Microsoft-Windows-SMBWitnessService
72 events across 2 channels
Event ID 1: Witness Service initialization failed with ErrorCode.
#Event ID 1
#Description
Witness Service initialization failed with.
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 |
Event ID 2: Witness Service protocol security callback failure (Error = ErrorCode, Authentication Level = AuthenticationLevel, Authentication Service = AuthenticationService).
#Event ID 2
#Description
Witness Service protocol security callback failure (Error = , Authentication Level = , Authentication Service = ).
Fields #
| Name | Description |
|---|---|
AuthenticationLevel UInt32 | |
AuthenticationService UInt32 | |
ErrorCode UInt32 |
Event ID 3: Witness Service received a registration request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 3
#Description
Witness Service received a registration request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 4: Witness Service successfully registered request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 4
#Description
Witness Service successfully registered request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 5: Witness Service registration request from Witness Client (ClientName) for NetName \\NetName failed with error (ErrorCode).
#Event ID 5
#Description
Witness Service registration request from Witness Client () for NetName \\ failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ErrorCode Int32 |
Event ID 6: Witness Service is queuing notifications for Clients clients.
#Event ID 6
#Description
Witness Service is queuing notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 7: Witness Service completed queuing notifications for Clients clients.
#Event ID 7
#Description
Witness Service completed queuing notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 8: Witness Service resource notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 8
#Description
Witness Service resource notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 9: Witness Service sent NumResources resource events to Witness Client (ClientName).
#Event ID 9
#Description
Witness Service sent resource events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 10: Witness Service received a move client request for client (ClientName).
#Event ID 10
#Description
Witness Service received a move client request for client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 11: Witness Service successfully sent a move request to client (ClientName).
#Event ID 11
#Description
Witness Service successfully sent a move request to client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 12: Witness Service ignored the move client request for client (ClientName).
#Event ID 12
#Description
Witness Service ignored the move client request for client (). Client is not registered with current Witness Service.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 13: Witness Service ignored the move client request for client (ClientName).
#Event ID 13
#Description
Witness Service ignored the move client request for client (). Destination server () is unavailable.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ServerName UnicodeString |
Event ID 14: Witness Service reported a failure (ErrorCode) to move client (ClientName).
#Event ID 14
#Description
Witness Service reported a failure () to move client ().
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 | |
ClientName UnicodeString |
Event ID 15: Witness Service received witness unregister request from Witness Client (ClientName) for NetName \\NetName.
#Event ID 15
#Description
Witness Service received witness unregister request from Witness Client () for NetName \\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString |
Event ID 16: Witness Service removed registration for Witness Client (ClientName).
#Event ID 16
#Description
Witness Service removed registration for Witness Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 17: Witness Service shutdown failed with error (ErrorCode).
#Event ID 17
#Description
Witness Service shutdown failed with error ().
Fields #
| Name | Description |
|---|---|
ErrorCode UInt32 |
Event ID 18: Witness Service successfully sent the list of Witness Servers to Client (ClientName).
#Event ID 18
#Description
Witness Service successfully sent the list of Witness Servers to Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 19: Witness Service is retrying to process the list of Witness Servers to Client (ClientName).
#Event ID 19
#Description
Witness Service is retrying to process the list of Witness Servers to Client ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 20: Witness Service failed to process the list of Witness Servers for Client (ClientName) with error (ErrorCode).
#Event ID 20
#Description
Witness Service failed to process the list of Witness Servers for Client () with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 21: Witness Service failed to move client (ClientName).
#Event ID 21
#Description
Witness Service failed to move client (). Client name is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString |
Event ID 22: Witness Service failed to move client (ClientName).
#Event ID 22
#Description
Witness Service failed to move client (). Destination node () is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
DestinationNode UnicodeString |
Event ID 23: Witness Service failed to move client (ClientName) to destination node (DestinationNode).
#Event ID 23
#Description
Witness Service failed to move client () to destination node (). NetName () is invalid.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
DestinationNode UnicodeString | |
NetName UnicodeString |
Event ID 24: Witness Service received a registration request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 24
#Description
Witness Service received a registration request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 25: Witness Service successfully registered request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 25
#Description
Witness Service successfully registered request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 26: Witness Service registration request from Witness Client (ClientName) for \\NetName\ShareName failed with error (ErrorCode).
#Event ID 26
#Description
Witness Service registration request from Witness Client () for \\\ failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString | |
ErrorCode Int32 |
Event ID 27: Witness Service received witness unregister request from Witness Client (ClientName) for \\NetName\ShareName.
#Event ID 27
#Description
Witness Service received witness unregister request from Witness Client () for \\\.
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
NetName UnicodeString | |
ShareName UnicodeString |
Event ID 28: Witness Service is queuing share move notifications for Clients clients.
#Event ID 28
#Description
Witness Service is queuing share move notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 29: Witness Service completed queuing share move notifications for Clients clients.
#Event ID 29
#Description
Witness Service completed queuing share move notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 30: Witness Service share move notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 30
#Description
Witness Service share move notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 31: Witness Service sent NumResources share move events to Witness Client (ClientName).
#Event ID 31
#Description
Witness Service sent share move events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 32: Witness Service is queuing IP notifications for Clients clients.
#Event ID 32
#Description
Witness Service is queuing IP notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 33: Witness Service completed queuing IP notifications for Clients clients.
#Event ID 33
#Description
Witness Service completed queuing IP notifications for clients.
Fields #
| Name | Description |
|---|---|
Clients UInt64 |
Event ID 34: Witness Service IP notification to Witness Client (ClientName) failed with error (ErrorCode).
#Event ID 34
#Description
Witness Service IP notification to Witness Client () failed with error ().
Fields #
| Name | Description |
|---|---|
ClientName UnicodeString | |
ErrorCode UInt32 |
Event ID 35: Witness Service sent NumResources IP events to Witness Client (ClientName).
#Event ID 35
#Description
Witness Service sent IP events to Witness Client ().
Fields #
| Name | Description |
|---|---|
NumResources Int32 | |
ClientName UnicodeString |
Event ID 36: Witness Service is requesting to move an SMB client that is optimized to connect to a specific SMB server for one or more file shares.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ce704b50-b105-4bc8-a24f-1792c0401c2a
Defined in Witness.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02