Microsoft-Windows-RemoteDesktopServices-RdpCoreTS

89 events across 3 channels

EventTitleChannelSample
1The RDP Graphics module failed to initialize.AdminN
2Remote Desktop Protocol will use the RDP Graphics module to connect to the …AdminN
3The RemoteFX module failed to initialize.AdminN
4The RemoteFX module failed to initialize.AdminN
5The client computer does not support RemoteFX.AdminN
6The resolution requested by the remote client is not supported by RemoteFX.AdminN
7The resolution requested by the remote client could not be set.AdminN
8Module terminated.AdminN
33Remote Desktop Protocol will use the RemoteFX guest mode module to connect to …OperationalY
34Remote Desktop Protocol will use the RemoteFX host mode module to connect to the …OperationalN
35Unable to initialize the RemoteFX host mode module.AdminN
36Unable to initialize the RemoteFX host mode module.AdminN
37The display resolution requested by the remote client is not supported by …OperationalN
38The display resolution requested by the remote client could not be enabled.OperationalN
65Connection ConnectionName created.OperationalY
66The connection ConnectionName was assigned to session SessionID.OperationalY
67The RemoteFX protocol connection ConnectionName encountered an error …OperationalN
68TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, …OperationalY
69Listener ModuleName is loaded.OperationalN
70The listener listens with display driver DisplayDriverName available.OperationalY
71The connection ConnectionName uses display driver DisplayDriverName.OperationalY
72Interface method called: Interface_method_called.OperationalY
73Inner encryption disabled?OperationalN
97The RDP protocol component ComponentName detected an error (ErrorCode) in the …OperationalN
98A TCP connection has been successfully established.OperationalY
99The TCP connection has failed with the error code ResultCode.OperationalN
100The server has confirmed that the client's multi-transport capability.OperationalY
101The network characteristics detection function has been disabled because of …OperationalY
102The server has terminated main RDP connection with the client.OperationalY
103The disconnect reason is ReasonCode.OperationalY
104Client timezone is TimezoneBiasHour hour from UTC.OperationalY
105The server's security layer setting allows it to use native RDP encryption, …AdminN
106Disconnect initiated by server; forcing an AutoReconnect since listener is …OperationalN
107Received Disconnect Provider Indication from the client.OperationalY
129The server is using TransportProtocolName to bind to port Port.OperationalY
130The server has initiated a multi-transport request to the client, for tunnel: …OperationalY
131The server accepted a new ConnType connection from client ClientIP.OperationalY
132A channel ChannelName has been connected between the server and the client using …OperationalY
133The following network characteristics have been detected for tunnel TunnelID; …OperationalN
134Link latency and bandwidth could not be detected for tunnel TunnelID.OperationalN
135The multi-transport connection finished for tunnel: …OperationalY
136Unable to establish a multi-transport connection; the connection will use TCP.OperationalN
137The following network characteristics have been detected for tunnel TunnelID; …OperationalN
138The DTLS initialization failed with the error code ResultCode, TLS will be used …AdminN
139The server security layer detected an error (ResultCode) in the protocol stream …OperationalN
140A connection from the client computer with an IP address of IPString failed …OperationalN
141PerfCounter session started with instance ID InstanceID.OperationalY
142TCP socket READ operation failed, error error.OperationalY
143TCP socket WRITE operation failed, error error.OperationalY
144TCP socket was gracefully terminatedOperationalY
145During this connection, server has not sent data or graphics update for Idle2 …OperationalY
146AutoReconnect failed with error Error.OperationalN
147LogonUserExEx failed with error Error.OperationalN
148Channel ChannelName has been closed between the server and the client on …OperationalY
149Logon certificate sent by client did not pass validation.OperationalN
150Long delay experienced while flushing data to the network.DebugN
151In the past ms_all_packets_throughout_connection ms, HistoryMs heartbeats were …DebugN
152Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last …DebugN
153Session negotiated TLS version TLSVersion.DebugN
154Message.OperationalN
155RDP Diagnostic HeartbeatDebugN
161The RemoteFX encoding engine encountered an error (ErrorCode).OperationalN
162The client supports version AVC_available of the RDP graphics protocol, client …OperationalY
163The client supports RDP 7.OperationalY
164The client advertised protocol configurations which are not supported by the …OperationalN
165RDP RemoteFX graphics encoding is enabled.OperationalN
166The RemoteFX Adaptive Graphics internal configuration changed to optimize for …OperationalN
167The RemoteFX Adaptive Graphics internal configuration changed to optimize for …OperationalN
168The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, …OperationalY
169The client operating system type is (MajorType, MinorType).OperationalY
170AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is …OperationalN
171The client is uncapable to support screen capture protection feature.OperationalN
172The client is uncapable to support watermarking feature.OperationalN
193The RemoteFX Media Remoting is not supported by the client.OperationalN
194The RemoteFX Media Remoting is not supported by the current server …OperationalN
195The RemoteFX Media Remoting module encountered an error.OperationalN
225StateTransition: Transitioned successfully from PreviousStateName to …DebugN
226StateTransition: An error was encountered when transitioning from …OperationalY
227CustomLevel.OperationalY
228Disconnect trace:Disconnect_trace Message, Error code:ErrorCode.OperationalY
229CustomLevel.OperationalY
257The connection is using advanced RemoteFX RemoteApp graphics.OperationalN
258The connection is not using advanced RemoteFX RemoteApp graphicsOperationalY
289Got UDP reverse connect request to URL port Port connection id ConnectionID.OperationalN
290UDP reverse connect successful.OperationalN
291UDP reverse connect failed with error Error.OperationalN
292Multi transport listener NOT initialized.OperationalN
293Multi transport listener initialized.OperationalN
294Reverse UDP connect is disabled by SxS registry settings.OperationalN

Event ID 1: The RDP Graphics module failed to initialize.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RDPStack
Opcode
Initialize

Description

The RDP Graphics module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status error code was HresultCode.

Message #

The RDP Graphics module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status error code was %1.

Fields #

NameDescription
HresultCode HexInt32

Event ID 2: Remote Desktop Protocol will use the RDP Graphics module to connect to the client computer.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RDPStack
Opcode
Initialize

Description

Remote Desktop Protocol will use the RDP Graphics module to connect to the client computer. The RDP Graphics module is being used based on the server configuration, client configuration, and network connection.

Message #

Remote Desktop Protocol will use the RDP Graphics module to connect to the client computer. The RDP Graphics module is being used based on the server configuration, client configuration, and network connection.

Event ID 3: The RemoteFX module failed to initialize.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was ErrorCode.

Message #

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 4: The RemoteFX module failed to initialize.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was ErrorCode.

Message #

The RemoteFX module failed to initialize. Verify that the server is correctly configured. A restart of the system may be needed. The relevant status code was %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 5: The client computer does not support RemoteFX.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The client computer does not support RemoteFX. The connection will be made with the RDP Graphics. The relevant status code was StatusCode.

Message #

The client computer does not support RemoteFX. The connection will be made with the RDP Graphics. The relevant status code was %1.

Fields #

NameDescription
StatusCode HexInt32NTSTATUS reference

Event ID 6: The resolution requested by the remote client is not supported by RemoteFX.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The resolution requested by the remote client is not supported by RemoteFX. The connection will be made with RemoteFX using a supported resolution. Resolution requested by the client: Monitors NumMonitors: RequestedMode. Resolution applied: AppliedMode.

Message #

The resolution requested by the remote client is not supported by RemoteFX. The connection will be made with RemoteFX using a supported resolution. Resolution requested by the client: Monitors %1: %2. Resolution applied: %3.

Fields #

NameDescription
NumMonitors UInt32
RequestedMode UnicodeString
AppliedMode UnicodeString

Event ID 7: The resolution requested by the remote client could not be set.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Initialize

Description

The resolution requested by the remote client could not be set. The default resolution will be set for the RemoteFX session. The server may be experiencing high load or require a restart.

Message #

The resolution requested by the remote client could not be set. The default resolution will be set for the RemoteFX session. The server may be experiencing high load or require a restart.

Event ID 8: Module terminated.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule
Opcode
Terminate

Description

Module terminated.

Message #

Module terminated.

Event ID 33: Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

Message #

Remote Desktop Protocol will use the RemoteFX guest mode module to connect to the client computer.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 33,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.553439Z",
    "event_record_id": 898,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 34: Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

Message #

Remote Desktop Protocol will use the RemoteFX host mode module to connect to the client computer.

Event ID 35: Unable to initialize the RemoteFX host mode module.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is HresultCode.

Message #

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is %1.

Fields #

NameDescription
HresultCode HexInt32

Event ID 36: Unable to initialize the RemoteFX host mode module.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
Initialize

Description

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is ErrorCode.

Message #

Unable to initialize the RemoteFX host mode module. Restart the computer to resolve the issue. If the issue is not resolved, verify the computer configuration.. The error code is %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 37: The display resolution requested by the remote client is not supported by RemoteFX host mode module.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The display resolution requested by the remote client is not supported by RemoteFX host mode module. The resolution requested by the client: Monitors NumMonitors: RequestedMode. Resolution applied: AppliedMode.

Message #

The display resolution requested by the remote client is not supported by RemoteFX host mode module. The resolution requested by the client: Monitors %1: %2. Resolution applied: %3.

Fields #

NameDescription
NumMonitors UInt32
RequestedMode UnicodeString
AppliedMode UnicodeString

Event ID 38: The display resolution requested by the remote client could not be enabled.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The display resolution requested by the remote client could not be enabled. The default resolution will be enabled for the RemoteFX session. The server may be experiencing high load.

Message #

The display resolution requested by the remote client could not be enabled. The default resolution will be enabled for the RemoteFX session. The server may be experiencing high load

Event ID 65: Connection ConnectionName created.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Connection ConnectionName created.

Message #

Connection %1 created

Fields #

NameDescription
ConnectionName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 65,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.546169Z",
    "event_record_id": 846,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1660
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#5"
  }
}

References #

Event ID 66: The connection ConnectionName was assigned to session SessionID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The connection ConnectionName was assigned to session SessionID.

Message #

The connection %1 was assigned to session %2

Fields #

NameDescription
ConnectionName UnicodeString
SessionID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 66,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.547380Z",
    "event_record_id": 897,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#7",
    "SessionID": 1
  }
}

References #

Event ID 67: The RemoteFX protocol connection ConnectionName encountered an error (ErrorCode).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The RemoteFX protocol connection ConnectionName encountered an error (ErrorCode).

Message #

The RemoteFX protocol connection %1 encountered an error (%2)

Fields #

NameDescription
ConnectionName UnicodeString
ErrorCode HexInt32

Event ID 68: TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, PromptForCredentialsDone=PromptForCredentialsDone, GfxChannelOpened=GfxChannelOpened, FirstGraphicsReceived=FirstGraph...

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

TMT: ConnectionName=ConnectionName, PromptForCredentials=PromptForCredentials, PromptForCredentialsDone=PromptForCredentialsDone, GfxChannelOpened=GfxChannelOpened, FirstGraphicsReceived=FirstGraphicsReceived [ms].

Message #

TMT: ConnectionName=%1, PromptForCredentials=%2, PromptForCredentialsDone=%3, GfxChannelOpened=%4, FirstGraphicsReceived=%5 [ms]

Fields #

NameDescription
ConnectionName UnicodeString
PromptForCredentials UInt32
PromptForCredentialsDone UInt32
GfxChannelOpened UInt32
FirstGraphicsReceived UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 68,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:15.885301Z",
    "event_record_id": 12592,
    "correlation": {
      "#attributes": {
        "ActivityID": "AF159B2D-D587-4709-AB35-F167130B0000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 8512
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#0",
    "PromptForCredentials": 0,
    "PromptForCredentialsDone": 0,
    "GfxChannelOpened": 8266,
    "FirstGraphicsReceived": 10672
  }
}

References #

Event ID 69: Listener ModuleName is loaded.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Listener ModuleName is loaded.

Message #

Listener %1 is loaded

Fields #

NameDescription
ModuleName UnicodeString

Event ID 70: The listener listens with display driver DisplayDriverName available.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The listener listens with display driver DisplayDriverName available.

Message #

The listener listens with display driver %1 available.

Fields #

NameDescription
DisplayDriverName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "{1139C61B-B549-4251-8ED3-27250A1EDEC8}",
    "event_source_name": "",
    "event_id": 70,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:32:54.1010884+00:00",
    "event_record_id": 104,
    "correlation": {
      "ActivityID": "{F462A52A-5DAA-46E2-960E-FB3B92800000}"
    },
    "execution": {
      "process_id": 1300,
      "thread_id": 1600
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "DisplayDriverName": "rdpudd.dll"
  },
  "message": "The listener listens with display driver rdpudd.dll available."
}

Event ID 71: The connection ConnectionName uses display driver DisplayDriverName.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

The connection ConnectionName uses display driver DisplayDriverName.

Message #

The connection %1 uses display driver %2.

Fields #

NameDescription
ConnectionName UnicodeString
DisplayDriverName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 71,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.622046Z",
    "event_record_id": 886,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7136
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnectionName": "RDP-Tcp#7",
    "DisplayDriverName": "RDPUDD"
  }
}

References #

Event ID 72: Interface method called: Interface_method_called.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Interface method called: Interface_method_called.

Message #

Interface method called: %1

Fields #

NameDescription
MethodName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 72,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 13,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.548440Z",
    "event_record_id": 847,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MethodName": "PrepareForAccept"
  }
}

References #

Event ID 73: Inner encryption disabled?

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
RCMProtocolImpl

Description

Inner encryption disabled? Disabled.

Message #

Inner encryption disabled? %1

Fields #

NameDescription
Disabled UInt32

Event ID 97: The RDP protocol component ComponentName detected an error (ErrorCode) in the protocol stream and the client was disconnected.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

The RDP protocol component ComponentName detected an error (ErrorCode) in the protocol stream and the client was disconnected.

Message #

The RDP protocol component %1 detected an error (%2) in the protocol stream and the client was disconnected.

Fields #

NameDescription
ComponentName UnicodeString
ErrorCode UInt32

Event ID 98: A TCP connection has been successfully established.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

A TCP connection has been successfully established.

Message #

A TCP connection has been successfully established.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 98,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624254Z",
    "event_record_id": 891,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 99: The TCP connection has failed with the error code ResultCode.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The TCP connection has failed with the error code ResultCode.

Message #

The TCP connection has failed with the error code %1.

Fields #

NameDescription
ResultCode HexInt32

Event ID 100: The server has confirmed that the client's multi-transport capability.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server has confirmed that the client's multi-transport capability.

Message #

The server has confirmed that the client's multi-transport capability.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 100,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624261Z",
    "event_record_id": 892,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 101: The network characteristics detection function has been disabled because of ReasonString.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The network characteristics detection function has been disabled because of ReasonString.

Message #

The network characteristics detection function has been disabled because of %1.

Fields #

NameDescription
ReasonString UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 101,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 16,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.621408Z",
    "event_record_id": 880,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ReasonString": "Reason Code: 2(Server Configuration)."
  }
}

References #

Event ID 102: The server has terminated main RDP connection with the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

The server has terminated main RDP connection with the client.

Message #

The server has terminated main RDP connection with the client.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 102,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852452Z",
    "event_record_id": 854,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 103: The disconnect reason is ReasonCode.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

The disconnect reason is ReasonCode.

Message #

The disconnect reason is %1

Fields #

NameDescription
ReasonCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 103,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852505Z",
    "event_record_id": 857,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ReasonCode": 14
  }
}

References #

Event ID 104: Client timezone is TimezoneBiasHour hour from UTC.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

Client timezone is TimezoneBiasHour hour from UTC.

Message #

Client timezone is %1 hour from UTC;

Fields #

NameDescription
TimezoneBiasHour UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 104,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2020-07-09T19:47:00.719124Z",
    "event_record_id": 1129,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420CA7A-0E56-4135-8A7C-CE2182D30000"
      }
    },
    "execution": {
      "process_id": 476,
      "thread_id": 4152
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TimezoneBiasHour": "[1]"
  }
}

References #

Event ID 105: The server's security layer setting allows it to use native RDP encryption, which is no longer recommended.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

The server's security layer setting allows it to use native RDP encryption, which is no longer recommended. Consider changing the server security layer to require SSL. You can change this setting in Group Policy.

Message #

The server's security layer setting allows it to use native RDP encryption, which is no longer recommended. Consider changing the server security layer to require SSL. You can change this setting in Group Policy.

Event ID 106: Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

Message #

Disconnect initiated by server; forcing an AutoReconnect since listener is disabled.

Event ID 107: Received Disconnect Provider Indication from the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Received Disconnect Provider Indication from the client.

Message #

Received Disconnect Provider Indication from the client.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 107,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T10:07:43.924049Z",
    "event_record_id": 1066,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4202795-713F-468C-BA0B-6C1C2F0C0000"
      }
    },
    "execution": {
      "process_id": 396,
      "thread_id": 1064
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 129: The server is using TransportProtocolName to bind to port Port.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
NetworkBinding

Description

The server is using TransportProtocolName to bind to port Port.

Message #

The server is using %1 to bind to port %2.

Fields #

NameDescription
TransportProtocolName UnicodeString
Port UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "{1139C61B-B549-4251-8ED3-27250A1EDEC8}",
    "event_source_name": "",
    "event_id": 129,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 18,
    "keywords": 4611686018427387904,
    "time_created": "2026-05-29T16:32:54.0988665+00:00",
    "event_record_id": 103,
    "correlation": {
      "ActivityID": "{F462A52A-5DAA-46E2-960E-FB3B92800000}"
    },
    "execution": {
      "process_id": 1300,
      "thread_id": 1600
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TransportProtocolName": "UDP",
    "Port": "3389"
  },
  "message": "The server is using UDP to bind to port 15629."
}

Event ID 130: The server has initiated a multi-transport request to the client, for tunnel: The_server_has_initiated_a_multitransport_request_to_the_client_for_tunnel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server has initiated a multi-transport request to the client, for tunnel: The_server_has_initiated_a_multitransport_request_to_the_client_for_tunnel.

Message #

The server has initiated a multi-transport request to the client, for tunnel: %1.

Fields #

NameDescription
TunnelIDThe server has initiated a multi-transport request to the client, for tunnel.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 130,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.625322Z",
    "event_record_id": 894,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TunnelID": 1
  }
}

References #

Event ID 131: The server accepted a new ConnType connection from client ClientIP.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The server accepted a new ConnType connection from client ClientIP.

Message #

The server accepted a new %1 connection from client %2.

Fields #

NameDescription
ConnType UnicodeString
ClientIP UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 131,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:07.084053Z",
    "event_record_id": 12551,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4207C37-D7A8-4A5E-9A35-4E79CAA60000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 1292
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ConnType": "TCP",
    "ClientIP": "10.0.2.16:52202"
  }
}

References #

Event ID 132: A channel ChannelName has been connected between the server and the client using transport tunnel: TunnelID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

A channel ChannelName has been connected between the server and the client using transport tunnel: TunnelID.

Message #

A channel %1 has been connected between the server and the client using transport tunnel: %2.

Fields #

NameDescription
ChannelName UnicodeString
TunnelID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 132,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.621433Z",
    "event_record_id": 881,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ChannelName": "rdplic",
    "TunnelID": 0
  }
}

References #

Event ID 133: The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

Message #

The following network characteristics have been detected for tunnel %1; Link latency : %2 milliseconds and Bandwidth: %3 kbps.

Fields #

NameDescription
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 134: Link latency and bandwidth could not be detected for tunnel TunnelID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

Link latency and bandwidth could not be detected for tunnel TunnelID. The error code is ResultCode. The following default network characteristics will be used; Link latency: RTT milliseconds and Bandwidth:Bandwidth kbps.

Message #

Link latency and bandwidth could not be detected for tunnel %2.  The error code is %1. The following default network characteristics will be used;  Link latency: %3 milliseconds and Bandwidth:%4 kbps.

Fields #

NameDescription
ResultCode HexInt32
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 135: The multi-transport connection finished for tunnel: The_multitransport_connection_finished_for_tunnel, its transport type set to TransportType.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The multi-transport connection finished for tunnel: The_multitransport_connection_finished_for_tunnel, its transport type set to TransportType.

Message #

The multi-transport connection finished for tunnel: %1, its transport type set to %2.

Fields #

NameDescription
TunnelIDThe multi-transport connection finished for tunnel.
TransportType

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 135,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.624288Z",
    "event_record_id": 893,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1692
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "TunnelID": 3,
    "TransportType": "TCP: Reason Code: 2 (Forced by Server Configuration)"
  }
}

References #

Event ID 136: Unable to establish a multi-transport connection; the connection will use TCP.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

Unable to establish a multi-transport connection; the connection will use TCP. Consult the product documentation to enable UDP Connections.

Message #

Unable to establish a multi-transport connection; the connection will use TCP. Consult the product documentation to enable UDP Connections.

Event ID 137: The following network characteristics have been detected for tunnel TunnelID; Link latency : RTT milliseconds and Bandwidth: Bandwidth kbps.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
NetworkDetect

Description

The following network characteristics have been detected for tunnel ; Link latency : milliseconds and Bandwidth: kbps. Connections with these network characteristics may impact user experience.

Message #

The following network characteristics have been detected for tunnel %1; Link latency : %2 milliseconds and Bandwidth: %3 kbps. Connections with these network characteristics may impact user experience.

Fields #

NameDescription
TunnelID UInt32
RTT UInt32
Bandwidth UInt32

Event ID 138: The DTLS initialization failed with the error code ResultCode, TLS will be used instead.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Admin
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

The DTLS initialization failed with the error code ResultCode, TLS will be used instead. Audio/Video experience may be impacted.

Message #

The DTLS initialization failed with the error code %1, TLS will be used instead. Audio/Video experience may be impacted.

Fields #

NameDescription
ResultCode HexInt32

Event ID 139: The server security layer detected an error (ResultCode) in the protocol stream and the client (Client IP:IPString) has been disconnected.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

The server security layer detected an error (ResultCode) in the protocol stream and the client (Client IP:IPString) has been disconnected.

Message #

The server security layer detected an error (%1) in the protocol stream and the client (Client IP:%2) has been disconnected.

Fields #

NameDescription
ResultCode HexInt32
IPString UnicodeString

Event ID 140: A connection from the client computer with an IP address of IPString failed because the user name or password is not correct.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
ProtocolExchange

Description

A connection from the client computer with an IP address of IPString failed because the user name or password is not correct.

Message #

A connection from the client computer with an IP address of %1 failed because the user name or password is not correct.

Fields #

NameDescription
IPString UnicodeString

Event ID 141: PerfCounter session started with instance ID InstanceID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

PerfCounter session started with instance ID InstanceID.

Message #

PerfCounter session started with instance ID %1

Fields #

NameDescription
InstanceID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 141,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:28.549456Z",
    "event_record_id": 849,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6492
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "InstanceID": 5
  }
}

References #

Event ID 142: TCP socket READ operation failed, error error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket READ operation failed, error error.

Message #

TCP socket READ operation failed, error %1

Fields #

NameDescription
error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 142,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851987Z",
    "event_record_id": 852,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 6776
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "error": 64
  }
}

References #

Event ID 143: TCP socket WRITE operation failed, error error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket WRITE operation failed, error error.

Message #

TCP socket WRITE operation failed, error %1

Fields #

NameDescription
error UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 143,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851924Z",
    "event_record_id": 850,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 4988
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "error": 64
  }
}

References #

Event ID 144: TCP socket was gracefully terminated

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
EstablishConnection

Description

TCP socket was gracefully terminated.

Message #

TCP socket was gracefully terminated

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 144,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 15,
    "keywords": 4611686018427387904,
    "time_created": "2026-03-11T10:16:51.112394+00:00",
    "event_record_id": 4129,
    "correlation": {
      "ActivityID": "F420FF93-1637-4090-92CE-51A628CA0000"
    },
    "execution": {
      "process_id": 1536,
      "thread_id": 9036
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {},
  "message": ""
}

Event ID 145: During this connection, server has not sent data or graphics update for Idle2 seconds (Idle1: IdleSeconds1, Idle2: IdleSeconds2).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

During this connection, server has not sent data or graphics update for Idle2 seconds (Idle1: IdleSeconds1, Idle2: IdleSeconds2).

Message #

During this connection, server has not sent data or graphics update for %1 seconds (Idle1: %2, Idle2: %3).

Fields #

NameDescription
IdleSeconds
IdleSeconds1
IdleSeconds2

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 145,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852455Z",
    "event_record_id": 855,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "IdleSeconds": 0,
    "IdleSeconds1": 0,
    "IdleSeconds2": 0
  }
}

References #

Event ID 146: AutoReconnect failed with error Error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

AutoReconnect failed with error Error.

Message #

AutoReconnect failed with error %1

Fields #

NameDescription
Error UnicodeString

Event ID 147: LogonUserExEx failed with error Error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

LogonUserExEx failed with error Error.

Message #

LogonUserExEx failed with error %1

Fields #

NameDescription
Error HexInt32

Event ID 148: Channel ChannelName has been closed between the server and the client on transport tunnel: TunnelID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
CloseConnection

Description

Channel ChannelName has been closed between the server and the client on transport tunnel: TunnelID.

Message #

Channel %1 has been closed between the server and the client on transport tunnel: %2.

Fields #

NameDescription
ChannelName UnicodeString
TunnelID UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 148,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 17,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.852505Z",
    "event_record_id": 856,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 1644
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ChannelName": "rdpinpt",
    "TunnelID": 0
  }
}

References #

Event ID 149: Logon certificate sent by client did not pass validation.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Logon certificate sent by client did not pass validation. Error: ErrorCode.

Message #

Logon certificate sent by client did not pass validation. Error: %1

Fields #

NameDescription
ErrorCode HexInt32

Event ID 150: Long delay experienced while flushing data to the network.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Long delay experienced while flushing data to the network. Flush time: FlushTimeMs ms, flush interval: FlushIntervalMs ms.

Message #

Long delay experienced while flushing data to the network. Flush time: %1 ms, flush interval: %2 ms.

Fields #

NameDescription
FlushTimeMs UInt32
FlushIntervalMs UInt32

Event ID 151: In the past ms_all_packets_throughout_connection ms, HistoryMs heartbeats were sent to the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

In the past HistoryMs ms, NumHeartbeats heartbeats were sent to the client. Max time without sending packets in recent history: MaxRecentTimeNoPacketMs ms (all packets); throughout connection: MaxTotalTimeNoDataMs ms (data), MaxTotalTimeNoHeartbeatMs ms (heartbeats), MaxTotalTimeNoPacketMs ms (all packets). Time between disconnect and last packet sent: TimeNoLastPacketMs ms

Message #

In the past %1 ms, %2 heartbeats were sent to the client. Max time without sending packets in recent history: %3 ms (all packets); throughout connection: %4 ms (data), %5 ms (heartbeats), %6 ms (all packets). Time between disconnect and last packet sent: %7 ms

Fields #

NameDescription
HistoryMs UInt32
NumHeartbeats UInt32
MaxRecentTimeNoPacketMs UInt32
MaxTotalTimeNoDataMs UInt32
MaxTotalTimeNoHeartbeatMs UInt32
MaxTotalTimeNoPacketMs UInt32
TimeNoLastPacketMs UInt32

Event ID 152: Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last sent: data_packet_last_sent ms, heartbeat last sent: ms_heartbeat_last_sent ms.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Timestamp: Timestamp ms, heartbeats sent: ms_heartbeats_sent, data packet last sent: data_packet_last_sent ms, heartbeat last sent: ms_heartbeat_last_sent ms.

Message #

Timestamp: %1 ms, heartbeats sent: %2, data packet last sent: %3 ms, heartbeat last sent: %4 ms.

Fields #

NameDescription
TimestampMs UInt32
NumHeartbeats UInt32
LastDataPacketMs UInt32
LastHeartbeatMs UInt32

Event ID 153: Session negotiated TLS version TLSVersion.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Session negotiated TLS version TLSVersion.

Message #

Session negotiated TLS version %1

Fields #

NameDescription
TLSVersion UnicodeString

Event ID 154: Message.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Message. Error Error

Message #

%1. Error %2

Fields #

NameDescription
Message UnicodeString
Error HexInt32

Event ID 155: RDP Diagnostic Heartbeat

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

RDP Diagnostic Heartbeat.

Message #

RDP Diagnostic Heartbeat

Event ID 161: The RemoteFX encoding engine encountered an error (ErrorCode).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX encoding engine encountered an error (ErrorCode). Server: ServerName.

Message #

The RemoteFX encoding engine encountered an error (%1). Server: %2

Fields #

NameDescription
ErrorCode HexInt32
ServerName UnicodeString

Event ID 162: The client supports version AVC_available of the RDP graphics protocol, client mode: Initial_profile, AVC available: Server, Initial profile: ProfileIdNum.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client supports version AVC_available of the RDP graphics protocol, client mode: Initial_profile, AVC available: Server, Initial profile: ProfileIdNum. Server: ServerName.

Message #

The client supports version %1 of the RDP graphics protocol, client mode: %2, AVC available: %3, Initial profile: %4. Server: %5

Fields #

NameDescription
Version
ClientMode
AvcEnabled
ProfileIdNum
ServerName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 162,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.742779Z",
    "event_record_id": 908,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 8020
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Version": "0xa0301",
    "ClientMode": 2,
    "AvcEnabled": 1,
    "ProfileIdNum": 2,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 163: The client supports RDP 7.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client supports RDP 7.1 or lower protocol. Server: Server.

Message #

The client supports RDP 7.1 or lower protocol. Server: %1

Fields #

NameDescription
ServerName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 163,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T14:22:27.573268Z",
    "event_record_id": 1356,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4201740-D459-489E-A55C-BFE842340000"
      }
    },
    "execution": {
      "process_id": 396,
      "thread_id": 1336
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 164: The client advertised protocol configurations which are not supported by the server.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client advertised protocol configurations which are not supported by the server. Server: ServerName.

Message #

The client advertised protocol configurations which are not supported by the server. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 165: RDP RemoteFX graphics encoding is enabled.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

RDP RemoteFX graphics encoding is enabled. Server: ServerName.

Message #

RDP RemoteFX graphics encoding is enabled. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 166: The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth. Server: ServerName.

Message #

The RemoteFX Adaptive Graphics internal configuration changed to optimize for the minimum use of network bandwidth. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 167: The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience. Server: ServerName.

Message #

The RemoteFX Adaptive Graphics internal configuration changed to optimize for experience. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 168: The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, MonitorHeight), origin: (MonitorX, MonitorY).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Initialize

Description

The resolution requested by the client: Monitor MonitorNum: (MonitorWidth, MonitorHeight), origin: (MonitorX, MonitorY). Server: ServerName.

Message #

The resolution requested by the client: Monitor %1: (%2, %3), origin: (%4, %5). Server: %6

Fields #

NameDescription
MonitorNum UInt32
MonitorWidth UInt32
MonitorHeight UInt32
MonitorX UInt32
MonitorY UInt32
ServerName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 168,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 11,
    "keywords": 4611686018427387904,
    "time_created": "2020-11-13T11:09:15.564770Z",
    "event_record_id": 12591,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4207C37-D7A8-4A5E-9A35-4E79CAA60000"
      }
    },
    "execution": {
      "process_id": 388,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MonitorNum": 0,
    "MonitorWidth": 200,
    "MonitorHeight": 200,
    "MonitorX": 0,
    "MonitorY": 0,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 169: The client operating system type is (MajorType, MinorType).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client operating system type is (MajorType, MinorType). Server: ServerName.

Message #

The client operating system type is (%1, %2).  Server: %3

Fields #

NameDescription
MajorType UInt32
MinorType UInt32
ServerName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 169,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:46.567652Z",
    "event_record_id": 902,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7312
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "MajorType": 1,
    "MinorType": 3,
    "ServerName": "MSEDGEWIN10"
  }
}

References #

Event ID 170: AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is IsHardwareEncode.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

AVC hardware encoder enabled: AVC_hardware_encoder_enabled, encoder name is IsHardwareEncode. Server: EncoderMFTName.

Message #

AVC hardware encoder enabled: %1, encoder name is %2. Server: %3

Fields #

NameDescription
IsHardwareEncode UInt32
EncoderMFTName UnicodeString
ServerName UnicodeString

Event ID 171: The client is uncapable to support screen capture protection feature.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client is uncapable to support screen capture protection feature. Server: ServerName.

Message #

The client is uncapable to support screen capture protection feature. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 172: The client is uncapable to support watermarking feature.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The client is uncapable to support watermarking feature. Server: ServerName.

Message #

The client is uncapable to support watermarking feature. Server: %1

Fields #

NameDescription
ServerName UnicodeString

Event ID 193: The RemoteFX Media Remoting is not supported by the client.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting is not supported by the client.

Message #

The RemoteFX Media Remoting is not supported by the client.

Event ID 194: The RemoteFX Media Remoting is not supported by the current server configuration.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting is not supported by the current server configuration.

Message #

The RemoteFX Media Remoting is not supported by the current server configuration.

Event ID 195: The RemoteFX Media Remoting module encountered an error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

The RemoteFX Media Remoting module encountered an error. The error code is ErrorCode.

Message #

The RemoteFX Media Remoting module encountered an error. The error code is %1.

Fields #

NameDescription
ErrorCode HexInt32

Event ID 225: StateTransition: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Debug
Task
RemoteFXmodule_4
Opcode
Runtime

Description

StateTransition: Transitioned successfully from PreviousStateName to NewStateName in response to EventName.

Message #

%1: Transitioned successfully from %3 to %5 in response to %7.

Fields #

NameDescription
StateTransition UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString

Event ID 226: StateTransition: An error was encountered when transitioning from PreviousStateName in response to EventName (error code ErrorCode).

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
Runtime

Description

StateTransition: An error was encountered when transitioning from PreviousStateName in response to EventName (error code ErrorCode).

Message #

%1: An error was encountered when transitioning from %3 in response to %7 (error code %8).

Fields #

NameDescription
StateTransition UnicodeString
PreviousState UInt32
PreviousStateName UnicodeString
NewState UInt32
NewStateName UnicodeString
Event UInt32
EventName UnicodeString
ErrorCode HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 226,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:16:34.851971Z",
    "event_record_id": 851,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420DD64-C87E-4E2D-A02E-7D0935770000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 4988
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "StateTransition": "RDP_TCP",
    "PreviousState": 23,
    "PreviousStateName": "StateUnknown",
    "NewState": 21,
    "NewStateName": "StateDisconnected",
    "Event": 43,
    "EventName": "Event_Disconnect",
    "ErrorCode": "0x80070040"
  }
}

References #

Event ID 227: CustomLevel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Error
Task
RemoteFXmodule_4
Opcode
Runtime

Description

CustomLevel

Message #

%3

Fields #

NameDescription
Name UnicodeString
Value UInt32
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 227,
    "version": 0,
    "level": 2,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:45.622336Z",
    "event_record_id": 887,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7136
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Name": "CUMRDPConnection",
    "Value": 2147500033,
    "CustomLevel": "'Failed GetConnectionProperty' in CUMRDPConnection::QueryProperty at 2884 err=[0x80004001]"
  }
}

References #

Event ID 228: Disconnect trace:Disconnect_trace Message, Error code:ErrorCode.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Warning
Task
RemoteFXmodule_4
Opcode
Runtime

Description

Disconnect trace:Disconnect_trace Message, Error code:ErrorCode.

Message #

Disconnect trace:%1 %2, Error code:%3

Fields #

NameDescription
ComponentName
Message
ErrorCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 228,
    "version": 0,
    "level": 3,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:26:41.767599Z",
    "event_record_id": 938,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7572
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "ComponentName": "CUMRDPConnection",
    "Message": "Disconnect trace:'calling spGfxPlugin->PreDisconnect()' in CUMRDPConnection::PreDisconnect at 4595 err=[0x5]",
    "ErrorCode": 5
  }
}

References #

Event ID 229: CustomLevel.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
Runtime

Description

CustomLevel

Message #

%2

Fields #

NameDescription
Name UnicodeString
CustomLevel UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 229,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 19,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-28T03:36:49.647283Z",
    "event_record_id": 975,
    "correlation": {
      "#attributes": {
        "ActivityID": "F4624E4C-DF38-4BB3-A4DB-3782C9880000"
      }
    },
    "execution": {
      "process_id": 480,
      "thread_id": 1196
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {
    "Name": "CUMRDPProtocolManager",
    "CustomLevel": "'CUMRDPProtocolManager::CreateListener(RDP-Tcp) DEBUG/VM/ReverseTCP/ReverseUDP/INET' in CUMRDPProtocolManager::CreateListener at 4134 err=[0x0]"
  }
}

References #

Event ID 257: The connection is using advanced RemoteFX RemoteApp graphics.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
AdvancedRemoteAppEnabled

Description

The connection is using advanced RemoteFX RemoteApp graphics.

Message #

The connection is using advanced RemoteFX RemoteApp graphics.

Event ID 258: The connection is not using advanced RemoteFX RemoteApp graphics

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Level
Informational
Task
RemoteFXmodule_4
Opcode
AdvancedRemoteAppNotEnabled

Description

The connection is not using advanced RemoteFX RemoteApp graphics.

Message #

The connection is not using advanced RemoteFX RemoteApp graphics

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS",
    "guid": "1139C61B-B549-4251-8ED3-27250A1EDEC8",
    "event_source_name": "",
    "event_id": 258,
    "version": 0,
    "level": 4,
    "task": 4,
    "opcode": 21,
    "keywords": 4611686018427387904,
    "time_created": "2019-08-27T17:17:47.617830Z",
    "event_record_id": 915,
    "correlation": {
      "#attributes": {
        "ActivityID": "F420C5E0-91BA-4CF1-97FF-34CCD7200000"
      }
    },
    "execution": {
      "process_id": 636,
      "thread_id": 7572
    },
    "channel": "Microsoft-Windows-RemoteDesktopServices-RdpCoreTS/Operational",
    "computer": "MSEDGEWIN10",
    "security": {
      "user_id": "S-1-5-20"
    }
  },
  "event_data": {}
}

References #

Event ID 289: Got UDP reverse connect request to URL port Port connection id ConnectionID.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Got UDP reverse connect request to URL port Port connection id ConnectionID.

Message #

Got UDP reverse connect request to %1 port %2 connection id %3.

Fields #

NameDescription
URL UnicodeString
Port UInt32
ConnectionID UnicodeString

Event ID 290: UDP reverse connect successful.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

UDP reverse connect successful.

Message #

UDP reverse connect successful.

Event ID 291: UDP reverse connect failed with error Error.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

UDP reverse connect failed with error Error.

Message #

UDP reverse connect failed with error %1.

Fields #

NameDescription
Error HexInt32

Event ID 292: Multi transport listener NOT initialized.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Multi transport listener NOT initialized. UDP reverse connect NOT supported.

Message #

Multi transport listener NOT initialized. UDP reverse connect NOT supported.

Event ID 293: Multi transport listener initialized.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Multi transport listener initialized. UDP reverse connect supported.

Message #

Multi transport listener initialized. UDP reverse connect supported.

Event ID 294: Reverse UDP connect is disabled by SxS registry settings.

#
Provider
Microsoft-Windows-RemoteDesktopServices-RdpCoreTS
Channel
Operational
Task
RemoteFXmodule_4
Opcode
UDPReverseConnect

Description

Reverse UDP connect is disabled by SxS registry settings.

Message #

Reverse UDP connect is disabled by SxS registry settings.

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 1139c61b-b549-4251-8ed3-27250a1edec8

Defined in RdpCoreTS.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads