Microsoft-Windows-SMBServer

207 events across 7 channels

EventTitleChannelSample
1SMB2 Request NegotiatePerformanceN
2SMB2 Request Session SetupPerformanceN
3SMB2 Request LogoffPerformanceN
4SMB2 Request Tree ConnectPerformanceN
5SMB2 Request Tree DisconnectPerformanceN
6SMB2 Request EchoPerformanceN
7SMB2 Request CancelPerformanceN
8SMB2 Request CreatePerformanceN
9SMB2 Request ClosePerformanceN
10SMB2 Request FlushPerformanceN
11SMB2 Request ReadPerformanceN
12SMB2 Request WritePerformanceN
13SMB2 Request Break OplockPerformanceN
14SMB2 Request Notify Break LeasePerformanceN
15SMB2 Request Acknowledge Break LeasePerformanceN
16SMB2 Request LockPerformanceN
17SMB2 Request IoctlPerformanceN
18SMB2 Request Query DirectoryPerformanceN
19SMB2 Request Change NotifyPerformanceN
20SMB2 Request Query InfoPerformanceN
21SMB2 Request Set InfoPerformanceN
101SMB2 Response NegotiatePerformanceN
102SMB2 Response Session SetupPerformanceN
103SMB2 Response LogoffPerformanceN
104SMB2 Response Tree ConnectPerformanceN
105SMB2 Response Tree DisconnectPerformanceN
106SMB2 Response EchoPerformanceN
108SMB2 Response CreatePerformanceN
109SMB2 Response ClosePerformanceN
110SMB2 Response FlushPerformanceN
111SMB2 Response ReadPerformanceN
112SMB2 Response WritePerformanceN
113SMB2 Response Break OplockPerformanceN
115SMB2 Response Acknowledge Break LeasePerformanceN
116SMB2 Response LockPerformanceN
117SMB2 Response IoctlPerformanceN
118SMB2 Response Query DirectoryPerformanceN
119SMB2 Response Change NotifyPerformanceN
120SMB2 Response Query InfoPerformanceN
121SMB2 Response Set InfoPerformanceN
122SMB2 Response ErrorPerformanceN
200SMB2 Work Item Component TransitionPerformanceN
201SMB2 Work Item allocatedPerformanceN
202SMB2 Work Item releasedPerformanceN
203SMB2 Work Item activity id transferPerformanceN
204SMB2 Work Item external activity id stopPerformanceN
500SMB2 Connection acceptedAnalyticN
501SMB2 Connection Disconnected by PeerAnalyticN
502SMB2 Connection TerminatedAnalyticN
550SMB2 Session AllocatedAnalyticN
551Smb Session Authentication FailureAnalyticY
551SMB Session Authentication Failure.SecurityY
552SMB2 Session Authentication SuccessAnalyticN
553SMB2 Session Bound to ConnectionAnalyticN
554SMB2 Session TerminatedAnalyticN
555SMB2 Session Closed.AnalyticN
600SMB2 TreeConnect AllocatedAnalyticN
601SMB2 TreeConnect DisconnectedAnalyticN
602SMB2 TreeConnect TerminatedAnalyticN
603SMB2 TreeConnect Failed due to Cluster Endpoint InitializingAnalyticN
604A client connection to a continuously available share has been marked so that …OperationalN
605A client request on a continuously available share has been failed so that the …OperationalN
650SMB2 Open establishedAnalyticN
651SMB2 Open Disconnected - PreservedAnalyticN
652SMB2 Open ReconnectedAnalyticN
653SMB2 Open Suspended - PreservedAnalyticN
654SMB2 Open ClosedAnalyticN
655SMB2 Open Timed OutAnalyticN
656SMB2 Open TerminatedAnalyticN
657SMB2 Open Clustered Client Failover ClosedAnalyticN
658File handle for file "ShareName\FileName" was invalidated by user UserName from …OperationalN
700SMB2 Share AddedAnalyticN
701SMB2 Share ModifiedAnalyticN
702SMB2 Share DeletedAnalyticN
1000S4U2Self authentication failure - The client could not be reauthenticated with …OperationalN
1001A client attempted to access the server using SMB1 and was rejected because SMB1 …OperationalY
1002RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for …OperationalN
1003The server received an unencrypted message from client when encryption was …OperationalN
1004The server rejected an incorrectly signed message.OperationalN
1005The server failed to validate negotiation from client TranslatedStatus.OperationalN
1006The share denied access to the client.SecurityY
1007The share denied anonymous access to the client.SecurityN
1009The server denied anonymous access to the client.SecurityY
1010Endpoint added.OperationalY
1011Endpoint removed.OperationalY
1012The network name information changed.OperationalY
1013Endpoint coming online.OperationalN
1014Endpoint going offline.OperationalN
1015Decrypt call failed.SecurityY
1016Reopen failed.OperationalN
1017Handle scavenged.OperationalN
1018Backchannel invalidation of session completed.OperationalN
1019Backchannel invalidation of file completed.OperationalN
1020File system operation has taken longer than expected.OperationalN
1021LmCompatibilityLevel value is different from the default.SecurityY
1022File and printer sharing firewall rule enabled.ConnectivityY
1023One or more shares present on this server have access based enumeration enabled.OperationalN
1024SMB2 and SMB3 have been disabled on this server.OperationalN
1025One or more named pipes or shares have been marked for access by anonymous …OperationalY
1026File leasing has been disabled for the SMB2 and SMB3 protocols.OperationalN
1027The file and printer sharing firewall ports are currently closed.OperationalY
1028The maximum cluster-supported SMB dialect has changed.OperationalN
1029The Cipher Suite Order group policy setting is invalid.OperationalN
1030An MDL read or write completion request failed.OperationalN
1031The server detected a problem and has captured a live kernel dump to collect …OperationalN
1032The server detected a problem but was unable to capture a live kernel dump to …OperationalN
1033Sent RDMA .AnalyticY
1033Sent RDMA EventData.NotificationType event to LanmanServer for interface …OperationalY
1034Send RDMA Endpoint notification failure - .AnalyticY
1034Send RDMA Endpoint notification failure - EventData.FailureType.OperationalY
1035RDMA Endpoint .AnalyticN
1035RDMA Endpoint TransportName for interface InterfaceIndex was EndpointState.OperationalN
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface .AnalyticN
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface …OperationalN
1037RDMA listener creation failure - .AnalyticN
1037RDMA listener creation failure - FailureType.OperationalN
1038RDMA Send endpoint notification RPC failure for device .AnalyticN
1038RDMA Send endpoint notification RPC failure for device EventData.DeviceName - …OperationalY
1039Received Nsi notification type .AnalyticN
1039Received Nsi notification type NotificationType for interface InterfaceIndex …OperationalN
1040Received Mib notification type .AnalyticY
1040Received Mib notification type EventData.NotificationType for interface …OperationalY
1041Error reading FSCTL properties information from the registry.OperationalN
1042The certificate for the server is about to expire.OperationalN
1043RDMA connection disconnected.OperationalN
1044Quic connection shutdown.OperationalN
1045The server failed to update server certificate mapping.AnalyticN
1045The server failed to update server certificate mapping.OperationalN
1046The server received a request and the server requires encryption, but the server …OperationalN
1047The server received a Smb2Command request but is taking an abnormal amount of …OperationalN
1048The server processed a Smb2Command request.OperationalN
1049The certificate for the server has expired.OperationalN
1050Found InterfaceID endpoint(s) related to interface ID NumberOfEndpointsFound, …OperationalN
1051The SMB negotiate request processing failed on the server to select the …OperationalN
1052Failed to restore a server certificate mapping from persistent storage.OperationalN
1053Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings …OperationalY
1054Network operation has taken longer than expected.OperationalN
1055RDMA rundown is active.OperationalN
1056RDMA rundown is complete.OperationalN
1057Reactivation of RDMA support has commenced.OperationalN
1058RDMA is no longer disabled.OperationalN
1059SMBDirect load attempt complete.OperationalN
1060SMB DDP security changed from OldValue to NewValue.OperationalN
1061SMB2 Request Negotiate Dialect Failure.OperationalN
1062SMB Dialect Change.OperationalN
1080Component capabilities: SrvNetComponentCapabilities.OperationalY
1800CA failure - Failed to set continuously available property on a new or existing …OperationalN
1801CA failure - Failed to set continuously available property on a new or existing …OperationalN
1802The server failed to reserve the next ID region in the cluster registry.OperationalN
1803The security descriptor differs from the default value.OperationalN
1804No SMB1 usage detected in the last 20 minutes.AnalyticN
1900TDI mode enabled: .AnalyticY
1900TDI mode enabled: IsTdiEnabled.OperationalY
1901Failed to allocate an NSI table for network interface enumeration: .AnalyticN
1901Failed to allocate an NSI table for network interface enumeration: Status.OperationalN
1902Received notification of a newly-started network interface with Luid .AnalyticN
1902Received notification of a newly-started network interface with Luid NetLuid on …OperationalN
1903Received notification of a stopped network interface with Luid .AnalyticN
1903Received notification of a stopped network interface with Luid NetLuid on …OperationalN
1904Failed to open network interface with Luid .AnalyticN
1904Failed to open network interface with Luid NetLuid: error Status.OperationalN
1905The server closed the session as part of periodic system cleanup.OperationalY
1906Session key for connection is weaker than required.SecurityN
1907Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.AnalyticN
1908Custom FSCTL allow list was not successfully loaded after several retries.AnalyticN
1909Send QUIC Endpoint notification failure - .AnalyticN
1909Send QUIC Endpoint notification failure - FailureType.OperationalN
1910RDMA listen socket disable override is CurrentDisableOverrideState.OperationalN
1911Server Certificate failure - FailureType.OperationalN
1912Warning to set the QoS policy on file FileNameLength.OperationalN
1913The SMB connection was successfully established.OperationalN
1914The server was unable to perform revocation checks on the client certificate …OperationalN
2000Packet Fragment (FragmentSize bytes).DiagnosticN
3000SMB1 access Client Address: ClientName Guidance: This event indicates that a …AuditY
3002A remote device attempted SMB1 connection to this computer.AuditN
3003SMB1 server service has been automatically uninstalled.AuditN
3004SMB server admin file rundownOperationalN
3005SMB server admin session rundownOperationalN
3006SMB server admin share rundownOperationalN
3007Access Denied Server certificate mapping name: ServerName Client socket address: …AuditN
3008Access Allowed.AuditN
3009An error occurred while checking client certificate chain access during mutual …AuditN
3010An administrator attempted to assign an alternative SMB server listener port …OperationalN
3011The SMB server service created an endpoint with the following listener rule …OperationalY
3012The SMB server service failed to create an endpoint with the following listener …OperationalN
3013An administrator created an alternative SMB server listener port rule entry.OperationalN
3014An administrator updated an existing alterative SMB server listener port rule …OperationalN
3015An administrator removed an existing alternative SMB server listener port rule …OperationalN
3016The SMB server service failed to enable an implicit loopback interface for …OperationalN
3017The SMB server service failed to disable an implicit loopback interface for …OperationalN
3018The inbound ProtocolType firewall rule already exists for port Port.OperationalN
3019The inbound ProtocolType firewall rule failed to be created for port Port.OperationalN
3020The inbound ProtocolType firewall rule was successfully created for port Port.OperationalN
3021The SMB server observed that the client doesn't support signing.AuditN
3022The SMB server observed that the client doesn't support encryption.AuditN
3023The SMB client was logged on as Guest account.OperationalN
3024The SMB server observed that the client did not send an SPN during …AuditN
3024The SMB server observed that the client did not send an SPN during …OperationalN
3025The SMB server observed that the client sent an unrecognized SPN during …AuditN
3025The SMB server observed that the client sent an unrecognized SPN during …OperationalN
3026The SMB server observed that the client sent an empty SPN during authentication, …AuditN
3026The SMB server observed that the client sent an empty SPN during authentication, …OperationalN
3027The SMBv1 server observed that the SMBv1 client does not have signing enabled.AuditN
3027The SMBv1 server observed that the SMBv1 client does not have signing enabledOperationalN
4000The SMB client connection to the share was established.ConnectivityY
4000The SMB client connection to the share was establishedOperationalY
40000Packet (PacketSize bytes).DiagnosticN

Event ID 1: SMB2 Request Negotiate

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestNegotiate

Description

SMB2 Request Negotiate.

Message #

SMB2 Request Negotiate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityMode UInt16
Capabilities UInt32
DialectCount UInt16
Dialects UInt16
ClientGuid GUID
ConnectionGUID GUID

Event ID 2: SMB2 Request Session Setup

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestSessionSetup

Description

SMB2 Request Session Setup.

Message #

SMB2 Request Session Setup

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
VcNumber UInt8
SecurityMode UInt8
Capabilities UInt32
Channel UInt32
PreviousSessionId UInt64
ConnectionGUID GUID
SessionGUID GUID

Event ID 3: SMB2 Request Logoff

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestLogoff

Description

SMB2 Request Logoff.

Message #

SMB2 Request Logoff

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID
SessionGUID GUID

Event ID 4: SMB2 Request Tree Connect

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestTreeConnect

Description

SMB2 Request Tree Connect.

Message #

SMB2 Request Tree Connect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
PathLength UInt16
Path UnicodeString
ConnectionGUID GUID
SessionGUID GUID

Event ID 5: SMB2 Request Tree Disconnect

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestTreeDisconnect

Description

SMB2 Request Tree Disconnect.

Message #

SMB2 Request Tree Disconnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Event ID 6: SMB2 Request Echo

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestEcho

Description

SMB2 Request Echo.

Message #

SMB2 Request Echo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID

Event ID 7: SMB2 Request Cancel

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestCancel

Description

SMB2 Request Cancel.

Message #

SMB2 Request Cancel

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID

Event ID 8: SMB2 Request Create

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestCreate

Description

SMB2 Request Create.

Message #

SMB2 Request Create

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityFlags UInt8
RequestedOplockLevel UInt8
ImpersonationLevel UInt32Impersonation level (SecurityAnonymous=0, SecurityIdentification=1, SecurityImpersonation=2, SecurityDelegation=3).
Known values
%%1831
Anonymous
%%1832
Identification
%%1833
Impersonation
%%1840
Delegation
CreateFlags UInt64
RootDirectoryFid UInt64
DesiredAccess Int32Process access rights reference
FileAttributes Int32
ShareAccess Int32
CreateDisposition Int32
CreateOptions Int32
NameLength UInt16
FileName UnicodeString
CreateContextsCount UInt32
LeaseKey GUID
LeaseLevel UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Event ID 9: SMB2 Request Close

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestClose

Description

SMB2 Request Close.

Message #

SMB2 Request Close

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
CloseFlags UInt16
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 10: SMB2 Request Flush

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestFlush

Description

SMB2 Request Flush.

Message #

SMB2 Request Flush

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 11: SMB2 Request Read

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestRead

Description

SMB2 Request Read.

Message #

SMB2 Request Read

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
Length UInt32
Offset UInt64
FileId UInt64
MinimumCount UInt32
Channel UInt32
RemainingBytes UInt32
ReadChannelInfoOffset UInt16
ReadChannelInfoLength UInt16
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 12: SMB2 Request Write

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestWrite

Description

SMB2 Request Write.

Message #

SMB2 Request Write

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
Length UInt32
Offset UInt64
FileId UInt64
Channel UInt32
RemainingBytes UInt32
WriteChannelInfoOffset UInt16
WriteChannelInfoLength UInt16
WriteFlags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 13: SMB2 Request Break Oplock

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestBreakOplock

Description

SMB2 Request Break Oplock.

Message #

SMB2 Request Break Oplock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
OplockLevel UInt8
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 14: SMB2 Request Notify Break Lease

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestNotifyBreakLease

Description

SMB2 Request Notify Break Lease.

Message #

SMB2 Request Notify Break Lease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
LeaseFlags UInt32
CurrentLeaseState UInt32
NewLeaseState UInt32
BreakReason UInt32
AccessMaskHint UInt32
ShareMaskHint UInt32
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 15: SMB2 Request Acknowledge Break Lease

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestAcknowledgeBreakLease

Description

SMB2 Request Acknowledge Break Lease.

Message #

SMB2 Request Acknowledge Break Lease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
LeaseFlags UInt32
LeaseState UInt32
LeaseDuration Int64
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 16: SMB2 Request Lock

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestLock

Description

SMB2 Request Lock.

Message #

SMB2 Request Lock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
LockCount UInt16
Locks GUID

Event ID 17: SMB2 Request Ioctl

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestIoctl

Description

SMB2 Request Ioctl.

Message #

SMB2 Request Ioctl

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ControlCode UInt32
IoctlFlags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 18: SMB2 Request Query Directory

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestQueryDirectory

Description

SMB2 Request Query Directory.

Message #

SMB2 Request Query Directory

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileInformationClass UInt8
QueryDirectoryFlags UInt8
FileIndex UInt32
FileId UInt64
OutputBufferLength UInt32
NameLength UInt16
FileName UnicodeString
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 19: SMB2 Request Change Notify

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestChangeNotify

Description

SMB2 Request Change Notify.

Message #

SMB2 Request Change Notify

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ChangeNotifyFlags UInt16
FileId UInt64
OutputBufferLength UInt32
CompletionFilter UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 20: SMB2 Request Query Info

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestQueryInfo

Description

SMB2 Request Query Info.

Message #

SMB2 Request Query Info

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
InfoType UInt8
InfoClass UInt8
OutputBufferLength UInt32
SecurityInformation UInt32
QueryInfoFlags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 21: SMB2 Request Set Info

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2RequestSetInfo

Description

SMB2 Request Set Info.

Message #

SMB2 Request Set Info

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
InfoType UInt8
InfoClass UInt8
SecurityInformation UInt32
FileId UInt64
OutputBufferLength UInt32
OutputBuffer Binary
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 101: SMB2 Response Negotiate

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseNegotiate

Description

SMB2 Response Negotiate.

Message #

SMB2 Response Negotiate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
SecurityMode UInt16
DialectRevision UInt16
Capabilities UInt32
MaxTransactSize UInt32
MaxReadSize UInt32
MaxWriteSize UInt32
SystemTime UInt64
ConnectionGUID GUID

Event ID 102: SMB2 Response Session Setup

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseSessionSetup

Description

SMB2 Response Session Setup.

Message #

SMB2 Response Session Setup

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
SessionFlags UInt16
ConnectionGUID GUID
SessionGUID GUID

Event ID 103: SMB2 Response Logoff

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseLogoff

Description

SMB2 Response Logoff.

Message #

SMB2 Response Logoff

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID

Event ID 104: SMB2 Response Tree Connect

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseTreeConnect

Description

SMB2 Response Tree Connect.

Message #

SMB2 Response Tree Connect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ShareType UInt8
ShareFlags UInt32
Capabilities UInt32
MaximalAccess UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Event ID 105: SMB2 Response Tree Disconnect

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseTreeDisconnect

Description

SMB2 Response Tree Disconnect.

Message #

SMB2 Response Tree Disconnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Event ID 106: SMB2 Response Echo

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseEcho

Description

SMB2 Response Echo.

Message #

SMB2 Response Echo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID

Event ID 108: SMB2 Response Create

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseCreate

Description

SMB2 Response Create.

Message #

SMB2 Response Create

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OplockLevel UInt8
CreateAction UInt32
CreationTime UInt64
LastAccessTime UInt64
LastWriteTime UInt64
LastChangeTime UInt64
AllocationSize UInt64
EndOfFile UInt64
FileAttributes UInt32
FileId UInt64
CreateContextsCount UInt32
LeaseKey GUID
LeaseLevel UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 109: SMB2 Response Close

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseClose

Description

SMB2 Response Close.

Message #

SMB2 Response Close

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
CloseFlags UInt16
CreationTime UInt64
LastAccessTime UInt64
LastWriteTime UInt64
ChangeTime UInt64
AllocationSize UInt64
EndOfFile UInt64
FileAttributes UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 110: SMB2 Response Flush

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseFlush

Description

SMB2 Response Flush.

Message #

SMB2 Response Flush

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 111: SMB2 Response Read

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseRead

Description

SMB2 Response Read.

Message #

SMB2 Response Read

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
TransportDPHits UInt32
TransportDPTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LengthRead UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
FileId UInt64

Event ID 112: SMB2 Response Write

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseWrite

Description

SMB2 Response Write.

Message #

SMB2 Response Write

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
TransportDPHits UInt32
TransportDPTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LengthWritten UInt32
Remaining UInt32
WriteChannelInfoOffset UInt16
WriteChannelInfoLength UInt16
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
FileId UInt64

Event ID 113: SMB2 Response Break Oplock

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseBreakOplock

Description

SMB2 Response Break Oplock.

Message #

SMB2 Response Break Oplock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OplockLevel UInt8
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 115: SMB2 Response Acknowledge Break Lease

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseAcknowledgeBreakLease

Description

SMB2 Response Acknowledge Break Lease.

Message #

SMB2 Response Acknowledge Break Lease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LeaseFlags UInt32
LeaseState UInt32
LeaseDuration Int64
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 116: SMB2 Response Lock

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseLock

Description

SMB2 Response Lock.

Message #

SMB2 Response Lock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 117: SMB2 Response Ioctl

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseIoctl

Description

SMB2 Response Ioctl.

Message #

SMB2 Response Ioctl

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ControlCode UInt32
IoctlFlags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 118: SMB2 Response Query Directory

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseQueryDirectory

Description

SMB2 Response Query Directory.

Message #

SMB2 Response Query Directory

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 119: SMB2 Response Change Notify

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseChangeNotify

Description

SMB2 Response Change Notify.

Message #

SMB2 Response Change Notify

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 120: SMB2 Response Query Info

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseQueryInfo

Description

SMB2 Response Query Info.

Message #

SMB2 Response Query Info

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OutputBufferLength UInt32
OutputBuffer Binary
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 121: SMB2 Response Set Info

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseSetInfo

Description

SMB2 Response Set Info.

Message #

SMB2 Response Set Info

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 122: SMB2 Response Error

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2ResponseError

Description

SMB2 Response Error.

Message #

SMB2 Response Error

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 200: SMB2 Work Item Component Transition

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2WorkItemTransition

Description

SMB2 Work Item Component Transition.

Message #

SMB2 Work Item Component Transition

Fields #

NameDescription
ComponentId UInt32
LineNumber UInt32
FunctionNameLength UInt16
FunctionName AnsiString

Event ID 201: SMB2 Work Item allocated

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2WorkItemStart
Opcode
Start

Description

SMB2 Work Item allocated.

Message #

SMB2 Work Item allocated

Fields #

NameDescription
WorkItem UInt64

Event ID 202: SMB2 Work Item released

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2WorkItemStop
Opcode
Stop

Description

SMB2 Work Item released.

Message #

SMB2 Work Item released

Fields #

NameDescription
WorkItem UInt64

Event ID 203: SMB2 Work Item activity id transfer

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2WorkItemActivityTransfer
Opcode
Send

Description

SMB2 Work Item activity id transfer.

Message #

SMB2 Work Item activity id transfer

Event ID 204: SMB2 Work Item external activity id stop

#
Provider
Microsoft-Windows-SMBServer
Channel
Performance
Task
Smb2WorkItemActivityStop
Opcode
Stop

Description

SMB2 Work Item external activity id stop.

Message #

SMB2 Work Item external activity id stop

Event ID 500: SMB2 Connection accepted

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ConnectionAccept
Opcode
Start

Description

SMB2 Connection accepted.

Message #

SMB2 Connection accepted

Fields #

NameDescription
ConnectionGUID GUID
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Event ID 501: SMB2 Connection Disconnected by Peer

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ConnectionDisconnectEvent

Description

SMB2 Connection Disconnected by Peer.

Message #

SMB2 Connection Disconnected by Peer

Fields #

NameDescription
ConnectionGUID GUID
Flags UInt32
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Event ID 502: SMB2 Connection Terminated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ConnectionTerminate
Opcode
Stop

Description

SMB2 Connection Terminated.

Message #

SMB2 Connection Terminated

Fields #

NameDescription
ConnectionGUID GUID
Reason UInt32
Status HexInt32NTSTATUS reference
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Event ID 550: SMB2 Session Allocated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionAllocate
Opcode
Start

Description

SMB2 Session Allocated.

Message #

SMB2 Session Allocated

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID

Event ID 551: Smb Session Authentication Failure

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionAuthFailure

Description

SMB Session Authentication Failure.

Message #

Smb Session Authentication Failure

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
ClientAddressLength UInt32
ClientAddress Binary
SessionId HexInt64
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
SPN UnicodeString
SPNValidationPolicy UInt32
ReasonCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 551,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-18T01:38:02.9935045+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Security"
  },
  "event_data": {
    "SPNValidationPolicy": "0",
    "SessionGUID": "{d604743a-bfc1-0003-9b05-15d6c1bfdc01}",
    "ConnectionGUID": "{d604743a-bfc1-0009-d409-13d6c1bfdc01}",
    "UserName": "NT AUTHORITY\\ANONYMOUS LOGON",
    "UserNameLength": "28",
    "ClientNameLength": "12",
    "SPN": "session setup failed before the SPN could be queried",
    "SessionId": "0x4802a0000039",
    "Status": "0xc0000022",
    "ClientAddress": "0200D3CC0A020A150000000000000000",
    "TranslatedStatus": "0xc0000022",
    "ReasonCode": "11",
    "ClientAddressLength": "16",
    "ClientName": "\\\\10.2.10.21"
  }
}

Event ID 551: SMB Session Authentication Failure.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Level
Error
Task
Smb2SessionAuthFailure

Description

SMB Session Authentication Failure.

Message #

SMB Session Authentication Failure



Client Name: %11

Client Address: %6

User Name: %9

Session ID: %7

Status: %4 (%3)

SPN: %12

SPN Validation Policy: %13



Guidance:



You should expect this error when attempting to connect to shares using incorrect credentials.



This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.



This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, an incorrect service principal name, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled

Fields #

NameDescription
SessionGUID
ConnectionGUID
Status
TranslatedStatus
ClientAddressLength
ClientAddress
SessionId
UserNameLength
UserName
ClientNameLength
ClientName
SPN
SPNValidationPolicy
ReasonCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 551,
    "version": 3,
    "level": 2,
    "task": 551,
    "opcode": 0,
    "keywords": 580964351930793992,
    "time_created": "2022-04-07T17:25:55.271679+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 4460
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "SessionGUID": "E0AAB88C-4A9F-0000-B5F0-AAE09F4AD801",
      "ConnectionGUID": "E0AAB88C-4A9F-0000-A5F0-AAE09F4AD801",
      "Status": "0xc000006d",
      "TranslatedStatus": "0xc000006d",
      "ClientAddressLength": 16,
      "ClientAddress": "0200C33B0A0002860000000000000000",
      "SessionId": "0x100000000061",
      "UserNameLength": 0,
      "UserName": null,
      "ClientNameLength": 12,
      "ClientName": "\\\\10.0.2.134",
      "SPN": "session setup failed before the SPN could be queried",
      "SPNValidationPolicy": 0,
      "ReasonCode": 3
    }
  },
  "message": ""
}

References #

Event ID 552: SMB2 Session Authentication Success

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionAuthenticated

Description

SMB2 Session Authentication Success.

Message #

SMB2 Session Authentication Success

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString

Event ID 553: SMB2 Session Bound to Connection

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionBind

Description

SMB2 Session Bound to Connection.

Message #

SMB2 Session Bound to Connection

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
BindingSessionGUID GUID

Event ID 554: SMB2 Session Terminated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionTerminate
Opcode
Stop

Description

SMB2 Session Terminated.

Message #

SMB2 Session Terminated

Fields #

NameDescription
SessionGUID GUID
Reason UInt32

Event ID 555: SMB2 Session Closed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2SessionClose
Opcode
Stop

Description

SMB2 Session Closed.

Message #

SMB2 Session Closed.

Fields #

NameDescription
SessionGUID GUID
InvalidateSession Boolean
Reason UInt32

Event ID 600: SMB2 TreeConnect Allocated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2TreeConnectAllocate
Opcode
Start

Description

SMB2 TreeConnect Allocated.

Message #

SMB2 TreeConnect Allocated

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID
ShareGUID GUID
ShareNameLength UInt16
ShareName UnicodeString
ScopeNameLength UInt16
ScopeName UnicodeString
ShareProperties UInt32

Event ID 601: SMB2 TreeConnect Disconnected

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2TreeConnectDisconnect

Description

SMB2 TreeConnect Disconnected.

Message #

SMB2 TreeConnect Disconnected

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID

Event ID 602: SMB2 TreeConnect Terminated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2TreeConnectTerminate
Opcode
Stop

Description

SMB2 TreeConnect Terminated.

Message #

SMB2 TreeConnect Terminated

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID

Event ID 603: SMB2 TreeConnect Failed due to Cluster Endpoint Initializing

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2TreeConnectFailedDueToPending

Description

SMB2 TreeConnect Failed due to Cluster Endpoint Initializing.

Message #

SMB2 TreeConnect Failed due to Cluster Endpoint Initializing

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
ShareNameLength UInt16
ShareName UnicodeString
ScopeNameLength UInt16
ScopeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 604: A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best p...

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2TreeConnectForceClientReconnect

Description

A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity.

Message #

A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields #

NameDescription
SessionGUID GUID
TreeConnectGUID GUID
ShareNameLength UInt16
ShareName UnicodeString

Event ID 605: A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best poss...

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2TreeConnectForceClientReconnect

Description

A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity.

Message #

A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields #

NameDescription
SessionGUID GUID
TreeConnectGUID GUID
ShareNameLength UInt16
ShareName UnicodeString

Event ID 650: SMB2 Open established

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileOpen
Opcode
Start

Description

SMB2 Open established.

Message #

SMB2 Open established

Fields #

NameDescription
OpenGUID GUID
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID
ShareGUID GUID
NameLength UInt16
Name UnicodeString
LeaseId GUID
DesiredAccess UInt32Process access rights reference
SharingMode UInt32
CreateOptions UInt32
FileAttributes UInt32
IsReplay Boolean
IsResume Boolean

Event ID 651: SMB2 Open Disconnected - Preserved

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileDisconnect

Description

SMB2 Open Disconnected - Preserved.

Message #

SMB2 Open Disconnected - Preserved

Fields #

NameDescription
OpenGUID GUID

Event ID 652: SMB2 Open Reconnected

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileReconnect

Description

SMB2 Open Reconnected.

Message #

SMB2 Open Reconnected

Fields #

NameDescription
OpenGUID GUID
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID

Event ID 653: SMB2 Open Suspended - Preserved

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileSuspend

Description

SMB2 Open Suspended - Preserved.

Message #

SMB2 Open Suspended - Preserved

Fields #

NameDescription
OpenGUID GUID

Event ID 654: SMB2 Open Closed

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileClose

Description

SMB2 Open Closed.

Message #

SMB2 Open Closed

Fields #

NameDescription
OpenGUID GUID

Event ID 655: SMB2 Open Timed Out

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileTimeout

Description

SMB2 Open Timed Out.

Message #

SMB2 Open Timed Out

Fields #

NameDescription
OpenGUID GUID

Event ID 656: SMB2 Open Terminated

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileTerminate

Description

SMB2 Open Terminated.

Message #

SMB2 Open Terminated

Fields #

NameDescription
OpenGUID GUID

Event ID 657: SMB2 Open Clustered Client Failover Closed

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2FileCCFClose

Description

SMB2 Open Clustered Client Failover Closed.

Message #

SMB2 Open Clustered Client Failover Closed

Fields #

NameDescription
OpenGUID GUID
AppInstanceGUID GUID

Event ID 658: File handle for file "ShareName\FileName" was invalidated by user UserName from computer ComputerName.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2FileCCFCloseAudit

Description

File handle for file "ShareName\FileName" was invalidated by user UserName from computer ComputerName.

Message #

File handle for file "%8\%2" was invalidated by user %4 from computer %6

Fields #

NameDescription
FileNameLength UInt16
FileName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ComputerNameLength UInt16
ComputerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString

Event ID 700: SMB2 Share Added

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ShareAdd

Description

SMB2 Share Added.

Message #

SMB2 Share Added

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
PathNameLength UInt16
PathName UnicodeString
CSCState UInt32
ClusterShareType UInt32
ShareProperties UInt32
CaTimeOut UInt32
ShareState UInt32

Event ID 701: SMB2 Share Modified

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ShareModify

Description

SMB2 Share Modified.

Message #

SMB2 Share Modified

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
PathNameLength UInt16
PathName UnicodeString
CSCState UInt32
ClusterShareType UInt32
ShareProperties UInt32
CaTimeOut UInt32
ShareState UInt32

Event ID 702: SMB2 Share Deleted

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Smb2ShareDelete

Description

SMB2 Share Deleted.

Message #

SMB2 Share Deleted

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString

Event ID 1000: S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvS4U2SelfFailure

Description

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims. This may be expected if the account is not a domain account.

Message #

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.  This may be expected if the account is not a domain account.

Fields #

NameDescription
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString
Status UInt32NTSTATUS reference

Event ID 1001: A client attempted to access the server using SMB1 and was rejected because SMB1 file sharing support is disabled or has been uninstalled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvDisabled

Description

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Message #

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1001,
    "version": 1,
    "level": 4,
    "task": 1001,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-03-13T18:46:45.797325+00:00",
    "event_record_id": 30,
    "correlation": {},
    "execution": {
      "process_id": 11352,
      "thread_id": 7956
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

Event ID 1002: RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2RkfFailure

Description

RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Message #

RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Event ID 1003: The server received an unencrypted message from client when encryption was required.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvUnencryptedAcccessFailure

Description

The server received an unencrypted message. Message was rejected.

Message #

The server received an unencrypted message. Message was rejected.

Client Name: %4

Guidance:

This event indicates that a client is sending unencrypted data even though the SMB share requires encryption.

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1004: The server rejected an incorrectly signed message.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSignatureValidationFailure

Description

The server received an incorrectly signed message. Message was rejected.

Message #

The server received an incorrectly signed message. Message was rejected.

Client Name: %2

Guidance:

This event indicates that a client is sending an incorrectly signed request.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1005: The server failed to validate negotiation from client TranslatedStatus.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNegotiateValidationFailure

Description

The server failed to validate negotiation from client TranslatedStatus. Connection was terminated.

Message #

The server failed to validate negotiation from client %2. Connection was terminated.

Fields #

NameDescription
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1006: The share denied access to the client.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Level
Error
Task
SrvShareAccessCheckFailure

Description

The share denied access to the client.

Message #

The share denied access to the client.

Client Name: %10
Client Address: %6
User Name: %8
Session ID: %17
Share Name: %2
Share Path: %4
Status: %16 (%15)
Mapped Access: %11
Granted Access: %12
Security Descriptor: %14

Guidance:

You should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue.

Applications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required.

If access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions.

This error does not indicate a problem with authentication, only authorization.

Fields #

NameDescription
EventData.ShareNameLength UInt16
EventData.ShareName UnicodeString
EventData.SharePathLength UInt16
EventData.SharePath UnicodeString
EventData.ClientAddressLength UInt32
EventData.ClientAddress Binary
EventData.UserNameLength UInt16
EventData.UserName UnicodeString
EventData.ClientNameLength UInt16
EventData.ClientName UnicodeString
EventData.MappedAccess HexInt32
EventData.GrantedAccess HexInt32Process access rights reference
EventData.ShareSecurityDescriptorLength UInt32
EventData.ShareSecurityDescriptor Binary
EventData.Status HexInt32NTSTATUS reference
EventData.TranslatedStatus HexInt32
EventData.SessionID HexInt64
ShareNameLength UInt16
ShareName UnicodeString
SharePathLength UInt16
SharePath UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
MappedAccess HexInt32
GrantedAccess HexInt32Process access rights reference
ShareSecurityDescriptorLength UInt32
ShareSecurityDescriptor Binary
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
SessionID HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "{D48CE617-33A2-4BC3-A5C7-11AA4F29619E}",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 2,
    "task": 1006,
    "opcode": 0,
    "keywords": 580964351930793992,
    "time_created": "2026-05-30T02:01:40.0630814+00:00",
    "event_record_id": 62,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2020
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ShareNameLength": "14",
      "ShareName": "\\\\*\\EvtLabDeny",
      "SharePathLength": "17",
      "SharePath": "\\??\\C:\\EvtLabDeny",
      "ClientAddressLength": "28",
      "ClientAddress": "1700EDB0000000000000000000000000000000000000000100000000",
      "UserNameLength": "17",
      "UserName": "ludus\\domainadmin",
      "ClientNameLength": "7",
      "ClientName": "\\\\[::1]",
      "MappedAccess": "0x80",
      "GrantedAccess": "0x0",
      "ShareSecurityDescriptorLength": "96",
      "ShareSecurityDescriptor": "0100048048000000540000000000000014000000020034000200000001001400FF011F0001010000000000010000000000001800FF011F0001020000000000052000000020020000010100000000000512000000010100000000000512000000",
      "Status": "0xc0000022",
      "TranslatedStatus": "0xc0000022",
      "SessionID": "0x50032c000029"
    }
  },
  "message": "The share denied access to the client.\r\n\r\nClient Name: \\\\[::1]\r\nClient Address: [::1]:60848\r\nUser Name: ludus\\domainadmin\r\nSession ID: 0x50032C000029\r\nShare Name: \\\\*\\EvtLabDeny\r\nShare Path: \\??\\C:\\EvtLabDeny\r\nStatus: {Access Denied}\r\nA process has requested access to an object, but has not been granted those access rights. (0xC0000022)\r\nMapped Access: 0x80\r\nGranted Access: 0x0\r\nSecurity Descriptor: 0x0100048048000000540000000000000014000000020034000200000001001400FF011F0001010000000000010000000000001800FF011F0001020000000000052000000020020000010100000000000512000000010100000000000512000000\r\n\r\nGuidance:\r\n\r\nYou should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue.\r\n\r\nApplications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required.\r\n\r\nIf access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions.\r\n\r\nThis error does not indicate a problem with authentication, only authorization."
}

Event ID 1007: The share denied anonymous access to the client.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Task
SrvShareAnonymousAccessDeniedFailure

Description

The share denied anonymous access to the client.

Message #

The share denied anonymous access to the client.

Client Name: %8
Client Address: %6
Share Name: %2
Share Path: %4

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
SharePathLength UInt16
SharePath UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString

Event ID 1009: The server denied anonymous access to the client.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Task
SrvSessionAnonymousAccessDenied

Description

The server denied anonymous access to the client.

Message #

The server denied anonymous access to the client.

Client Name: %4
 Client Address: %2
Session ID: %5

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, Windows Server denies anonymous access to shares.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields #

NameDescription
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString
SessionId HexInt64
SessionGUID GUID
ConnectionGUID GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1009,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-18T01:38:02.9935019+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Security"
  },
  "event_data": {
    "SessionID": "0x4802a0000039",
    "ClientName": "\\\\10.2.10.21",
    "ClientAddressLength": "16",
    "ClientNameLength": "12",
    "ClientAddress": "0200D3CC0A020A150000000000000000",
    "ConnectionGUID": "{d604743a-bfc1-0009-d409-13d6c1bfdc01}",
    "SessionGUID": "{d604743a-bfc1-0003-9b05-15d6c1bfdc01}"
  }
}

Event ID 1010: Endpoint added.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvEndpointAdded

Description

Endpoint added.

Message #

Endpoint added.

Name: %2
Domain Name: %4
Transport Name: %6
Transport Flags: %7

Guidance:

You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required.

Fields #

NameDescription
EventData.NameLength
EventData.Name
EventData.DomainNameLength
EventData.DomainName
EventData.TransportNameLength
EventData.TransportName
EventData.TransportFlags
NameLength
Name
DomainNameLength
DomainName
TransportNameLength
TransportName
TransportFlags

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "{D48CE617-33A2-4BC3-A5C7-11AA4F29619E}",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 4,
    "task": 1010,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-05-29T16:33:06.3560975+00:00",
    "event_record_id": 43,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 488
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NameLength": "16",
      "Name": "TELEMETRY-DC-A  ",
      "DomainNameLength": "6",
      "DomainName": "cell-a",
      "TransportNameLength": "58",
      "TransportName": "\\Device\\NetBT_Tcpip_{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
      "TransportFlags": "0x1"
    }
  },
  "message": "Endpoint added.\r\n\r\nName: TELEMETRY-DC-A  \r\nDomain Name: cell-a\r\nTransport Name: \\Device\\NetBT_Tcpip_{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}\r\nTransport Flags: 0x1\r\n\r\nGuidance:\r\n\r\nYou should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required."
}

Event ID 1011: Endpoint removed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvEndpointRemoved

Description

Endpoint removed.

Message #

Endpoint removed.

Name: %2
Domain Name: %4
Transport Name: %6

Guidance:

You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. No user action is required.

Fields #

NameDescription
NameLength
Name
DomainNameLength
DomainName
TransportNameLength
TransportName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1011,
    "version": 0,
    "level": 4,
    "task": 1011,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2022-04-04T12:00:04.359257+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 196
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NameLength": 0,
      "Name": null,
      "DomainNameLength": 0,
      "DomainName": null,
      "TransportNameLength": 58,
      "TransportName": "\\Device\\NetBT_Tcpip_{64AAD862-869C-436D-A905-CCB55AA6A79F}"
    }
  },
  "message": ""
}

References #

Event ID 1012: The network name information changed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvNetNameInfoChange

Description

The network name information changed.

Message #

The network name information changed.

Change Type: %1
Net Name: %3
IP Address: %9
Flags: %4
Interface Index: %5
Capability: %6
Link Speed: %7

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network configuration. No user action is required.

Fields #

NameDescription
ChangeType UInt32
NetNameLength UInt16
NetName UnicodeString
Flags HexInt32
InterfaceIndex UInt32
Capability HexInt32
LinkSpeed UInt64
ClientAddressLength UInt16
ClientAddress Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1012,
    "version": 0,
    "level": 4,
    "task": 1012,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-03-13T17:13:21.447992+00:00",
    "event_record_id": 89,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 5676
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ChangeType": 0,
      "NetNameLength": 1,
      "NetName": "*",
      "Flags": "0x1",
      "InterfaceIndex": 5,
      "Capability": "0x1",
      "LinkSpeed": 10000000000,
      "ClientAddressLength": 128,
      "ClientAddress": "020000000A020A15000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"
    }
  },
  "message": ""
}

Event ID 1013: Endpoint coming online.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvEndpointOnline

Description

Endpoint coming online.

Message #

Endpoint coming online.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1014: Endpoint going offline.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvEndpointOffline

Description

Endpoint going offline.

Message #

Endpoint going offline.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1015: Decrypt call failed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Level
Error
Task
SrvDecryptionFailure

Description

Decrypt call failed.

Message #

Decrypt call failed.

Client Name: %2
Client Address: %4
Session ID: %7
Status: %6 (%5)

Guidance:

This event commonly occurs because a previous SMB session no longer exists. It may also be caused by packets that are altered on the network between the computers due to either errors or a "man-in-the-middle" attack.

Fields #

NameDescription
ClientNameLength UInt16
ClientName AnsiString
ClientAddressLength UInt16
ClientAddress Binary
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
SessionID HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1015,
    "level": 2,
    "task": 1015,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8803405+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B00000000000000000000FFFF0A020A0B0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
    "ClientName": "\\",
    "ClientAddressLength": "128",
    "ClientNameLength": "24",
    "TranslatedStatus": "0xc0000203",
    "Status": "0xc0000203",
    "SessionID": "0x0"
  }
}

Event ID 1016: Reopen failed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvReopenFailure

Description

Reopen failed.

Message #

Reopen failed.

Client Name: %7
Client Address: %9
User Name: %13
Session ID: %14
Share Name: %11
File Name: %16
Resume Key: %20
Status: %2 (%1)
RKF Status: %4 (%3)
Durable: %17
Resilient: %18
Persistent: %19
Reason: %21

Guidance:

The client attempted to reopen a continuously available handle, but the attempt failed. This typically indicates a problem with the network or underlying file being re-opened.

Fields #

NameDescription
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
RKFStatus HexInt32
TranslatedRKFStatus HexInt32
ConnectionGUID GUID
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
UserNameLength UInt16
UserName UnicodeString
SessionId HexInt64
FileNameLength UInt16
FileName UnicodeString
DurableHandle Boolean
ResilientHandle Boolean
PersistentHandle Boolean
ResumeKey GUID
Reason UInt32

Event ID 1017: Handle scavenged.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvHandleScavenge

Description

Handle scavenged.

Message #

Handle scavenged.

Share Name: %7
File Name: %9
Resume Key: %5
Persistent File ID: %3
Volatile File ID: %4
Durable: %1
Resilient or Persistent: %2

Guidance:

The server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted.

Fields #

NameDescription
DurableHandle Boolean
ResilientHandle Boolean
PersistentFID HexInt64
VolatileFID HexInt64
ResumeKey GUID
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Event ID 1018: Backchannel invalidation of session completed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSessionInvalidate

Description

Backchannel invalidation of session completed.

Message #

Backchannel invalidation of session completed.

Session ID: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields #

NameDescription
SessionId HexInt64
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
TaskStatus HexInt32
TranslatedTaskStatus HexInt32

Event ID 1019: Backchannel invalidation of file completed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvFileInvalidate

Description

Backchannel invalidation of file completed.

Message #

Backchannel invalidation of file completed.

Resume Key: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields #

NameDescription
ResumeKey GUID
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
TaskStatus HexInt32
TranslatedTaskStatus HexInt32

Event ID 1020: File system operation has taken longer than expected.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSlowFsOperation

Description

File system operation has taken longer than expected.

Message #

File system operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields #

NameDescription
Command UInt32
SessionGuid GUID
SessionId HexInt64
ConnectionGuid GUID
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
DurationInMilliseconds UInt64
ThresholdInMilliseconds UInt64
CtlCode UInt32
SubCode UInt32
TunneledControl UInt32

Event ID 1021: LmCompatibilityLevel value is different from the default.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Level
Informational
Task
SrvLmCompatibilityLevelNonDefault

Description

LmCompatibilityLevel value is different from the default.

Message #

LmCompatibilityLevel value is different from the default.

Configured LM Compatibility Level: %1
Default LM Compatibility Level: %2

Guidance:

LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers.

Value (Setting) - Description

0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication.

5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication.

Incompatibly configured  LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings.

Fields #

NameDescription
ConfiguredLmCompatibilityLevel UInt32
DefaultLmCompatibilityLevel UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 4,
    "task": 1021,
    "opcode": 0,
    "keywords": 576460752303423496,
    "time_created": "2026-03-14T00:02:46.284357+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 3608,
      "thread_id": 3620
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ConfiguredLmCompatibilityLevel": 5,
      "DefaultLmCompatibilityLevel": 3
    }
  },
  "message": ""
}

Event ID 1022: File and printer sharing firewall rule enabled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Connectivity
Level
Informational
Task
SrvFileSharingFirewallRuleEnabled

Description

File and printer sharing firewall rule enabled.

Message #

File and printer sharing firewall rule enabled.

Guidance:

You should expect this event when Windows Firewall is configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that has custom shares configured.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1022,
    "version": 0,
    "level": 4,
    "task": 1022,
    "opcode": 0,
    "keywords": 288230376151711752,
    "time_created": "2026-03-14T00:03:01.608520+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 3608,
      "thread_id": 3640
    },
    "channel": "Microsoft-Windows-SMBServer/Connectivity",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

Event ID 1023: One or more shares present on this server have access based enumeration enabled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvABESharesPresent

Description

One or more shares present on this server have access based enumeration enabled.

Message #

One or more shares present on this server have access based enumeration enabled.

Guidance:

You should expect this event when enabling access-based enumeration on one or more shares by using either Server Manager or the Set-SmbShare Windows PowerShell cmdlet. Access-based enumeration can raise CPU utilization when clients connect to shares with folders containing many peer-level resources to which a user does not have access. You can control the CPU utilization by configuring the ABELevel value in the Windows registry:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters\ABELevel [DWORD]

You can set the value for ABELevel to greater depths to minimize CPU overhead, but doing so diminishes the effectiveness of access-based enumeration:

Value = 0: access-based enumeration is enabled for all levels

Value = 1: access-based enumeration is enabled for a depth of 1 (example: \server\share)

Value = 2: access-based enumeration is enabled for a depth of 2 (example: \server\share\folder)

You can continue setting values for multiple depth levels.

Event ID 1024: SMB2 and SMB3 have been disabled on this server.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSmb2Disabled

Description

SMB2 and SMB3 have been disabled on this server. This results in reduced functionality and performance.

Message #

SMB2 and SMB3 have been disabled on this server.  This results in reduced functionality and performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: Smb2
Default Value: 1 (or not present)
Current Value: 0

Guidance:

You should expect this event when disabling SMB2/SMB3. Microsoft does not recommend disabling SMB2/SMB3. When SMB3 is disabled, you cannot use features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. In most scenarios, SMB provides a troubleshooting workaround as an alternative to disabling SMB2/SMB3. Use the Set-SmbServerConfiguration Windows PowerShell cmdlet to enable SMB2/SMB3.

Event ID 1025: One or more named pipes or shares have been marked for access by anonymous users.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Warning
Task
SrvNullSessionsAllowed

Description

One or more named pipes or shares have been marked for access by anonymous users. This increases the security risk of the computer by allowing unauthenticated users to connect to this server.

Message #

One or more named pipes or shares have been marked for access by anonymous users.  This increases the security risk of the computer by allowing unauthenticated users to connect to this server.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Values: NullSessionPipes, NullSessionShares
Default Value: Empty (or not present)
Current Value: Non-empty

Guidance:

You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 3,
    "task": 1025,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2023-11-06T06:25:44.207725+00:00",
    "event_record_id": 96,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 3512
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

References #

Event ID 1026: File leasing has been disabled for the SMB2 and SMB3 protocols.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvLeasingDisabled

Description

File leasing has been disabled for the SMB2 and SMB3 protocols. This reduces functionality and can decrease performance.

Message #

File leasing has been disabled for the SMB2 and SMB3 protocols.  This reduces functionality and can decrease performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: DisableLeasing
Default Value: 0 (or not present)
Current Value: non-zero

Guidance:

You should expect this event when disabling SMB 3 Leasing. Microsoft does not recommend disabling SMB Leasing. Once disabled, traffic from client to server may increase since metadata and data may no longer be retrieved from a local cache.

Event ID 1027: The file and printer sharing firewall ports are currently closed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvFirewallPortsClosed

Description

The file and printer sharing firewall ports are currently closed. This is the default configuration for a system that is not sharing content or is on a Public network.

Message #

The file and printer sharing firewall ports are currently closed.  This is the default configuration for a system that is not sharing content or is on a Public network.

Guidance:

You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer until SMB traffic is allowed through the firewall.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1027,
    "version": 0,
    "level": 4,
    "task": 1027,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2023-11-05T22:32:38.630794+00:00",
    "event_record_id": 124,
    "correlation": {},
    "execution": {
      "process_id": 3368,
      "thread_id": 3592
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

References #

Event ID 1028: The maximum cluster-supported SMB dialect has changed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2MaxClusterDialectUpdated

Description

The maximum cluster-supported SMB dialect has changed.

Message #

The maximum cluster-supported SMB dialect has changed.

NewMaxDialect: %1
OldMaxDialect: %2

Guidance:

You should expect this event during a Windows Failover Cluster upgrade. No user action is required.

Fields #

NameDescription
NewDialect UInt16
OldDialect UInt16

Event ID 1029: The Cipher Suite Order group policy setting is invalid.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2CipherSuiteOrder

Description

The Cipher Suite Order group policy setting is invalid.

Message #

The Cipher Suite Order group policy setting is invalid.

Guidance:

This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher Suite Order" group policy setting. The server will use the default cipher suite order "%1" until this error is resolved.

Fields #

NameDescription
CipherSuiteOrder UnicodeString

Event ID 1030: An MDL read or write completion request failed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2MdlIoCompletionFailure

Description

An MDL read or write completion request failed.

Message #

An MDL read or write completion request failed.

Server Name: %2
Share Name: %4
File Name: %6
IsRead: %7
Status: %8

Guidance:

The SMB server sends MDL completion requests to a file system upon completion of a buffered I/O to release system resources. The file system and its filter drivers must not fail MDL completion requests. Failures may result in memory leaks and degraded system performance and stability. Non-Microsoft file system filter drivers are the most common cause of failed MDL completion requests.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
IsRead Boolean
Status HexInt32NTSTATUS reference

Event ID 1031: The server detected a problem and has captured a live kernel dump to collect debug information.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2LiveDumpSucceeded

Description

The server detected a problem and has captured a live kernel dump to collect debug information.

Message #

The server detected a problem and has captured a live kernel dump to collect debug information.

Reason: %1
Dump Location: %SystemRoot%\LiveKernelReports

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields #

NameDescription
Reason UInt32

Event ID 1032: The server detected a problem but was unable to capture a live kernel dump to collect debug information.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2LiveDumpThrotteled

Description

The server detected a problem but was unable to capture a live kernel dump to collect debug information.

Message #

The server detected a problem but was unable to capture a live kernel dump to collect debug information.

Reason: %1

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. In this case, the server's request to create a live kernel dump was rejected. This is usually due to the live kernel dump throttle, which prevents frequent dumps from consuming too much disk space. Either wait for the throttle limit to expire (by default, 7 days), or contact Microsoft Support for steps to override the throttle. This event is written to the log no more than once per day. The problem that caused the server to the request a live kernel dump may be occuring more frequently.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields #

NameDescription
Reason UInt32

Event ID 1033: Sent RDMA .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Level
Informational
Task
Srv2RDMASendEndpointNotification

Description

Sent RDMA event to LanmanServer for interface .

Message #

Sent RDMA %1 event to LanmanServer for interface %3.

Fields #

NameDescription
NotificationType UInt32
InterfaceNameLength UInt16
InterfaceName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1033,
    "level": 4,
    "task": 3012,
    "opcode": 0,
    "time_created": "2026-04-17T21:57:31.5541370+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1033: Sent RDMA EventData.NotificationType event to LanmanServer for interface EventData.InterfaceName.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotification

Description

Sent RDMA EventData.NotificationType event to LanmanServer for interface EventData.InterfaceName.

Message #

Sent RDMA %1 event to LanmanServer for interface %3.

Fields #

NameDescription
NotificationType
InterfaceNameLength
InterfaceName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1033,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-10-26T04:17:52.198363+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 436
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NotificationType": 0,
      "InterfaceNameLength": 34,
      "InterfaceName": "\\Device\\RdmaSmbIpv4_169.254.253.61"
    }
  },
  "message": ""
}

References #

Event ID 1034: Send RDMA Endpoint notification failure - .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Level
Error
Task
Srv2RDMASendEndpointNotificationFailure

Description

Send RDMA Endpoint notification failure -.

Message #

Send RDMA Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1034,
    "level": 4,
    "task": 3013,
    "opcode": 0,
    "time_created": "2026-04-17T21:57:31.5668163+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1034: Send RDMA Endpoint notification failure - EventData.FailureType.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotificationFailure

Description

Send RDMA Endpoint notification failure - EventData.FailureType.

Message #

Send RDMA Endpoint notification failure - %1

Fields #

NameDescription
FailureType
InterfaceIndex
Error
DeviceNameLength
DeviceName
ExtraInformation

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1034,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-10-26T04:17:52.198365+00:00",
    "event_record_id": 19,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 436
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "FailureType": 6,
      "InterfaceIndex": 0,
      "Error": "0xc0000034",
      "DeviceNameLength": 34,
      "DeviceName": "\\Device\\RdmaSmbIpv4_169.254.253.61",
      "ExtraInformation": 0
    }
  },
  "message": ""
}

References #

Event ID 1035: RDMA Endpoint .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Srv2RDMAEndpointChange

Description

RDMA Endpoint for interface was .

Message #

RDMA Endpoint %4 for interface %2 was %1.

Fields #

NameDescription
EndpointState UInt32
InterfaceIndex UInt32
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1035: RDMA Endpoint TransportName for interface InterfaceIndex was EndpointState.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2RDMAEndpointChange

Description

RDMA Endpoint TransportName for interface InterfaceIndex was EndpointState.

Message #

RDMA Endpoint %4 for interface %2 was %1.

Fields #

NameDescription
EndpointState UInt32
InterfaceIndex UInt32
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1036: RDMA Endpoint allocation failure - Endpoint allocation failed for interface .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Srv2RDMAEndpointAllocationFailure

Description

RDMA Endpoint allocation failure - Endpoint allocation failed for interface .

Message #

RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2

Fields #

NameDescription
InterfaceIndex UInt32
Error HexInt32

Event ID 1036: RDMA Endpoint allocation failure - Endpoint allocation failed for interface InterfaceIndex.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2RDMAEndpointAllocationFailure

Description

RDMA Endpoint allocation failure - Endpoint allocation failed for interface InterfaceIndex. Error.

Message #

RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2

Fields #

NameDescription
InterfaceIndex UInt32
Error HexInt32

Event ID 1037: RDMA listener creation failure - .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Srv2RDMACreateListenerFailure

Description

RDMA listener creation failure -.

Message #

RDMA listener creation failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32

Event ID 1037: RDMA listener creation failure - FailureType.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2RDMACreateListenerFailure

Description

RDMA listener creation failure - FailureType.

Message #

RDMA listener creation failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32

Event ID 1038: RDMA Send endpoint notification RPC failure for device .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Srv2RDMASendEndpointNotificationRPCFailure

Description

RDMA Send endpoint notification RPC failure for device -.

Message #

RDMA Send endpoint notification RPC failure for device %3 - %1

Fields #

NameDescription
FailureType UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
Error HexInt32

Event ID 1038: RDMA Send endpoint notification RPC failure for device EventData.DeviceName - EventData.FailureType.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotificationRPCFailure

Description

RDMA Send endpoint notification RPC failure for device EventData.DeviceName - EventData.FailureType.

Message #

RDMA Send endpoint notification RPC failure for device %3 - %1

Fields #

NameDescription
FailureType
DeviceNameLength
DeviceName
Error

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1038,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-06T06:25:49.867686+00:00",
    "event_record_id": 98,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 428
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "FailureType": 3,
      "DeviceNameLength": 58,
      "DeviceName": "\\Device\\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}",
      "Error": "0x102"
    }
  },
  "message": ""
}

References #

Event ID 1039: Received Nsi notification type .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
Srv2RDMANsiNotificationReceived

Description

Received Nsi notification type for interface with NdkOperationalState.

Message #

Received Nsi notification type %1 for interface %2 with NdkOperationalState %3

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32
NdkOperationalState UInt16

Event ID 1039: Received Nsi notification type NotificationType for interface InterfaceIndex with NdkOperationalState NdkOperationalState.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Srv2RDMANsiNotificationReceived

Description

Received Nsi notification type NotificationType for interface InterfaceIndex with NdkOperationalState NdkOperationalState.

Message #

Received Nsi notification type %1 for interface %2 with NdkOperationalState %3

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32
NdkOperationalState UInt16

Event ID 1040: Received Mib notification type .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Level
Informational
Task
Srv2RDMAMibNotificationReceived

Description

Received Mib notification type for interface.

Message #

Received Mib notification type %1 for interface %2

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1040,
    "level": 4,
    "task": 3019,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:33.7279216+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1040: Received Mib notification type EventData.NotificationType for interface EventData.InterfaceIndex.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
Srv2RDMAMibNotificationReceived

Description

Received Mib notification type EventData.NotificationType for interface EventData.InterfaceIndex.

Message #

Received Mib notification type %1 for interface %2

Fields #

NameDescription
NotificationType
InterfaceIndex

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1040,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-05T22:32:37.991590+00:00",
    "event_record_id": 123,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 136
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NotificationType": 3,
      "InterfaceIndex": 0
    }
  },
  "message": ""
}

References #

Event ID 1041: Error reading FSCTL properties information from the registry.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvAdminFsctlPropertiesListReadingFailure

Description

Error reading FSCTL properties information from the registry. Registry value entry RegistryValueName will be ignored. Error: FailureType.

Message #

Error reading FSCTL properties information from the registry. Registry value entry %3 will be ignored. Error: %1

Fields #

NameDescription
FailureType UInt32
RegistryValueNameLength UInt32
RegistryValueName UnicodeString

Event ID 1042: The certificate for the server is about to expire.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ServerCertMappingExpiring

Description

The certificate for the server is about to expire.

Message #

The certificate for the server is about to expire. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate is about to expire. 

Renew or issue new certificates to avoid service interruption.

Fields #

NameDescription
CertSubjectNameLength UInt16
CertSubjectName UnicodeString
CertThumbprintLength UInt16
CertThumbprint UnicodeString
Expiring FILETIME

Event ID 1043: RDMA connection disconnected.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetRdmaConnectionClosed

Description

RDMA connection disconnected.

Message #

RDMA connection disconnected.

Transport name: %3
Milliseconds spent closing the connection: %1

Guidance:

Closing an RDMA connection should not take longer than 2 minutes. An RDMA IO that takes an abnormally long time to complete indicates a problem with the RDMA network adapters on this computer or its remote host. Contact your RDMA vendor for an updated driver and further troubleshooting.

Fields #

NameDescription
CloseOperationDurationInMillieconds UInt64
TransportNameLength UInt32
TransportName UnicodeString
EndpointShutdown UInt8
EndpointRemoved UInt8

Event ID 1044: Quic connection shutdown.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetQuicShutdownFailure

Description

Quic connection shutdown.

Message #

Quic connection shutdown.

Error: %1
Reason: %2
Endpoint Name: %4
Transport Name: %6

Guidance:

This event indicates that the winquic connection is shutting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections.

Fields #

NameDescription
ErrorCode UInt16
Reason UInt16
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1045: The server failed to update server certificate mapping.

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
ServerCertMappingUpdateFailure

Description

The server failed to update server certificate mapping.

Message #

The server failed to update server certificate mapping.____Name: %2__Subject: %4__Thumbprint: %6____The certificate can't be used for the server due to error %7____The server certificate mapping %9 removed.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
SubjectLength UInt16
Subject UnicodeString
ThumbPrintLength UInt16
ThumbPrint UnicodeString
Status HexInt32NTSTATUS reference
RemovedLength UInt16
Removed UnicodeString

Event ID 1045: The server failed to update server certificate mapping.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ServerCertMappingUpdateFailure

Description

The server failed to update server certificate mapping.

Message #

The server failed to update server certificate mapping.

Name: %2
Subject: %4
Thumbprint: %6

The certificate can't be used for the server due to error %7

The server certificate mapping %9 removed.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
SubjectLength UInt16
Subject UnicodeString
ThumbPrintLength UInt16
ThumbPrint UnicodeString
Status HexInt32NTSTATUS reference
RemovedLength UInt16
Removed UnicodeString

Event ID 1046: The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server...

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNoNegotiatedCipher

Description

The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access.

Message #

The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access.

Request: %10
Client Name: %4
Client Address: %8
User Name: %6
Session ID: %9
Share Name: %2

Guidance:

This event indicates that client is trying to access a server that requires encryption, but no cipher was negotiated, and server does not allow unencrypted access. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\RejectUnencryptedAccess to see if the value has been changed.

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64
Smb2Command UInt16

Event ID 1047: The server received a Smb2Command request but is taking an abnormal amount of time to process it.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2SlowCommand

Description

The server received a Smb2Command request but is taking an abnormal amount of time to process it.

Message #

The server received a %2 request but is taking an abnormal amount of time to process it.

Instance Id: %1
Command: %2
PerfBlock: %3
Duration(s): %4
Threshold(s): %5

Fields #

NameDescription
InstanceId UInt32
Smb2Command UInt16
Smb2PerfBlock UInt16
Duration UInt64
Threshold UInt64

Event ID 1048: The server processed a Smb2Command request.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2CommandTimeDistribution

Description

The server processed a Smb2Command request. Times taken to complete each stage below.

Message #

The server processed a %1 request. Times taken to complete each stage below.

Command: %1
AcquireLockTime(s): %2
IoTime(s): %3
TotalTime(s): %4
Threshold(s): %5

Fields #

NameDescription
Smb2Command UInt16
AcquireLockTime UInt64
IoTime UInt64
TotalTime UInt64
Threshold UInt64

Event ID 1049: The certificate for the server has expired.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ServerCertMappingExpired

Description

The certificate for the server has expired.

Message #

The certificate for the server has expired. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate has expired. 

Renew or issue new certificates to avoid service interruption.

Fields #

NameDescription
CertSubjectNameLength UInt16
CertSubjectName UnicodeString
CertThumbprintLength UInt16
CertThumbprint UnicodeString
Expiring FILETIME

Event ID 1050: Found InterfaceID endpoint(s) related to interface ID NumberOfEndpointsFound, closed NumberOfEndpointsClosed of which.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2ClosedEndpointsOutsideUnicastIPTable

Description

Found InterfaceID endpoint(s) related to interface ID NumberOfEndpointsFound, closed NumberOfEndpointsClosed of which.

Message #

Found %1 endpoint(s) related to interface ID %2, closed %3 of which.

Fields #

NameDescription
InterfaceID UInt32
NumberOfEndpointsFound UInt32
NumberOfEndpointsClosed UInt32

Event ID 1051: The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNegotiateCipherFailure

Description

The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Message #

The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Client encryption cipher suite order (most to least preferred): %2
Server encryption cipher suite order (most to least preferred): %4

Fields #

NameDescription
ClientCipherSuiteOrderLength UInt32
ClientCipherSuiteOrder UnicodeString
ServerCipherSuiteOrderLength UInt32
ServerCipherSuiteOrder UnicodeString
ClientCipherCount UInt16
LoggedClientCipherCount UInt16
ClientCipherOrder UInt16

Event ID 1052: Failed to restore a server certificate mapping from persistent storage.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ServerCertMappingRestoreFailure

Description

Failed to restore a server certificate mapping from persistent storage.

Message #

Failed to restore a server certificate mapping from persistent storage.

Subject: %2
Thumbprint: %4

Error code: %5.

Fields #

NameDescription
SubjectLength UInt16
Subject UnicodeString
ThumbprintLength UInt16
Thumbprint UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1053: Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings from persistent storage.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
ServerCertMappingRestoreSummary

Description

Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings from persistent storage. Last error code: Status.

Message #

Restored %2 of %1 server certificate mappings from persistent storage. Last error code: %3.

Fields #

NameDescription
CountOfCertsTotal UInt16
CountOfCertsRestored UInt16
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1053,
    "level": 4,
    "task": 3032,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:33.7687422+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1054: Network operation has taken longer than expected.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSlowNetworkOperation

Description

Network operation has taken longer than expected.

Message #

Network operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields #

NameDescription
Command UInt32
SessionGuid GUID
SessionId HexInt64
ConnectionGuid GUID
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
DurationInMilliseconds UInt64
ThresholdInMilliseconds UInt64
CtlCode UInt32
SubCode UInt32
TunneledControl UInt32

Event ID 1055: RDMA rundown is active.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetRdmaRundownActive

Description

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently ActiveRdmaResourceCount active RDMA resources.

Message #

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources.

Fields #

NameDescription
ActiveRdmaResourceCount UInt32

Event ID 1056: RDMA rundown is complete.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetRdmaRundownComplete

Description

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: NoOp.

Message #

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1.

Fields #

NameDescription
NoOp Boolean

Event ID 1057: Reactivation of RDMA support has commenced.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetRdmaReactivation

Description

Reactivation of RDMA support has commenced.

Message #

Reactivation of RDMA support has commenced.

Event ID 1058: RDMA is no longer disabled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetRdmaReactivationComplete

Description

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: NoOp.

Message #

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1.

Fields #

NameDescription
NoOp Boolean

Event ID 1059: SMBDirect load attempt complete.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetSmbDirectLoad

Description

SMBDirect load attempt complete.

Message #

SMBDirect load attempt complete.

Success: %1
Status code: %2
Service path: %4

Fields #

NameDescription
IsSuccess Boolean
LoadStatus HexInt32
ServicePathLength UInt16
ServicePath UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString

Event ID 1060: SMB DDP security changed from OldValue to NewValue.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2DirectDataPlacementSecurityChanged

Description

SMB DDP security changed from OldValue to NewValue.

Message #

SMB DDP security changed from %1 to %2.

Fields #

NameDescription
OldValue UInt32
NewValue UInt32

Event ID 1061: SMB2 Request Negotiate Dialect Failure.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2RequestNegotiate

Description

SMB2 Request Negotiate Dialect Failure.

Message #

SMB2 Request Negotiate Dialect Failure

Session ID: %1
Client Address: %18
Client Name:%20
Client Dialects: %12
Minimum dialect required by server: %15
Maximum dialect required by server: %16

Guidance:

You should expect this error when servers don't meet the dialects requested by client. Please check the minimum and maximum dialects set by the client and ensure the server supports the dialects.

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityMode UInt16
Capabilities UInt32
DialectCount UInt16
Dialects UInt16
ClientGuid GUID
ConnectionGUID GUID
MinSmb2Dialect HexInt32
MaxSmb2Dialect HexInt32
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString

Event ID 1062: SMB Dialect Change.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb2DialectChange

Description

SMB Dialect Change.

Message #

SMB Dialect Change 

%1 was changed from %2 to %3.

Fields #

NameDescription
SmbDialect UnicodeString
OldDialect HexInt32
NewDialect HexInt32

Event ID 1080: Component capabilities: SrvNetComponentCapabilities.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvNetComponentCapabilities

Description

Component capabilities: SrvNetComponentCapabilities.

Message #

Component capabilities: %1
Internal patch number: %2

Fields #

NameDescription
SrvNetComponentCapabilities HexInt32
PatchNumber HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1080,
    "level": 4,
    "task": 3069,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.1025119+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1800: CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SSClusterCaFailure

Description

CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Message #

CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString

Event ID 1801: CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to att...

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SSRkfCaFailure

Description

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume.

Message #

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
Status UInt32NTSTATUS reference

Event ID 1802: The server failed to reserve the next ID region in the cluster registry.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetGetNextIdFailure

Description

The server failed to reserve the next ID region in the cluster registry.

Message #

The server failed to reserve the next ID region in the cluster registry.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1803: The security descriptor differs from the default value.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SecurityCertificateChanged

Description

The security descriptor differs from the default value.

Message #

The security descriptor differs from the default value.

 Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity\%1

 Guidance:

 This is typically caused by an administrator or a third party changing the security on the object manually. To reset the security back to the default value, delete the path shown above.
 Microsoft does not recommend changing the default security of %1 as it may cause application incompatibilities or security concerns.

Fields #

NameDescription
DescriptorName UnicodeString

Event ID 1804: No SMB1 usage detected in the last 20 minutes.

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
NoSmb1ObservedInLastPeriod

Description

No SMB1 usage detected in the last 20 minutes.

Message #

No SMB1 usage detected in the last 20 minutes.

Guidance:

This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Server service will automatically uninstall.

Fields #

NameDescription
Days UInt32

Event ID 1900: TDI mode enabled: .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Level
Informational
Task
TdiModeEnabled

Description

TDI mode enabled.

Message #

TDI mode enabled: %1

Fields #

NameDescription
IsTdiEnabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1900,
    "level": 4,
    "task": 3042,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.1015487+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "IsTdiEnabled": "true"
  }
}

Event ID 1900: TDI mode enabled: IsTdiEnabled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
TdiModeEnabled

Description

TDI mode enabled: IsTdiEnabled.

Message #

TDI mode enabled: %1

Fields #

NameDescription
IsTdiEnabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1900,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-06T06:25:43.357313+00:00",
    "event_record_id": 95,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 224
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsTdiEnabled": true
  },
  "message": ""
}

References #

Event ID 1901: Failed to allocate an NSI table for network interface enumeration: .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
NsiTableAllocationFailed

Description

Failed to allocate an NSI table for network interface enumeration.

Message #

Failed to allocate an NSI table for network interface enumeration: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1901: Failed to allocate an NSI table for network interface enumeration: Status.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
NsiTableAllocationFailed

Description

Failed to allocate an NSI table for network interface enumeration: Status.

Message #

Failed to allocate an NSI table for network interface enumeration: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1902: Received notification of a newly-started network interface with Luid .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
NsiInterfaceAdded

Description

Received notification of a newly-started network interface with Luid on address family (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1902: Received notification of a newly-started network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
NsiInterfaceAdded

Description

Received notification of a newly-started network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1903: Received notification of a stopped network interface with Luid .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
NsiInterfaceRemoved

Description

Received notification of a stopped network interface with Luid on address family (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1903: Received notification of a stopped network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
NsiInterfaceRemoved

Description

Received notification of a stopped network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1904: Failed to open network interface with Luid .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
IPInterfaceNotFound

Description

Failed to open network interface with Luid : error.

Message #

Failed to open network interface with Luid %1: error %2

Fields #

NameDescription
NetLuid HexInt64
Status HexInt32NTSTATUS reference

Event ID 1904: Failed to open network interface with Luid NetLuid: error Status.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
IPInterfaceNotFound

Description

Failed to open network interface with Luid NetLuid: error Status.

Message #

Failed to open network interface with Luid %1: error %2

Fields #

NameDescription
NetLuid HexInt64
Status HexInt32NTSTATUS reference

Event ID 1905: The server closed the session as part of periodic system cleanup.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvSessionInvalidate

Description

The server closed the session as part of periodic system cleanup.

Message #

The server closed the session as part of periodic system cleanup.

Session Id: %1
Instance Id: %2
Reason: %3

Fields #

NameDescription
SessionId HexInt64
InstanceId UInt32
Reason UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1905,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-25T05:36:17.4681377+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Operational"
  },
  "event_data": {
    "Reason": "Idle session, no open files",
    "InstanceId": "0",
    "SessionId": "0x5000fc000021"
  }
}

Event ID 1906: Session key for connection is weaker than required.

#
Provider
Microsoft-Windows-SMBServer
Channel
Security
Task
Srv2SessionKeyTooShort

Description

Session key for connection is weaker than required. Connection will be closed as a result.

Message #

Session key for connection is weaker than required. Connection will be closed as a result.

Client: %2
User: %6
Session key length: %3
Required Session key length: %4

Guidance:
To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters]
"MinimumSessionKeyLength"

Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SessionKeyLength UInt32
RequiredSessionKeyLength UInt32
SessionId UInt64
UserName UnicodeString
AuthProtocol UInt32

Event ID 1907: Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
ReceivedNullReparseBuffer

Description

Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

Message #

Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

Event ID 1908: Custom FSCTL allow list was not successfully loaded after several retries.

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
AllowListLoadFailed

Description

Custom FSCTL allow list was not successfully loaded after several retries.

Message #

Custom FSCTL allow list was not successfully loaded after several retries.

Event ID 1909: Send QUIC Endpoint notification failure - .

#
Provider
Microsoft-Windows-SMBServer
Channel
Analytic
Task
SrvNetQuicSendEndpointNotificationFailure

Description

Send QUIC Endpoint notification failure -.

Message #

Send QUIC Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Event ID 1909: Send QUIC Endpoint notification failure - FailureType.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetQuicSendEndpointNotificationFailure

Description

Send QUIC Endpoint notification failure - FailureType.

Message #

Send QUIC Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Event ID 1910: RDMA listen socket disable override is CurrentDisableOverrideState.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetEventDisableRdmaListenSocketsState

Description

RDMA listen socket disable override is CurrentDisableOverrideState. New value is NewState. SrvNetIsRDMASupportEnabled is SrvNetEnableRdmaSupport. Action taken SrvNetEvaluateRdmaEnabledPolicy.

Message #

RDMA listen socket disable override is %1. New value is %2. SrvNetIsRDMASupportEnabled is %3. Action taken %4.

Fields #

NameDescription
CurrentDisableOverrideState Boolean
NewState Boolean
SrvNetEnableRdmaSupport Boolean
SrvNetEvaluateRdmaEnabledPolicy Boolean
SrvNetIsSMBDirectSupported Boolean
ActionTaken Boolean

Event ID 1911: Server Certificate failure - FailureType.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ServerCertificateFailure

Description

Server Certificate failure - FailureType.

Message #

Server Certificate failure - %1

Fields #

NameDescription
FailureType UInt32
Error HexInt32
MappingNameLength UInt16
MappingName UnicodeString
ThumprintLength UInt16
Thumbprint UnicodeString

Event ID 1912: Warning to set the QoS policy on file FileNameLength.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
ShareQosPolicySettingFailure

Description

Warning to set the QoS policy on file FileNameLength.

Message #

Warning to set the QoS policy on file %6.
Status=%1

Fields #

NameDescription
Status UInt32NTSTATUS reference
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Event ID 1913: The SMB connection was successfully established.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetConnectionEstablished

Description

The SMB connection was successfully established.

Message #

The SMB connection was successfully established.

Endpoint Name: %2
Transport: %3
Server socket address: %5
Client socket address: %7
Connection ID: %9
Mutual authentication: %10
Access control: %11

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
ConnectionType UInt32
ServerSocketAddressLength UInt32
ServerSocketAddress Binary
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
ConnectionIdSize UInt32
ConnectionId Binary
MutualAuthentication UInt32
AccessControlCheck UInt32

Event ID 1914: The server was unable to perform revocation checks on the client certificate chain.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetClientCertificateChainRevocationChecksFailed

Description

The server was unable to perform revocation checks on the client certificate chain. The connection will proceed.

Message #

The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. 

Verification Status: %1

Endpoint Name: %3
Transport: %4
Server socket address: %6
Client socket address: %8
Connection ID: %10

Fields #

NameDescription
Status UInt32NTSTATUS reference
EndpointNameLength UInt16
EndpointName UnicodeString
ConnectionType UInt32
TransportNameLength UInt16
TransportName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary

Event ID 2000: Packet Fragment (FragmentSize bytes).

#
Provider
Microsoft-Windows-SMBServer
Channel
Diagnostic
Task
PacketFragment

Description

Packet Fragment (FragmentSize bytes).

Message #

Packet Fragment (%2 bytes)

Fields #

NameDescription
ReassembledEventID UInt16
FragmentSize UInt32
FragmentData Binary

Event ID 3000: SMB1 access Client Address: ClientName Guidance: This event indicates that a client attempted to access the server using SMB1.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Level
Informational
Task
AuditSmb1Access

Description

SMB1 access.

Message #

SMB1 access

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields #

NameDescription
ClientName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 3000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 144115188075855872,
    "time_created": "2026-03-13T18:46:45.797324+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11352,
      "thread_id": 7956
    },
    "channel": "Microsoft-Windows-SMBServer/Audit",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ClientName": "10.2.10.11"
  },
  "message": ""
}

Event ID 3002: A remote device attempted SMB1 connection to this computer.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
AuditSmb1Access

Description

A remote device attempted SMB1 connection to this computer.

Message #

A remote device attempted SMB1 connection to this computer.

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields #

NameDescription
ClientName AnsiString

Event ID 3003: SMB1 server service has been automatically uninstalled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
UninstallSmb1Server

Description

SMB1 server service has been automatically uninstalled.n.

Message #

SMB1 server service has been automatically uninstalled.n
Guidance:

This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Server service was automatically uninstalled.

Fields #

NameDescription
Days UInt32

Event ID 3004: SMB server admin file rundown

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvAdminFileRundown

Description

SMB server admin file rundown.

Message #

SMB server admin file rundown

Fields #

NameDescription
FileId UInt64
FileNameLength UInt16
FileName UnicodeString
SessionId UInt64
ShareId UInt64

Event ID 3005: SMB server admin session rundown

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvAdminSessionRundown

Description

SMB server admin session rundown.

Message #

SMB server admin session rundown

Fields #

NameDescription
SessionId UInt64
ComputerNameLength UInt16
ComputerName UnicodeString
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString
DomainAndUserNameLength UInt16
DomainAndUserName UnicodeString
ClientOsLength UInt16
ClientOs UnicodeString
TransportNameLength UInt16
TransportName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
StartTime UInt64
LastActiveTime UInt64

Event ID 3006: SMB server admin share rundown

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvAdminShareRundown

Description

SMB server admin share rundown.

Message #

SMB server admin share rundown

Fields #

NameDescription
ShareId UInt64
ShareNameLength UInt16
ShareName UnicodeString

Event ID 3007: Access Denied Server certificate mapping name: ServerName Client socket address: ClientSocketAddress Client certificate chain: Subject, Issuer, Serial Number, SupportedHashAlgsStr CertChainProperti...

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
MutualAuthClientAccessDenied

Description

Access Denied.

Message #

Access Denied

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
SupportedHashAlgsStrLength UInt16
SupportedHashAlgsStr UnicodeString
CertChainPropertiesStrLength UInt16
CertChainPropertiesStr UnicodeString
DenySidsStrLength UInt16
DenySidsStr UnicodeString
AllowSidsStrLength UInt16
AllowSidsStr UnicodeString
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3008: Access Allowed.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
MutualAuthClientAccessAllowed

Description

Access Allowed.

Message #

Access Allowed

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
SupportedHashAlgsStrLength UInt16
SupportedHashAlgsStr UnicodeString
CertChainPropertiesStrLength UInt16
CertChainPropertiesStr UnicodeString
DenySidsStrLength UInt16
DenySidsStr UnicodeString
AllowSidsStrLength UInt16
AllowSidsStr UnicodeString
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3009: An error occurred while checking client certificate chain access during mutual authentication.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
SrvAdminMutualAuthClientAccessErrorShareRundown

Description

An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: Error.

Message #

An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1

Server certificate mapping name: %3
Client socket address: %5

Guidance:

For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709

Fields #

NameDescription
Error UInt32
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3010: An administrator attempted to assign an alternative SMB server listener port Port, but it is either in the 0?

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetAddEndpointListenerRulePortNotSupported

Description

An administrator attempted to assign an alternative SMB server listener port Port, but it is either in the 0―1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Message #

An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0?1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields #

NameDescription
Port UInt16

Event ID 3011: The SMB server service created an endpoint with the following listener rule entry settings.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
Informational
Task
SrvNetAddEndpointListenerRuleSuccess

Description

The SMB server service created an endpoint with the following listener rule entry settings.

Message #

The SMB server service created an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5

Guidance:

You should expect this event when assigning alternative SMB server listener ports and on any subsequent restarts of the SMB server service.

Fields #

NameDescription
TransportNameLength UInt16
TransportName UnicodeString
Port UInt16
TransportType UInt32
SrvInstances UInt32
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 3011,
    "level": 4,
    "task": 3062,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.6025061+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "TransportName": "\\Device\\NetbiosSmb",
    "SrvInstances": "15",
    "Status": "0x0",
    "Port": "445",
    "TransportNameLength": "18",
    "TransportType": "1"
  }
}

Event ID 3012: The SMB server service failed to create an endpoint with the following listener rule entry settings.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetAddEndpointListenerRuleFailure

Description

The SMB server service failed to create an endpoint with the following listener rule entry settings.

Message #

The SMB server service failed to create an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5
Error: %6

Guidance:

This error is usually caused by another process already listening on the same IP address and port. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields #

NameDescription
TransportNameLength UInt16
TransportName UnicodeString
Port UInt16
TransportType UInt32
SrvInstances UInt32
Status HexInt32NTSTATUS reference

Event ID 3013: An administrator created an alternative SMB server listener port rule entry.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetAddListenerRuleNew

Description

An administrator created an alternative SMB server listener port rule entry.

Message #

An administrator created an alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this alternative SMB server listener port.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3014: An administrator updated an existing alterative SMB server listener port rule entry.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetAddListenerRuleUpdate

Description

An administrator updated an existing alterative SMB server listener port rule entry.

Message #

An administrator updated an existing alterative SMB server listener port rule entry:

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this updated alternative SMB server listener port.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3015: An administrator removed an existing alternative SMB server listener port rule entry.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetAddListenerRuleRemove

Description

An administrator removed an existing alternative SMB server listener port rule entry.

Message #

An administrator removed an existing alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

This will close the specified listening sockets for the transport type on the specified port number. SMB clients cannot connect to this SMB server on that alternative port anymore.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3016: The SMB server service failed to enable an implicit loopback interface for interface Interface with NTSTATUS Status.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetEnableImplicitLoopbackInterfaceError

Description

The SMB server service failed to enable an implicit loopback interface for interface Interface with NTSTATUS Status.

Message #

The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields #

NameDescription
Interface UInt32
Status HexInt32NTSTATUS reference

Event ID 3017: The SMB server service failed to disable an implicit loopback interface for interface Interface with NTSTATUS Status.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetDisableImplicitLoopbackInterfaceError

Description

The SMB server service failed to disable an implicit loopback interface for interface Interface with NTSTATUS Status.

Message #

The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields #

NameDescription
Interface UInt32
Status HexInt32NTSTATUS reference

Event ID 3018: The inbound ProtocolType firewall rule already exists for port Port.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
AlternativePortFirewallRuleAlreadyAdded

Description

The inbound ProtocolType firewall rule already exists for port Port.

Message #

The inbound %2 firewall rule already exists for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3019: The inbound ProtocolType firewall rule failed to be created for port Port.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
AlternativePortFirewallRuleAddFailure

Description

The inbound ProtocolType firewall rule failed to be created for port Port.

Message #

The inbound %2 firewall rule failed to be created for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3020: The inbound ProtocolType firewall rule was successfully created for port Port.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
AlternativePortFirewallRuleAddSuccess

Description

The inbound ProtocolType firewall rule was successfully created for port Port.

Message #

The inbound %2 firewall rule was successfully created for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3021: The SMB server observed that the client doesn't support signing.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
Smb2ClientDoesNotSupportSigning

Description

The SMB server observed that the client doesn't support signing.

Message #

The SMB server observed that the client doesn't support signing.

Client name: %2
Server requires signing: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ServerRequiresSigning Boolean

Event ID 3022: The SMB server observed that the client doesn't support encryption.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
Smb2ClientDoesNotSupportEncryption

Description

The SMB server observed that the client doesn't support encryption.

Message #

The SMB server observed that the client doesn't support encryption.

Client name: %2
Server requires encryption: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
ServerRequiresEncryption Boolean
SmbClientDoesNotSupportEncryptionType UInt32

Event ID 3023: The SMB client was logged on as Guest account.

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
InsecureGuestLogon

Description

The SMB client was logged on as Guest account.

Message #

The SMB client was logged on as Guest account.

Client name: %2

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString

Event ID 3024: The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection ...

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
SrvNetClientDoesNotSupportSpn

Description

The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled. Client name: ClientName SPN Query Status: Status SPN Validation Policy: SPNValidationPolicy

Message #

The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled.

Client name: %2
SPN Query Status: %3
SPN Validation Policy: %4

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
Status HexInt32NTSTATUS reference
SPNValidationPolicy UInt32

Event ID 3024: The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA i...

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetClientDoesNotSupportSpn

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
Status HexInt32NTSTATUS reference
SPNValidationPolicy UInt32

Event ID 3025: The SMB server observed that the client sent an unrecognized SPN during authentication.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
SrvNetClientSentUnrecognizedSpn

Description

The SMB server observed that the client sent an unrecognized SPN during authentication.

Message #

The SMB server observed that the client sent an unrecognized SPN during authentication.

Client name: %2
SPN: %3
SPN Validation Policy: %6

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPN UnicodeString
ServiceClassIsValid Boolean
PrincipalNameIsValid Boolean
SPNValidationPolicy UInt32

Event ID 3025: The SMB server observed that the client sent an unrecognized SPN during authentication

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetClientSentUnrecognizedSpn

Description

The SMB server observed that the client sent an unrecognized SPN during authentication.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPN UnicodeString
ServiceClassIsValid Boolean
PrincipalNameIsValid Boolean
SPNValidationPolicy UInt32

Event ID 3026: The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but electe...

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
SrvNetClientSentEmptySpn

Description

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Message #

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Client name: %2
SPN Validation Policy: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPNValidationPolicy UInt32

Event ID 3026: The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
SrvNetClientSentEmptySpn

Description

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPNValidationPolicy UInt32

Event ID 3027: The SMBv1 server observed that the SMBv1 client does not have signing enabled.

#
Provider
Microsoft-Windows-SMBServer
Channel
Audit
Task
Smb1ClientDoesNotSupportSigning

Description

The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Message #

The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Client name: %2
Server requires signing: %3

Guidance:

This event indicates that the SMBv1 client may not support SMB signing, but due to protocol limitations, this cannot be determined with certainty. Further evaluation is recommended to verify the client's signing capabilities.

Prior to Windows Vista, SMBv1 clients that did not have signing explicitly enabled could not perform SMB signing.
This behavior was changed with the release of Windows Vista and was also backported to Windows XP and Windows Server 2003 through updates. With these changes, SMB clients may support signing even if it is not explicitly enabled, provided the server requires it.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
ServerRequiresSigning Boolean

Event ID 3027: The SMBv1 server observed that the SMBv1 client does not have signing enabled

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Task
Smb1ClientDoesNotSupportSigning

Description

The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
ServerRequiresSigning Boolean

Event ID 4000: The SMB client connection to the share was established.

#
Provider
Microsoft-Windows-SMBServer
Channel
Connectivity
Level
Informational
Task
Smb2ShareConnectionEstablished

Description

The SMB client connection to the share was established.

Message #

The SMB client connection to the share was established.

Share name: %2
Client name: %6
Client address: %4
Session ID: %7
Tree ID: %8
Transport type: %9
Signing used: %10
Encryption used: %11
Compression activated: %12

Fields #

NameDescriptionRules
ShareNameLength UInt16
ShareName UnicodeString3 detection rules
ClientAddressLength UInt32
ClientAddress Binary5 detection rules
ClientNameLength UInt16
ClientName UnicodeString
SessionId UInt64
TreeId UInt32
ConnectionType UInt32
SigningUsed Boolean1 detection rule
EncyptionUsed Boolean1 detection rule
CompressionUsed Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 4000,
    "level": 4,
    "task": 3076,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8656925+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B0000000000000000",
    "SigningUsed": "true",
    "ClientName": "\\\\10.2.10.11",
    "ClientAddressLength": "16",
    "ShareNameLength": "6",
    "ClientNameLength": "12",
    "TreeId": "13",
    "ShareName": "ADMIN$",
    "CompressionUsed": "false",
    "ConnectionType": "1",
    "EncyptionUsed": "false",
    "SessionId": "21990232555529"
  }
}

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 4000: The SMB client connection to the share was established

#
Provider
Microsoft-Windows-SMBServer
Channel
Operational
Level
4
Task
Smb2ShareConnectionEstablished

Description

The SMB client connection to the share was established.

Fields #

NameDescriptionRules
ShareNameLength UInt16
ShareName UnicodeString3 detection rules
ClientAddressLength UInt32
ClientAddress Binary5 detection rules
ClientNameLength UInt16
ClientName UnicodeString
SessionId UInt64
TreeId UInt32
ConnectionType UInt32
SigningUsed Boolean1 detection rule
EncyptionUsed Boolean1 detection rule
CompressionUsed Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 4000,
    "level": 4,
    "task": 3076,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8656925+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B0000000000000000",
    "SigningUsed": "true",
    "ClientName": "\\\\10.2.10.11",
    "ClientAddressLength": "16",
    "ShareNameLength": "6",
    "ClientNameLength": "12",
    "TreeId": "13",
    "ShareName": "ADMIN$",
    "CompressionUsed": "false",
    "ConnectionType": "1",
    "EncyptionUsed": "false",
    "SessionId": "21990232555529"
  }
}

Detection Rules #

View all rules referencing this event →

Sigma # view in coverage

Event ID 40000: Packet (PacketSize bytes).

#
Provider
Microsoft-Windows-SMBServer
Channel
Diagnostic
Task
Packet

Description

Packet (PacketSize bytes).

Message #

Packet (%4 bytes)

Fields #

NameDescription
ConnectionType UInt32
PeerAddressLength UInt32
PeerAddress Binary
PacketSize UInt32
PacketData Binary

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID d48ce617-33a2-4bc3-a5c7-11aa4f29619e

Defined in srv2.sys, the binary that emits these events.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4171, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02

Downloads