Microsoft-Windows-Remote-Desktop-Management-Service

EventTitleChannelSampleRule
1Event ID 1OperationalNN
1The Remote Desktop Management service failed to start.AdminYN
2Event ID 2OperationalNN
2Config sync failed with error: ConfigSyncFailedWithError.AdminNN
3Event ID 3OperationalNN
3Remote configuration sync on server function failed.AdminNN
4Event ID 4OperationalNN
4Cancelling job on collection param1 and on RDMS server param2 - Failed.AdminNN
5Event ID 5OperationalNN
5The Remote Desktop Management service Patch Manager failed to start with error …AdminNN
6Event ID 6OperationalNN
6Config sync failed with error: Param1.AdminNN
260Event ID 260OperationalNN
260The Remote Desktop Management service successfully started and is running.OperationalYN
261Event ID 261OperationalNN
261The Remote Desktop Management service stopped.OperationalYN
262Event ID 262OperationalNN
262Config last sync timestamp param1.OperationalNN
263Event ID 263OperationalNN
263Config Sync Succeeded.OperationalNN
264Event ID 264OperationalNN
264Remote configuration sync on server param1 started.OperationalNN
265Event ID 265OperationalNN
265Remote configuration sync on server param1 succeeded.OperationalNN
266Event ID 266OperationalNN
266Cancelling job on collection param1 and on RDMS server param2 - Started.OperationalNN
267Event ID 267OperationalNN
267Cancelling job on collection param1 and on RDMS server param2 - Succeeded.OperationalNN
268Event ID 268OperationalNN
268Couldn't cancel the job on collection param1 as the RDMS server param2 is not …OperationalNN
4097Event ID 4097OperationalNN
4097function - hr - param2.DebugNN
4098Event ID 4098OperationalNN
4098Config last sync timestamp param1.DebugNN

Event ID 1

#
Channel
Operational

Description

The Remote Desktop Management service failed to start. Error code.

Fields #

NameDescription
Param1 UInt32

Event ID 1: The Remote Desktop Management service failed to start.

#
Channel
Admin
Level
2

Description

The Remote Desktop Management service failed to start. Error code: Param1.

Message #

The Remote Desktop Management service failed to start. Error code: %1

Fields #

NameDescription
EventXML.Param1 UInt32
Param1 UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Remote-Desktop-Management-Service",
    "guid": "{05DA6B40-219E-4F17-92E6-D663FD87CBA8}",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 2,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T13:40:35.2735228+00:00",
    "event_record_id": 1,
    "correlation": {
      "ActivityID": "{94E5E6B3-6E2D-4044-BBF8-22895CD42C9C}"
    },
    "execution": {
      "process_id": 4068,
      "thread_id": 6348
    },
    "channel": "Remote-Desktop-Management-Service/Admin",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "user_data": {
    "EventXML": {
      "Param1": "2284126209"
    }
  },
  "message": "The Remote Desktop Management service failed to start. Error code: 0x88250001"
}

Event ID 2

#
Channel
Operational

Description

Config sync failed with error: . Check database connectivity, connect string: .

Fields #

NameDescription
param1 UInt32
param2 UnicodeString

Event ID 2: Config sync failed with error: ConfigSyncFailedWithError.

#
Channel
Admin

Description

Config sync failed with error: ConfigSyncFailedWithError. Check database connectivity, connect string: CheckDatabaseConnectivity,ConnectString.

Message #

Config sync failed with error: %1. Check database connectivity, connect string: %2.

Fields #

NameDescription
param1 UInt32
param2 UnicodeString

Event ID 3

#
Channel
Operational

Description

Remote configuration sync on server failed. Following error occurred.

Fields #

NameDescription
function UnicodeString
param2 UInt32

Event ID 3: Remote configuration sync on server function failed.

#
Channel
Admin

Description

Remote configuration sync on server function failed. Following error occurred: FollowingErrorOccurred.

Message #

Remote configuration sync on server %1 failed. Following error occurred: %2

Fields #

NameDescription
function UnicodeString
param2 UInt32

Event ID 4

#
Channel
Operational

Description

Cancelling job on collection and on RDMS server - Failed. Following error occurred.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UInt32

Event ID 4: Cancelling job on collection param1 and on RDMS server param2 - Failed.

#
Channel
Admin

Description

Cancelling job on collection param1 and on RDMS server param2 - Failed. Following error occurred: FollowingErrorOccurred.

Message #

Cancelling job on collection %1 and on RDMS server %2 - Failed. Following error occurred: %3

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString
param3 UInt32

Event ID 5

#
Channel
Operational

Description

The Remote Desktop Management service Patch Manager failed to start with error code: , will retry.

Fields #

NameDescription
Param1 UInt32

Event ID 5: The Remote Desktop Management service Patch Manager failed to start with error code: Param1, will retry.

#
Channel
Admin

Message #

The Remote Desktop Management service Patch Manager failed to start with error code: %1, will retry

Fields #

NameDescription
Param1 UInt32

Event ID 6

#
Channel
Operational

Description

Config sync failed with error: . Check that Windows Internal Database service is running.

Fields #

NameDescription
Param1 UInt32

Event ID 6: Config sync failed with error: Param1.

#
Channel
Admin

Description

Config sync failed with error: Param1. Check that Windows Internal Database service is running.

Message #

Config sync failed with error: %1. Check that Windows Internal Database service is running.

Fields #

NameDescription
Param1 UInt32

Event ID 260

#
Channel
Operational

Description

The Remote Desktop Management service successfully started and is running.

Event ID 260: The Remote Desktop Management service successfully started and is running.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Remote-Desktop-Management-Service",
    "guid": "{05DA6B40-219E-4F17-92E6-D663FD87CBA8}",
    "event_source_name": "",
    "event_id": 260,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T13:44:11.4395882+00:00",
    "event_record_id": 4,
    "correlation": {
      "ActivityID": "{83B81391-1D74-49F1-A618-674142F6C903}"
    },
    "execution": {
      "process_id": 6544,
      "thread_id": 1240
    },
    "channel": "Remote-Desktop-Management-Service/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Remote Desktop Management service successfully started and is running."
}

Event ID 261

#
Channel
Operational

Description

The Remote Desktop Management service stopped.

Event ID 261: The Remote Desktop Management service stopped.

#
Channel
Operational
Level
4

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Remote-Desktop-Management-Service",
    "guid": "{05DA6B40-219E-4F17-92E6-D663FD87CBA8}",
    "event_source_name": "",
    "event_id": 261,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 4611686018427387904,
    "time_created": "2026-06-13T13:40:35.4059691+00:00",
    "event_record_id": 2,
    "correlation": {
      "ActivityID": "{94E5E6B3-6E2D-4044-BBF8-22895CD42C9C}"
    },
    "execution": {
      "process_id": 4068,
      "thread_id": 6348
    },
    "channel": "Remote-Desktop-Management-Service/Operational",
    "computer": "telemetry-DC-d.cell-d.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": "The Remote Desktop Management service stopped."
}

Event ID 262

#
Channel
Operational

Description

Config last sync timestamp . Database last updated timestamp . Sync started.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 262: Config last sync timestamp param1.

#
Channel
Operational

Description

Config last sync timestamp param1. Database last updated timestamp param2. Sync started.

Message #

Config last sync timestamp %1. Database last updated timestamp %2. Sync started.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 263

#
Channel
Operational

Description

Config Sync Succeeded.

Event ID 263: Config Sync Succeeded.

#
Channel
Operational

Event ID 264

#
Channel
Operational

Description

Remote configuration sync on server started.

Fields #

NameDescription
param1 UnicodeString

Event ID 264: Remote configuration sync on server param1 started.

#
Channel
Operational

Message #

Remote configuration sync on server %1 started.

Fields #

NameDescription
param1 UnicodeString

Event ID 265

#
Channel
Operational

Description

Remote configuration sync on server succeeded.

Fields #

NameDescription
param1 UnicodeString

Event ID 265: Remote configuration sync on server param1 succeeded.

#
Channel
Operational

Message #

Remote configuration sync on server %1 succeeded.

Fields #

NameDescription
param1 UnicodeString

Event ID 266

#
Channel
Operational

Description

Cancelling job on collection and on RDMS server - Started.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 266: Cancelling job on collection param1 and on RDMS server param2 - Started.

#
Channel
Operational

Message #

Cancelling job on collection %1 and on RDMS server %2 - Started.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 267

#
Channel
Operational

Description

Cancelling job on collection and on RDMS server - Succeeded.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 267: Cancelling job on collection param1 and on RDMS server param2 - Succeeded.

#
Channel
Operational

Message #

Cancelling job on collection %1 and on RDMS server %2 - Succeeded.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 268

#
Channel
Operational

Description

Couldn't cancel the job on collection as the RDMS server is not reachable. Marking the job as aborted.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 268: Couldn't cancel the job on collection param1 as the RDMS server param2 is not reachable.

#
Channel
Operational

Description

Couldn't cancel the job on collection param1 as the RDMS server param2 is not reachable. Marking the job as aborted.

Message #

Couldn't cancel the job on collection %1 as the RDMS server %2 is not reachable. Marking the job as aborted.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 4097

#
Channel
Operational

Fields #

NameDescription
function UnicodeString
param2 UInt32

Event ID 4097: function - hr - param2.

#
Channel
Debug

Message #

%1 - hr - %2

Fields #

NameDescription
function UnicodeString
param2 UInt32

Event ID 4098

#
Channel
Operational

Description

Config last sync timestamp . Database last updated timestamp . Sync not needed.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString

Event ID 4098: Config last sync timestamp param1.

#
Channel
Debug

Description

Config last sync timestamp param1. Database last updated timestamp param2. Sync not needed.

Message #

Config last sync timestamp %1. Database last updated timestamp %2. Sync not needed.

Fields #

NameDescription
param1 UnicodeString
param2 UnicodeString