Microsoft-Windows-RemoteAssistance

EventTitleChannelSampleRule
1Entering function FuncName.TracingNN
2Leaving function FuncName.TracingNN
3Application will terminate, a critical error was detected in file Line line …ApplicationNN
4Hit exception block of code at file Line line in function function.TracingNN
5Branching on Line:line File:file with the string Condition.TracingNN
6Switching on Line:line File:file with the value Condition.TracingNN
7Entering conditional block at Line:Entering_conditional_block_at_Line File:File.TracingNN
8Exiting conditional block at Line:Exiting_conditional_block_at_Line File:File.TracingNN
9There was a problem interacting with COM object FuncName.AdminNN
10A user tried to use Remote Assistance and send an invitation for help through …AdminNN
11A user opened a Remote Assistance invitation, but the invitation was closed due …AdminNN
12A user tried to use Remote Assistance, group policy requires a session log to be …AdminNN
13Remote Assistance started with: FuncName as the command line parameters.OperationalNN
14A Remote Assistance Invitation was successfully opened.OperationalNN
15An RDP connection was successfully made.OperationalNN
16The Remote Assistance password was verified.OperationalNN
17The Remote Assistance password provided was incorrect.OperationalNN
18The Remote Assistance session was disconnected remotely.OperationalNN
19The Remote Assistance session was disconnected locally.OperationalNN
20The Remote Assistance invitation was closed, any information concerning it given …OperationalNN
21The helper is sharing control.OperationalNN
22The helper can now view the screen.OperationalNN
23Remote Assistance detected that it didn't restore the background and screen …OperationalNN
24The time limit of offered invitations has been reached.OperationalNN
25User setting value currently applied is Code.OperationalNN
26The system or GP settings do not allow an Remote Assistance invitation to be …OperationalNN
27The system or GP settings do not allow a helper to share control.OperationalNN
28The Windows firewall has been checked and it appears that it is configured so …OperationalNN
29The error message: FuncName has been shown to the user.OperationalNN
30Remote Assistance has ended.OperationalNN
31Remote Assistance COM server has started.OperationalYN
32Remote Assistance COM server has ended.OperationalYN
33The Remote Assistance ticket contained the following IP addresses: FuncName.OperationalNN
34A PNRP Node was created at the following address: FuncName.OperationalNN
35The following PNRP clouds were detected: FuncName.OperationalNN
36A PNRP Node was released at the following address: FuncName.OperationalNN
37Started looking for PNRP node with the following address: FuncName.OperationalNN
38Stopped looking for PNRP node, address: FuncName.OperationalNN
39There was a problem interacting with the PNRP service.AdminNN
40Diagnosis Repro Attempt resulted in a success.OperationalNN
41Diagnosis Repro Attempt resulted in a failure.OperationalNN
42Current time on NTP Server: FuncName.TracingNN
43Remote Assistance troubleshooting rejected problem Code.TracingNN
44Remote Assistance troubleshooting has confirmed the problem: FuncName.OperationalNN
45Remote Assistance troubleshooting is starting to repair the identified problem: …OperationalNN
46Remote Assistance troubleshooting successfully repaired the problem: FuncName.OperationalNN
47Remote Assistance troubleshooting failed to repair the problem: FuncName.OperationalNN
100Remote OS Type : Remote_OS_Type.TracingNN
101Remote Assistance connection attempt failed with error code: Code.TracingNN
102Remote Assistance reproduced the problem and created following ticket to verify …TracingNN

Event ID 1: Entering function FuncName.

#
Channel
Tracing
Opcode
Info

Message #

Entering function %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 2: Leaving function FuncName.

#
Channel
Tracing
Opcode
Info

Message #

Leaving function %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 3: Application will terminate, a critical error was detected in file Line line Function function.

#
Channel
Application
Opcode
Stop

Message #

Application will terminate, a critical error was detected in %1 Line %2 Function %3

Fields #

NameDescription
file UnicodeString
line UInt32
function UnicodeString
error UInt32

Event ID 4: Hit exception block of code at file Line line in function function.

#
Channel
Tracing
Opcode
Info

Message #

Hit exception block of code at %1 Line %2 in function %3

Fields #

NameDescription
file UnicodeString
line UInt32
function UnicodeString
error UInt32

Event ID 5: Branching on Line:line File:file with the string Condition.

#
Channel
Tracing
Opcode
Info

Message #

Branching on Line:%2 File:%1 with the string %3

Fields #

NameDescription
file UnicodeString
line UInt32
Condition UnicodeString

Event ID 6: Switching on Line:line File:file with the value Condition.

#
Channel
Tracing
Opcode
Info

Message #

Switching on Line:%2 File:%1 with the value %3

Fields #

NameDescription
file UnicodeString
line UInt32
Condition UInt32

Event ID 7: Entering conditional block at Line:Entering_conditional_block_at_Line File:File.

#
Channel
Tracing
Opcode
Info

Message #

Entering conditional block at Line:%1 File:%2

Fields #

NameDescription
line UInt32
File UnicodeString

Event ID 8: Exiting conditional block at Line:Exiting_conditional_block_at_Line File:File.

#
Channel
Tracing
Opcode
Info

Message #

Exiting conditional block at Line:%1 File:%2

Fields #

NameDescription
line UInt32
File UnicodeString

Event ID 9: There was a problem interacting with COM object FuncName.

#
Channel
Admin
Opcode
Info

Description

There was a problem interacting with COM object FuncName. An outdated version might be installed, or the component might not be installed at all.

Message #

There was a problem interacting with COM object %1.  An outdated version might be installed, or the component might not be installed at all.

Fields #

NameDescription
FuncName UnicodeString

Event ID 10: A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfu...

#
Channel
Admin
Opcode
Info

Description

A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfully send the invitation. It is possible the email client configured as the default client does not support SMAPI calls, or that the email client is improperly configured. It is also possible that the user closed the email client without sending the message.

Message #

A user tried to use Remote Assistance and send an invitation for help through their default email client, but Remote Assistance failed to successfully send the invitation.  It is possible the email client configured as the default client does not support SMAPI calls, or that the email client is improperly configured.  It is also possible that the user closed the email client without sending the message.

Event ID 11: A user opened a Remote Assistance invitation, but the invitation was closed due to too many bad password attempts to connect to the machine.

#
Channel
Admin
Opcode
Info

Event ID 12: A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.

#
Channel
Admin
Opcode
Info

Description

A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created. Remote Assistance was terminated. Check the disk to see if there are problems with the disk or if it is full.

Message #

A user tried to use Remote Assistance, group policy requires a session log to be maintained, and a session log couldn't be created.  Remote Assistance was terminated.  Check the disk to see if there are problems with the disk or if it is full.

Event ID 13: Remote Assistance started with: FuncName as the command line parameters.

#
Channel
Operational
Opcode
Info

Message #

Remote Assistance started with: %1    as the command line parameters.

Fields #

NameDescription
FuncName UnicodeString

Event ID 14: A Remote Assistance Invitation was successfully opened.

#
Channel
Operational
Opcode
Info

Event ID 15: An RDP connection was successfully made.

#
Channel
Operational
Opcode
Info

Event ID 16: The Remote Assistance password was verified.

#
Channel
Operational
Opcode
Info

Description

The Remote Assistance password was verified. The Remote Assistance session has begun.

Message #

The Remote Assistance password was verified.  The Remote Assistance session has begun.

Event ID 17: The Remote Assistance password provided was incorrect.

#
Channel
Operational
Opcode
Info

Description

The Remote Assistance password provided was incorrect. The RDP session was terminated, IP address of the connecting machine is FuncName.

Message #

The Remote Assistance password provided was incorrect.  The RDP session was terminated, IP address of the connecting machine is %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 18: The Remote Assistance session was disconnected remotely.

#
Channel
Operational
Opcode
Info

Event ID 19: The Remote Assistance session was disconnected locally.

#
Channel
Operational
Opcode
Info

Event ID 20: The Remote Assistance invitation was closed, any information concerning it given out is now invalid.

#
Channel
Operational
Opcode
Info

Event ID 21: The helper is sharing control.

#
Channel
Operational
Opcode
Info

Event ID 22: The helper can now view the screen.

#
Channel
Operational
Opcode
Info

Event ID 23: Remote Assistance detected that it didn't restore the background and screen settings before shutting down.

#
Channel
Operational
Opcode
Info

Description

Remote Assistance detected that it didn't restore the background and screen settings before shutting down. An attempt was made to restore these settings.

Message #

Remote Assistance detected that it didn't restore the background and screen settings before shutting down.  An attempt was made to restore these settings.

Event ID 24: The time limit of offered invitations has been reached.

#
Channel
Operational
Opcode
Info

Event ID 25: User setting value currently applied is Code.

#
Channel
Operational
Opcode
Info

Message #

User setting value currently applied is %1

Fields #

NameDescription
Code UInt32

Event ID 26: The system or GP settings do not allow an Remote Assistance invitation to be created.

#
Channel
Operational
Opcode
Info

Description

The system or GP settings do not allow an Remote Assistance invitation to be created. This action has been blocked by the application.

Message #

The system or GP settings do not allow an Remote Assistance invitation to be created.  This action has been blocked by the application.

Event ID 27: The system or GP settings do not allow a helper to share control.

#
Channel
Operational
Opcode
Info

Description

The system or GP settings do not allow a helper to share control. This action has been blocked by the application.

Message #

The system or GP settings do not allow a helper to share control.  This action has been blocked by the application.

Event ID 28: The Windows firewall has been checked and it appears that it is configured so that it will stop Remote Assistance from working.

#
Channel
Operational
Opcode
Info

Event ID 29: The error message: FuncName has been shown to the user.

#
Channel
Operational
Opcode
Info

Message #

The error message: %1    has been shown to the user.

Fields #

NameDescription
FuncName UnicodeString

Event ID 30: Remote Assistance has ended.

#
Channel
Operational
Opcode
Info

Event ID 31: Remote Assistance COM server has started.

#
Channel
Operational
Level
Verbose
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteAssistance",
    "guid": "5B0A651A-8807-45CC-9656-7579815B6AF0",
    "event_source_name": "",
    "event_id": 31,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:50:13.780543+00:00",
    "event_record_id": 41,
    "correlation": {},
    "execution": {
      "process_id": 11236,
      "thread_id": 9452
    },
    "channel": "Microsoft-Windows-RemoteAssistance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 32: Remote Assistance COM server has ended.

#
Channel
Operational
Level
Verbose
Opcode
Info

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteAssistance",
    "guid": "5B0A651A-8807-45CC-9656-7579815B6AF0",
    "event_source_name": "",
    "event_id": 32,
    "version": 0,
    "level": 5,
    "task": 0,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T23:50:13.791029+00:00",
    "event_record_id": 42,
    "correlation": {},
    "execution": {
      "process_id": 11236,
      "thread_id": 9452
    },
    "channel": "Microsoft-Windows-RemoteAssistance/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {},
  "message": ""
}

References #

Event ID 33: The Remote Assistance ticket contained the following IP addresses: FuncName.

#
Channel
Operational
Opcode
Info

Message #

The Remote Assistance ticket contained the following IP addresses: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 34: A PNRP Node was created at the following address: FuncName.

#
Channel
Operational
Opcode
Info

Message #

A PNRP Node was created at the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 35: The following PNRP clouds were detected: FuncName.

#
Channel
Operational
Opcode
Info

Message #

The following PNRP clouds were detected: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 36: A PNRP Node was released at the following address: FuncName.

#
Channel
Operational
Opcode
Info

Message #

A PNRP Node was released at the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 37: Started looking for PNRP node with the following address: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Started looking for PNRP node with the following address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 38: Stopped looking for PNRP node, address: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Stopped looking for PNRP node, address: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 39: There was a problem interacting with the PNRP service.

#
Channel
Admin
Opcode
Info

Description

There was a problem interacting with the PNRP service. This component might not be installed correctly. The error code received was: FuncName.

Message #

There was a problem interacting with the PNRP service.  This component might not be installed correctly. The error code received was: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 40: Diagnosis Repro Attempt resulted in a success.

#
Channel
Operational
Opcode
Info

Event ID 41: Diagnosis Repro Attempt resulted in a failure.

#
Channel
Operational
Opcode
Info

Event ID 42: Current time on NTP Server: FuncName.

#
Channel
Tracing
Opcode
Info

Message #

Current time on NTP Server: %1

Fields #

NameDescription
FuncName UnicodeString

Event ID 43: Remote Assistance troubleshooting rejected problem Code.

#
Channel
Tracing
Opcode
Info

Message #

Remote Assistance troubleshooting rejected problem %1.

Fields #

NameDescription
Code UInt32

Event ID 44: Remote Assistance troubleshooting has confirmed the problem: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Remote Assistance troubleshooting has confirmed the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 45: Remote Assistance troubleshooting is starting to repair the identified problem: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Remote Assistance troubleshooting is starting to repair the identified problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 46: Remote Assistance troubleshooting successfully repaired the problem: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Remote Assistance troubleshooting successfully repaired the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 47: Remote Assistance troubleshooting failed to repair the problem: FuncName.

#
Channel
Operational
Opcode
Info

Message #

Remote Assistance troubleshooting failed to repair the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Event ID 100: Remote OS Type : Remote_OS_Type.

#
Channel
Tracing
Opcode
Info

Message #

Remote OS Type : %1.

Fields #

NameDescription
Code UInt32

Event ID 101: Remote Assistance connection attempt failed with error code: Code.

#
Channel
Tracing
Opcode
Info

Message #

Remote Assistance connection attempt failed with error code: %1.

Fields #

NameDescription
Code UInt32

Event ID 102: Remote Assistance reproduced the problem and created following ticket to verify the problem: FuncName.

#
Channel
Tracing
Opcode
Info

Message #

Remote Assistance reproduced the problem and created following ticket to verify the problem: %1.

Fields #

NameDescription
FuncName UnicodeString

Provenance

ETW provider GUID 5b0a651a-8807-45cc-9656-7579815b6af0

Defined in msra.exe, which carries the event manifest.

  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB