Microsoft-Windows-SMBServer

EventTitleChannelSampleRule
1SMB2 Request NegotiatePerformanceYN
2SMB2 Request Session SetupPerformanceYN
3SMB2 Request LogoffPerformanceYN
4SMB2 Request Tree ConnectPerformanceYN
5SMB2 Request Tree DisconnectPerformanceYN
6SMB2 Request EchoPerformanceNN
7SMB2 Request CancelPerformanceNN
8SMB2 Request CreatePerformanceNN
9SMB2 Request ClosePerformanceNN
10SMB2 Request FlushPerformanceNN
11SMB2 Request ReadPerformanceNN
12SMB2 Request WritePerformanceNN
13SMB2 Request Break OplockPerformanceNN
14SMB2 Request Notify Break LeasePerformanceNN
15SMB2 Request Acknowledge Break LeasePerformanceNN
16SMB2 Request LockPerformanceNN
17SMB2 Request IoctlPerformanceYN
18SMB2 Request Query DirectoryPerformanceNN
19SMB2 Request Change NotifyPerformanceNN
20SMB2 Request Query InfoPerformanceNN
21SMB2 Request Set InfoPerformanceNN
101SMB2 Response NegotiatePerformanceYN
102SMB2 Response Session SetupPerformanceYN
103SMB2 Response LogoffPerformanceYN
104SMB2 Response Tree ConnectPerformanceYN
105SMB2 Response Tree DisconnectPerformanceYN
106SMB2 Response EchoPerformanceNN
108SMB2 Response CreatePerformanceNN
109SMB2 Response ClosePerformanceNN
110SMB2 Response FlushPerformanceNN
111SMB2 Response ReadPerformanceNN
112SMB2 Response WritePerformanceNN
113SMB2 Response Break OplockPerformanceNN
115SMB2 Response Acknowledge Break LeasePerformanceNN
116SMB2 Response LockPerformanceNN
117SMB2 Response IoctlPerformanceNN
118SMB2 Response Query DirectoryPerformanceNN
119SMB2 Response Change NotifyPerformanceNN
120SMB2 Response Query InfoPerformanceNN
121SMB2 Response Set InfoPerformanceNN
122SMB2 Response ErrorPerformanceYN
200SMB2 Work Item Component TransitionPerformanceYN
201SMB2 Work Item allocatedPerformanceYN
202SMB2 Work Item releasedPerformanceYN
203SMB2 Work Item activity id transferPerformanceYN
204SMB2 Work Item external activity id stopPerformanceNN
500SMB2 Connection acceptedAnalyticYN
501SMB2 Connection Disconnected by PeerAnalyticYN
502SMB2 Connection TerminatedAnalyticYN
550SMB2 Session AllocatedAnalyticYN
551Smb Session Authentication FailureAnalyticYN
551SMB Session Authentication Failure.SecurityYN
552SMB2 Session Authentication SuccessAnalyticYN
553SMB2 Session Bound to ConnectionAnalyticNN
554SMB2 Session TerminatedAnalyticYN
555SMB2 Session Closed.AnalyticYN
600SMB2 TreeConnect AllocatedAnalyticYN
601SMB2 TreeConnect DisconnectedAnalyticYN
602SMB2 TreeConnect TerminatedAnalyticYN
603SMB2 TreeConnect Failed due to Cluster Endpoint InitializingAnalyticNN
604A client connection to a continuously available share has been marked so that …OperationalNN
605A client request on a continuously available share has been failed so that the …OperationalNN
650SMB2 Open establishedAnalyticNN
651SMB2 Open Disconnected - PreservedAnalyticNN
652SMB2 Open ReconnectedAnalyticNN
653SMB2 Open Suspended - PreservedAnalyticNN
654SMB2 Open ClosedAnalyticNN
655SMB2 Open Timed OutAnalyticNN
656SMB2 Open TerminatedAnalyticNN
657SMB2 Open Clustered Client Failover ClosedAnalyticNN
658File handle for file "ShareName\FileName" was invalidated by user UserName from …OperationalNN
700SMB2 Share AddedAnalyticYN
701SMB2 Share ModifiedAnalyticYN
702SMB2 Share DeletedAnalyticYN
1000S4U2Self authentication failure - The client could not be reauthenticated with …OperationalNN
1001A client attempted to access the server using SMB1 and was rejected because SMB1 …OperationalYN
1002RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for …OperationalNN
1003The server received an unencrypted message from client when encryption was …OperationalNN
1004The server rejected an incorrectly signed message.OperationalNN
1005The server failed to validate negotiation from client TranslatedStatus.OperationalNN
1006The share denied access to the client.SecurityYN
1007The share denied anonymous access to the client.SecurityYN
1009The server denied anonymous access to the client.SecurityYN
1010Endpoint added.OperationalYN
1011Endpoint removed.OperationalYN
1012The network name information changed.OperationalYN
1013Endpoint coming online.OperationalNN
1014Endpoint going offline.OperationalNN
1015Decrypt call failed.SecurityYN
1016Reopen failed.OperationalNN
1017Handle scavenged.OperationalYN
1018Backchannel invalidation of session completed.OperationalNN
1019Backchannel invalidation of file completed.OperationalNN
1020File system operation has taken longer than expected.OperationalNN
1021LmCompatibilityLevel value is different from the default.SecurityYN
1022File and printer sharing firewall rule enabled.ConnectivityYN
1023One or more shares present on this server have access based enumeration enabled.OperationalNN
1024SMB2 and SMB3 have been disabled on this server.OperationalNN
1025One or more named pipes or shares have been marked for access by anonymous …OperationalYN
1026File leasing has been disabled for the SMB2 and SMB3 protocols.OperationalNN
1027The file and printer sharing firewall ports are currently closed.OperationalYN
1028The maximum cluster-supported SMB dialect has changed.OperationalNN
1029The Cipher Suite Order group policy setting is invalid.OperationalNN
1030An MDL read or write completion request failed.OperationalNN
1031The server detected a problem and has captured a live kernel dump to collect …OperationalNN
1032The server detected a problem but was unable to capture a live kernel dump to …OperationalNN
1033Sent RDMA .AnalyticYN
1033Sent RDMA EventData.NotificationType event to LanmanServer for interface …OperationalYN
1034Send RDMA Endpoint notification failure - .AnalyticYN
1034Send RDMA Endpoint notification failure - EventData.FailureType.OperationalYN
1035RDMA Endpoint .AnalyticNN
1035RDMA Endpoint TransportName for interface InterfaceIndex was EndpointState.OperationalNN
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface .AnalyticNN
1036RDMA Endpoint allocation failure - Endpoint allocation failed for interface …OperationalNN
1037RDMA listener creation failure - .AnalyticNN
1037RDMA listener creation failure - FailureType.OperationalNN
1038RDMA Send endpoint notification RPC failure for device .AnalyticNN
1038RDMA Send endpoint notification RPC failure for device EventData.DeviceName - …OperationalYN
1039Received Nsi notification type .AnalyticNN
1039Received Nsi notification type NotificationType for interface InterfaceIndex …OperationalNN
1040Received Mib notification type .AnalyticYN
1040Received Mib notification type EventData.NotificationType for interface …OperationalYN
1041Error reading FSCTL properties information from the registry.OperationalNN
1042The certificate for the server is about to expire.OperationalNN
1043RDMA connection disconnected.OperationalNN
1044Quic connection shutdown.OperationalNN
1045The server failed to update server certificate mappingAnalytic, OperationalNN
1046The server received a request and the server requires encryption, but the server …OperationalNN
1047The server received a Smb2Command request but is taking an abnormal amount of …OperationalNN
1048The server processed a Smb2Command request.OperationalNN
1049The certificate for the server has expired.OperationalNN
1050Found InterfaceID endpoint(s) related to interface ID NumberOfEndpointsFound, …OperationalNN
1051The SMB negotiate request processing failed on the server to select the …OperationalNN
1052Failed to restore a server certificate mapping from persistent storage.OperationalNN
1053Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings …OperationalYN
1054Network operation has taken longer than expected.OperationalNN
1055RDMA rundown is active.OperationalNN
1056RDMA rundown is complete.OperationalNN
1057Reactivation of RDMA support has commenced.OperationalNN
1058RDMA is no longer disabled.OperationalNN
1059SMBDirect load attempt complete.OperationalNN
1060SMB DDP security changed from OldValue to NewValue.OperationalNN
1061SMB2 Request Negotiate Dialect Failure.OperationalNN
1062SMB Dialect Change.OperationalNN
1080Component capabilities: SrvNetComponentCapabilities.OperationalYN
1800CA failure - Failed to set continuously available property on a new or existing …OperationalNN
1801CA failure - Failed to set continuously available property on a new or existing …OperationalNN
1802The server failed to reserve the next ID region in the cluster registry.OperationalNN
1803The security descriptor differs from the default value.OperationalNN
1804No SMB1 usage detected in the last 20 minutes.AnalyticNN
1900TDI mode enabled: .AnalyticYN
1900TDI mode enabled: IsTdiEnabled.OperationalYN
1901Failed to allocate an NSI table for network interface enumeration: .AnalyticNN
1901Failed to allocate an NSI table for network interface enumeration: Status.OperationalNN
1902Received notification of a newly-started network interface with Luid .AnalyticNN
1902Received notification of a newly-started network interface with Luid NetLuid on …OperationalNN
1903Received notification of a stopped network interface with Luid .AnalyticNN
1903Received notification of a stopped network interface with Luid NetLuid on …OperationalNN
1904Failed to open network interface with Luid .AnalyticNN
1904Failed to open network interface with Luid NetLuid: error Status.OperationalNN
1905The server closed the session as part of periodic system cleanup.OperationalYN
1906Session key for connection is weaker than required.SecurityNN
1907Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.AnalyticNN
1908Custom FSCTL allow list was not successfully loaded after several retries.AnalyticNN
1909Send QUIC Endpoint notification failure - .AnalyticNN
1909Send QUIC Endpoint notification failure - FailureType.OperationalNN
1910RDMA listen socket disable override is CurrentDisableOverrideState.OperationalNN
1911Server Certificate failure - FailureType.OperationalNN
1912Warning to set the QoS policy on file FileNameLength.OperationalNN
1913The SMB connection was successfully established.OperationalNN
1914The server was unable to perform revocation checks on the client certificate …OperationalNN
2000Packet Fragment (FragmentSize bytes).DiagnosticNN
3000SMB1 access Client Address: ClientName Guidance: This event indicates that a …AuditYN
3002A remote device attempted SMB1 connection to this computer.AuditNN
3003SMB1 server service has been automatically uninstalled.AuditNN
3004SMB server admin file rundownOperationalNN
3005SMB server admin session rundownOperationalNN
3006SMB server admin share rundownOperationalNN
3007Access Denied Server certificate mapping name: ServerName Client socket address: …AuditNN
3008Access Allowed.AuditNN
3009An error occurred while checking client certificate chain access during mutual …AuditNN
3010An administrator attempted to assign an alternative SMB server listener port …OperationalNN
3011The SMB server service created an endpoint with the following listener rule …OperationalYN
3012The SMB server service failed to create an endpoint with the following listener …OperationalNN
3013An administrator created an alternative SMB server listener port rule entry.OperationalNN
3014An administrator updated an existing alterative SMB server listener port rule …OperationalNN
3015An administrator removed an existing alternative SMB server listener port rule …OperationalNN
3016The SMB server service failed to enable an implicit loopback interface for …OperationalNN
3017The SMB server service failed to disable an implicit loopback interface for …OperationalNN
3018The inbound ProtocolType firewall rule already exists for port Port.OperationalNN
3019The inbound ProtocolType firewall rule failed to be created for port Port.OperationalNN
3020The inbound ProtocolType firewall rule was successfully created for port Port.OperationalNN
3021The SMB server observed that the client doesn't support signing.AuditNN
3022The SMB server observed that the client doesn't support encryption.AuditNN
3023The SMB client was logged on as Guest account.OperationalNN
3024The SMB server observed that the client did not send an SPN during …AuditNN
3024The SMB server observed that the client did not send an SPN during …OperationalNN
3025The SMB server observed that the client sent an unrecognized SPN during …Audit, OperationalNN
3026The SMB server observed that the client sent an empty SPN during authentication, …AuditNN
3026The SMB server observed that the client sent an empty SPN during authentication, …OperationalNN
3027The SMBv1 server observed that the SMBv1 client does not have signing enabledAudit, OperationalNN
4000The SMB client connection to the share was established.ConnectivityYY
4000The SMB client connection to the share was establishedOperationalYY
40000Packet (PacketSize bytes).DiagnosticYN

Event ID 1: SMB2 Request Negotiate

#
Channel
Performance
Level
Informational
Task
Smb2RequestNegotiate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityMode UInt16
Capabilities UInt32
DialectCount UInt16
Dialects UInt16
ClientGuid GUID
ConnectionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.819Z",
    "version": 0
  },
  "event_data": {
    "Capabilities": 127,
    "ClientGuid": "{03000210-0302-0311-0385-F3887B85F111}",
    "Command": 0,
    "ConnectionGUID": "{0101D79F-0101-0000-C952-9026A3170D00}",
    "CreditsRequested": 0,
    "DialectCount": 5,
    "Dialects": 514,
    "Flags": 0,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 1,
    "ProcessId": 65279,
    "SecurityMode": 1,
    "SessionId": 0,
    "TreeId": 0
  },
  "message": ""
}

Event ID 2: SMB2 Request Session Setup

#
Channel
Performance
Level
Informational
Task
Smb2RequestSessionSetup

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
VcNumber UInt8
SecurityMode UInt8
Capabilities UInt32
Channel UInt32
PreviousSessionId UInt64
ConnectionGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 2,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.822Z",
    "version": 0
  },
  "event_data": {
    "Capabilities": 1,
    "Channel": 0,
    "Command": 1,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsRequested": 33,
    "Flags": 16,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 2,
    "PreviousSessionId": 0,
    "ProcessId": 65279,
    "SecurityMode": 1,
    "SessionGUID": "{00000000-0000-0000-0000-000000000000}",
    "SessionId": 0,
    "TreeId": 0,
    "VcNumber": 0
  },
  "message": ""
}

Event ID 3: SMB2 Request Logoff

#
Channel
Performance
Level
Informational
Task
Smb2RequestLogoff

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 3,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.580Z",
    "version": 0
  },
  "event_data": {
    "Command": 2,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsRequested": 5,
    "Flags": 16,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 9,
    "ProcessId": 65279,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "TreeId": 0
  },
  "message": ""
}

Event ID 4: SMB2 Request Tree Connect

#
Channel
Performance
Level
Informational
Task
Smb2RequestTreeConnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
PathLength UInt16
Path UnicodeString
ConnectionGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 4,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.824Z",
    "version": 0
  },
  "event_data": {
    "Command": 3,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsRequested": 9,
    "Flags": 24,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 4,
    "Path": "\\\\localhost\\IPC$",
    "PathLength": 16,
    "ProcessId": 65279,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "TreeId": 0
  },
  "message": ""
}

Event ID 5: SMB2 Request Tree Disconnect

#
Channel
Performance
Level
Informational
Task
Smb2RequestTreeDisconnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 5,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.579Z",
    "version": 0
  },
  "event_data": {
    "Command": 4,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsRequested": 6,
    "Flags": 16,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 7,
    "ProcessId": 65279,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}",
    "TreeId": 1
  },
  "message": ""
}

Event ID 6: SMB2 Request Echo

#
Channel
Performance
Task
Smb2RequestEcho

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID

Event ID 7: SMB2 Request Cancel

#
Channel
Performance
Task
Smb2RequestCancel

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ConnectionGUID GUID

Event ID 8: SMB2 Request Create

#
Channel
Performance
Task
Smb2RequestCreate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityFlags UInt8
RequestedOplockLevel UInt8
ImpersonationLevel UInt32Impersonation level (SecurityAnonymous=0, SecurityIdentification=1, SecurityImpersonation=2, SecurityDelegation=3).
Known values
%%1831
Anonymous
%%1832
Identification
%%1833
Impersonation
%%1840
Delegation
CreateFlags UInt64
RootDirectoryFid UInt64
DesiredAccess Int32Process access rights reference
FileAttributes Int32
ShareAccess Int32
CreateDisposition Int32
CreateOptions Int32
NameLength UInt16
FileName UnicodeString
CreateContextsCount UInt32
LeaseKey GUID
LeaseLevel UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Event ID 9: SMB2 Request Close

#
Channel
Performance
Task
Smb2RequestClose

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
CloseFlags UInt16
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 10: SMB2 Request Flush

#
Channel
Performance
Task
Smb2RequestFlush

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 11: SMB2 Request Read

#
Channel
Performance
Task
Smb2RequestRead

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
Length UInt32
Offset UInt64
FileId UInt64
MinimumCount UInt32
Channel UInt32
RemainingBytes UInt32
ReadChannelInfoOffset UInt16
ReadChannelInfoLength UInt16
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 12: SMB2 Request Write

#
Channel
Performance
Task
Smb2RequestWrite

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
Length UInt32
Offset UInt64
FileId UInt64
Channel UInt32
RemainingBytes UInt32
WriteChannelInfoOffset UInt16
WriteChannelInfoLength UInt16
WriteFlags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 13: SMB2 Request Break Oplock

#
Channel
Performance
Task
Smb2RequestBreakOplock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
OplockLevel UInt8
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 14: SMB2 Request Notify Break Lease

#
Channel
Performance
Task
Smb2RequestNotifyBreakLease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
LeaseFlags UInt32
CurrentLeaseState UInt32
NewLeaseState UInt32
BreakReason UInt32
AccessMaskHint UInt32
ShareMaskHint UInt32
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 15: SMB2 Request Acknowledge Break Lease

#
Channel
Performance
Task
Smb2RequestAcknowledgeBreakLease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
LeaseFlags UInt32
LeaseState UInt32
LeaseDuration Int64
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 16: SMB2 Request Lock

#
Channel
Performance
Task
Smb2RequestLock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
LockCount UInt16
Locks GUID

Event ID 17: SMB2 Request Ioctl

#
Channel
Performance
Level
Informational
Task
Smb2RequestIoctl

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileId UInt64
ControlCode UInt32
IoctlFlags UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 17,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.826Z",
    "version": 0
  },
  "event_data": {
    "Command": 11,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "ControlCode": 393620,
    "CreditsRequested": 8,
    "FileGUID": "{00000000-0000-0000-0000-000000000000}",
    "FileId": 18446744073709551615,
    "Flags": 48,
    "IoctlFlags": 1,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 5,
    "ProcessId": 65279,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}",
    "TreeId": 1
  },
  "message": ""
}

Event ID 18: SMB2 Request Query Directory

#
Channel
Performance
Task
Smb2RequestQueryDirectory

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
FileInformationClass UInt8
QueryDirectoryFlags UInt8
FileIndex UInt32
FileId UInt64
OutputBufferLength UInt32
NameLength UInt16
FileName UnicodeString
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 19: SMB2 Request Change Notify

#
Channel
Performance
Task
Smb2RequestChangeNotify

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
ChangeNotifyFlags UInt16
FileId UInt64
OutputBufferLength UInt32
CompletionFilter UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 20: SMB2 Request Query Info

#
Channel
Performance
Task
Smb2RequestQueryInfo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
InfoType UInt8
InfoClass UInt8
OutputBufferLength UInt32
SecurityInformation UInt32
QueryInfoFlags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 21: SMB2 Request Set Info

#
Channel
Performance
Task
Smb2RequestSetInfo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
InfoType UInt8
InfoClass UInt8
SecurityInformation UInt32
FileId UInt64
OutputBufferLength UInt32
OutputBuffer Binary
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 101: SMB2 Response Negotiate

#
Channel
Performance
Level
Informational
Task
Smb2ResponseNegotiate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
SecurityMode UInt16
DialectRevision UInt16
Capabilities UInt32
MaxTransactSize UInt32
MaxReadSize UInt32
MaxWriteSize UInt32
SystemTime UInt64
ConnectionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 101,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3476
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.819Z",
    "version": 0
  },
  "event_data": {
    "Capabilities": 7,
    "Command": 0,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 1,
    "DialectRevision": 767,
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 1,
    "MasterMessageId": 18446744073709551615,
    "MaxReadSize": 8388608,
    "MaxTransactSize": 8388608,
    "MaxWriteSize": 8388608,
    "MessageId": 0,
    "ProcessId": 0,
    "ProcessingCycles": 457,
    "ProcessingHits": 1,
    "QueueCycles": 31434,
    "QueueHits": 2,
    "SecurityCycles": 5251,
    "SecurityHits": 1,
    "SecurityMode": 1,
    "SessionId": 0,
    "Status": 0,
    "SystemTime": 134291727697784609,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeId": 0
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 102: SMB2 Response Session Setup

#
Channel
Performance
Level
Informational
Task
Smb2ResponseSessionSetup

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
SessionFlags UInt16
ConnectionGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 102,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 2728
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.823Z",
    "version": 0
  },
  "event_data": {
    "Command": 1,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 65,
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 25,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 3,
    "ProcessId": 65279,
    "ProcessingCycles": 1719,
    "ProcessingHits": 3,
    "QueueCycles": 3347,
    "QueueHits": 2,
    "SecurityCycles": 2923,
    "SecurityHits": 3,
    "SessionFlags": 0,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "Status": 0,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeId": 0
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 103: SMB2 Response Logoff

#
Channel
Performance
Level
Informational
Task
Smb2ResponseLogoff

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 103,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.580Z",
    "version": 0
  },
  "event_data": {
    "Command": 2,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 5,
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 17,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 9,
    "ProcessId": 65279,
    "ProcessingCycles": 0,
    "ProcessingHits": 0,
    "QueueCycles": 1911,
    "QueueHits": 1,
    "SecurityCycles": 0,
    "SecurityHits": 0,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "Status": 0,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeId": 0
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 104: SMB2 Response Tree Connect

#
Channel
Performance
Level
Informational
Task
Smb2ResponseTreeConnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ShareType UInt8
ShareFlags UInt32
Capabilities UInt32
MaximalAccess UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 104,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3476
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.825Z",
    "version": 0
  },
  "event_data": {
    "Capabilities": 0,
    "Command": 3,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 9,
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 25,
    "MasterMessageId": 18446744073709551615,
    "MaximalAccess": 18809343,
    "MessageId": 4,
    "ProcessId": 65279,
    "ProcessingCycles": 641,
    "ProcessingHits": 1,
    "QueueCycles": 3200,
    "QueueHits": 2,
    "SecurityCycles": 1075,
    "SecurityHits": 1,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "ShareFlags": 48,
    "ShareType": 2,
    "Status": 0,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}",
    "TreeId": 1
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 105: SMB2 Response Tree Disconnect

#
Channel
Performance
Level
Informational
Task
Smb2ResponseTreeDisconnect

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 105,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.579Z",
    "version": 0
  },
  "event_data": {
    "Command": 4,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 6,
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 17,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 7,
    "ProcessId": 65279,
    "ProcessingCycles": 0,
    "ProcessingHits": 0,
    "QueueCycles": 1801,
    "QueueHits": 1,
    "SecurityCycles": 0,
    "SecurityHits": 0,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "Status": 0,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}",
    "TreeId": 1
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 106: SMB2 Response Echo

#
Channel
Performance
Task
Smb2ResponseEcho

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID

Event ID 108: SMB2 Response Create

#
Channel
Performance
Task
Smb2ResponseCreate

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OplockLevel UInt8
CreateAction UInt32
CreationTime UInt64
LastAccessTime UInt64
LastWriteTime UInt64
LastChangeTime UInt64
AllocationSize UInt64
EndOfFile UInt64
FileAttributes UInt32
FileId UInt64
CreateContextsCount UInt32
LeaseKey GUID
LeaseLevel UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 109: SMB2 Response Close

#
Channel
Performance
Task
Smb2ResponseClose

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
CloseFlags UInt16
CreationTime UInt64
LastAccessTime UInt64
LastWriteTime UInt64
ChangeTime UInt64
AllocationSize UInt64
EndOfFile UInt64
FileAttributes UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 110: SMB2 Response Flush

#
Channel
Performance
Task
Smb2ResponseFlush

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 111: SMB2 Response Read

#
Channel
Performance
Task
Smb2ResponseRead

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
TransportDPHits UInt32
TransportDPTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LengthRead UInt32
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
FileId UInt64

Event ID 112: SMB2 Response Write

#
Channel
Performance
Task
Smb2ResponseWrite

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
TransportDPHits UInt32
TransportDPTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LengthWritten UInt32
Remaining UInt32
WriteChannelInfoOffset UInt16
WriteChannelInfoLength UInt16
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID
FileId UInt64

Event ID 113: SMB2 Response Break Oplock

#
Channel
Performance
Task
Smb2ResponseBreakOplock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OplockLevel UInt8
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 115: SMB2 Response Acknowledge Break Lease

#
Channel
Performance
Task
Smb2ResponseAcknowledgeBreakLease

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
LeaseFlags UInt32
LeaseState UInt32
LeaseDuration Int64
LeaseKey GUID
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 116: SMB2 Response Lock

#
Channel
Performance
Task
Smb2ResponseLock

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 117: SMB2 Response Ioctl

#
Channel
Performance
Task
Smb2ResponseIoctl

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ControlCode UInt32
IoctlFlags UInt32
FileId UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 118: SMB2 Response Query Directory

#
Channel
Performance
Task
Smb2ResponseQueryDirectory

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 119: SMB2 Response Change Notify

#
Channel
Performance
Task
Smb2ResponseChangeNotify

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 120: SMB2 Response Query Info

#
Channel
Performance
Task
Smb2ResponseQueryInfo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
OutputBufferLength UInt32
OutputBuffer Binary
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 121: SMB2 Response Set Info

#
Channel
Performance
Task
Smb2ResponseSetInfo

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Event ID 122: SMB2 Response Error

#
Channel
Performance
Level
Informational
Task
Smb2ResponseError

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsGranted UInt16
Flags UInt32
Status UInt32NTSTATUS reference
Srv2Instance UInt32
ProcessingHits UInt32
ProcessingTime UInt64
QueueHits UInt32
QueueTime UInt64
FileSystemFastHits UInt32
FileSystemFastTime UInt64
FileSystemSlowHits UInt32
FileSystemSlowTime UInt64
TransportFastHits UInt32
TransportFastTime UInt64
TransportSlowHits UInt32
TransportSlowTime UInt64
SecurityHits UInt32
SecurityTime UInt64
TotalTime UInt64
ConnectionGUID GUID
SessionGUID GUID
TreeConnectGUID GUID
FileGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 122,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3476
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.822Z",
    "version": 0
  },
  "event_data": {
    "Command": 1,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "CreditsGranted": 1,
    "FileGUID": "{00000000-0000-0000-0000-000000000000}",
    "FileSystemFastCycles": 0,
    "FileSystemFastHits": 0,
    "FileSystemSlowCycles": 0,
    "FileSystemSlowHits": 0,
    "Flags": 17,
    "MasterMessageId": 18446744073709551615,
    "MessageId": 2,
    "ProcessId": 65279,
    "ProcessingCycles": 300,
    "ProcessingHits": 1,
    "QueueCycles": 3241,
    "QueueHits": 2,
    "SecurityCycles": 1758,
    "SecurityHits": 1,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "SessionId": 140737488355349,
    "Status": 3221225494,
    "TransportFastCycles": 0,
    "TransportFastHits": 0,
    "TransportSlowCycles": 0,
    "TransportSlowHits": 0,
    "TreeConnectGUID": "{00000000-0000-0000-0000-000000000000}",
    "TreeId": 0
  },
  "message": ""
}

Example keys not documented in the fields table: FileSystemFastCycles, FileSystemSlowCycles, ProcessingCycles, QueueCycles, SecurityCycles, TransportFastCycles, TransportSlowCycles

Event ID 200: SMB2 Work Item Component Transition

#
Channel
Performance
Level
Informational
Task
Smb2WorkItemTransition

Fields #

NameDescription
ComponentId UInt32
LineNumber UInt32
FunctionNameLength UInt16
FunctionName AnsiString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 200,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14260
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.815Z",
    "version": 0
  },
  "event_data": {
    "ComponentId": 1,
    "FunctionName": "Srv2PostToThreadPool",
    "FunctionNameLength": 20,
    "LineNumber": 307
  },
  "message": ""
}

Event ID 201: SMB2 Work Item allocated

#
Channel
Performance
Level
Informational
Task
Smb2WorkItemStart
Opcode
Start

Fields #

NameDescription
WorkItem UInt64

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 201,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14260
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.815Z",
    "version": 0
  },
  "event_data": {
    "WorkItem": 18446682534291524296
  },
  "message": ""
}

Event ID 202: SMB2 Work Item released

#
Channel
Performance
Level
Informational
Task
Smb2WorkItemStop
Opcode
Stop

Fields #

NameDescription
WorkItem UInt64

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 202,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.819Z",
    "version": 0
  },
  "event_data": {
    "WorkItem": 18446682534291524296
  },
  "message": ""
}

Event ID 203: SMB2 Work Item activity id transfer

#
Channel
Performance
Level
Informational
Task
Smb2WorkItemActivityTransfer
Opcode
Send

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Performance",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 203,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 9,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.818Z",
    "version": 0
  },
  "event_data": {},
  "message": ""
}

Event ID 204: SMB2 Work Item external activity id stop

#
Channel
Performance
Task
Smb2WorkItemActivityStop
Opcode
Stop

Event ID 500: SMB2 Connection accepted

#
Channel
Analytic
Level
Informational
Task
Smb2ConnectionAccept
Opcode
Start

Fields #

NameDescription
ConnectionGUID GUID
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 500,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.818Z",
    "version": 0
  },
  "event_data": {
    "Address": "1700EEB5000000000000000000000000000000000000000100000000",
    "AddressLength": 28,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "TransportLength": 18,
    "TransportName": "\\Device\\NetbiosSmb"
  },
  "message": ""
}

Event ID 501: SMB2 Connection Disconnected by Peer

#
Channel
Analytic
Level
Informational
Task
Smb2ConnectionDisconnectEvent

Fields #

NameDescription
ConnectionGUID GUID
Flags UInt32
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 501,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 4520
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.581Z",
    "version": 0
  },
  "event_data": {
    "Address": "1700EEB5000000000000000000000000000000000000000100000000",
    "AddressLength": 28,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "Flags": 0,
    "TransportLength": 18,
    "TransportName": "\\Device\\NetbiosSmb"
  },
  "message": ""
}

Event ID 502: SMB2 Connection Terminated

#
Channel
Analytic
Level
Informational
Task
Smb2ConnectionTerminate
Opcode
Stop

Fields #

NameDescription
ConnectionGUID GUID
Reason UInt32
Status HexInt32NTSTATUS reference
AddressLength UInt32
Address Binary
TransportLength UInt32
TransportName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 502,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 4520
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.581Z",
    "version": 0
  },
  "event_data": {
    "Address": "1700EEB5000000000000000000000000000000000000000100000000",
    "AddressLength": 28,
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "Reason": 2,
    "Status": "00000000",
    "TransportLength": 18,
    "TransportName": "\\Device\\NetbiosSmb"
  },
  "message": ""
}

Event ID 550: SMB2 Session Allocated

#
Channel
Analytic
Level
Informational
Task
Smb2SessionAllocate
Opcode
Start

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 550,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3476
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.822Z",
    "version": 0
  },
  "event_data": {
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 551: Smb Session Authentication Failure

#
Channel
Analytic
Task
Smb2SessionAuthFailure

Description

SMB Session Authentication Failure.

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
ClientAddressLength UInt32
ClientAddress Binary
SessionId HexInt64
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
SPN UnicodeString
SPNValidationPolicy UInt32
ReasonCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 551,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-18T01:38:02.9935045+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Security"
  },
  "event_data": {
    "SPNValidationPolicy": "0",
    "SessionGUID": "{d604743a-bfc1-0003-9b05-15d6c1bfdc01}",
    "ConnectionGUID": "{d604743a-bfc1-0009-d409-13d6c1bfdc01}",
    "UserName": "NT AUTHORITY\\ANONYMOUS LOGON",
    "UserNameLength": "28",
    "ClientNameLength": "12",
    "SPN": "session setup failed before the SPN could be queried",
    "SessionId": "0x4802a0000039",
    "Status": "0xc0000022",
    "ClientAddress": "0200D3CC0A020A150000000000000000",
    "TranslatedStatus": "0xc0000022",
    "ReasonCode": "11",
    "ClientAddressLength": "16",
    "ClientName": "\\\\10.2.10.21"
  }
}

Event ID 551: SMB Session Authentication Failure.

#
Channel
Security
Level
Error
Task
Smb2SessionAuthFailure

Message #

SMB Session Authentication Failure



Client Name: %11

Client Address: %6

User Name: %9

Session ID: %7

Status: %4 (%3)

SPN: %12

SPN Validation Policy: %13



Guidance:



You should expect this error when attempting to connect to shares using incorrect credentials.



This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.



This error can occur when using incorrect usernames and passwords with NTLM, mismatched LmCompatibility settings between client and server, an incorrect service principal name, duplicate Kerberos service principal names, incorrect Kerberos ticket-granting service tickets, or Guest accounts without Guest access enabled

Fields #

NameDescription
SessionGUID
ConnectionGUID
Status
TranslatedStatus
ClientAddressLength
ClientAddress
SessionId
UserNameLength
UserName
ClientNameLength
ClientName
SPN
SPNValidationPolicy
ReasonCode

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 551,
    "version": 3,
    "level": 2,
    "task": 551,
    "opcode": 0,
    "keywords": 580964351930793992,
    "time_created": "2022-04-07T17:25:55.271679+00:00",
    "event_record_id": 10,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 4460
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "WIN-FPV0DSIC9O6.lab.local",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "SessionGUID": "E0AAB88C-4A9F-0000-B5F0-AAE09F4AD801",
      "ConnectionGUID": "E0AAB88C-4A9F-0000-A5F0-AAE09F4AD801",
      "Status": "0xc000006d",
      "TranslatedStatus": "0xc000006d",
      "ClientAddressLength": 16,
      "ClientAddress": "0200C33B0A0002860000000000000000",
      "SessionId": "0x100000000061",
      "UserNameLength": 0,
      "UserName": null,
      "ClientNameLength": 12,
      "ClientName": "\\\\10.0.2.134",
      "SPN": "session setup failed before the SPN could be queried",
      "SPNValidationPolicy": 0,
      "ReasonCode": 3
    }
  },
  "message": ""
}

References #

Event ID 552: SMB2 Session Authentication Success

#
Channel
Analytic
Level
Informational
Task
Smb2SessionAuthenticated

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 552,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 2728
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.823Z",
    "version": 0
  },
  "event_data": {
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "DomainName": "ludus",
    "DomainNameLength": 5,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "UserName": "domainadmin",
    "UserNameLength": 11
  },
  "message": ""
}

Event ID 553: SMB2 Session Bound to Connection

#
Channel
Analytic
Task
Smb2SessionBind

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
BindingSessionGUID GUID

Event ID 554: SMB2 Session Terminated

#
Channel
Analytic
Level
Informational
Task
Smb2SessionTerminate
Opcode
Stop

Fields #

NameDescription
SessionGUID GUID
Reason UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 554,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.580Z",
    "version": 0
  },
  "event_data": {
    "Reason": 0,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 555: SMB2 Session Closed.

#
Channel
Analytic
Level
Informational
Task
Smb2SessionClose
Opcode
Stop

Fields #

NameDescription
SessionGUID GUID
InvalidateSession Boolean
Reason UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 555,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13908
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.580Z",
    "version": 0
  },
  "event_data": {
    "InvalidateSession": false,
    "Reason": 0,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 600: SMB2 TreeConnect Allocated

#
Channel
Analytic
Level
Informational
Task
Smb2TreeConnectAllocate
Opcode
Start

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID
ShareGUID GUID
ShareNameLength UInt16
ShareName UnicodeString
ScopeNameLength UInt16
ScopeName UnicodeString
ShareProperties UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 600,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 3476
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 1,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.825Z",
    "version": 0
  },
  "event_data": {
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "ScopeName": "*",
    "ScopeNameLength": 1,
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "ShareGUID": "{269052C9-17A3-000C-AF53-9026A317DD01}",
    "ShareName": "IPC$",
    "ShareNameLength": 4,
    "ShareProperties": 0,
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 601: SMB2 TreeConnect Disconnected

#
Channel
Analytic
Level
Informational
Task
Smb2TreeConnectDisconnect

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 601,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.579Z",
    "version": 0
  },
  "event_data": {
    "ConnectionGUID": "{269052C9-17A3-000D-3DFA-9426A317DD01}",
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 602: SMB2 TreeConnect Terminated

#
Channel
Analytic
Level
Informational
Task
Smb2TreeConnectTerminate
Opcode
Stop

Fields #

NameDescription
TreeConnectGUID GUID
SessionGUID GUID

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 602,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 13096
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 2,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:20.579Z",
    "version": 0
  },
  "event_data": {
    "SessionGUID": "{269052C9-17A3-000C-14DF-9526A317DD01}",
    "TreeConnectGUID": "{269052C9-17A3-000C-15DF-9526A317DD01}"
  },
  "message": ""
}

Event ID 603: SMB2 TreeConnect Failed due to Cluster Endpoint Initializing

#
Channel
Analytic
Task
Smb2TreeConnectFailedDueToPending

Fields #

NameDescription
SessionGUID GUID
ConnectionGUID GUID
ShareNameLength UInt16
ShareName UnicodeString
ScopeNameLength UInt16
ScopeName UnicodeString
Status UInt32NTSTATUS reference

Event ID 604: A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best p...

#
Channel
Operational
Task
Smb2TreeConnectForceClientReconnect

Description

A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity.

Message #

A client connection to a continuously available share has been marked so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields #

NameDescription
SessionGUID GUID
TreeConnectGUID GUID
ShareNameLength UInt16
ShareName UnicodeString

Event ID 605: A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best poss...

#
Channel
Operational
Task
Smb2TreeConnectForceClientReconnect

Description

A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity.

Message #

A client request on a continuously available share has been failed so that the client will be forced to reconnect to the server node with best possible storage connectivity. 

Session ID: %1
TreeConnect ID: %2
Share: %4

Fields #

NameDescription
SessionGUID GUID
TreeConnectGUID GUID
ShareNameLength UInt16
ShareName UnicodeString

Event ID 650: SMB2 Open established

#
Channel
Analytic
Task
Smb2FileOpen
Opcode
Start

Fields #

NameDescription
OpenGUID GUID
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID
ShareGUID GUID
NameLength UInt16
Name UnicodeString
LeaseId GUID
DesiredAccess UInt32Process access rights reference
SharingMode UInt32
CreateOptions UInt32
FileAttributes UInt32
IsReplay Boolean
IsResume Boolean

Event ID 651: SMB2 Open Disconnected - Preserved

#
Channel
Analytic
Task
Smb2FileDisconnect

Fields #

NameDescription
OpenGUID GUID

Event ID 652: SMB2 Open Reconnected

#
Channel
Analytic
Task
Smb2FileReconnect

Fields #

NameDescription
OpenGUID GUID
TreeConnectGUID GUID
SessionGUID GUID
ConnectionGUID GUID

Event ID 653: SMB2 Open Suspended - Preserved

#
Channel
Analytic
Task
Smb2FileSuspend

Fields #

NameDescription
OpenGUID GUID

Event ID 654: SMB2 Open Closed

#
Channel
Analytic
Task
Smb2FileClose

Fields #

NameDescription
OpenGUID GUID

Event ID 655: SMB2 Open Timed Out

#
Channel
Analytic
Task
Smb2FileTimeout

Fields #

NameDescription
OpenGUID GUID

Event ID 656: SMB2 Open Terminated

#
Channel
Analytic
Task
Smb2FileTerminate

Fields #

NameDescription
OpenGUID GUID

Event ID 657: SMB2 Open Clustered Client Failover Closed

#
Channel
Analytic
Task
Smb2FileCCFClose

Fields #

NameDescription
OpenGUID GUID
AppInstanceGUID GUID

Event ID 658: File handle for file "ShareName\FileName" was invalidated by user UserName from computer ComputerName.

#
Channel
Operational
Task
Smb2FileCCFCloseAudit

Message #

File handle for file "%8\%2" was invalidated by user %4 from computer %6

Fields #

NameDescription
FileNameLength UInt16
FileName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ComputerNameLength UInt16
ComputerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString

Event ID 700: SMB2 Share Added

#
Channel
Analytic
Level
Informational
Task
Smb2ShareAdd

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
PathNameLength UInt16
PathName UnicodeString
CSCState UInt32
ClusterShareType UInt32
ShareProperties UInt32
CaTimeOut UInt32
ShareState UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 700,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 180
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:35.059Z",
    "version": 0
  },
  "event_data": {
    "CSCState": 0,
    "CaTimeOut": 0,
    "ClusterShareType": 0,
    "PathName": "C:\\Windows\\Temp",
    "PathNameLength": 15,
    "ServerName": "*",
    "ServerNameLength": 1,
    "ShareName": "dwh_tlb_s1",
    "ShareNameLength": 10,
    "ShareProperties": 0,
    "ShareState": 1
  },
  "message": ""
}

Event ID 701: SMB2 Share Modified

#
Channel
Analytic
Level
Informational
Task
Smb2ShareModify

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
PathNameLength UInt16
PathName UnicodeString
CSCState UInt32
ClusterShareType UInt32
ShareProperties UInt32
CaTimeOut UInt32
ShareState UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 701,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 4520
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:10.164Z",
    "version": 0
  },
  "event_data": {
    "CSCState": 0,
    "CaTimeOut": 0,
    "ClusterShareType": 0,
    "PathName": "C:\\Windows\\Temp",
    "PathNameLength": 15,
    "ServerName": "*",
    "ServerNameLength": 1,
    "ShareName": "dwh_smb2",
    "ShareNameLength": 8,
    "ShareProperties": 0,
    "ShareState": 1
  },
  "message": ""
}

Event ID 702: SMB2 Share Deleted

#
Channel
Analytic
Level
Informational
Task
Smb2ShareDelete

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Analytic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 702,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 180
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:22:52.285Z",
    "version": 0
  },
  "event_data": {
    "ServerName": "*",
    "ServerNameLength": 1,
    "ShareName": "dwh_tlb_s1",
    "ShareNameLength": 10
  },
  "message": ""
}

Event ID 1000: S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.

#
Channel
Operational
Task
SrvS4U2SelfFailure

Description

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims. This may be expected if the account is not a domain account.

Message #

S4U2Self authentication failure - The client could not be reauthenticated with S4U2Self to obtain claims.  This may be expected if the account is not a domain account.

Fields #

NameDescription
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString
Status UInt32NTSTATUS reference

Event ID 1001: A client attempted to access the server using SMB1 and was rejected because SMB1 file sharing support is disabled or has been uninstalled.

#
Channel
Operational
Level
Informational
Task
SrvDisabled

Description

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Message #

SRV Disabled - The SMB1 negotiate request fails due to SMB1 is disabled.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1001,
    "version": 1,
    "level": 4,
    "task": 1001,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-03-13T18:46:45.797325+00:00",
    "event_record_id": 30,
    "correlation": {},
    "execution": {
      "process_id": 11352,
      "thread_id": 7956
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

Event ID 1002: RKF failure - SRV2 failed to get acknowledgement from Resume Key filter for persistent handle request.

#
Channel
Operational
Task
Smb2RkfFailure

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Event ID 1003: The server received an unencrypted message from client when encryption was required.

#
Channel
Operational
Task
SrvUnencryptedAcccessFailure

Description

The server received an unencrypted message. Message was rejected.

Message #

The server received an unencrypted message. Message was rejected.

Client Name: %4

Guidance:

This event indicates that a client is sending unencrypted data even though the SMB share requires encryption.

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1004: The server rejected an incorrectly signed message.

#
Channel
Operational
Task
SrvSignatureValidationFailure

Description

The server received an incorrectly signed message. Message was rejected.

Message #

The server received an incorrectly signed message. Message was rejected.

Client Name: %2

Guidance:

This event indicates that a client is sending an incorrectly signed request.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1005: The server failed to validate negotiation from client TranslatedStatus.

#
Channel
Operational
Task
SrvNegotiateValidationFailure

Description

The server failed to validate negotiation from client TranslatedStatus. Connection was terminated.

Message #

The server failed to validate negotiation from client %2. Connection was terminated.

Fields #

NameDescription
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64

Event ID 1006: The share denied access to the client.

#
Channel
Security
Level
Error
Task
SrvShareAccessCheckFailure

Message #

The share denied access to the client.

Client Name: %10
Client Address: %6
User Name: %8
Session ID: %17
Share Name: %2
Share Path: %4
Status: %16 (%15)
Mapped Access: %11
Granted Access: %12
Security Descriptor: %14

Guidance:

You should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue.

Applications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required.

If access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions.

This error does not indicate a problem with authentication, only authorization.

Fields #

NameDescription
EventData.ShareNameLength UInt16
EventData.ShareName UnicodeString
EventData.SharePathLength UInt16
EventData.SharePath UnicodeString
EventData.ClientAddressLength UInt32
EventData.ClientAddress Binary
EventData.UserNameLength UInt16
EventData.UserName UnicodeString
EventData.ClientNameLength UInt16
EventData.ClientName UnicodeString
EventData.MappedAccess HexInt32
EventData.GrantedAccess HexInt32Process access rights reference
EventData.ShareSecurityDescriptorLength UInt32
EventData.ShareSecurityDescriptor Binary
EventData.Status HexInt32NTSTATUS reference
EventData.TranslatedStatus HexInt32
EventData.SessionID HexInt64
ShareNameLength UInt16
ShareName UnicodeString
SharePathLength UInt16
SharePath UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
MappedAccess HexInt32
GrantedAccess HexInt32Process access rights reference
ShareSecurityDescriptorLength UInt32
ShareSecurityDescriptor Binary
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
SessionID HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "{D48CE617-33A2-4BC3-A5C7-11AA4F29619E}",
    "event_source_name": "",
    "event_id": 1006,
    "version": 0,
    "level": 2,
    "task": 1006,
    "opcode": 0,
    "keywords": 580964351930793992,
    "time_created": "2026-05-30T02:01:40.0630814+00:00",
    "event_record_id": 62,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 2020
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ShareNameLength": "14",
      "ShareName": "\\\\*\\EvtLabDeny",
      "SharePathLength": "17",
      "SharePath": "\\??\\C:\\EvtLabDeny",
      "ClientAddressLength": "28",
      "ClientAddress": "1700EDB0000000000000000000000000000000000000000100000000",
      "UserNameLength": "17",
      "UserName": "ludus\\domainadmin",
      "ClientNameLength": "7",
      "ClientName": "\\\\[::1]",
      "MappedAccess": "0x80",
      "GrantedAccess": "0x0",
      "ShareSecurityDescriptorLength": "96",
      "ShareSecurityDescriptor": "0100048048000000540000000000000014000000020034000200000001001400FF011F0001010000000000010000000000001800FF011F0001020000000000052000000020020000010100000000000512000000010100000000000512000000",
      "Status": "0xc0000022",
      "TranslatedStatus": "0xc0000022",
      "SessionID": "0x50032c000029"
    }
  },
  "message": "The share denied access to the client.\r\n\r\nClient Name: \\\\[::1]\r\nClient Address: [::1]:60848\r\nUser Name: ludus\\domainadmin\r\nSession ID: 0x50032C000029\r\nShare Name: \\\\*\\EvtLabDeny\r\nShare Path: \\??\\C:\\EvtLabDeny\r\nStatus: {Access Denied}\r\nA process has requested access to an object, but has not been granted those access rights. (0xC0000022)\r\nMapped Access: 0x80\r\nGranted Access: 0x0\r\nSecurity Descriptor: 0x0100048048000000540000000000000014000000020034000200000001001400FF011F0001010000000000010000000000001800FF011F0001020000000000052000000020020000010100000000000512000000010100000000000512000000\r\n\r\nGuidance:\r\n\r\nYou should expect access denied errors when a principal accesses a share without the necessary permissions. Usually, this indicates that the principal does not have direct security permissions or lacks membership in a group that has direct access permissions. To determine and correct the permissions on the specified share, an administrator can use the Security tab in File Explorer Properties dialog, the SMBSHARE Windows PowerShell module, or the NET SHARE command. You can also use the Effective Access tab in File Explorer to help diagnose the issue.\r\n\r\nApplications may generate access denied errors if they attempt to open files in a writable mode first, and then reopen the files in a read-only mode. In this case, no user action is required.\r\n\r\nIf access to the share is denied and this event is not logged, you can examine the file and folder NTFS/REFS permissions.\r\n\r\nThis error does not indicate a problem with authentication, only authorization."
}

Event ID 1007: The share denied anonymous access to the client.

#
Channel
Security
Level
Error
Task
SrvShareAnonymousAccessDeniedFailure

Message #

The share denied anonymous access to the client.

Client Name: %8
Client Address: %6
Share Name: %2
Share Path: %4

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields #

NameDescription
EventData.ShareNameLength UInt16
EventData.ShareName UnicodeString
EventData.SharePathLength UInt16
EventData.SharePath UnicodeString
EventData.ClientAddressLength UInt32
EventData.ClientAddress Binary
EventData.ClientNameLength UInt16
EventData.ClientName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
SharePathLength UInt16
SharePath UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "d48ce617-33a2-4bc3-a5c7-11aa4f29619e",
    "event_source_name": "",
    "event_id": 1007,
    "version": 0,
    "level": 2,
    "task": 1007,
    "opcode": 0,
    "keywords": 580964351930793992,
    "time_created": "2026-07-19T17:04:48.4560592+00:00",
    "event_record_id": 63,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 4,
      "thread_id": 22256
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ShareNameLength": "10",
      "ShareName": "\\\\*\\SYSVOL",
      "SharePathLength": "28",
      "SharePath": "\\??\\C:\\Windows\\SYSVOL\\sysvol",
      "ClientAddressLength": "16",
      "ClientAddress": "0200D3B00A020A150000000000000000",
      "ClientNameLength": "12",
      "ClientName": "\\\\10.2.10.21"
    }
  },
  "message": "The share denied anonymous access to the client.\r\n\r\nClient Name: \\\\10.2.10.21\r\nClient Address: 10.2.10.21:54192\r\nShare Name: \\\\*\\SYSVOL\r\nShare Path: \\??\\C:\\Windows\\SYSVOL\\sysvol\r\n\r\nGuidance:\r\n\r\nYou should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, anonymous access to shares is denied.\r\n\r\nThis error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients."
}

Event ID 1009: The server denied anonymous access to the client.

#
Channel
Security
Task
SrvSessionAnonymousAccessDenied

Message #

The server denied anonymous access to the client.

Client Name: %4
 Client Address: %2
Session ID: %5

Guidance:

You should expect this error when a client attempts to connect to shares and does not provide any credentials. This indicates that the client is not providing a user name (and domain credentials, if necessary). By default, Windows Server denies anonymous access to shares.

This error does not always indicate a problem with authorization, but mainly authentication. It is more common with non-Windows clients.

Fields #

NameDescription
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString
SessionId HexInt64
SessionGUID GUID
ConnectionGUID GUID

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1009,
    "level": "Error",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-18T01:38:02.9935019+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Security"
  },
  "event_data": {
    "SessionID": "0x4802a0000039",
    "ClientName": "\\\\10.2.10.21",
    "ClientAddressLength": "16",
    "ClientNameLength": "12",
    "ClientAddress": "0200D3CC0A020A150000000000000000",
    "ConnectionGUID": "{d604743a-bfc1-0009-d409-13d6c1bfdc01}",
    "SessionGUID": "{d604743a-bfc1-0003-9b05-15d6c1bfdc01}"
  }
}

Example keys not documented in the fields table: SessionID

Event ID 1010: Endpoint added.

#
Channel
Operational
Level
Informational
Task
SrvEndpointAdded

Message #

Endpoint added.

Name: %2
Domain Name: %4
Transport Name: %6
Transport Flags: %7

Guidance:

You should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required.

Fields #

NameDescription
EventData.NameLength
EventData.Name
EventData.DomainNameLength
EventData.DomainName
EventData.TransportNameLength
EventData.TransportName
EventData.TransportFlags
NameLength
Name
DomainNameLength
DomainName
TransportNameLength
TransportName
TransportFlags

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "{D48CE617-33A2-4BC3-A5C7-11AA4F29619E}",
    "event_source_name": "",
    "event_id": 1010,
    "version": 0,
    "level": 4,
    "task": 1010,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-05-29T16:33:06.3560975+00:00",
    "event_record_id": 43,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 488
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "telemetry-DC-a.cell-a.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NameLength": "16",
      "Name": "TELEMETRY-DC-A  ",
      "DomainNameLength": "6",
      "DomainName": "cell-a",
      "TransportNameLength": "58",
      "TransportName": "\\Device\\NetBT_Tcpip_{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}",
      "TransportFlags": "0x1"
    }
  },
  "message": "Endpoint added.\r\n\r\nName: TELEMETRY-DC-A  \r\nDomain Name: cell-a\r\nTransport Name: \\Device\\NetBT_Tcpip_{2A7BD48E-DDC6-4641-9F41-682F29F1D76C}\r\nTransport Flags: 0x1\r\n\r\nGuidance:\r\n\r\nYou should expect this event when the server starts listening on an interface, such as during system restart or when enabling a network adaptor. No user action is required."
}

Event ID 1011: Endpoint removed.

#
Channel
Operational
Level
Informational
Task
SrvEndpointRemoved

Message #

Endpoint removed.

Name: %2
Domain Name: %4
Transport Name: %6

Guidance:

You should expect this event when the server stops listening on an interface, such as during shutdown or when disabling a network adaptor. No user action is required.

Fields #

NameDescription
NameLength
Name
DomainNameLength
DomainName
TransportNameLength
TransportName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1011,
    "version": 0,
    "level": 4,
    "task": 1011,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2022-04-04T12:00:04.359257+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 196
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-TKC15D7KHUR",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NameLength": 0,
      "Name": null,
      "DomainNameLength": 0,
      "DomainName": null,
      "TransportNameLength": 58,
      "TransportName": "\\Device\\NetBT_Tcpip_{64AAD862-869C-436D-A905-CCB55AA6A79F}"
    }
  },
  "message": ""
}

References #

Event ID 1012: The network name information changed.

#
Channel
Operational
Level
Informational
Task
SrvNetNameInfoChange

Message #

The network name information changed.

Change Type: %1
Net Name: %3
IP Address: %9
Flags: %4
Interface Index: %5
Capability: %6
Link Speed: %7

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations, at system startup, or during network configuration. No user action is required.

Fields #

NameDescription
ChangeType UInt32
NetNameLength UInt16
NetName UnicodeString
Flags HexInt32
InterfaceIndex UInt32
Capability HexInt32
LinkSpeed UInt64
ClientAddressLength UInt16
ClientAddress Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1012,
    "version": 0,
    "level": 4,
    "task": 1012,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-03-13T17:13:21.447992+00:00",
    "event_record_id": 89,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 5676
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ChangeType": 0,
      "NetNameLength": 1,
      "NetName": "*",
      "Flags": "0x1",
      "InterfaceIndex": 5,
      "Capability": "0x1",
      "LinkSpeed": 10000000000,
      "ClientAddressLength": 128,
      "ClientAddress": "020000000A020A15000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"
    }
  },
  "message": ""
}

Event ID 1013: Endpoint coming online.

#
Channel
Operational
Task
SrvEndpointOnline

Message #

Endpoint coming online.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1014: Endpoint going offline.

#
Channel
Operational
Task
SrvEndpointOffline

Message #

Endpoint going offline.

Endpoint Name: %2
Transport Name: %4

Guidance:

You should expect this event on a Windows Failover Cluster node during failover operations. No user action is required.

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1015: Decrypt call failed.

#
Channel
Security
Level
Error
Task
SrvDecryptionFailure

Message #

Decrypt call failed.

Client Name: %2
Client Address: %4
Session ID: %7
Status: %6 (%5)

Guidance:

This event commonly occurs because a previous SMB session no longer exists. It may also be caused by packets that are altered on the network between the computers due to either errors or a "man-in-the-middle" attack.

Fields #

NameDescription
ClientNameLength UInt16
ClientName AnsiString
ClientAddressLength UInt16
ClientAddress Binary
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
SessionID HexInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1015,
    "level": 2,
    "task": 1015,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8803405+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B00000000000000000000FFFF0A020A0B0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000",
    "ClientName": "\\",
    "ClientAddressLength": "128",
    "ClientNameLength": "24",
    "TranslatedStatus": "0xc0000203",
    "Status": "0xc0000203",
    "SessionID": "0x0"
  }
}

Event ID 1016: Reopen failed.

#
Channel
Operational
Task
SrvReopenFailure

Message #

Reopen failed.

Client Name: %7
Client Address: %9
User Name: %13
Session ID: %14
Share Name: %11
File Name: %16
Resume Key: %20
Status: %2 (%1)
RKF Status: %4 (%3)
Durable: %17
Resilient: %18
Persistent: %19
Reason: %21

Guidance:

The client attempted to reopen a continuously available handle, but the attempt failed. This typically indicates a problem with the network or underlying file being re-opened.

Fields #

NameDescription
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
RKFStatus HexInt32
TranslatedRKFStatus HexInt32
ConnectionGUID GUID
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
UserNameLength UInt16
UserName UnicodeString
SessionId HexInt64
FileNameLength UInt16
FileName UnicodeString
DurableHandle Boolean
ResilientHandle Boolean
PersistentHandle Boolean
ResumeKey GUID
Reason UInt32

Event ID 1017: Handle scavenged.

#
Channel
Operational
Level
Informational
Task
SrvHandleScavenge

Message #

Handle scavenged.

Share Name: %7
File Name: %9
Resume Key: %5
Persistent File ID: %3
Volatile File ID: %4
Durable: %1
Resilient or Persistent: %2

Guidance:

The server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted.

Fields #

NameDescription
EventData.DurableHandle Boolean
EventData.ResilientHandle Boolean
EventData.PersistentFID HexInt64
EventData.VolatileFID HexInt64
EventData.ResumeKey GUID
EventData.ShareNameLength UInt16
EventData.ShareName UnicodeString
EventData.FileNameLength UInt16
EventData.FileName UnicodeString
DurableHandle Boolean
ResilientHandle Boolean
PersistentFID HexInt64
VolatileFID HexInt64
ResumeKey GUID
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "d48ce617-33a2-4bc3-a5c7-11aa4f29619e",
    "event_source_name": "",
    "event_id": 1017,
    "version": 0,
    "level": 4,
    "task": 1017,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2026-06-02T17:36:56.2098757+00:00",
    "event_record_id": 73,
    "correlation": {
      "ActivityID": "",
      "RelatedActivityID": ""
    },
    "execution": {
      "process_id": 4,
      "thread_id": 17400
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "JD-DC01-2022.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "DurableHandle": "true",
      "ResilientHandle": "false",
      "PersistentFID": "0x1800003963",
      "VolatileFID": "0x18ffffffff",
      "ResumeKey": "{b480d463-5e4f-11f1-a6bf-00155d283457}",
      "ShareNameLength": "6",
      "ShareName": "SYSVOL",
      "FileNameLength": "81",
      "FileName": "ludus.domain\\Policies\\{21CCD04C-3F38-45DC-A824-24F084271951}\\Machine\\registry.pol"
    }
  },
  "message": "Handle scavenged.\r\n\r\nShare Name: SYSVOL\r\nFile Name: ludus.domain\\Policies\\{21CCD04C-3F38-45DC-A824-24F084271951}\\Machine\\registry.pol\r\nResume Key: {b480d463-5e4f-11f1-a6bf-00155d283457}\r\nPersistent File ID: 0x1800003963\r\nVolatile File ID: 0x18FFFFFFFF\r\nDurable: true\r\nResilient or Persistent: false\r\n\r\nGuidance:\r\n\r\nThe server closed a handle that was previously reserved for a client after 60 seconds. You should expect this event on a computer that is continuously available where a client did not gracefully close its session. For instance, this may occur when the client unexpectedly restarted."
}

Event ID 1018: Backchannel invalidation of session completed.

#
Channel
Operational
Task
SrvSessionInvalidate

Message #

Backchannel invalidation of session completed.

Session ID: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields #

NameDescription
SessionId HexInt64
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
TaskStatus HexInt32
TranslatedTaskStatus HexInt32

Event ID 1019: Backchannel invalidation of file completed.

#
Channel
Operational
Task
SrvFileInvalidate

Message #

Backchannel invalidation of file completed.

Resume Key: %1
Status: %3 (%2)
Task Status: %5 (%4)

Guidance:

You should expect this event on a computer that is continuously available. No user action is required

Fields #

NameDescription
ResumeKey GUID
Status HexInt32NTSTATUS reference
TranslatedStatus HexInt32
TaskStatus HexInt32
TranslatedTaskStatus HexInt32

Event ID 1020: File system operation has taken longer than expected.

#
Channel
Operational
Task
SrvSlowFsOperation

Message #

File system operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields #

NameDescription
Command UInt32
SessionGuid GUID
SessionId HexInt64
ConnectionGuid GUID
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
DurationInMilliseconds UInt64
ThresholdInMilliseconds UInt64
CtlCode UInt32
SubCode UInt32
TunneledControl UInt32

Event ID 1021: LmCompatibilityLevel value is different from the default.

#
Channel
Security
Level
Informational
Task
SrvLmCompatibilityLevelNonDefault

Message #

LmCompatibilityLevel value is different from the default.

Configured LM Compatibility Level: %1
Default LM Compatibility Level: %2

Guidance:

LAN Manager (LM) authentication is the protocol used to authenticate Windows clients for network operations. This includes joining a domain, accessing network resources, and authenticating users or computers. This determines which challenge/response authentication protocol is negotiated between the client and the server computers. Specifically, the LM authentication level determines which authentication protocols the client will try to negotiate or the server will accept. The value set for LmCompatibilityLevel determines which challenge/response authentication protocol is used for network logons. This value affects the level of authentication protocol that clients use, the level of session security negotiated, and the level of authentication accepted by servers.

Value (Setting) - Description

0 (Send LM & NTLM responses) - Clients use LM and NTLM authentication and never use NTLMv2 session security. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

1 (Send LM & NTLM - use NTLMv2 session security if negotiated) - Clients use LM and NTLM authentication, and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

2 (Send NTLM response only) - Clients use NTLM authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

3 (Send NTLM v2 response only) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers accept LM, NTLM, and NTLMv2 authentication.

4 (Send NTLMv2 response only/refuse LM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and accept only NTLM and NTLMv2 authentication.

5 (Send NTLM v2 response only/refuse LM & NTLM) - Clients use NTLMv2 authentication only and use NTLMv2 session security if the server supports it. Domain controllers refuse LM and NTLM and accept only NTLMv2 authentication.

Incompatibly configured  LmCompatibility levels between a client and server (such as 0 on a client and 5 on a server) prevent access to the server. Non-Microsoft clients and servers also provide these configuration settings.

Fields #

NameDescription
ConfiguredLmCompatibilityLevel UInt32
DefaultLmCompatibilityLevel UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1021,
    "version": 0,
    "level": 4,
    "task": 1021,
    "opcode": 0,
    "keywords": 576460752303423496,
    "time_created": "2026-03-14T00:02:46.284357+00:00",
    "event_record_id": 6,
    "correlation": {},
    "execution": {
      "process_id": 3608,
      "thread_id": 3620
    },
    "channel": "Microsoft-Windows-SMBServer/Security",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "ConfiguredLmCompatibilityLevel": 5,
      "DefaultLmCompatibilityLevel": 3
    }
  },
  "message": ""
}

Event ID 1022: File and printer sharing firewall rule enabled.

#
Channel
Connectivity
Level
Informational
Task
SrvFileSharingFirewallRuleEnabled

Message #

File and printer sharing firewall rule enabled.

Guidance:

You should expect this event when Windows Firewall is configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that has custom shares configured.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1022,
    "version": 0,
    "level": 4,
    "task": 1022,
    "opcode": 0,
    "keywords": 288230376151711752,
    "time_created": "2026-03-14T00:03:01.608520+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 3608,
      "thread_id": 3640
    },
    "channel": "Microsoft-Windows-SMBServer/Connectivity",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

Event ID 1023: One or more shares present on this server have access based enumeration enabled.

#
Channel
Operational
Task
SrvABESharesPresent

Message #

One or more shares present on this server have access based enumeration enabled.

Guidance:

You should expect this event when enabling access-based enumeration on one or more shares by using either Server Manager or the Set-SmbShare Windows PowerShell cmdlet. Access-based enumeration can raise CPU utilization when clients connect to shares with folders containing many peer-level resources to which a user does not have access. You can control the CPU utilization by configuring the ABELevel value in the Windows registry:

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\LanmanServer\Parameters\ABELevel [DWORD]

You can set the value for ABELevel to greater depths to minimize CPU overhead, but doing so diminishes the effectiveness of access-based enumeration:

Value = 0: access-based enumeration is enabled for all levels

Value = 1: access-based enumeration is enabled for a depth of 1 (example: \server\share)

Value = 2: access-based enumeration is enabled for a depth of 2 (example: \server\share\folder)

You can continue setting values for multiple depth levels.

Event ID 1024: SMB2 and SMB3 have been disabled on this server.

#
Channel
Operational
Task
SrvSmb2Disabled

Description

SMB2 and SMB3 have been disabled on this server. This results in reduced functionality and performance.

Message #

SMB2 and SMB3 have been disabled on this server.  This results in reduced functionality and performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: Smb2
Default Value: 1 (or not present)
Current Value: 0

Guidance:

You should expect this event when disabling SMB2/SMB3. Microsoft does not recommend disabling SMB2/SMB3. When SMB3 is disabled, you cannot use features such as SMB Transparent Failover, SMB Scale Out, SMB Multichannel, SMB Direct (RDMA), SMB Encryption, VSS for SMB file shares, and SMB Directory Leasing. In most scenarios, SMB provides a troubleshooting workaround as an alternative to disabling SMB2/SMB3. Use the Set-SmbServerConfiguration Windows PowerShell cmdlet to enable SMB2/SMB3.

Event ID 1025: One or more named pipes or shares have been marked for access by anonymous users.

#
Channel
Operational
Level
Warning
Task
SrvNullSessionsAllowed

Description

One or more named pipes or shares have been marked for access by anonymous users. This increases the security risk of the computer by allowing unauthenticated users to connect to this server.

Message #

One or more named pipes or shares have been marked for access by anonymous users.  This increases the security risk of the computer by allowing unauthenticated users to connect to this server.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Values: NullSessionPipes, NullSessionShares
Default Value: Empty (or not present)
Current Value: Non-empty

Guidance:

You should expect this event when modifying the default values of NullSessionShares and NullSessionPipes. On a typical file server, these settings do not exist or do not contain values, which is the most secure configuration. By default, domain controllers populate the NullSessionShares entry with netlogon, samr, and lsarpc to allow legacy access methods.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1025,
    "version": 0,
    "level": 3,
    "task": 1025,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2023-11-06T06:25:44.207725+00:00",
    "event_record_id": 96,
    "correlation": {},
    "execution": {
      "process_id": 3912,
      "thread_id": 3512
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

References #

Event ID 1026: File leasing has been disabled for the SMB2 and SMB3 protocols.

#
Channel
Operational
Task
SrvLeasingDisabled

Description

File leasing has been disabled for the SMB2 and SMB3 protocols. This reduces functionality and can decrease performance.

Message #

File leasing has been disabled for the SMB2 and SMB3 protocols.  This reduces functionality and can decrease performance.

Registry Key: HKLM\System\CurrentControlSet\Services\LanmanServer\Parameters
Registry Value: DisableLeasing
Default Value: 0 (or not present)
Current Value: non-zero

Guidance:

You should expect this event when disabling SMB 3 Leasing. Microsoft does not recommend disabling SMB Leasing. Once disabled, traffic from client to server may increase since metadata and data may no longer be retrieved from a local cache.

Event ID 1027: The file and printer sharing firewall ports are currently closed.

#
Channel
Operational
Level
Informational
Task
SrvFirewallPortsClosed

Description

The file and printer sharing firewall ports are currently closed. This is the default configuration for a system that is not sharing content or is on a Public network.

Message #

The file and printer sharing firewall ports are currently closed.  This is the default configuration for a system that is not sharing content or is on a Public network.

Guidance:

You should expect this event when Windows Firewall is not configured to enable the File and Printer Sharing rule, which allows inbound SMB traffic. This event occurs on a computer that does not have custom shares configured. Clients cannot access SMB shares on this computer until SMB traffic is allowed through the firewall.

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1027,
    "version": 0,
    "level": 4,
    "task": 1027,
    "opcode": 0,
    "keywords": 2305843009213693960,
    "time_created": "2023-11-05T22:32:38.630794+00:00",
    "event_record_id": 124,
    "correlation": {},
    "execution": {
      "process_id": 3368,
      "thread_id": 3592
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {}
  },
  "message": ""
}

References #

Event ID 1028: The maximum cluster-supported SMB dialect has changed.

#
Channel
Operational
Task
Smb2MaxClusterDialectUpdated

Message #

The maximum cluster-supported SMB dialect has changed.

NewMaxDialect: %1
OldMaxDialect: %2

Guidance:

You should expect this event during a Windows Failover Cluster upgrade. No user action is required.

Fields #

NameDescription
NewDialect UInt16
OldDialect UInt16

Event ID 1029: The Cipher Suite Order group policy setting is invalid.

#
Channel
Operational
Task
Smb2CipherSuiteOrder

Message #

The Cipher Suite Order group policy setting is invalid.

Guidance:

This event indicates that an administrator has configured an invalid value for the "Computer Configuration\Administrative Templates\Network\Lanman Server\Cipher Suite Order" group policy setting. The server will use the default cipher suite order "%1" until this error is resolved.

Fields #

NameDescription
CipherSuiteOrder UnicodeString

Event ID 1030: An MDL read or write completion request failed.

#
Channel
Operational
Task
Smb2MdlIoCompletionFailure

Message #

An MDL read or write completion request failed.

Server Name: %2
Share Name: %4
File Name: %6
IsRead: %7
Status: %8

Guidance:

The SMB server sends MDL completion requests to a file system upon completion of a buffered I/O to release system resources. The file system and its filter drivers must not fail MDL completion requests. Failures may result in memory leaks and degraded system performance and stability. Non-Microsoft file system filter drivers are the most common cause of failed MDL completion requests.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
IsRead Boolean
Status HexInt32NTSTATUS reference

Event ID 1031: The server detected a problem and has captured a live kernel dump to collect debug information.

#
Channel
Operational
Task
Srv2LiveDumpSucceeded

Message #

The server detected a problem and has captured a live kernel dump to collect debug information.

Reason: %1
Dump Location: %SystemRoot%\LiveKernelReports

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields #

NameDescription
Reason UInt32

Event ID 1032: The server detected a problem but was unable to capture a live kernel dump to collect debug information.

#
Channel
Operational
Task
Srv2LiveDumpThrotteled

Message #

The server detected a problem but was unable to capture a live kernel dump to collect debug information.

Reason: %1

Guidance:

The server supports the Live Dump feature, where the detection of a problem results in a kernel memory dump, but no bugcheck and reboot. This allows Microsoft Support to examine memory dumps without requiring a reboot or manual intervention. The reason code indicates the type of problem that was detected. In this case, the server's request to create a live kernel dump was rejected. This is usually due to the live kernel dump throttle, which prevents frequent dumps from consuming too much disk space. Either wait for the throttle limit to expire (by default, 7 days), or contact Microsoft Support for steps to override the throttle. This event is written to the log no more than once per day. The problem that caused the server to the request a live kernel dump may be occuring more frequently.

Stalled I/O

An I/O is taking an unreasonably long time to complete. Malfunctioning third-party file system minifilter drivers are a common source of this problem. Other causes include failed disks or a client-driven I/O workload that greatly exceeds the server's capacity.

Fields #

NameDescription
Reason UInt32

Event ID 1033: Sent RDMA .

#
Channel
Analytic
Level
Informational
Task
Srv2RDMASendEndpointNotification

Description

Sent RDMA event to LanmanServer for interface .

Message #

Sent RDMA %1 event to LanmanServer for interface %3.

Fields #

NameDescription
NotificationType UInt32
InterfaceNameLength UInt16
InterfaceName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1033,
    "level": 4,
    "task": 3012,
    "opcode": 0,
    "time_created": "2026-04-17T21:57:31.5541370+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1033: Sent RDMA EventData.NotificationType event to LanmanServer for interface EventData.InterfaceName.

#
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotification

Message #

Sent RDMA %1 event to LanmanServer for interface %3.

Fields #

NameDescription
NotificationType
InterfaceNameLength
InterfaceName

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1033,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-10-26T04:17:52.198363+00:00",
    "event_record_id": 18,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 436
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NotificationType": 0,
      "InterfaceNameLength": 34,
      "InterfaceName": "\\Device\\RdmaSmbIpv4_169.254.253.61"
    }
  },
  "message": ""
}

References #

Event ID 1034: Send RDMA Endpoint notification failure - .

#
Channel
Analytic
Level
Error
Task
Srv2RDMASendEndpointNotificationFailure

Message #

Send RDMA Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1034,
    "level": 4,
    "task": 3013,
    "opcode": 0,
    "time_created": "2026-04-17T21:57:31.5668163+00:00",
    "computer": "WIN11-25H2-X64",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1034: Send RDMA Endpoint notification failure - EventData.FailureType.

#
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotificationFailure

Message #

Send RDMA Endpoint notification failure - %1

Fields #

NameDescription
FailureType
InterfaceIndex
Error
DeviceNameLength
DeviceName
ExtraInformation

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1034,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-10-26T04:17:52.198365+00:00",
    "event_record_id": 19,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 436
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WIN-OQ6R0RVA4NF",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "FailureType": 6,
      "InterfaceIndex": 0,
      "Error": "0xc0000034",
      "DeviceNameLength": 34,
      "DeviceName": "\\Device\\RdmaSmbIpv4_169.254.253.61",
      "ExtraInformation": 0
    }
  },
  "message": ""
}

References #

Event ID 1035: RDMA Endpoint .

#
Channel
Analytic
Task
Srv2RDMAEndpointChange

Description

RDMA Endpoint for interface was .

Message #

RDMA Endpoint %4 for interface %2 was %1.

Fields #

NameDescription
EndpointState UInt32
InterfaceIndex UInt32
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1035: RDMA Endpoint TransportName for interface InterfaceIndex was EndpointState.

#
Channel
Operational
Task
Srv2RDMAEndpointChange

Message #

RDMA Endpoint %4 for interface %2 was %1.

Fields #

NameDescription
EndpointState UInt32
InterfaceIndex UInt32
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1036: RDMA Endpoint allocation failure - Endpoint allocation failed for interface .

#
Channel
Analytic
Task
Srv2RDMAEndpointAllocationFailure

Message #

RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2

Fields #

NameDescription
InterfaceIndex UInt32
Error HexInt32

Event ID 1036: RDMA Endpoint allocation failure - Endpoint allocation failed for interface InterfaceIndex.

#
Channel
Operational
Task
Srv2RDMAEndpointAllocationFailure

Description

RDMA Endpoint allocation failure - Endpoint allocation failed for interface InterfaceIndex. Error.

Message #

RDMA Endpoint allocation failure - Endpoint allocation failed for interface %1. %2

Fields #

NameDescription
InterfaceIndex UInt32
Error HexInt32

Event ID 1037: RDMA listener creation failure - .

#
Channel
Analytic
Task
Srv2RDMACreateListenerFailure

Message #

RDMA listener creation failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32

Event ID 1037: RDMA listener creation failure - FailureType.

#
Channel
Operational
Task
Srv2RDMACreateListenerFailure

Message #

RDMA listener creation failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32

Event ID 1038: RDMA Send endpoint notification RPC failure for device .

#
Channel
Analytic
Task
Srv2RDMASendEndpointNotificationRPCFailure

Description

RDMA Send endpoint notification RPC failure for device -.

Message #

RDMA Send endpoint notification RPC failure for device %3 - %1

Fields #

NameDescription
FailureType UInt32
DeviceNameLength UInt16
DeviceName UnicodeString
Error HexInt32

Event ID 1038: RDMA Send endpoint notification RPC failure for device EventData.DeviceName - EventData.FailureType.

#
Channel
Operational
Level
Informational
Task
Srv2RDMASendEndpointNotificationRPCFailure

Message #

RDMA Send endpoint notification RPC failure for device %3 - %1

Fields #

NameDescription
FailureType
DeviceNameLength
DeviceName
Error

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1038,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-06T06:25:49.867686+00:00",
    "event_record_id": 98,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 428
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "FailureType": 3,
      "DeviceNameLength": 58,
      "DeviceName": "\\Device\\NetBT_Tcpip_{8E4162AD-6500-4899-BA95-24051405E207}",
      "Error": "0x102"
    }
  },
  "message": ""
}

References #

Event ID 1039: Received Nsi notification type .

#
Channel
Analytic
Task
Srv2RDMANsiNotificationReceived

Description

Received Nsi notification type for interface with NdkOperationalState.

Message #

Received Nsi notification type %1 for interface %2 with NdkOperationalState %3

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32
NdkOperationalState UInt16

Event ID 1039: Received Nsi notification type NotificationType for interface InterfaceIndex with NdkOperationalState NdkOperationalState.

#
Channel
Operational
Task
Srv2RDMANsiNotificationReceived

Message #

Received Nsi notification type %1 for interface %2 with NdkOperationalState %3

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32
NdkOperationalState UInt16

Event ID 1040: Received Mib notification type .

#
Channel
Analytic
Level
Informational
Task
Srv2RDMAMibNotificationReceived

Description

Received Mib notification type for interface.

Message #

Received Mib notification type %1 for interface %2

Fields #

NameDescription
NotificationType UInt32
InterfaceIndex UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1040,
    "level": 4,
    "task": 3019,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:33.7279216+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1040: Received Mib notification type EventData.NotificationType for interface EventData.InterfaceIndex.

#
Channel
Operational
Level
Informational
Task
Srv2RDMAMibNotificationReceived

Message #

Received Mib notification type %1 for interface %2

Fields #

NameDescription
NotificationType
InterfaceIndex

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1040,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-05T22:32:37.991590+00:00",
    "event_record_id": 123,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 136
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "user_data": {
    "EventData": {
      "NotificationType": 3,
      "InterfaceIndex": 0
    }
  },
  "message": ""
}

References #

Event ID 1041: Error reading FSCTL properties information from the registry.

#
Channel
Operational
Task
SrvAdminFsctlPropertiesListReadingFailure

Description

Error reading FSCTL properties information from the registry. Registry value entry RegistryValueName will be ignored. Error: FailureType.

Message #

Error reading FSCTL properties information from the registry. Registry value entry %3 will be ignored. Error: %1

Fields #

NameDescription
FailureType UInt32
RegistryValueNameLength UInt32
RegistryValueName UnicodeString

Event ID 1042: The certificate for the server is about to expire.

#
Channel
Operational
Task
ServerCertMappingExpiring

Message #

The certificate for the server is about to expire. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate is about to expire. 

Renew or issue new certificates to avoid service interruption.

Fields #

NameDescription
CertSubjectNameLength UInt16
CertSubjectName UnicodeString
CertThumbprintLength UInt16
CertThumbprint UnicodeString
Expiring FILETIME

Event ID 1043: RDMA connection disconnected.

#
Channel
Operational
Task
SrvNetRdmaConnectionClosed

Message #

RDMA connection disconnected.

Transport name: %3
Milliseconds spent closing the connection: %1

Guidance:

Closing an RDMA connection should not take longer than 2 minutes. An RDMA IO that takes an abnormally long time to complete indicates a problem with the RDMA network adapters on this computer or its remote host. Contact your RDMA vendor for an updated driver and further troubleshooting.

Fields #

NameDescription
CloseOperationDurationInMillieconds UInt64
TransportNameLength UInt32
TransportName UnicodeString
EndpointShutdown UInt8
EndpointRemoved UInt8

Event ID 1044: Quic connection shutdown.

#
Channel
Operational
Task
SrvNetQuicShutdownFailure

Message #

Quic connection shutdown.

Error: %1
Reason: %2
Endpoint Name: %4
Transport Name: %6

Guidance:

This event indicates that the winquic connection is shutting down by the server. This event commonly occurs because the server certificate mapping is not created. It may also be caused by the server failed to configure the winquic connections.

Fields #

NameDescription
ErrorCode UInt16
Reason UInt16
EndpointNameLength UInt16
EndpointName UnicodeString
TransportNameLength UInt16
TransportName UnicodeString

Event ID 1045: The server failed to update server certificate mapping

#
Channel
Analytic, Operational
Task
ServerCertMappingUpdateFailure

Message #

The server failed to update server certificate mapping.____Name: %2__Subject: %4__Thumbprint: %6____The certificate can't be used for the server due to error %7____The server certificate mapping %9 removed.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
SubjectLength UInt16
Subject UnicodeString
ThumbPrintLength UInt16
ThumbPrint UnicodeString
Status HexInt32NTSTATUS reference
RemovedLength UInt16
Removed UnicodeString

Event ID 1046: The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server...

#
Channel
Operational
Task
SrvNoNegotiatedCipher

Description

The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access.

Message #

The server received a request and the server requires encryption, but the server and client did not negotiate an encryption cipher, nor does server allow unencrypted access.

Request: %10
Client Name: %4
Client Address: %8
User Name: %6
Session ID: %9
Share Name: %2

Guidance:

This event indicates that client is trying to access a server that requires encryption, but no cipher was negotiated, and server does not allow unencrypted access. Check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\RejectUnencryptedAccess to see if the value has been changed.

Fields #

NameDescription
ShareNameLength UInt16
ShareName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ClientAddressLength UInt32
ClientAddress Binary
SessionID HexInt64
Smb2Command UInt16

Event ID 1047: The server received a Smb2Command request but is taking an abnormal amount of time to process it.

#
Channel
Operational
Task
Smb2SlowCommand

Message #

The server received a %2 request but is taking an abnormal amount of time to process it.

Instance Id: %1
Command: %2
PerfBlock: %3
Duration(s): %4
Threshold(s): %5

Fields #

NameDescription
InstanceId UInt32
Smb2Command UInt16
Smb2PerfBlock UInt16
Duration UInt64
Threshold UInt64

Event ID 1048: The server processed a Smb2Command request.

#
Channel
Operational
Task
Smb2CommandTimeDistribution

Description

The server processed a Smb2Command request. Times taken to complete each stage below.

Message #

The server processed a %1 request. Times taken to complete each stage below.

Command: %1
AcquireLockTime(s): %2
IoTime(s): %3
TotalTime(s): %4
Threshold(s): %5

Fields #

NameDescription
Smb2Command UInt16
AcquireLockTime UInt64
IoTime UInt64
TotalTime UInt64
Threshold UInt64

Event ID 1049: The certificate for the server has expired.

#
Channel
Operational
Task
ServerCertMappingExpired

Message #

The certificate for the server has expired. 

Subject: %2
Thumbprint: %4
Expires on %5.

Guidance:

This event indicates the certificate has expired. 

Renew or issue new certificates to avoid service interruption.

Fields #

NameDescription
CertSubjectNameLength UInt16
CertSubjectName UnicodeString
CertThumbprintLength UInt16
CertThumbprint UnicodeString
Expiring FILETIME

Event ID 1050: Found InterfaceID endpoint(s) related to interface ID NumberOfEndpointsFound, closed NumberOfEndpointsClosed of which.

#
Channel
Operational
Task
Smb2ClosedEndpointsOutsideUnicastIPTable

Message #

Found %1 endpoint(s) related to interface ID %2, closed %3 of which.

Fields #

NameDescription
InterfaceID UInt32
NumberOfEndpointsFound UInt32
NumberOfEndpointsClosed UInt32

Event ID 1051: The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server.

#
Channel
Operational
Task
SrvNegotiateCipherFailure

Description

The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Message #

The SMB negotiate request processing failed on the server to select the encryption cipher for the client and server. Please ensure there is a common cipher between the client and server.

Client encryption cipher suite order (most to least preferred): %2
Server encryption cipher suite order (most to least preferred): %4

Fields #

NameDescription
ClientCipherSuiteOrderLength UInt32
ClientCipherSuiteOrder UnicodeString
ServerCipherSuiteOrderLength UInt32
ServerCipherSuiteOrder UnicodeString
ClientCipherCount UInt16
LoggedClientCipherCount UInt16
ClientCipherOrder UInt16

Event ID 1052: Failed to restore a server certificate mapping from persistent storage.

#
Channel
Operational
Task
ServerCertMappingRestoreFailure

Message #

Failed to restore a server certificate mapping from persistent storage.

Subject: %2
Thumbprint: %4

Error code: %5.

Fields #

NameDescription
SubjectLength UInt16
Subject UnicodeString
ThumbprintLength UInt16
Thumbprint UnicodeString
Status HexInt32NTSTATUS reference

Event ID 1053: Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings from persistent storage.

#
Channel
Operational
Level
Informational
Task
ServerCertMappingRestoreSummary

Description

Restored CountOfCertsRestored of CountOfCertsTotal server certificate mappings from persistent storage. Last error code: Status.

Message #

Restored %2 of %1 server certificate mappings from persistent storage. Last error code: %3.

Fields #

NameDescription
CountOfCertsTotal UInt16
CountOfCertsRestored UInt16
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1053,
    "level": 4,
    "task": 3032,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:33.7687422+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1054: Network operation has taken longer than expected.

#
Channel
Operational
Task
SrvSlowNetworkOperation

Message #

Network operation has taken longer than expected.

Client Name: %8
Client Address: %10
User Name: %6
Session ID: %3
Share Name: %12
File Name: %14
Command: %1
Duration (in milliseconds): %15
Warning Threshold (in milliseconds): %16

Guidance:

The underlying file system has taken too long to respond to an operation. This typically indicates a problem with the storage and not SMB.

Fields #

NameDescription
Command UInt32
SessionGuid GUID
SessionId HexInt64
ConnectionGuid GUID
UserNameLength UInt16
UserName UnicodeString
ClientNameLength UInt16
ClientName UnicodeString
ClientAddressLength UInt16
ClientAddress Binary
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString
DurationInMilliseconds UInt64
ThresholdInMilliseconds UInt64
CtlCode UInt32
SubCode UInt32
TunneledControl UInt32

Event ID 1055: RDMA rundown is active.

#
Channel
Operational
Task
SrvNetRdmaRundownActive

Description

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently ActiveRdmaResourceCount active RDMA resources.

Message #

RDMA rundown is active. Active RDMA-based operations will be wound down. There are currently %1 active RDMA resources.

Fields #

NameDescription
ActiveRdmaResourceCount UInt32

Event ID 1056: RDMA rundown is complete.

#
Channel
Operational
Task
SrvNetRdmaRundownComplete

Description

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: NoOp.

Message #

RDMA rundown is complete. No further RDMA-based operations are allowed. Rundown no-op: %1.

Fields #

NameDescription
NoOp Boolean

Event ID 1057: Reactivation of RDMA support has commenced.

#
Channel
Operational
Task
SrvNetRdmaReactivation

Event ID 1058: RDMA is no longer disabled.

#
Channel
Operational
Task
SrvNetRdmaReactivationComplete

Description

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: NoOp.

Message #

RDMA is no longer disabled. RDMA-based operations can proceed, given hardware capabilities and OS policy. No-op: %1.

Fields #

NameDescription
NoOp Boolean

Event ID 1059: SMBDirect load attempt complete.

#
Channel
Operational
Task
SrvNetSmbDirectLoad

Message #

SMBDirect load attempt complete.

Success: %1
Status code: %2
Service path: %4

Fields #

NameDescription
IsSuccess Boolean
LoadStatus HexInt32
ServicePathLength UInt16
ServicePath UnicodeString
DeviceNameLength UInt16
DeviceName UnicodeString

Event ID 1060: SMB DDP security changed from OldValue to NewValue.

#
Channel
Operational
Task
Smb2DirectDataPlacementSecurityChanged

Message #

SMB DDP security changed from %1 to %2.

Fields #

NameDescription
OldValue UInt32
NewValue UInt32

Event ID 1061: SMB2 Request Negotiate Dialect Failure.

#
Channel
Operational
Task
Smb2RequestNegotiate

Message #

SMB2 Request Negotiate Dialect Failure

Session ID: %1
Client Address: %18
Client Name:%20
Client Dialects: %12
Minimum dialect required by server: %15
Maximum dialect required by server: %16

Guidance:

You should expect this error when servers don't meet the dialects requested by client. Please check the minimum and maximum dialects set by the client and ensure the server supports the dialects.

Fields #

NameDescription
SessionId UInt64
ProcessId UInt32
TreeId UInt32
MessageId UInt64
MasterMessageId UInt64
Command UInt16
CreditsRequested UInt16
Flags UInt32
SecurityMode UInt16
Capabilities UInt32
DialectCount UInt16
Dialects UInt16
ClientGuid GUID
ConnectionGUID GUID
MinSmb2Dialect HexInt32
MaxSmb2Dialect HexInt32
ClientAddressLength UInt32
ClientAddress Binary
ClientNameLength UInt16
ClientName UnicodeString

Event ID 1062: SMB Dialect Change.

#
Channel
Operational
Task
Smb2DialectChange

Message #

SMB Dialect Change 

%1 was changed from %2 to %3.

Fields #

NameDescription
SmbDialect UnicodeString
OldDialect HexInt32
NewDialect HexInt32

Event ID 1080: Component capabilities: SrvNetComponentCapabilities.

#
Channel
Operational
Level
Informational
Task
SrvNetComponentCapabilities

Message #

Component capabilities: %1
Internal patch number: %2

Fields #

NameDescription
SrvNetComponentCapabilities HexInt32
PatchNumber HexInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1080,
    "level": 4,
    "task": 3069,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.1025119+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {}
}

Event ID 1800: CA failure - Failed to set continuously available property on a new or existing file share as the file share is not a cluster share.

#
Channel
Operational
Task
SSClusterCaFailure

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString

Event ID 1801: CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to att...

#
Channel
Operational
Task
SSRkfCaFailure

Description

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume.

Message #

CA failure - Failed to set continuously available property on a new or existing file share as Resume Key filter is not started or has failed to attach to the underlying volume.

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
Status UInt32NTSTATUS reference

Event ID 1802: The server failed to reserve the next ID region in the cluster registry.

#
Channel
Operational
Task
SrvNetGetNextIdFailure

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1803: The security descriptor differs from the default value.

#
Channel
Operational
Task
SecurityCertificateChanged

Message #

The security descriptor differs from the default value.

 Path: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\DefaultSecurity\%1

 Guidance:

 This is typically caused by an administrator or a third party changing the security on the object manually. To reset the security back to the default value, delete the path shown above.
 Microsoft does not recommend changing the default security of %1 as it may cause application incompatibilities or security concerns.

Fields #

NameDescription
DescriptorName UnicodeString

Event ID 1804: No SMB1 usage detected in the last 20 minutes.

#
Channel
Analytic
Task
NoSmb1ObservedInLastPeriod

Message #

No SMB1 usage detected in the last 20 minutes.

Guidance:

This event indicates that no attempt was made to contact this computer via the SMB1 protocol. After %1 online days of no SMB1 contact attempts, the SMB1 Server service will automatically uninstall.

Fields #

NameDescription
Days UInt32

Event ID 1900: TDI mode enabled: .

#
Channel
Analytic
Level
Informational
Task
TdiModeEnabled

Description

TDI mode enabled.

Message #

TDI mode enabled: %1

Fields #

NameDescription
IsTdiEnabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1900,
    "level": 4,
    "task": 3042,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.1015487+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "IsTdiEnabled": "true"
  }
}

Event ID 1900: TDI mode enabled: IsTdiEnabled.

#
Channel
Operational
Level
Informational
Task
TdiModeEnabled

Message #

TDI mode enabled: %1

Fields #

NameDescription
IsTdiEnabled Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 1900,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 2305843009213694464,
    "time_created": "2023-11-06T06:25:43.357313+00:00",
    "event_record_id": 95,
    "correlation": {},
    "execution": {
      "process_id": 4,
      "thread_id": 224
    },
    "channel": "Microsoft-Windows-SMBServer/Operational",
    "computer": "WinDev2310Eval",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "IsTdiEnabled": true
  },
  "message": ""
}

References #

Event ID 1901: Failed to allocate an NSI table for network interface enumeration: .

#
Channel
Analytic
Task
NsiTableAllocationFailed

Description

Failed to allocate an NSI table for network interface enumeration.

Message #

Failed to allocate an NSI table for network interface enumeration: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1901: Failed to allocate an NSI table for network interface enumeration: Status.

#
Channel
Operational
Task
NsiTableAllocationFailed

Message #

Failed to allocate an NSI table for network interface enumeration: %1

Fields #

NameDescription
Status HexInt32NTSTATUS reference

Event ID 1902: Received notification of a newly-started network interface with Luid .

#
Channel
Analytic
Task
NsiInterfaceAdded

Description

Received notification of a newly-started network interface with Luid on address family (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1902: Received notification of a newly-started network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

#
Channel
Operational
Task
NsiInterfaceAdded

Message #

Received notification of a newly-started network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1903: Received notification of a stopped network interface with Luid .

#
Channel
Analytic
Task
NsiInterfaceRemoved

Description

Received notification of a stopped network interface with Luid on address family (IPv4 == 2, IPv6 == 23).

Message #

Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1903: Received notification of a stopped network interface with Luid NetLuid on address family AddressFamily (IPv4 == 2, IPv6 == 23).

#
Channel
Operational
Task
NsiInterfaceRemoved

Message #

Received notification of a stopped network interface with Luid %2 on address family %1 (IPv4 == 2, IPv6 == 23)

Fields #

NameDescription
AddressFamily UInt32
NetLuid HexInt64

Event ID 1904: Failed to open network interface with Luid .

#
Channel
Analytic
Task
IPInterfaceNotFound

Description

Failed to open network interface with Luid : error.

Message #

Failed to open network interface with Luid %1: error %2

Fields #

NameDescription
NetLuid HexInt64
Status HexInt32NTSTATUS reference

Event ID 1904: Failed to open network interface with Luid NetLuid: error Status.

#
Channel
Operational
Task
IPInterfaceNotFound

Message #

Failed to open network interface with Luid %1: error %2

Fields #

NameDescription
NetLuid HexInt64
Status HexInt32NTSTATUS reference

Event ID 1905: The server closed the session as part of periodic system cleanup.

#
Channel
Operational
Task
SrvSessionInvalidate

Message #

The server closed the session as part of periodic system cleanup.

Session Id: %1
Instance Id: %2
Reason: %3

Fields #

NameDescription
SessionId HexInt64
InstanceId UInt32
Reason UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 1905,
    "level": "Information",
    "task": null,
    "opcode": "Info",
    "time_created": "2026-04-25T05:36:17.4681377+00:00",
    "computer": "JD-DC01-2022.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer/Operational"
  },
  "event_data": {
    "Reason": "Idle session, no open files",
    "InstanceId": "0",
    "SessionId": "0x5000fc000021"
  }
}

Event ID 1906: Session key for connection is weaker than required.

#
Channel
Security
Task
Srv2SessionKeyTooShort

Description

Session key for connection is weaker than required. Connection will be closed as a result.

Message #

Session key for connection is weaker than required. Connection will be closed as a result.

Client: %2
User: %6
Session key length: %3
Required Session key length: %4

Guidance:
To establish a connection with a shorter session key, set the following registry DWORD value name with the value as decimal bits:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters]
"MinimumSessionKeyLength"

Important: If you have configured the 'Network security: Configure encryption types allowed for Kerberos' security policy to prevent use of 256-bit keys but also set the MinimumSessionKeyLength greater than 128 bits, the computer will not be able to make SMB connections. Setting MinimumSessionKeyLength higher than 128 bits will also prevent SMB connections using NTLM.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SessionKeyLength UInt32
RequiredSessionKeyLength UInt32
SessionId UInt64
UserName UnicodeString
AuthProtocol UInt32

Event ID 1907: Server received STATUS_STOPPED_ON_SYMLINK but the reparse buffer is NULL.

#
Channel
Analytic
Task
ReceivedNullReparseBuffer

Event ID 1908: Custom FSCTL allow list was not successfully loaded after several retries.

#
Channel
Analytic
Task
AllowListLoadFailed

Event ID 1909: Send QUIC Endpoint notification failure - .

#
Channel
Analytic
Task
SrvNetQuicSendEndpointNotificationFailure

Message #

Send QUIC Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Event ID 1909: Send QUIC Endpoint notification failure - FailureType.

#
Channel
Operational
Task
SrvNetQuicSendEndpointNotificationFailure

Message #

Send QUIC Endpoint notification failure - %1

Fields #

NameDescription
FailureType UInt32
InterfaceIndex UInt32
Error HexInt32
DeviceNameLength UInt16
DeviceName UnicodeString
ExtraInformation UInt32

Event ID 1910: RDMA listen socket disable override is CurrentDisableOverrideState.

#
Channel
Operational
Task
SrvNetEventDisableRdmaListenSocketsState

Description

RDMA listen socket disable override is CurrentDisableOverrideState. New value is NewState. SrvNetIsRDMASupportEnabled is SrvNetEnableRdmaSupport. Action taken SrvNetEvaluateRdmaEnabledPolicy.

Message #

RDMA listen socket disable override is %1. New value is %2. SrvNetIsRDMASupportEnabled is %3. Action taken %4.

Fields #

NameDescription
CurrentDisableOverrideState Boolean
NewState Boolean
SrvNetEnableRdmaSupport Boolean
SrvNetEvaluateRdmaEnabledPolicy Boolean
SrvNetIsSMBDirectSupported Boolean
ActionTaken Boolean

Event ID 1911: Server Certificate failure - FailureType.

#
Channel
Operational
Task
ServerCertificateFailure

Message #

Server Certificate failure - %1

Fields #

NameDescription
FailureType UInt32
Error HexInt32
MappingNameLength UInt16
MappingName UnicodeString
ThumprintLength UInt16
Thumbprint UnicodeString

Event ID 1912: Warning to set the QoS policy on file FileNameLength.

#
Channel
Operational
Task
ShareQosPolicySettingFailure

Message #

Warning to set the QoS policy on file %6.
Status=%1

Fields #

NameDescription
Status UInt32NTSTATUS reference
ServerNameLength UInt16
ServerName UnicodeString
ShareNameLength UInt16
ShareName UnicodeString
FileNameLength UInt16
FileName UnicodeString

Event ID 1913: The SMB connection was successfully established.

#
Channel
Operational
Task
SrvNetConnectionEstablished

Message #

The SMB connection was successfully established.

Endpoint Name: %2
Transport: %3
Server socket address: %5
Client socket address: %7
Connection ID: %9
Mutual authentication: %10
Access control: %11

Fields #

NameDescription
EndpointNameLength UInt16
EndpointName UnicodeString
ConnectionType UInt32
ServerSocketAddressLength UInt32
ServerSocketAddress Binary
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
ConnectionIdSize UInt32
ConnectionId Binary
MutualAuthentication UInt32
AccessControlCheck UInt32

Event ID 1914: The server was unable to perform revocation checks on the client certificate chain.

#
Channel
Operational
Task
SrvNetClientCertificateChainRevocationChecksFailed

Description

The server was unable to perform revocation checks on the client certificate chain. The connection will proceed.

Message #

The server was unable to perform revocation checks on the client certificate chain. The connection will proceed. 

Verification Status: %1

Endpoint Name: %3
Transport: %4
Server socket address: %6
Client socket address: %8
Connection ID: %10

Fields #

NameDescription
Status UInt32NTSTATUS reference
EndpointNameLength UInt16
EndpointName UnicodeString
ConnectionType UInt32
TransportNameLength UInt16
TransportName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary

Event ID 2000: Packet Fragment (FragmentSize bytes).

#
Channel
Diagnostic
Task
PacketFragment

Message #

Packet Fragment (%2 bytes)

Fields #

NameDescription
ReassembledEventID UInt16
FragmentSize UInt32
FragmentData Binary

Event ID 3000: SMB1 access Client Address: ClientName Guidance: This event indicates that a client attempted to access the server using SMB1.

#
Channel
Audit
Level
Informational
Task
AuditSmb1Access

Description

SMB1 access.

Message #

SMB1 access

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields #

NameDescription
ClientName AnsiString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "guid": "D48CE617-33A2-4BC3-A5C7-11AA4F29619E",
    "event_source_name": "",
    "event_id": 3000,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 144115188075855872,
    "time_created": "2026-03-13T18:46:45.797324+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 11352,
      "thread_id": 7956
    },
    "channel": "Microsoft-Windows-SMBServer/Audit",
    "computer": "LAB-DC01.ludus.domain",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ClientName": "10.2.10.11"
  },
  "message": ""
}

Event ID 3002: A remote device attempted SMB1 connection to this computer.

#
Channel
Audit
Task
AuditSmb1Access

Message #

A remote device attempted SMB1 connection to this computer.

Client Address: %1

Guidance:

This event indicates that a client attempted to access the server using SMB1. To stop auditing SMB1 access, use the Windows PowerShell cmdlet Set-SmbServerConfiguration.

Fields #

NameDescription
ClientName AnsiString

Event ID 3003: SMB1 server service has been automatically uninstalled.

#
Channel
Audit
Task
UninstallSmb1Server

Description

SMB1 server service has been automatically uninstalled.n.

Message #

SMB1 server service has been automatically uninstalled.n
Guidance:

This event indicates that after detecting no attempts to contact this computer via the SMB1 protocol for %1 online days, the SMB1 Server service was automatically uninstalled.

Fields #

NameDescription
Days UInt32

Event ID 3004: SMB server admin file rundown

#
Channel
Operational
Task
SrvAdminFileRundown

Fields #

NameDescription
FileId UInt64
FileNameLength UInt16
FileName UnicodeString
SessionId UInt64
ShareId UInt64

Event ID 3005: SMB server admin session rundown

#
Channel
Operational
Task
SrvAdminSessionRundown

Fields #

NameDescription
SessionId UInt64
ComputerNameLength UInt16
ComputerName UnicodeString
UserNameLength UInt16
UserName UnicodeString
DomainNameLength UInt16
DomainName UnicodeString
DomainAndUserNameLength UInt16
DomainAndUserName UnicodeString
ClientOsLength UInt16
ClientOs UnicodeString
TransportNameLength UInt16
TransportName UnicodeString
ServerNameLength UInt16
ServerName UnicodeString
StartTime UInt64
LastActiveTime UInt64

Event ID 3006: SMB server admin share rundown

#
Channel
Operational
Task
SrvAdminShareRundown

Fields #

NameDescription
ShareId UInt64
ShareNameLength UInt16
ShareName UnicodeString

Event ID 3007: Access Denied Server certificate mapping name: ServerName Client socket address: ClientSocketAddress Client certificate chain: Subject, Issuer, Serial Number, SupportedHashAlgsStr CertChainProperti...

#
Channel
Audit
Task
MutualAuthClientAccessDenied

Description

Access Denied.

Message #

Access Denied

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server denied access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243808

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
SupportedHashAlgsStrLength UInt16
SupportedHashAlgsStr UnicodeString
CertChainPropertiesStrLength UInt16
CertChainPropertiesStr UnicodeString
DenySidsStrLength UInt16
DenySidsStr UnicodeString
AllowSidsStrLength UInt16
AllowSidsStr UnicodeString
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3008: Access Allowed.

#
Channel
Audit
Task
MutualAuthClientAccessAllowed

Message #

Access Allowed

Server certificate mapping name: %2
Client socket address: %4

Client certificate chain:

Subject, Issuer, Serial Number, %6
%8
Deny entries:

%10
Allow Entries:

%12
Guidance:

The server allowed access to the client during mutual authentication. If you did not expect this result, examine the deny and allow entries above. For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243809

Fields #

NameDescription
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
SupportedHashAlgsStrLength UInt16
SupportedHashAlgsStr UnicodeString
CertChainPropertiesStrLength UInt16
CertChainPropertiesStr UnicodeString
DenySidsStrLength UInt16
DenySidsStr UnicodeString
AllowSidsStrLength UInt16
AllowSidsStr UnicodeString
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3009: An error occurred while checking client certificate chain access during mutual authentication.

#
Channel
Audit
Task
SrvAdminMutualAuthClientAccessErrorShareRundown

Description

An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: Error.

Message #

An error occurred while checking client certificate chain access during mutual authentication. Win32 error code: %1

Server certificate mapping name: %3
Client socket address: %5

Guidance:

For more information on troubleshooting this behavior, review https://go.microsoft.com/fwlink/?linkid=2243709

Fields #

NameDescription
Error UInt32
ServerNameLength UInt16
ServerName UnicodeString
ClientSocketAddressLength UInt32
ClientSocketAddress Binary
ConnectionIdSize UInt32
ConnectionId Binary

Event ID 3010: An administrator attempted to assign an alternative SMB server listener port Port, but it is either in the 0?

#
Channel
Operational
Task
SrvNetAddEndpointListenerRulePortNotSupported

Description

An administrator attempted to assign an alternative SMB server listener port Port, but it is either in the 0―1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Message #

An administrator attempted to assign an alternative SMB server listener port %1, but it is either in the 0?1024 reserved range or it is already assigned to another process. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields #

NameDescription
Port UInt16

Event ID 3011: The SMB server service created an endpoint with the following listener rule entry settings.

#
Channel
Operational
Level
Informational
Task
SrvNetAddEndpointListenerRuleSuccess

Message #

The SMB server service created an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5

Guidance:

You should expect this event when assigning alternative SMB server listener ports and on any subsequent restarts of the SMB server service.

Fields #

NameDescription
TransportNameLength UInt16
TransportName UnicodeString
Port UInt16
TransportType UInt32
SrvInstances UInt32
Status HexInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 3011,
    "level": 4,
    "task": 3062,
    "opcode": 0,
    "time_created": "2026-04-18T03:03:30.6025061+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "TransportName": "\\Device\\NetbiosSmb",
    "SrvInstances": "15",
    "Status": "0x0",
    "Port": "445",
    "TransportNameLength": "18",
    "TransportType": "1"
  }
}

Event ID 3012: The SMB server service failed to create an endpoint with the following listener rule entry settings.

#
Channel
Operational
Task
SrvNetAddEndpointListenerRuleFailure

Message #

The SMB server service failed to create an endpoint with the following listener rule entry settings: 
Transport: %2
Port: %3
TransportType: %4
SrvInstances: %5
Error: %6

Guidance:

This error is usually caused by another process already listening on the same IP address and port. Use NETSTAT -abno to list all listening ports and their processes in use on this computer.

Fields #

NameDescription
TransportNameLength UInt16
TransportName UnicodeString
Port UInt16
TransportType UInt32
SrvInstances UInt32
Status HexInt32NTSTATUS reference

Event ID 3013: An administrator created an alternative SMB server listener port rule entry.

#
Channel
Operational
Task
SrvNetAddListenerRuleNew

Message #

An administrator created an alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this alternative SMB server listener port.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3014: An administrator updated an existing alterative SMB server listener port rule entry.

#
Channel
Operational
Task
SrvNetAddListenerRuleUpdate

Message #

An administrator updated an existing alterative SMB server listener port rule entry:

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

SMB clients can now connect to this updated alternative SMB server listener port.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3015: An administrator removed an existing alternative SMB server listener port rule entry.

#
Channel
Operational
Task
SrvNetAddListenerRuleRemove

Message #

An administrator removed an existing alternative SMB server listener port rule entry: 

Port: %1
TransportType: %2
SrvInstances: %3

Guidance:

This will close the specified listening sockets for the transport type on the specified port number. SMB clients cannot connect to this SMB server on that alternative port anymore.

Fields #

NameDescription
Port UInt16
TransportType UInt32
SrvInstances UInt32

Event ID 3016: The SMB server service failed to enable an implicit loopback interface for interface Interface with NTSTATUS Status.

#
Channel
Operational
Task
SrvNetEnableImplicitLoopbackInterfaceError

Message #

The SMB server service failed to enable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields #

NameDescription
Interface UInt32
Status HexInt32NTSTATUS reference

Event ID 3017: The SMB server service failed to disable an implicit loopback interface for interface Interface with NTSTATUS Status.

#
Channel
Operational
Task
SrvNetDisableImplicitLoopbackInterfaceError

Message #

The SMB server service failed to disable an implicit loopback interface for interface %1 with NTSTATUS %2.

Fields #

NameDescription
Interface UInt32
Status HexInt32NTSTATUS reference

Event ID 3018: The inbound ProtocolType firewall rule already exists for port Port.

#
Channel
Operational
Task
AlternativePortFirewallRuleAlreadyAdded

Message #

The inbound %2 firewall rule already exists for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3019: The inbound ProtocolType firewall rule failed to be created for port Port.

#
Channel
Operational
Task
AlternativePortFirewallRuleAddFailure

Message #

The inbound %2 firewall rule failed to be created for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3020: The inbound ProtocolType firewall rule was successfully created for port Port.

#
Channel
Operational
Task
AlternativePortFirewallRuleAddSuccess

Message #

The inbound %2 firewall rule was successfully created for port %1.

Fields #

NameDescription
Port UInt16
ProtocolType UInt32

Event ID 3021: The SMB server observed that the client doesn't support signing.

#
Channel
Audit
Task
Smb2ClientDoesNotSupportSigning

Message #

The SMB server observed that the client doesn't support signing.

Client name: %2
Server requires signing: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
UserNameLength UInt16
UserName UnicodeString
ServerRequiresSigning Boolean

Event ID 3022: The SMB server observed that the client doesn't support encryption.

#
Channel
Audit
Task
Smb2ClientDoesNotSupportEncryption

Message #

The SMB server observed that the client doesn't support encryption.

Client name: %2
Server requires encryption: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
ServerRequiresEncryption Boolean
SmbClientDoesNotSupportEncryptionType UInt32

Event ID 3023: The SMB client was logged on as Guest account.

#
Channel
Operational
Task
InsecureGuestLogon

Message #

The SMB client was logged on as Guest account.

Client name: %2

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString

Event ID 3024: The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection ...

#
Channel
Audit
Task
SrvNetClientDoesNotSupportSpn

Description

The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled. Client name: ClientName SPN Query Status: Status SPN Validation Policy: SPNValidationPolicy

Message #

The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA is disabled.

Client name: %2
SPN Query Status: %3
SPN Validation Policy: %4

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
Status HexInt32NTSTATUS reference
SPNValidationPolicy UInt32

Event ID 3024: The SMB server observed that the client did not send an SPN during authentication, indicating that the client does not support Extended Protection for Authentication (EPA) or that support for EPA i...

#
Channel
Operational
Task
SrvNetClientDoesNotSupportSpn

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
Status HexInt32NTSTATUS reference
SPNValidationPolicy UInt32

Event ID 3025: The SMB server observed that the client sent an unrecognized SPN during authentication

#
Channel
Audit, Operational
Task
SrvNetClientSentUnrecognizedSpn

Message #

The SMB server observed that the client sent an unrecognized SPN during authentication.

Client name: %2
SPN: %3
SPN Validation Policy: %6

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPN UnicodeString
ServiceClassIsValid Boolean
PrincipalNameIsValid Boolean
SPNValidationPolicy UInt32

Event ID 3026: The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but electe...

#
Channel
Audit
Task
SrvNetClientSentEmptySpn

Description

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Message #

The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one.

Client name: %2
SPN Validation Policy: %3

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPNValidationPolicy UInt32

Event ID 3026: The SMB server observed that the client sent an empty SPN during authentication, which indicates the client is capable of sending an SPN but elected not to supply one

#
Channel
Operational
Task
SrvNetClientSentEmptySpn

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
SPNValidationPolicy UInt32

Event ID 3027: The SMBv1 server observed that the SMBv1 client does not have signing enabled

#
Channel
Audit, Operational
Task
Smb1ClientDoesNotSupportSigning

Message #

The SMBv1 server observed that the SMBv1 client does not have signing enabled.

Client name: %2
Server requires signing: %3

Guidance:

This event indicates that the SMBv1 client may not support SMB signing, but due to protocol limitations, this cannot be determined with certainty. Further evaluation is recommended to verify the client's signing capabilities.

Prior to Windows Vista, SMBv1 clients that did not have signing explicitly enabled could not perform SMB signing.
This behavior was changed with the release of Windows Vista and was also backported to Windows XP and Windows Server 2003 through updates. With these changes, SMB clients may support signing even if it is not explicitly enabled, provided the server requires it.

Fields #

NameDescription
ClientNameLength UInt16
ClientName UnicodeString
ServerRequiresSigning Boolean

Event ID 4000: The SMB client connection to the share was established.

#
Channel
Connectivity
Level
Informational
Task
Smb2ShareConnectionEstablished

Message #

The SMB client connection to the share was established.

Share name: %2
Client name: %6
Client address: %4
Session ID: %7
Tree ID: %8
Transport type: %9
Signing used: %10
Encryption used: %11
Compression activated: %12

Fields #

NameDescriptionRules
ShareNameLength UInt16
ShareName UnicodeString3 detection rules
ClientAddressLength UInt32
ClientAddress Binary5 detection rules
ClientNameLength UInt16
ClientName UnicodeString
SessionId UInt64
TreeId UInt32
ConnectionType UInt32
SigningUsed Boolean1 detection rule
EncyptionUsed Boolean1 detection rule
CompressionUsed Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 4000,
    "level": 4,
    "task": 3076,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8656925+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B0000000000000000",
    "SigningUsed": "true",
    "ClientName": "\\\\10.2.10.11",
    "ClientAddressLength": "16",
    "ShareNameLength": "6",
    "ClientNameLength": "12",
    "TreeId": "13",
    "ShareName": "ADMIN$",
    "CompressionUsed": "false",
    "ConnectionType": "1",
    "EncyptionUsed": "false",
    "SessionId": "21990232555529"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 4000: The SMB client connection to the share was established

#
Channel
Operational
Level
4
Task
Smb2ShareConnectionEstablished

Fields #

NameDescriptionRules
ShareNameLength UInt16
ShareName UnicodeString3 detection rules
ClientAddressLength UInt32
ClientAddress Binary5 detection rules
ClientNameLength UInt16
ClientName UnicodeString
SessionId UInt64
TreeId UInt32
ConnectionType UInt32
SigningUsed Boolean1 detection rule
EncyptionUsed Boolean1 detection rule
CompressionUsed Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-SMBServer",
    "event_id": 4000,
    "level": 4,
    "task": 3076,
    "opcode": 0,
    "time_created": "2026-04-18T03:08:10.8656925+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-SMBServer"
  },
  "event_data": {
    "ClientAddress": "0200F00F0A020A0B0000000000000000",
    "SigningUsed": "true",
    "ClientName": "\\\\10.2.10.11",
    "ClientAddressLength": "16",
    "ShareNameLength": "6",
    "ClientNameLength": "12",
    "TreeId": "13",
    "ShareName": "ADMIN$",
    "CompressionUsed": "false",
    "ConnectionType": "1",
    "EncyptionUsed": "false",
    "SessionId": "21990232555529"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma # view in coverage

Event ID 40000: Packet (PacketSize bytes).

#
Channel
Diagnostic
Level
Informational
Task
Packet

Message #

Packet (%4 bytes)

Fields #

NameDescription
ConnectionType UInt32
PeerAddressLength UInt32
PeerAddress Binary
PacketSize UInt32
PacketData Binary

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-SMBServer/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 40000,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 14260
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-SMBServer",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:46:09.815Z",
    "version": 0
  },
  "event_data": {
    "ConnectionType": 1,
    "PacketData": "FF534D4272000000001853C8000000000000000000000000FFFFFFFE00000000007800025043204E4554574F524B2050524F4752414D20312E3000024C414E4D414E312E30000257696E646F777320666F7220576F726B67726F75707320332E316100024C4D312E325830303200024C414E4D414E322E3100024E54204C4D20302E31320002534D4220322E3030320002534D4220322E3F3F3F00",
    "PacketSize": 155,
    "PeerAddress": "1700EEB5000000000000000000000000000000000000000100000000",
    "PeerAddressLength": 28
  },
  "message": ""
}

Provenance

ETW provider GUID d48ce617-33a2-4bc3-a5c7-11aa4f29619e

Defined in srv2.sys, the binary that emits these events.

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4171, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.6584, captured 2026-06-02 — Manifest XML pack, 2.0 MB