7110E3B"
    },
    "execution": {
      "process_id": 8924,
      "thread_id": 7064
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1104"
    }
  },
  "event_data": {
    "PackageFullName": "Microsoft.DesktopAppInstaller_1.27.470.0_x64__8wekyb3d8bbwe",
    "AppUserModelId": "Microsoft.DesktopAppInstaller_8wekyb3d8bbwe!WinGetMCPServer",
    "AppSettings": 67141376,
    "AppType": 268435456,
    "ErrorCode": 0
  },
  "message": ""
}

Event ID 2415: An application was unregistered with the following parameters: AppUserModelId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

An application was unregistered with the following parameters: %1 [AppUserModelId] %2 [ErrorCode]

Fields #

NameDescription
AppUserModelId UnicodeStringAn application was unregistered with the following parameters.
ErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 2415,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036846386688,
    "time_created": "2026-06-13T05:51:28.3191580+00:00",
    "event_record_id": 334,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 7832
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "AppUserModelId": "Windows.Defender.MpUxDlp",
    "ErrorCode": "0"
  },
  "message": "An application was unregistered with the following parameters: Windows.Defender.MpUxDlp [AppUserModelId] The operation completed successfully. [ErrorCode]"
}

Event ID 2416: A local notification was received from AppUserModelId [AppUserModelId] with a NotificationId [NotificationId] through an application endpoint.

#
Channel
Operational
Level
Informational

Message #

A local notification was received from %1 [AppUserModelId] with a %2 [NotificationId] through an application endpoint.

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 2416,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T17:04:07.6582837+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "AppUserModelId": "Windows.Defender.SecurityCenter",
    "NotificationId": "0"
  }
}

Event ID 2416: A local notification was received from AppUserModelId [AppUserModelId] with a NotificationId [NotificationId] through an application endpoint

#
Channel
Operational
Level
4

Description

A local notification was received from [AppUserModelId] with a [NotificationId] through an application endpoint.

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 2416,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T17:04:07.6582837+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "AppUserModelId": "Windows.Defender.SecurityCenter",
    "NotificationId": "0"
  }
}

Event ID 2417: A local notification failed to be submitted to threadpool: ErrorCode [HResult]

#
Channel
Operational

Message #

A local notification failed to be submitted to threadpool: %1 [HResult]

Fields #

NameDescription
ErrorCode Int32

Event ID 2418: A local notification was submitted to threadpool: AppUserModelId [AppUserModelId] NotificationType [NotificationType] TrackingId [NotificationTrackingId] NotificationSource [NotificationSource].

#
Channel
Operational
Level
Informational
Task
NewLocalNotificationArrival
Opcode
Start

Message #

A local notification was submitted to threadpool: %1 [AppUserModelId] %2 [NotificationType] %3 [NotificationTrackingId] %4 [NotificationSource].

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
NotificationSource UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 2418,
    "level": 4,
    "task": 18,
    "opcode": 1,
    "time_created": "2026-05-27T17:04:07.6605475+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "NotificationType": "toast",
    "TrackingId": "26",
    "NotificationSource": "0",
    "AppUserModelId": "Windows.Defender.SecurityCenter"
  }
}

Event ID 2418: A local notification was submitted to threadpool: AppUserModelId [AppUserModelId] NotificationType [NotificationType] TrackingId [NotificationTrackingId] NotificationSource [NotificationSource]

#
Channel
Operational
Level
4
Task
NewLocalNotificationArrival
Opcode
Start

Description

A local notification was submitted to threadpool: [AppUserModelId] [NotificationType] [NotificationTrackingId] [NotificationSource].

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
NotificationSource UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 2418,
    "level": 4,
    "task": 18,
    "opcode": 1,
    "time_created": "2026-05-27T17:04:07.6605475+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "NotificationType": "toast",
    "TrackingId": "26",
    "NotificationSource": "0",
    "AppUserModelId": "Windows.Defender.SecurityCenter"
  }
}

Event ID 2419: A raw notification has activated a system task: AppUserModelID [AppUserModelID]

#
Channel
Operational

Message #

A raw notification has activated a system task: %1 [AppUserModelID].

Fields #

NameDescription
AppUserModelID UnicodeString

Event ID 3000: Tile session creation is requested for ProcessName endpoint Object.

#
Channel
Operational
Level
Informational
Task
TileSessionCreate
Opcode
Start

Message #

Tile session creation is requested for %2 endpoint %1.

Fields #

NameDescription
Object Pointer
ProcessName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3000,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 1,
    "keywords": -9223372036854773760,
    "time_created": "2026-05-29T16:34:11.9218720+00:00",
    "event_record_id": 330,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5428
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Object": "0x1f0839f91b0",
    "ProcessName": "C:\\Windows\\explorer.exe"
  },
  "message": "Tile session creation is requested for C:\\Windows\\explorer.exe endpoint 0x1f0839f91b0."
}

Event ID 3001: Tile session creation is finished for ProcessName from endpoint Endpoint with result Error, and SessionId is assigned as session id.

#
Channel
Operational
Level
Informational
Task
TileSessionCreate
Opcode
Stop

Description

Tile session creation is finished for ProcessName from endpoint Endpoint with result Error, and SessionId is assigned as session id. Queued Closes = QueuedTileCloses, Queued Cleanups = QueuedTileCleanups.

Message #

Tile session creation is finished for %4 from endpoint %1 with result %3, and %2 is assigned as session id. Queued Closes = %5, Queued Cleanups = %6

Fields #

NameDescription
Endpoint Pointer
SessionId UInt32
Error Int32
ProcessName UnicodeString
QueuedTileCloses Int32
QueuedTileCleanups Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3001,
    "version": 0,
    "level": 4,
    "task": 1,
    "opcode": 2,
    "keywords": -9223372036854773760,
    "time_created": "2026-05-29T16:34:11.9220010+00:00",
    "event_record_id": 331,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5428
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Endpoint": "0x1f0839f91b0",
    "SessionId": "3",
    "Error": "0",
    "ProcessName": "C:\\Windows\\explorer.exe",
    "QueuedTileCloses": "0",
    "QueuedTileCleanups": "0"
  },
  "message": "Tile session creation is finished for C:\\Windows\\explorer.exe from endpoint 0x1f0839f91b0 with result The operation completed successfully., and 3 is assigned as session id. Queued Closes = 0, Queued Cleanups = 0"
}

Event ID 3002: Tile session SessionId is being updated.

#
Channel
Debug
Task
TileSessionUpdate
Opcode
Start

Message #

Tile session %1 is being updated.

Fields #

NameDescription
SessionId UInt32

Event ID 3003: Tile session SessionId is updated with error code Error.

#
Channel
Debug
Task
TileSessionUpdate
Opcode
Stop

Message #

Tile session %1 is updated with error code %3.

Fields #

NameDescription
SessionId UInt32
Count UInt32
Error Int32

Event ID 3004: Tile session SessionId is being closed.

#
Channel
Operational
Level
Informational
Task
TileSessionClose
Opcode
Start

Message #

Tile session %1 is being closed

Fields #

NameDescription
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3004,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 1,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5167410+00:00",
    "event_record_id": 335,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2560
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "3"
  },
  "message": "Tile session 3 is being closed"
}

Event ID 3005: Tile session SessionId is closed with error code Error.

#
Channel
Operational
Level
Informational
Task
TileSessionClose
Opcode
Stop

Message #

Tile session %1 is closed with error code %2.

Fields #

NameDescription
SessionId UInt32
Error Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3005,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 2,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5167489+00:00",
    "event_record_id": 336,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2560
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "3",
    "Error": "0"
  },
  "message": "Tile session 3 is closed with error code The operation completed successfully.."
}

Event ID 3006: Toast session creation is requested for ProcessName from endpoint Object.

#
Channel
Operational
Level
Informational
Task
ToastSessionCreate
Opcode
Start

Message #

Toast session creation is requested for %2 from endpoint %1.

Fields #

NameDescription
Object Pointer
ProcessName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3006,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 1,
    "keywords": -9223372036854773760,
    "time_created": "2026-05-29T16:33:59.0114193+00:00",
    "event_record_id": 324,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5356
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Object": "0x1f081cddde0",
    "ProcessName": "C:\\Windows\\System32\\svchost.exe"
  },
  "message": "Toast session creation is requested for C:\\Windows\\System32\\svchost.exe from endpoint 0x1f081cddde0."
}

Event ID 3007: Toast session creation is finished for ProcessName from endpoint Endpoint with result Error, and SessionId is assigned as session id.

#
Channel
Operational
Level
Informational
Task
ToastSessionCreate
Opcode
Stop

Message #

Toast session creation is finished for %4 from endpoint %1 with result %3, and %2 is assigned as session id.

Fields #

NameDescription
Endpoint Pointer
SessionId UInt32
Error Int32
ProcessName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3007,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 2,
    "keywords": -9223372036854773760,
    "time_created": "2026-05-29T16:33:59.0114588+00:00",
    "event_record_id": 325,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 5356
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Endpoint": "0x1f081cddde0",
    "SessionId": "1",
    "Error": "0",
    "ProcessName": "C:\\Windows\\System32\\svchost.exe"
  },
  "message": "Toast session creation is finished for C:\\Windows\\System32\\svchost.exe from endpoint 0x1f081cddde0 with result The operation completed successfully., and 1 is assigned as session id."
}

Event ID 3008: Toast session SessionId is being closed.

#
Channel
Operational
Level
Informational
Task
ToastSessionClose
Opcode
Start

Message #

Toast session %1 is being closed

Fields #

NameDescription
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3008,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 1,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5914694+00:00",
    "event_record_id": 338,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2560
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "1"
  },
  "message": "Toast session 1 is being closed"
}

Event ID 3009: Toast session SessionId is closed with error code Error.

#
Channel
Operational
Level
Informational
Task
ToastSessionClose
Opcode
Stop

Message #

Toast session %1 is closed with error code %2.

Fields #

NameDescription
SessionId UInt32
Error Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3009,
    "version": 0,
    "level": 4,
    "task": 5,
    "opcode": 2,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5914800+00:00",
    "event_record_id": 339,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2560
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "1",
    "Error": "0"
  },
  "message": "Toast session 1 is closed with error code The operation completed successfully.."
}

Event ID 3010: Started tracking Notification Request performance.

#
Channel
Debug
Task
RequestNotification
Opcode
Start

Event ID 3011: Finished tracking Notification Request performance.

#
Channel
Debug
Task
RequestNotification
Opcode
Stop

Event ID 3012: Toast with notification tracking id TrackingId is delivered to AppUserModelId on session SessionId.

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

Toast with notification tracking id %1 is delivered to %2 on session %3.

Fields #

NameDescription
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID

Event ID 3013: NotificationType with notification tracking id TrackingId is delivered to AppUserModelId.

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

%1 with notification tracking id %2 is delivered to %3.

Fields #

NameDescription
NotificationType UnicodeString
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID
ErrorCode Int32
SessionErrorCode Int32

Event ID 3014: Tile queue entry is created for AppUserModelId.

#
Channel
Debug
Opcode
Info

Message #

Tile queue entry is created for %1.

Fields #

NameDescription
AppUserModelId UnicodeString

Event ID 3015: Tile notification id NotificationId for AppUserModelId is stored at QueueIndex in queue.

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

Tile notification id %2 for %1 is stored at %3 in queue.

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationId UInt32
QueueIndex UInt16

Event ID 3016: Tile notification id OverridingNotificationId overrided existing notification id OverridedNotificationId.

#
Channel
Debug
Opcode
Info

Message #

Tile notification id %2 overrided existing notification id %1.

Fields #

NameDescription
OverridedNotificationId UInt32
OverridingNotificationId UInt32

Event ID 3017: This is a verbose debug event that dumps Tile Queue information.

#
Channel
Debug
Opcode
Info

Fields #

NameDescription
AppUserModelId UnicodeString
SessionMask UInt32
Flag UInt16
UpdateIndex UInt16
KeystoneNotificationId UInt32
KeystoneFlag UInt16
Appspace Int32

Event ID 3018: Badge notification id TrackingId is stored for AppUserModelId.

#
Channel
Debug
Task
NewCloudNotificationArrival

Message #

Badge notification id %2 is stored for %1.

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32

Event ID 3019: Tile image request RequestId has started.

#
Channel
Debug
Task
TileImageDownload
Opcode
Start

Message #

Tile image request %1 has started.

Fields #

NameDescription
RequestId UInt32
RequestCountInHighPriority UInt32
RequestCountInMedPriority UInt32
RequestCountInLowPriority UInt32

Event ID 3020: Tile image request RequestId has been canceled due to new request.

#
Channel
Debug
Task
TileImageDownload

Message #

Tile image request %1 has been canceled due to new request.

Fields #

NameDescription
RequestId UInt32

Event ID 3021: Tile image request for notification NotificationId in AppUserModelId contains URLCount URL.

#
Channel
Debug
Task
TileImageDownload

Message #

Tile image request for notification %3 in %2 contains %4 URL.

Fields #

NameDescription
PriorityIndex UInt32
AppUserModelId UnicodeString
NotificationId UInt32
URLCount UInt32
Flag UInt32

Event ID 3022: Image download request is being processed for first time: resource id [ResourceId], URL [URL].

#
Channel
Debug
Task
TileImageDownload

Message #

Image download request is being processed for first time: resource id [%1],  URL [%2]

Fields #

NameDescription
ResourceId UInt32
URL UnicodeString

Event ID 3023: Image download is complete for a single URL: notification id [NotificationId], resource id [ResourceId], local path [LocalPath], error code [ErrorCode], flags [Flag].

#
Channel
Debug
Task
TileImageDownload

Message #

Image download is complete for a single URL: notification id [%1], resource id [%2], local path [%3], error code [%4], flags [%5]

Fields #

NameDescription
NotificationId UInt32
ResourceId UInt32
LocalPath UnicodeString
ErrorCode Int32
Flag UInt32

Event ID 3024: Image download is complete for all URL with notification id [NotificationId].

#
Channel
Debug
Task
TileImageDownload
Opcode
Stop

Message #

Image download is complete for all URL with notification id [%1]

Fields #

NameDescription
NotificationId UInt32
Flag UInt32
Count UInt32
URLComplete UInt8

Event ID 3025: Processing initial batch on Image request for toast: AppUserModelId [AppUserModelId], Notification Id [NotificationId], UrlCount [URLCount], Flags [Flag].

#
Channel
Debug
Opcode
Info

Message #

Processing initial batch on Image request for toast: AppUserModelId [%1], Notification Id [%2], UrlCount [%3], Flags [%4]

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationId UInt32
URLCount UInt32
Flag UInt32

Event ID 3026: Processing Toast Image request URL: Resource Id [ResourceId], URL [URL].

#
Channel
Debug
Opcode
Info

Message #

Processing Toast Image request URL: Resource Id [%1], URL [%2]

Fields #

NameDescription
ResourceId UInt32
URL UnicodeString

Event ID 3027: Scheduling Image Download Task: [Slot Index] SlotIndex, [Notification Id] NotificationId, [Priority] BITSPriority, [IsTile] IsTile, [URL] URL.

#
Channel
Debug
Opcode
Info

Message #

Scheduling Image Download Task: [Slot Index] %1, [Notification Id] %2, [Priority] %3, [IsTile] %4, [URL] %5

Fields #

NameDescription
SlotIndex UInt32
NotificationId UInt32
BITSPriority UInt32
IsTile Boolean
URL UnicodeString

Event ID 3028: Completed Image Download Task: [Notification Id] NotificationId, [IsTile] IsTile, [Path] Path.

#
Channel
Debug
Opcode
Info

Message #

Completed Image Download Task: [Notification Id] %1, [IsTile] %2, [Path] %3

Fields #

NameDescription
NotificationId UInt32
IsTile Boolean
Path UnicodeString

Event ID 3029: Download image has failed: [Notification Id] NotificationId [Tile] IsTile [ErrorCode] ErrorCode [URL] URL.

#
Channel
Debug
Opcode
Info

Message #

Download image has failed: [Notification Id] %1 [Tile] %2 [ErrorCode] %3 [URL] %4

Fields #

NameDescription
NotificationId UInt32
IsTile Boolean
ErrorCode Int32
URL UnicodeString

Event ID 3030: Image resource is being processed.

#
Channel
Debug
Task
RequestResource
Opcode
Start

Event ID 3031: Image resource has been processed.

#
Channel
Debug
Task
RequestResource
Opcode
Stop

Event ID 3032: Clearing all tile notifiction is being processed.

#
Channel
Debug
Task
ClearAllTiles
Opcode
Start

Event ID 3033: Clearing all tile notifiction has been processed.

#
Channel
Debug
Task
ClearAllTiles
Opcode
Stop

Event ID 3034: Clearing all images is being processed.

#
Channel
Debug
Task
ClearAllImages
Opcode
Start

Event ID 3035: Clearing all images has been processed.

#
Channel
Debug
Task
ClearAllImages
Opcode
Stop

Event ID 3036: Image Download Manager policy is changed to IDM_Enabled.

#
Channel
Debug
Opcode
Info

Message #

Image Download Manager policy is changed to %1.

Fields #

NameDescription
IDM_Enabled Boolean

Event ID 3037: Detail event for tile session SessionId update.

#
Channel
Debug
Task
TileSessionUpdate
Opcode
Start

Message #

Detail event for tile session %1 update.

Fields #

NameDescription
SessionId UInt32
Count UInt32
UpdateControl Int8

Event ID 3038: Detail event at start of Notification Request performance tracking.

#
Channel
Debug
Task
RequestNotification
Opcode
Start

Fields #

NameDescription
Count UInt32
RequestControl AnsiString

Event ID 3039: Image Download Manager drop request due to newer request arrival.

#
Channel
Debug
Opcode
Info

Event ID 3040: Downloading image has failed because protocol is not supported: URL [URL].

#
Channel
Debug
Opcode
Info

Message #

Downloading image has failed because protocol is not supported: URL [%1]

Fields #

NameDescription
URL UnicodeString

Event ID 3041: Downloading image has failed because downloaded image it too big over maximum 150KB: URL [URL].

#
Channel
Debug
Opcode
Info

Message #

Downloading image has failed because downloaded image it too big over maximum 150KB: URL [%1]

Fields #

NameDescription
URL UnicodeString

Event ID 3042: Downloading image has failed because downloaded image is empty: URL [URL].

#
Channel
Debug
Opcode
Info

Message #

Downloading image has failed because downloaded image is empty: URL [%1]

Fields #

NameDescription
URL UnicodeString

Event ID 3043: The new tile notification was found to be a duplicate of a previous notification: new notification id [NewNotificationId], previous notification id [OldNotificationId].

#
Channel
Debug
Opcode
Info

Message #

The new tile notification was found to be a duplicate of a previous notification: new notification id [%1], previous notification id [%2]

Fields #

NameDescription
NewNotificationId UInt64
OldNotificationId UInt64

Event ID 3044: The new badge notification was found to be a duplicate of a previous notification: new notification id [NewNotificationId], previous notification id [OldNotificationId].

#
Channel
Debug
Opcode
Info

Message #

The new badge notification was found to be a duplicate of a previous notification: new notification id [%1], previous notification id [%2]

Fields #

NameDescription
NewNotificationId UInt64
OldNotificationId UInt64

Event ID 3045: Started tracking Toast Notification Request performance.

#
Channel
Debug
Task
ToastRequestNotification
Opcode
Start

Event ID 3046: Finished tracking Toast Notification Request performance.

#
Channel
Debug
Task
ToastRequestNotification
Opcode
Start

Event ID 3047: The new tile flyout notification was found to be a duplicate of a previous notification: new notification id [NewNotificationId], previous notification id [OldNotificationId].

#
Channel
Debug
Opcode
Info

Message #

The new tile flyout notification was found to be a duplicate of a previous notification: new notification id [%1], previous notification id [%2]

Fields #

NameDescription
NewNotificationId UInt64
OldNotificationId UInt64

Event ID 3048: Badge notification id TrackingId is stored for AppUserModelId.

#
Channel
Debug
Task
NewCloudNotificationArrival

Message #

Badge notification id %2 is stored for %1.

Fields #

NameDescription
AppUserModelId UnicodeString
TrackingId UInt32

Event ID 3049: Endpoint Object is being cleanedup.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

Endpoint %1 is being cleanedup

Fields #

NameDescription
Object Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3049,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:39:34.5886985+00:00",
    "event_record_id": 333,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 8144
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Object": "0x1f081cdd900"
  },
  "message": "Endpoint 0x1f081cdd900 is being cleanedup"
}

Event ID 3050: Toast notification id NotificationId for AppUserModelId is stored at QueueIndex in queue.

#
Channel
Debug
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

Toast notification id %2 for %1 is stored at %3 in queue.

Fields #

NameDescription
AppUserModelId UnicodeString
NotificationId UInt32
QueueIndex UInt16

Event ID 3051: Toast notification id OverridingNotificationId overrided existing notification id OverridedNotificationId.

#
Channel
Debug
Opcode
Info

Message #

Toast notification id %2 overrided existing notification id %1.

Fields #

NameDescription
OverridedNotificationId UInt32
OverridingNotificationId UInt32

Event ID 3052: Toast with notification tracking id TrackingId is being delivered to AppUserModelId on session SessionId.

#
Channel
Operational
Level
Informational
Task
NewCloudNotificationArrival
Opcode
Start

Message #

Toast with notification tracking id %1 is being delivered to %2 on session %3.

Fields #

NameDescription
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3052,
    "version": 0,
    "level": 4,
    "task": 10,
    "opcode": 1,
    "keywords": -9223372034698901501,
    "time_created": "2026-06-13T05:39:34.2734448+00:00",
    "event_record_id": 332,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 3840
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "TrackingId": "3",
    "AppUserModelId": "Windows.Defender.SecurityCenter",
    "SessionId": "1",
    "MessageId": "{aefd3884-df92-4266-84fc-cb4a8b4319bc}"
  },
  "message": "Toast with notification tracking id 3 is being delivered to Windows.Defender.SecurityCenter on session 1."
}

Event ID 3053: NotificationType with notification tracking id TrackingId is being delivered to AppUserModelId.

#
Channel
Operational
Task
NewCloudNotificationArrival
Opcode
Start

Message #

%1 with notification tracking id %2 is being delivered to %3.

Fields #

NameDescription
NotificationType UnicodeString
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID

Event ID 3054: Toast with notification tracking id TrackingId is canceled by AppUserModelId - informed session SessionId.

#
Channel
Operational
Opcode
Info

Message #

Toast with notification tracking id %1 is canceled by %2 - informed session %3.

Fields #

NameDescription
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32

Event ID 3055: Some toast notifications have been cleared - informed session SessionId.

#
Channel
Operational
Level
Informational
Task
ClearToastNotification

Message #

Some toast notifications have been cleared - informed session %1.

Fields #

NameDescription
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3055,
    "version": 0,
    "level": 4,
    "task": 23,
    "opcode": 0,
    "keywords": -9223372034144761856,
    "time_created": "2026-06-13T04:42:23.5219544+00:00",
    "event_record_id": 340,
    "correlation": {},
    "execution": {
      "process_id": 1072,
      "thread_id": 3524
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-b.cell-b.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "1"
  },
  "message": "Some toast notifications have been cleared - informed session 1."
}

Event ID 3056: NotificationType are being cleared for AppUserModelId - informed session SessionId.

#
Channel
Operational
Level
Informational
Opcode
Info

Message #

%1 are being cleared for %2 - informed session %3.

Fields #

NameDescription
NotificationType UInt32
AppUserModelId UnicodeString
SessionId UInt32
ErrorCode Int32
SessionErrorCode Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3056,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372034144761856,
    "time_created": "2026-06-13T05:51:28.3399704+00:00",
    "event_record_id": 336,
    "correlation": {},
    "execution": {
      "process_id": 1568,
      "thread_id": 3764
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "NotificationType": "2",
    "AppUserModelId": "Windows.Defender.MpUxDlp",
    "SessionId": "2",
    "ErrorCode": "0",
    "SessionErrorCode": "0"
  },
  "message": "Badge Notification are being cleared for Windows.Defender.MpUxDlp - informed session 2."
}

Event ID 3057: Presentation Endpoint received a call to close session SessionId.

#
Channel
Operational
Level
Informational
Task
TileSessionClose
Opcode
Start

Message #

Presentation Endpoint received a call to close session %1.

Fields #

NameDescription
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3057,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 1,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5167064+00:00",
    "event_record_id": 333,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2820
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "3"
  },
  "message": "Presentation Endpoint received a call to close session 3."
}

Event ID 3058: Presentation Endpoint ended a call to close session SessionId.

#
Channel
Operational
Level
Informational
Task
TileSessionClose
Opcode
Stop

Message #

Presentation Endpoint ended a call to close session %1.

Fields #

NameDescription
SessionId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "guid": "{88CD9180-4491-4640-B571-E3BEE2527943}",
    "event_source_name": "",
    "event_id": 3058,
    "version": 0,
    "level": 4,
    "task": 3,
    "opcode": 2,
    "keywords": -9223372036854773760,
    "time_created": "2026-06-13T05:22:33.5167184+00:00",
    "event_record_id": 334,
    "correlation": {},
    "execution": {
      "process_id": 5472,
      "thread_id": 2820
    },
    "channel": "Microsoft-Windows-PushNotification-Platform/Operational",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "SessionId": "3"
  },
  "message": "Presentation Endpoint ended a call to close session 3."
}

Event ID 3100: Started tracking Clear Toast Notification performance.

#
Channel
Debug
Task
ClearToastNotification
Opcode
Start

Event ID 3101: Finished tracking Clear Toast Notification performance.

#
Channel
Debug
Task
ClearToastNotification
Opcode
Start

Event ID 3102: Started tracking Clear Toast Notifications performance.

#
Channel
Debug
Task
ClearToastNotifications
Opcode
Start

Event ID 3103: Finished tracking Clear Toast Notifications performance.

#
Channel
Debug
Task
ClearToastNotifications
Opcode
Start

Event ID 3104: Toast with notification id [TrackingId] has expired and will be removed from the queue.

#
Channel
Debug
Opcode
Info

Message #

Toast with notification id [%1] has expired and will be removed from the queue.

Fields #

NameDescription
TrackingId UInt32

Event ID 3105: Started tracking Remove Toast Notifications performance.

#
Channel
Debug
Task
RemoveToastNotifications
Opcode
Start

Event ID 3106: Finished tracking Remove Toast Notifications performance.

#
Channel
Debug
Task
RemoveToastNotifications
Opcode
Start

Event ID 3107: Processing of Push Notification has failed: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] ErrorCode [ErrorCode].

#
Channel
Debug
Opcode
Info

Message #

Processing of Push Notification has failed: ChannelId [%1], NotificationType [%2], TrackingId [%3] AppId [%4] ErrorCode [%5]

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
ErrorCode Int32

Event ID 3108: Started tracking Clear Toast Notification Rollover performance.

#
Channel
Debug
Task
ClearToastNotificationRollover
Opcode
Start

Event ID 3109: Finished tracking Clear Toast Notification Rollover performance.

#
Channel
Debug
Task
ClearToastNotificationRollover
Opcode
Stop

Event ID 3110: Toast Notification Forwarding Global Settings: isFwToCdpEnabled = IsFwdToCdpEnabled isMirrorMasterSwitchEnabled = IsMirrorMasterSwitchEnabled MirroringDisabled = MirroringEnabled.

#
Channel
Operational
Task
AFCForwardToast

Message #

Toast Notification Forwarding Global Settings: isFwToCdpEnabled = %1 isMirrorMasterSwitchEnabled = %2 MirroringDisabled = %3

Fields #

NameDescription
IsFwdToCdpEnabled Boolean
IsMirrorMasterSwitchEnabled Boolean
MirroringEnabled Boolean

Event ID 3111: Start Toast Notification Forwarding activity

#
Channel
Operational
Task
AFCForwardToast
Opcode
Start

Event ID 3112: Stop Toast Notification Forwarding activity

#
Channel
Operational
Task
AFCForwardToast
Opcode
Stop

Event ID 3113: Toast Notification Forwarding Local Settings: isDeveloperAppMirroringEnabled = IsFwdToCdpEnabled isMirrorMasterSwitchEnabled = IsMirrorMasterSwitchEnabled isGroupPolicyEnabled = IsGPEnabled.

#
Channel
Operational
Task
AFCForwardToast

Message #

Toast Notification Forwarding Local Settings: isDeveloperAppMirroringEnabled = %1 isMirrorMasterSwitchEnabled = %2 isGroupPolicyEnabled = %3

Fields #

NameDescription
IsFwdToCdpEnabled Boolean
IsMirrorMasterSwitchEnabled Boolean
IsGPEnabled Boolean

Event ID 3114: Start Toast Notification Forwarding Do Forward To AFC

#
Channel
Operational
Task
AFCDoForwardToast
Opcode
Start

Event ID 3115: Stop Toast Notification Forwarding Do Forward To AFC

#
Channel
Operational
Task
AFCDoForwardToast
Opcode
Stop

Event ID 3116: Start Toast Notification Forwarding Make Activity from Notification

#
Channel
Operational
Task
AFCMakeActivity
Opcode
Start

Event ID 3117: Stop Toast Notification Forwarding Make Activity from Notification

#
Channel
Operational
Task
AFCMakeActivity
Opcode
Stop

Event ID 3118: Toast Notification Forwarding Finished Decorating Payload

#
Channel
Operational
Task
AFCMakeActivity

Event ID 3119: Toast Notification Forwarding Finished Loading Payload onto Activity

#
Channel
Operational
Task
AFCMakeActivity

Event ID 3120: Toast Notification Forwarding Finished setting attributes onto activity

#
Channel
Operational
Task
AFCMakeActivity

Event ID 3121: Start Toast Notification Forwarding Asset Resolution

#
Channel
Operational
Opcode
Start

Event ID 3122: Toast Notification Forwarding Asset Resolution Successful

#
Channel
Operational
Opcode
Stop

Event ID 3123: Toast Notification Forwarding Making Activity TrackingId = TrackingId AppUserModelId = AppUserModelId.

#
Channel
Operational
Task
AFCMakeActivity

Message #

Toast Notification Forwarding Making Activity TrackingId = %1 AppUserModelId = %2

Fields #

NameDescription
TrackingId UInt32
AppUserModelId UnicodeString

Event ID 3124: Toast Notification Forwarding Published Activity with Result = ErrorCode.

#
Channel
Operational
Task
AFCDoForwardToast

Message #

Toast Notification Forwarding Published Activity with Result = %1

Fields #

NameDescription
ErrorCode Int32

Event ID 3125: VerboseLog.

#
Channel
Operational
Task
AFCDoForwardToast

Message #

%1

Fields #

NameDescription
VerboseLog UnicodeString

Event ID 3126: Sync Dismiss: Dismiss Activities for App Start

#
Channel
Operational
Task
AFCDismissActivitiesForApp
Opcode
Start

Event ID 3127: Sync Dismiss: Dismiss Activities for App Stop

#
Channel
Operational
Task
AFCDismissActivitiesForApp
Opcode
Stop

Event ID 3128: Sync Dismiss: Dismiss Activities Start

#
Channel
Operational
Task
AFCDismissActivities
Opcode
Start

Event ID 3129: Sync Dismiss: Dismiss Activities Stop

#
Channel
Operational
Task
AFCDismissActivities
Opcode
Stop

Event ID 3130: Sync Dismiss: Dismiss Activities Start

#
Channel
Operational
Task
AFCOnActivityDismissed
Opcode
Start

Event ID 3131: Sync Dismiss: Dismiss Activities Stop

#
Channel
Operational
Task
AFCOnActivityDismissed
Opcode
Stop

Event ID 3132: Sync Dismiss: Remove Notification using Activity Start

#
Channel
Operational
Task
AFCRemoveNotificationUsingActivity
Opcode
Start

Event ID 3133: Sync Dismiss: Remove Notification using Activity Stop

#
Channel
Operational
Task
AFCRemoveNotificationUsingActivity
Opcode
Stop

Event ID 3134: Sync Dismiss: Get Activities Start

#
Channel
Operational
Task
AFCGetActivities
Opcode
Stop

Event ID 3135: Sync Dismiss: Get Activities Stop

#
Channel
Operational
Task
AFCGetActivities
Opcode
Stop

Event ID 3136: Sync Dismiss: CDPGetPlatformDeviceId Start

#
Channel
Operational
Task
AFCGetPlatformDeviceId
Opcode
Start

Event ID 3137: Sync Dismiss: CDPGetPlatformDeviceId Stop

#
Channel
Operational
Task
AFCGetPlatformDeviceId
Opcode
Stop

Event ID 3138: VerboseLog.

#
Channel
Operational
Opcode
Info

Message #

%1

Fields #

NameDescription
VerboseLog UnicodeString

Event ID 3139: Sync Dismiss Removed Activity with Result = ErrorCode.

#
Channel
Operational
Opcode
Info

Message #

Sync Dismiss Removed Activity with Result = %1

Fields #

NameDescription
ErrorCode Int32

Event ID 3140: Sync Dismiss Removed Notification with Result = ErrorCode.

#
Channel
Operational
Task
AFCRemoveNotificationUsingActivity

Message #

Sync Dismiss Removed Notification with Result = %1

Fields #

NameDescription
ErrorCode Int32

Event ID 3141: SyncDismissRemoveNotificationUsingActivityParams: MatchOnNotificationId = MatchOnNotificationId NotificationId = NotificationId ActivityId = ActivityId.

#
Channel
Operational
Task
AFCRemoveNotificationUsingActivity

Message #

SyncDismissRemoveNotificationUsingActivityParams: MatchOnNotificationId = %1 NotificationId = %2 ActivityId = %3

Fields #

NameDescription
MatchOnNotificationId Boolean
NotificationId UInt32
ActivityId UnicodeString

Event ID 3142: Sync Dismiss: Matched Activity using Notification!

#
Channel
Operational
Opcode
Info

Event ID 3143: Sync Dismiss: Matched Notification using Activity!

#
Channel
Operational
Task
AFCRemoveNotificationUsingActivity

Event ID 3144: Received WNF_CDP_CDPUSERSVC_READY

#
Channel
Operational
Opcode
Info

Event ID 3145: [Sqlite][Informational] Status: SqliteInformational_Status.

#
Channel
Debug
Opcode
Info

Description

[Sqlite][Informational] Status: SqliteInformational_Status. Message: Message.

Message #

[Sqlite][Informational] Status: %1. Message: %2

Fields #

NameDescription
Error Int32
Message AnsiString

Event ID 3146: [Sqlite][Warning] Status: SqliteWarning_Status.

#
Channel
Operational
Opcode
Info

Description

[Sqlite][Warning] Status: SqliteWarning_Status. Message: Message.

Message #

[Sqlite][Warning] Status: %1. Message: %2

Fields #

NameDescription
Error Int32
Message AnsiString

Event ID 3147: [Sqlite][Error] Status: SqliteError_Status.

#
Channel
Operational
Opcode
Info

Description

[Sqlite][Error] Status: SqliteError_Status. Message: Message.

Message #

[Sqlite][Error] Status: %1. Message: %2

Fields #

NameDescription
Error Int32
Message AnsiString

Event ID 3148: [Sqlite][Other] Status: SqliteOther_Status.

#
Channel
Debug
Opcode
Info

Description

[Sqlite][Other] Status: SqliteOther_Status. Message: Message.

Message #

[Sqlite][Other] Status: %1. Message: %2

Fields #

NameDescription
Error Int32
Message AnsiString

Event ID 3149: Processing of Push Notification has succeeded: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] MessageId [MessageId] PolicyReason [PolicyR...

#
Channel
Debug

Description

Processing of Push Notification has succeeded: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] MessageId [MessageId] PolicyReason [PolicyReason] HResult [ErrorCode].

Message #

Processing of Push Notification has succeeded: ChannelId [%1], NotificationType [%2], TrackingId [%3] AppId [%4]  MessageId [%5] PolicyReason [%6] HResult [%7]

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
MessageId UInt64
PolicyReason UnicodeString
ErrorCode Int32

Event ID 3149: Processing of Push Notification has succeeded: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] MessageId [MessageId] PolicyReason [Policy...

#
Channel
Operational

Description

Processing of Push Notification has succeeded: ChannelId [], NotificationType [], TrackingId [] AppId [] MessageId [] PolicyReason [] HResult [].

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
MessageId UInt64
PolicyReason UnicodeString
ErrorCode Int32

Event ID 3150: Processing of Local Notification has failed: NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] PolicyReason [PolicyReason] HResult [ErrorCode]

#
Channel
Operational

Message #

Processing of Local Notification has failed: NotificationType [%1], TrackingId [%2] AppId [%3] PolicyReason [%4] HResult [%5]

Fields #

NameDescription
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
PolicyReason UnicodeString
ErrorCode Int32

Event ID 3151: Processing of Local Notification has succeeded: NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId] PolicyReason [PolicyReason] HResult [ErrorCode]

#
Channel
Debug, Operational

Message #

Processing of Local Notification has succeeded: NotificationType [%1], TrackingId [%2] AppId [%3] PolicyReason [%4] HResult [%5]

Fields #

NameDescription
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
PolicyReason UnicodeString
ErrorCode Int32

Event ID 3152: Processing of Push Notification has failed: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId], PolicyReason [PolicyReason] ErrorCode [ErrorC

#
Channel
Operational

Description

Processing of Push Notification has failed: ChannelId [ChannelId], NotificationType [NotificationType], TrackingId [TrackingId] AppId [AppUserModelId], PolicyReason [PolicyReason] ErrorCode [ErrorCode].

Message #

Processing of Push Notification has failed: ChannelId [%1], NotificationType [%2], TrackingId [%3] AppId [%4], PolicyReason [%5] ErrorCode [%6]

Fields #

NameDescription
ChannelId UnicodeString
NotificationType UnicodeString
TrackingId UInt32
AppUserModelId UnicodeString
PolicyReason UnicodeString
ErrorCode Int32

Event ID 3153: Toast with notification tracking id TrackingId is delivered to AppUserModelId on session SessionId.

#
Channel
Operational
Level
Informational
Task
NewCloudNotificationArrival
Opcode
Stop

Message #

Toast with notification tracking id %1 is delivered to %2 on session %3.

Fields #

NameDescription
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 3153,
    "level": 4,
    "task": 10,
    "opcode": 2,
    "time_created": "2026-05-27T17:04:07.6624095+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "SessionId": "1",
    "TrackingId": "26",
    "MessageId": "{c62b4aa6-2030-4b27-8f99-18032d0c8703}",
    "AppUserModelId": "Windows.Defender.SecurityCenter"
  }
}

Event ID 3153: Toast with notification tracking id TrackingId is delivered to AppUserModelId on session

#
Channel
Operational
Level
4
Task
NewCloudNotificationArrival
Opcode
Stop

Description

Toast with notification tracking id is delivered to on session .

Fields #

NameDescription
TrackingId Int32
AppUserModelId UnicodeString
SessionId UInt32
MessageId GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-PushNotifications-Platform",
    "event_id": 3153,
    "level": 4,
    "task": 10,
    "opcode": 2,
    "time_created": "2026-05-27T17:04:07.6624095+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-PushNotification-Platform"
  },
  "event_data": {
    "SessionId": "1",
    "TrackingId": "26",
    "MessageId": "{c62b4aa6-2030-4b27-8f99-18032d0c8703}",
    "AppUserModelId": "Windows.Defender.SecurityCenter"
  }
}

Event ID 3154: Processing and publishing of Resume Notification has succeeded: TrackingId [TrackingId].

#
Channel
Debug

Message #

Processing and publishing of Resume Notification has succeeded: TrackingId [%1]

Fields #

NameDescription
TrackingId UInt32

Event ID 3154

#
Channel
Operational

Description

Processing and publishing of Resume Notification has succeeded: TrackingId [].

Fields #

NameDescription
TrackingId UInt32

Event ID 3155: Processing and publishing of Resume Notification has failed: TrackingId [TrackingId], Location [Location], ErrorCode [ErrorCode].

#
Channel
Operational

Message #

Processing and publishing of Resume Notification has failed: TrackingId [%1], Location [%2], ErrorCode [%3]

Fields #

NameDescription
TrackingId UInt32
Location UnicodeString
ErrorCode Int32

Event ID 3155

#
Channel
Operational

Description

Processing and publishing of Resume Notification has failed: TrackingId [], Location [], ErrorCode [].

Fields #

NameDescription
TrackingId UInt32
Location UnicodeString
ErrorCode Int32

Event ID 3156: Processing of Resume Response has succeeded: TrackingId [TrackingId].

#
Channel
Debug

Message #

Processing of Resume Response has succeeded: TrackingId [%1]

Fields #

NameDescription
TrackingId UInt32

Event ID 3156

#
Channel
Operational

Description

Processing of Resume Response has succeeded: TrackingId [].

Fields #

NameDescription
TrackingId UInt32

Event ID 3157: Processing of Resume Response has failed: TrackingId [TrackingId], Location [Location], ErrorCode [ErrorCode].

#
Channel
Operational

Message #

Processing of Resume Response has failed: TrackingId [%1], Location [%2], ErrorCode [%3]

Fields #

NameDescription
TrackingId UInt32
Location UnicodeString
ErrorCode Int32

Event ID 3157

#
Channel
Operational

Description

Processing of Resume Response has failed: TrackingId [], Location [], ErrorCode [].

Fields #

NameDescription
TrackingId UInt32
Location UnicodeString
ErrorCode Int32

Event ID 10000: DebugTrace: DebugTrace.

#
Channel
Debug
Opcode
Info

Message #

DebugTrace: %1

Fields #

NameDescription
debugString UnicodeString

Provenance

ETW provider GUID 88cd9180-4491-4640-b571-e3bee2527943

Defined in wpncore.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.4768, captured 2026-06-02 — Manifest XML pack, 2.0 MB