Microsoft-Windows-Servicing

EventTitleChannelSampleRule
1Initiating changes for package CbsPackageInitiateChanges.PackageIdentifier.SetupYN
2Package CbsPackageChangeState.PackageIdentifier was successfully changed to the …SetupYN
3Package identifier failed to be changed to the targetPackageState state.SetupNN
4A reboot is necessary before package CbsPackageChangeState.PackageIdentifier can …SetupYN
5The servicing request received for package identifier cannot be satisfied since …SetupNN
6Package identifier failed to be changed to the targetPackageState state and is …SetupNN
7Initiating changes to turn on update CbsUpdateChangeState.UpdateName of package …SetupYN
8Initiating changes to turn off update updateName of package identifier.SetupYN
9Selectable update CbsUpdateChangeState.UpdateName of package …SetupYY
10Selectable update updateName of package identifier was successfully turned off.SetupYN
11Update CbsUpdateChangeState.UpdateName of package …SetupYN
12Update updateName of package identifier failed to be turned off.SetupNN
13A reboot is necessary before the selectable update …SetupYN
14A reboot is necessary before the selectable update updateName of package …SetupYN
15Selectable update updateName of package identifier was successfully turned off …SetupYN
16Update updateName of package identifier failed to be turned off.SetupNN
17Report:[EventReport].DebugNN
18START [Resolve]:[EventReport].DebugNN
20END [Resolve]:[EventReport].DebugNN
21START [Execute]:[EventReport].DebugNN
23END [Execute]:[EventReport].DebugNN
24START [Stage]:[EventReport].DebugNN
26END [Stage]:[EventReport].DebugNN
33START [DPX Expansion]:[EventReport].DebugNN
34END [DPX Expansion]:[EventReport].DebugNN
35START [Doq Stage]:[EventReport].DebugNN
37END [Doq Stage]:[EventReport].DebugNN
38START [Doq Unstage]:[EventReport].DebugNN
39END [Doq Unstage]:[EventReport].DebugNN
40START [Doq Critical Install]:[EventReport].DebugNN
41END [Doq Critical Install]:[EventReport].DebugNN
42START [Doq Install]:[EventReport].DebugNN
43END [Doq Install]:[EventReport].DebugNN
44STARt [Doq Critical Uninstall]:[EventReport].DebugNN
45END [Doq Critical Uninstall]:[EventReport].DebugNN
46START [Doq Uninstall]:[EventReport].DebugNN
47END [Doq Uninstall]:[EventReport].DebugNN
48START [Doq Device Install]:[EventReport].DebugNN
49END [Doq Device Install]:[EventReport].DebugNN
50START [InstallUninstall]:[EventReport].DebugNN
51END [InstallUninstall]:[EventReport].DebugNN
52START [Poqexec]:[EventReport].DebugNN
53END [Poqexec]:[EventReport].DebugNN
54START [Shutdown Processing]:[EventReport].DebugNN
55END [Shutdown Processing]:[EventReport].DebugNN
56START [Non-Critical Doq]:[EventReport].DebugNN
57END [Non-Critical Doq]:[EventReport].DebugNN
58START [Critical Doq]:[EventReport].DebugNN
59END [Critical Doq]:[EventReport].DebugNN
60START [Plan Package]:[EventReport].DebugNN
61END [Plan Package]:[EventReport].DebugNN
62TrustedInstaller Finalize Event Report:[EventReport].DebugNN
63TrustedInstaller Initialize Event Report:[EventReport].DebugNN
64Doq Stage Progress Event Report:[EventReport].DebugNN
65Doq Unstage Progress Event Report:[EventReport].DebugNN
66Doq Install Progress Event Report:[EventReport].DebugNN
67Doq Uninstall Progress Event Report:[EventReport].DebugNN
68Startup Complete Event Report:[EventReport].DebugNN
69START [AI Queue Processing]:[DescString].DebugNN
70END [AI Queue Processing]:[DescString].DebugNN
71START [AI Install]:[Description = [DescString], Phase = [Phase], Mode = [Mode], …DebugNN
72END [AI Install]:[Status=[DescString]].DebugNN
73Report: [DescString].DebugNN
74CSI INSTALL Deployment Event Report: [DescString].DebugNN
75CSI UNINSTALL Deployment Event Report: [DescString].DebugNN
76START [KTM Transaction]:[DescString].DebugNN
77END [KTM Transaction]:[DescString].DebugNN
78CSI COMPRESS Event Report: [DescString].DebugNN
79CSI Stage Component Event Report: [DescString].DebugNN
80CSI AI Completion Event Report: [DescString].DebugNN
82START [CSI SMIPI]:[DescString].DebugNN
83END [CSI SMIPI]:[DescString].DebugNN
84CSI SMIPI INSTALL Event Report: [DescString].DebugNN
85CSI Transaction Start Event Report: [DescString].DebugNN
86CSI Transaction End Event Report: [DescString].DebugNN
87START [CSI Corruption Detection Event]:[DescString].DebugNN
88END [CSI Corruption Detection Event]:[DescString].DebugNN
89START [CSI Corruption Repair Event]:[DescString].DebugNN
90END [CSI Corruption Repair Event]:[DescString].DebugNN
91START [CSI Scavenge]:[DescString].DebugNN
92END [CSI Scavenge]:[DescString].DebugNN
93START [CBS Scavenge]:[EventReport].DebugNN
94END [CBS Scavenge]:[EventReport].DebugNN
95START [Archive Logs]:[EventReport].DebugNN
96END [Archive Logs]:[EventReport].DebugNN
97START [Drain Catalogs]:[EventReport].DebugNN
98END [Drain Catalogs]:[EventReport].DebugNN
99START [Automatic Deepclean]:[EventReport].DebugNN
100END [Automatic Deepclean]:[EventReport].DebugNN
101START [Manual Deepclean]:[EventReport].DebugNN
102END [Manual Deepclean]:[EventReport].DebugNN
103START [Delete Session Files]:[EventReport].DebugNN
104END [Delete Session Files]:[EventReport].DebugNN
105Progress: UI message updated.DebugNN
1000Windows Servicing is processing hotpatch package identifier(releaseType).SetupNN
1001Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1002Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1003Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1004Windows Servicing successfully installed hotpatching package …SetupNN
1005Windows Servicing has required a reboot to complete the installation of …SetupNN
1006Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1007Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1008Windows Servicing failed to perform hotpatching for package …SetupNN
1009Windows Servicing failed to perform hotpatching for package …SetupNN
1010Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1011Windows Servicing disabled hotpatching for package identifier(releaseType) …SetupNN
1012Windows Servicing disabled hotpatching for package identifier(releaseType) to …SetupNN
1013Initiating system store corruption detection and repair.SetupYN
1014System store corruption detection and repair has completed.SetupYN
1015repaired of totalCorruption instances of system store corruption have been …SetupYN
4371Windows Servicing started a process of changing package identifier(releaseType) …OperationalNN
4372Windows Servicing is setting package identifier(releaseType) state to …OperationalNN
4373Windows Servicing successfully set package identifier(releaseType) state to …OperationalNN
4374Windows Servicing identified that package identifier(releaseType) is not …OperationalNN
4375Windows Servicing failed to complete the process of setting package identifier …OperationalNN
4376Servicing has required reboot to complete the operation of setting package …OperationalNN
4383Windows Servicing completed the process of changing update updateName from …OperationalNN
4385Windows Servicing failed to complete the process of changing update updateName …OperationalNN
4386Windows Servicing required reboot to complete the process of changing update …OperationalNN
4400Windows Servicing is processing hotpatch package identifier(releaseType)OperationalNN
4401Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4402Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4403Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4404Windows Servicing successfully installed hotpatching package …OperationalNN
4405Windows Servicing has required a reboot to complete the installation of …OperationalNN
4406Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4407Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4408Windows Servicing failed to perform hotpatching for package …OperationalNN
4409Windows Servicing failed to perform hotpatching for package …OperationalNN
4416Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4417Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
4418Windows Servicing disabled hotpatching for package identifier(releaseType) to …OperationalNN
1073746195Windows Servicing started a process of changing package identifier(releaseType) …OperationalNN
1073746196Windows Servicing is setting package identifier(releaseType) state to …OperationalNN
1073746197Windows Servicing successfully set package identifier(releaseType) state to …OperationalNN
1073746207Windows Servicing completed the process of changing update updateName from …OperationalNN
1073746224Windows Servicing is processing hotpatch package identifier(releaseType).OperationalNN
1073746225Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
1073746226Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
1073746227Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
1073746228Windows Servicing successfully installed hotpatching package …OperationalNN
1073746229Windows Servicing has required a reboot to complete the installation of …OperationalNN
1073746240Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
2147488022Windows Servicing identified that package identifier(releaseType) is not …OperationalNN
2147488024Servicing has required reboot to complete the operation of setting package …OperationalNN
2147488034Windows Servicing required reboot to complete the process of changing update …OperationalNN
2147488054Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
2147488055Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
2147488056Windows Servicing failed to perform hotpatching for package …OperationalNN
2147488057Windows Servicing failed to perform hotpatching for package …OperationalNN
2147488065Windows Servicing disabled hotpatching for package identifier(releaseType) …OperationalNN
2147488066Windows Servicing disabled hotpatching for package identifier(releaseType) to …OperationalNN
3221229847Windows Servicing failed to complete the process of setting package identifier …OperationalNN
3221229857Windows Servicing failed to complete the process of changing update updateName …OperationalNN

Event ID 1: Initiating changes for package CbsPackageInitiateChanges.PackageIdentifier.

#
Channel
Setup
Task
Generic_Task

Description

Initiating changes for package CbsPackageInitiateChanges.PackageIdentifier. Current state is CbsPackageInitiateChanges.InitialPackageState. Target state is CbsPackageInitiateChanges.IntendedPackageState. Client id: CbsPackageInitiateChanges.Client.

Message #

Initiating changes for package %1. Current state is %2. Target state is %4. Client id: %6.

Fields #

NameDescription
identifier
currentPackageState
currentPackageStateTextized
targetPackageState
targetPackageStateTextized
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "BD12F3B8-FC40-4A61-A307-B7A013A069C1",
    "event_source_name": "",
    "event_id": 1,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:27:07.962339+00:00",
    "event_record_id": 11,
    "correlation": {},
    "execution": {
      "process_id": 5140,
      "thread_id": 5984
    },
    "channel": "Setup",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsPackageInitiateChanges": {
      "PackageIdentifier": "KB5032381",
      "InitialPackageState": 5000,
      "InitialPackageStateTextized": "Absent",
      "IntendedPackageState": 5112,
      "IntendedPackageStateTextized": "Installed",
      "Client": "WindowsUpdateAgent"
    }
  },
  "message": ""
}

References #

Event ID 2: Package CbsPackageChangeState.PackageIdentifier was successfully changed to the CbsPackageChangeState.IntendedPackageState state.

#
Channel
Setup
Collection Priority
Recommended (NSA)
Task
Generic_Task

Message #

Package %1 was successfully changed to the %2 state.

Fields #

NameDescription
identifier
targetPackageState
targetPackageStateTextized
errorCode
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "BD12F3B8-FC40-4A61-A307-B7A013A069C1",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2023-11-05T22:27:38.467765+00:00",
    "event_record_id": 12,
    "correlation": {},
    "execution": {
      "process_id": 5140,
      "thread_id": 5124
    },
    "channel": "Setup",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsPackageChangeState": {
      "PackageIdentifier": "KB5032381",
      "IntendedPackageState": 5112,
      "IntendedPackageStateTextized": "Installed",
      "ErrorCode": "0x0",
      "Client": "WindowsUpdateAgent"
    }
  },
  "message": ""
}

References #

Event ID 3: Package identifier failed to be changed to the targetPackageState state.

#
Channel
Setup
Task
Generic_Task

Description

Package identifier failed to be changed to the targetPackageState state. Status: errorCode.

Message #

Package %1 failed to be changed to the %2 state. Status: %4.

Fields #

NameDescription
identifier UnicodeString
targetPackageState UInt32
targetPackageStateTextized UnicodeString
errorCode UnicodeString
client UnicodeString

Event ID 4: A reboot is necessary before package CbsPackageChangeState.PackageIdentifier can be changed to the CbsPackageChangeState.IntendedPackageState state.

#
Channel
Setup
Task
Generic_Task

Message #

A reboot is necessary before package %1 can be changed to the %2 state.

Fields #

NameDescription
identifier
targetPackageState
targetPackageStateTextized
errorCode
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "BD12F3B8-FC40-4A61-A307-B7A013A069C1",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-07T08:29:46.442470+00:00",
    "event_record_id": 30,
    "correlation": {},
    "execution": {
      "process_id": 6644,
      "thread_id": 5384
    },
    "channel": "Setup",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsPackageChangeState": {
      "PackageIdentifier": "KB5009470",
      "IntendedPackageState": 5112,
      "IntendedPackageStateTextized": "Installed",
      "ErrorCode": "0x0",
      "Client": "WindowsUpdateAgent"
    }
  },
  "message": ""
}

References #

Event ID 5: The servicing request received for package identifier cannot be satisfied since the package is not applicable.

#
Channel
Setup
Task
Generic_Task

Message #

The servicing request received for package %1 cannot be satisfied since the package is not applicable.

Fields #

NameDescription
identifier UnicodeString
targetPackageState UInt32
targetPackageStateTextized UnicodeString
errorCode UnicodeString
client UnicodeString

Event ID 6: Package identifier failed to be changed to the targetPackageState state and is now partially installed.

#
Channel
Setup
Task
Generic_Task

Description

Package identifier failed to be changed to the targetPackageState state and is now partially installed. Status: errorCode.

Message #

Package %1 failed to be changed to the %2 state and is now partially installed. Status: %4.

Fields #

NameDescription
identifier UnicodeString
targetPackageState UInt32
targetPackageStateTextized UnicodeString
errorCode UnicodeString
client UnicodeString

Event ID 7: Initiating changes to turn on update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier.

#
Channel
Setup
Task
Generic_Task

Description

Initiating changes to turn on update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier. Client id: CbsUpdateChangeState.Client.

Message #

Initiating changes to turn on update %1 of package %2. Client id: %4.

Fields #

NameDescription
CbsUpdateChangeState.UpdateName
CbsUpdateChangeState.PackageIdentifier
CbsUpdateChangeState.ErrorCode
CbsUpdateChangeState.Client
updateName
identifier
errorCode
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 7,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:18.8620128+00:00",
    "event_record_id": 63,
    "correlation": {},
    "execution": {
      "process_id": 1436,
      "thread_id": 708
    },
    "channel": "Setup",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "MSMQ-ADIntegration",
      "PackageIdentifier": "Microsoft-Windows-MSMQ-Server",
      "ErrorCode": "",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": "Initiating changes to turn on update MSMQ-ADIntegration of package Microsoft-Windows-MSMQ-Server. Client id: DISM Package Manager Provider."
}

Event ID 8: Initiating changes to turn off update updateName of package identifier.

#
Channel
Setup
Task
Generic_Task

Description

Initiating changes to turn off update updateName of package identifier. Client id: client.

Message #

Initiating changes to turn off update %1 of package %2. Client id: %4.

Fields #

NameDescription
CbsUpdateChangeState.UpdateName
CbsUpdateChangeState.PackageIdentifier
CbsUpdateChangeState.ErrorCode
CbsUpdateChangeState.Client
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 8,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:12:43.6374269+00:00",
    "event_record_id": 44,
    "correlation": {},
    "execution": {
      "process_id": 1436,
      "thread_id": 1136
    },
    "channel": "Setup",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "IIS-ApplicationDevelopment",
      "PackageIdentifier": "IIS-WebServer-Core-Package",
      "ErrorCode": "",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": "Initiating changes to turn off update IIS-ApplicationDevelopment of package IIS-WebServer-Core-Package. Client id: DISM Package Manager Provider."
}

Event ID 9: Selectable update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier was successfully turned on.

#
Channel
Setup
Task
Generic_Task

Message #

Selectable update %1 of package %2 was successfully turned on.

Fields #

NameDescription
CbsUpdateChangeState.UpdateName
CbsUpdateChangeState.PackageIdentifier
CbsUpdateChangeState.ErrorCode
CbsUpdateChangeState.Client
updateName
identifier
errorCode
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 9,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:22:20.9509189+00:00",
    "event_record_id": 64,
    "correlation": {},
    "execution": {
      "process_id": 1436,
      "thread_id": 708
    },
    "channel": "Setup",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "MSMQ-ADIntegration",
      "PackageIdentifier": "Microsoft-Windows-MSMQ-Server",
      "ErrorCode": "0x0",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": "Selectable update MSMQ-ADIntegration of package Microsoft-Windows-MSMQ-Server was successfully turned on."
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 10: Selectable update updateName of package identifier was successfully turned off.

#
Channel
Setup
Task
Generic_Task

Message #

Selectable update %1 of package %2 was successfully turned off.

Fields #

NameDescription
CbsUpdateChangeState.UpdateName
CbsUpdateChangeState.PackageIdentifier
CbsUpdateChangeState.ErrorCode
CbsUpdateChangeState.Client
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 10,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-06-13T05:13:28.1168946+00:00",
    "event_record_id": 54,
    "correlation": {},
    "execution": {
      "process_id": 1436,
      "thread_id": 1136
    },
    "channel": "Setup",
    "computer": "telemetry-DC-c.cell-c.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "IIS-ApplicationDevelopment",
      "PackageIdentifier": "IIS-WebServer-Core-Package",
      "ErrorCode": "0x0",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": "Selectable update IIS-ApplicationDevelopment of package IIS-WebServer-Core-Package was successfully turned off."
}

Event ID 11: Update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier failed to be turned on.

#
Channel
Setup
Task
Generic_Task

Description

Update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier failed to be turned on. Status: CbsUpdateChangeState.ErrorCode.

Message #

Update %1 of package %2 failed to be turned on. Status: %3.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "BD12F3B8-FC40-4A61-A307-B7A013A069C1",
    "event_source_name": "",
    "event_id": 11,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2026-03-13T20:03:35.142239+00:00",
    "event_record_id": 67,
    "correlation": {
      "ActivityID": "FB184003-DCB7-4B69-9E92-32E15BDF0739"
    },
    "execution": {
      "process_id": 6332,
      "thread_id": 6572
    },
    "channel": "Setup",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "NetFx3",
      "PackageIdentifier": "Microsoft .NET Framework 3.0",
      "ErrorCode": "0x80070005",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": ""
}

Event ID 12: Update updateName of package identifier failed to be turned off.

#
Channel
Setup
Task
Generic_Task

Description

Update updateName of package identifier failed to be turned off. Status: errorCode.

Message #

Update %1 of package %2 failed to be turned off. Status: %3.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Event ID 13: A reboot is necessary before the selectable update CbsUpdateChangeState.UpdateName of package CbsUpdateChangeState.PackageIdentifier can be turned on.

#
Channel
Setup
Task
Generic_Task

Message #

A reboot is necessary before the selectable update %1 of package %2 can be turned on.

Fields #

NameDescription
updateName
identifier
errorCode
client

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "BD12F3B8-FC40-4A61-A307-B7A013A069C1",
    "event_source_name": "",
    "event_id": 13,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": 9223372036854775808,
    "time_created": "2022-04-04T10:59:07.927880+00:00",
    "event_record_id": 85,
    "correlation": {},
    "execution": {
      "process_id": 3472,
      "thread_id": 2576
    },
    "channel": "Setup",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "TFTP",
      "PackageIdentifier": "Microsoft-Windows-TFTP-Client",
      "ErrorCode": "0x0",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": ""
}

References #

Event ID 14: A reboot is necessary before the selectable update updateName of package identifier can be turned off.

#
Channel
Setup
Task
Generic_Task

Message #

A reboot is necessary before the selectable update %1 of package %2 can be turned off.

Fields #

NameDescription
CbsUpdateChangeState.UpdateName
CbsUpdateChangeState.PackageIdentifier
CbsUpdateChangeState.ErrorCode
CbsUpdateChangeState.Client
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 14,
    "version": 0,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-04-17T04:14:39.3221439+00:00",
    "event_record_id": 170,
    "correlation": {
      "ActivityID": "{88818765-142B-403C-9C5F-A690EC1C7401}"
    },
    "execution": {
      "process_id": 4220,
      "thread_id": 536
    },
    "channel": "Setup",
    "computer": "JD-WIN11-22H2-1.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsUpdateChangeState": {
      "UpdateName": "Containers-DisposableClientVM",
      "PackageIdentifier": "Containers-OptionalFeature-DisposableClientVM",
      "ErrorCode": "0x0",
      "Client": "DISM Package Manager Provider"
    }
  },
  "message": "A reboot is necessary before the selectable update Containers-DisposableClientVM of package Containers-OptionalFeature-DisposableClientVM can be turned off."
}

Event ID 15: Selectable update updateName of package identifier was successfully turned off with its payload removed.

#
Channel
Setup
Task
Generic_Task

Message #

Selectable update %1 of package %2 was successfully turned off with its payload removed.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "event_id": 15,
    "level": 0,
    "task": 1,
    "opcode": 0,
    "time_created": "2026-04-18T00:32:48.5275254+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Setup"
  },
  "event_data": {
    "PackageIdentifier": "UserExperience-Recall",
    "ErrorCode": "0x0",
    "UpdateName": "Recall",
    "Client": "DISM Package Manager Provider"
  }
}

Example keys not documented in the fields table: Client, ErrorCode, PackageIdentifier, UpdateName

Event ID 16: Update updateName of package identifier failed to be turned off.

#
Channel
Setup
Task
Generic_Task

Description

Update updateName of package identifier failed to be turned off. Payload removal was requested. Status: errorCode.

Message #

Update %1 of package %2 failed to be turned off. Payload removal was requested. Status: %3.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
errorCode UnicodeString
client UnicodeString

Event ID 17: Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 18: START [Resolve]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Resolve]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 20: END [Resolve]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Resolve]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 21: START [Execute]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Execute]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 23: END [Execute]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Execute]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 24: START [Stage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Stage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 26: END [Stage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Stage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 33: START [DPX Expansion]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [DPX Expansion]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 34: END [DPX Expansion]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [DPX Expansion]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 35: START [Doq Stage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Stage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 37: END [Doq Stage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Stage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 38: START [Doq Unstage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Unstage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 39: END [Doq Unstage]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Unstage]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 40: START [Doq Critical Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Critical Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 41: END [Doq Critical Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Critical Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 42: START [Doq Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 43: END [Doq Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 44: STARt [Doq Critical Uninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

STARt [Doq Critical Uninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 45: END [Doq Critical Uninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Critical Uninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 46: START [Doq Uninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Uninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 47: END [Doq Uninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Uninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 48: START [Doq Device Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Doq Device Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 49: END [Doq Device Install]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Doq Device Install]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 50: START [InstallUninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [InstallUninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 51: END [InstallUninstall]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [InstallUninstall]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 52: START [Poqexec]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Poqexec]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 53: END [Poqexec]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Poqexec]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 54: START [Shutdown Processing]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Shutdown Processing]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 55: END [Shutdown Processing]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Shutdown Processing]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 56: START [Non-Critical Doq]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Non-Critical Doq]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 57: END [Non-Critical Doq]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Non-Critical Doq]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 58: START [Critical Doq]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Critical Doq]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 59: END [Critical Doq]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Critical Doq]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 60: START [Plan Package]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Plan Package]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 61: END [Plan Package]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Plan Package]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 62: TrustedInstaller Finalize Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

TrustedInstaller Finalize Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 63: TrustedInstaller Initialize Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

TrustedInstaller Initialize Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 64: Doq Stage Progress Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Doq Stage Progress Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 65: Doq Unstage Progress Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Doq Unstage Progress Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 66: Doq Install Progress Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Doq Install Progress Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 67: Doq Uninstall Progress Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Doq Uninstall Progress Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 68: Startup Complete Event Report:[EventReport].

#
Channel
Debug
Task
Generic_Task

Message #

Startup Complete Event Report:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 69: START [AI Queue Processing]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [AI Queue Processing]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 70: END [AI Queue Processing]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [AI Queue Processing]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 71: START [AI Install]:[Description = [DescString], Phase = [Phase], Mode = [Mode], PrevComponent=[PrevComponent], NewComponent=[NewComponent]].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [AI Install]:[Description = [%1], Phase = [%2], Mode = [%3], PrevComponent=[%4], NewComponent=[%5]]

Fields #

NameDescription
DescString UnicodeString
Phase UInt32
Mode UInt32
PrevComponent UnicodeString
NewComponent UnicodeString

Event ID 72: END [AI Install]:[Status=[DescString]].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [AI Install]:[Status=[%1]]

Fields #

NameDescription
DescString UnicodeString
InstallerEndEvent UInt64

Event ID 73: Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 74: CSI INSTALL Deployment Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI INSTALL Deployment Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 75: CSI UNINSTALL Deployment Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI UNINSTALL Deployment Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 76: START [KTM Transaction]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [KTM Transaction]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 77: END [KTM Transaction]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [KTM Transaction]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 78: CSI COMPRESS Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI COMPRESS Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 79: CSI Stage Component Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI Stage Component Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 80: CSI AI Completion Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI AI Completion Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 82: START [CSI SMIPI]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [CSI SMIPI]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 83: END [CSI SMIPI]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [CSI SMIPI]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 84: CSI SMIPI INSTALL Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task

Message #

CSI SMIPI INSTALL Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 85: CSI Transaction Start Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

CSI Transaction Start Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 86: CSI Transaction End Event Report: [DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

CSI Transaction End Event Report: [%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 87: START [CSI Corruption Detection Event]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [CSI Corruption Detection Event]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 88: END [CSI Corruption Detection Event]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [CSI Corruption Detection Event]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 89: START [CSI Corruption Repair Event]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [CSI Corruption Repair Event]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 90: END [CSI Corruption Repair Event]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [CSI Corruption Repair Event]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 91: START [CSI Scavenge]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [CSI Scavenge]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 92: END [CSI Scavenge]:[DescString].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [CSI Scavenge]:[%1]

Fields #

NameDescription
DescString UnicodeString

Event ID 93: START [CBS Scavenge]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [CBS Scavenge]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 94: END [CBS Scavenge]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [CBS Scavenge]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 95: START [Archive Logs]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Archive Logs]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 96: END [Archive Logs]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Archive Logs]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 97: START [Drain Catalogs]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Drain Catalogs]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 98: END [Drain Catalogs]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Drain Catalogs]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 99: START [Automatic Deepclean]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Automatic Deepclean]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 100: END [Automatic Deepclean]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Automatic Deepclean]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 101: START [Manual Deepclean]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Manual Deepclean]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 102: END [Manual Deepclean]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Manual Deepclean]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 103: START [Delete Session Files]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Start

Message #

START [Delete Session Files]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 104: END [Delete Session Files]:[EventReport].

#
Channel
Debug
Task
Generic_Task
Opcode
Stop

Message #

END [Delete Session Files]:[%1]

Fields #

NameDescription
EventReport UnicodeString

Event ID 105: Progress: UI message updated.

#
Channel
Debug
Task
Generic_Task

Description

Progress: UI message updated. EventReport.

Message #

Progress: UI message updated. %1

Fields #

NameDescription
EventReport UnicodeString

Event ID 1000: Windows Servicing is processing hotpatch package identifier(releaseType).

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing is processing hotpatch package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1001: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is not enabled for hotpatching.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %2(%3) because update %1 is not enabled for hotpatching.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1002: Windows Servicing disabled hotpatching for package identifier(releaseType) because servicing is being performed offline.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %1(%2) because servicing is being performed offline.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1003: Windows Servicing disabled hotpatching for package identifier(releaseType) because a reboot is required to complete a prior operation.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %1(%2) because a reboot is required to complete a prior operation.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1004: Windows Servicing successfully installed hotpatching package identifier(releaseType).

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing successfully installed hotpatching package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1005: Windows Servicing has required a reboot to complete the installation of hotpatching package identifier(releaseType).

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing has required a reboot to complete the installation of hotpatching package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1006: Windows Servicing disabled hotpatching for package identifier(releaseType) because a file could not be replaced immediately.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %1(%2) because a file could not be replaced immediately.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1007: Windows Servicing disabled hotpatching for package identifier(releaseType) because required files or custom actions are incompatible with hotpatching.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %1(%2) because required files or custom actions are incompatible with hotpatching.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1008: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because the hotpatch installer required a reboot.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing failed to perform hotpatching for package %1(%2) because the hotpatch installer required a reboot.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1009: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because of an error (errorCode).

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing failed to perform hotpatching for package %1(%2) because of an error (%8).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1010: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is being set to state updateStateLoc(updateState).

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %2(%3) because update %1 is being set to state %4(%5).

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1011: Windows Servicing disabled hotpatching for package identifier(releaseType) because hotpatch update updateName will not be installed.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %2(%3) because hotpatch update %1 will not be installed.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1012: Windows Servicing disabled hotpatching for package identifier(releaseType) to process regular update updateName.

#
Channel
Setup
Opcode
Info

Message #

Windows Servicing disabled hotpatching for package %2(%3) to process regular update %1.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1013: Initiating system store corruption detection and repair.

#
Channel
Setup
Opcode
Info

Description

Initiating system store corruption detection and repair. Detection Only: detectionType, Automatically Triggered: triggerType.

Message #

Initiating system store corruption detection and repair. Detection Only: %1, Automatically Triggered: %2.

Fields #

NameDescription
CbsStoreCorruptionRepairStart.DetectionOnly
CbsStoreCorruptionRepairStart.AutoTriggered
detectionType UInt32
triggerType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 1013,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T02:09:07.6272920+00:00",
    "event_record_id": 183,
    "correlation": {
      "ActivityID": "{085B8FD5-7274-4CCD-A741-0CB01744C0E8}"
    },
    "execution": {
      "process_id": 13664,
      "thread_id": 7404
    },
    "channel": "Setup",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsStoreCorruptionRepairStart": {
      "DetectionOnly": "1",
      "AutoTriggered": "0"
    }
  },
  "message": "Initiating system store corruption detection and repair. Detection Only: 1, Automatically Triggered: 0."
}

Event ID 1014: System store corruption detection and repair has completed.

#
Channel
Setup
Opcode
Info

Description

System store corruption detection and repair has completed. Status: errorCode, Total instances of corruption found: totalCorruption, total instances of corruption repaired: repaired.

Message #

System store corruption detection and repair has completed. Status: %1, Total instances of corruption found: %3, total instances of corruption repaired: %2.

Fields #

NameDescription
CbsStoreCorruptionRepairFinish.ErrorCode
CbsStoreCorruptionRepairFinish.Repaired
CbsStoreCorruptionRepairFinish.TotalCorruption
errorCode UnicodeString
repaired UInt32
totalCorruption UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 1014,
    "version": 0,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T02:13:58.8361346+00:00",
    "event_record_id": 184,
    "correlation": {
      "ActivityID": "{085B8FD5-7274-4CCD-A741-0CB01744C0E8}"
    },
    "execution": {
      "process_id": 13664,
      "thread_id": 7404
    },
    "channel": "Setup",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsStoreCorruptionRepairFinish": {
      "ErrorCode": "0x0",
      "Repaired": "0",
      "TotalCorruption": "1"
    }
  },
  "message": "System store corruption detection and repair has completed. Status: 0x0, Total instances of corruption found: 1, total instances of corruption repaired: 0."
}

Event ID 1015: repaired of totalCorruption instances of system store corruption have been repaired.

#
Channel
Setup
Level
Warning
Opcode
Info

Description

repaired of totalCorruption instances of system store corruption have been repaired. Unrepaired corruptions may lead to failures in future system servicing.

Message #

%2 of %3 instances of system store corruption have been repaired. Unrepaired corruptions may lead to failures in future system servicing.

Fields #

NameDescription
CbsStoreCorruptionRepairFinish.ErrorCode
CbsStoreCorruptionRepairFinish.Repaired
CbsStoreCorruptionRepairFinish.TotalCorruption
errorCode UnicodeString
repaired UInt32
totalCorruption UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-Servicing",
    "guid": "{BD12F3B8-FC40-4A61-A307-B7A013A069C1}",
    "event_source_name": "",
    "event_id": 1015,
    "version": 0,
    "level": 3,
    "task": 0,
    "opcode": 0,
    "keywords": -9223372036854775808,
    "time_created": "2026-05-30T02:13:58.8361368+00:00",
    "event_record_id": 185,
    "correlation": {
      "ActivityID": "{085B8FD5-7274-4CCD-A741-0CB01744C0E8}"
    },
    "execution": {
      "process_id": 13664,
      "thread_id": 7404
    },
    "channel": "Setup",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "CbsStoreCorruptionRepairFinish": {
      "ErrorCode": "0x0",
      "Repaired": "0",
      "TotalCorruption": "1"
    }
  },
  "message": "0 of 1 instances of system store corruption have been repaired. Unrepaired corruptions may lead to failures in future system servicing."
}

Event ID 4371: Windows Servicing started a process of changing package identifier(releaseType) state from initialPackageStateLoc(initialPackageState) to packageStateLoc(packageState)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
initialPackageStateLoc UnicodeString
initialPackageState UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
client UnicodeString
supportInformation UnicodeString

Event ID 4372: Windows Servicing is setting package identifier(releaseType) state to packageStateLoc(packageState)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4373: Windows Servicing successfully set package identifier(releaseType) state to packageStateLoc(packageState)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4374: Windows Servicing identified that package identifier(releaseType) is not applicable for this system

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4375: Windows Servicing failed to complete the process of setting package identifier (releaseType) into packageStateLoc(packageState) state

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4376: Servicing has required reboot to complete the operation of setting package identifier(releaseType) into packageStateLoc(packageState) state

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4383: Windows Servicing completed the process of changing update updateName from package identifier (releaseType) into updateStateLoc(updateState) state

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4385: Windows Servicing failed to complete the process of changing update updateName from package identifier(releaseType) into updateStateLoc(updateState) state

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4386: Windows Servicing required reboot to complete the process of changing update updateName from package identifier(releaseType) into updateStateLoc(updateState) state

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4400: Windows Servicing is processing hotpatch package identifier(releaseType)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4401: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is not enabled for hotpatching

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4402: Windows Servicing disabled hotpatching for package identifier(releaseType) because servicing is being performed offline

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4403: Windows Servicing disabled hotpatching for package identifier(releaseType) because a reboot is required to complete a prior operation

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4404: Windows Servicing successfully installed hotpatching package identifier(releaseType)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4405: Windows Servicing has required a reboot to complete the installation of hotpatching package identifier(releaseType)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4406: Windows Servicing disabled hotpatching for package identifier(releaseType) because a file could not be replaced immediately

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4407: Windows Servicing disabled hotpatching for package identifier(releaseType) because required files or custom actions are incompatible with hotpatching

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4408: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because the hotpatch installer required a reboot

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4409: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because of an error (errorCode)

#
Channel
Operational

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 4416: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is being set to state updateStateLoc(updateState)

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4417: Windows Servicing disabled hotpatching for package identifier(releaseType) because hotpatch update updateName will not be installed

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 4418: Windows Servicing disabled hotpatching for package identifier(releaseType) to process regular update

#
Channel
Operational

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1073746195: Windows Servicing started a process of changing package identifier(releaseType) state from initialPackageStateLoc(initialPackageState) to packageStateLoc(packageState).

#
Channel
Operational
Opcode
Info

Message #

Windows Servicing started a process of changing package %1(%2) state from %3(%4) to %5(%6)

Fields #

NameDescription
identifier UnicodeStringWindows Servicing started a process of changing package
releaseType UnicodeString
initialPackageStateLoc UnicodeString) state from
initialPackageState UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
client UnicodeString
supportInformation UnicodeString

Event ID 1073746196: Windows Servicing is setting package identifier(releaseType) state to packageStateLoc(packageState).

#
Channel
Operational
Opcode
Info

Message #

Windows Servicing is setting package %1(%2) state to %3(%4)

Fields #

NameDescription
identifier UnicodeStringWindows Servicing is setting package
releaseType UnicodeString
packageStateLoc UnicodeString) state to
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746197: Windows Servicing successfully set package identifier(releaseType) state to packageStateLoc(packageState).

#
Channel
Operational
Opcode
Info

Message #

Windows Servicing successfully set package %1(%2) state to %3(%4)

Fields #

NameDescription
identifier UnicodeStringWindows Servicing successfully set package
releaseType UnicodeString
packageStateLoc UnicodeString) state to
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746207: Windows Servicing completed the process of changing update updateName from package identifier (releaseType) into updateStateLoc(updateState) state.

#
Channel
Operational

Message #

Windows Servicing completed the process of changing update %1 from package %2 (%3) into %4(%5) state

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1073746224: Windows Servicing is processing hotpatch package identifier(releaseType).

#
Channel
Operational

Message #

Windows Servicing is processing hotpatch package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746225: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is not enabled for hotpatching.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %2(%3) because update %1 is not enabled for hotpatching.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 1073746226: Windows Servicing disabled hotpatching for package identifier(releaseType) because servicing is being performed offline.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %1(%2) because servicing is being performed offline.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746227: Windows Servicing disabled hotpatching for package identifier(releaseType) because a reboot is required to complete a prior operation.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %1(%2) because a reboot is required to complete a prior operation.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746228: Windows Servicing successfully installed hotpatching package identifier(releaseType).

#
Channel
Operational

Message #

Windows Servicing successfully installed hotpatching package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746229: Windows Servicing has required a reboot to complete the installation of hotpatching package identifier(releaseType).

#
Channel
Operational

Message #

Windows Servicing has required a reboot to complete the installation of hotpatching package %1(%2).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 1073746240: Windows Servicing disabled hotpatching for package identifier(releaseType) because update updateName is being set to state updateStateLoc(updateState).

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %2(%3) because update %1 is being set to state %4(%5).

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 2147488022: Windows Servicing identified that package identifier(releaseType) is not applicable for this system.

#
Channel
Operational

Message #

Windows Servicing identified that package %1(%2) is not applicable for this system

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488024: Servicing has required reboot to complete the operation of setting package identifier(releaseType) into packageStateLoc(packageState) state.

#
Channel
Operational

Message #

Servicing has required reboot to complete the operation of setting package %1(%2) into %3(%4) state

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488034: Windows Servicing required reboot to complete the process of changing update updateName from package identifier(releaseType) into updateStateLoc(updateState) state.

#
Channel
Operational

Message #

Windows Servicing required reboot to complete the process of changing update %1 from package %2(%3) into %4(%5) state

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 2147488054: Windows Servicing disabled hotpatching for package identifier(releaseType) because a file could not be replaced immediately.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %1(%2) because a file could not be replaced immediately.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488055: Windows Servicing disabled hotpatching for package identifier(releaseType) because required files or custom actions are incompatible with hotpatching.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %1(%2) because required files or custom actions are incompatible with hotpatching.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488056: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because the hotpatch installer required a reboot.

#
Channel
Operational

Message #

Windows Servicing failed to perform hotpatching for package %1(%2) because the hotpatch installer required a reboot.

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488057: Windows Servicing failed to perform hotpatching for package identifier(releaseType) because of an error (errorCode).

#
Channel
Operational

Message #

Windows Servicing failed to perform hotpatching for package %1(%2) because of an error (%8).

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 2147488065: Windows Servicing disabled hotpatching for package identifier(releaseType) because hotpatch update updateName will not be installed.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %2(%3) because hotpatch update %1 will not be installed.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 2147488066: Windows Servicing disabled hotpatching for package identifier(releaseType) to process regular update updateName.

#
Channel
Operational

Message #

Windows Servicing disabled hotpatching for package %2(%3) to process regular update %1.

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Event ID 3221229847: Windows Servicing failed to complete the process of setting package identifier (releaseType) into packageStateLoc(packageState) state.

#
Channel
Operational

Message #

Windows Servicing failed to complete the process of setting package %1 (%2) into %3(%4) state

Fields #

NameDescription
identifier UnicodeString
releaseType UnicodeString
packageStateLoc UnicodeString
packageState UnicodeString
packageAssembly UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString
missingElements UnicodeString

Event ID 3221229857: Windows Servicing failed to complete the process of changing update updateName from package identifier(releaseType) into updateStateLoc(updateState) state.

#
Channel
Operational

Message #

Windows Servicing failed to complete the process of changing update %1 from package %2(%3) into %4(%5) state

Fields #

NameDescription
updateName UnicodeString
identifier UnicodeString
releaseType UnicodeString
updateStateLoc UnicodeString
updateState UnicodeString
packageAssembly UnicodeString
updateDisplayName UnicodeString
operation UnicodeString
operationCompleted UnicodeString
errorCode UnicodeString
rebootOption UnicodeString

Provenance

ETW provider GUID bd12f3b8-fc40-4a61-a307-b7a013a069c1

Defined in cbsmsg.dll, which carries the event manifest.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02 — Manifest XML pack, 2.0 MB