Microsoft-Windows-Resource-Exhaustion-Resolver
17 events across 1 channel
Event ID 1001: The Windows Resource Exhaustion Resolver started.
#Description
The Windows Resource Exhaustion Resolver started.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Resource-Exhaustion-Resolver",
"guid": "{91F5FB12-FDEA-4095-85D5-614B495CD9DE}",
"event_source_name": "",
"event_id": 1001,
"version": 0,
"level": 4,
"task": 1,
"opcode": 11,
"keywords": -9223372036854771712,
"time_created": "2026-05-29T06:44:06.0373204+00:00",
"event_record_id": 4,
"correlation": {},
"execution": {
"process_id": 2368,
"thread_id": 2008
},
"channel": "Microsoft-Windows-Resource-Exhaustion-Resolver/Operational",
"computer": "telemetry-DC-b.cell-b.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"event_data": {},
"message": "The Windows Resource Exhaustion Resolver started."
}
Event ID 1002: The Windows Resource Exhaustion Resolver stopped.
#Description
The Windows Resource Exhaustion Resolver stopped.
Message #
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Resource-Exhaustion-Resolver",
"event_id": 1002,
"level": "Information",
"task": "Lifecycle Events",
"opcode": "Events logged when the resource exhaustion resolver is stopped.",
"time_created": "2026-04-22T05:44:22.3054467+00:00",
"computer": "JD-DC01-2022.ludus.domain",
"channel": "Microsoft-Windows-Resource-Exhaustion-Resolver/Operational"
},
"event_data": {}
}
Event ID 1003: The Windows Resource Exhaustion Resolver received a notification that the computer is low on virtual memory.
#Description
The Windows Resource Exhaustion Resolver received a notification that the computer is low on virtual memory. This notification was ignored as it is no longer valid.
Message #
Fields #
| Name | Description |
|---|---|
TimeSinceLastUI UInt32 | |
EventGenerationTime FILETIME | |
EventType UInt32 | |
DropReasonCode UInt32 | |
TimesUIShown UInt8 | |
MaxCommit UInt8 |
Event ID 1004: The Windows Resource Exhaustion Resolver close programs UI was launched.
#Description
The Windows Resource Exhaustion Resolver close programs UI was launched.
Message #
Fields #
| Name | Description |
|---|---|
Process_1_Name UnicodeString | |
Process_1_ID UInt32 | |
Process_1_CreationTime FILETIME | |
Process_1_Version UnicodeString | |
Process_2_Name UnicodeString | |
Process_2_ID UInt32 | |
Process_2_CreationTime FILETIME | |
Process_2_Version UnicodeString | |
Process_3_Name UnicodeString | |
Process_3_ID UInt32 | |
Process_3_CreationTime FILETIME | |
Process_3_Version UnicodeString | |
ResolverID UInt32 | |
EventGenerationTime FILETIME |
Event ID 1005: The Windows Resource Exhaustion Resolver failed to start due to an error.
#Event ID 1006: The Windows Resource Exhaustion Resolver failed to stop due to an error.
#Event ID 1007: The Windows Resource Exhaustion Resolver experienced a memory allocation failure.
#Event ID 1008: The Windows Resource Exhaustion Resolver failed to launch the close programs UI.
#Event ID 1009: The Windows Resource Exhaustion Resolver close programs UI was closed.
#Event ID 1010: Windows could not restore the computer's virtual memory.
#Event ID 1011: Windows could not restore the computer's virtual memory because some programs could not be closed.
#Event ID 1012: Windows successfully restored your computer's virtual memory.
#Event ID 1013: Windows successfully restored your computer's virtual memory without closing any programs.
#Event ID 1014: The Windows Resource Exhaustion Resolver received a notification to perform memory leak diagnosis.
#Description
The Windows Resource Exhaustion Resolver received a notification to perform memory leak diagnosis. This notification was processed and dropped.
Message #
Fields #
| Name | Description |
|---|---|
DroppedLeakDiagnosisEventInfo.ProcessImageName | |
DroppedLeakDiagnosisEventInfo.ProcessId | |
DroppedLeakDiagnosisEventInfo.ProcessCreationTime | |
DroppedLeakDiagnosisEventInfo.DropReasonCode | |
ProcessImageName | |
PID | |
CreationTime | |
DropReasonCode |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Resource-Exhaustion-Resolver",
"guid": "{91F5FB12-FDEA-4095-85D5-614B495CD9DE}",
"event_source_name": "",
"event_id": 1014,
"version": 0,
"level": 4,
"task": 5,
"opcode": 41,
"keywords": -9223372036854759424,
"time_created": "2026-05-29T06:44:08.0835351+00:00",
"event_record_id": 6,
"correlation": {
"ActivityID": "{559E5142-CDCD-4213-BC43-A528C3D24645}"
},
"execution": {
"process_id": 2368,
"thread_id": 2008
},
"channel": "Microsoft-Windows-Resource-Exhaustion-Resolver/Operational",
"computer": "telemetry-DC-b.cell-b.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"user_data": {
"DroppedLeakDiagnosisEventInfo": {
"ProcessImageName": "wsmprovhost.exe",
"ProcessId": "5772",
"ProcessCreationTime": "2026-05-29T06:42:05.7051460Z",
"DropReasonCode": "16"
}
},
"message": "The Windows Resource Exhaustion Resolver received a notification to perform memory leak diagnosis. This notification was processed and dropped."
}
Event ID 1015: The Windows Resource Exhaustion Resolver received an event from the Windows Resource Exhaustion Detector.
#Description
The Windows Resource Exhaustion Resolver received an event from the Windows Resource Exhaustion Detector.
Message #
Fields #
| Name | Description |
|---|---|
EventInfo.Event | |
Event |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-Resource-Exhaustion-Resolver",
"guid": "{91F5FB12-FDEA-4095-85D5-614B495CD9DE}",
"event_source_name": "",
"event_id": 1015,
"version": 0,
"level": 4,
"task": 3,
"opcode": 21,
"keywords": -9223372036854767616,
"time_created": "2026-05-29T06:44:06.0374855+00:00",
"event_record_id": 5,
"correlation": {
"ActivityID": "{559E5142-CDCD-4213-BC43-A528C3D24645}"
},
"execution": {
"process_id": 2368,
"thread_id": 2008
},
"channel": "Microsoft-Windows-Resource-Exhaustion-Resolver/Operational",
"computer": "telemetry-DC-b.cell-b.ludus.domain",
"security": {
"user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
}
},
"user_data": {
"EventInfo": {
"Event": "4"
}
},
"message": "The Windows Resource Exhaustion Resolver received an event from the Windows Resource Exhaustion Detector."
}
Event ID 1016: Windows could not restore the computer's virtual memory.
#Event ID 1017: The Windows Resource Exhaustion Resolver resolution failure notification UI was closed.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 91f5fb12-fdea-4095-85d5-614b495cd9de
Defined in radarrs.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02