Microsoft-Windows-SetupCl
30 events across 1 channel
Event ID 1: SetupCl statistic (Name): Description = Statistic.
#Event ID 2: SourceFunction@SourceLine : Message.
#Event ID 3: SourceFunction@SourceLine : Message.
#Event ID 4: SetupCl has started processing the registry to update SIDs and file paths (as necessary).
#Description
SetupCl has started processing the registry to update SIDs and file paths (as necessary).
Message #
Event ID 5: SetupCl has finished processing the registry to update SIDs and file paths (as necessary).
#Description
SetupCl has finished processing the registry to update SIDs and file paths (as necessary).
Message #
Event ID 6: SetupCl has started processing the file system to update SIDs.
#Description
SetupCl has started processing the file system to update SIDs.
Message #
Event ID 7: SetupCl has finished processing the file system to update SIDs.
#Description
SetupCl has finished processing the file system to update SIDs.
Message #
Event ID 8: SetupCl has started updating disk signatures.
#Description
SetupCl has started updating disk signatures.
Message #
Event ID 9: SetupCl has finished updating disk signatures.
#Description
SetupCl has finished updating disk signatures.
Message #
Event ID 10: SetupCl has started processing system registry hives.
#Description
SetupCl has started processing system registry hives.
Message #
Event ID 11: SetupCl has finished processing system registry hives.
#Description
SetupCl has finished processing system registry hives.
Message #
Event ID 12: SetupCl has started processing system registry hive: HiveName.
#Event ID 13: SetupCl has finished processing system registry hive: HiveName.
#Event ID 14: SetupCl has started processing user profile hives.
#Description
SetupCl has started processing user profile hives.
Message #
Event ID 15: SetupCl has finished processing user profile hives.
#Description
SetupCl has finished processing user profile hives.
Message #
Event ID 16: SetupCl will replace all instances of SID: [SID].
#Event ID 17: SetupCl will rewrite the old SID to: [SID].
#Event ID 18: SetupCl will replace all instances of path: [Path].
#Event ID 19: SetupCl will rewrite the old path to: [Path].
#Event ID 20: SetupCl has started retargeting symbolic links and directory junctions.
#Description
SetupCl has started retargeting symbolic links and directory junctions.
Message #
Event ID 21: SetupCl has finished retargeting symbolic links and directory junctions.
#Description
SetupCl has finished retargeting symbolic links and directory junctions.
Message #
Event ID 22: Error: Error (status = 0xMessage).
#Description
Error: Error (status = 0xMessage).
Message #
Fields #
| Name | Description |
|---|---|
Message UnicodeString | |
Status HexInt32 | NTSTATUS reference |
Event ID 23: SetupCl has started extending a partition.
#Description
SetupCl has started extending a partition.
Message #
Event ID 24: SetupCl has finished extending a partition.
#Description
SetupCl has finished extending a partition.
Message #
Event ID 25: SetupCl will extend the following partition: [Path].
#Event ID 26: SourceFunction@SourceLine : Message.
#Event ID 27: SetupCl has started executing upgrade hive updates.
#Description
SetupCl has started executing upgrade hive updates.
Message #
Event ID 28: SetupCl has finished executing upgrade hive updates.
#Description
SetupCl has finished executing upgrade hive updates.
Message #
Event ID 29: SetupCl has started executing request.
#Description
SetupCl has started executing request.
Message #
Event ID 30: SetupCl has finished executing request.
#Description
SetupCl has finished executing request.
Message #
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 75ebc33e-d017-4d0f-93ab-0b4f86579164
Defined in setupcl.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02