Microsoft-Windows-SettingSync-OneDrive

EventTitleChannelSampleRule
1000Event ID 1000OperationalNN
1001Event ID 1001OperationalNN
1002Event ID 1002OperationalNN
1003Cannot find restore folder for collection {CollectionId}.OperationalNN
1004Reupload Needed request for {CollectionId}.OperationalNN
1005Shared settings in the collection {CollectionId} didnt sync.OperationalNN
1006Cloud sync provider encountered an unexpected null setting unit in collection …OperationalNN
1007Cloud provider failed to update setting unit {SettingUnitId} in collection …OperationalNN
1008MSA ticket request failed for current user.OperationalNN
1012The sync server returned error {Value}.OperationalNN
1013Settings view failed to parse.OperationalNN
1014UserTile view failed to parse.OperationalNN
1015Failed to parse response from Live Storage Quota API.OperationalNN
1016Activation of PDC failed.OperationalNN
1017Policy document failed to parse.OperationalNN
1018Policy document failed to download.OperationalNN
1019Policy document failed to save.OperationalNN
1020Notification WNS channel {ChannelName} creation failed (Result: {HRESULT}).OperationalNN
1021Notification WLS channel {ChannelName} creation failed (Result: {HRESULT}).OperationalNN
3000Event ID 3000DebugNN
3001Event ID 3001DebugNN
3002Event ID 3002DebugNN
3003Setting unit {SettingUnitId} failed to upload with WriteStatus ({WriteStatus}).DebugNN
3004A garbage collection occurred in cloud storage.DebugNN
3005Device was still interested in garbge collected collection {CollectionId}.DebugNN
3006Collection {CollectionId} was removed completely from the device due to a …DebugNN
3008Collection {CollectionId} failed to back up (Result: {HRESULT}).DebugNN
3009Property {PropStoreName} of the setting unit {SettingUnitId} was not applied as …DebugNN
3010The {ProviderName} provider cleaned up tombstones for {CollectionId} (HRESULT: …DebugNN
3011Setting unit {SettingUnitId} in collection {CollectionId} was backed up via BITS …DebugNN
3012Cloud provider updated setting unit {SettingUnitId} in collection {CollectionId} …DebugNN
3013A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was …DebugNN
3014A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was …DebugNN
3015Ramp State Update: {Name} upgraded from {OldValue} to {NewValue}.DebugNN
3017BITS Upload session failed for setting unit {SettingUnitId} for collection …DebugNN
3018Register Notification Response: {Response}.DebugNN
3020Storage request: {Verb} to {Url} completed with status code {StatusCode}.DebugNN
3021Uploading Batch to service with transaction Id: {TransactionId}.DebugNN
3022Collection Metadata Destroy Failure.DebugNN
3023PDCActivation was used by process {Message} instead of SettingSyncHost.DebugNN
3024Collection {CollectionId} was blocked from uploading to cloud storage.DebugNN
3025Collection {CollectionId} was blocked from downloading to Windows.DebugNN
3026Storage subscription operation (create/update) failed for {CollectionId} …DebugNN
3027Storage subscription operation (delete) failed for {CollectionId} (HRESULT: …DebugNN
3029The collection ({CollectionId}) is being throttled due to excessive syncing.DebugNN
9000Event ID 9000AnalyticNN
9001Event ID 9001AnalyticNN
9002Event ID 9002AnalyticNN

Event ID 1000

#
Channel
Operational

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 1001

#
Channel
Operational

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 1002

#
Channel
Operational

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 1003: Cannot find restore folder for collection {CollectionId}.

#
Channel
Operational

Description

Cannot find restore folder for collection {CollectionId}. Looks like it was stolen by another device and then deleted.

Message #

Cannot find restore folder for collection {CollectionId}. Looks like it was stolen by another device and then deleted.

Fields #

NameDescription
CollectionId

Event ID 1004: Reupload Needed request for {CollectionId}.

#
Channel
Operational

Description

Reupload Needed request for {CollectionId}. (Result: {HRESULT}).

Message #

Reupload Needed request for {CollectionId}. (Result: {HRESULT})

Fields #

NameDescription
CollectionId
HRESULT

Event ID 1005: Shared settings in the collection {CollectionId} didnt sync.

#
Channel
Operational

Message #

Shared settings in the collection {CollectionId} didnt sync. The updates were blocked by the server because theyre too big or have changed too frequently. The settings will sync again when the limits have been reset.

Fields #

NameDescription
CollectionId

Event ID 1006: Cloud sync provider encountered an unexpected null setting unit in collection {CollectionId} (saveAction: {Value}; Result: {HRESULT}).

#
Channel
Operational

Fields #

NameDescription
CollectionId
Value
HRESULT

Event ID 1007: Cloud provider failed to update setting unit {SettingUnitId} in collection {CollectionId} (Operation: {Operation}; Result: {HRESULT}).

#
Channel
Operational

Fields #

NameDescription
SettingUnitId
CollectionId
Operation
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
HRESULT

Event ID 1008: MSA ticket request failed for current user.

#
Channel
Operational

Description

MSA ticket request failed for current user. (Result: {HRESULT}).

Message #

MSA ticket request failed for current user. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1012: The sync server returned error {Value}.

#
Channel
Operational

Description

The sync server returned error {Value}. Shared settings might be out of sync.

Message #

The sync server returned error {Value}. Shared settings might be out of sync.

Fields #

NameDescription
Value

Event ID 1013: Settings view failed to parse.

#
Channel
Operational

Description

Settings view failed to parse. (Result: {HRESULT}).

Message #

Settings view failed to parse. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1014: UserTile view failed to parse.

#
Channel
Operational

Description

UserTile view failed to parse. (Result: {HRESULT}).

Message #

UserTile view failed to parse. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1015: Failed to parse response from Live Storage Quota API.

#
Channel
Operational

Description

Failed to parse response from Live Storage Quota API. (Result: {HRESULT}).

Message #

Failed to parse response from Live Storage Quota API. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1016: Activation of PDC failed.

#
Channel
Operational

Description

Activation of PDC failed. (Result: {HRESULT}).

Message #

Activation of PDC failed. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1017: Policy document failed to parse.

#
Channel
Operational

Description

Policy document failed to parse. (Result: {HRESULT}).

Message #

Policy document failed to parse. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1018: Policy document failed to download.

#
Channel
Operational

Description

Policy document failed to download. (Result: {HRESULT}).

Message #

Policy document failed to download. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1019: Policy document failed to save.

#
Channel
Operational

Description

Policy document failed to save. (Result: {HRESULT}).

Message #

Policy document failed to save. (Result: {HRESULT})

Fields #

NameDescription
HRESULT

Event ID 1020: Notification WNS channel {ChannelName} creation failed (Result: {HRESULT}).

#
Channel
Operational

Fields #

NameDescription
ChannelName
HRESULT

Event ID 1021: Notification WLS channel {ChannelName} creation failed (Result: {HRESULT}).

#
Channel
Operational

Fields #

NameDescription
ChannelName
HRESULT

Event ID 3000

#
Channel
Debug

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 3001

#
Channel
Debug

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 3002

#
Channel
Debug

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 3003: Setting unit {SettingUnitId} failed to upload with WriteStatus ({WriteStatus}).

#
Channel
Debug

Fields #

NameDescription
SettingUnitId
WriteStatus

Event ID 3004: A garbage collection occurred in cloud storage.

#
Channel
Debug

Description

A garbage collection occurred in cloud storage. {Value} collection(s) on this device were removed.

Message #

A garbage collection occurred in cloud storage. {Value} collection(s) on this device were removed.

Fields #

NameDescription
Value

Event ID 3005: Device was still interested in garbge collected collection {CollectionId}.

#
Channel
Debug

Fields #

NameDescription
CollectionId

Event ID 3006: Collection {CollectionId} was removed completely from the device due to a garbage collection in cloud storage.

#
Channel
Debug

Fields #

NameDescription
CollectionId

Event ID 3008: Collection {CollectionId} failed to back up (Result: {HRESULT}).

#
Channel
Debug

Fields #

NameDescription
CollectionId
HRESULT

Event ID 3009: Property {PropStoreName} of the setting unit {SettingUnitId} was not applied as more recent settings were detected locally.

#
Channel
Debug

Fields #

NameDescription
PropStoreName
SettingUnitId

Event ID 3010: The {ProviderName} provider cleaned up tombstones for {CollectionId} (HRESULT: {HRESULT}).

#
Channel
Debug

Fields #

NameDescription
ProviderName
CollectionId
HRESULT

Event ID 3011: Setting unit {SettingUnitId} in collection {CollectionId} was backed up via BITS (Result: {HRESULT}).

#
Channel
Debug

Fields #

NameDescription
SettingUnitId
CollectionId
HRESULT

Event ID 3012: Cloud provider updated setting unit {SettingUnitId} in collection {CollectionId} (Operation: {Operation}).

#
Channel
Debug

Fields #

NameDescription
SettingUnitId
CollectionId
Operation
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 3013: A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was detected in cloud storage.

#
Channel
Debug

Description

A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was detected in cloud storage. Attempting repair.

Message #

A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was detected in cloud storage. Attempting repair.

Fields #

NameDescription
SettingUnitId
CollectionId

Event ID 3014: A missing blob for setting unit {SettingUnitId} in collection {CollectionId} was detected in cloud storage; but this client cannot repair it.

#
Channel
Debug

Fields #

NameDescription
SettingUnitId
CollectionId

Event ID 3015: Ramp State Update: {Name} upgraded from {OldValue} to {NewValue}.

#
Channel
Debug

Fields #

NameDescription
Name
OldValue
NewValue

Event ID 3017: BITS Upload session failed for setting unit {SettingUnitId} for collection {CollectionId} (HRESULT: {Operation}).

#
Channel
Debug

Fields #

NameDescription
SettingUnitId
CollectionId
Operation
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.

Event ID 3018: Register Notification Response: {Response}.

#
Channel
Debug

Fields #

NameDescription
Response

Event ID 3020: Storage request: {Verb} to {Url} completed with status code {StatusCode}.

#
Channel
Debug

Fields #

NameDescription
Verb
Url
StatusCodeNTSTATUS reference

Event ID 3021: Uploading Batch to service with transaction Id: {TransactionId}.

#
Channel
Debug

Fields #

NameDescription
TransactionId

Event ID 3022: Collection Metadata Destroy Failure.

#
Channel
Debug

Description

Collection Metadata Destroy Failure. Collection Id: {Message}. HRESULT: {HRESULT}.

Message #

Collection Metadata Destroy Failure. Collection Id: {Message}. HRESULT: {HRESULT}.

Fields #

NameDescription
Message
HRESULT

Event ID 3023: PDCActivation was used by process {Message} instead of SettingSyncHost.

#
Channel
Debug

Fields #

NameDescription
Message

Event ID 3024: Collection {CollectionId} was blocked from uploading to cloud storage.

#
Channel
Debug

Description

Collection {CollectionId} was blocked from uploading to cloud storage. (Reason: {Reason}).

Message #

Collection {CollectionId} was blocked from uploading to cloud storage. (Reason: {Reason})

Fields #

NameDescription
CollectionId
Reason

Event ID 3025: Collection {CollectionId} was blocked from downloading to Windows.

#
Channel
Debug

Description

Collection {CollectionId} was blocked from downloading to Windows. (Reason: {Reason}).

Message #

Collection {CollectionId} was blocked from downloading to Windows. (Reason: {Reason})

Fields #

NameDescription
CollectionId
Reason

Event ID 3026: Storage subscription operation (create/update) failed for {CollectionId} (HRESULT: {HRESULT}).

#
Channel
Debug

Fields #

NameDescription
CollectionId
HRESULT

Event ID 3027: Storage subscription operation (delete) failed for {CollectionId} (HRESULT: {HRESULT}).

#
Channel
Debug

Fields #

NameDescription
CollectionId
HRESULT

Event ID 3029: The collection ({CollectionId}) is being throttled due to excessive syncing.

#
Channel
Debug

Fields #

NameDescription
CollectionId

Event ID 9000

#
Channel
Analytic

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 9001

#
Channel
Analytic

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message

Event ID 9002

#
Channel
Analytic

Description

{Message}.

Message #

{Message}

Fields #

NameDescription
Message