Microsoft-Windows-Ras-AgileVpn
16 events across 2 channels
| Event | Title | Channel | Sample |
|---|---|---|---|
| 2100 | DebugString. | Operational | N |
| 2101 | DebugString. | Operational | N |
| 2102 | DebugString. | Operational | N |
| 2103 | DebugString. | Operational | N |
| 3100 | DebugString. | Debug | N |
| 3101 | DebugString. | Debug | N |
| 3102 | DebugString. | Debug | N |
| 3103 | DebugString. | Debug | N |
| 3104 | DebugString DebugParam. | Debug | N |
| 3105 | DebugString DebugParam. | Debug | N |
| 3106 | FunctionName IPAddress: IpAddress. | Debug | N |
| 3201 | (Packet(s):Number of packets:NumberOfPackets Source Address:SrcAddress … | Debug | N |
| 3202 | (Packet(s)Drop Reason Source_Address :Number of packets:Destination_Address … | Debug | N |
| 3203 | AddressFamily:AddressFamily Start Port:Start_Port End Port:End_Port … | Debug | N |
| 3204 | UpdateTsInfo: for TS ID :TSID (fDelete:fDelete). | Debug | N |
| 3205 | AgileVpnCmIncomingCallComplete called for tunnel ID TunnelID: Status. | Debug | N |
Event ID 2100: DebugString.
#Event ID 2101: DebugString.
#Event ID 2102: DebugString.
#Event ID 2103: DebugString.
#Event ID 3100: DebugString.
#Event ID 3101: DebugString.
#Event ID 3102: DebugString.
#Event ID 3103: DebugString.
#Event ID 3104: DebugString DebugParam.
#Event ID 3105: DebugString DebugParam.
#Event ID 3106: FunctionName IPAddress: IpAddress.
#Event ID 3201: (Packet(s):Number of packets:NumberOfPackets Source Address:SrcAddress Destination Address:DestAddress Source Port:SrcPort Destination Port:DestPort Next Protocol:NextProtocol).
#Description
(Packet(s):Number of packets:NumberOfPackets Source Address:SrcAddress Destination Address:DestAddress Source Port:SrcPort Destination Port:DestPort Next Protocol:NextProtocol).
Message #
Fields #
| Name | Description |
|---|---|
NumberOfPackets UInt32 | |
SrcAddress AnsiString | |
DestAddress AnsiString | |
SrcPort UInt32 | |
DestPort UInt32 | |
NextProtocol UInt32 |
Event ID 3202: (Packet(s)Drop Reason Source_Address :Number of packets:Destination_Address Source Address:Source_Port Destination Address:Destination_Port Source Port:Next_Protocol Destination Port:DropReason Nex...
#Description
(Packet(s)Drop Reason Source_Address :Number of packets:Destination_Address Source Address:Source_Port Destination Address:Destination_Port Source Port:Next_Protocol Destination Port:DropReason Next Protocol:NumberOfPackets).
Message #
Fields #
| Name | Description |
|---|---|
DropReason AnsiString | |
NumberOfPackets UInt32 | |
SrcAddress AnsiString | |
DestAddress AnsiString | |
SrcPort UInt32 | |
DestPort UInt32 | |
NextProtocol UInt32 |
Event ID 3203: AddressFamily:AddressFamily Start Port:Start_Port End Port:End_Port ProtocolID:ProtocolID Start Address:Start_Address End Address:End_Address.
#Event ID 3204: UpdateTsInfo: for TS ID :TSID (fDelete:fDelete).
#Event ID 3205: AgileVpnCmIncomingCallComplete called for tunnel ID TunnelID: Status.
#Description
AgileVpnCmIncomingCallComplete called for tunnel ID TunnelID: Status.
Message #
Fields #
| Name | Description |
|---|---|
TunnelID UInt64 | |
Status UInt32 | NTSTATUS reference |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID b5325cd6-438e-4ec1-aa46-14f46f2570e4
Defined in agilevpn.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02