Microsoft-Windows-TCPIP

EventTitleChannelSampleRule
1001TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = …DiagnosticYN
1002TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.DiagnosticYN
1003TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.DiagnosticYN
1004TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale …DiagnosticYN
1005TCP: endpoint bind failed: address LocalAddressLength cannot be resolved …DiagnosticNN
1006TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status …DiagnosticYN
1007TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = …DiagnosticNN
1008TCP: endpoint (sockaddr=LocalAddressLength) bound.DiagnosticYN
1009TCP: endpoint (sockaddr=LocalAddressLength) closed.DiagnosticYN
1010TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family …DiagnosticNN
1011TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment …DiagnosticNN
1012TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection …DiagnosticNN
1013TCP: endpoint (Family=CompartmentId PID=Status) created.DiagnosticYN
1014TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route …DiagnosticNN
1015TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: …DiagnosticNN
1016TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client …DiagnosticNN
1017TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed.DiagnosticYN
1018TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) …DiagnosticNN
1019TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) …DiagnosticNN
1020TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) …DiagnosticNN
1021TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1022TCP: Bypass rate limiting since flag is set on path Path (local=LocalAddress …DiagnosticNN
1023TCP: Charge rate limiting quota and set rate limiting flag for path Path …DiagnosticNN
1024TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.DiagnosticNN
1025TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog …DiagnosticNN
1026TCP: Release and set rate limiting flag on path Path (local=LocalAddress …DiagnosticNN
1027TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.DiagnosticNN
1028TCP: Clear rate limiting flag on path Path (local=LocalAddress …DiagnosticNN
1029TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1030TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect …DiagnosticNN
1031TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect …DiagnosticYN
1032TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to …DiagnosticNN
1033TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed.DiagnosticYN
1034TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt …DiagnosticYN
1035TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1036TCP: ApplySynOptions, failed to create session state with status = Status, TCB = …DiagnosticNN
1037TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.DiagnosticNN
1038TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.DiagnosticYN
1039TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.DiagnosticYN
1040TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.DiagnosticYN
1041TCP: Injecting disconnect on a shutdown TCB failed.DiagnosticNN
1042TCP: connection disconnect Injected, length=Length.DiagnosticYN
1043TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect …DiagnosticYN
1044TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated …DiagnosticYN
1045TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1046TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: …DiagnosticYN
1047TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: …DiagnosticNN
1048TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: …DiagnosticNN
1049TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1050TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: …DiagnosticNN
1051TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.DiagnosticYN
1052TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at …DiagnosticNN
1053TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting …DiagnosticNN
1054TCP: Process with PID = ProcessId completed global port reservation of …DiagnosticNN
1055TCP: entering SYN attack resistance mode, Syn Attacks Detected = …DiagnosticNN
1056TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since …DiagnosticNN
1057TCP: connection rate-limiting violated ConnectionRateLimitViolations times since …DiagnosticNN
1058TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.DiagnosticNN
1059TCP: low memory state detected.DiagnosticNN
1060TCP: leaving low memory state.DiagnosticNN
1061TCP: address family AddressFamily added to interface InterfaceIndex.DiagnosticNN
1062TCP: address family AddressFamily removed from interface InterfaceIndex.DiagnosticNN
1063TCP: leaving SYN attack resistance mode, Syn Attacks Detected = …DiagnosticNN
1064TCP: Connection Tcb TimerType timer started.DiagnosticYN
1065TCP: Connection Tcb stopping TimerType timer.DiagnosticYN
1066TCP: Connection Tcb TimerType timer has expired.DiagnosticYN
1067TCP: ISB changed to IsbSize.DiagnosticYN
1068TCP: moving RSS indirection table index TableEntry from processor …DiagnosticNN
1069TCP: connection Tcb: Timeout Event updated cwnd = Cwnd and updated ssthresh = …DiagnosticNN
1070TCP: connection Tcb: Rtt sample recorded RttSample.DiagnosticNN
1071TCP: connection Tcb: Cumulative ACK updated cwnd = Cwnd.DiagnosticNN
1072TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = …DiagnosticNN
1073TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence …DiagnosticNN
1074TCP: connection Tcb: Received data with number of bytes = NumBytes.DiagnosticYN
1075TCP: connection Tcb: ECN Echo updated cwnd = Cwnd and updated ssthresh = …DiagnosticNN
1076TCP: connection Tcb: Spurious timeout with SndUna = SndUna.DiagnosticNN
1077TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, …DiagnosticNN
1078TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax …DiagnosticYN
1079TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax …DiagnosticYN
1080TCP: connection Tcb entering SACK mode with SndUna = SndUna.DiagnosticNN
1081TCP: connection Tcb leaving SACK mode with SndUna = SndUna.DiagnosticNN
1082TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and …DiagnosticNN
1084TCP: connection Tcb entered BH, BH MSS BHMSS, original MSS OriginalMSS.DiagnosticNN
1085TCP: connection Tcb Exiting BH due to TraceString, BH mss BHMSS, Original MSS …DiagnosticNN
1086TCP: connection Tcb not entering BH due to TraceString.DiagnosticNN
1087TCP: connection Tcb spurious RTO detection initiated at SndUna.DiagnosticNN
1088TCP: connection Tcb spurious RTO detection terminated at SndUna.DiagnosticNN
1089TCP: active connect failed (family=Status) connect-complete inspection failed: …DiagnosticNN
1090TCP: TcpReleaseIndicationList: Nbl = NBL.DiagnosticYN
1091TCP: connection Tcb posted an average of NumBytes bytes per send.DiagnosticNN
1092TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive …DiagnosticYN
1093TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window …DiagnosticYN
1094TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter …DiagnosticNN
1095TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter …DiagnosticNN
1096TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter …DiagnosticNN
1097TCP: connection (local=LocalAddress remote=RemoteAddress) auto-tuner adjusted …DiagnosticYN
1098TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = …DiagnosticNN
1099TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState.DiagnosticNN
1100TCP: SWS avoidance began on connection Tcb.DiagnosticYN
1101TCP: SWS avoidance ended on connection Tcb.DiagnosticNN

Event ID 1001: TCP: endpoint Endpoint (Family=AddressFamily, PID=Pid) created with status = Status.

#
Channel
Diagnostic
Level
Informational
Task
TcpEndpointCreation

Message #

TCP: endpoint %2 (Family=%3, PID=%4) created with status = %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference
Endpoint Pointer
AddressFamily UInt32
Pid UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1001",
    "version": "0",
    "level": "4",
    "task": "1001",
    "opcode": "0",
    "keywords": 9223372036854776832,
    "time_created": "2026-03-16T00:21:40.064345500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Status": "0x0",
    "Endpoint": "0xFFFF980A15F74B50",
    "AddressFamily": "      23",
    "Pid": "    3688"
  },
  "message": ""
}

Event ID 1002: TCP: Tcb Tcb (local=LocalAddress remote=RemoteAddress) requested to connect.

#
Channel
Diagnostic
Level
Informational
Task
TcpRequestConnect

Message #

TCP: Tcb %1 (local=%3 remote=%5) requested to connect.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1002",
    "version": "0",
    "level": "4",
    "task": "1002",
    "opcode": "0",
    "keywords": 9223372054034646144,
    "time_created": "2026-03-16T00:21:40.119471500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52999",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "13.89.179.13:443",
    "NewState": "       0",
    "RexmitCount": "       0"
  },
  "message": ""
}

Event ID 1003: TCP: Inspect Connect has been completed on Tcb Tcb with status = Status.

#
Channel
Diagnostic
Level
Informational
Task
TcpInspectConnectComplete

Message #

TCP: Inspect Connect has been completed on Tcb %1 with status = %2.

Fields #

NameDescription
Tcb Pointer
Status UInt32NTSTATUS reference
AddressFamily UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1003",
    "version": "0",
    "level": "4",
    "task": "1003",
    "opcode": "0",
    "keywords": 9223372054034646144,
    "time_created": "2026-03-16T00:21:40.119557300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "Status": "0x0",
    "AddressFamily": "       0"
  },
  "message": ""
}

Event ID 1004: TCP: Tcb Tcb is going to output SYN with ISN = ISN, RcvWnd = RcvWnd, RcvWndScale = RcvWndScale.

#
Channel
Diagnostic
Level
Informational
Task
TcpTcbSynSend

Message #

TCP: Tcb %1 is going to output SYN with ISN = %2, RcvWnd = %3, RcvWndScale = %4.

Fields #

NameDescription
Tcb Pointer
ISN UInt32
RcvWnd UInt32
RcvWndScale UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1004",
    "version": "0",
    "level": "4",
    "task": "1004",
    "opcode": "0",
    "keywords": 9223372058329612416,
    "time_created": "2026-03-16T00:21:40.119603700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "ISN": "155000287",
    "RcvWnd": "   64240",
    "RcvWndScale": "8"
  },
  "message": ""
}

Event ID 1005: TCP: endpoint bind failed: address LocalAddressLength cannot be resolved (LocalAddress).

#
Channel
Diagnostic
Task
TcpBindEndpointResolutionFailure

Message #

TCP: endpoint bind failed: address %2 cannot be resolved (%3).

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Event ID 1006: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: port-acquisition status = LocalAddress.

#
Channel
Diagnostic
Level
Error
Task
TcpBindEndpointPortFailure

Message #

TCP: endpoint (sockaddr=%2) bind failed: port-acquisition status = %3.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1006,
    "version": 1,
    "level": 2,
    "task": 1006,
    "opcode": 0,
    "keywords": "0x8000000000000409",
    "time_created": "2026-07-19T03:41:08.856850100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "000B6A50-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 1500,
      "thread_id": 12200
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF800A000B6A50",
    "LocalAddressLength": "16",
    "LocalAddress": "127.0.0.1",
    "Status": "0xC0000043"
  },
  "message": "TCP: endpoint 0xFFFF800A000B6A50 (sockaddr=127.0.0.1) bind failed: port-acquisition status = A file cannot be opened because the share access flags are incompatible.."
}

Event ID 1007: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: inspection status = LocalAddress.

#
Channel
Diagnostic
Task
TcpBindEndpointInspectionFailure

Message #

TCP: endpoint (sockaddr=%2) bind failed: inspection status = %3.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Event ID 1008: TCP: endpoint (sockaddr=LocalAddressLength) bound.

#
Channel
Diagnostic
Level
Informational
Task
TcpBindEndpointComplete

Message #

TCP: endpoint (sockaddr=%2) bound.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1008",
    "version": "1",
    "level": "4",
    "task": "1008",
    "opcode": "0",
    "keywords": 9223372036854776841,
    "time_created": "2026-03-16T00:21:40.119123100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A0DA8A910",
    "LocalAddressLength": "      16",
    "LocalAddress": "0.0.0.0:52999",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1009: TCP: endpoint (sockaddr=LocalAddressLength) closed.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpCloseEndpoint

Message #

TCP: endpoint (sockaddr=%2) closed.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1009",
    "version": "1",
    "level": "4",
    "task": "1009",
    "opcode": "0",
    "keywords": 9223372105574253569,
    "time_created": "2026-03-16T00:21:40.064514900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A15F74B50",
    "LocalAddressLength": "      28",
    "LocalAddress": "::",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1010: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: address family not attached.

#
Channel
Diagnostic
Task
TcpCreateEndpointAfFailure

Message #

TCP: endpoint (Family=%6 PID=%4) create failed: address family not attached.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1011: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: compartment CompartmentId not found.

#
Channel
Diagnostic
Task
TcpCreateEndpointCompartmentFailure

Message #

TCP: endpoint (Family=%6 PID=%4) create failed: compartment %5 not found.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1012: TCP: endpoint (Family=AddressFamily PID=ProcessId) create failed: inspection status Status.

#
Channel
Diagnostic
Task
TcpCreateEndpointInspectionFailure

Message #

TCP: endpoint (Family=%6 PID=%4) create failed: inspection status %3.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1013: TCP: endpoint (Family=CompartmentId PID=Status) created.

#
Channel
Diagnostic
Level
Informational
Task
TcpCreateEndpointComplete

Message #

TCP: endpoint (Family=%6 PID=%4) created.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1013",
    "version": "2",
    "level": "4",
    "task": "1013",
    "opcode": "0",
    "keywords": 9223372036854776833,
    "time_created": "2026-03-16T00:21:40.064333400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A15F74B50",
    "LocalAddressLength": "       0",
    "LocalAddress": "",
    "Status": "0x0",
    "ProcessId": "    3688",
    "CompartmentId": "       1",
    "AddressFamily": "      23",
    "ProcessStartKey": "2814749767106643"
  },
  "message": ""
}

Event ID 1014: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: Route lookup status = Status, TCB = Tcb.

#
Channel
Diagnostic
Task
TcpAccpetListenerRouteLookupFailure

Message #

TCP: listener (local=%2 remote=%4) accept failed: Route lookup status = %5, TCB = %8.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1015: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: connection insertion.

#
Channel
Diagnostic
Task
TcpAcceptListenerInsertionFailure

Description

TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: connection insertion. Duplicate TCB = Tcb.

Message #

TCP: listener (local=%3 remote=%5) accept failed: connection insertion. Duplicate TCB = %1.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1016: TCP: listener (local=LocalAddress remote=RemoteAddress) accept failed: client rejection status = Status.

#
Channel
Diagnostic
Task
TcpAcceptListenerRejected

Message #

TCP: listener (local=%2 remote=%4) accept failed: client rejection status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1017: TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed.

#
Channel
Diagnostic
Level
Informational
Task
TcpAcceptListenerComplete

Description

TCP: listener (local=LocalAddress remote=RemoteAddress) accept completed. TCB = Tcb. PID = ProcessId.

Message #

TCP: listener (local=%2 remote=%4) accept completed. TCB = %8. PID = %6.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1017",
    "version": "1",
    "level": "4",
    "task": "1017",
    "opcode": "0",
    "keywords": 9223372054034646150,
    "time_created": "2026-03-16T00:21:38.720229400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51201",
    "Status": "0x0",
    "ProcessId": "       4",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0EEE7560",
    "ProcessStartKey": "2814749767106561"
  },
  "message": ""
}

Event ID 1018: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: address family not attached.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedAf

Message #

TCP: connection %8 (local=%2 remote=%4 PID=%6) connect failed: address family not attached.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1019: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: compartment Compartment not found.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedCompartment

Message #

TCP: connection %8 (local=%2 remote=%4 PID=%6) connect failed: compartment %7 not found.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1020: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId) connect failed: inspection status = Status.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedInspect

Message #

TCP: connection %8 (local=%2 remote=%4 PID=%6) connect failed: inspection status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1021: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: route lookup status = Status.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedRoute

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: route lookup status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1022: TCP: Bypass rate limiting since flag is set on path Path (local=LocalAddress remote=RemoteAddress).

#
Channel
Diagnostic
Task
TcpConnectTcbSkipRateLimit

Message #

TCP: Bypass rate limiting since flag is set on path %5 (local=%2 remote=%4)

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Path Pointer

Event ID 1023: TCP: Charge rate limiting quota and set rate limiting flag for path Path (local=LocalAddress remote=RemoteAddress).

#
Channel
Diagnostic
Task
TcpConnectTcbPassRateLimit

Message #

TCP: Charge rate limiting quota and set rate limiting flag for path %5 (local=%2 remote=%4)

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Path Pointer

Event ID 1024: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) deferred.

#
Channel
Diagnostic
Task
TcpConnectTcbCheckRateLimit

Message #

TCP: connection %8 (local=%2 remote=%4) deferred.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1025: TCP: ConnectionRateLimitDepth rate-limiting paths ConnectionRateLimitBacklog backlogged connections.

#
Channel
Diagnostic
Task
TcpSecurityRateLimit

Message #

TCP: %6 rate-limiting paths %3 backlogged connections.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1026: TCP: Release and set rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress).

#
Channel
Diagnostic
Task
TcpRateLimitPathRelease

Message #

TCP: Release and set rate limiting flag on path %5 (local=%2 remote=%4)

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Path Pointer

Event ID 1027: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released.

#
Channel
Diagnostic
Task
TcpConnectTcbRateLimitRelease

Message #

TCP: connection %8 (local=%2 remote=%4) released.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1028: TCP: Clear rate limiting flag on path Path (local=LocalAddress remote=RemoteAddress) since connection is cancelled.

#
Channel
Diagnostic
Task
TcpRateLimitPathCancel

Message #

TCP: Clear rate limiting flag on path %5 (local=%2 remote=%4) since connection is cancelled.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Path Pointer

Event ID 1029: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connection cancelled.

#
Channel
Diagnostic
Task
TcpConnectTcbCancel

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: connection cancelled.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1030: TCP: connection (local=LocalAddressLength remote=RemoteAddressLength) connect failed: connection insertion status = RemoteAddress.

#
Channel
Diagnostic
Task
TcpConnectTcbFailInsertion

Message #

TCP: connection (local=%2 remote=%4) connect failed: connection insertion status = %5.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1031: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect proceeding.

#
Channel
Diagnostic
Level
Informational
Task
TcpConnectTcbProceeding

Message #

TCP: connection %8 (local=%2 remote=%4) connect proceeding.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1031",
    "version": "1",
    "level": "4",
    "task": "1031",
    "opcode": "0",
    "keywords": 9223372054034646148,
    "time_created": "2026-03-16T00:21:40.119618200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52999",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "13.89.179.13:443",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A15CE6AE0",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1032: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) released due to cancel.

#
Channel
Diagnostic
Task
TcpConnectTcbRateLimitCancel

Message #

TCP: connection %8 (local=%2 remote=%4) released due to cancel.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1033: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed.

#
Channel
Diagnostic
Level
Informational
Task
TcpConnectTcbComplete

Description

TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect completed. PID = ProcessId.

Message #

TCP: connection %8 (local=%2 remote=%4) connect completed. PID = %6.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1033",
    "version": "1",
    "level": "4",
    "task": "1033",
    "opcode": "0",
    "keywords": 9223372054034646148,
    "time_created": "2026-03-16T00:21:40.246461800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52999",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "13.89.179.13:443",
    "Status": "0x0",
    "ProcessId": "    3688",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A15CE6AE0",
    "ProcessStartKey": "2814749767106643"
  },
  "message": ""
}

Event ID 1034: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect attempt failed with status = Status.

#
Channel
Diagnostic
Level
Error
Task
TcpConnectTcbFailure

Message #

TCP: connection %8 (local=%2 remote=%4) connect attempt failed with status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1034",
    "version": "1",
    "level": "2",
    "task": "1034",
    "opcode": "0",
    "keywords": 9223372054034646148,
    "time_created": "2026-03-15T23:27:04.870761200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{009c52a0-d780-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3912",
      "thread_id": "13412"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::1]:51202",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::1]:389",
    "Status": "0xC0000120",
    "ProcessId": "    3912",
    "Compartment": "       0",
    "Tcb": "0xFFFFD780009C52A0",
    "ProcessStartKey": "3940649673949252"
  },
  "message": ""
}

Event ID 1035: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-complete inspect status = Status.

#
Channel
Diagnostic
Task
TcpConnectTcbFailInspectConnectComplete

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: connect-complete inspect status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1036: TCP: ApplySynOptions, failed to create session state with status = Status, TCB = Tcb.

#
Channel
Diagnostic
Task
TcpConnectTcbFailSessionState

Message #

TCP: ApplySynOptions, failed to create session state with status = %5, TCB = %8.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1037: TCP: ApplySynOptions, failed to update DF with status = Status, TCB = Tcb.

#
Channel
Diagnostic
Task
TcpConnectTcbFailDontFragment

Message #

TCP: ApplySynOptions, failed to update DF with status = %5, TCB = %8.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1038: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) close issued.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpCloseTcbRequest

Message #

TCP: connection %8 (local=%2 remote=%4) close issued.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1038",
    "version": "1",
    "level": "4",
    "task": "1038",
    "opcode": "0",
    "keywords": 9223372105574253572,
    "time_created": "2026-03-16T00:21:38.733239500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7444"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51201",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0EEE7560",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1039: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort issued.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpAbortTcbRequest

Message #

TCP: connection %8 (local=%2 remote=%4) abort issued.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1039",
    "version": "1",
    "level": "4",
    "task": "1039",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-16T00:22:37.889609500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52990",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "52.159.108.190:443",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0E584560",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1040: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) abort completed.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpAbortTcbComplete

Message #

TCP: connection %8 (local=%2 remote=%4) abort completed.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1040",
    "version": "1",
    "level": "4",
    "task": "1040",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-16T00:22:37.890003800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52990",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "52.159.108.190:443",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0E584560",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1041: TCP: Injecting disconnect on a shutdown TCB failed.

#
Channel
Diagnostic
Task
TcpDisconnectTcbInjectFailed

Description

TCP: Injecting disconnect on a shutdown TCB failed. TCB = Tcb.

Message #

TCP: Injecting disconnect on a shutdown TCB failed. TCB = %1.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1042: TCP: connection disconnect Injected, length=Length.

#
Channel
Diagnostic
Level
Informational
Task
TcpDisconnectTcbRequest

Message #

TCP: connection disconnect %3, length=%1.

Fields #

NameDescription
Length Pointer
Timeout UInt64
Injected UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1042",
    "version": "0",
    "level": "4",
    "task": "1042",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-16T00:21:38.732224500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7444"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Length": "0x0",
    "Timeout": "0x0",
    "Injected": "issued"
  },
  "message": ""
}

Event ID 1043: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) disconnect completed.

#
Channel
Diagnostic
Level
Informational
Task
TcpDisconnectTcbComplete

Message #

TCP: connection %8 (local=%2 remote=%4) disconnect completed.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64
Inspect Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1043",
    "version": "1",
    "level": "4",
    "task": "1043",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-16T00:21:38.732982900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51201",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0EEE7560",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1044: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status).

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpShutdownTcb

Description

TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) shutdown initiated (Status). PID = ProcessId.

Message #

TCP: connection %8 (local=%2 remote=%4) shutdown initiated (%5). PID = %6.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1044",
    "version": "1",
    "level": "4",
    "task": "1044",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-16T00:21:38.733255900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7444"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51201",
    "Status": "0xC0000241",
    "ProcessId": "       4",
    "Compartment": "       0",
    "Tcb": "0xFFFF980A0EEE7560",
    "ProcessStartKey": "2814749767106561"
  },
  "message": ""
}

Event ID 1045: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: connect-request timeout expired.

#
Channel
Diagnostic
Task
TcpConnectTcbTimeout

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: connect-request timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1046: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: retransmission timeout expired.

#
Channel
Diagnostic
Level
Informational
Task
TcpDisconnectTcbRtoTimeout

Message #

TCP: connection %8 (local=%2 remote=%4) terminating: retransmission timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1046",
    "version": "1",
    "level": "4",
    "task": "1046",
    "opcode": "0",
    "keywords": 9223372105574253700,
    "time_created": "2026-03-15T23:32:02.749394100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.11:51269",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "10.2.10.21:389",
    "Status": "0x0",
    "ProcessId": "       0",
    "Compartment": "       0",
    "Tcb": "0xFFFFD78FF9CA95F0",
    "ProcessStartKey": "0"
  },
  "message": ""
}

Event ID 1047: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: keep-alive timeout expired.

#
Channel
Diagnostic
Task
TcpDisconnectTcbKeepaliveTimeout

Message #

TCP: connection %8 (local=%2 remote=%4) terminating: keep-alive timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1048: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: disconnect timeout expired.

#
Channel
Diagnostic
Task
TcpDisconnectTcbTimeout

Message #

TCP: connection %8 (local=%2 remote=%4) terminating: disconnect timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1049: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: extended statistics status = Status.

#
Channel
Diagnostic
Task
TcpConnectTcbEstatsFailed

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: extended statistics status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1050: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: port-acquisition status = Status.

#
Channel
Diagnostic
Task
TcpConnectFailedPortAcquire

Message #

TCP: connection %8 (local=%2 remote=%4) connect failed: port-acquisition status = %5.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1051: TCP: connection Tcb transition from OldState to NewState, SndNxt = SndNxt.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpTcbStateChange

Message #

TCP: connection %4 transition from %1 to %2, SndNxt = %3.

Fields #

NameDescription
OldState UInt32
NewState UInt32
SndNxt UInt32
Tcb Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1051",
    "version": "0",
    "level": "4",
    "task": "1051",
    "opcode": "0",
    "keywords": 9223372036854776836,
    "time_created": "2026-03-16T00:21:38.719167800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "OldState": "       1",
    "NewState": "       3",
    "SndNxt": "       0",
    "Tcb": "0xFFFF980A0EEE7560"
  },
  "message": ""
}

Event ID 1052: TCP: Process with PID = ProcessId reserved NumberOfPorts ports starting at StartPort.

#
Channel
Diagnostic
Task
TcpEndpointAcquirePortReservation

Message #

TCP: Process with PID = %1 reserved %4 ports starting at %3.

Fields #

NameDescription
ProcessId UInt32
Status UInt32NTSTATUS reference
StartPort UInt16
NumberOfPorts UInt16
ProcessStartKey UInt64

Event ID 1053: TCP: Process with PID = ProcessId failed to reserve NumberOfPorts ports starting at StartPort with status = Status.

#
Channel
Diagnostic
Task
TcpEndpointFailedPortReservation

Message #

TCP: Process with PID = %1 failed to reserve %4 ports starting at %3 with status = %2.

Fields #

NameDescription
ProcessId UInt32
Status UInt32NTSTATUS reference
StartPort UInt16
NumberOfPorts UInt16
ProcessStartKey UInt64

Event ID 1054: TCP: Process with PID = ProcessId completed global port reservation of NumberOfPorts ports starting at StartPort with status = Status.

#
Channel
Diagnostic
Task
TcpGlobalPortReservation

Message #

TCP: Process with PID = %1 completed global port reservation of %4 ports starting at %3 with status = %2.

Fields #

NameDescription
ProcessId UInt32
Status UInt32NTSTATUS reference
StartPort UInt16
NumberOfPorts UInt16
ProcessStartKey UInt64

Event ID 1055: TCP: entering SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.

#
Channel
Diagnostic
Task
TcpGlobalSynAttackEntry

Message #

TCP: entering SYN attack resistance mode, Syn Attacks Detected = %1.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1056: TCP: reasembly rate-limiting violated ReassemblyLimitViolations times since boot.

#
Channel
Diagnostic
Task
TcpGlobalReassemblyLimitViolation

Message #

TCP: reasembly rate-limiting violated %2 times since boot.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1057: TCP: connection rate-limiting violated ConnectionRateLimitViolations times since boot.

#
Channel
Diagnostic
Task
TcpGlobalConnectionRateLimitViolation

Message #

TCP: connection rate-limiting violated %4 times since boot.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1058: TCP: land attack has dropped LandAttackSegmentsDropped packets since boot.

#
Channel
Diagnostic
Task
TcpGlobalLandAttackSegmentDrop

Message #

TCP: land attack has dropped %5 packets since boot.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1059: TCP: low memory state detected.

#
Channel
Diagnostic
Task
TcpGlobalIsbBeginThrottle

Description

TCP: low memory state detected. LowMemoryEvent =LowMemoryEvent LowPagedPoolEvent = LowPagedPoolEvent.

Message #

TCP: low memory state detected. LowMemoryEvent =%3 LowPagedPoolEvent = %4.

Fields #

NameDescription
HighMemoryEvent UInt32
HighPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowPagedPoolEvent UInt32

Event ID 1060: TCP: leaving low memory state.

#
Channel
Diagnostic
Task
TcpGlobalIsbEndThrottle

Description

TCP: leaving low memory state. HighMemoryEvent = HighMemoryEvent HighPagedPoolEvent = HighPagedPoolEvent.

Message #

TCP: leaving low memory state. HighMemoryEvent = %1 HighPagedPoolEvent = %2.

Fields #

NameDescription
HighMemoryEvent UInt32
HighPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowPagedPoolEvent UInt32

Event ID 1061: TCP: address family AddressFamily added to interface InterfaceIndex.

#
Channel
Diagnostic
Task
TcpGlobalAddInterface

Message #

TCP: address family %2 added to interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt32

Event ID 1062: TCP: address family AddressFamily removed from interface InterfaceIndex.

#
Channel
Diagnostic
Task
TcpGlobalDeleteInterface

Message #

TCP: address family %2 removed from interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt32

Event ID 1063: TCP: leaving SYN attack resistance mode, Syn Attacks Detected = SynAttacksDetected.

#
Channel
Diagnostic
Task
TcpGlobalSynAttackExit

Message #

TCP: leaving SYN attack resistance mode, Syn Attacks Detected = %1.

Fields #

NameDescription
SynAttacksDetected UInt32
ReassemblyLimitViolations UInt32
ConnectionRateLimitBacklog UInt32
ConnectionRateLimitViolations UInt32
LandAttackSegmentsDropped UInt32
ConnectionRateLimitDepth UInt32

Event ID 1064: TCP: Connection Tcb TimerType timer started.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpTcbStartTimer

Description

TCP: Connection Tcb TimerType timer started. Scheduled to expire in WaitTimeMilliseconds ms.

Message #

TCP: Connection %1 %2 timer started. Scheduled to expire in %3 ms.

Fields #

NameDescription
Tcb Pointer
TimerType UInt32
WaitTimeMilliseconds UInt32
Processor UInt32
LastInterruptTime UInt64
LastMicroseconds UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1064",
    "version": "1",
    "level": "5",
    "task": "1064",
    "opcode": "0",
    "keywords": 9223372036854776836,
    "time_created": "2026-03-16T00:21:34.388854500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "TimerType": "       0",
    "WaitTimeMilliseconds": "     201",
    "Processor": "       9",
    "LastInterruptTime": "577532689097",
    "LastMicroseconds": "57753289800",
    "CachedKQPCValues": "577532898003",
    "CachedFrequencyValues": "10000000"
  },
  "message": ""
}

Example keys not documented in the fields table: CachedFrequencyValues, CachedKQPCValues

Event ID 1065: TCP: Connection Tcb stopping TimerType timer.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpTcbStopTimer

Message #

TCP: Connection %1 stopping %2 timer.

Fields #

NameDescription
Tcb Pointer
TimerType UInt32
WaitTimeMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1065",
    "version": "0",
    "level": "5",
    "task": "1065",
    "opcode": "0",
    "keywords": 9223372036854776836,
    "time_created": "2026-03-16T00:21:34.388747900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "TimerType": "       7",
    "WaitTimeMilliseconds": "       0"
  },
  "message": ""
}

Event ID 1066: TCP: Connection Tcb TimerType timer has expired.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpTcbExpireTimer

Message #

TCP: Connection %1 %2 timer has expired.

Fields #

NameDescription
Tcb Pointer
TimerType UInt32
WaitTimeMilliseconds UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1066",
    "version": "0",
    "level": "5",
    "task": "1066",
    "opcode": "0",
    "keywords": 9223372036854776836,
    "time_created": "2026-03-16T00:21:34.715526000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "TimerType": "       2",
    "WaitTimeMilliseconds": "       0"
  },
  "message": ""
}

Event ID 1067: TCP: ISB changed to IsbSize.

#
Channel
Diagnostic
Level
Informational
Task
TcpTcbChangeIsb

Description

TCP: ISB changed to IsbSize. CWnd = Cwnd SndWnd = SndWnd SendAvailable = SendAvailable SSThresh = SSThresh.

Message #

TCP: ISB changed to %1. CWnd = %2 SndWnd = %3 SendAvailable = %4 SSThresh = %5.

Fields #

NameDescription
IsbSize UInt32
Cwnd UInt32
SndWnd UInt32
SendAvailable UInt32
SSThresh UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1067,
    "version": 0,
    "level": 4,
    "task": 1067,
    "opcode": 0,
    "keywords": "0x8000000000000484",
    "time_created": "2026-07-19T03:41:10.078122300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "10129010-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IsbSize": "131072",
    "Cwnd": "72624",
    "SndWnd": "4194560",
    "SendAvailable": "66815",
    "SSThresh": "4294967295"
  },
  "message": "TCP: ISB changed to 131072. CWnd = 72624 SndWnd = 4194560 SendAvailable = 66815 SSThresh = 4294967295."
}

Event ID 1068: TCP: moving RSS indirection table index TableEntry from processor SourceProcessor to processor DestinationProcessor.

#
Channel
Diagnostic
Task
TcpRssTableChange

Message #

TCP: moving RSS indirection table index %6 from processor %1 to processor %3.

Fields #

NameDescription
SourceProcessor UInt32
SourceActivity UInt32
DestinationProcessor UInt32
DestinationActivity UInt32
PartitionMovesRemaining UInt32
TableEntry UInt8

Event ID 1069: TCP: connection Tcb: Timeout Event updated cwnd = Cwnd and updated ssthresh = SSThresh.

#
Channel
Diagnostic
Task
TcpDataTransferTimeout

Message #

TCP: connection %1: Timeout Event updated cwnd = %2 and updated ssthresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1070: TCP: connection Tcb: Rtt sample recorded RttSample.

#
Channel
Diagnostic
Task
TcpDataTransferRttSample

Message #

TCP: connection %1:  Rtt sample recorded %4.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1071: TCP: connection Tcb: Cumulative ACK updated cwnd = Cwnd.

#
Channel
Diagnostic
Task
TcpDataTransferCumAck

Message #

TCP: connection %1: Cumulative ACK updated cwnd = %2.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1072: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh.

#
Channel
Diagnostic
Task
TcpDataTransferDupAck

Message #

TCP: connection %1: Duplicate ACK updated cwnd = %2 and updated ssthresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1073: TCP: connection Tcb: Sent data with number of bytes = NumBytes and Sequence number = SeqNo.

#
Channel
Diagnostic
Task
TcpDataTransferSend

Message #

TCP: connection %1: Sent data with number of bytes = %5 and Sequence number = %6.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1074: TCP: connection Tcb: Received data with number of bytes = NumBytes.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpDataTransferReceive

Description

TCP: connection Tcb: Received data with number of bytes = NumBytes. ThSeq = SeqNo.

Message #

TCP: connection %1: Received data with number of bytes = %2. ThSeq = %3.

Fields #

NameDescription
Tcb Pointer
NumBytes UInt32
SeqNo UInt32
NumPkt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1074",
    "version": "0",
    "level": "4",
    "task": "1074",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:34.390777500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "NumBytes": "       6",
    "SeqNo": "3537939053"
  },
  "message": ""
}

Event ID 1075: TCP: connection Tcb: ECN Echo updated cwnd = Cwnd and updated ssthresh = SSThresh.

#
Channel
Diagnostic
Task
TcpDataTransferEcn

Description

TCP: connection Tcb: ECN Echo updated cwnd = Cwnd and updated ssthresh = SSThresh. SndUna = SndUna, Mss = Mss, ThAck = ThAck.

Message #

TCP: connection %1: ECN Echo updated cwnd = %2 and updated ssthresh = %3. SndUna = %4, Mss = %5, ThAck = %6.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
SndUna UInt32
Mss UInt32
ThAck UInt32
DWnd UInt32
BaseRtt UInt32

Event ID 1076: TCP: connection Tcb: Spurious timeout with SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpDataTransferSpuriousTimeout

Message #

TCP: connection %1: Spurious timeout with SndUna = %7.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1077: TCP: connection Tcb: Send Retransmit round with SndUna = SeqNo, Round = Round, SRTT = SRTT, RTO = RTO.

#
Channel
Diagnostic
Task
TcpDataTransferRetransmitRound

Message #

TCP: connection %1: Send Retransmit round with SndUna = %6, Round = %8, SRTT = %9, RTO = %10.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1078: TCP: connection Tcb: Entered loss recovery phase with SndUna = SndUna and SndMax = SndMax.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoveryEntry

Message #

TCP: connection %1: Entered loss recovery phase with SndUna = %2 and SndMax = %3.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1078",
    "version": "0",
    "level": "4",
    "task": "1078",
    "opcode": "0",
    "keywords": 9223372045444710528,
    "time_created": "2026-03-16T00:21:40.489867400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "SndUna": "155002622",
    "SndMax": "155007102"
  },
  "message": ""
}

Event ID 1079: TCP: connection Tcb: Leaving loss recovery phase with SndUna = SndUna and SndMax = SndMax.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoveryExit

Message #

TCP: connection %1: Leaving loss recovery phase with SndUna = %2 and SndMax = %3.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1079",
    "version": "0",
    "level": "4",
    "task": "1079",
    "opcode": "0",
    "keywords": 9223372045444710528,
    "time_created": "2026-03-16T00:21:40.494494300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6656"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "SndUna": "155007102",
    "SndMax": "155007102"
  },
  "message": ""
}

Event ID 1080: TCP: connection Tcb entering SACK mode with SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpLossRecoverySackEntry

Message #

TCP: connection %1 entering SACK mode with SndUna = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Reason UnicodeString
IsSack UInt32

Event ID 1081: TCP: connection Tcb leaving SACK mode with SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpLossRecoverySackExit

Message #

TCP: connection %1 leaving SACK mode with SndUna = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Reason UnicodeString
IsSack UInt32

Event ID 1082: TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.

#
Channel
Diagnostic
Task
TcpSlowStartToCongestionAvoidance

Message #

TCP: connection %1 entering Congestion Avoidance Phase with cwnd = %2 and ssthresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1084: TCP: connection Tcb entered BH, BH MSS BHMSS, original MSS OriginalMSS.

#
Channel
Diagnostic
Task
TcpBlackHoleDetectionEntry

Message #

TCP: connection %1 entered BH, BH MSS %2, original MSS %3.

Fields #

NameDescription
Tcb Pointer
BHMSS UInt32
OriginalMSS UInt32
TraceString UnicodeString

Event ID 1085: TCP: connection Tcb Exiting BH due to TraceString, BH mss BHMSS, Original MSS OriginalMSS.

#
Channel
Diagnostic
Task
TcpBlackHoleDetectionExit

Message #

TCP: connection %1 Exiting BH due to %4, BH mss %2, Original MSS %3.

Fields #

NameDescription
Tcb Pointer
BHMSS UInt32
OriginalMSS UInt32
TraceString UnicodeString

Event ID 1086: TCP: connection Tcb not entering BH due to TraceString.

#
Channel
Diagnostic
Task
TcpBlackHoleDetectionFailed

Message #

TCP: connection %1 not entering BH due to %4.

Fields #

NameDescription
Tcb Pointer
BHMSS UInt32
OriginalMSS UInt32
TraceString UnicodeString

Event ID 1087: TCP: connection Tcb spurious RTO detection initiated at SndUna.

#
Channel
Diagnostic
Task
TcpSpuriousRtoDetectionBegin

Message #

TCP: connection %1 spurious RTO detection initiated at %7.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1088: TCP: connection Tcb spurious RTO detection terminated at SndUna.

#
Channel
Diagnostic
Task
TcpSpuriousRtoDetectionEnd

Message #

TCP: connection %1 spurious RTO detection terminated at %7.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1089: TCP: active connect failed (family=Status) connect-complete inspection failed: status = AddressFamily.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedActiveConnect

Message #

TCP: active connect failed (family=%2) connect-complete inspection failed: status = %3.

Fields #

NameDescription
Tcb Pointer
Status UInt32NTSTATUS reference
AddressFamily UInt32

Event ID 1090: TCP: TcpReleaseIndicationList: Nbl = NBL.

#
Channel
Diagnostic
Level
Verbose
Task
TcpReleaseIndication

Message #

TCP: TcpReleaseIndicationList: Nbl = %1.

Fields #

NameDescription
NBL Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1090",
    "version": "0",
    "level": "5",
    "task": "1090",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:34.509548500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NBL": "0xFFFF980A0EE312B0"
  },
  "message": ""
}

Event ID 1091: TCP: connection Tcb posted an average of NumBytes bytes per send.

#
Channel
Diagnostic
Task
TcpAppSendBufferSize

Message #

TCP: connection %1 posted an average of %5 bytes per send.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1092: TCP: connection (local=LocalAddress remote=RemoteAddress) starting receive window auto-tuning.

#
Channel
Diagnostic
Level
Verbose
Task
TcpAutoTuningBegin

Message #

TCP: connection (local=%2 remote=%4) starting receive window auto-tuning.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1092",
    "version": "0",
    "level": "5",
    "task": "1092",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:40.316699400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52999",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "13.89.179.13:443",
    "BufferSize": "       0"
  },
  "message": ""
}

Event ID 1093: TCP: connection (local=LocalAddress remote=RemoteAddress) ending receive window auto-tuning.

#
Channel
Diagnostic
Level
Verbose
Task
TcpAutoTuningEnd

Message #

TCP: connection (local=%2 remote=%4) ending receive window auto-tuning.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1093",
    "version": "0",
    "level": "5",
    "task": "1093",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:22:31.341328500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e7ae010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51208",
    "BufferSize": "       0"
  },
  "message": ""
}

Event ID 1094: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because fine-grained RTT estimation could not be started.

#
Channel
Diagnostic
Task
TcpAutoTuningFailedRttEstimation

Message #

TCP: connection (local=%2 remote=%4) failed to enter auto-tuning because fine-grained RTT estimation could not be started.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Event ID 1095: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because receiver bandwidth estimation could not be started.

#
Channel
Diagnostic
Task
TcpAutoTuningFailedBandwidthEstimation

Message #

TCP: connection (local=%2 remote=%4) failed to enter auto-tuning because receiver bandwidth estimation could not be started.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Event ID 1096: TCP: connection (local=LocalAddress remote=RemoteAddress) failed to enter auto-tuning because of receive window tuning allocation failure.

#
Channel
Diagnostic
Task
TcpAutoTuningFailedAllocationFailure

Message #

TCP: connection (local=%2 remote=%4) failed to enter auto-tuning because of receive window tuning allocation failure.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Event ID 1097: TCP: connection (local=LocalAddress remote=RemoteAddress) auto-tuner adjusted receive buffer size to BufferSize bytes.

#
Channel
Diagnostic
Level
Informational
Task
TcpAutoTuningChangeRcvBufferSize

Message #

TCP: connection (local=%2 remote=%4) auto-tuner adjusted receive buffer size to %5 bytes.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
BufferSize UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1097,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 05:24:10.173Z",
    "version": 0
  },
  "event_data": {
    "BufferSize": 525920,
    "LocalAddress": "0200EE330A020A150000000000000000",
    "LocalAddressLength": 16,
    "RemoteAddress": "020001BB17D43E900000000000000000",
    "RemoteAddressLength": 16
  },
  "message": ""
}

Event ID 1098: TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.

#
Channel
Diagnostic
Task
TcpRttResiliencyDetection

Message #

TCP: connection %1: Rtt resiliency detection complete with Rtt sample = %4 and new SRTT = %9.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1099: TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState.

#
Channel
Diagnostic
Task
TcpConnectionOffloadStateChange

Description

TCP: connection Tcb: Connection State = TcbState, Offload State = OcbState. SndNxt = SndNxt, RcvNxt = RcvNxt. NdisStatus = Status.

Message #

TCP: connection %5: Connection State = %1, Offload State = %2. SndNxt = %3, RcvNxt = %4. NdisStatus = %6.

Fields #

NameDescription
TcbState UInt32
OcbState UInt32
SndNxt UInt32
RcvNxt UInt32
Tcb Pointer
Status UInt32NTSTATUS reference

Event ID 1100: TCP: SWS avoidance began on connection Tcb.

#
Channel
Diagnostic
Level
Informational
Task
TcpSwsAvoidanceBegin

Description

TCP: SWS avoidance began on connection Tcb. Timer set for TimerValue ms. BytesToSend = BytesToSend, SendAvailable = SendAvailable, Cwnd = Cwnd, MaxSndWnd = MaxSndWnd.

Message #

TCP: SWS avoidance began on connection %1. Timer set for %2 ms. BytesToSend = %3, SendAvailable = %4, Cwnd = %5, MaxSndWnd = %6.

Fields #

NameDescription
Tcb Pointer
TimerValue UInt32
BytesToSend Pointer
SendAvailable UInt32
Cwnd UInt32
MaxSndWnd Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1100",
    "version": "0",
    "level": "4",
    "task": "1100",
    "opcode": "0",
    "keywords": 9223372041149743232,
    "time_created": "2026-03-16T00:23:27.100938500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "10580"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A170D1290",
    "TimerValue": "    5000",
    "BytesToSend": "0x10E0",
    "SendAvailable": "   18500",
    "Cwnd": "   14786",
    "MaxSndWnd": "0x400000"
  },
  "message": ""
}

Event ID 1101: TCP: SWS avoidance ended on connection Tcb.

#
Channel
Diagnostic
Task
TcpSwsAvoidanceEnd

Message #

TCP: SWS avoidance ended on connection %1.

Fields #

NameDescription
Tcb Pointer
TimerValue UInt32
BytesToSend Pointer
SendAvailable UInt32
Cwnd UInt32
MaxSndWnd Pointer

Event ID 1102: TCP: connection Tcb send: Beginning zero-window probing with SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpZeroWindowProbingBegin

Message #

TCP: connection %1 send: Beginning zero-window probing with SndUna = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Event ID 1103: TCP: connection Tcb send: Leaving zero-window probing with SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpZeroWindowProbingEnd

Message #

TCP: connection %1 send: Leaving zero-window probing with SndUna = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Event ID 1104: TCP: Option OptionType is going to be set for connection Tcb.

#
Channel
Diagnostic
Level
Informational
Task
TcpSetTcpOption

Message #

TCP: Option %2 is going to be set for connection %1.

Fields #

NameDescription
Tcb Pointer
OptionType UInt32
SoOptionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1104",
    "version": "0",
    "level": "4",
    "task": "1104",
    "opcode": "0",
    "keywords": 9223372311732683780,
    "time_created": "2026-03-16T00:23:28.314606700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "1356",
      "thread_id": "4456"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0E584560",
    "OptionType": "       1",
    "SoOptionType": "       0"
  },
  "message": ""
}

Event ID 1105: TCP: Socket Option SoOptionType is going to be set for connection Tcb.

#
Channel
Diagnostic
Level
Informational
Task
TcpSetTcpSoOption

Message #

TCP: Socket Option %3 is going to be set for connection %1.

Fields #

NameDescription
Tcb Pointer
OptionType UInt32
SoOptionType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1105",
    "version": "0",
    "level": "4",
    "task": "1105",
    "opcode": "0",
    "keywords": 9223372311732683780,
    "time_created": "2026-03-16T00:23:28.314680700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "1356",
      "thread_id": "4456"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0E584560",
    "OptionType": "       0",
    "SoOptionType": "       8"
  },
  "message": ""
}

Event ID 1106: IP: Disconnecting interface InterfaceIndex, trace = TraceString.

#
Channel
Diagnostic
Task
TcpMediaDisconnect

Message #

IP: Disconnecting interface %1, trace = %2.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1107: TCPIP: Module ModuleNameString started.

#
Channel
Diagnostic
Task
TcpModuleStarted

Message #

TCPIP: Module %1 started.

Fields #

NameDescription
ModuleNameString UnicodeString

Event ID 1108: TCPIP: Module ModuleNameString stopped.

#
Channel
Diagnostic
Task
TcpModuleStopped

Message #

TCPIP: Module %1 stopped.

Fields #

NameDescription
ModuleNameString UnicodeString

Event ID 1109: TCPIP: Failure allocating AllocationObjectString.

#
Channel
Diagnostic
Task
TcpMemoryFailures

Message #

TCPIP: Failure allocating %1.

Fields #

NameDescription
AllocationObjectString UnicodeString

Event ID 1110: TCP: Global parameters updated for Address Family AddressFamily: EnablePMtuDiscovery = EnablePMTUDiscovery, UseRfc1122UrgentPointer = TcpUseRFC1122UrgentPointer, DisableTaskOffload = DisableTaskOff...

#
Channel
Diagnostic
Task
TcpGlobalParameters

Description

TCP: Global parameters updated for Address Family AddressFamily: EnablePMtuDiscovery = EnablePMTUDiscovery, UseRfc1122UrgentPointer = TcpUseRFC1122UrgentPointer, DisableTaskOffload = DisableTaskOffload, DisableTcpChimneyOffload = EnablePMTUBHDetect, DisableRss = DisableTcpChimneyOffload, EnablePMtuBHDetect = DisableRss, EcnCapability = EcnCapability, MaxDataRetransmissions = TcpMaxDataRetransmissions, KeepAliveTime = KeepAliveTime, KeepAliveInterval = KeepAliveInterval, TimedWaitDelay = TcpTimedWaitDelay, SillyWindowTimeout = SillyWindowTimeout, FinWait2Timeout = TcpFinWait2Delay, CongestionAlgorithm = CongestionAlgorithm, UseRfc1323Timestamps = Tcp1323Opts, AutoTuningLevelLocal = AutoTuningLevelLocal, AutoTuningLevelGroupPolicy = AutoTuningLevelGroupPolicy.

Message #

TCP: Global parameters updated for Address Family %1: EnablePMtuDiscovery = %2, UseRfc1122UrgentPointer = %3, DisableTaskOffload = %4, DisableTcpChimneyOffload = %5, DisableRss = %6, EnablePMtuBHDetect = %7, EcnCapability = %8, MaxDataRetransmissions = %9, KeepAliveTime = %10, KeepAliveInterval = %11, TimedWaitDelay = %12, SillyWindowTimeout = %13, FinWait2Timeout = %14, CongestionAlgorithm = %15, UseRfc1323Timestamps = %16, AutoTuningLevelLocal = %17, AutoTuningLevelGroupPolicy = %18.

Fields #

NameDescription
AddressFamily UInt32
EnablePMTUDiscovery UInt8
TcpUseRFC1122UrgentPointer UInt8
DisableTaskOffload UInt8
EnablePMTUBHDetect UInt8
DisableTcpChimneyOffload UInt8
DisableRss UInt8
EcnCapability UInt8
TcpMaxDataRetransmissions UInt8
KeepAliveTime UInt32
KeepAliveInterval UInt32
TcpTimedWaitDelay UInt32
SillyWindowTimeout UInt32
TcpFinWait2Delay UInt32
CongestionAlgorithm UInt8
Tcp1323Opts UInt8
AutoTuningLevelLocal UInt32
AutoTuningLevelGroupPolicy UInt32

Event ID 1111: TCP: Connection Tcb Large Send Offload, Bytes in segment = BytesInSegment and Bytes remaining = BytesRemaining.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpLso

Message #

TCP: Connection %1 Large Send Offload, Bytes in segment = %2 and Bytes remaining = %3.

Fields #

NameDescription
Tcb Pointer
BytesInSegment UInt32
BytesRemaining UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1111",
    "version": "0",
    "level": "5",
    "task": "1111",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.415610100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6972"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "BytesInSegment": "    1492",
    "BytesRemaining": "       0"
  },
  "message": ""
}

Event ID 1112: TCP: Connection Tcb status changed to Status.

#
Channel
Diagnostic
Task
TcpConnectionOffloadStatus

Message #

TCP: Connection %1 status changed to %2.

Fields #

NameDescription
Tcb Pointer
Status UInt32NTSTATUS reference
Interface UInt32
PMax UInt32

Event ID 1113: TCP: Connection Tcb status = Status, Interface = Interface, PMax = PMax.

#
Channel
Diagnostic
Task
TcpConnectionOffloadPmax

Message #

TCP: Connection %1 status = %2, Interface = %3, PMax = %4.

Fields #

NameDescription
Tcb Pointer
Status UInt32NTSTATUS reference
Interface UInt32
PMax UInt32

Event ID 1114: IP: DAD successful for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.

#
Channel
Diagnostic
Task
IpDadSuccessful

Message #

IP: DAD successful for IP address = %7 %9 %8 on interface = %1, protocol = %2.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CompartmentId UInt32

Event ID 1115: IP: DAD failed for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, DL address of packet = DLAddress.

#
Channel
Diagnostic
Task
IpDadFailed

Message #

IP: DAD failed for IP address = %7 %9 %8 on interface = %1, protocol = %2, DL address of packet = %5.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CompartmentId UInt32

Event ID 1116: IP: DAD started for IP address = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol.

#
Channel
Diagnostic
Task
IpDadStarted

Message #

IP: DAD started for IP address = %7 %9 %8 on interface = %1, protocol = %2.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CompartmentId UInt32

Event ID 1117: TCP: listener (sockaddr=SocketAddress PID=ProcessId) activation failed: address family not attached.

#
Channel
Diagnostic
Task
TcpListenerActivationFailedAf

Message #

TCP: listener (sockaddr=%3 PID=%5) activation failed: address family not attached.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1118: TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found.

#
Channel
Diagnostic
Task
TcpListenerActivationFailedCompartment

Description

TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: compartment CompartmentId not found. Status=Status.

Message #

TCP: listener %1 (family=%7 PID=%5) activation failed: compartment %6 not found. Status=%4.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1119: TCP: listener Listener (family=AddressFamily PID=ProcessId) activation failed: inspection status=Status.

#
Channel
Diagnostic
Task
TcpListenerActivationFailedInspection1

Message #

TCP: listener %1 (family=%7 PID=%5) activation failed: inspection status=%4.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1120: TCP: listener Listener (sockaddr=SocketAddress) activation failed: inspection status=Status.

#
Channel
Diagnostic
Task
TcpListenerActivationFailedInspection2

Message #

TCP: listener %1 (sockaddr=%3) activation failed: inspection status=%4.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1121: TCP: listener Listener (sockaddr=SocketAddress) bind failed: port-acquisition status=Status.

#
Channel
Diagnostic
Task
TcpListenerBindFailedResolution

Message #

TCP: listener %1 (sockaddr=%3) bind failed: port-acquisition status=%4.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1122: TCP: listener Listener (family=AddressFamily PID=ProcessId) bind failed: address SocketAddress cannot be resolved (Status=Status).

#
Channel
Diagnostic
Task
TcpListenerBindFailedPort

Message #

TCP: listener %1 (family=%7 PID=%5) bind failed: address %3 cannot be resolved (Status=%4).

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1123: TCP: listener Listener (sockaddr=SocketAddress) activated.

#
Channel
Diagnostic
Task
TcpListenerActivated

Message #

TCP: listener %1 (sockaddr=%3) activated.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "",
    "event_source_name": "",
    "event_id": 1123,
    "version": 1,
    "level": 0,
    "task": 0,
    "opcode": 0,
    "keywords": 0,
    "time_created": "2026-07-19T02:32:42.819+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "05564E70-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 3180,
      "thread_id": 4700
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressFamily": 0,
    "AddressLength": 16,
    "CompartmentId": 0,
    "Listener": "0xFFFF800A05564E70",
    "ProcessId": 3180,
    "ProcessStartKey": 8725724278041289,
    "SocketAddress": "0200F72B7F0000010000000000000000",
    "Status": 0
  },
  "message": ""
}

Event ID 1124: TCP: listener Listener (sockaddr=SocketAddress) unbound.

#
Channel
Diagnostic
Task
TcpListenerUnbound

Message #

TCP: listener %1 (sockaddr=%3) unbound.

Fields #

NameDescription
Listener Pointer
AddressLength UInt32
SocketAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1127: IP: IP address = IPv4Address IPProtocol IPv6Address added on interface = Interface, Protocol = Protocol.

#
Channel
Diagnostic
Task
IpAddressAdded

Message #

IP: IP address = %7 %9 %8 added on interface = %1, Protocol = %2.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CompartmentId UInt32
PrefixOrigin UInt32
SuffixOrigin UInt32

Event ID 1128: IP: IP address = IPv4Address IPProtocol IPv6Address deleted on interface = Interface, Protocol = Protocol.

#
Channel
Diagnostic
Task
IpAddressDeleted

Message #

IP: IP address = %7 %9 %8 deleted on interface = %1, Protocol = %2.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CompartmentId UInt32

Event ID 1130: Framing: Interface operation status change.

#
Channel
Diagnostic
Task
FramingIfOperStatus

Description

Framing: Interface Interface Operational Status = OperationalStatus, Operational Status Flags = Status.

Message #

Framing: Interface %1 Operational Status = %2, Operational Status Flags = %3.

Fields #

NameDescription
Interface UInt32
OperationalStatus UInt32
Status UInt64NTSTATUS reference
CompartmentId UInt32

Event ID 1136: Framing: NDIS pause event on interface InterfaceIndex.

#
Channel
Diagnostic
Task
FramingNdisPause

Message #

Framing: NDIS pause event on interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1137: Framing: NDIS restart event on interface InterfaceIndex.

#
Channel
Diagnostic
Task
FramingNdisRestart

Message #

Framing: NDIS restart event on interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1138: IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred.

#
Channel
Diagnostic
Task
IpAddressStatePreferred

Description

IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Preferred. Interface = Interface.

Message #

IP: IP address = %7 %9 %8 state changed to Preferred. Interface = %1.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32

Event ID 1139: IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred.

#
Channel
Diagnostic
Task
IpAddressStateNonPreferred

Description

IP: IP address = IPv4Address IPProtocol IPv6Address state changed to Non-preferred. Interface = Interface. DadState = DadState.

Message #

IP: IP address = %7 %9 %8 state changed to Non-preferred. Interface = %1. DadState = %3.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DadState UInt32
DlAddrLength UInt32
DLAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32

Event ID 1144: IP: Interface Interface property change.

#
Channel
Diagnostic
Task
IpInterfacePropertyChange

Description

IP: Interface Interface property change. Advertise= Advertise, AdvertiseDefaultRoute = AdvertiseDefaultRoute, Forward = Forward, ForwardMulticast = ForwardMulticast, UseNud = UseNud, AdvertisingEnabled = AdvertisingEnabled.

Message #

IP: Interface %1 property change. Advertise= %2, AdvertiseDefaultRoute = %3, Forward = %4, ForwardMulticast = %5, UseNud = %6, AdvertisingEnabled = %7.

Fields #

NameDescription
Interface UInt32
Advertise UInt32
AdvertiseDefaultRoute UInt32
Forward UInt32
ForwardMulticast UInt32
UseNud UInt32
AdvertisingEnabled UInt32
WeakHostSend UInt32
WeakHostReceive UInt32
CompartmentId UInt32
AddressFamily UInt32
StrictSourceForwarding UInt32

Event ID 1145: IP: Route Route created on interface Interface.

#
Channel
Diagnostic
Task
IpRouteCreated

Description

IP: Route Route created on interface Interface. Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime.

Message #

IP: Route %1 created on interface %2. Protocol = %5, DestinationPrefix = %16 %18 %7 /%6, Nexthop = %17 %18 %8, ValidLifetime = %9, PreferredLifetime = %10.

Fields #

NameDescription
Route Pointer
Interface UInt32
CompartmentId UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
DestinationPrefixLength UInt32
ValidLifetime UInt64
PreferredLifetime UInt64
Metric UInt32
Loopback UInt32
AutoconfigureAddress UInt32
Publish UInt32
Immortal UInt32
IPUnicastroutedeletionreason UInt32

Event ID 1146: IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 Destinatio...

#
Channel
Diagnostic
Task
IpRouteDeleted

Description

IP: Route Route deleted on interface Interface, Protocol = DestinationPrefix, DestinationPrefix = IPUnicastroutedeletionreason %18 NextHopAddress /NextHopAddressLength, Nexthop = %17 %18 DestinationPrefixLength, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Reason = %19.

Message #

IP: Route %1 deleted on interface %2, Protocol = %5, DestinationPrefix = %16 %18 %7 /%6, Nexthop = %17 %18 %8, ValidLifetime = %9, PreferredLifetime = %10, Reason = %19.

Fields #

NameDescription
Route Pointer
Interface UInt32
CompartmentId UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
DestinationPrefixLength UInt32
ValidLifetime UInt64
PreferredLifetime UInt64
Metric UInt32
Loopback UInt32
AutoconfigureAddress UInt32
Publish UInt32
Immortal UInt32
IPUnicastroutedeletionreason UInt32

Event ID 1147: IP: Route Route property change.

#
Channel
Diagnostic
Task
IpRoutePropertyChange

Description

IP: Route Route property change. Interface = Interface, Compartment = CompartmentId, DestinationPrefix = DestinationPrefix/DestinationPrefixLength, Nexthop = NextHopAddress. Properties: ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Metric = Metric, Loopback = Loopback, AutoconfigureAddress = AutoconfigureAddress, Publish = Publish, Immortal = Immortal.

Message #

IP: Route %1 property change. Interface = %2, Protocol = %5, DestinationPrefix = %16 %18 %7 /%6, Nexthop = %17 %18 %8. Properties: ValidLifetime = %9, PreferredLifetime = %10, Metric = %11, Loopback = %12, AutoconfigureAddress = %13, Publish = %14, Immortal = %15.

Fields #

NameDescription
Route Pointer
Interface UInt32
CompartmentId UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
DestinationPrefixLength UInt32
ValidLifetime UInt64
PreferredLifetime UInt64
Metric UInt32
Loopback UInt32
AutoconfigureAddress UInt32
Publish UInt32
Immortal UInt32
IPUnicastroutedeletionreason UInt32

Event ID 1148: IP: Neighbor unreachable.

#
Channel
Diagnostic
Task
IpNeighborUnreachable

Description

IP: Neighbor unreachable. Interface Interface, IP address = IPv4Address IPProtocol IPv6Address.

Message #

IP: Neighbor unreachable. Interface %1, IP address = %5 %7 %6.

Fields #

NameDescription
Interface UInt32
DlAddrLength UInt32
DlAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32

Event ID 1149: IP: Neighbor reachable.

#
Channel
Diagnostic
Task
IpNeighborReachable

Description

IP: Neighbor reachable. Interface Interface, IP address = IPv4Address IPProtocol IPv6Address, DlAddress = DlAddress.

Message #

IP: Neighbor reachable. Interface %1, IP address = %5 %7 %6, DlAddress = %3.

Fields #

NameDescription
Interface UInt32
DlAddrLength UInt32
DlAddress Binary
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32

Event ID 1150: TCP: CTCP DataTransferTimeout event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferTimeout

Description

TCP: CTCP DataTransferTimeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.

Message #

TCP: CTCP DataTransferTimeout event. Connection %1, CWnd = %2, SsThresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1151: TCP: CTCP Cumulative Ack event Connection Tcb, sequence = SeqNo, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferCumAck

Message #

TCP: CTCP Cumulative Ack event Connection %1, sequence = %6, CWnd = %2, DWnd = %11, BaseRtt = %12.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1152: TCP: CTCP Duplicate Ack event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferDupAck

Description

TCP: CTCP Duplicate Ack event. Connection Tcb, sequence = SeqNo, SndUna = SndUna, CWnd = Cwnd, DWnd = DWnd, BaseRtt = BaseRtt, DupAckCount = DupAckCount.

Message #

TCP: CTCP Duplicate Ack event. Connection %1, sequence = %6, SndUna = %7, CWnd = %2, DWnd = %11, BaseRtt = %12, DupAckCount = %13.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1153: TCP: CTCP Send event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferSend

Description

TCP: CTCP Send event. Connection Tcb, sequence = SeqNo, length = NumBytes.

Message #

TCP: CTCP Send event. Connection %1, sequence = %6, length = %5.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1154: TCP: CTCP ECN event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferEcn

Description

TCP: CTCP ECN event. Connection Tcb, CWnd Cwnd, SndUna = SndUna, Mss = Mss, DWnd = DWnd, BaseRtt = BaseRtt.

Message #

TCP: CTCP ECN event. Connection %1, CWnd %2, SndUna = %4, Mss = %5, DWnd = %7, BaseRtt = %8.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
SndUna UInt32
Mss UInt32
ThAck UInt32
DWnd UInt32
BaseRtt UInt32

Event ID 1155: TCP: CTCP Spurious timeout event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferSpuriousTimeout

Description

TCP: CTCP Spurious timeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.

Message #

TCP: CTCP Spurious timeout event. Connection %1, CWnd = %2, SsThresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
RttSample UInt32
NumBytes UInt32
SeqNo UInt32
SndUna UInt32
Round UInt32
SRTT UInt32
RTO UInt32
DWnd UInt32
BaseRtt UInt32
DupAckCount UInt32

Event ID 1156: TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags.

#
Channel
Diagnostic
Level
Informational
Task
TcpReceiveRequest

Description

TCP: connection Tcb, delivery Delivery, Request Request posted for NumBytes bytes, flags = RequestFlags. RcvNxt = RcvNxt.

Message #

TCP: connection %1, delivery %2, Request %3  posted for %4 bytes, flags = %5. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1156",
    "version": "0",
    "level": "4",
    "task": "1156",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:34.389030100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Delivery": "0xFFFF980A1018B790",
    "Request": "0xFFFF980A15EC82E0",
    "NumBytes": "0x6",
    "RequestFlags": "       0",
    "Length": "0x0",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "3537939053"
  },
  "message": ""
}

Event ID 1157: TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpDeliveryIndicated

Description

TCP: connection Tcb delivery Delivery indicated NumBytes bytes accepted Length bytes, status = RequestStatus. RcvNxt = RcvNxt.

Message #

TCP: connection %1 delivery %2 indicated %4 bytes accepted %6 bytes, status = %7. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1157",
    "version": "0",
    "level": "4",
    "task": "1157",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:34.418359700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "8632"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Delivery": "0xFFFF980A1018B790",
    "Request": "0x0",
    "NumBytes": "0x6",
    "RequestFlags": "       0",
    "Length": "0x0",
    "RequestStatus": "0xC000021B",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "3537939065"
  },
  "message": ""
}

Event ID 1158: TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested.

#
Channel
Diagnostic
Level
Informational
Task
TcpDeliverySatisfied

Description

TCP: connection Tcb delivery Delivery satisfied NumBytes bytes Length requested. IsFullySatisfied = FullySatisfiedORDelayedPush. RcvNxt = RcvNxt.

Message #

TCP: connection %1 delivery %2 satisfied %4 bytes %6 requested. IsFullySatisfied = %9. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1158",
    "version": "0",
    "level": "4",
    "task": "1158",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:34.390668300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Delivery": "0xFFFF980A1018B790",
    "Request": "0xFFFF980A15EC82E0",
    "NumBytes": "0x6",
    "RequestFlags": "       0",
    "Length": "0x6",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       1",
    "RcvNxt": "3537939053"
  },
  "message": ""
}

Event ID 1159: TCP: connection Tcb send Injected NumBytes bytes at SndNxt.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpSendPosted

Message #

TCP: connection %1 send %2 %3 bytes at %4.

Fields #

NameDescription
Tcb Pointer
Injected UnicodeString
NumBytes UInt32
SndNxt UInt32
SendAvailable UInt32
ActivityID Pointer
SndLimBytesSnd UInt64
SndLimBytesRwin UInt64
SndLimBytesCwnd UInt64
CWnd UInt32
SRtt UInt32
LossRecoveryEpisodes UInt32
RtoEpisodes UInt32
PtoEpisodes UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1159",
    "version": "0",
    "level": "4",
    "task": "1159",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.388647300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Injected": "posted",
    "NumBytes": "    1303",
    "SndNxt": "2307521250"
  },
  "message": ""
}

Event ID 1160: TCP: connection Tcb send transmitted NumBytes bytes at SndNxt.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendTransmitted

Message #

TCP: connection %1 send transmitted %3 bytes at %4.

Fields #

NameDescription
Tcb Pointer
Injected UnicodeString
NumBytes UInt32
SndNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1160",
    "version": "0",
    "level": "5",
    "task": "1160",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.388761700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Injected": "",
    "NumBytes": "    1303",
    "SndNxt": "2307521250"
  },
  "message": ""
}

Event ID 1161: TCP: connection Tcb send advance NumBytes bytes at SndNxt.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendAdvance

Message #

TCP: connection %1 send advance %3 bytes at %4.

Fields #

NameDescription
Tcb Pointer
Injected UnicodeString
NumBytes UInt32
SndNxt UInt32
SendAvailable UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1161",
    "version": "0",
    "level": "5",
    "task": "1161",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.390443300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Injected": "",
    "NumBytes": "    1303",
    "SndNxt": "2307521250"
  },
  "message": ""
}

Event ID 1162: TCP: CTcp: Connection Tcb Delay window has not kicked in.

#
Channel
Diagnostic
Task
TcpCTcpDelayWndwInactive

Message #

TCP: CTcp: Connection %1 Delay window has not kicked in.

Fields #

NameDescription
Tcb Pointer
Status UInt32NTSTATUS reference
AddressFamily UInt32

Event ID 1163: TCP: CTcp: Allocated blocks: AssignedBlocks; Assigned blocks: AllocatedBlocks.

#
Channel
Diagnostic
Task
TcpCTcpAssignedBlocks

Message #

TCP: CTcp: Allocated blocks: %1; Assigned blocks: %2.

Fields #

NameDescription
AssignedBlocks UInt32
AllocatedBlocks UInt32

Event ID 1164: TCP: CTcp: Connection Tcb, DWnd = DWnd (Prev = PrevDWnd), BaseRtt = BaseRtt, AverageRtt = AvgRtt, CWnd =Cwnd, DiffWnd = DiffWnd, DWnd increment = DwndIncrement.

#
Channel
Diagnostic
Task
TcpCTcpCongestionWndw

Message #

TCP: CTcp: Connection %1, DWnd = %2 (Prev = %3), BaseRtt = %4, AverageRtt = %5, CWnd =%6, DiffWnd = %7, DWnd increment = %8.

Fields #

NameDescription
Tcb Pointer
DWnd UInt32
PrevDWnd UInt32
BaseRtt UInt32
AvgRtt UInt32
Cwnd UInt32
DiffWnd UInt32
DwndIncrement UInt32

Event ID 1165: TCP: CTcp: Gamma Autotuning: Connection Tcb Updated Gamma Gamma, Average backlog AverageBacklog, Average backlog across LFPs AverageBacklogAcrossLFP.

#
Channel
Diagnostic
Task
TcpCTcpGamma

Message #

TCP: CTcp: Gamma Autotuning: Connection %1 Updated Gamma %2, Average backlog %3, Average backlog across LFPs %4.

Fields #

NameDescription
Tcb Pointer
Gamma UInt32
AverageBacklog UInt32
AverageBacklogAcrossLFP UInt32

Event ID 1166: TCP: connection Tcb SRTT measurement started (seq = SeqNum, tick = Tick).

#
Channel
Diagnostic
Task
TcpSrttMeasurementStarted

Message #

TCP: connection %1 SRTT measurement started (seq = %2, tick = %3).

Fields #

NameDescription
Tcb Pointer
SeqNum UInt32
Tick UInt32
RttSample UInt32
NewSrtt UInt32

Event ID 1167: TCP: connection Tcb SRTT measurement complete (tick = Tick, sample = RttSample ms, new srtt = NewSrtt ms).

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpSrttMeasurementComplete

Message #

TCP: connection %1 SRTT measurement complete (tick = %3, sample = %4 ms, new srtt = %5 ms).

Fields #

NameDescription
Tcb Pointer
SeqNum UInt32
Tick UInt32
RttSample UInt32
NewSrtt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1167",
    "version": "0",
    "level": "4",
    "task": "1167",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:26:13.268231300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4200",
      "thread_id": "7084"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFF7AF7E0",
    "SeqNum": "       0",
    "Tick": "66907815",
    "RttSample": "       0",
    "NewSrtt": "       0"
  },
  "message": ""
}

Event ID 1168: TCP: connection Tcb: SRTT measurement cancelled.

#
Channel
Diagnostic
Level
Verbose
Task
TcpSrttMeasurementCancelled

Message #

TCP: connection %1: SRTT measurement cancelled.

Fields #

NameDescription
Tcb Pointer
SeqNum UInt32
Tick UInt32
RttSample UInt32
NewSrtt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1168",
    "version": "0",
    "level": "5",
    "task": "1168",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:27:12.440661100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFD182260",
    "SeqNum": "       0",
    "Tick": "       0",
    "RttSample": "       0",
    "NewSrtt": "       0"
  },
  "message": ""
}

Event ID 1169: UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
UdpEndpointSendMessages

Description

UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes. PID = Pid.

Message #

UDP: endpoint %1 (LocalAddress = %5, RemoteAddress = %7) sending %2 messages and a total of %3 bytes. PID = %8.

Fields #

NameDescription
Endpoint Pointer
NumMessages UInt32
NumBytes UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary
Pid UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1169",
    "version": "0",
    "level": "4",
    "task": "1169",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.078234200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A11735E80",
    "NumMessages": "       1",
    "NumBytes": "      63",
    "LocalSockAddrLength": "      28",
    "LocalSockAddr": "[::ffff:0:0]:53893",
    "RemoteSockAddrLength": "      28",
    "RemoteSockAddr": "[::ffff:10.2.10.11]:53",
    "Pid": "     228"
  },
  "message": ""
}

Event ID 1170: UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
UdpEndpointReceiveMessages

Description

UDP: endpoint Endpoint (LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes. PID = Pid.

Message #

UDP: endpoint %1 (LocalAddress = %5, RemoteAddress = %7) delivering %3 bytes. PID = %8.

Fields #

NameDescription
Endpoint Pointer
NumMessages UInt32
NumBytes UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary
Pid UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1170",
    "version": "0",
    "level": "4",
    "task": "1170",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:40.117082900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A11735E80",
    "NumMessages": "       0",
    "NumBytes": "     186",
    "LocalSockAddrLength": "      28",
    "LocalSockAddr": "[::ffff:10.2.10.21]:53893",
    "RemoteSockAddrLength": "      28",
    "RemoteSockAddr": "[::ffff:10.2.10.11]:53",
    "Pid": "     228"
  },
  "message": ""
}

Event ID 1171: TCP: connection Tcb delivery Delivery flushing NumBytes bytes Length requested status = RequestStatus.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpDeliveryFlush

Message #

TCP: connection %1 delivery %2 flushing %4 bytes %6 requested status = %7.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1171",
    "version": "0",
    "level": "5",
    "task": "1171",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:40.593480400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "Delivery": "0xFFFF980A15CE6D10",
    "Request": "0xFFFF980A11C13950",
    "NumBytes": "0x0",
    "RequestFlags": "       0",
    "Length": "0x2000",
    "RequestStatus": "0xC0000120",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "       0"
  },
  "message": ""
}

Event ID 1172: TCP: Injecting receive on a shutdown TCB failed.

#
Channel
Diagnostic
Task
TcpTcbInjectRcvFailure

Description

TCP: Injecting receive on a shutdown TCB failed. TCB = Tcb.

Message #

TCP: Injecting receive on a shutdown TCB failed. TCB = %1.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1173: TCP: connection Tcb delivery Delivery injecting NumBytes bytes delta Length, IsUrgentDelivery = IsUrgentDelivery.

#
Channel
Diagnostic
Level
Verbose
Task
TcpDeliveryInjectingData

Message #

TCP: connection %1 delivery %2 injecting %4 bytes delta %6, IsUrgentDelivery = %8.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1173",
    "version": "0",
    "level": "5",
    "task": "1173",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:23:28.315732300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7644"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0E584560",
    "Delivery": "0xFFFF980A0E584790",
    "Request": "0x0",
    "NumBytes": "0x0",
    "RequestFlags": "       0",
    "Length": "0x70",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "       0"
  },
  "message": ""
}

Event ID 1174: TCP: Injecting fin on a shutdown TCB failed.

#
Channel
Diagnostic
Task
TcpTcbInjectFinFailure

Description

TCP: Injecting fin on a shutdown TCB failed. TCB = Tcb.

Message #

TCP: Injecting fin on a shutdown TCB failed. TCB = %1.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1175: TCP: connection Tcb delivery Delivery accepting NumBytes bytes.

#
Channel
Diagnostic
Level
Verbose
Task
TcpDeliveryAccept

Description

TCP: connection Tcb delivery Delivery accepting NumBytes bytes. RcvNxt = RcvNxt.

Message #

TCP: connection %1 delivery %2 accepting %4 bytes. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1175",
    "version": "0",
    "level": "5",
    "task": "1175",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:22:29.058226900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Delivery": "0xFFFF980A1018B790",
    "Request": "0x0",
    "NumBytes": "0x6",
    "RequestFlags": "       0",
    "Length": "0x0",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "3537945353"
  },
  "message": ""
}

Event ID 1176: TCP: connection Tcb delivery Delivery delivering FIN.

#
Channel
Diagnostic
Level
Informational
Task
TcpDeliveryFin

Description

TCP: connection Tcb delivery Delivery delivering FIN. RcvNxt = RcvNxt.

Message #

TCP: connection %1 delivery %2 delivering FIN. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1176",
    "version": "0",
    "level": "4",
    "task": "1176",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:38.731999900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0EEE7560",
    "Delivery": "0xFFFF980A0EEE7790",
    "Request": "0x0",
    "NumBytes": "0x0",
    "RequestFlags": "       0",
    "Length": "0x0",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "2633618840"
  },
  "message": ""
}

Event ID 1178: TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested.

#
Channel
Diagnostic
Task
TcpDeliveryPush

Description

TCP: connection Tcb delivery Delivery pushing NumBytes bytes Length requested. Delayed push = FullySatisfiedORDelayedPush.

Message #

TCP: connection %1 delivery %2 pushing %4 bytes %6 requested. Delayed push = %9.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1180: TCP: Injecting fin on TCB completed.

#
Channel
Diagnostic
Level
Verbose
Task
TcpTcbInjectFinComplete

Description

TCP: Injecting fin on TCB completed. TCB = Tcb, Processor = NumBytes.

Message #

TCP: Injecting fin on TCB completed. TCB = %1, Processor = %4.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1180",
    "version": "0",
    "level": "5",
    "task": "1180",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:23:59.852963300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "13080"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A14CDE010",
    "Delivery": "0x0",
    "Request": "0x0",
    "NumBytes": "0xD",
    "RequestFlags": "       0",
    "Length": "0x0",
    "RequestStatus": "0x0",
    "IsUrgentDelivery": "       0",
    "FullySatisfiedORDelayedPush": "       0",
    "RcvNxt": "       0"
  },
  "message": ""
}

Event ID 1181: TCP: connection Tcb delivery Delivery urgent boundary completing NumBytes bytes Length requested.

#
Channel
Diagnostic
Task
TcpDeliveryCompleting

Message #

TCP: connection %1 delivery %2 urgent boundary completing %4 bytes %6 requested.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1182: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress): initiating SYN/RST validation.

#
Channel
Diagnostic
Task
TcpInitiateSynRstValidation

Message #

TCP: connection %1 (local=%3 remote=%5): initiating SYN/RST validation.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1183: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connect failed: received RST.

#
Channel
Diagnostic
Level
Informational
Task
TcpConnectTcbFailedRcvdRst

Message #

TCP: connection %1 (local=%3 remote=%5) connect failed: received RST.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1183,
    "version": 0,
    "level": 4,
    "task": 1183,
    "opcode": 0,
    "keywords": "0x8000000600000080",
    "time_created": "2026-07-19T03:41:10.987276200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "10910630-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF800A10910630",
    "LocalAddressLength": "16",
    "LocalAddress": "127.0.0.1:57033",
    "RemoteAddressLength": "16",
    "RemoteAddress": "127.0.0.1:18091",
    "NewState": "0",
    "RexmitCount": "0"
  },
  "message": "TCP: connection 0xFFFF800A10910630 (local=127.0.0.1:57033 remote=127.0.0.1:18091) connect failed: received RST."
}

Event ID 1184: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received RST.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpConnectionTerminatedRcvdRst

Message #

TCP: connection %1 (local=%3 remote=%5) connection terminated: received RST.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1184",
    "version": "0",
    "level": "4",
    "task": "1184",
    "opcode": "0",
    "keywords": 9223372062624579712,
    "time_created": "2026-03-16T00:23:11.140010200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11ae9ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A11AE9AE0",
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:53002",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "10.2.10.11:445",
    "NewState": "       0",
    "RexmitCount": "       0"
  },
  "message": ""
}

Event ID 1185: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) connection terminated: received SYN in state NewState.

#
Channel
Diagnostic
Task
TcpConnectionTerminatedRcvdSyn

Message #

TCP: connection %1 (local=%3 remote=%5) connection terminated: received SYN in state %6.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1186: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting connect attempt, RexmitCount = RexmitCount.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpConnectRestransmit

Message #

TCP: connection %1 (local=%3 remote=%5) retransmitting connect attempt, RexmitCount = %7.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1186",
    "version": "0",
    "level": "4",
    "task": "1186",
    "opcode": "0",
    "keywords": 9223372058329612416,
    "time_created": "2026-03-15T23:31:42.716275300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FF9CA95F0",
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.11:51269",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "10.2.10.21:389",
    "NewState": "       0",
    "RexmitCount": "       1"
  },
  "message": ""
}

Event ID 1187: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) retransmitting data, RexmitCount = RexmitCount.

#
Channel
Diagnostic
Task
TcpDataTransferRestransmit

Message #

TCP: connection %1 (local=%3 remote=%5) retransmitting data, RexmitCount = %7.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1188: TCP: connection Tcb send keep-alive at SndUna = SndUna.

#
Channel
Diagnostic
Level
Informational
Task
TcpConnectionKeepAlive

Message #

TCP: connection %1 send keep-alive at SndUna = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1188",
    "version": "0",
    "level": "4",
    "task": "1188",
    "opcode": "0",
    "keywords": 9223372058329612416,
    "time_created": "2026-03-16T00:21:53.057881700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0e584560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0E584560",
    "SndUna": "2262383926",
    "SndMax": "       0"
  },
  "message": ""
}

Event ID 1189: TCP: connection Tcb, delivery Delivery: delivery state changed from OldDeliveryState to NewDeliveryState.

#
Channel
Diagnostic
Task
TcpDeliveryStateChange

Message #

TCP: connection %1, delivery %2: delivery state changed from %3 to %4.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
OldDeliveryState UInt32
NewDeliveryState UInt32

Event ID 1190: TCP: connection Tcb delivery Delivery dropping data.

#
Channel
Diagnostic
Task
TcpDeliveryDataDropped

Description

TCP: connection Tcb delivery Delivery dropping data. TotalBytesEnqueued = NumBytes. Length = Length. RcvNxt = RcvNxt.

Message #

TCP: connection %1 delivery %2 dropping data. TotalBytesEnqueued = %4. Length = %6. RcvNxt = %10.

Fields #

NameDescription
Tcb Pointer
Delivery Pointer
Request Pointer
NumBytes Pointer
RequestFlags UInt32
Length Pointer
RequestStatus UInt32
IsUrgentDelivery UInt32
FullySatisfiedORDelayedPush UInt32
RcvNxt UInt32

Event ID 1191: TCP: endpoint/connection PortAcquirer acquired port number PortNumber.

#
Channel
Diagnostic
Level
Informational
Task
TcpAcquirePort

Message #

TCP: endpoint/connection %1 acquired port number %2.

Fields #

NameDescription
PortAcquirer Pointer
PortNumber UInt16
WeakReference UInt32
OriginalAcquirer Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1191",
    "version": "0",
    "level": "4",
    "task": "1191",
    "opcode": "0",
    "keywords": 9223372054034644992,
    "time_created": "2026-03-16T00:21:40.119043200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0da8a910-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PortAcquirer": "0xFFFF980A0DA8A910",
    "PortNumber": "52999",
    "WeakReference": "       0",
    "OriginalAcquirer": "0x0"
  },
  "message": ""
}

Event ID 1192: TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer.

#
Channel
Diagnostic
Level
Informational
Task
TcpAcquireWeakRefPort

Description

TCP: connection PortAcquirer attempted to acquire weak reference on port number PortNumber inherited from endpoint OriginalAcquirer. Successful = WeakReference.

Message #

TCP: connection %1 attempted to acquire weak reference on port number %2 inherited from endpoint %4. Successful = %3.

Fields #

NameDescription
PortAcquirer Pointer
PortNumber UInt16
WeakReference UInt32
OriginalAcquirer Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1192",
    "version": "0",
    "level": "4",
    "task": "1192",
    "opcode": "0",
    "keywords": 9223372054034644992,
    "time_created": "2026-03-16T00:21:38.719220200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PortAcquirer": "0xFFFF980A0EEE7560",
    "PortNumber": "5985",
    "WeakReference": "       1",
    "OriginalAcquirer": "0xFFFF980A0EF4B580"
  },
  "message": ""
}

Event ID 1193: TCP: endpoint/connection PortAcquirer released port number PortNumber.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpReleasePort

Description

TCP: endpoint/connection PortAcquirer released port number PortNumber. WeakReference = WeakReference.

Message #

TCP: endpoint/connection %1 released port number %2. WeakReference = %3.

Fields #

NameDescription
PortAcquirer Pointer
PortNumber UInt16
WeakReference UInt32
OriginalAcquirer Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1193",
    "version": "0",
    "level": "4",
    "task": "1193",
    "opcode": "0",
    "keywords": 9223372054034644992,
    "time_created": "2026-03-16T00:21:38.733428000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7444"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PortAcquirer": "0xFFFF980A0EEE7560",
    "PortNumber": "5985",
    "WeakReference": "       1",
    "OriginalAcquirer": "0x0"
  },
  "message": ""
}

Event ID 1194: TCP: endpoint/connection PortAcquirer replaced base endpoint OriginalAcquirer and acquired reference to port number PortNumber.

#
Channel
Diagnostic
Level
Informational
Task
TcpReplacePort

Message #

TCP: endpoint/connection %1 replaced base endpoint %4 and acquired reference to port number %2.

Fields #

NameDescription
PortAcquirer Pointer
PortNumber UInt16
WeakReference UInt32
OriginalAcquirer Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1194,
    "version": 0,
    "level": 4,
    "task": 1194,
    "opcode": 0,
    "keywords": 9223372054034644992,
    "time_created": "2026-07-19T03:23:59.817100900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fe57eb50-8009-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": 13872,
      "thread_id": 8204
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "OriginalAcquirer": "0xFFFF800A0D49B390",
    "PortAcquirer": "0xFFFF8009FE57EB50",
    "PortNumber": "56962",
    "WeakReference": "0"
  },
  "message": "TCP: endpoint/connection 0xFFFF8009FE57EB50 replaced base endpoint 0xFFFF800A0D49B390 and acquired reference to port number 56962. "
}

Event ID 1195: TCP: Portpool assigned port number PortNumber with weak references due to port exhaustion.

#
Channel
Diagnostic
Task
TcpAssignedWeakReferencePort

Message #

TCP: Portpool assigned port number %2 with weak references due to port exhaustion.

Fields #

NameDescription
PortAcquirer Pointer
PortNumber UInt16
WeakReference UInt32
OriginalAcquirer Pointer

Event ID 1196: TCP: connection Tcb BH receive ACK for full size seq.

#
Channel
Diagnostic
Level
Informational
Task
TcpBhDetectFullSizeAck

Description

TCP: connection Tcb BH receive ACK for full size seq. Seq = SndUna. IsSack = IsSack.

Message #

TCP: connection %1 BH receive ACK for full size seq. Seq = %2. IsSack = %5.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Reason UnicodeString
IsSack UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1196",
    "version": "0",
    "level": "4",
    "task": "1196",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:23:27.217663000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A170D1290",
    "SndUna": "1228953133",
    "SndMax": "       0",
    "Reason": "NULL",
    "IsSack": "       0"
  },
  "message": ""
}

Event ID 1197: TCP: connection Tcb flushed SACK state at SndUna = SndUna.

#
Channel
Diagnostic
Task
TcpFlushSack

Description

TCP: connection Tcb flushed SACK state at SndUna = SndUna. Reason: Reason.

Message #

TCP: connection %1 flushed SACK state at SndUna = %2. Reason: %4.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Reason UnicodeString
IsSack UInt32

Event ID 1198: TCP: Connection Tcb entering reassembly at RcvNxt = SndUna.

#
Channel
Diagnostic
Level
Verbose
Task
TcpReassemblyEntry

Message #

TCP: Connection %1 entering reassembly at RcvNxt = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1198",
    "version": "0",
    "level": "5",
    "task": "1198",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:23:59.839186900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A14CDE010",
    "SndUna": "3358248696",
    "SndMax": "       0"
  },
  "message": ""
}

Event ID 1199: TCP: Connection Tcb leaving reassembly at RcvNxt = SndUna.

#
Channel
Diagnostic
Level
Verbose
Task
TcpReassemblyExit

Message #

TCP: Connection %1 leaving reassembly at RcvNxt = %2.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1199",
    "version": "0",
    "level": "5",
    "task": "1199",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:23:59.839225300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{14cde010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A14CDE010",
    "SndUna": "3358248696",
    "SndMax": "       0"
  },
  "message": ""
}

Event ID 1200: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: Zero window probe timeout expired.

#
Channel
Diagnostic
Task
TcpDisconnectTcbZeroWindowTimeout

Message #

TCP: connection %8 (local=%2 remote=%4) terminating: Zero window probe timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1201: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) terminating: FIN-WAIT-2 timeout expired.

#
Channel
Diagnostic
Level
Informational
Task
TcpDisconnectTcbFinWait2Timeout

Message #

TCP: connection %8 (local=%2 remote=%4) terminating: FIN-WAIT-2 timeout expired.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1201,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:11:51.726Z",
    "version": 0
  },
  "event_data": {
    "Compartment": 0,
    "LocalAddress": "0200D2C90A020A150000000000000000",
    "LocalAddressLength": 16,
    "ProcessId": 0,
    "ProcessStartKey": 0,
    "RemoteAddress": "02000D3D0A020A0B0000000000000000",
    "RemoteAddressLength": 16,
    "Status": 0,
    "Tcb": "0xFFFFC807CC3DC010"
  },
  "message": ""
}

Event ID 1202: IP: Interface rundown: Index = IfIndex, Linkspeed = CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType, IP Address = IPv4 Address IPProtocol IPv6 Address.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
InterfaceRundown

Message #

IP: Interface rundown: Index = %1, Linkspeed = %2 bps, PhysicalMediumType = %7, IP Address = %4 %3 %6.

Fields #

NameDescription
IfIndex UInt32
CurrLinkSpeed UInt64
IPProtocol UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary
PhysicalMediumType UInt32
CompartmentId UInt32
OldLinkSpeed UInt64
NetworkCategory UInt32
Metric UInt32
Connected UInt32
InternetConnectivityStatus UInt32
Flags UInt64
IsolationId UInt32
NlMtu UInt32
ForwardingTag UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1202",
    "version": "4",
    "level": "4",
    "task": "1202",
    "opcode": "0",
    "keywords": 9223372586610589840,
    "time_created": "2026-03-15T23:26:13.264840100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "15176",
      "thread_id": "13152"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfIndex": "       1",
    "CurrLinkSpeed": "0",
    "IPProtocol": "       4",
    "IPv4 Address": "127.0.0.1",
    "IpAddrLength": "       0",
    "IPv6 Address": "",
    "PhysicalMediumType": "       0",
    "CompartmentId": "       1",
    "OldLinkSpeed": "0",
    "NetworkCategory": "       0",
    "Metric": "      75",
    "Connected": "       1",
    "InternetConnectivityStatus": "4294967295",
    "Flags": "0x10262102300",
    "IsolationId": "       0"
  },
  "message": ""
}

Example keys not documented in the fields table: IPv4 Address, IPv6 Address

Event ID 1203: IP: Interface Index = IfIndex, Linkspeed changed to CurrLinkSpeed bps, PhysicalMediumType = PhysicalMediumType.

#
Channel
Diagnostic
Task
IpInterfaceSpeedChange

Message #

IP: Interface Index = %1, Linkspeed changed to %2 bps, PhysicalMediumType = %7.

Fields #

NameDescription
IfIndex UInt32
CurrLinkSpeed UInt64
IPProtocol UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary
PhysicalMediumType UInt32
CompartmentId UInt32
OldLinkSpeed UInt64
ReceiveLinkSpeed UInt64
MediaConnectState UInt32

Event ID 1204: TCP: Connection Tcb flushing reassembly state at RcvNxt = SndUna.

#
Channel
Diagnostic
Task
TcpReassemblyFlush

Description

TCP: Connection Tcb flushing reassembly state at RcvNxt = SndUna. Reason = Reason.

Message #

TCP: Connection %1 flushing reassembly state at RcvNxt = %2. Reason = %4.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Reason UnicodeString
IsSack UInt32

Event ID 1205: TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpipReceiveSlowPath

Description

TCPIP: NBL Nbl fell off the receive fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.

Message #

TCPIP: NBL %1 fell off the receive fast path, Reason: %10. Protocol = %2, Family = %3, Number of NBLs = %11. SourceAddress = %4 %12 %7. DestAddress = %5 %12 %9.

Fields #

NameDescription
Nbl Pointer
IPTransportProtocol UInt32
AddressFamily UInt32
SourceIPv4Address UInt32
DestIPv4Address UInt32
IPv6SourceIpAddrLength UInt32
IPv6SourceAddress Binary
IPv6DestIpAddrLength UInt32
IPv6DestAddress Binary
Reason UInt32
NblCount UInt32
IPProtocol UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1205",
    "version": "0",
    "level": "5",
    "task": "1205",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:38.718814700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Nbl": "0xFFFF980A1D7C5570",
    "IPTransportProtocol": "       6",
    "AddressFamily": "       2",
    "Source IPv4 Address": "10.2.10.11",
    "Dest IPv4 Address": "10.2.10.21",
    "IPv6SourceIpAddrLength": "       0",
    "IPv6 Source Address": "",
    "IPv6DestIpAddrLength": "       0",
    "IPv6 Dest Address": "",
    "Reason": "      17",
    "NblCount": "       1",
    "IPProtocol": "       4"
  },
  "message": ""
}

Example keys not documented in the fields table: Dest IPv4 Address, IPv6 Dest Address, IPv6 Source Address, Source IPv4 Address

Event ID 1206: TCPIP: NBL Nbl fell off the send fast path, Reason: Reason.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpipSendSlowPath

Description

TCPIP: NBL Nbl fell off the send fast path, Reason: Reason. Protocol = IPTransportProtocol, Family = AddressFamily, Number of NBLs = NblCount. SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address.

Message #

TCPIP: NBL %1 fell off the send fast path, Reason: %10. Protocol = %2, Family = %3, Number of NBLs = %11. SourceAddress = %4 %12 %7. DestAddress = %5 %12 %9.

Fields #

NameDescription
Nbl Pointer
IPTransportProtocol UInt32
AddressFamily UInt32
SourceIPv4Address UInt32
DestIPv4Address UInt32
IPv6SourceIpAddrLength UInt32
IPv6SourceAddress Binary
IPv6DestIpAddrLength UInt32
IPv6DestAddress Binary
Reason UInt32
NblCount UInt32
IPProtocol UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1206",
    "version": "0",
    "level": "5",
    "task": "1206",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.388870500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Nbl": "0xFFFF980A11CCA4F0",
    "IPTransportProtocol": "       6",
    "AddressFamily": "       2",
    "Source IPv4 Address": "10.2.10.21",
    "Dest IPv4 Address": "10.2.20.41",
    "IPv6SourceIpAddrLength": "       0",
    "IPv6 Source Address": "",
    "IPv6DestIpAddrLength": "       0",
    "IPv6 Dest Address": "",
    "Reason": "      11",
    "NblCount": "       1",
    "IPProtocol": "       4"
  },
  "message": ""
}

Example keys not documented in the fields table: Dest IPv4 Address, IPv6 Dest Address, IPv6 Source Address, Source IPv4 Address

Event ID 1207: TCP: WSD - TcpWsdEtwPoint Status: Status.

#
Channel
Diagnostic
Task
TcpWsdInitializationErrors

Message #

TCP: WSD - %1 Status: %2.

Fields #

NameDescription
TcpWsdEtwPoint UInt32
Status UInt32NTSTATUS reference

Event ID 1208: TCP: WSD - TcpWsdEtwPoint Status: Status.

#
Channel
Diagnostic
Task
TcpWsdInitializationInformation

Message #

TCP: WSD - %1 Status: %2.

Fields #

NameDescription
TcpWsdEtwPoint UInt32
Status UInt32NTSTATUS reference

Event ID 1209: TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.

#
Channel
Diagnostic
Task
TcpWsdWsRestrictedProfile

Message #

TCP: WSD - TCB %2 will use a highly restricted window scale factor due to a %1.

Fields #

NameDescription
TcpWsdEtwPoint UInt32
Tcb Pointer

Event ID 1210: TCP: WSD - TCB Tcb will use a highly restricted window scale factor due to a TcpWsdEtwPoint.

#
Channel
Diagnostic
Task
TcpWsdWsRestrictedDestination

Message #

TCP: WSD - TCB %2 will use a highly restricted window scale factor due to a %1.

Fields #

NameDescription
TcpWsdEtwPoint UInt32
Tcb Pointer

Event ID 1211: TCP: WSD - Entry (Processor, Entry) moved from OldState to NewState due to TcpWsdEtwPoint.

#
Channel
Diagnostic
Task
TcpWsdCacheEntryStateChange

Message #

TCP: WSD - Entry (%2, %3) moved from %4 to %5 due to %1.

Fields #

NameDescription
TcpWsdEtwPoint UInt32
Processor UInt32
Entry UInt32
OldState UInt32
NewState UInt32
ProbeCount UInt32
ProbeCountWs UInt32

Event ID 1212: TCP: WSD - Profile: Profile State: State Qualified: Qualified EreQualified: EreQualified.

#
Channel
Diagnostic
Task
TcpWsdProfileStateChange

Message #

TCP: WSD - Profile: %1 State: %2 Qualified: %3 EreQualified: %4.

Fields #

NameDescription
Profile UInt32
State UInt32
Qualified UInt32
EreQualified UInt32

Event ID 1213: TCP: WSD - Enabled moved from OldEnabledState to NewEnabledState.

#
Channel
Diagnostic
Task
TcpWsdStateChange

Description

TCP: WSD - Enabled moved from OldEnabledState to NewEnabledState. Threshold moved from OldThreshold to NewThreshold.

Message #

TCP: WSD - Enabled moved from %1 to %2. Threshold moved from  %3 to %4.

Fields #

NameDescription
OldEnabledState UInt32
NewEnabledState UInt32
OldThreshold UInt32
NewThreshold UInt32

Event ID 1214: TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipTransportPacketDrops

Description

TCPIP: Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s) with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.

Message #

TCPIP: Transport (Protocol %1, AddressFamily = %2) dropped %8 packet(s) with Local = %4, Remote = %6. Reason = %7.

Fields #

NameDescription
IPTransportProtocol UInt32
AddressFamily UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary
Reason UInt32
PacketCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1214",
    "version": "0",
    "level": "4",
    "task": "1214",
    "opcode": "0",
    "keywords": 9223373694712152192,
    "time_created": "2026-03-16T00:21:38.733034500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IPTransportProtocol": "       6",
    "AddressFamily": "       2",
    "LocalSockAddrLength": "      16",
    "LocalSockAddr": "10.2.10.21:5985",
    "RemoteSockAddrLength": "      16",
    "RemoteSockAddr": "10.2.10.11:51201",
    "Reason": "      20",
    "PacketCount": "       1"
  },
  "message": ""
}

Event ID 1215: TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s).

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipNetworkPacketDrops

Description

TCPIP: Network layer (Protocol IPTransportProtocol, AddressFamily = AddressFamily) dropped PacketCount packet(s). SourceAddress = Source IPv4 Address IPProtocol IPv6 Source Address. DestAddress = Dest IPv4 Address IPProtocol IPv6 Dest Address. Reason = Reason.

Message #

TCPIP: Network layer (Protocol %1, AddressFamily = %2) dropped %10 packet(s). SourceAddress = %3 %11 %6. DestAddress = %4 %11 %8. Reason = %9.

Fields #

NameDescription
IPTransportProtocol UInt32
AddressFamily UInt32
SourceIPv4Address UInt32
DestIPv4Address UInt32
IPv6SourceIpAddrLength UInt32
IPv6SourceAddress Binary
IPv6DestIpAddrLength UInt32
IPv6DestAddress Binary
Reason UInt32
PacketCount UInt32
IPProtocol UInt32
SourceAddressLength UInt32
SourceAddress Binary
DestAddressLength UInt32
DestAddress Binary
IfIndex UInt32
PathDirection UInt32
Nbl Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1215",
    "version": "1",
    "level": "4",
    "task": "1215",
    "opcode": "0",
    "keywords": 9223373699007119488,
    "time_created": "2026-03-15T23:27:04.761762100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "3912",
      "thread_id": "13412"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IPTransportProtocol": "       6",
    "AddressFamily": "      23",
    "Source IPv4 Address": "0.0.0.0",
    "Dest IPv4 Address": "0.0.0.0",
    "IPv6SourceIpAddrLength": "      16",
    "IPv6 Source Address": "::1",
    "IPv6DestIpAddrLength": "      16",
    "IPv6 Dest Address": "::1",
    "Reason": "     256",
    "PacketCount": "       1",
    "IPProtocol": "       6",
    "SourceAddressLength": "      28",
    "SourceAddress": "::1",
    "DestAddressLength": "      28",
    "DestAddress": "::1",
    "IfIndex": "       1",
    "PathDirection": "       1"
  },
  "message": ""
}

Example keys not documented in the fields table: Dest IPv4 Address, IPv6 Dest Address, IPv6 Source Address, Source IPv4 Address

Event ID 1216: TCP: MPP NPP Evaluation PhysicalPages = PhysicalPages NonPagedPoolPages = NonPagedPoolPages Current = CurrentWatermark Peak = PeakWatermark Low = HighWatermark High = LowWatermark.

#
Channel
Diagnostic
Task
TcpMppNppEvaluation

Message #

TCP: MPP NPP Evaluation PhysicalPages = %1 NonPagedPoolPages = %2 Current = %3 Peak = %4 Low = %5 High = %6.

Fields #

NameDescription
PhysicalPages UInt32
NonPagedPoolPages UInt32
CurrentWatermark UInt32
PeakWatermark UInt32
HighWatermark UInt32
LowWatermark UInt32

Event ID 1217: TCP: MPP: Episode started.

#
Channel
Diagnostic
Task
TcpMppStartEpisode

Description

TCP: MPP: Episode started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Current = CurrentWatermark Low = LowWatermark Reentry = ReentryWatermark.

Message #

TCP: MPP: Episode started. LowNppEventState = %1 HighNppEventState = %2 EpisodeStartTick = %3 EpisodeStopTick = %4 Current = %5 Low = %6 Reentry = %7.

Fields #

NameDescription
LowNppEventState UInt32
HighNppEventState UInt32
EpisodeStartTick UInt64
EpisodeStopTick UInt64
CurrentWatermark UInt32
LowWatermark UInt32
ReentryWatermark UInt32

Event ID 1218: TCP: MPP: Episode ended.

#
Channel
Diagnostic
Task
TcpMppStopEpisode

Description

TCP: MPP: Episode ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpisodeStartTick = EpisodeStartTick EpisodeStopTick = EpisodeStopTick Reentry = ReentryWatermark.

Message #

TCP: MPP: Episode ended. LowNppEventState = %1 HighNppEventState = %2 EpisodeStartTick = %3 EpisodeStopTick = %4 Reentry = %5.

Fields #

NameDescription
LowNppEventState UInt32
HighNppEventState UInt32
EpisodeStartTick UInt64
EpisodeStopTick UInt64
ReentryWatermark UInt32

Event ID 1219: TCP: MPP: Epoch Epoch started.

#
Channel
Diagnostic
Task
TcpMppStartEpoch

Description

TCP: MPP: Epoch Epoch started. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = OldSynDropRate -> NewSynDropRate TcbKillRate = OldTcbKillRate -> NewTcbKillRate CurrentWatermark = CurrentWatermark.

Message #

TCP: MPP: Epoch %1 started. LowNppEventState = %2 HighNppEventState = %3 EpochStartTick = %4 EpochStopTick = %5 SynDropRate = %6 -> %7 TcbKillRate = %8 -> %9 CurrentWatermark = %10.

Fields #

NameDescription
Epoch UInt32
LowNppEventState UInt32
HighNppEventState UInt32
EpochStartTick UInt64
EpochStopTick UInt64
OldSynDropRate UInt32
NewSynDropRate UInt32
OldTcbKillRate UInt32
NewTcbKillRate UInt32
CurrentWatermark UInt32

Event ID 1220: TCP: MPP: Epoch Epoch ended.

#
Channel
Diagnostic
Task
TcpMppStopEpoch

Description

TCP: MPP: Epoch Epoch ended. LowNppEventState = LowNppEventState HighNppEventState = HighNppEventState EpochStartTick = EpochStartTick EpochStopTick = EpochStopTick SynDropRate = SynDropRate TcbKillRate = TcbKillRate Current = CurrentWatermark.

Message #

TCP: MPP: Epoch %1 ended. LowNppEventState = %2 HighNppEventState = %3 EpochStartTick = %4 EpochStopTick = %5 SynDropRate = %6 TcbKillRate = %7 Current = %8.

Fields #

NameDescription
Epoch UInt32
LowNppEventState UInt32
HighNppEventState UInt32
EpochStartTick UInt64
EpochStopTick UInt64
SynDropRate UInt32
TcbKillRate UInt32
CurrentWatermark UInt32

Event ID 1221: TCP: Connection Tcb restarting Cwnd.

#
Channel
Diagnostic
Task
TcpCwndRestart

Description

TCP: Connection Tcb restarting Cwnd. Old Cwnd = OldCwnd, New Cwnd = NewCwnd, Processor = Processor, CurrentTick = CurrentTick, IdleTick = IdleTick, Rto = Rto.

Message #

TCP: Connection %1 restarting Cwnd. Old Cwnd = %2, New Cwnd = %3, Processor = %4, CurrentTick = %5, IdleTick = %6, Rto = %7.

Fields #

NameDescription
Tcb Pointer
OldCwnd UInt32
NewCwnd UInt32
Processor UInt32
CurrentTick UInt32
IdleTick UInt32
Rto UInt32

Event ID 1222: TCP: Connection Tcb adjust InitalCwnd.

#
Channel
Diagnostic
Task
TcpInitialCwndAdjusted

Description

TCP: Connection Tcb adjust InitalCwnd. Cwnd = OldCwnd, New Initial Cwnd = NewCwnd MSS.

Message #

TCP: Connection %1 adjust InitalCwnd. Cwnd = %2, New Initial Cwnd = %3 MSS.

Fields #

NameDescription
Tcb Pointer
OldCwnd UInt32
NewCwnd UInt32
Processor UInt32
CurrentTick UInt32
IdleTick UInt32
Rto UInt32

Event ID 1223: TCP: Connection Tcb committed TemplateType = TemplateType.

#
Channel
Diagnostic
Level
Informational
Task
TcpTemplateParameters

Description

TCP: Connection Tcb committed TemplateType = TemplateType. MinRto = MinRto msec, EnableCwndRestart = EnableCwndRestart, InitialCwnd = InitialCwnd MSS, CongestionAlgorithm = CongestionAlgorithm, MaxDataRetransmissions = MaxDataRetransmissions, DelayedAckTicks = DelayedAckTicks msec, DelayedAckFrequency = DelayedAckFrequency, RACK enabled = Rack, Tail Loss Probe enabled = TailLossProbe.

Message #

TCP: Connection %1 committed TemplateType = %2. MinRto = %3 msec, EnableCwndRestart = %4, InitialCwnd = %5 MSS, CongestionAlgorithm = %6, MaxDataRetransmissions = %7, DelayedAckTicks = %8 msec, DelayedAckFrequency = %9, RACK enabled = %10, Tail Loss Probe enabled = %11.

Fields #

NameDescription
Tcb Pointer
TemplateType UInt32
MinRto UInt32
EnableCwndRestart UInt32
InitialCwnd UInt32
CongestionAlgorithm UInt32
MaxDataRetransmissions UInt32
DelayedAckTicks UInt32
DelayedAckFrequency UInt32
Rack UInt32
TailLossProbe UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1223",
    "version": "0",
    "level": "4",
    "task": "1223",
    "opcode": "0",
    "keywords": 9223372586610589696,
    "time_created": "2026-03-16T00:21:38.719984100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0EEE7560",
    "TemplateType": "       0",
    "MinRto": "     300",
    "EnableCwndRestart": "       0",
    "InitialCwnd": "      10",
    "CongestionAlgorithm": "       5",
    "MaxDataRetransmissions": "       5",
    "DelayedAckTicks": "      40",
    "DelayedAckFrequency": "       2",
    "Rack": "       1",
    "TailLossProbe": "       1"
  },
  "message": ""
}

Event ID 1224: TCP: Connection Tcb template changed.

#
Channel
Diagnostic
Level
Verbose
Task
TcpTemplateChanged

Description

TCP: Connection Tcb template changed. New template=TemplateType. Context=Context.

Message #

TCP: Connection %1 template changed. New template=%2. Context=%3.

Fields #

NameDescription
Tcb Pointer
TemplateType UInt32
Context UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1224",
    "version": "0",
    "level": "5",
    "task": "1224",
    "opcode": "0",
    "keywords": 9223372586610589696,
    "time_created": "2026-03-16T00:21:38.719121800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0EEE7560",
    "TemplateType": "       0",
    "Context": "Initializing Template Accept TCB"
  },
  "message": ""
}

Event ID 1225: TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount.

#
Channel
Diagnostic
Task
TcpDataTransferEcnAlpha

Description

TCP: connection Tcb: End of a round, SndRound = SndRound, Bytes sent = EcnTotalByteCount. Bytes marked = EcnTotalMarkedCount, ThAck = ThAck, updated EcnAlpha = EcnAlpha.

Message #

TCP: connection %1: End of a round, SndRound = %2, Bytes sent = %3. Bytes marked = %4, ThAck = %5, updated EcnAlpha = %6.

Fields #

NameDescription
Tcb Pointer
SndRound UInt32
EcnTotalByteCount UInt32
EcnTotalMarkedCount UInt32
ThAck UInt32
EcnAlpha UInt32

Event ID 1226: TCP: interface IfIndex: RSC state changed, IPV4 State = StateV4, IPV4 Failure Reason = FailureReasonV4, IPV6 State = StateV6, IPV6 Failure Reason = FailureReasonV6, Event = Event.

#
Channel
Diagnostic
Task
TcpInterfaceRscStateChange

Message #

TCP: interface %1: RSC state changed, IPV4 State = %2, IPV4 Failure Reason = %3, IPV6 State = %4, IPV6 Failure Reason = %5, Event = %6.

Fields #

NameDescription
IfIndex UInt32
StateV4 UInt32
FailureReasonV4 UInt32
StateV6 UInt32
FailureReasonV6 UInt32
Event UInt32

Event ID 1227: TCP: connection Tcb: RSC SCU received.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpRscNblOobInfo

Description

TCP: connection Tcb: RSC SCU received. CoalescedSegCount = CoalescedSegCount, DupAckCount = DupAckCount, RscTcpTimestampDelta = RscTcpTimestampDelta, HeaderFlags = HeaderFlags, EcnCePresent = EcnCePresent.

Message #

TCP: connection %1: RSC SCU received. CoalescedSegCount = %2, DupAckCount = %3, RscTcpTimestampDelta = %4, HeaderFlags = %5, EcnCePresent = %6.

Fields #

NameDescription
Tcb Pointer
CoalescedSegCount UInt16
DupAckCount UInt16
RscTcpTimestampDelta UInt32
HeaderFlags UInt16
EcnCePresent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1227",
    "version": "0",
    "level": "5",
    "task": "1227",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:36.016716200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{10708010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A10708010",
    "CoalescedSegCount": "2",
    "DupAckCount": "0",
    "RscTcpTimestampDelta": "       0",
    "HeaderFlags": "24",
    "EcnCePresent": "       0"
  },
  "message": ""
}

Event ID 1228: TCPIP: TCB Tcb does not take fast path, Cause: Cause.

#
Channel
Diagnostic
Task
TcpLoopbackFastPathFailReason

Message #

TCPIP: TCB %1 does not take fast path, Cause: %2.

Fields #

NameDescription
Tcb Pointer
Cause UInt32

Event ID 1229: TCP: Connection Tcb send queue is idle.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpCwndRestart

Description

TCP: Connection Tcb send queue is idle. Cwnd = OldCwnd, Processor = Processor, CurrentTick = CurrentTick, IdleTick = IdleTick.

Message #

TCP: Connection %1 send queue is idle. Cwnd = %2, Processor = %4, CurrentTick = %5, IdleTick = %6.

Fields #

NameDescription
Tcb Pointer
OldCwnd UInt32
NewCwnd UInt32
Processor UInt32
CurrentTick UInt32
IdleTick UInt32
Rto UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1229",
    "version": "0",
    "level": "4",
    "task": "1221",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.390542000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "OldCwnd": " 2110976",
    "NewCwnd": "       0",
    "Processor": "       8",
    "CurrentTick": "57753291",
    "IdleTick": "57753291",
    "Rto": "       0"
  },
  "message": ""
}

Event ID 1230: RSS: Bind notification for AddressFamily on interface InterfaceIndex.

#
Channel
Diagnostic
Task
RssBindingChange

Message #

RSS: %3 notification for %2 on interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt16
Bind UInt32

Event ID 1231: RSS: Bind notification for adapter AdapterIndex.

#
Channel
Diagnostic
Task
RssPortChange

Message #

RSS: %4 notification for adapter %1.

Fields #

NameDescription
AdapterIndex UInt32
InterfaceIndex UInt32
PortNumber UInt32
Bind UInt32

Event ID 1232: RSS: ReferenceAdded reference on adapter AdapterIndex.

#
Channel
Diagnostic
Task
RssPortReference

Message #

RSS: %4 reference on adapter %1.

Fields #

NameDescription
AdapterIndex UInt32
ExistingInterfaceIndex UInt32
ExistingPortNumber UInt32
ReferenceAdded UInt8

Event ID 1233: RSS: adapter AdapterIndex with capabilities CapabilitiesFlags and NumberOfReceiveQueues receive queues.

#
Channel
Diagnostic
Task
RssPortCapabilities

Message #

RSS: adapter %1 with capabilities %2 and %4 receive queues.

Fields #

NameDescription
AdapterIndex UInt32
CapabilitiesFlags UInt32
NumberOfInterruptMessages UInt32
NumberOfReceiveQueues UInt32

Event ID 1234: RSS: adapter AdapterIndex processor group GroupNumber maximum processors MaximumProcessors processor affinity GroupAffinity.

#
Channel
Diagnostic
Task
RssPortProcessors

Message #

RSS: adapter %1 processor group %2 maximum processors %3 processor affinity %4.

Fields #

NameDescription
AdapterIndex UInt32
GroupNumber UInt16
MaximumProcessors UInt32
GroupAffinity UInt64
AvailableProcessorsSize UInt32
AvailableProcessors Binary

Event ID 1235: RSS: assigning processor ProcessorIndex from adapter PreviousAdapterIndex to NewAdapterIndex.

#
Channel
Diagnostic
Task
RssProcessorAssignment

Message #

RSS: assigning processor %2 from adapter %3 to %1.

Fields #

NameDescription
NewAdapterIndex UInt32
ProcessorIndex UInt32
PreviousAdapterIndex UInt32
TriggeringProcessorIndex UInt32

Event ID 1236: RSS: unassigning processor ProcessorIndex from adapter PreviousAdapterIndex.

#
Channel
Diagnostic
Task
RssProcessorUnassignment

Message #

RSS: unassigning processor %2 from adapter %1.

Fields #

NameDescription
PreviousAdapterIndex UInt32
ProcessorIndex UInt32

Event ID 1237: RSS: adapter AdapterIndex reassigning indirection entry IndirectionIndex from processor OldProcessorIndex to NewProcessorIndex.

#
Channel
Diagnostic
Task
RssIndirectionChange

Message #

RSS: adapter %1 reassigning indirection entry %2 from processor %3 to %4.

Fields #

NameDescription
AdapterIndex UInt32
IndirectionIndex UInt16
OldProcessorIndex UInt32
NewProcessorIndex UInt32

Event ID 1238: RSS: adapter AdapterIndex removing processor ProcessorIndex from its indirection table.

#
Channel
Diagnostic
Task
RssProcessorConsolidation

Message #

RSS: adapter %1 removing processor %2 from its indirection table.

Fields #

NameDescription
AdapterIndex UInt32
ProcessorIndex UInt8

Event ID 1239: RSS: adapter AdapterIndex changing Setting to Value.

#
Channel
Diagnostic
Task
RssConfigurationChange

Message #

RSS: adapter %1 changing %2 to %3.

Fields #

NameDescription
AdapterIndex UInt32
Setting UInt32
Value UInt32

Event ID 1240: RSS: Failed to FailureDescription on IfIndex InterfaceIndex: Status.

#
Channel
Diagnostic
Task
RssFailure

Message #

RSS: Failed to %2 on IfIndex %1: %3

Fields #

NameDescription
InterfaceIndex UInt32
FailureDescription UInt32
Status UInt32NTSTATUS reference

Event ID 1241: RSS: bind completed successfully for AddressFamily on interface InterfaceIndex.

#
Channel
Diagnostic
Task
RssBindingBindComplete

Message #

RSS: bind completed successfully for %2 on interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt16

Event ID 1242: RSS: bind completed successfully for adapter AdapterIndex.

#
Channel
Diagnostic
Task
RssPortBindComplete

Message #

RSS: bind completed successfully for adapter %1.

Fields #

NameDescription
AdapterIndex UInt32

Event ID 1243: RSS: adapter AdapterIndex not supported.

#
Channel
Diagnostic
Task
RssPortNotSupported

Message #

RSS: adapter %1 not supported.

Fields #

NameDescription
AdapterIndex UInt32

Event ID 1244: RSS: adapter AdapterIndex indirection table initialized on group GroupNumber with processor set ActiveAffinity.

#
Channel
Diagnostic
Task
RssInitializeIndirectionTable

Message #

RSS: adapter %1 indirection table initialized on group %4 with processor set %5.

Fields #

NameDescription
AdapterIndex UInt32
IndirectionTableSize UInt32
IndirectionTable Binary
GroupNumber UInt16
ActiveAffinity UInt64

Event ID 1245: RSS: Rundown: interface InterfaceIndex with adapter AdapterIndex at port PortNumber.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
RssBindingRundown

Message #

RSS: Rundown: interface %1 with adapter %2 at port %3.

Fields #

NameDescription
InterfaceIndex UInt32
AdapterIndex UInt32
PortNumber UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1245",
    "version": "0",
    "level": "4",
    "task": "1245",
    "opcode": "0",
    "keywords": 9223372586610591888,
    "time_created": "2026-03-16T00:21:34.295777000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{517fdda0-f803-ffff-0600-000000000000}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "InterfaceIndex": "       6",
    "AdapterIndex": "       6",
    "PortNumber": "       0"
  },
  "message": ""
}

Event ID 1246: RSS: Rundown: adapter AdapterIndex hash info HashInfo maximum processors MaximumProcessors group GroupNumber affinity GroupAffinity active processors ActiveAffinity active mode: ActiveMode.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
RssPortRundown

Message #

RSS: Rundown: adapter %1 hash info %2 maximum processors %3 group %4 affinity %5 active processors %6 active mode: %7.

Fields #

NameDescription
AdapterIndex UInt32
HashInfo UInt32
MaximumProcessors UInt32
GroupNumber UInt16
GroupAffinity UInt64
ActiveAffinity UInt64
ActiveMode UInt32
IndirectionTableSize UInt32
IndirectionTable Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1246",
    "version": "0",
    "level": "4",
    "task": "1246",
    "opcode": "0",
    "keywords": 9223372586610591888,
    "time_created": "2026-03-15T23:26:13.264909200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0f1f9564-f803-ffff-0400-000000000000}"
    },
    "execution": {
      "process_id": "15176",
      "thread_id": "13152"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AdapterIndex": "       4",
    "HashInfo": "0xD701",
    "MaximumProcessors": "      14",
    "GroupNumber": "0",
    "GroupAffinity": "0x3FFF",
    "ActiveAffinity": "0x3FFF",
    "ActiveMode": "    1002",
    "IndirectionTableSize": "     128",
    "IndirectionTable": "0x000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D000102030405060708090A0B0C0D0001"
  },
  "message": ""
}

Event ID 1247: RSS: interface InterfaceIndex support: Capability.

#
Channel
Diagnostic
Task
RssBindingCapability

Message #

RSS: interface %1 support: %2.

Fields #

NameDescription
InterfaceIndex UInt32
Capability UInt32

Event ID 1248: NDKPI Create CQ: RequestContext RequestContext Adapter NdkAdapter CqDepth CqDepth CqNotificationContext CqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.

#
Channel
Diagnostic
Task
Ndkpi_Create_Cq

Message #

NDKPI Create CQ: RequestContext %6 Adapter %1 CqDepth %2 CqNotificationContext %3 AffinityMask %4 AffinityGroup %5

Fields #

NameDescription
NdkAdapter Pointer
CqDepth UInt32
CqNotificationContext Pointer
AffinityMask UInt64
AffinityGroup UInt16
RequestContext Pointer

Event ID 1249: NDKPI Create Completion: RequestContext RequestContext Status Status (CompletionType) NdkObjectType NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Create_Completion

Message #

NDKPI Create Completion: RequestContext %1 Status %2 (%4) %5 %3

Fields #

NameDescription
RequestContext Pointer
Status UInt32NTSTATUS reference
NdkObject Pointer
CompletionType UInt32
NdkObjectType UInt32

Event ID 1250: NDKPI Close NdkObjectType: RequestContext RequestContext NdkObjectType NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Close_Obj

Message #

NDKPI Close %2: RequestContext %3 %2 %1

Fields #

NameDescription
NdkObject Pointer
NdkObjectType UInt32
RequestContext Pointer

Event ID 1251: NDKPI Close Completion: RequestContext RequestContext (CompletionType).

#
Channel
Diagnostic
Task
Ndkpi_Close_Completion

Message #

NDKPI Close Completion: RequestContext %1 (%2)

Fields #

NameDescription
RequestContext Pointer
CompletionType UInt32

Event ID 1252: NDKPI Resize CQ: RequestContext RequestContext CQ NdkCq CqDepth CqDepth.

#
Channel
Diagnostic
Task
Ndkpi_Resize_Cq

Message #

NDKPI Resize CQ: RequestContext %3 CQ %1 CqDepth %2

Fields #

NameDescription
NdkCq Pointer
CqDepth UInt32
RequestContext Pointer

Event ID 1253: NDKPI Request Completion: RequestContext RequestContext Status Status (CompletionType).

#
Channel
Diagnostic
Task
Ndkpi_Request_Completion

Message #

NDKPI Request Completion: RequestContext %1 Status %2 (%3)

Fields #

NameDescription
RequestContext Pointer
Status UInt32NTSTATUS reference
CompletionType UInt32

Event ID 1254: NDKPI Arm CQ: CQ NdkCq ArmType.

#
Channel
Diagnostic
Task
Ndkpi_Arm_Cq

Message #

NDKPI Arm CQ: CQ %1 %2

Fields #

NameDescription
NdkCq Pointer
ArmType UInt32

Event ID 1255: NDKPI Result ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext.

#
Channel
Diagnostic
Task
Ndkpi_Cq_Result

Message #

NDKPI Result %6/%7: CQ %1 RequestContext %5 Status %2 BytesTransferred %3 QpContext %4

Fields #

NameDescription
NdkCq Pointer
Status UInt32NTSTATUS reference
BytesTransferred UInt32
QpContext Pointer
RequestContext Pointer
ResultIndex Int32
ResultCount Int32

Event ID 1256: NDKPI Create MR: RequestContext RequestContext PD NdkPd FastRegister FastRegister.

#
Channel
Diagnostic
Task
Ndkpi_Create_Mr

Message #

NDKPI Create MR: RequestContext %3 PD %1 FastRegister %2

Fields #

NameDescription
NdkPd Pointer
FastRegister UInt32
RequestContext Pointer

Event ID 1257: NDKPI Flush: QP NdkQp.

#
Channel
Diagnostic
Task
Ndkpi_Flush

Message #

NDKPI Flush: QP %1

Fields #

NameDescription
NdkQp Pointer

Event ID 1258: NDKPI Send (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Send

Message #

NDKPI Send (SGE %8/%6): RequestContext %2 QP %1 SGE %3/%4/%5 Flags %7

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32

Event ID 1259: NDKPI Receive (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken.

#
Channel
Diagnostic
Task
Ndkpi_Receive

Message #

NDKPI Receive (SGE %8/%6): RequestContext %2 QP %1 SGE %3/%4/%5

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32

Event ID 1260: NDKPI Register MR: RequestContext RequestContext MR NdkMr MDL Mdl Length Length Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Register_Mr

Message #

NDKPI Register MR: RequestContext %5 MR %1 MDL %2 Length %3 Flags %4

Fields #

NameDescription
NdkMr Pointer
Mdl Pointer
Length UInt64
Flags UInt32
RequestContext Pointer

Event ID 1261: NDKPI Deregister MR: RequestContext RequestContext MR NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Deregister_Mr

Message #

NDKPI Deregister MR: RequestContext %2 MR %1

Fields #

NameDescription
NdkObject Pointer
RequestContext Pointer

Event ID 1262: NDKPI Initialize FastRegister MR: RequestContext RequestContext MR NdkMr AdapterPageCount AdapterPageCount RemoteAccess RemoteAccess.

#
Channel
Diagnostic
Task
Ndkpi_Initialize_Fast_Register_Mr

Message #

NDKPI Initialize FastRegister MR: RequestContext %4 MR %1 AdapterPageCount %2 RemoteAccess %3

Fields #

NameDescription
NdkMr Pointer
AdapterPageCount UInt32
RemoteAccess UInt32
RequestContext Pointer

Event ID 1263: NDKPI Modify SRQ: RequestContext RequestContext SRQ NdkSrq SrqDepth SrqDepth NotifyThreshold NotifyThreshold.

#
Channel
Diagnostic
Task
Ndkpi_Modify_Srq

Message #

NDKPI Modify SRQ: RequestContext %4 SRQ %1 SrqDepth %2 NotifyThreshold %3

Fields #

NameDescription
NdkSrq Pointer
SrqDepth UInt32
NotifyThreshold UInt32
RequestContext Pointer

Event ID 1264: NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SrcAddress SrcSockAddr DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.

#
Channel
Diagnostic
Task
Ndkpi_Connect

Message #

NDKPI Connect: RequestContext %9 Connector %1 QP %2 SrcAddress %4 DestAddress %6 IRD %7 ORD %8 PrivateDataLength %11

Fields #

NameDescription
NdkConnector Pointer
NdkQp Pointer
SrcSockAddrLength UInt32
SrcSockAddr Binary
DestSockAddrLength UInt32
DestSockAddr Binary
IRD UInt32
ORD UInt32
RequestContext Pointer
NdkSharedEndpoint Pointer
PrivateDataLength UInt32

Event ID 1265: NDKPI Connect: RequestContext RequestContext Connector NdkConnector QP NdkQp SharedEndpoint NdkSharedEndpoint DestAddress DestSockAddr IRD IRD ORD ORD PrivateDataLength PrivateDataLength.

#
Channel
Diagnostic
Task
Ndkpi_Connect_Shared_Endpoint

Message #

NDKPI Connect: RequestContext %9 Connector %1 QP %2 SharedEndpoint %10 DestAddress %6 IRD %7 ORD %8 PrivateDataLength %11

Fields #

NameDescription
NdkConnector Pointer
NdkQp Pointer
SrcSockAddrLength UInt32
SrcSockAddr Binary
DestSockAddrLength UInt32
DestSockAddr Binary
IRD UInt32
ORD UInt32
RequestContext Pointer
NdkSharedEndpoint Pointer
PrivateDataLength UInt32

Event ID 1266: NDKPI CompleteConnect: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Complete_Connect

Message #

NDKPI CompleteConnect: RequestContext %3 Connector %1 DisconnectEventContext %2

Fields #

NameDescription
NdkConnector Pointer
DisconnectEventContext Pointer
RequestContext Pointer

Event ID 1267: NDKPI Accept: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Accept

Message #

NDKPI Accept: RequestContext %6 Connector %1 QP %2 IRD %3 ORD %4 PrivateDataLength %7 DisconnectEventContext %5

Fields #

NameDescription
NdkConnector Pointer
NdkQp Pointer
IRD UInt32
ORD UInt32
DisconnectEventContext Pointer
RequestContext Pointer
PrivateDataLength UInt32

Event ID 1268: NDKPI Disconnect: RequestContext RequestContext Connector NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Disconnect

Message #

NDKPI Disconnect: RequestContext %2 Connector %1

Fields #

NameDescription
NdkObject Pointer
RequestContext Pointer

Event ID 1269: NDKPI Listen: RequestContext RequestContext Listener NdkListener Address SockAddr.

#
Channel
Diagnostic
Task
Ndkpi_Listen

Message #

NDKPI Listen: RequestContext %4 Listener %1 Address %3

Fields #

NameDescription
NdkListener Pointer
SockAddrLength UInt32
SockAddr Binary
RequestContext Pointer

Event ID 1270: NDKPI Create MW: RequestContext RequestContext PD NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Create_Mw

Message #

NDKPI Create MW: RequestContext %2 PD %1

Fields #

NameDescription
NdkObject Pointer
RequestContext Pointer

Event ID 1271: NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext Af...

#
Channel
Diagnostic
Task
Ndkpi_Create_Srq

Description

NDKPI Create SRQ: RequestContext RequestContext PD NdkPd SrqDepth SrqDepth MaxReceiveRequestSge MaxReceiveRequestSge NotifyThreshold NotifyThreshold SrqNotificationContext SrqNotificationContext AffinityMask AffinityMask AffinityGroup AffinityGroup.

Message #

NDKPI Create SRQ: RequestContext %8 PD %1 SrqDepth %2 MaxReceiveRequestSge %3 NotifyThreshold %4 SrqNotificationContext %5 AffinityMask %6 AffinityGroup %7

Fields #

NameDescription
NdkPd Pointer
SrqDepth UInt32
MaxReceiveRequestSge UInt32
NotifyThreshold UInt32
SrqNotificationContext Pointer
AffinityMask UInt64
AffinityGroup UInt16
RequestContext Pointer

Event ID 1272: NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth M...

#
Channel
Diagnostic
Task
Ndkpi_Create_Qp

Description

NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq QPContext QPContext ReceiveQueueDepth ReceiveQueueDepth InitiatorQueueDepth InitiatorQueueDepth MaxReceiveRequestSge MaxReceiveRequestSge MaxInitiatorRequestSge MaxInitiatorRequestSge.

Message #

NDKPI Create QP: RequestContext %9 PD %1 ReceiveCQ %2 InitiatorCQ %3 QPContext %4 ReceiveQueueDepth %5 InitiatorQueueDepth %6 MaxReceiveRequestSge %7 MaxInitiatorRequestSge %8

Fields #

NameDescription
NdkPd Pointer
ReceiveCq Pointer
InitiatorCq Pointer
QPContext Pointer
ReceiveQueueDepth UInt32
InitiatorQueueDepth UInt32
MaxReceiveRequestSge UInt32
MaxInitiatorRequestSge UInt32
RequestContext Pointer
NdkSrq Pointer

Event ID 1273: NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge Max...

#
Channel
Diagnostic
Task
Ndkpi_Create_Qp_Srq

Description

NDKPI Create QP: RequestContext RequestContext PD NdkPd ReceiveCQ ReceiveCq InitiatorCQ InitiatorCq SRQ NdkSrq QPContext QPContext InitiatorQueueDepth InitiatorQueueDepth MaxInitiatorRequestSge MaxInitiatorRequestSge.

Message #

NDKPI Create QP: RequestContext %9 PD %1 ReceiveCQ %2 InitiatorCQ %3 SRQ %10 QPContext %4 InitiatorQueueDepth %6 MaxInitiatorRequestSge %8

Fields #

NameDescription
NdkPd Pointer
ReceiveCq Pointer
InitiatorCq Pointer
QPContext Pointer
ReceiveQueueDepth UInt32
InitiatorQueueDepth UInt32
MaxReceiveRequestSge UInt32
MaxInitiatorRequestSge UInt32
RequestContext Pointer
NdkSrq Pointer

Event ID 1274: NDKPI Create PD: RequestContext RequestContext Adapter NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Create_Pd

Message #

NDKPI Create PD: RequestContext %2 Adapter %1

Fields #

NameDescription
NdkObject Pointer
RequestContext Pointer

Event ID 1275: NDKPI Create SharedEndpoint: RequestContext RequestContext Adapter NdkListener Address SockAddr.

#
Channel
Diagnostic
Task
Ndkpi_Create_Shared_Endpoint

Message #

NDKPI Create SharedEndpoint: RequestContext %4 Adapter %1 Address %3

Fields #

NameDescription
NdkListener Pointer
SockAddrLength UInt32
SockAddr Binary
RequestContext Pointer

Event ID 1276: NDKPI Create Connector: RequestContext RequestContext Adapter NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Create_Connector

Message #

NDKPI Create Connector: RequestContext %2 Adapter %1

Fields #

NameDescription
NdkObject Pointer
RequestContext Pointer

Event ID 1277: NDKPI Create Listener: RequestContext RequestContext Adapter NdkAdapter ConnectEventContext ConnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Create_Listener

Message #

NDKPI Create Listener: RequestContext %3 Adapter %1 ConnectEventContext %2

Fields #

NameDescription
NdkAdapter Pointer
ConnectEventContext Pointer
RequestContext Pointer

Event ID 1278: NDKPI Build LAM: RequestContext RequestContext Adapter NdkAdapter MDL Mdl Length Length LAMBuffer LAMBuffer LAMBufferSize LAMBufferSize.

#
Channel
Diagnostic
Task
Ndkpi_Build_Lam

Message #

NDKPI Build LAM: RequestContext %4 Adapter %1 MDL %2 Length %3 LAMBuffer %5 LAMBufferSize %6

Fields #

NameDescription
NdkAdapter Pointer
Mdl Pointer
Length UInt64
RequestContext Pointer
LAMBuffer Pointer
LAMBufferSize UInt32

Event ID 1279: NDKPI Release LAM: Adapter NdkAdapter LAMBuffer LAMBuffer.

#
Channel
Diagnostic
Task
Ndkpi_Release_Lam

Message #

NDKPI Release LAM: Adapter %1 LAMBuffer %2

Fields #

NameDescription
NdkAdapter Pointer
LAMBuffer Pointer

Event ID 1280: NDKPI CQ Notification Callback: CqNotificationContext CqNotificationContext CqStatus CqStatus.

#
Channel
Diagnostic
Task
Ndkpi_Cq_Notification_Callback

Message #

NDKPI CQ Notification Callback: CqNotificationContext %1 CqStatus %2

Fields #

NameDescription
CqNotificationContext Pointer
CqStatus UInt32

Event ID 1281: NDKPI SRQ Notification Callback: SrqNotificationContext SrqNotificationContext SrqStatus SrqStatus.

#
Channel
Diagnostic
Task
Ndkpi_Srq_Notification_Callback

Message #

NDKPI SRQ Notification Callback: SrqNotificationContext %1 SrqStatus %2

Fields #

NameDescription
SrqNotificationContext Pointer
SrqStatus UInt32

Event ID 1282: NDKPI Disconnect Event Callback: DisconnectEventContext DisconnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Disconnect_Event_Callback

Message #

NDKPI Disconnect Event Callback: DisconnectEventContext %1

Fields #

NameDescription
DisconnectEventContext Pointer

Event ID 1283: NDKPI Connect Event Callback: ConnectEventContext ConnectEventContext Connector NdkConnector.

#
Channel
Diagnostic
Task
Ndkpi_Connect_Event_Callback

Message #

NDKPI Connect Event Callback: ConnectEventContext %1 Connector %2

Fields #

NameDescription
ConnectEventContext Pointer
NdkConnector Pointer

Event ID 1284: NDKPI Got TokenType Token Token from NdkObjectType NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Get_Token

Message #

NDKPI Got %3 Token %4 from %2 %1

Fields #

NameDescription
NdkObject Pointer
NdkObjectType UInt32
TokenType UInt32
Token UInt32

Event ID 1285: NDKPI Got SockAddrType Address SockAddr from NdkObjectType NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Get_Sockaddr

Message #

NDKPI Got %3 Address %5 from %2 %1

Fields #

NameDescription
NdkObject Pointer
NdkObjectType UInt32
SockAddrType UInt32
SockAddrLength UInt32
SockAddr Binary

Event ID 1286: NDKPI SockAddrType Address query failure Status on NdkObjectType NdkObject.

#
Channel
Diagnostic
Task
Ndkpi_Get_Sockaddr_Failure

Message #

NDKPI %3 Address query failure %4 on %2 %1

Fields #

NameDescription
NdkObject Pointer
NdkObjectType UInt32
SockAddrType UInt32
Status UInt32NTSTATUS reference

Event ID 1287: NDKPI Reject: Connector NdkConnector PrivateDataLength PrivateDataLength Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Reject

Message #

NDKPI Reject: Connector %1 PrivateDataLength %2 Status %3

Fields #

NameDescription
NdkConnector Pointer
PrivateDataLength UInt32
Status UInt32NTSTATUS reference

Event ID 1288: NDKPI Get Connect Data: Connector NdkConnector IRD IRD ORD ORD PrivateDataLength PrivateDataLength Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Get_Connect_Data

Message #

NDKPI Get Connect Data: Connector %1 IRD %2 ORD %3 PrivateDataLength %4 Status %5

Fields #

NameDescription
NdkConnector Pointer
IRD UInt32
ORD UInt32
PrivateDataLength UInt32
Status UInt32NTSTATUS reference

Event ID 1289: NDKPI Work Request Inline Failure: RequestContext RequestContext QP NdkQp Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Work_Request_Inline_Failure

Message #

NDKPI Work Request Inline Failure: RequestContext %2 QP %1 Status %3

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
Status UInt32NTSTATUS reference

Event ID 1290: NDKPI Bind: RequestContext RequestContext QP NdkQp MR NdkMr MW NdkMw VirtualAddress VirtualAddress Length Length Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Bind

Message #

NDKPI Bind: RequestContext %2 QP %1 MR %3 MW %4 VirtualAddress %5 Length %6 Flags %7

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
NdkMr Pointer
NdkMw Pointer
VirtualAddress Pointer
Length UInt64
Flags UInt32

Event ID 1291: NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress F...

#
Channel
Diagnostic
Task
Ndkpi_Fast_Register

Description

NDKPI FastRegister: RequestContext RequestContext QP NdkQp MR NdkMr AdapterPageCount AdapterPageCount AdapterPageArray AdapterPageArray FBO FBO Length Length BaseVirtualAddress BaseVirtualAddress Flags Flags.

Message #

NDKPI FastRegister: RequestContext %2 QP %1 MR %3 AdapterPageCount %4 AdapterPageArray %5 FBO %6 Length %7 BaseVirtualAddress %8 Flags %9

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
NdkMr Pointer
AdapterPageCount UInt32
AdapterPageArray Pointer
FBO UInt32
Length UInt64
BaseVirtualAddress Pointer
Flags UInt32

Event ID 1292: NDKPI Invalidate: RequestContext RequestContext QP NdkQp NdkObjectType NdkObject Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Invalidate

Message #

NDKPI Invalidate: RequestContext %2 QP %1 %4 %3 Flags %5

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
NdkObject Pointer
NdkObjectType UInt32
Flags UInt32

Event ID 1293: NDKPI Read (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Read

Message #

NDKPI Read (SGE %8/%6): RequestContext %2 QP %1 SGE %3/%4/%5 RemoteAddress %9 RemoteToken %10 Flags %7

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32
RemoteAddress UInt64
RemoteToken UInt32

Event ID 1294: NDKPI Write (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteAddress RemoteAddress RemoteToken RemoteToken Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Write

Message #

NDKPI Write (SGE %8/%6): RequestContext %2 QP %1 SGE %3/%4/%5 RemoteAddress %9 RemoteToken %10 Flags %7

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32
RemoteAddress UInt64
RemoteToken UInt32

Event ID 1295: NDKPI SRQ Receive (SGE SgeIndex/NumSge): RequestContext RequestContext SRQ NdkSrq SGE SgeAddress/SgeLength/SgeMemoryRegionToken.

#
Channel
Diagnostic
Task
Ndkpi_SrqReceive

Message #

NDKPI SRQ Receive (SGE %8/%6): RequestContext %2 SRQ %1 SGE %3/%4/%5

Fields #

NameDescription
NdkSrq Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32

Event ID 1296: NDKPI SRQ Work Request Inline Failure: RequestContext RequestContext SRQ NdkSrq Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Srq_Work_Request_Inline_Failure

Message #

NDKPI SRQ Work Request Inline Failure: RequestContext %2 SRQ %1 Status %3

Fields #

NameDescription
NdkSrq Pointer
RequestContext Pointer
Status UInt32NTSTATUS reference

Event ID 1297: NDKPI Open Adapter: InterfaceIndex InterfaceIndex Adapter NdkAdapter Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Open_Adapter

Message #

NDKPI Open Adapter: InterfaceIndex %1 Adapter %2 Status %3

Fields #

NameDescription
InterfaceIndex UInt32
NdkAdapter Pointer
Status UInt32NTSTATUS reference

Event ID 1298: NDKPI Close Adapter (Enter): Adapter NdkAdapter.

#
Channel
Diagnostic
Task
Ndkpi_Close_Adapter_Enter

Message #

NDKPI Close Adapter (Enter): Adapter %1

Fields #

NameDescription
NdkAdapter Pointer

Event ID 1299: NDKPI Close Adapter (Exit): Adapter NdkAdapter.

#
Channel
Diagnostic
Task
Ndkpi_Close_Adapter_Exit

Message #

NDKPI Close Adapter (Exit): Adapter %1

Fields #

NameDescription
NdkAdapter Pointer

Event ID 1300: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpConnectionRundown

Description

TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) exists. State = State. PID = Pid.

Message #

TCP: connection %1 (local=%3 remote=%5) exists. State = %6. PID = %7.

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
State UInt32
Pid UInt32
ProcessStartKey UInt64
SendTrackerEnabled UInt32
RcvBufSet UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1300",
    "version": "2",
    "level": "4",
    "task": "1300",
    "opcode": "0",
    "keywords": 9223372054034646148,
    "time_created": "2026-03-16T00:21:34.294712000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1cf5fec0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1CF5FEC0",
    "LocalAddressLength": "      16",
    "LocalAddress": "10.2.10.21:52992",
    "RemoteAddressLength": "      16",
    "RemoteAddress": "10.2.10.11:49669",
    "State": "      10",
    "Pid": "       0",
    "ProcessStartKey": "0",
    "SendTrackerEnabled": "       0"
  },
  "message": ""
}

Event ID 1301: NDKPI Interface Event: InterfaceIndex InterfaceIndex, NDK-Operational NDKOperational, EventDescription (StatusCode).

#
Channel
Diagnostic
Task
Ndkpi_Interface_Event

Message #

NDKPI Interface Event: InterfaceIndex %1, NDK-Operational %3, %2 (%4)

Fields #

NameDescription
InterfaceIndex UInt32
EventDescription UInt32
NDKOperational UInt32
StatusCode UInt32NTSTATUS reference

Event ID 1302: Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.

#
Channel
Diagnostic
Task
TcpipWakePacketIndicated

Description

Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination: DestAddress : DestPort.

Message #

Network adapter Luid %1 received a wake packet matching pattern %2. Protocol: %8. Destination MAC address: %5. Source: %6 : %9, Destination: %7 : %10.

Fields #

NameDescription
AdapterLuid UInt64
PatternFriendlyName UnicodeString
DlAddrLength UInt32
SrcDLAddress Binary
DestDLAddress Binary
SrcAddress UInt32
DestAddress UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
SrcPort UInt16
DestPort UInt16

Event ID 1302: Network adapter Luid .

#
Channel
Operational
Task
TcpipWakePacketIndicated

Description

Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination: : .

Message #

Network adapter Luid %1 received a wake packet matching pattern %2. Protocol: %8. Destination MAC address: %5. Source: %6 : %9, Destination: %7 : %10.

Fields #

NameDescription
AdapterLuid UInt64
PatternFriendlyName UnicodeString
DlAddrLength UInt32
SrcDLAddress Binary
DestDLAddress Binary
SrcAddress UInt32
DestAddress UInt32
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
SrcPort UInt16
DestPort UInt16

Event ID 1303: Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName.

#
Channel
Diagnostic
Task
TcpipWakePacketIndicated

Description

Network adapter Luid AdapterLuid received a wake packet matching pattern PatternFriendlyName. Protocol: Protocol. Destination MAC address: DestDLAddress. Source: SrcAddress : SrcPort, Destination DestAddress : DestPort.

Message #

Network adapter Luid %1 received a wake packet matching pattern %2. Protocol: %9. Destination MAC address: %5. Source: %7 : %10, Destination %8 : %11.

Fields #

NameDescription
AdapterLuid UInt64
PatternFriendlyName UnicodeString
DlAddrLength UInt32
SrcDLAddress Binary
DestDLAddress Binary
IpAddrLength UInt32
SrcAddress Binary
DestAddress Binary
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
SrcPort UInt16
DestPort UInt16

Event ID 1303: Network adapter Luid .

#
Channel
Operational
Task
TcpipWakePacketIndicated

Description

Network adapter Luid received a wake packet matching pattern . Protocol: . Destination MAC address: . Source: : , Destination : .

Message #

Network adapter Luid %1 received a wake packet matching pattern %2. Protocol: %9. Destination MAC address: %5. Source: %7 : %10, Destination %8 : %11.

Fields #

NameDescription
AdapterLuid UInt64
PatternFriendlyName UnicodeString
DlAddrLength UInt32
SrcDLAddress Binary
DestDLAddress Binary
IpAddrLength UInt32
SrcAddress Binary
DestAddress Binary
Protocol UInt32
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
SrcPort UInt16
DestPort UInt16

Event ID 1304: TCP: Connection Tcb: Silent Mode SilentModeEvent Context Context.

#
Channel
Diagnostic
Task
TcpipSilentMode

Message #

TCP: Connection %1: Silent Mode %2 Context %3

Fields #

NameDescription
Tcb Pointer
SilentModeEvent UInt32
Context Pointer

Event ID 1305: TCP: Connection Tcb notification channel request.

#
Channel
Diagnostic
Task
TcpCreateNotificationChannelRequest

Description

TCP: Connection Tcb notification channel request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, Status = Status.

Message #

TCP: Connection %1 notification channel request. NcmContext = %2, TCB State = %3, PID = %4, IsLoopback = %5, Status = %7.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
State UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1306: TCP: Connection Tcb query notification channel status request.

#
Channel
Diagnostic
Task
TcpQueryNotificationChannelStatusRequest

Description

TCP: Connection Tcb query notification channel status request. NcmContext = NcmContext, PID = Pid, Channel Status = ChannelStatus, Status = Status.

Message #

TCP: Connection %1 query notification channel status request. NcmContext = %2, PID = %4, Channel Status = %6, Status = %7.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
State UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1307: TCP: Connection Tcb notification channel request processed.

#
Channel
Diagnostic
Task
TcpCreateNotificationChannelRequestProcessed

Description

TCP: Connection Tcb notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.

Message #

TCP: Connection %1 notification channel request processed. NcmContext = %2, PID = %3, Status = %4 PushNotificationId = %5.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
Pid UInt32
Status UInt32NTSTATUS reference
PushNotificationGuid GUID

Event ID 1308: TCP: Connection Tcb notification channel signal event.

#
Channel
Diagnostic
Task
TcpSignalNotificationChannelEvent

Description

TCP: Connection Tcb notification channel signal event. NcmContext = NcmContext, PID = Pid, RcvNxt = RcvNxt, Delivered Data = Delivered, Indicated Data = Indicated, FinalEvent = FinalEvent.

Message #

TCP: Connection %1 notification channel signal event. NcmContext = %2, PID = %3, RcvNxt = %4, Delivered Data = %5, Indicated Data = %6, FinalEvent = %7.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
Pid UInt32
RcvNxt UInt32
Delivered UInt32
Indicated UInt32
FinalEvent UInt32

Event ID 1309: TCP: Connection Tcb notification channel detached.

#
Channel
Diagnostic
Task
TcpDetachNotificationChannel

Description

TCP: Connection Tcb notification channel detached. NcmContext = NcmContext, TCB State = State. Cleanup NcmContext = IsLoopback.

Message #

TCP: Connection %1 notification channel detached. NcmContext = %2, TCB State = %3. Cleanup NcmContext = %5

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
State UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1310: TCP: Connection Tcb notification channel unlinked.

#
Channel
Diagnostic
Task
TcpUnlinkNotificationChannel

Description

TCP: Connection Tcb notification channel unlinked. TCB State = State.

Message #

TCP: Connection %1 notification channel unlinked. TCB State = %3.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
State UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1311: TCP: Connection Tcb notification channel wake pattern plumbing.

#
Channel
Diagnostic
Task
TcpPlumbWakePattern

Description

TCP: Connection Tcb notification channel wake pattern plumbing. SystemReserved = SystemReserved, Wake-on-Lan Handle = WolHandle, Status = Status.

Message #

TCP: Connection %1 notification channel wake pattern plumbing. SystemReserved = %2, Wake-on-Lan Handle = %3, Status = %4.

Fields #

NameDescription
Tcb Pointer
SystemReserved UInt32
WolHandle UInt32
Status UInt32NTSTATUS reference

Event ID 1312: TCP: Connection Tcb notification channel wake pattern deplumbing.

#
Channel
Diagnostic
Task
TcpDeplumbWakePattern

Description

TCP: Connection Tcb notification channel wake pattern deplumbing. Wake-on-Lan Handle = WolHandle, Status = Status.

Message #

TCP: Connection %1 notification channel wake pattern deplumbing. Wake-on-Lan Handle = %3, Status = %4.

Fields #

NameDescription
Tcb Pointer
SystemReserved UInt32
WolHandle UInt32
Status UInt32NTSTATUS reference

Event ID 1313: TCPIP: Interface index InterfaceIndex wake pattern properties.

#
Channel
Diagnostic
Task
TcpipPlumbWakePatternOnInterface

Description

TCPIP: Interface index InterfaceIndex wake pattern properties. AOAC capable = AoAcCapable, Bitmap pattern supported = BitmapPatternSupported, ARP/ND offload supported = ARPNDOffloadSupported, IP address = IPv4Address IPProtocol IPv6Address wake ready = IPAddressWakeReady, Wol handle = WolHandle, pattern priority = PhysicalMediumType, interface medium = IpAddrLength, Status = Status, Has been AOAC capable = HasBeenAoAcCapable.

Message #

TCPIP: Interface index %1 wake pattern properties. AOAC capable = %2, Bitmap pattern supported = %3, ARP/ND offload supported = %4, IP address = %9 %11 %10 wake ready = %5, pattern priority = %6, interface medium = %7, Status = %12.

Fields #

NameDescription
InterfaceIndex UInt32
AoAcCapable UInt32
BitmapPatternSupported UInt32
ARPNDOffloadSupported UInt32
IPAddressWakeReady UInt32
PatternPriority UInt32
PhysicalMediumType UInt32
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
Status UInt32NTSTATUS reference
HasBeenAoAcCapable UInt32
WolHandle UInt32

Event ID 1314: NDKPI Control CQ Interrupt Moderation: CQ NdkCq Interval ModerationInterval Count ModerationCount Status Status.

#
Channel
Diagnostic
Task
Ndkpi_Control_Cq_Im

Message #

NDKPI Control CQ Interrupt Moderation: CQ %1 Interval %2 Count %3 Status %4

Fields #

NameDescription
NdkCq Pointer
ModerationInterval UInt32
ModerationCount UInt32
Status UInt32NTSTATUS reference

Event ID 1315: TCP: Connection Tcb notification channel request processing.

#
Channel
Diagnostic
Task
TcpCreateNotificationChannelRequestProcessing

Description

TCP: Connection notification channel request processing. IsRedirected = , WfpFailure = , Status = , WaitStatus = , Local IP address = , Remote IP address = Local Port = , Remote Port = .

Message #

TCP: Connection %1 notification channel request processing. IsRedirected = %2, WfpFailure = %3, Status = %4, WaitStatus = %5, Local IP address = %7 %9 %8, Remote IP address = %10 %9 %11 Local Port = %12, Remote Port = %13.

Fields #

NameDescription
Tcb Pointer
IsRedirected UInt32
WfpFailure UInt32
Status UInt32NTSTATUS reference
WaitStatus UInt32
IpAddrLength UInt32
LocalIPv4Address UInt32
LocalIPv6Address Binary
IPProtocol UInt32
RemoteIPv4Address UInt32
RemoteIPv6Address Binary
SrcPort UInt16
DestPort UInt16

Event ID 1316: IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New Bas...

#
Channel
Diagnostic
Task
TcpipIpAddressLifetime

Description

IP: IP address lifetime = IPv4Address IPProtocol IPv6Address on interface = Interface, protocol = Protocol, CurrentTime = CurrentTime Old BaseTime = OldBaseTime Old ValidTime = OldValidTime New BaseTime = NewBaseTime New ValidTime = NewValidTime.

Message #

IP: IP address lifetime = %4 %6 %5 on interface = %1, protocol = %2, CurrentTime = %7 Old BaseTime = %8 Old ValidTime = %9 New BaseTime = %11 New ValidTime = %12.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32
CurrentTime UInt32
OldBaseTime UInt32
OldValidTime UInt32
OldPreferredTime UInt32
NewBaseTime UInt32
NewValidTime UInt32
NewPreferredTime UInt32
InterfaceGuid GUID
IpAddressLifetimeChangeReason UInt32

Event ID 1317: TCP: Repartition event Event (Type) OldPartitionCount.

#
Channel
Diagnostic
Task
TcpRepartitionEvent

Message #

TCP: Repartition event %1 (%2) %5.

Fields #

NameDescription
Event Pointer
Type UInt32
Processor UInt32
PowerSource UInt32
OldPartitionCount UInt32
NewPartitionCount UInt32
Progress UInt32

Event ID 1318: Component PowerStateTransition on processor IndicatingProcessor at Tick = CurrentTick Time = CurrentTime.

#
Channel
Diagnostic
Task
TcpipPowerStateTransitionEvent

Message #

%1 %2 on processor %3 at Tick = %4 Time = %5.

Fields #

NameDescription
Component UInt32
PowerStateTransition UInt32
IndicatingProcessor UInt32
CurrentTick UInt32
CurrentTime UInt64

Event ID 1319: Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpipTimerDpcRescheduleEvent

Description

Component timer rescheduled by processor Indicating Processor for processor Target Processor at Tick = Current Tick to Tick = Next Expiration Tick, OldScheduledExpiration = Old Scheduled Expiration NewScheduledExpiration = New Scheduled Expiration DueTime = Due Time Aperiodic = Aperiodic.

Message #

%1 timer rescheduled by processor %2 for processor %3 at Tick = %4 to Tick = %5, OldScheduledExpiration = %6 NewScheduledExpiration = %7 DueTime = %8 Aperiodic = %9.

Fields #

NameDescription
Component UInt32
IndicatingProcessor UInt32
TargetProcessor UInt32
CurrentTick UInt32
NextExpirationTick UInt32
DueTime Int64
Aperiodic UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1319",
    "version": "0",
    "level": "5",
    "task": "1460",
    "opcode": "0",
    "keywords": 9223372586610589696,
    "time_created": "2026-03-16T00:21:34.388840200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Component": "       1",
    "Indicating Processor": "       9",
    "Target Processor": "      10",
    "Current Tick": "57753289",
    "Next Expiration Tick": "57753299",
    "Old Scheduled Expiration": "577539799250",
    "New Scheduled Expiration": "577532789097",
    "Due Time": "-100000",
    "Aperiodic": "       1"
  },
  "message": ""
}

Example keys not documented in the fields table: Current Tick, Due Time, Indicating Processor, New Scheduled Expiration, Next Expiration Tick, Old Scheduled Expiration, Target Processor

Event ID 1320: Component timer fired on processor Target Processor at Tick = Current Tick, was scheduled for = Next Expiration.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpipTimerDpcFiredEvent

Message #

%1 timer fired on processor %2 at Tick = %3, was scheduled for = %4.

Fields #

NameDescription
Component UInt32
TargetProcessor UInt32
CurrentTick UInt32
NextExpiration UInt32
ExternalTrigger UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1320",
    "version": "0",
    "level": "5",
    "task": "1461",
    "opcode": "0",
    "keywords": 9223372586610589696,
    "time_created": "2026-03-16T00:21:34.401656600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Component": "       1",
    "Target Processor": "      10",
    "Current Tick": "57753302",
    "Next Expiration": "57753299",
    "Current Interrupt Time": "577532821643",
    "Scheduled Expiration Time": "577532789097",
    "External Trigger": "       0"
  },
  "message": ""
}

Example keys not documented in the fields table: Current Interrupt Time, Current Tick, External Trigger, Next Expiration, Scheduled Expiration Time, Target Processor

Event ID 1321: IP: Connecting interface InterfaceIndex, trace = TraceString.

#
Channel
Diagnostic
Task
TcpipMediaConnect

Message #

IP: Connecting interface %1, trace = %2.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1322: IP: Limited link connectivity set on interface InterfaceIndex, trace = TraceString.

#
Channel
Diagnostic
Task
TcpipLimitedLinkConnectivity

Message #

IP: Limited link connectivity set on interface %1, trace = %2.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1323: IP: Limited link connectivity reset on interface InterfaceIndex, trace = TraceString.

#
Channel
Diagnostic
Task
TcpipLimitedLinkConnectivity

Message #

IP: Limited link connectivity reset on interface %1, trace = %2.

Fields #

NameDescription
InterfaceIndex UInt32
TraceString AnsiString
CompartmentId UInt32

Event ID 1324: IP: Neighbor with IpAddress = IP Address DlAddress = DL Address on Interface = Interface changed state from Old Neighbor State to New Neighbor State due to Event = Neighbor Event.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
IpNeighborState

Message #

IP: Neighbor with IpAddress = %3 DlAddress = %5 on Interface = %1 changed state from %6 to %7 due to Event = %8.

Fields #

NameDescription
Interface UInt32
IpAddrLength UInt32
IPAddress Binary
DlAddrLength UInt32
DLAddress Binary
OldNeighborState UInt32
NewNeighborState UInt32
NeighborEvent UInt32
CompartmentId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1324",
    "version": "1",
    "level": "4",
    "task": "1324",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-16T00:22:30.711141200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Interface": "       6",
    "IpAddrLength": "      16",
    "IP Address": "10.2.10.11",
    "DlAddrLength": "       6",
    "DL Address": "0xBC241141F258",
    "Old Neighbor State": "       5",
    "New Neighbor State": "       2",
    "Neighbor Event": "       9",
    "CompartmentId": "       1"
  },
  "message": ""
}

Example keys not documented in the fields table: DL Address, IP Address, Neighbor Event, New Neighbor State, Old Neighbor State

Event ID 1325: IP: Neighbor Event on Interface = Interface from SourceIpAddress = Source IP Address for TargetIpAddress = Target IP Address.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
IpNeighborDiscovery

Message #

IP: %5 on Interface = %1 from SourceIpAddress = %3 for TargetIpAddress = %4.

Fields #

NameDescription
Interface UInt32
IpAddrLength UInt32
SourceIPAddress Binary
TargetIPAddress Binary
NeighborEvent UInt32
CompartmentId UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1325",
    "version": "1",
    "level": "5",
    "task": "1325",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-16T00:21:59.242716700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Interface": "       6",
    "IpAddrLength": "      16",
    "Source IP Address": "10.2.10.254",
    "Target IP Address": "10.2.10.21",
    "Neighbor Event": "      12",
    "CompartmentId": "       1"
  },
  "message": ""
}

Example keys not documented in the fields table: Neighbor Event, Source IP Address, Target IP Address

Event ID 1326: IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName.

#
Channel
Diagnostic
Task
IpSourceAddressSelection

Description

IP: Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).

Message #

IP: Source address %2 is preferred over %3 for Destination %4 in Compartment %5, Reason: %8 (Rule %6.%7).

Fields #

NameDescription
IpAddrLength UInt32
PreferredSourceIPAddress Binary
NonPreferredSourceIPAddress Binary
DestinationIPAddress Binary
CompartmentId UInt32
Rule UInt32
RuleExtension UInt32
RuleName UInt32

Event ID 1327: IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Opti...

#
Channel
Diagnostic
Level
Verbose
Task
IpSortedAddressPairs

Description

IP: Address pair (Preferred Source IP Address, Preferred Destination IP Address) is preferred over (Non-Preferred Source IP Address, Non-Preferred Destination IP Address) by SortOptions = Sort Option, Rule = Rule Type Rule Major.Rule Minor.

Message #

IP: Address pair (%2, %3) is preferred over (%4, %5) by SortOptions = %6, Rule = %7 %8.%9.

Fields #

NameDescription
IpAddrLength UInt32
PreferredSourceIPAddress Binary
PreferredDestinationIPAddress Binary
NonPreferredSourceIPAddress Binary
NonPreferredDestinationIPAddress Binary
SortOption UInt32
RuleType AnsiString
RuleMajor UInt32
RuleMinor UInt32
RuleName UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1327",
    "version": "1",
    "level": "5",
    "task": "1327",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-16T00:23:59.745142800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "1992",
      "thread_id": "6452"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IpAddrLength": "      28",
    "Preferred Source IP Address": "::ffff:10.2.10.21",
    "Preferred Destination IP Address": "::ffff:192.228.79.201",
    "Non-Preferred Source IP Address": "::",
    "Non-Preferred Destination IP Address": "2001:478:65::53",
    "Sort Option": "       0",
    "Rule Type": "D",
    "Rule Major": "       1",
    "Rule Minor": "       0",
    "RuleName": "      16"
  },
  "message": ""
}

Example keys not documented in the fields table: Non-Preferred Destination IP Address, Non-Preferred Source IP Address, Preferred Destination IP Address, Preferred Source IP Address, Rule Major, Rule Minor, Rule Type, Sort Option

Event ID 1328: NDKPI ResultEx ResultIndex/ResultCount: CQ NdkCq RequestContext RequestContext Status Status BytesTransferred BytesTransferred QpContext QpContext Type Type TypeSpecific TypeSpecificCompletionOutput.

#
Channel
Diagnostic
Task
Ndkpi_Cq_Result_Ex

Message #

NDKPI ResultEx %6/%7: CQ %1 RequestContext %5 Status %2 BytesTransferred %3 QpContext %4 Type %8 TypeSpecific %9

Fields #

NameDescription
NdkCq Pointer
Status UInt32NTSTATUS reference
BytesTransferred UInt32
QpContext Pointer
RequestContext Pointer
ResultIndex Int32
ResultCount Int32
Type UInt32
TypeSpecificCompletionOutput UInt64
ProviderErrorCode UInt32

Event ID 1329: NDKPI SendInvalidate (SGE SgeIndex/NumSge): RequestContext RequestContext QP NdkQp SGE SgeAddress/SgeLength/SgeMemoryRegionToken RemoteToken RemoteToken Flags Flags.

#
Channel
Diagnostic
Task
Ndkpi_Send_Invalidate

Message #

NDKPI SendInvalidate (SGE %8/%6): RequestContext %2 QP %1 SGE %3/%4/%5 RemoteToken %9 Flags %7

Fields #

NameDescription
NdkQp Pointer
RequestContext Pointer
SgeAddress Pointer
SgeLength UInt32
SgeMemoryRegionToken UInt32
NumSge Int32
Flags UInt32
SgeIndex Int32
RemoteToken UInt32

Event ID 1330: TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpDataTransferCumAck

Message #

TCP: connection %1: Cumulative Ack event, SeqNo = %5, BytesAcked = %4, CWnd = %2, SndWnd =%3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesAcked UInt32
SeqNo UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1330",
    "version": "0",
    "level": "4",
    "task": "1071",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.390572700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Cwnd": " 2110976",
    "SndWnd": " 2110976",
    "BytesAcked": "    1303",
    "SeqNo": "2307521250"
  },
  "message": ""
}

Event ID 1331: TCP: connection Tcb: CTCP Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd =SndWnd.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferCumAck

Message #

TCP: connection %1: CTCP Cumulative Ack event, SeqNo = %5, BytesAcked = %4, CWnd = %2, SndWnd =%3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesAcked UInt32
SeqNo UInt32

Event ID 1332: TCP: connection Tcb: TCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpDataTransferSend

Message #

TCP: connection %1: TCP send event, SeqNo = %5, BytesSent = %4, CWnd = %2, SndWnd = %3, SRtt = %6, RttVar = %7, RTO = %8

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesSent UInt32
SeqNo UInt32
SRtt UInt32
RttVar UInt32
RTO UInt32
RcvWnd UInt32
PacingRate UInt32
TcpState UInt32
CongestionState UInt32
SndUna UInt32
SndMax UInt32
RecoveryMax UInt32
RcvBufSet UInt32
MaxRcvBuf UInt32
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1332",
    "version": "1",
    "level": "4",
    "task": "1073",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:26:13.266633700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{ff7af7e0-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFF7AF7E0",
    "Cwnd": " 1705088",
    "SndWnd": " 1705088",
    "BytesSent": "       0",
    "SeqNo": "644684595",
    "SRtt": "     596",
    "RttVar": "     279",
    "RTO": "      60",
    "RcvWnd": "  261882"
  },
  "message": ""
}

Event ID 1333: TCP: connection Tcb: TCP CTCP send event, SeqNo = SeqNo, BytesSent = BytesSent, CWnd = Cwnd, SndWnd = SndWnd, SRtt = SRtt, RttVar = RttVar, RTO = RTO.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferSend

Message #

TCP: connection %1: TCP CTCP send event, SeqNo = %5, BytesSent = %4, CWnd = %2, SndWnd = %3, SRtt = %6, RttVar = %7, RTO = %8.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesSent UInt32
SeqNo UInt32
SRtt UInt32
RttVar UInt32
RTO UInt32
RcvWnd UInt32

Event ID 1334: UDP: Endpoint UdpEndpoint notification channel request.

#
Channel
Diagnostic
Task
UdpCreateNotificationChannelRequest

Description

UDP: Endpoint UdpEndpoint notification channel request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, IsLoopback = IsLoopback, Status = Status.

Message #

UDP: Endpoint %1 notification channel request. NcmContext = %2, Endpoint State = %3, PID = %4, IsLoopback = %5, Status = %7.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Activated UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1335: UDP: Endpoint UdpEndpoint query notification channel status request.

#
Channel
Diagnostic
Task
UdpQueryNotificationChannelStatusRequest

Description

UDP: Endpoint UdpEndpoint query notification channel status request. NcmContext = NcmContext, Endpoint State = Activated, PID = Pid, Channel Status = ChannelStatus, Status = Status.

Message #

UDP: Endpoint %1 query notification channel status request. NcmContext = %2, Endpoint State = %3, PID = %4, Channel Status = %6, Status = %7.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Activated UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1336: UDP: Endpoint UdpEndpoint notification channel request processed.

#
Channel
Diagnostic
Task
UdpCreateNotificationChannelRequestProcessed

Description

UDP: Endpoint UdpEndpoint notification channel request processed. NcmContext = NcmContext, PID = Pid, Status = Status PushNotificationId = PushNotificationGuid.

Message #

UDP: Endpoint %1 notification channel request processed. NcmContext = %2, PID = %3, Status = %4 PushNotificationId = %5.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Pid UInt32
Status UInt32NTSTATUS reference
PushNotificationGuid GUID

Event ID 1337: UDP: Endpoint UdpEndpoint notification channel signal event.

#
Channel
Diagnostic
Task
UdpSignalNotificationChannelEvent

Description

UDP: Endpoint UdpEndpoint notification channel signal event. NcmContext = NcmContext, PID = Pid, Delivered Data = Delivered FinalEvent = FinalEvent.

Message #

UDP: Endpoint %1 notification channel signal event. NcmContext = %2, PID = %3, Delivered Data = %4 FinalEvent = %5.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Pid UInt32
Delivered UInt32
FinalEvent UInt32

Event ID 1338: UDP: Endpoint UdpEndpoint notification channel detached.

#
Channel
Diagnostic
Task
UdpDetachNotificationChannel

Description

UDP: Endpoint UdpEndpoint notification channel detached. NcmContext = NcmContext, Endpoint State = Activated.

Message #

UDP: Endpoint %1 notification channel detached. NcmContext = %2, Endpoint State = %3.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Activated UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1339: UDP: Endpoint UdpEndpoint notification channel unlinked.

#
Channel
Diagnostic
Task
UdpUnlinkNotificationChannel

Description

UDP: Endpoint UdpEndpoint notification channel unlinked. Endpoint State = Activated.

Message #

UDP: Endpoint %1 notification channel unlinked. Endpoint State = %3.

Fields #

NameDescription
UdpEndpoint Pointer
NcmContext Pointer
Activated UInt32
Pid UInt32
IsLoopback UInt32
ChannelStatus UInt32
Status UInt32NTSTATUS reference

Event ID 1340: UDP: Endpoint UdpEndpoint notification channel request processing.

#
Channel
Diagnostic
Task
UdpCreateNotificationChannelRequestProcessing

Description

UDP: Endpoint UdpEndpoint notification channel request processing. Local IP address = LocalIPv4Address IPProtocol LocalIPv6Address, Local Port = SrcPort.

Message #

UDP: Endpoint %1 notification channel request processing. Local IP address = %3 %5 %4, Local Port = %6.

Fields #

NameDescription
UdpEndpoint Pointer
IpAddrLength UInt32
LocalIPv4Address UInt32
LocalIPv6Address Binary
IPProtocol UInt32
SrcPort UInt16

Event ID 1341: TCP: connection Tcb: Rtt sample recorded RttSample SRTT SRTT RttVar RttVar.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpDataTransferRttSample

Message #

TCP: connection %1:  Rtt sample recorded %2 SRTT %4 RttVar %3.

Fields #

NameDescription
Tcb Pointer
RttSample UInt32
RttVar UInt32
SRTT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1341",
    "version": "0",
    "level": "5",
    "task": "1070",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.390489700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "RttSample": "    1632",
    "RttVar": "     544",
    "SRTT": "    1626"
  },
  "message": ""
}

Event ID 1342: TCP: connection Tcb: Rtt resiliency detection complete with Rtt sample = RttSample and new SRTT = SRTT.

#
Channel
Diagnostic
Task
TcpRttResiliencyDetection

Message #

TCP: connection %1: Rtt resiliency detection complete with Rtt sample = %2 and new SRTT = %4.

Fields #

NameDescription
Tcb Pointer
RttSample UInt32
RttVar UInt32
SRTT UInt32

Event ID 1343: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo.

#
Channel
Diagnostic
Level
Informational
Task
TcpDataTransferDupAck

Message #

TCP: connection %1: Duplicate ACK updated cwnd = %2 and updated ssthresh = %3 DupAckCount = %4 SndUna = %5.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
DupAckCount UInt32
SeqNo UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1343",
    "version": "0",
    "level": "4",
    "task": "1072",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-16T00:21:40.488225900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "Cwnd": "   16734",
    "SSThresh": "4294967295",
    "DupAckCount": "       1",
    "SeqNo": "155002622"
  },
  "message": ""
}

Event ID 1344: TCP: CTCP Duplicate Ack event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferDupAck

Description

TCP: CTCP Duplicate Ack event. Connection Tcb, SndUna = SeqNo, CWnd = Cwnd, DupAckCount = DupAckCount.

Message #

TCP: CTCP Duplicate Ack event. Connection %1, SndUna = %5, CWnd = %2, DupAckCount = %4.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
DupAckCount UInt32
SeqNo UInt32

Event ID 1345: TCP: connection Tcb: Spurious timeout at Seq = SeqNo.

#
Channel
Diagnostic
Task
TcpDataTransferSpuriousTimeout

Message #

TCP: connection %1: Spurious timeout at Seq = %2.

Fields #

NameDescription
Tcb Pointer
SeqNo UInt32

Event ID 1346: TCP: connection Tcb spurious RTO detection initiated at SeqNo.

#
Channel
Diagnostic
Task
TcpSpuriousRtoDetectionBegin

Message #

TCP: connection %1 spurious RTO detection initiated at %2.

Fields #

NameDescription
Tcb Pointer
SeqNo UInt32

Event ID 1347: TCP: connection Tcb spurious RTO detection terminated at SeqNo.

#
Channel
Diagnostic
Task
TcpSpuriousRtoDetectionEnd

Message #

TCP: connection %1 spurious RTO detection terminated at %2.

Fields #

NameDescription
Tcb Pointer
SeqNo UInt32

Event ID 1348: TCP: CTCP DataTransferTimeout event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferTimeout

Description

TCP: CTCP DataTransferTimeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.

Message #

TCP: CTCP DataTransferTimeout event. Connection %1, CWnd = %2, SsThresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32

Event ID 1349: TCP: CTCP Spurious timeout event.

#
Channel
Diagnostic
Task
TcpCtcpDataTransferSpuriousTimeout

Description

TCP: CTCP Spurious timeout event. Connection Tcb, CWnd = Cwnd, SsThresh = SSThresh.

Message #

TCP: CTCP Spurious timeout event. Connection %1, CWnd = %2, SsThresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32

Event ID 1350: TCP: connection Tcb entering Congestion Avoidance Phase with cwnd = Cwnd and ssthresh = SSThresh.

#
Channel
Diagnostic
Level
Informational
Task
TcpSlowStartToCongestionAvoidance

Message #

TCP: connection %1 entering Congestion Avoidance Phase with cwnd = %2 and ssthresh = %3.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1350",
    "version": "0",
    "level": "4",
    "task": "1082",
    "opcode": "0",
    "keywords": 9223372045444710528,
    "time_created": "2026-03-15T23:27:12.440659500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFD182260",
    "Cwnd": "   15414",
    "SSThresh": "   15414"
  },
  "message": ""
}

Event ID 1351: TCP: connection Tcb: Send Retransmit round with SndUna = SndUna, Round = RexmitCount, SRTT = SRTT, RTO = RTO.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpDataTransferRetransmitRound

Message #

TCP: connection %1: Send Retransmit round with SndUna = %2, Round = %3, SRTT = %4, RTO = %5.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
RexmitCount UInt32
SRTT UInt32
RTO UInt32
SndMax UInt32
RecoveryMax UInt32
TcpState UInt32
CongestionState UInt32
Frto UInt32
TotalRT UInt32
MaxRT UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1351",
    "version": "0",
    "level": "4",
    "task": "1077",
    "opcode": "0",
    "keywords": 9223372041149743232,
    "time_created": "2026-03-15T23:31:42.716273800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{f9ca95f0-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FF9CA95F0",
    "SndUna": "2098991634",
    "RexmitCount": "       1",
    "SRTT": "    3000",
    "RTO": "    2000"
  },
  "message": ""
}

Event ID 1352: TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...

#
Channel
Diagnostic
Task
TcpConnectionSummary
Opcode
Info

Description

TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa \ NonRecovDa NonRecovDaEpisodes NonRecovDaEpisodes DupAcksIn DupAcksIn BytesRetrans BytesRetrans Timeouts Timeouts SpuriousRtoDetections SpuriousRtoDetections FastRetran FastRetran MaxSsthresh MaxSsthresh MaxSsCwnd MaxSsCwnd \ MaxCaCwnd MaxCaCwnd SndLimTransRwin SndLimTransRwin SndLimTimeRwin SndLimTimeRwin SndLimBytesRwin SndLimBytesRwin SndLimTransCwnd SndLimTransCwnd SndLimTimeCwnd SndLimTimeCwnd SndLimBytesCwnd SndLimBytesCwnd \ SndLimTransSnd SndLimTransSnd SndLimTimeSnd SndLimTimeRSnd SndLimBytesSnd SndLimBytesRSnd.

Message #

TCP: Connection %1 Summary: DataBytesOut %2 DataBytesIn %3 DataSegmentsOut %4 DataSegmentsIn %5 SegmentsOut %6 SegmentsIn %7 NonRecovDa \   %8 NonRecovDaEpisodes %9 DupAcksIn %10 BytesRetrans %11 Timeouts %12 SpuriousRtoDetections %13 FastRetran %14 MaxSsthresh %15 MaxSsCwnd %16 \   MaxCaCwnd %17 SndLimTransRwin %18 SndLimTimeRwin %19 SndLimBytesRwin %20 SndLimTransCwnd %21 SndLimTimeCwnd %22 SndLimBytesCwnd %23 \   SndLimTransSnd %24 SndLimTimeSnd %25 SndLimBytesSnd %26.

Fields #

NameDescription
Tcb Pointer
DataBytesOut UInt64
DataBytesIn UInt64
DataSegmentsOut UInt64
DataSegmentsIn UInt64
SegmentsOut UInt64
SegmentsIn UInt64
NonRecovDa UInt32
NonRecovDaEpisodes UInt32
DupAcksIn UInt32
BytesRetrans UInt32
Timeouts UInt32
SpuriousRtoDetections UInt32
FastRetran UInt32
MaxSsthresh UInt32
MaxSsCwnd UInt32
MaxCaCwnd UInt32
SndLimTransRwin UInt32
SndLimTimeRwin UInt32
SndLimBytesRwin UInt64
SndLimTransCwnd UInt32
SndLimTimeCwnd UInt32
SndLimBytesCwnd UInt64
SndLimTransSnd UInt32
SndLimTimeRSnd UInt32
SndLimBytesRSnd UInt64

Event ID 1353: TCPIP: Message AllocationObjectString Param1 Param2 Param3 Param4.

#
Channel
Diagnostic
Task
TcpipGeneric

Message #

TCPIP: Message %1 %2 %3 %4 %5.

Fields #

NameDescription
AllocationObjectString UnicodeString
Param1 Pointer
Param2 Pointer
Param3 UInt32
Param4 UInt32

Event ID 1354: TCP: Connection Tcb SACK updated SndUna SndUna SndMax SndMax SackCount SackCount SackBytes SackBytes SackInFlight SackInFlight SackIsLost SackIsLost.

#
Channel
Diagnostic
Task
TcpSackUpdate

Message #

TCP: Connection %1 SACK updated SndUna %2 SndMax %3 SackCount %4 SackBytes %5 SackInFlight %6 SackIsLost %7.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
SackCount UInt32
SackBytes UInt32
SackInFlight UInt32
SackIsLost UInt32

Event ID 1355: TCP: TCB Tcb Requires address based pattern = RequireAddressCoalescing LocalPort = LocalPort RtcPortRange = [RtcStartPort, RtcEndPort] Status = Status.

#
Channel
Diagnostic
Task
TcpIsPatternCoalescingRequired

Message #

TCP: TCB %1 Requires address based pattern = %2 LocalPort = %3 RtcPortRange = [%4, %5] Status = %6.

Fields #

NameDescription
Tcb Pointer
RequireAddressCoalescing UInt32
LocalPort UInt16
RtcStartPort UInt16
RtcEndPort UInt16
Status UInt32NTSTATUS reference

Event ID 1356: TCP: Rtc Port Range Assignment.

#
Channel
Diagnostic
Task
TcpRtcPortRangeAssignment

Description

TCP: Rtc Port Range Assignment. Allocated = AssignedFromRtcRange, Port = Port.

Message #

TCP: Rtc Port Range Assignment. Allocated = %1, Port = %2.

Fields #

NameDescription
AssignedFromRtcRange UInt32
Port UInt16

Event ID 1357: TCPIP has failed a RequestType request from LocalAddress to RemoteAddress on endpoint TcbOrEndpoint owned by process ProcessId with Status since network interface InterfaceIndex is in low-power mode.

#
Channel
Diagnostic
Task
TcpipAoacFailFast

Message #

TCPIP has failed a %1 request from %4 to %6 on endpoint %2 owned by process %8 with %7 since network interface %9 is in low-power mode.

Fields #

NameDescription
RequestType UInt32
TcbOrEndpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
InterfaceIndex UInt32
ProcessStartKey UInt64

Event ID 1358: IP: Interface configuration updated on interface InterfaceIndex property Property value Value event InterfaceUpdateEvent.

#
Channel
Diagnostic
Task
TcpipUpdateInterfaceConfigFlags

Message #

IP: Interface configuration updated on interface %1 property %2 value %3 event %4.

Fields #

NameDescription
InterfaceIndex UInt32
Property AnsiString
Value UInt32
InterfaceUpdateEvent UInt32
CompartmentId UInt32
AddressFamily UInt32

Event ID 1359: TCP: Connection Tcb notification channel unmark request.

#
Channel
Diagnostic
Task
TcpCreateNotificationChannelUnmarkRequest

Description

TCP: Connection Tcb notification channel unmark request. NcmContext = NcmContext, TCB State = State, PID = Pid, IsLoopback = IsLoopback, IsShutdown = IsShutdown, Status = Status.

Message #

TCP: Connection %1 notification channel unmark request. NcmContext = %2, TCB State = %3, PID = %4, IsLoopback = %5, IsShutdown = %6, Status = %7.

Fields #

NameDescription
Tcb Pointer
NcmContext Pointer
State UInt32
Pid UInt32
IsLoopback UInt32
IsShutdown UInt32
Status UInt32NTSTATUS reference

Event ID 1360: TCPIP: A packet has been cloned for a raw listener.

#
Channel
Diagnostic
Task
TcpipNblClonedForRaw

Description

TCPIP: A packet has been cloned for a raw listener. NBL ClonedNbl cloned from NBL Nbl. Protocol = IPTransportProtocol, Family = AddressFamily.

Message #

TCPIP: A packet has been cloned for a raw listener. NBL %2 cloned from NBL %1. Protocol = %3, Family = %4.

Fields #

NameDescription
Nbl Pointer
ClonedNbl Pointer
IPTransportProtocol UInt32
AddressFamily UInt32

Event ID 1361: TCPIP: A cloned packet has been dropped.

#
Channel
Diagnostic
Task
TcpipCloneDropped

Description

TCPIP: A cloned packet has been dropped. NBL ClonedNbl cloned from NBL Nbl. Family = AddressFamily.

Message #

TCPIP: A cloned packet has been dropped. NBL %2 cloned from NBL %1. Family = %3.

Fields #

NameDescription
Nbl Pointer
ClonedNbl Pointer
AddressFamily UInt32

Event ID 1362: IP: Interface = Interface IpAddress = IPAddress processing WolEvent = WoLEvent with Status = Status.

#
Channel
Diagnostic
Task
IpAddressWolStateChange

Message #

IP: Interface = %1 IpAddress = %3 processing WolEvent = %4 with Status = %5.

Fields #

NameDescription
Interface UInt32
IpAddrLength UInt32
IPAddress Binary
WoLEvent UInt32
Status UInt32NTSTATUS reference

Event ID 1363: IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processin...

#
Channel
Diagnostic
Task
IpWolContextChange

Description

IP: Interface = Interface WolHandle = WolHandle has DestinationIpAddress = DestinationIPAddress TargetIpAddress1 = TargetIPAddress1 TargetIpAddress2 = TargetIPAddress2 Flags = Flags while processing WolEvent = WoLEvent with Status = Status.

Message #

IP: Interface = %1 WolHandle = %3 has DestinationIpAddress = %4 TargetIpAddress1 = %5 TargetIpAddress2 = %6 Flags = %7 while processing WolEvent = %8 with Status = %9.

Fields #

NameDescription
Interface UInt32
IpAddrLength UInt32
WolHandle UInt32
DestinationIPAddress Binary
TargetIPAddress1 Binary
TargetIPAddress2 Binary
Flags UInt32
WoLEvent UInt32
Status UInt32NTSTATUS reference

Event ID 1364: TCP connection tuple inserted- TCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.

#
Channel
Diagnostic
Task
TcpInsertConnectionTuple

Message #

TCP connection tuple inserted- TCB: %1 LocalAddress: %3 RemoteAddress: %5

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1365: TCP connection tuple removed- TCB/TWTCB: Tcb LocalAddress: LocalAddress RemoteAddress: RemoteAddress.

#
Channel
Diagnostic
Task
TcpRemoveConnectionTuple

Message #

TCP connection tuple removed- TCB/TWTCB: %1 LocalAddress: %3 RemoteAddress: %5

Fields #

NameDescription
Tcb Pointer
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
NewState UInt32
RexmitCount UInt32

Event ID 1366: TCP port selection deferred for outbound connect- LocalAddress: LocalAddress.

#
Channel
Diagnostic
Task
TcpDeferPortSelection

Message #

TCP port selection deferred for outbound connect- LocalAddress: %2

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Event ID 1367: Nbl Nbl OOB info (PathDirection): TcpIpChecksumNetBufferListInfo TcpIpChecksumNetBufferListInfo, TcpLargeSendNetBufferListInfo TcpLargeSendNetBufferListInfo, Ieee8021QNetBufferListInfo Ieee8021QNet...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
TcpIpPerPacket
Task
TcpipNblOob
Opcode
Info

Description

Nbl Nbl OOB info (PathDirection): TcpIpChecksumNetBufferListInfo TcpIpChecksumNetBufferListInfo, TcpLargeSendNetBufferListInfo TcpLargeSendNetBufferListInfo, Ieee8021QNetBufferListInfo Ieee8021QNetBufferListInfo, NetBufferListHashValue NetBufferListHashValue, NetBufferListHashInfo NetBufferListHashInfo, VirtualSubnetInfo VirtualSubnetInfo, UdpSegmentationOffloadInfo/TcpRecvSegCoalesceInfo TcpRecvSegCoalesceInfo, NrtNameResolutionId/UdpRecvSegCoalesceOffloadInfo NrtNameResolutionInfo

Message #

Nbl %1 OOB info (%2): TcpIpChecksumNetBufferListInfo %3, TcpLargeSendNetBufferListInfo %4, Ieee8021QNetBufferListInfo %5, NetBufferListHashValue %6, NetBufferListHashInfo %7, VirtualSubnetInfo %8, TcpRecvSegCoalesceInfo %9

Fields #

NameDescription
Nbl Pointer
PathDirection UInt32
TcpIpChecksumNetBufferListInfo Pointer
TcpLargeSendNetBufferListInfo Pointer
Ieee8021QNetBufferListInfo Pointer
NetBufferListHashValue Pointer
NetBufferListHashInfo Pointer
VirtualSubnetInfo Pointer
TcpRecvSegCoalesceInfo Pointer
NrtNameResolutionInfo Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1367",
    "version": "1",
    "level": "17",
    "task": "1367",
    "opcode": "0",
    "keywords": 9223372049739677696,
    "time_created": "2026-03-16T00:21:34.388895400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Nbl": "0xFFFF980A11CCA4F0",
    "PathDirection": "       0",
    "TcpIpChecksumNetBufferListInfo": "0x220015",
    "TcpLargeSendNetBufferListInfo": "0x0",
    "Ieee8021QNetBufferListInfo": "0x0",
    "NetBufferListHashValue": "0xF92BBC40",
    "NetBufferListHashInfo": "0x0",
    "VirtualSubnetInfo": "0x0",
    "TcpRecvSegCoalesceInfo": "0x0",
    "NrtNameResolutionInfo": "0x0"
  },
  "message": ""
}

Event ID 1368: Teredo Add -- PID: PID started listening on LocalAddress.

#
Channel
Diagnostic
Task
TcpipTeredoOpen

Description

Teredo Add -- PID: PID started listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.

Message #

Teredo Add -- PID: %1 started listening on %3. AddressType %4. ScopeLevel %5. Port %6. EndpointRecord %7.

Fields #

NameDescription
PID UInt64
LocalAddressLength UInt32
LocalAddress Binary
AddressType UInt32
ScopeLevel UInt32
Port UInt32
EndpointRecord Pointer

Event ID 1369: Teredo Remove -- PID: PID stopped listening on LocalAddress.

#
Channel
Diagnostic
Task
TcpipTeredoClose

Description

Teredo Remove -- PID: PID stopped listening on LocalAddress. AddressType AddressType. ScopeLevel ScopeLevel. Port Port. EndpointRecord EndpointRecord.

Message #

Teredo Remove -- PID: %1 stopped listening on %3. AddressType %4. ScopeLevel %5. Port %6. EndpointRecord %7.

Fields #

NameDescription
PID UInt64
LocalAddressLength UInt32
LocalAddress Binary
AddressType UInt32
ScopeLevel UInt32
Port UInt32
EndpointRecord Pointer

Event ID 1370: IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpipRouteLookup

Description

IP: RouteLookup - API: API DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintOveridden: ConstraintOverridden ReturnConstrained: ReturnConstrained OutgoingIfIndex: OutgoingInterfaceIndex NextHopAddr: NextHopAddress Status: Status.

Message #

IP: RouteLookup - API: %1 DstAddr: %3 ConstrainSrcAddr: %4 ConstrainIfIndex: %5 ConstraintOveridden: %6 ReturnConstrained: %7 OutgoingIfIndex: %8 NextHopAddr: %9 Status: %10

Fields #

NameDescription
API AnsiString
IpAddrLength UInt32
DestinationAddress Binary
ConstrainSourceAddress Binary
ConstrainInterfaceIndex UInt32
ConstrainForwardingTag UInt32
ConstraintOverridden UInt32
ReturnConstrained UInt32
OutgoingInterfaceIndex UInt32
NextHopAddress Binary
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1370",
    "version": "0",
    "level": "5",
    "task": "1370",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-15T23:26:13.698249300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "1868",
      "thread_id": "2740"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "API": "IppFindPath",
    "IpAddrLength": "      16",
    "DestinationAddress": "127.0.0.1",
    "ConstrainSourceAddress": "0.0.0.0",
    "ConstrainInterfaceIndex": "       0",
    "ConstraintOverridden": "       0",
    "ReturnConstrained": "       0",
    "OutgoingInterfaceIndex": "       1",
    "NextHopAddress": "127.0.0.1",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1371: IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: Retu...

#
Channel
Diagnostic
Level
Verbose
Task
TcpipSrcAddrLookup

Description

IP: SourceAddrLookup - DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex OutgoingIfIndex: OutgoingInterfaceIndex ReturnConstrained: ReturnConstrained SelectedSrcAddr: SelectedSourceAddress.

Message #

IP: SourceAddrLookup - DstAddr: %2 ConstrainSrcAddr: %3 ConstrainIfIndex: %4 OutgoingIfIndex: %5 ReturnConstrained: %6 SelectedSrcAddr: %7

Fields #

NameDescription
IpAddrLength UInt32
DestinationAddress Binary
ConstrainSourceAddress Binary
ConstrainInterfaceIndex UInt32
OutgoingInterfaceIndex UInt32
ReturnConstrained UInt32
SelectedSourceAddress Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1371",
    "version": "0",
    "level": "5",
    "task": "1371",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-16T00:21:40.067796000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IpAddrLength": "      16",
    "DestinationAddress": "0.0.0.0",
    "ConstrainSourceAddress": "0.0.0.0",
    "ConstrainInterfaceIndex": "       0",
    "OutgoingInterfaceIndex": "       6",
    "ReturnConstrained": "       0",
    "SelectedSourceAddress": "10.2.10.21"
  },
  "message": ""
}

Event ID 1372: WFP-ALE: Partition Count=PartitionCount Partition Mask=PartitionMask: Partition Id=%d Partition NumEntries = NumEntries.

#
Channel
Diagnostic
Task
Partition

Message #

WFP-ALE: Partition Count=%1 Partition Mask=%2: Partition Id=%d Partition NumEntries = %4.

Fields #

NameDescription
PartitionCount UInt64
PartitionMask UInt64
PartitionId UInt64
NumEntries UInt64

Event ID 1373: WFP-ALE: HotAdd/Remove: Old Partiton Count=OldPartitionCount Old Partition Mask=OldPartitionMask New Partiton Count=OldPartitionCount New Partition Mask=OldPartitionMask.

#
Channel
Diagnostic
Task
Partition

Message #

WFP-ALE: HotAdd/Remove: Old Partiton Count=%1 Old Partition Mask=%2 New Partiton Count=%1 New Partition Mask=%2.

Fields #

NameDescription
OldPartitionCount UInt64
OldPartitionMask UInt64
NewPartitionCount UInt64
NewPartitionMask UInt64

Event ID 1374: WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEnt...

#
Channel
Diagnostic
Task
RemoteEndpoint

Description

WFP-ALE: RemoteEndPoint Insertion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.

Message #

WFP-ALE: RemoteEndPoint Insertion: AddrLen=%1 RemoteAddr=%2 RemotePort=%3 LocalAddr=%4 LocalPort=%5 PartitionId=%6 PartitionNumEntries=%7

Fields #

NameDescription
AddressLength UInt32
RemoteAddress Binary
RemotePort UInt64
LocalAddress Binary
LocalPort UInt16
PartitionId UInt64
NumEntries UInt64

Event ID 1375: WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntr...

#
Channel
Diagnostic
Task
RemoteEndpoint

Description

WFP-ALE: RemoteEndPoint Deletion: AddrLen=AddressLength RemoteAddr=RemoteAddress RemotePort=RemotePort LocalAddr=LocalAddress LocalPort=LocalPort PartitionId=PartitionId PartitionNumEntries=NumEntries.

Message #

WFP-ALE: RemoteEndPoint Deletion: AddrLen=%1 RemoteAddr=%2 RemotePort=%3 LocalAddr=%4 LocalPort=%5 PartitionId=%6 PartitionNumEntries=%7

Fields #

NameDescription
AddressLength UInt32
RemoteAddress Binary
RemotePort UInt64
LocalAddress Binary
LocalPort UInt16
PartitionId UInt64
NumEntries UInt64

Event ID 1376: WFP-ALE: ALE: low memory state detected.

#
Channel
Diagnostic
Task
Memory

Description

WFP-ALE: ALE: low memory state detected. LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.

Message #

WFP-ALE: ALE: low memory state detected. LowMemoryEvent = %3 LowNonPagedPoolEvent = %4.

Fields #

NameDescription
HighMemoryEvent UInt32
HighNonPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowNonPagedPoolEvent UInt32

Event ID 1377: WFP-ALE: leaving low memory state.

#
Channel
Diagnostic
Level
Informational
Task
Memory

Description

WFP-ALE: leaving low memory state. HighMemoryEvent = HighMemoryEvent HighNonPagedPoolEvent = HighNonPagedPoolEvent.

Message #

WFP-ALE: leaving low memory state. HighMemoryEvent = %1 HighNonPagedPoolEvent = %2.

Fields #

NameDescription
HighMemoryEvent UInt32
HighNonPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowNonPagedPoolEvent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1377",
    "version": "0",
    "level": "4",
    "task": "1373",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-15T23:26:23.462874700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HighMemoryEvent": "       1",
    "HighNonPagedPoolEvent": "       1",
    "LowMemoryEvent": "       0",
    "LowNonPagedPoolEvent": "       0"
  },
  "message": ""
}

Event ID 1378: WFP-ALE: Dpc for cleanup initiated: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.

#
Channel
Diagnostic
Task
Memory

Message #

WFP-ALE: Dpc for cleanup initiated: LowMemoryEvent = %3 LowNonPagedPoolEvent = %4.

Fields #

NameDescription
HighMemoryEvent UInt32
HighNonPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowNonPagedPoolEvent UInt32

Event ID 1379: WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = LowMemoryEvent LowNonPagedPoolEvent = LowNonPagedPoolEvent.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
Memory

Message #

WFP: Dpc for cleanup QUEUED or RE-QUEUED: LowMemoryEvent = %3 LowNonPagedPoolEvent = %4.

Fields #

NameDescription
HighMemoryEvent UInt32
HighNonPagedPoolEvent UInt32
LowMemoryEvent UInt32
LowNonPagedPoolEvent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1379",
    "version": "0",
    "level": "5",
    "task": "1373",
    "opcode": "0",
    "keywords": 9223372036854841344,
    "time_created": "2026-03-16T00:21:40.078370400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "HighMemoryEvent": "       1",
    "HighNonPagedPoolEvent": "       1",
    "LowMemoryEvent": "       0",
    "LowNonPagedPoolEvent": "       0"
  },
  "message": ""
}

Event ID 1380: TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPerc...

#
Channel
Diagnostic
Task
TcpLedbatState

Description

TCP: LEDBAT LedbatEvent: Connection Tcb, BaseDelayMs = BaseDelayMs, CurrentDelayMs = CurrentDelayMs, CWnd = Cwnd, SsThresh = SsThresh, SndWnd = SndWnd, DelayBasedCwndFactor DelayBasedCwndFactorPercent%, RemainingTimeMs = RemainingTimeMs.

Message #

TCP: LEDBAT %2: Connection %1, BaseDelayMs = %6, CurrentDelayMs = %7, CWnd = %3, SsThresh = %4, SndWnd = %5, DelayBasedCwndFactor %9%%, RemainingTimeMs = %8.

Fields #

NameDescription
Tcb Pointer
LedbatEvent UInt32
Cwnd UInt32
SsThresh UInt32
SndWnd UInt32
BaseDelayMs UInt16
CurrentDelayMs UInt16
RemainingTimeMs UInt32
DelayBasedCwndFactorPercent Int32

Event ID 1381: TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %...

#
Channel
Diagnostic
Task
TcpAssociateNameResContext

Description

TCP: AssociateNameResContext Endpoint: EndpointObj Status: %16 NameResolutionContext: IsConnectionObj DnsName: NameResContext InterfaceIndex: Status IPAddrCount: %5 IPAddrs: %7 %9 %11 %13 %15.

Message #

TCP: AssociateNameResContext Endpoint: %1 Status: %16 NameResolutionContext: %2 DnsName: %3 InterfaceIndex: %4 IPAddrCount: %5 IPAddrs: %7 %9 %11 %13 %15

Fields #

NameDescription
EndpointObj Pointer
IsConnectionObj UInt32
NameResContext Pointer
Status UInt32NTSTATUS reference

Event ID 1382: TCP: InspectConnectWithNameResContext Connection: Tcb (local: LocalAddress remote: RemoteAddress) NameResolutionContext: NameResContext DnsName: DnsName Status: Status.

#
Channel
Diagnostic
Task
TcpInspectConnectWithNameResContext

Message #

TCP: InspectConnectWithNameResContext Connection: %5 (local: %2 remote: %4) NameResolutionContext: %6 DnsName: %7 Status: %8.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Tcb Pointer
NameResContext Pointer
DnsName UnicodeString
Status UInt32NTSTATUS reference

Event ID 1383: IP: Route [DestinationPrefix: PrDestinationPrefix/PrDestinationPrefixLength NextHop: PrNextHopAddress InterfaceIndex: PrInterfaceIndex InterfaceMetric: PrInterfaceMetric RouteMetric: PrRouteMetric]...

#
Channel
Diagnostic
Level
Verbose
Task
IpRouteSelection

Description

IP: Route [DestinationPrefix: PrDestinationPrefix/PrDestinationPrefixLength NextHop: PrNextHopAddress InterfaceIndex: PrInterfaceIndex InterfaceMetric: PrInterfaceMetric RouteMetric: PrRouteMetric] is preferred over Route [DestinationPrefix: NonPrDestinationPrefix/NonPrDestinationPrefixLength NextHop: NonPrNextHopAddress InterfaceIndex: NonPrInterfaceIndex InterfaceMetric: NonPrInterfaceMetric RouteMetric: NonPrRouteMetric] for Destination: DestinationAddress in Compartment: CompartmentId, Reason: PreferenceReason.

Message #

IP: Route [DestinationPrefix: %6/%4 NextHop: %8 InterfaceIndex: %9 InterfaceMetric: %10 RouteMetric: %11] is preferred over Route [DestinationPrefix: %14/%12 NextHop: %16 InterfaceIndex: %17 InterfaceMetric: %18 RouteMetric: %19] for Destination: %3 in Compartment: %1, Reason: %20.

Fields #

NameDescription
CompartmentId UInt32
DestinationAddressLength UInt32
DestinationAddress Binary
PrDestinationPrefixLength UInt32
PrDestinationPrefixAddressLength UInt32
PrDestinationPrefix Binary
PrNextHopAddressLength UInt32
PrNextHopAddress Binary
PrInterfaceIndex UInt32
PrInterfaceMetric UInt32
PrRouteMetric UInt32
NonPrDestinationPrefixLength UInt32
NonPrDestinationPrefixAddressLength UInt32
NonPrDestinationPrefix Binary
NonPrNextHopAddressLength UInt32
NonPrNextHopAddress Binary
NonPrInterfaceIndex UInt32
NonPrInterfaceMetric UInt32
NonPrRouteMetric UInt32
PreferenceReason UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1383,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 11848
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:11:26.378Z",
    "version": 0
  },
  "event_data": {
    "CompartmentId": 1,
    "DestinationAddress": "020000000A020A1F0000000000000000",
    "DestinationAddressLength": 16,
    "NonPrDestinationPrefix": "020000000A020A000000000000000000",
    "NonPrDestinationPrefixAddressLength": 16,
    "NonPrDestinationPrefixLength": 24,
    "NonPrInterfaceIndex": 11,
    "NonPrInterfaceMetric": 15,
    "NonPrNextHopAddress": "020000000A020A1F0000000000000000",
    "NonPrNextHopAddressLength": 16,
    "NonPrRouteMetric": 256,
    "PrDestinationPrefix": "02000000000000000000000000000000",
    "PrDestinationPrefixAddressLength": 16,
    "PrDestinationPrefixLength": 0,
    "PrInterfaceIndex": 11,
    "PrInterfaceMetric": 15,
    "PrNextHopAddress": "020000000A020AFE0000000000000000",
    "PrNextHopAddressLength": 16,
    "PrRouteMetric": 256,
    "PreferenceReason": 1
  },
  "message": ""
}

Event ID 1384: IP: Route [DestinationPrefix: DestinationPrefix/DestinationPrefixLength NextHop: NextHopAddress InterfaceIndex: InterfaceIndex RouteMetric: RouteMetric] is blocked for Destination: DestinationAddre...

#
Channel
Diagnostic
Task
IpRouteBlocked

Description

IP: Route [DestinationPrefix: / NextHop: InterfaceIndex: RouteMetric: ] is blocked for Destination: ConstrainInterfaceIndex: ConstrainScopeZone: in Compartment: , Reason: .

Message #

IP: Route [DestinationPrefix: %6/%4 NextHop: %8 InterfaceIndex: %9 RouteMetric: %10] is blocked for Destination: %3 ConstrainInterfaceIndex: %11 ConstrainScopeZone: %12 in Compartment: %1, Reason: %13.

Fields #

NameDescription
CompartmentId UInt32
DestinationAddressLength UInt32
DestinationAddress Binary
DestinationPrefixLength UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
InterfaceIndex UInt32
RouteMetric UInt32
ConstrainInterfaceIndex UInt32
ConstrainScope UInt32
BlockReason UInt32

Event ID 1385: TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSe...

#
Channel
Diagnostic
Level
Informational
Task
TcpTailLossProbe

Description

TCP: Tail Loss Probe Send Connection = Tcb SndUna = SndUna, SndMax = SndMax, SendAvailable = SendAvailable, TailProbeSeq = TailProbeSeq, TailProbeLast = TailProbeLast, ControlsToSend = ControlsToSend, ThFlags = ThFlags.

Message #

TCP: Tail Loss Probe Send Connection = %1 SndUna = %2, SndMax = %3, SendAvailable = %4, TailProbeSeq = %5, TailProbeLast = %6, ControlsToSend = %7, ThFlags = %8.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
SendAvailable UInt32
TailProbeSeq UInt32
TailProbeLast UInt32
ControlsToSend UInt32
ThFlags UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1385",
    "version": "0",
    "level": "4",
    "task": "1380",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.721122900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "SndUna": "2308839694",
    "SndMax": "2308842691",
    "SendAvailable": "    2997",
    "TailProbeSeq": "2308841231",
    "TailProbeLast": "2308842691",
    "ControlsToSend": "       0",
    "ThFlags": "16"
  },
  "message": ""
}

Event ID 1386: TCP: Tail Loss Probe Event Connection = Tcb, Event = TlpEvent.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpTailLossProbe

Message #

TCP: Tail Loss Probe Event Connection = %1, Event = %2.

Fields #

NameDescription
Tcb Pointer
TlpEvent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1386",
    "version": "0",
    "level": "4",
    "task": "1380",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.388823900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "TlpEvent": "       1"
  },
  "message": ""
}

Event ID 1387: TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample =...

#
Channel
Diagnostic
Level
Informational
Task
TcpRack

Description

TCP: RACK Event Connection = Tcb, Event = RackEvent, MinRTT = RackMinRtt, ReoWind = RackReoWind, TimeSlotDeltaMin = RackTimeSlotDeltaMin, SeqNum = SequenceNumber, Timestamp = Timestamp, RttSample = RttSample.

Message #

TCP: RACK Event Connection = %1, Event = %2, MinRTT = %3, ReoWind = %4, TimeSlotDeltaMin = %5, SeqNum = %6, Timestamp = %7, RttSample = %8.

Fields #

NameDescription
Tcb Pointer
RackEvent UInt32
RackMinRtt UInt32
RackReoWind UInt32
RackTimeSlotDeltaMin UInt32
SequenceNumber UInt32
Timestamp UInt32
RttSample UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1387",
    "version": "0",
    "level": "4",
    "task": "1381",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:26:14.411027300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{f6654220-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "10828",
      "thread_id": "9684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FF6654220",
    "RackEvent": "       1",
    "RackMinRtt": "     751",
    "RackReoWind": "       0",
    "RackTimeSlotDeltaMin": "       0",
    "SequenceNumber": "2723729970",
    "Timestamp": "4090263552",
    "RttSample": "     751"
  },
  "message": ""
}

Event ID 1388: TCP: Fastopen state changed for connection = Tcb from OldState = OldState to NewState = NewState.

#
Channel
Diagnostic
Task
TcpFastopenStateChange

Message #

TCP: Fastopen state changed for connection = %1 from OldState = %2 to NewState = %3.

Fields #

NameDescription
Tcb Pointer
OldState UInt32
NewState UInt32

Event ID 1389: UDP: endpoint (family=AddressFamily pid=ProcessId) create failed: address family not attached.

#
Channel
Diagnostic
Task
UdpCreateEndpointAfFailure

Message #

UDP: endpoint (family=%5 pid=%3) create failed: address family not attached.

Fields #

NameDescription
Endpoint Pointer
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1390: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: compartment CompartmentId not found.

#
Channel
Diagnostic
Task
UdpCreateEndpointCompartmentFailure

Message #

UDP: endpoint %1 (family=%5 pid=%3) create failed: compartment %4 not found.

Fields #

NameDescription
Endpoint Pointer
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1391: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) created.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
UdpCreateEndpointComplete

Message #

UDP: endpoint %1 (family=%5 pid=%3) created.

Fields #

NameDescription
Endpoint Pointer
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1391",
    "version": "1",
    "level": "4",
    "task": "1385",
    "opcode": "0",
    "keywords": 9223372036854776833,
    "time_created": "2026-03-16T00:21:40.077667700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A11735E80",
    "Status": "0x0",
    "ProcessId": "     228",
    "CompartmentId": "       1",
    "AddressFamily": "      23",
    "ProcessStartKey": "2814749767106594"
  },
  "message": ""
}

Event ID 1392: UDP: endpoint Endpoint (family=AddressFamily pid=ProcessId) create failed: inspection status = Status.

#
Channel
Diagnostic
Task
UdpCreateEndpointInspectionFailure

Message #

UDP: endpoint %1 (family=%5 pid=%3) create failed: inspection status = %2

Fields #

NameDescription
Endpoint Pointer
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1393: UDP: endpoint Endpoint bind failed: address LocalAddress cannot be resolved, status = Status.

#
Channel
Diagnostic
Task
UdpBindEndpointResolutionFailure

Message #

UDP: endpoint %4 bind failed: address %2 cannot be resolved, status = %3

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Event ID 1394: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: port-acquisition status = Status.

#
Channel
Diagnostic
Task
UdpBindEndpointPortFailure

Message #

UDP: endpoint %4 (sockaddr=%2) bind failed: port-acquisition status = %3

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Event ID 1395: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: inspection status = Status.

#
Channel
Diagnostic
Task
UdpBindEndpointInspectionFailure

Message #

UDP: endpoint %4 (sockaddr=%2) bind failed: inspection status = %3

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Event ID 1396: UDP: endpoint Endpoint (sockaddr=LocalAddress) bound.

#
Channel
Diagnostic
Level
Informational
Task
UdpBindEndpointComplete

Message #

UDP: endpoint %4 (sockaddr=%2) bound.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer
Pid UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1396",
    "version": "0",
    "level": "4",
    "task": "1390",
    "opcode": "0",
    "keywords": 9223372036854776841,
    "time_created": "2026-03-16T00:21:40.078017600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::]:53893",
    "Status": "0x0",
    "Endpoint": "0xFFFF980A11735E80"
  },
  "message": ""
}

Event ID 1397: UDP: endpoint Endpoint (sockaddr=LocalAddress) closed.

#
Channel
Diagnostic
Level
Informational
Task
UdpCloseEndpointBound

Message #

UDP: endpoint %4 (sockaddr=%2) closed.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1397",
    "version": "0",
    "level": "4",
    "task": "1391",
    "opcode": "0",
    "keywords": 9223372105574253569,
    "time_created": "2026-03-16T00:21:40.117474200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "2612"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "      28",
    "LocalAddress": "[::]:53893",
    "Status": "0x0",
    "Endpoint": "0xFFFF980A11735E80"
  },
  "message": ""
}

Event ID 1398: UDP: endpoint Endpoint closed.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
UdpCloseEndpointUnBound

Message #

UDP: endpoint %4 closed.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1398",
    "version": "0",
    "level": "4",
    "task": "1392",
    "opcode": "0",
    "keywords": 9223372105574253569,
    "time_created": "2026-03-16T00:21:40.118277500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11737aa0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "10580"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "LocalAddressLength": "       0",
    "LocalAddress": "",
    "Status": "0x0",
    "Endpoint": "0xFFFF980A11737AA0"
  },
  "message": ""
}

Event ID 1399: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address resolution status = Status.

#
Channel
Diagnostic
Task
UdpSendMessagesResolutionFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: address resolution status = %6

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1400: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: address validation failed.

#
Channel
Diagnostic
Task
UdpSendMessagesValidationFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: address validation failed.

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1401: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: source-address selection status = Status.

#
Channel
Diagnostic
Task
UdpSendMessagesSrcAddrSelectionFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: source-address selection status = %6

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1402: UDP: endpoint {Endpoint} too many packets queued for the pending join path.

#
Channel
Diagnostic

Fields #

NameDescription
Endpoint

Event ID 1403: UDP: address family AddressFamilyadded to interface InterfaceIndex.

#
Channel
Diagnostic
Task
UdpGlobalAddInterface

Message #

UDP: address family %2added to interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt32

Event ID 1404: UDP: address family AddressFamilyremoved from interface InterfaceIndex.

#
Channel
Diagnostic
Task
UdpGlobalDeleteInterface

Message #

UDP: address family %2removed from interface %1.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt32

Event ID 1405: UDP: Failure initializing transport protocol, status = Status.

#
Channel
Diagnostic
Task
UdpStartInetModuleFailure

Message #

UDP: Failure initializing transport protocol, status = %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1406: UDP: Failure starting NLNPI client, status = Status.

#
Channel
Diagnostic
Task
UdpStartNlnpiClientFailure

Message #

UDP: Failure starting NLNPI client, status = %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1407: UDP: Failure initializing NSI support, status = Status.

#
Channel
Diagnostic
Task
UdpStartNsiProviderFailure

Message #

UDP: Failure initializing NSI support, status = %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1408: UDP: Failure starting TLNPI provider, status = Status.

#
Channel
Diagnostic
Task
UdpStartTlnpiProviderFailure

Message #

UDP: Failure starting TLNPI provider, status = %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1409: UDP: Failure initializing QoS support, status = Status.

#
Channel
Diagnostic
Task
UdpStartQosClientFailure

Message #

UDP: Failure initializing QoS support, status = %1

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1410: UDP: Failure starting FailedQueueString, status = Status.

#
Channel
Diagnostic
Task
UdpStartEndpointModuleFailure

Message #

UDP: Failure starting %1, status = %2

Fields #

NameDescription
FailedQueueString UnicodeString
Status UInt32NTSTATUS reference

Event ID 1411: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: could not allocate send context.

#
Channel
Diagnostic
Task
UdpSendMessagesSendContextResourceFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: could not allocate send context.

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1412: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path af failure, status = Status.

#
Channel
Diagnostic
Task
UdpSendMessagesPathAfFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: path af failure, status = %6

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1413: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path missing next hop failure.

#
Channel
Diagnostic
Task
UdpSendMessagesPathNextHopMissingFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: path missing next hop failure.

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1414: UDP: endpoint Endpoint (sockaddr=EndpointAddress) send messages SendAddress: path next hop address failure.

#
Channel
Diagnostic
Task
UdpSendMessagesPathNextHopAddrFailure

Message #

UDP: endpoint %1 (sockaddr=%3) send messages %5: path next hop address failure.

Fields #

NameDescription
Endpoint Pointer
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Status UInt32NTSTATUS reference

Event ID 1415: TCP: Early Retransmission, FACK or RACK, Connection = Tcb, SndUna = SndUna, SackIsLostSeq = SackIsLostSeq, DupAckCount = DupAckCount.

#
Channel
Diagnostic
Level
Informational
Task
TcpEarlyRetransmit

Message #

TCP: Early Retransmission, FACK or RACK, Connection = %1, SndUna = %2, SackIsLostSeq = %3, DupAckCount = %4

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SackIsLostSeq UInt32
DupAckCount UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1415",
    "version": "0",
    "level": "4",
    "task": "1409",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:27:12.440656500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFD182260",
    "SndUna": "4068749001",
    "SackIsLostSeq": "       0",
    "DupAckCount": "       1"
  },
  "message": ""
}

Event ID 1416: TCP: Ignoring fastopen SYN option due to limit on concurrent SYN_RCVD fastopen connections, Connection = Tcb, SynRcvdLimit = SynRcvdLimit.

#
Channel
Diagnostic
Task
TcpFastopenSynRcvdLimit

Message #

TCP: Ignoring fastopen SYN option due to limit on concurrent SYN_RCVD fastopen connections, Connection = %1, SynRcvdLimit = %2

Fields #

NameDescription
Tcb Pointer
SynRcvdLimit UInt32

Event ID 1417: TCP: Failed to update fastopen key state, Location = Location, Status = Status.

#
Channel
Diagnostic
Task
TcpFastopenKeyUpdateFailure

Description

TCP: Failed to update fastopen key state, Location = Location, Status = Status. Server-side fastopen will be disabled.

Message #

TCP: Failed to update fastopen key state, Location = %1, Status = %2. Server-side fastopen will be disabled

Fields #

NameDescription
Location UInt32
Status UInt32NTSTATUS reference

Event ID 1418: TCP: Fast Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoverySend

Message #

TCP: Fast Retransmit Send, Connection = %1, BytesToSend = %2, SndNxt = %3

Fields #

NameDescription
Tcb Pointer
BytesToSend UInt32
SndNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1418",
    "version": "0",
    "level": "4",
    "task": "1412",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.489901200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "BytesToSend": "    1440",
    "SndNxt": "155002622"
  },
  "message": ""
}

Event ID 1419: TCP: SACK Retransmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoverySend

Message #

TCP: SACK Retransmit Send, Connection = %1, BytesToSend = %2, SndNxt = %3

Fields #

NameDescription
Tcb Pointer
BytesToSend UInt32
SndNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1419",
    "version": "0",
    "level": "4",
    "task": "1412",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.490433800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "BytesToSend": "      38",
    "SndNxt": "155004100"
  },
  "message": ""
}

Event ID 1420: TCP: Limited Transmit Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoverySend

Message #

TCP: Limited Transmit Send, Connection = %1, BytesToSend = %2, SndNxt = %3

Fields #

NameDescription
Tcb Pointer
BytesToSend UInt32
SndNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1420",
    "version": "0",
    "level": "4",
    "task": "1412",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:23:27.162052500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A170D1290",
    "BytesToSend": "    1440",
    "SndNxt": "1228953133"
  },
  "message": ""
}

Event ID 1421: TCP: SACK Retransmit Additional Send, Connection = Tcb, BytesToSend = BytesToSend, SndNxt = SndNxt.

#
Channel
Diagnostic
Level
Informational
Task
TcpLossRecoverySend

Message #

TCP: SACK Retransmit Additional Send, Connection = %1, BytesToSend = %2, SndNxt = %3

Fields #

NameDescription
Tcb Pointer
BytesToSend UInt32
SndNxt UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1421",
    "version": "0",
    "level": "4",
    "task": "1412",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:23:27.167320000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{170d1290-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A170D1290",
    "BytesToSend": "    1440",
    "SndNxt": "1228956013"
  },
  "message": ""
}

Event ID 1422: IPTransportProtocol: PathDirectionmessage.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
IcmpSendRecv

Description

IPTransportProtocol: PathDirectionmessage. Type = IcmpType, Code = IcmpCode, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.

Message #

%1: %2message. Type = %3, Code = %4, CompartmentId = %5, SourceAddress = %7, DestAddress = %9

Fields #

NameDescription
IPTransportProtocol UInt32
PathDirection UInt32
IcmpType UInt32
IcmpCode UInt32
CompartmentId UInt32
SourceAddressLength UInt32
SourceAddress Binary
DestAddressLength UInt32
DestAddress Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1422",
    "version": "0",
    "level": "4",
    "task": "1413",
    "opcode": "0",
    "keywords": 9223372586610589696,
    "time_created": "2026-03-16T00:21:40.180500700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IPTransportProtocol": "       1",
    "PathDirection": "       0",
    "IcmpType": "       3",
    "IcmpCode": "       3",
    "CompartmentId": "       1",
    "SourceAddressLength": "      16",
    "SourceAddress": "10.2.10.21",
    "DestAddressLength": "      16",
    "DestAddress": "8.8.8.8"
  },
  "message": ""
}

Event ID 1423: IPTransportProtocol: PathDirectionpath drop.

#
Channel
Diagnostic
Level
Informational
Task
IcmpPacketDrops

Description

IPTransportProtocol: PathDirectionpath drop. Type = IcmpType, Code = IcmpCode, Reason = DropReason, Status = Status, CompartmentId = CompartmentId, SourceAddress = SourceAddress, DestAddress = DestAddress.

Message #

%1: %2path drop. Type = %3, Code = %4, Reason = %5, Status = %6, CompartmentId = %7, SourceAddress = %9, DestAddress = %11

Fields #

NameDescription
IPTransportProtocol UInt32
PathDirection UInt32
IcmpType UInt32
IcmpCode UInt32
DropReason UInt32
Status UInt32NTSTATUS reference
CompartmentId UInt32
SourceAddressLength UInt32
SourceAddress Binary
DestAddressLength UInt32
DestAddress Binary
IfIndex UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1423",
    "version": "1",
    "level": "4",
    "task": "1414",
    "opcode": "0",
    "keywords": 9223373136366403712,
    "time_created": "2026-03-15T23:30:50.067428800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "10828",
      "thread_id": "12980"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IPTransportProtocol": "       1",
    "PathDirection": "       0",
    "IcmpType": "       3",
    "IcmpCode": "       3",
    "DropReason": "      12",
    "Status": "0xC000021B",
    "CompartmentId": "       1",
    "SourceAddressLength": "      16",
    "SourceAddress": "10.2.10.11",
    "DestAddressLength": "      16",
    "DestAddress": "10.2.10.21",
    "IfIndex": "       4"
  },
  "message": ""
}

Event ID 1424: IPTransportProtocol: Echo timeout.

#
Channel
Diagnostic
Task
IcmpEchoTimeout

Description

IPTransportProtocol: Echo timeout. Status = IcmpCode.

Message #

%1: Echo timeout. Status = %4

Fields #

NameDescription
IPTransportProtocol UInt32
PathDirection UInt32
IcmpType UInt32
IcmpCode UInt32
DropReason UInt32
Status UInt32NTSTATUS reference
CompartmentId UInt32
SourceAddressLength UInt32
SourceAddress Binary
DestAddressLength UInt32
DestAddress Binary

Event ID 1425: Component Timer state changed to CurrentState by Processor Processor Usage = ProcessorUsage at Tick = CurrentTick.

#
Channel
Diagnostic
Task
TcpipTimerStateChange

Message #

%1 Timer state changed to %3 by Processor %2 Usage = %4 at Tick = %5

Fields #

NameDescription
Component UInt32
Processor UInt32
CurrentState UInt32
ProcessorUsage UInt32
CurrentTick UInt32

Event ID 1426: TCP: connection Tcb send complete NumBytes bytes at SndNxt (Injected).

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendComplete

Message #

TCP: connection %1 send complete %3 bytes at %4 (%2).

Fields #

NameDescription
Tcb Pointer
Injected UnicodeString
NumBytes UInt32
SndNxt UInt32
ActivityID Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1426",
    "version": "0",
    "level": "5",
    "task": "1417",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:34.390792600+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4248",
      "thread_id": "4684"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A1018B560",
    "Injected": "normal",
    "NumBytes": "    1303",
    "SndNxt": "2307521250"
  },
  "message": ""
}

Event ID 1427: IP: Compartment creation.

#
Channel
Diagnostic
Task
IpCompartmentCreation

Description

IP: Compartment creation. Compartment = CompartmentId, Protocol = AddressFamily, Private = Private, Status = Status.

Message #

IP: Compartment creation. Compartment = %1, Protocol = %2, Private = %3, Status = %4.

Fields #

NameDescription
CompartmentId UInt32
AddressFamily UInt32
Private UInt32
Status UInt32NTSTATUS reference

Event ID 1428: IP: Compartment deletion.

#
Channel
Diagnostic
Task
IpCompartmentDeletion

Description

IP: Compartment deletion. Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: Compartment deletion. Compartment = %1, Protocol = %2.

Fields #

NameDescription
CompartmentId UInt32
AddressFamily UInt32
Private UInt32
Status UInt32NTSTATUS reference

Event ID 1429: TCP: connection Tcb: Cumulative Ack event, SeqNo = SeqNo, BytesAcked = BytesAcked, CWnd = Cwnd, SndWnd = SndWnd, InRecovery = InRecovery, TimeSinceLastLossMS = TimeSinceLastLossMS, CubicCwnd...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpCubicDataTransferCumAck

Description

TCP: connection : Cumulative Ack event, SeqNo = , BytesAcked = , CWnd = , SndWnd = , InRecovery = , TimeSinceLastLossMS = , CubicCwnd = , AimdCwnd = , K = , Wmax = , LastWmax = , MaxSndWnd = .

Message #

TCP: connection %1: Cumulative Ack event, SeqNo = %5, BytesAcked = %4, CWnd = %2, SndWnd = %3, InRecovery = %6, TimeSinceLastLossMS = %7, CubicCwnd = %8, AimdCwnd = %9, K = %10, Wmax = %11, LastWmax = %12, MaxSndWnd = %13.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesAcked UInt32
SeqNo UInt32
InRecovery UInt8
TimeSinceLastLossMS UInt64
CubicCwnd UInt64
AimdCwnd UInt32
K UInt64
Wmax UInt32
LastWmax UInt32
MaxSndWnd UInt32
IsLimitedSlowStart UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1429",
    "version": "1",
    "level": "4",
    "task": "1420",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:36.015001500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{10708010-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A10708010",
    "Cwnd": "   27376",
    "SndWnd": "  262656",
    "BytesAcked": "       0",
    "SeqNo": "3807647817",
    "InRecovery": "0",
    "TimeSinceLastLossMS": "0",
    "CubicCwnd": "0",
    "AimdCwnd": "       0",
    "K": "0",
    "Wmax": "       0",
    "LastWmax": "       0",
    "MaxSndWnd": "  262656",
    "IsLimitedSlowStart": "0"
  },
  "message": ""
}

Event ID 1430: TCP: connection Tcb: Duplicate ACK updated cwnd = Cwnd and updated ssthresh = SSThresh DupAckCount = DupAckCount SndUna = SeqNo CwrMax = CwrMax.

#
Channel
Diagnostic
Level
Informational
Task
TcpCubicDataTransferDupAck

Message #

TCP: connection %1: Duplicate ACK updated cwnd = %2 and updated ssthresh = %3 DupAckCount = %4 SndUna = %5 CwrMax = %6.

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
DupAckCount UInt32
SeqNo UInt32
CwrMax UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1430",
    "version": "0",
    "level": "4",
    "task": "1421",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-15T23:27:12.440654900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFD182260",
    "Cwnd": "   22020",
    "SSThresh": "   16760",
    "DupAckCount": "       1",
    "SeqNo": "4068749001",
    "CwrMax": "4068749000"
  },
  "message": ""
}

Event ID 1431: IP: Compartment cleanup.

#
Channel
Diagnostic
Task
IpCompartmentCleanup

Description

IP: Compartment cleanup. Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: Compartment cleanup. Compartment = %1, Protocol = %2.

Fields #

NameDescription
CompartmentId UInt32
AddressFamily UInt32
Private UInt32
Status UInt32NTSTATUS reference

Event ID 1432: IP: Interface network category state change.

#
Channel
Diagnostic
Task
IpUpdateInterfaceNetworkCategoryState

Description

IP: Interface network category state change. Interface = IfIndex, Compartment = CompartmentId , Protocol = AddressFamily, NetworkCategory = NetworkCategory, DomainNetworkLocation = DomainNetworkLocation, DomainType = DomainType, Signature = NetworkSignature.

Message #

IP: Interface network category state change. Interface = %1, Compartment = %2 , Protocol = %3, NetworkCategory = %4, DomainNetworkLocation = %5, DomainType = %6, Signature = %7.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
NetworkCategory UInt32
DomainNetworkLocation UInt32
DomainType UInt32
NetworkSignature GUID

Event ID 1433: IP: Interface creation.

#
Channel
Diagnostic
Task
IpInterfaceCreation

Description

IP: Interface creation. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, PhysicalMediumType = PhysicalMediumType, Status = Status.

Message #

IP: Interface creation. Interface = %1, Compartment = %2, Protocol = %3, PhysicalMediumType = %4, Status = %5.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
PhysicalMediumType UInt32
Status UInt32NTSTATUS reference

Event ID 1434: IP: Interface deletion.

#
Channel
Diagnostic
Task
IpInterfaceDeletion

Description

IP: Interface deletion. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: Interface deletion. Interface = %1, Compartment = %2, Protocol = %3.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
PhysicalMediumType UInt32
Status UInt32NTSTATUS reference

Event ID 1435: IP: Interface cleanup.

#
Channel
Diagnostic
Task
IpInterfaceCleanup

Description

IP: Interface cleanup. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: Interface cleanup. Interface = %1, Compartment = %2, Protocol = %3.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
PhysicalMediumType UInt32
Status UInt32NTSTATUS reference

Event ID 1436: IP: SubInterface creation.

#
Channel
Diagnostic
Task
IpSubInterfaceCreation

Description

IP: SubInterface creation. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, Status = Status.

Message #

IP: SubInterface creation. SubInterface = %1, Interface = %2, Compartment = %3, Protocol = %4, Status = %5.

Fields #

NameDescription
SubIfIndex UInt32
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
Status UInt32NTSTATUS reference

Event ID 1437: IP: SubInterface deletion.

#
Channel
Diagnostic
Task
IpSubInterfaceDeletion

Description

IP: SubInterface deletion. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: SubInterface deletion. SubInterface = %1, Interface = %2, Compartment = %3, Protocol = %4.

Fields #

NameDescription
SubIfIndex UInt32
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
Status UInt32NTSTATUS reference

Event ID 1438: IP: SubInterface cleanup.

#
Channel
Diagnostic
Task
IpSubInterfaceCleanup

Description

IP: SubInterface cleanup. SubInterface = SubIfIndex, Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily.

Message #

IP: SubInterface cleanup. SubInterface = %1, Interface = %2, Compartment = %3, Protocol = %4.

Fields #

NameDescription
SubIfIndex UInt32
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
Status UInt32NTSTATUS reference

Event ID 1439: IP: Interface change Notification.

#
Channel
Diagnostic
Task
IpInterfaceChangeNotification

Description

IP: Interface change Notification. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, Reason = Reason.

Message #

IP: Interface change Notification. Interface = %1, Compartment = %2, Protocol = %3, Reason = %4.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
Reason UInt32
State UInt32
NotificationType UInt32

Event ID 1440: IP: Interface internet connectivity status change.

#
Channel
Diagnostic
Task
IpInterfaceInternetConnectivityStatus

Description

IP: Interface internet connectivity status change. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, OldConnectivityStatus = OldConnectivityStatus, NewConnectivityStatus = NewConnectivityStatus.

Message #

IP: Interface internet connectivity status change. Interface = %1, Compartment = %2, Protocol = %3, OldConnectivityStatus = %4, NewConnectivityStatus = %5.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
OldConnectivityStatus UInt32
NewConnectivityStatus UInt32

Event ID 1441: IP: Address change notification.

#
Channel
Diagnostic
Task
IpAddressChangeNotification

Description

IP: Address change notification. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, Protocol = Protocol, Reason = Reason.

Message #

IP: Address change notification. Address = %2, Interface = %3, Compartment = %4, Protocol = %5, Reason = %6.

Fields #

NameDescription
SourceAddressLength UInt32
SourceAddress Binary
IfIndex UInt32
CompartmentId UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
Reason UInt32
State UInt32
NotificationType UInt32
DadState UInt32

Event ID 1442: IP: Route change notification.

#
Channel
Diagnostic
Task
IpRouteChangeNotification

Description

IP: Route change notification. DestinationPrefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Interface = IfIndex, Compartment = CompartmentId, NotifyFlags = NotifyFlags.

Message #

IP: Route change notification. DestinationPrefix = %2/%5, NextHop = %4, Interface = %7, Compartment = %6, NotifyFlags = %8.

Fields #

NameDescription
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
DestinationPrefixLength UInt32
CompartmentId UInt32
IfIndex UInt32
NotifyFlags UInt64
State UInt32
NotificationType UInt32

Event ID 1443: IP: Neighbor change notification.

#
Channel
Diagnostic
Task
IpNeighborChangeNotification

Description

IP: Neighbor change notification. IpAddress = IPAddress, DlAddress = DLAddress, Interface = IfIndex, Compartment = CompartmentId, State = NeighborState, Reason = Reason.

Message #

IP: Neighbor change notification. IpAddress = %2, DlAddress = %4, Interface = %5, Compartment = %6, State = %7, Reason = %8.

Fields #

NameDescription
IpAddrLength UInt32
IPAddress Binary
DlAddrLength UInt32
DLAddress Binary
IfIndex UInt32
CompartmentId UInt32
NeighborState UInt32
Reason UInt32
NotificationState UInt32
NotificationType UInt32

Event ID 1444: IP: Address DAD state change.

#
Channel
Diagnostic
Task
IpAddressDadStateChange

Description

IP: Address DAD state change. Address = SourceAddress, Interface = IfIndex, Compartment = CompartmentId, OldState = OldDadState, NewState = NewDadState, Reason = Reason.

Message #

IP: Address DAD state change. Address = %2, Interface = %3, Compartment = %4, OldState = %5, NewState = %6, Reason = %7.

Fields #

NameDescription
SourceAddressLength UInt32
SourceAddress Binary
IfIndex UInt32
CompartmentId UInt32
OldDadState UInt32
NewDadState UInt32
Reason UInt32

Event ID 1445: IP: Route Dead Gateway Detection state change.

#
Channel
Diagnostic
Task
IpRouteDGDStateChange

Description

IP: Route Dead Gateway Detection state change. DestinationPrefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Interface = IfIndex, Compartment = CompartmentId, OldState = OldState, NewState = NewState, OldProbeCount = OldProbeCount, NewProbeCount = NewProbeCount, OldUnreachablePaths = OldUnreachablePaths, NewUnreachablePaths = NewUnreachablePaths, OldMovedPaths = OldMovedPaths, NewMovedPaths = NewMovedPaths, TotalPaths = TotalPaths, OldStateChangeTick = OldStateChangeTick, NewStateChangeTick = NewStateChangeTick, DgdNeedsReset = DgdNeedsReset, Reason = Reason.

Message #

IP: Route Dead Gateway Detection state change. DestinationPrefix = %2/%5, NextHop = %4, Interface = %7, Compartment = %6, OldState = %8, NewState = %9, OldProbeCount = %10, NewProbeCount = %11, OldUnreachablePaths = %12, NewUnreachablePaths = %13, OldMovedPaths = %14, NewMovedPaths = %15, TotalPaths = %16, OldStateChangeTick = %17, NewStateChangeTick = %18, DgdNeedsReset = %19, Reason = %20.

Fields #

NameDescription
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
NextHopAddressLength UInt32
NextHopAddress Binary
DestinationPrefixLength UInt32
CompartmentId UInt32
IfIndex UInt32
OldState UInt32
NewState UInt32
OldProbeCount UInt32
NewProbeCount UInt32
OldUnreachablePaths UInt32
NewUnreachablePaths UInt32
OldMovedPaths UInt32
NewMovedPaths UInt32
TotalPaths UInt32
OldStateChangeTick UInt32
NewStateChangeTick UInt32
DgdNeedsReset UInt32
Reason UInt32

Event ID 1446: IP: Disconnecting TCP connections with Address = Address, Interface = IfIndex, Compartment = CompartmentId, SkipLocal = SkipLocal, SkipOnLink = SkipOnLink.

#
Channel
Diagnostic
Task
IpInterfaceDisconnect

Message #

IP: Disconnecting TCP connections with Address = %2, Interface = %3, Compartment = %4, SkipLocal = %5, SkipOnLink = %6.

Fields #

NameDescription
AddressLength UInt32
Address Binary
IfIndex UInt32
CompartmentId UInt32
SkipLocal UInt32
SkipOnLink UInt32

Event ID 1447: TCP: connection Tcb: Sending paced chunk of QuantizedAllowance bytes with CWnd = Cwnd, SndWnd = SndWnd, BytesAvailable = BytesAvailable, BytesOutstanding = BytesOutstanding.

#
Channel
Diagnostic
Task
TcpPacingSend

Message #

TCP: connection %1: Sending paced chunk of %6 bytes with CWnd = %2, SndWnd = %3, BytesAvailable = %4, BytesOutstanding = %5

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SndWnd UInt32
BytesAvailable UInt32
BytesOutstanding UInt32
QuantizedAllowance UInt32
Allowance UInt32
OriginalBytesToSend UInt32

Event ID 1448: Fallback: Context = Fallback, Feature = Feature, TraceReason = Reason, Confidence = Confidence, Successes = Successes, Failures = Failures.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

Fallback: Context = %1, Feature = %2, TraceReason = %3, Confidence = %4, Successes = %5, Failures = %6

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Reason UInt32
Confidence Int32
Successes UInt32
Failures UInt32

Event ID 1449: TCPIP: TCB Tcb using fast loopback.

#
Channel
Diagnostic
Task
TcpLoopbackFastPathSuccess

Message #

TCPIP: TCB %1 using fast loopback

Fields #

NameDescription
Tcb Pointer

Event ID 1450: IP: Router information change notification.

#
Channel
Diagnostic
Task
IpRouterInformationChangeNotification

Description

IP: Router information change notification. Interface = IfIndex, Compartment = CompartmentId, Protocol = AddressFamily, Reason = Reason.

Message #

IP: Router information change notification. Interface = %1, Compartment = %2, Protocol = %3, Reason = %4.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
Reason UInt32

Event ID 1451: IP: Event.

#
Channel
Diagnostic
Task
IpRaDnsEvent

Description

IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, DNS Server/Suffix: DNSServerAddress DNSSuffix, Lifetime = Lifetime.

Message #

IP: %1. Interface = %2, Compartment = %3, RouterAddress = %5, DNS Server/Suffix: %7 %8, Lifetime = %9.

Fields #

NameDescription
Event UInt32
Interface UInt32
CompartmentId UInt32
RouterAddrLength UInt32
RouterAddress Binary
DnsAddrLength UInt32
DNSServerAddress Binary
DNSSuffix AnsiString
Lifetime UInt32

Event ID 1452: IP: Route rundown.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
IpRouteRundown

Description

IP: Route rundown. Interface = Interface, Compartment = Compartment, Prefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Metric = Metric, State = State, Origin = Origin, Age = Age, ValidLifetime = ValidLifetime, PreferredLifetime = PreferredLifetime, Flags = Flags.

Message #

IP: Route rundown. Interface = %1, Compartment = %2, Prefix = %4/%5, NextHop = %7, Metric = %8, State = %9, Origin = %10, Age = %11, ValidLifetime = %12, PreferredLifetime = %13, Flags = %14.

Fields #

NameDescription
Interface UInt32
Compartment UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
DestinationPrefixLength UInt32
NextHopAddressLength UInt32
NextHopAddress Binary
Metric UInt32
State UInt32
Origin UInt32
Age UInt64
ValidLifetime UInt64
PreferredLifetime UInt64
Flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1452",
    "version": "0",
    "level": "4",
    "task": "1443",
    "opcode": "0",
    "keywords": 9223372586610589856,
    "time_created": "2026-03-16T00:21:34.295267700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Interface": "       6",
    "Compartment": "       1",
    "DestinationPrefixAddressLength": "      16",
    "DestinationPrefix": "0.0.0.0",
    "DestinationPrefixLength": "       0",
    "NextHopAddressLength": "      16",
    "NextHopAddress": "10.2.10.254",
    "Metric": "     256",
    "State": "       0",
    "Origin": "       0",
    "Age": "0x1A11",
    "ValidLifetime": "0xFFFFFFFF",
    "PreferredLifetime": "0xFFFFFFFF",
    "Flags": "0x388"
  },
  "message": ""
}

Event ID 1453: TCP: CUBIC ECN event.

#
Channel
Diagnostic
Task
TcpCubicDataTransferEcn

Description

TCP: CUBIC ECN event. Connection Tcb, CWnd Cwnd, SSThresh = SSThresh, SndUna = SndUna.

Message #

TCP: CUBIC ECN event. Connection %1, CWnd %2, SSThresh = %3, SndUna = %4

Fields #

NameDescription
Tcb Pointer
Cwnd UInt32
SSThresh UInt32
SndUna UInt32

Event ID 1454: INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectAction, Status = Status.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
InetInspect

Message #

INETINSPECT: Owner = %1, InspectHandle = %2, InspectType = %3, Action = %4, Status = %5

Fields #

NameDescription
Owner Pointer
InspectHandle Pointer
InspectType UInt32
InspectAction UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1454",
    "version": "0",
    "level": "4",
    "task": "1445",
    "opcode": "0",
    "keywords": 9223372036854775936,
    "time_created": "2026-03-16T00:21:34.388718700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{1018b560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4168",
      "thread_id": "6880"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Owner": "0xFFFF980A1018B560",
    "InspectHandle": "0xFFFF980A17030CE0",
    "InspectType": "       0",
    "InspectAction": "       1",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1455: INETINSPECT: Owner = Owner, InspectHandle = InspectHandle, InspectType = InspectType, Action = InspectPort, Status = Status.

#
Channel
Diagnostic
Level
Informational
Task
InetInspect

Message #

INETINSPECT: Owner = %1, InspectHandle = %2, InspectType = %3, Action = %4, Status = %5

Fields #

NameDescription
Owner Pointer
InspectHandle Pointer
InspectType UInt32
InspectPort UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1455",
    "version": "0",
    "level": "4",
    "task": "1445",
    "opcode": "0",
    "keywords": 9223372036854775936,
    "time_created": "2026-03-16T00:21:40.077855500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0b1c4090-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Owner": "0xFFFF980A0B1C4090",
    "InspectHandle": "0xFFFF980A13FE6CC0",
    "InspectType": "      17",
    "InspectPort": "       0",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1456: FallbackCheck: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

FallbackCheck: Ctx = %1, Feature = %2, Failed = %3, Succeeeded = %4, InProbe = %5, PathsProbed = %6, Status = %7

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Failed UInt32
Succeeded UInt32
InProbe UInt32
PathsProbed UInt32
Status UInt32NTSTATUS reference

Event ID 1457: FallbackUpdate: Ctx = Fallback, Feature = Feature, Failed = Failed, Succeeeded = Succeeded, InProbe = InProbe, PathsProbed = PathsProbed, Status = Status.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

FallbackUpdate: Ctx = %1, Feature = %2, Failed = %3, Succeeeded = %4, InProbe = %5, PathsProbed = %6, Status = %7

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Failed UInt32
Succeeded UInt32
InProbe UInt32
PathsProbed UInt32
Status UInt32NTSTATUS reference

Event ID 1458: Fallback: Permanently disabling feature, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

Fallback: Permanently disabling feature, Ctx = %1, Feature = %2, PathsProbed = %6

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Failed UInt32
Succeeded UInt32
InProbe UInt32
PathsProbed UInt32
Status UInt32NTSTATUS reference

Event ID 1459: Fallback: Enabling feature for this boot session, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

Fallback: Enabling feature for this boot session, Ctx = %1, Feature = %2, PathsProbed = %6

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Failed UInt32
Succeeded UInt32
InProbe UInt32
PathsProbed UInt32
Status UInt32NTSTATUS reference

Event ID 1460: Fallback: Feature previously disabled, Ctx = Fallback, Feature = Feature, PathsProbed = PathsProbed.

#
Channel
Diagnostic
Task
FeatureFallback

Message #

Fallback: Feature previously disabled, Ctx = %1, Feature = %2, PathsProbed = %6

Fields #

NameDescription
Fallback Pointer
Feature UInt32
Failed UInt32
Succeeded UInt32
InProbe UInt32
PathsProbed UInt32
Status UInt32NTSTATUS reference

Event ID 1461: TCP Fastopen fallback update: Tcb = Tcb, FastopenState = FastopenState, DataBytesIn = DataBytesIn, ShutdownStatus = ShutdownStatus, ProbeStatus = ProbeStatus.

#
Channel
Diagnostic
Task
TcpFastopenFallbackUpdate

Message #

TCP Fastopen fallback update: Tcb = %1, FastopenState = %2, DataBytesIn = %3, ShutdownStatus = %4, ProbeStatus = %5

Fields #

NameDescription
Tcb Pointer
FastopenState UInt32
DataBytesIn UInt64
ShutdownStatus UInt32
ProbeStatus UInt32

Event ID 1462: Disabling feature until connectivity is established: CompartmentId =CompartmentId, IfIndex = IfIndex, Feature = Feature, ConnectivityStatus = ConnectivityStatus.

#
Channel
Diagnostic
Task
FeatureFallbackNcsiNoConnectivity

Message #

Disabling feature until connectivity is established: CompartmentId =%1, IfIndex = %2, Feature = %3, ConnectivityStatus = %4

Fields #

NameDescription
CompartmentId UInt32
IfIndex UInt32
Feature UInt32
ConnectivityStatus UInt32

Event ID 1463: Disabling Feature for loopback connection.

#
Channel
Diagnostic
Task
FeatureFallbackLoopback

Message #

Disabling %1 for loopback connection

Fields #

NameDescription
Feature UInt32

Event ID 1464: Disabling TCP Fastopen for BaseEndpoint = BaseEndpoint because an incompatible WFP callout is installed.

#
Channel
Diagnostic
Task
TcpFastopenIncompatCallout

Message #

Disabling TCP Fastopen for BaseEndpoint = %1 because an incompatible WFP callout is installed

Fields #

NameDescription
BaseEndpoint Pointer

Event ID 1465: IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFl...

#
Channel
Diagnostic
Level
Verbose
Task
TcpipSourceConstraint

Description

IP: Setting source constraint for route lookup - Compartment: Compartment DstAddr: DestinationAddress ConstrainSrcAddr: ConstrainSourceAddress ConstrainIfIndex: ConstrainInterfaceIndex ConstraintFlags: ConstraintFlags.

Message #

IP: Setting source constraint for route lookup - Compartment: %1 DstAddr: %3 ConstrainSrcAddr: %5 ConstrainIfIndex: %6 ConstraintFlags: %7

Fields #

NameDescription
Compartment UInt32
DestinationAddrLength UInt32
DestinationAddress Binary
ConstrainSourceAddrLength UInt32
ConstrainSourceAddress Binary
ConstrainInterfaceIndex UInt32
ConstraintFlags UInt32
TransportProtocol UInt32
IcmpType UInt8
IcmpCode UInt8

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1465",
    "version": "0",
    "level": "5",
    "task": "1450",
    "opcode": "0",
    "keywords": 9223372036854775840,
    "time_created": "2026-03-16T00:21:38.719138100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Compartment": "       1",
    "DestinationAddrLength": "      16",
    "DestinationAddress": "10.2.10.11",
    "ConstrainSourceAddrLength": "      16",
    "ConstrainSourceAddress": "10.2.10.21",
    "ConstrainInterfaceIndex": "       6",
    "ConstraintFlags": "0x1"
  },
  "message": ""
}

Event ID 1466: WFP-ALE: RemoteEndPoint Insertion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
RemoteEndpoint

Message #

WFP-ALE: RemoteEndPoint Insertion: (local=%2 remote=%3) PartitionId=%4 PartitionNumEntries=%5

Fields #

NameDescription
AddressLength UInt32
LocalAddress Binary
RemoteAddress Binary
PartitionId UInt64
NumEntries UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1466",
    "version": "0",
    "level": "4",
    "task": "1372",
    "opcode": "0",
    "keywords": 9223372036854808576,
    "time_created": "2026-03-16T00:21:40.078425500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressLength": "      16",
    "LocalAddress": "10.2.10.21:53893",
    "RemoteAddress": "10.2.10.11:53",
    "PartitionId": "4",
    "NumEntries": "4"
  },
  "message": ""
}

Event ID 1467: WFP-ALE: RemoteEndPoint Deletion: (local=LocalAddress remote=RemoteAddress) PartitionId=PartitionId PartitionNumEntries=NumEntries.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
RemoteEndpoint

Message #

WFP-ALE: RemoteEndPoint Deletion: (local=%2 remote=%3) PartitionId=%4 PartitionNumEntries=%5

Fields #

NameDescription
AddressLength UInt32
LocalAddress Binary
RemoteAddress Binary
PartitionId UInt64
NumEntries UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1467",
    "version": "0",
    "level": "4",
    "task": "1372",
    "opcode": "0",
    "keywords": 9223372036854808576,
    "time_created": "2026-03-16T00:21:40.078776800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressLength": "      16",
    "LocalAddress": "10.2.10.21",
    "RemoteAddress": "8.8.8.8:1",
    "PartitionId": "4",
    "NumEntries": "3"
  },
  "message": ""
}

Event ID 1468: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort.

#
Channel
Diagnostic
Task
TcpSystemAbortTcb

Description

TCP: connection Tcb (local=LocalAddress remote=RemoteAddress) system abort. PID = ProcessId.

Message #

TCP: connection %8 (local=%2 remote=%4) system abort. PID = %6.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64
Reason UInt32

Event ID 1469: Disabling Feature due to no next hop.

#
Channel
Diagnostic
Task
FeatureFallbackNoNextHop

Message #

Disabling %1 due to no next hop

Fields #

NameDescription
Feature UInt32

Event ID 1470: TCP: endpoint (sockaddr=LocalAddressLength) bind failed: wake status = LocalAddress.

#
Channel
Diagnostic
Task
TcpBindEndpointWakeFailure

Message #

TCP: endpoint (sockaddr=%2) bind failed: wake status = %3.

Fields #

NameDescription
Endpoint Pointer
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference

Event ID 1471: UDP: endpoint Endpoint (sockaddr=LocalAddress) bind failed: wake status = Status.

#
Channel
Diagnostic
Task
UdpBindEndpointWakeFailure

Message #

UDP: endpoint %4 (sockaddr=%2) bind failed: wake status = %3

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
Endpoint Pointer

Event ID 1472: Acquire wake port Port, type=AcquireType, family=AddressFamily, IF=Interface, compartment=Compartment.

#
Channel
Diagnostic
Task
InetWakeAcquirePort

Message #

Acquire wake port %2, type=%1, family=%3, IF=%4, compartment=%5

Fields #

NameDescription
AcquireType UInt32
Port UInt16
AddressFamily UInt32
Interface UInt32
Compartment UInt32

Event ID 1473: TCP: Connection Tcb reached max SACK queue length.

#
Channel
Diagnostic
Task
TcpSackUpdateLimitReached

Message #

TCP: Connection %1 reached max SACK queue length

Fields #

NameDescription
Tcb Pointer
Location UInt32

Event ID 1474: TCP: Connection Tcb requested fast open.

#
Channel
Diagnostic
Task
TcpFastopenRequested

Message #

TCP: Connection %1 requested fast open

Fields #

NameDescription
Tcb Pointer

Event ID 1475: TCP: CUBIC Hystart state change event.

#
Channel
Diagnostic
Level
Informational
Task
TcpCubicHystartStateChange

Description

TCP: CUBIC Hystart state change event. Connection Tcb, State State, CWnd Cwnd, SSThresh = SSThresh.

Message #

TCP: CUBIC Hystart state change event. Connection %1, State %2, CWnd %3, SSThresh = %4.

Fields #

NameDescription
Tcb Pointer
State UInt16
Cwnd UInt32
SSThresh UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1475",
    "version": "0",
    "level": "4",
    "task": "1463",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.489856100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "State": "2",
    "Cwnd": "   16734",
    "SSThresh": "4294967295"
  },
  "message": ""
}

Event ID 1476: IP: Transmitting loopback Nbl Nbl.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
TcpIpPerPacket
Task
TcpipLoopbackPacketTransmit
Opcode
Info

Description

IP: Transmitting loopback Nbl Nbl. Interface=Interface, Compartment=Compartment, Src=SourceAddress, Dst=DestinationAddress, Proto=IPTransportProtocol.

Message #

IP: Transmitting loopback Nbl %1. Interface=%2, Compartment=%3, Src=%6, Dst=%5, Proto=%7.

Fields #

NameDescription
Nbl Pointer
Interface UInt32
Compartment UInt32
AddressLength UInt32
DestinationAddress Binary
SourceAddress Binary
IPTransportProtocol UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1476",
    "version": "0",
    "level": "17",
    "task": "1464",
    "opcode": "0",
    "keywords": 9223372036858970112,
    "time_created": "2026-03-16T00:23:11.240868900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "11564"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Nbl": "0xFFFF980A1A0CE070",
    "Interface": "       6",
    "Compartment": "       1",
    "AddressLength": "      16",
    "DestinationAddress": "224.0.0.251:5353",
    "SourceAddress": "10.2.10.21:5353",
    "IPTransportProtocol": "      17"
  },
  "message": ""
}

Event ID 1477: TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
TcpSummary
Task
TcpConnectionSummary
Opcode
Info

Description

TCP: Connection Tcb Summary: DataBytesOut DataBytesOut DataBytesIn DataBytesIn DataSegmentsOut DataSegmentsOut DataSegmentsIn DataSegmentsIn SegmentsOut SegmentsOut SegmentsIn SegmentsIn NonRecovDa \ NonRecovDa NonRecovDaEpisodes NonRecovDaEpisodes DupAcksIn DupAcksIn BytesRetrans BytesRetrans Timeouts Timeouts SpuriousRtoDetections SpuriousRtoDetections FastRetran FastRetran MaxSsthresh MaxSsthresh MaxSsCwnd MaxSsCwnd \ MaxCaCwnd MaxCaCwnd SndLimTransRwin SndLimTransRwin SndLimTimeRwin SndLimTimeRwin SndLimBytesRwin SndLimBytesRwin SndLimTransCwnd SndLimTransCwnd SndLimTimeCwnd SndLimTimeCwnd SndLimBytesCwnd SndLimBytesCwnd \ SndLimTransSnd SndLimTransSnd SndLimTimeSnd SndLimTimeRSnd SndLimBytesSnd SndLimBytesRSnd ConnectionTimeMs ConnectionTimeMs Timestamps TimestampsEnabled RttUs RttUs MinRtt MinRttUs MaxRtt MaxRttUs SynRetrans SynRetrans CongestionAlgorithm CongestionAlgorithm \ State State Local LocalAddress Remote RemoteAddress CWnd CWnd SsThresh SsThresh RcvWnd RcvWnd RcvBuf RcvBuf SndWnd SndWnd \ InterfaceIndex InterfaceIndex LocalPort LocalPort IsLoopback IsLoopback.

Message #

TCP: Connection %1 Summary: DataBytesOut %2 DataBytesIn %3 DataSegmentsOut %4 DataSegmentsIn %5 SegmentsOut %6 SegmentsIn %7 NonRecovDa \   %8 NonRecovDaEpisodes %9 DupAcksIn %10 BytesRetrans %11 Timeouts %12 SpuriousRtoDetections %13 FastRetran %14 MaxSsthresh %15 MaxSsCwnd %16 \   MaxCaCwnd %17 SndLimTransRwin %18 SndLimTimeRwin %19 SndLimBytesRwin %20 SndLimTransCwnd %21 SndLimTimeCwnd %22 SndLimBytesCwnd %23 \   SndLimTransSnd %24 SndLimTimeSnd %25 SndLimBytesSnd %26 ConnectionTimeMs %27 Timestamps %28 RttUs %29 MinRtt %30 MaxRtt %31 SynRetrans %32 CongestionAlgorithm %33 \   State %34 Local %36 Remote %38 CWnd %39 SsThresh %40 RcvWnd %41 RcvBuf %42 SndWnd %43.

Fields #

NameDescription
Tcb Pointer
DataBytesOut UInt64
DataBytesIn UInt64
DataSegmentsOut UInt64
DataSegmentsIn UInt64
SegmentsOut UInt64
SegmentsIn UInt64
NonRecovDa UInt32
NonRecovDaEpisodes UInt32
DupAcksIn UInt32
BytesRetrans UInt32
Timeouts UInt32
SpuriousRtoDetections UInt32
FastRetran UInt32
MaxSsthresh UInt32
MaxSsCwnd UInt32
MaxCaCwnd UInt32
SndLimTransRwin UInt32
SndLimTimeRwin UInt32
SndLimBytesRwin UInt64
SndLimTransCwnd UInt32
SndLimTimeCwnd UInt32
SndLimBytesCwnd UInt64
SndLimTransSnd UInt32
SndLimTimeRSnd UInt32
SndLimBytesRSnd UInt64
ConnectionTimeMs UInt64
TimestampsEnabled UInt32
RttUs UInt32
MinRttUs UInt32
MaxRttUs UInt32
SynRetrans UInt32
CongestionAlgorithm UInt32
State UInt32
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
CWnd UInt32
SsThresh UInt32
RcvWnd UInt32
RcvBuf UInt32
SndWnd UInt32
InterfaceIndex UInt32
LocalPort UInt32
IsLoopback Boolean

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1477",
    "version": "1",
    "level": "16",
    "task": "1341",
    "opcode": "0",
    "keywords": 9223407221226864640,
    "time_created": "2026-03-16T00:21:38.733329900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0eee7560-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4",
      "thread_id": "7444"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0EEE7560",
    "DataBytesOut": "426",
    "DataBytesIn": "5091",
    "DataSegmentsOut": "2",
    "DataSegmentsIn": "5",
    "SegmentsOut": "6",
    "SegmentsIn": "8",
    "NonRecovDa": "       0",
    "NonRecovDaEpisodes": "       0",
    "DupAcksIn": "       0",
    "BytesRetrans": "       0",
    "Timeouts": "       0",
    "SpuriousRtoDetections": "       0",
    "FastRetran": "       0",
    "MaxSsthresh": "4294967295",
    "MaxSsCwnd": "   15027",
    "MaxCaCwnd": "       0",
    "SndLimTransRwin": "       0",
    "SndLimTimeRwin": "       0",
    "SndLimBytesRwin": "0",
    "SndLimTransCwnd": "       0",
    "SndLimTimeCwnd": "       0",
    "SndLimBytesCwnd": "0",
    "SndLimTransSnd": "       1",
    "SndLimTimeRSnd": "       0",
    "SndLimBytesRSnd": "430",
    "ConnectionTimeMs": "14",
    "TimestampsEnabled": "       0",
    "RttUs": "    1146",
    "MinRttUs": "     982",
    "MaxRttUs": "    1717",
    "SynRetrans": "       0",
    "CongestionAlgorithm": "       5",
    "State": "       0",
    "LocalAddressLength": "      28",
    "LocalAddress": "[::ffff:10.2.10.21]:5985",
    "RemoteAddressLength": "      28",
    "RemoteAddress": "[::ffff:10.2.10.11]:51201",
    "CWnd": "   15027",
    "SsThresh": "4294967295",
    "RcvWnd": " 2098020",
    "RcvBuf": " 2098020",
    "SndWnd": "  262144",
    "InterfaceIndex": "       6",
    "LocalPort": "   24855",
    "IsLoopback": "false"
  },
  "message": ""
}

Event ID 1478: TCPIP: Framing layer PathDirection (AddressFamily=AddressFamily) dropped PacketCount packet(s) on interface=Interface, Reason=Reason, Data=Data.

#
Channel
Diagnostic
Task
TcpipFramingPacketDrops

Message #

TCPIP: Framing layer %1 (AddressFamily=%2) dropped %4 packet(s) on interface=%3, Reason=%5, Data=%6.

Fields #

NameDescription
PathDirection UInt32
AddressFamily UInt32
Interface UInt32
PacketCount UInt32
Reason UInt32
Data UInt32

Event ID 1479: TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpRstSend

Description

TCP: Connection Tcb Transport (Protocol IPTransportProtocol, AddressFamily = AddressFamily) sent RST with Local = LocalSockAddr, Remote = RemoteSockAddr. Reason = Reason.

Message #

TCP: Connection %1 Transport (Protocol %2, AddressFamily = %3) sent RST with Local = %5, Remote = %7. Reason = %8.

Fields #

NameDescription
Tcb Pointer
IPTransportProtocol UInt32
AddressFamily UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary
Reason UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1479",
    "version": "0",
    "level": "4",
    "task": "1466",
    "opcode": "0",
    "keywords": 9223372586610589824,
    "time_created": "2026-03-16T00:22:37.889812500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A0E584560",
    "IPTransportProtocol": "       6",
    "AddressFamily": "       2",
    "LocalSockAddrLength": "      16",
    "LocalSockAddr": "10.2.10.21:52990",
    "RemoteSockAddrLength": "      16",
    "RemoteSockAddr": "52.159.108.190:443",
    "Reason": "      10"
  },
  "message": ""
}

Event ID 1480: TCP connection failed with Status = Status, Local = LocalSockAddr, Remote = RemoteSockAddr, ProcessId = TcpState, TcpState = ProcessId at Hour:Minute:Second Reason = Reason.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
TcpSummary
Task
TcpRecentConnectionFailure
Opcode
Info

Message #

TCP connection failed with Status = %1, Local = %3, Remote = %5, ProcessId = %6, TcpState = %7 at %8:%9:%10 Reason = %11.

Fields #

NameDescription
Status UInt32NTSTATUS reference
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary
TcpState UInt32
ProcessId UInt32
Hour UInt16
Minute UInt16
Second UInt16
Reason UInt32
ProcessStartKey UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1480",
    "version": "1",
    "level": "16",
    "task": "1467",
    "opcode": "0",
    "keywords": 9223407221226864640,
    "time_created": "2026-03-16T00:21:34.294926800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Status": "0xC0000241",
    "LocalSockAddrLength": "      16",
    "LocalSockAddr": "10.2.10.21:50542",
    "RemoteSockAddrLength": "      16",
    "RemoteSockAddr": "20.42.65.85:443",
    "TcpState": "       6",
    "ProcessId": "    3688",
    "Hour": "0",
    "Minute": "17",
    "Second": "1",
    "Reason": "      14",
    "ProcessStartKey": "2814749767106643"
  },
  "message": ""
}

Event ID 1481: TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight B...

#
Channel
Operational
Level
Verbose
Task
TcpPrrSend

Description

TCP: Connection Tcb PRR send SackIsLostSeq SackIsLostSeq SackInFlight SackInFlight SackBytes SackBytes SackIsLost SackIsLost SsThresh SsThresh RecoveryFS HeadSeq AckedData AckedData BytesInFlight BytesInFlight BytesToSend BytesToSend PrrDelivered PrrDelivered PrrOut PrrOut.

Message #

TCP: Connection %1 PRR send SackIsLostSeq %2 SackInFlight %3 SackBytes %4 SackIsLost %5 SsThresh %6 RecoveryFS %7 AckedData %8 BytesInFlight %9 BytesToSend %10 PrrDelivered %11 PrrOut %12.

Fields #

NameDescription
Tcb Pointer
SackIsLostSeq UInt32
SackInFlight UInt32
SackBytes UInt32
SackIsLost UInt32
SsThresh UInt32
HeadSeq UInt32
AckedData UInt32
BytesInFlight UInt32
BytesToSend Int64
PrrDelivered UInt32
PrrOut UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Operational",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1481,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 06:30:35.523Z",
    "version": 0
  },
  "event_data": {
    "AckedData": 1440,
    "BytesInFlight": 10487,
    "BytesToSend": 2880,
    "HeadSeq": 14400,
    "PrrDelivered": 1440,
    "PrrOut": 1440,
    "SackBytes": 0,
    "SackInFlight": 0,
    "SackIsLost": 0,
    "SackIsLostSeq": 0,
    "SsThresh": 14400,
    "Tcb": "0xFFFFC807C759AAB0"
  },
  "message": ""
}

Event ID 1482: UDP: Endpoint Endpoint segment message.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
UdpSegmentMessage

Description

UDP: Endpoint Endpoint segment message. SegmentSize = SegmentSize (0 == No Segmentation) MessageLength = MessageLength HwDatagrams = HwDatagrams HwSegments = HwSegments SwSegments = SwSegments Status = SubMssSegments.

Message #

UDP: Endpoint %1 segment message. SegmentSize = %2 (0 == No Segmentation) MessageLength = %3 HwDatagrams = %4 HwSegments = %5 SwSegments = %6 Status = %7.

Fields #

NameDescription
Endpoint Pointer
SegmentSize UInt32
MessageLength UInt64
HwDatagrams UInt32
HwSegments UInt32
SwSegments UInt32
SubMssSegments UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1482",
    "version": "1",
    "level": "5",
    "task": "1469",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.078220100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{11735e80-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "8220"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A11735E80",
    "SegmentSize": "       0",
    "MessageLength": "63",
    "HwDatagrams": "       0",
    "HwSegments": "       0",
    "SwSegments": "       0",
    "SubMssSegments": "       0",
    "Status": "0x0"
  },
  "message": ""
}

Event ID 1483: UDP: Endpoint Endpoint segmentation offload unavailable.

#
Channel
Diagnostic
Level
Verbose
Task
UdpUsoFallback

Description

UDP: Endpoint Endpoint segmentation offload unavailable. Reason = FailureReason SegmentSize = SegmentSize LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr.

Message #

UDP: Endpoint %1 segmentation offload unavailable. Reason = %2 SegmentSize = %3 LocalAddress = %5, RemoteAddress = %7.

Fields #

NameDescription
Endpoint Pointer
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
SegmentSize UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1483,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 4,
      "thread_id": 6124
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:11:27.475Z",
    "version": 0
  },
  "event_data": {
    "Endpoint": "0xFFFFC807B57BCCF0",
    "FailureReason": 6,
    "LocalSockAddr": "1700C3EF0000000000000000000000000000FFFF0000000000000000",
    "LocalSockAddrLength": 28,
    "RemoteSockAddr": "170001BB0000000000000000000000000000FFFF0A020A1F00000000",
    "RemoteSockAddrLength": 28,
    "SegmentSize": 1220
  },
  "message": ""
}

Event ID 1484: TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider.

#
Channel
Diagnostic
Task
TcpipFramingInterfaceStatus

Description

TCPIP: Framing layer interface IfIndex (AddressFamily = AddressFamily) failed to bind to its provider. Code = FailureCode. Status = Status.

Message #

TCPIP: Framing layer interface %1 (AddressFamily = %2) failed to bind to its provider. Code = %3. Status = %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
FailureCode UInt32NTSTATUS reference
Status UInt32NTSTATUS reference

Event ID 1485: TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed.

#
Channel
Diagnostic
Task
TcpipFramingOidFailure

Description

TCPIP: OID request from framing layer interface IfIndex (AddressFamily = AddressFamily) failed. OID = OID. Status = Status.

Message #

TCPIP: OID request from framing layer interface %1 (AddressFamily = %2) failed. OID = %3. Status = %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
OID UInt32
Status UInt32NTSTATUS reference

Event ID 1486: TCPIP received a status indication on interface IfIndex.

#
Channel
Diagnostic
Task
TcpipStatusIndication

Description

TCPIP received a status indication on interface IfIndex. AddressFamily = AddressFamily. NdisStatus = NdisStatus.

Message #

TCPIP received a status indication on interface %1. AddressFamily = %2. NdisStatus = %3.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
NdisStatus UInt32

Event ID 1487: IP: Failed to set socket option.

#
Channel
Diagnostic
Level
Error
Task
IpSessionFailure

Description

IP: Failed to set socket option. Level = SocketOptionLevel. Option = SocketOptionValue. Status = Status.

Message #

IP: Failed to set socket option. Level = %1. Option = %2. Status = %3.

Fields #

NameDescription
SocketOptionLevel UInt32
SocketOptionValue UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1487",
    "version": "0",
    "level": "2",
    "task": "1474",
    "opcode": "0",
    "keywords": 9223372036854775952,
    "time_created": "2026-03-16T00:23:11.242873300+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "228",
      "thread_id": "2612"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "SocketOptionLevel": "      41",
    "SocketOptionValue": "       9",
    "Status": "0xC0000225"
  },
  "message": ""
}

Event ID 1488: IP: Failed to set socket IOCTL.

#
Channel
Diagnostic
Task
IpSessionFailure

Description

IP: Failed to set socket IOCTL. IOCTL = SocketIoctl. Status = Status.

Message #

IP: Failed to set socket IOCTL. IOCTL = %1. Status = %2.

Fields #

NameDescription
SocketIoctl UInt32
Status UInt32NTSTATUS reference

Event ID 1489: Failed to process multicast RequestType request.

#
Channel
Diagnostic
Task
IpSessionMulticastOperation

Description

Failed to process multicast RequestType request. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress. Reason = FailureReason. Status = Status.

Message #

Failed to process multicast %1 request. Address = %2 %6. Source Address = %3 %7. Reason = %8. Status = %9.

Fields #

NameDescription
RequestType UInt32
IPv4Address UInt32
IPv4SourceAddress UInt32
IpAddrLength UInt32
IpSourceAddrLength UInt32
IPv6Address Binary
IPv6SourceAddress Binary
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference

Event ID 1490: Processed multicast RequestType request successfully.

#
Channel
Diagnostic
Task
IpSessionMulticastOperation

Description

Processed multicast RequestType request successfully. Address = IPv4Address IPv6Address. Source Address = IPv4SourceAddress IPv6SourceAddress.

Message #

Processed multicast %1 request successfully. Address = %2 %6. Source Address = %3 %7.

Fields #

NameDescription
RequestType UInt32
IPv4Address UInt32
IPv4SourceAddress UInt32
IpAddrLength UInt32
IpSourceAddrLength UInt32
IPv6Address Binary
IPv6SourceAddress Binary

Event ID 1491: MessageType.

#
Channel
Diagnostic
Task
IpMulticast

Description

MessageType. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data.

Message #

%1. Interface = %2. Address = %3 %5. Data = %6.

Fields #

NameDescription
MessageType UInt32
IfIndex UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary
Data UInt32

Event ID 1492: MessageType.

#
Channel
Diagnostic
Task
IpMulticast

Description

MessageType. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.

Message #

%1. Interface = %2. Address = %3 %5. Data = %6. Status = %7.

Fields #

NameDescription
MessageType UInt32
IfIndex UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary
Data UInt32
Status UInt32NTSTATUS reference

Event ID 1493: Invalid ECN codepoints in reassembly.

#
Channel
Diagnostic
Task
IpReassembly

Description

Invalid ECN codepoints in reassembly. Ce = Ce. Ect0 = Ect0. Ect1 = Ect1. NotEct = NotEct.

Message #

Invalid ECN codepoints in reassembly. Ce = %1. Ect0 = %2. Ect1 = %3. NotEct = %4.

Fields #

NameDescription
Ce UInt32
Ect0 UInt32
Ect1 UInt32
NotEct UInt32

Event ID 1494: Reassembly failure: packets do not add up correctly.

#
Channel
Diagnostic
Task
IpReassembly

Description

Reassembly failure: packets do not add up correctly. Interface = InterfaceIndex. Address family = AddressFamily.

Message #

Reassembly failure: packets do not add up correctly.  Interface = %1. Address family = %2.

Fields #

NameDescription
InterfaceIndex UInt32
AddressFamily UInt32

Event ID 1495: Reassembly failure: failed to restore IPSec packet history.

#
Channel
Diagnostic
Task
IpReassembly

Description

Reassembly failure: failed to restore IPSec packet history. Interface = IfIndex. Address family = AddressFamily. Status = Status.

Message #

Reassembly failure: failed to restore IPSec packet history.  Interface = %1. Address family = %2. Status = %3.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
Status UInt32NTSTATUS reference

Event ID 1496: Could not transfer FragmentContextDirection.

#
Channel
Diagnostic
Task
IpReassembly

Description

Could not transfer FragmentContextDirection. Interface = IfIndex. Address family = AddressFamily.

Message #

Could not transfer %1.  Interface = %2. Address family = %3.

Fields #

NameDescription
FragmentContextDirection UInt32
IfIndex UInt32
AddressFamily UInt32

Event ID 1497: Attempting to GroupChangeType the multicast group at FL.

#
Channel
Diagnostic
Task
IpMulticast

Description

Attempting to GroupChangeType the multicast group at FL. Interface = IfIndex. Address = IPv4Address IPv6Address. Data = Data. Status = Status.

Message #

Attempting to %1 the multicast group at FL.  Interface = %2. Address = %3 %5. Data = %6. Status = %7.

Fields #

NameDescription
GroupChangeType UInt32
IfIndex UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary
Data UInt32
Status UInt32NTSTATUS reference

Event ID 1498: Failed to update address list at FL.

#
Channel
Diagnostic
Task
IpFlUpdateAddressList

Description

Failed to update address list at FL. Interface = IfIndex. Address Family = AddressFamily. Status = Status.

Message #

Failed to update address list at FL. Interface = %1. Address Family = %2. Status = %3.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
Status UInt32NTSTATUS reference

Event ID 1499: Too many DAD failures, so will not create temporary address.

#
Channel
Diagnostic
Task
IpTemporaryAddressCreation

Description

Too many DAD failures, so will not create temporary address. Interface = IfIndex. Address = IPv4Address IPv6Address.

Message #

Too many DAD failures, so will not create temporary address. Interface = %1. Address = %2 %4.

Fields #

NameDescription
IfIndex UInt32
IPv4Address UInt32
IpAddrLength UInt32
IPv6Address Binary

Event ID 1500: Failed to address interface; deleting it.

#
Channel
Diagnostic
Task
IpSubInterfaceCreation

Description

Failed to address interface; deleting it. Interface = IfIndex. Status = Status.

Message #

Failed to address interface; deleting it. Interface = %1. Status = %2.

Fields #

NameDescription
IfIndex UInt32
Status UInt32NTSTATUS reference

Event ID 1501: Failed to reach default gateway after reconnect; cleaning settings.

#
Channel
Diagnostic
Task
TcpipMediaReconnect

Description

Failed to reach default gateway after reconnect; cleaning settings. Interface = IfIndex.

Message #

Failed to reach default gateway after reconnect; cleaning settings.  Interface = %1.

Fields #

NameDescription
IfIndex UInt32

Event ID 1502: Failed to sync interface with registry.

#
Channel
Diagnostic
Task
TcpipRegSyncInterface

Description

Failed to sync interface with registry. Interface = IfIndex. Field = Field. Status = Status.

Message #

Failed to sync interface with registry.  Interface = %1. Field = %2. Status = %3.

Fields #

NameDescription
IfIndex UInt32
Field UnicodeString
Status UInt32NTSTATUS reference

Event ID 1503: Failed to Release an active reference on the interface.

#
Channel
Diagnostic
Task
TcpipActiveRefFailure

Description

Failed to Release an active reference on the interface. Interface = IfIndex. Reference Reason = Subtask. Status = Status.

Message #

Failed to %1 an active reference on the interface.  Interface = %2. Reference Reason = %3. Status = %4.

Fields #

NameDescription
Release UInt32
IfIndex UInt32
Subtask UInt32
Status UInt32NTSTATUS reference

Event ID 1504: Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop.

#
Channel
Diagnostic
Task
TcpipIpRedirectPath

Description

Redirect path hijack for destination IPv4DestinationAddress IPv4NextHop from IPv6DestinationAddress IPv6NextHop. Interface = IfIndex.

Message #

Redirect path hijack for destination %2 %3 from %5 %6. Interface = %1.

Fields #

NameDescription
IfIndex UInt32
IPv4DestinationAddress UInt32
IPv4NextHop UInt32
IpAddrLength UInt32
IPv6DestinationAddress Binary
IPv6NextHop Binary

Event ID 1505: Redirect path rate limit for IPv6 source address IPv6Address.

#
Channel
Diagnostic
Task
TcpipIpRedirectPath

Description

Redirect path rate limit for IPv6 source address IPv6Address. Interface = IfIndex.

Message #

Redirect path rate limit for IPv6 source address %3. Interface = %1.

Fields #

NameDescription
IfIndex UInt32
IpAddrLength UInt32
IPv6Address Binary

Event ID 1506: Dropped AddressFamily fragment.

#
Channel
Diagnostic
Task
IpReassembly

Description

Dropped AddressFamily fragment. Interface = IfIndex. Reason = Release.

Message #

Dropped %2 fragment. Interface = %3. Reason = %1.

Fields #

NameDescription
Release UInt32
AddressFamily UInt32
IfIndex UInt32

Event ID 1507: Reassembly timeout.

#
Channel
Diagnostic
Task
IpReassembly

Description

Reassembly timeout. Interface = IfIndex. Id = ReassemblyId. Source Address = IPv4SourceAddress IPv6SourceAddress. Destination Address = IPv4DestinationAddress IPv6DestinationAddress.

Message #

Reassembly timeout. Interface = %1. Id = %2. Source Address = %3 %6.  Destination Address = %4 %7.

Fields #

NameDescription
IfIndex UInt32
ReassemblyId UInt32
IPv4SourceAddress UInt32
IPv4DestinationAddress UInt32
IpAddrLength UInt32
IPv6SourceAddress Binary
IPv6DestinationAddress Binary

Event ID 1508: Invalid IP option.

#
Channel
Diagnostic
Task
IpAncillaryData

Description

Invalid IP option. Option = SocketOption. Level = SocketLevel. Reason = Reason.

Message #

Invalid IP option. Option = %3. Level = %2. Reason = %1.

Fields #

NameDescription
Reason UInt32
SocketLevel UInt32
SocketOption UInt32

Event ID 1509: Invalid IP hop-by-hop option.

#
Channel
Diagnostic
Task
IpAncillaryData

Description

Invalid IP hop-by-hop option. Option = Option. Reason = Reason.

Message #

Invalid IP hop-by-hop option.  Option = %2. Reason = %1.

Fields #

NameDescription
Reason UInt32
Option UInt32

Event ID 1510: Invalid IP hop-by-hop option.

#
Channel
Diagnostic
Task
IpAncillaryData

Description

Invalid IP hop-by-hop option. Option = Option. Reason = Reason.

Message #

Invalid IP hop-by-hop option.  Option = %2. Reason = %1.

Fields #

NameDescription
Reason UInt32
Option UInt32

Event ID 1511: Invalid IP routing header option.

#
Channel
Diagnostic
Task
IpAncillaryData

Description

Invalid IP routing header option. Reason = Reason.

Message #

Invalid IP routing header option. Reason = %1.

Fields #

NameDescription
Reason UInt32

Event ID 1512: Invalid IP routing header option.

#
Channel
Diagnostic
Task
IpAncillaryData

Description

Invalid IP routing header option. Reason = Reason.

Message #

Invalid IP routing header option. Reason = %1.

Fields #

NameDescription
Reason UInt32

Event ID 1513: This option cannot be specified by the user

#
Channel
Diagnostic
Task
IpAncillaryData

Fields #

NameDescription
Reason UInt32

Event ID 1514: TCP: interface IfIndex: received potential RSC status indication.

#
Channel
Diagnostic
Task
TcpInterfaceRscStateChange

Description

TCP: interface IfIndex: received potential RSC status indication. Current IPv4 State = TcpRscEnabledIpv4, Offload IPv4 State = OffloadRscEnabledIpv4, Current IPv6 State = TcpRscEnabledIpv6, Offload IPv6 State = OffloadRscEnabledIpv6.

Message #

TCP: interface %1: received potential RSC status indication. Current IPv4 State = %2, Offload IPv4 State = %3, Current IPv6 State = %4, Offload IPv6 State = %5.

Fields #

NameDescription
IfIndex UInt32
TcpRscEnabledIpv4 UInt32
OffloadRscEnabledIpv4 UInt32
TcpRscEnabledIpv6 UInt32
OffloadRscEnabledIpv6 UInt32

Event ID 1515: UDP: endpoint Endpoint: URO SCU received.

#
Channel
Diagnostic
Task
UdpUroNblOobInfo

Description

UDP: endpoint Endpoint: URO SCU received. SegCount = SegCount, SegSize = SegSize, DataLength = DataLength.

Message #

UDP: endpoint %1: URO SCU received. SegCount = %2, SegSize = %3, DataLength = %4.

Fields #

NameDescription
Endpoint Pointer
SegCount UInt16
SegSize UInt16
DataLength UInt32

Event ID 1516: TCP software RSC global disabled mask = TcpRscDisabledMask, UDP software URO global disabled mask = UdpUroDisabledMask.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
SoftwareReceiveOffloadGlobalState

Message #

TCP software RSC global disabled mask = %1, UDP software URO global disabled mask = %2.

Fields #

NameDescription
TcpRscDisabledMask Int32
UdpUroDisabledMask Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1516",
    "version": "0",
    "level": "4",
    "task": "1486",
    "opcode": "0",
    "keywords": 9223372586610589824,
    "time_created": "2026-03-16T00:21:34.295804400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "TcpRscDisabledMask": "0",
    "UdpUroDisabledMask": "48"
  },
  "message": ""
}

Event ID 1517: UDP: Global parameters updated for Address Family AddressFamily: DisableUro = DisableUro.

#
Channel
Diagnostic
Task
UdpGlobalParameters

Message #

UDP: Global parameters updated for Address Family %1: DisableUro = %2.

Fields #

NameDescription
AddressFamily UInt32
DisableUro UInt8
DisableUso UInt8

Event ID 1518: IP: IPSNPI client rundown.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
InterfaceRundown
Opcode
win:Info

Description

IP: IPSNPI client rundown. AddressFamily Interface = IfIndex, Compartment = CompartmentId, Client = ClientName.

Message #

IP: IPSNPI client rundown. %3 Interface = %1, Compartment = %2, Client = %4.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
AddressFamily UInt32
ClientName UnicodeString

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1518,
    "version": 0,
    "level": 4,
    "task": 1202,
    "opcode": 0,
    "keywords": "0x0000008000000090",
    "time_created": "2026-06-02T06:03:32.470+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
    },
    "execution": {
      "process_id": 11500,
      "thread_id": 16068
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressFamily": 2,
    "ClientName": "SlbNat",
    "CompartmentId": 1,
    "IfIndex": 1
  },
  "message": "InterfaceRundown"
}

Event ID 1519: TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at St...

#
Channel
Diagnostic
Task
TcpGlobalPortReservation

Description

TCPIP: Process with PID=ProcessId, ProcessSeqNum=ProcessSequenceNumber acquired port tracker reservation of type ReservationType, Protocol IPTransportProtocol for NumberOfPorts ports starting at StartPort with status = Status.

Message #

TCPIP: Process with PID=%1, ProcessSeqNum=%7 acquired port tracker reservation of type %3, Protocol %4 for %6 ports starting at %5 with status = %2.

Fields #

NameDescription
ProcessId UInt32
Status UInt32NTSTATUS reference
ReservationType UInt32
IPTransportProtocol UInt32
StartPort UInt16
NumberOfPorts UInt16
ProcessSequenceNumber UInt64

Event ID 1520: Illegal tunnel.

#
Channel
Diagnostic
Task
TcpipFramingTunnels

Description

Illegal tunnel. Interface: IfIndex, Tunnel type: TunnelType. Reason: Reason.

Message #

Illegal tunnel. Interface: %1, Tunnel type: %2. Reason: %3.

Fields #

NameDescription
IfIndex UInt32
TunnelType UInt32
Reason UInt32

Event ID 1521: Framing: Interface change in progress.

#
Channel
Diagnostic
Task
TcpipFramingInterfaceStatus

Description

Framing: Interface change in progress. Interface: IfIndex. Address Family: AddressFamily. Current progress: CurrentProgress. Status: NtStatus.

Message #

Framing: Interface change in progress. Interface: %1. Address Family: %2. Current progress: %3. Status: %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
CurrentProgress UInt32
NtStatus UInt32

Event ID 1522: Framing: Isolation is not supported on this network adapter.

#
Channel
Diagnostic
Task
TcpipFramingIsolation

Description

Framing: Isolation is not supported on this network adapter. Interface: IfIndex. Address Family: AddressFamily. Reason: Reason.

Message #

Framing: Isolation is not supported on this network adapter. Interface: %1. Address Family: %2. Reason: %3.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
Reason UInt32

Event ID 1523: Framing: Failed to set pattern.

#
Channel
Diagnostic
Task
TcpipFramingPatterns

Description

Framing: Failed to set pattern. Interface: IfIndex. Address Family: AddressFamily. Pattern type: FailureType. Status: NtStatus.

Message #

Framing: Failed to set pattern. Interface: %1. Address Family: %2. Pattern type: %3. Status: %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
FailureType UInt32
NtStatus UInt32

Event ID 1524: Framing: Interface management request.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipFramingInterfaceMgmt

Description

Framing: Interface management request. Interface: IfIndex. Address Family: AddressFamily. Request code: FlicCode. Status: NtStatus.

Message #

Framing: Interface management request. Interface: %1. Address Family: %2. Request code: %3. Status: %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
FlicCode UInt32
NtStatus UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1524",
    "version": "0",
    "level": "4",
    "task": "1491",
    "opcode": "0",
    "keywords": 9223372586610589712,
    "time_created": "2026-03-15T23:27:10.979455500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "7392",
      "thread_id": "7388"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfIndex": "       4",
    "AddressFamily": "       2",
    "FlicCode": "0x7",
    "NtStatus": "0x0"
  },
  "message": ""
}

Event ID 1525: Framing: WOL capabilities update in progress.

#
Channel
Diagnostic
Task
TcpipFramingPatterns

Description

Framing: WOL capabilities update in progress. Interface: IfIndex. Address Family: AddressFamily. Current progress: CurrentProgress. Status: NtStatus.

Message #

Framing: WOL capabilities update in progress. Interface: %1. Address Family: %2. Current progress: %3. Status: %4.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
CurrentProgress UInt32
NtStatus UInt32

Event ID 1526: Framing: A PNP event has been indicated.

#
Channel
Diagnostic
Task
TcpipFramingPnp

Description

Framing: A PNP event has been indicated. Interface: IfIndex. Address Family: AddressFamily. Compartment: Compartment. Event: Event. Data: Data.

Message #

Framing: A PNP event has been indicated. Interface: %1. Address Family: %2. Compartment: %3. Event: %4. Data: %5.

Fields #

NameDescription
IfIndex UInt32
AddressFamily UInt32
Compartment UInt32
Event UInt32
Data UInt32

Event ID 1527: Framing: interface rundown: Interface = IfIndex, Luid = IfLuid, Address family = AddressFamily, Compartment = Compartment, Isolation mode = IsolationMode, Isolation ID = IsolalationId, DL address =...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
InterfaceRundown

Description

Framing: interface rundown: Interface = IfIndex, Luid = IfLuid, Address family = AddressFamily, Compartment = Compartment, Isolation mode = IsolationMode, Isolation ID = IsolalationId, DL address = DLAddress, Interface type = InterfaceType, Physical medium type = PhysicalMediumType, SW RSC/URO applicable = SwRscUroApplicable, SW RSC enabled = SwRscEnabled, Alias = IfAlias, SW URO enabled = SwUroEnabled.

Message #

Framing: interface rundown: Interface = %1, Luid = %2, Address family = %3, Compartment = %4, Isolation mode = %5, Isolation ID = %6, DL address = %8, Interface type = %9, Physical medium type = %10, SW RSC/URO applicable = %11, SW RSC enabled = %12, Alias = %13.

Fields #

NameDescription
IfIndex UInt32
IfLuid UInt64
AddressFamily UInt32
Compartment UInt32
IsolationMode UInt32
IsolalationId UInt32
DlAddrLength UInt32
DLAddress Binary
InterfaceType UInt32
PhysicalMediumType UInt32
SwRscUroApplicable UInt32
SwRscEnabled UInt32
IfAlias UnicodeString
SwUroEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1527",
    "version": "0",
    "level": "4",
    "task": "1202",
    "opcode": "0",
    "keywords": 9223372586610589712,
    "time_created": "2026-03-16T00:21:34.295249100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfIndex": "       6",
    "IfLuid": "0x6008001000000",
    "AddressFamily": "       2",
    "Compartment": "       1",
    "IsolationMode": "       0",
    "IsolalationId": "       0",
    "DlAddrLength": "       6",
    "DLAddress": "0xBC24119A4DC2",
    "InterfaceType": "       6",
    "PhysicalMediumType": "       0",
    "SwRscUroApplicable": "       1",
    "SwRscEnabled": "       0",
    "IfAlias": "Ethernet"
  },
  "message": ""
}

Event ID 1528: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) sending NumMessages messages and a total of NumBytes bytes.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Proto = %2, LocalAddress = %6, RemoteAddress = %8) sending %3 messages and a total of %4 bytes.

Fields #

NameDescription
Endpoint Pointer
IPTransportProtocol UInt32
NumMessages UInt32
NumBytes UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary

Event ID 1529: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr, RemoteAddress = RemoteSockAddr) delivering NumBytes bytes.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Proto = %2, LocalAddress = %6, RemoteAddress = %8) delivering %4 bytes.

Fields #

NameDescription
Endpoint Pointer
IPTransportProtocol UInt32
NumMessages UInt32
NumBytes UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddrLength UInt32
RemoteSockAddr Binary

Event ID 1530: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = EndpointAddress, RemoteAddress = SendAddress) send failed with reason = Reason status = Status.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Proto = %2, LocalAddress = %4, RemoteAddress = %6) send failed with reason = %7 status = %8.

Fields #

NameDescription
Endpoint Pointer
IPTransportProtocol UInt32
EndpointAddressLength UInt32
EndpointAddress Binary
SendAddressLength UInt32
SendAddress Binary
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1531: RAW: endpoint Endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) created.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Family = %2, Proto = %3, Compartment = %4, PID = %5, ProcessSeqNum = %6) created.

Fields #

NameDescription
Endpoint Pointer
AddressFamily UInt32
IPTransportProtocol UInt32
Compartment UInt32
ProcessId UInt32
ProcessSequenceNumber UInt64
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1532: RAW: endpoint (Family = AddressFamily, Proto = IPTransportProtocol, Compartment = Compartment, PID = ProcessId, ProcessSeqNum = ProcessSequenceNumber) create failed with reason Reason status Status.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint (Family = %2, Proto = %3, Compartment = %4, PID = %5, ProcessSeqNum = %6) create failed with reason %7 status %8.

Fields #

NameDescription
Endpoint Pointer
AddressFamily UInt32
IPTransportProtocol UInt32
Compartment UInt32
ProcessId UInt32
ProcessSequenceNumber UInt64
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1533: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bound.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Proto = %2, LocalAddress = %4) bound.

Fields #

NameDescription
Endpoint Pointer
IPTransportProtocol UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1534: RAW: endpoint Endpoint (Proto = IPTransportProtocol, LocalAddress = LocalSockAddr) bind failed with reason Reason status Status.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 (Proto = %2, LocalAddress = %4) bind failed with reason %5 status %6.

Fields #

NameDescription
Endpoint Pointer
IPTransportProtocol UInt32
LocalSockAddrLength UInt32
LocalSockAddr Binary
Reason UInt32
Status UInt32NTSTATUS reference

Event ID 1535: RAW: endpoint Endpoint closed.

#
Channel
Diagnostic
Task
RawEndpoint

Message #

RAW: endpoint %1 closed.

Fields #

NameDescription
Endpoint Pointer

Event ID 1536: TCPIP: Error processing router advertisement on interface index IfIndex - Preferred lifetime of PreferredLifetime should not be greater than the valid lifetime of ValidLifetime.

#
Channel
Diagnostic
Task
IcmpRouterAdvertisement

Message #

TCPIP: Error processing router advertisement on interface index %1 - Preferred lifetime of %2 should not be greater than the valid lifetime of %3.

Fields #

NameDescription
IfIndex UInt32
PreferredLifetime UInt32
ValidLifetime UInt32

Event ID 1537: TCPIP: Error processing router advertisement on interface index IfIndex - Prefix length of PrefixLength and identifier of IdentifierLength must add up to the size of an IPv6 ad...

#
Channel
Diagnostic
Task
IcmpRouterAdvertisement

Description

TCPIP: Error processing router advertisement on interface index IfIndex - Prefix length of PrefixLength and identifier of IdentifierLength must add up to the size of an IPv6 address (128 bits).

Message #

TCPIP: Error processing router advertisement on interface index %1 - Prefix length of %2 and identifier of %3 must add up to the size of an IPv6 address (128 bits).

Fields #

NameDescription
IfIndex UInt32
PrefixLength UInt32
IdentifierLength UInt32

Event ID 1538: TCPIP: An ARP request was dropped on interface IfIndex.

#
Channel
Diagnostic
Task
ArpPacketDrops

Description

TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.

Message #

TCPIP: An ARP request was dropped on interface %1. Physical address = %3, IP source address = %4, IP target address = %5, Reason = %6.

Fields #

NameDescription
IfIndex UInt32
DlAddrLength UInt32
DlSourceAddress Binary
IpSourceAddress UInt32
IpTargetAddress UInt32
DropReason UInt32

Event ID 1539: TCPIP: An ARP reply was dropped on interface IfIndex.

#
Channel
Diagnostic
Task
ArpPacketDrops

Description

TCPIP: An ARP reply was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, Directed to this interface = Directed, Reason = DropReason.

Message #

TCPIP: An ARP reply was dropped on interface %1. Physical address = %3, IP source address = %4, Directed to this interface = %5, Reason = %6.

Fields #

NameDescription
IfIndex UInt32
DlAddrLength UInt32
DlSourceAddress Binary
IpSourceAddress UInt32
Directed UInt32
DropReason UInt32

Event ID 1540: TCPIP: No handler found for an AddressFamily packet with upper layer protocol IPTransportProtocol.

#
Channel
Diagnostic
Task
UpperLayerProtocolFailure

Message #

TCPIP: No handler found for an %1 packet with upper layer protocol %2

Fields #

NameDescription
AddressFamily UInt32
IPTransportProtocol UInt32

Event ID 1541: TCPIP: Handler for upper layer protocol IPTransportProtocol for an AddressFamily packet returned with error Status.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
UpperLayerProtocolFailure

Message #

TCPIP: Handler for upper layer protocol %2 for an %1 packet returned with error %3

Fields #

NameDescription
AddressFamily UInt32
IPTransportProtocol UInt32
Status UInt32NTSTATUS reference

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1541",
    "version": "0",
    "level": "5",
    "task": "1496",
    "opcode": "0",
    "keywords": 9223372045444710400,
    "time_created": "2026-03-15T23:27:12.462571400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressFamily": "       2",
    "IPTransportProtocol": "       6",
    "Status": "0x40000026"
  },
  "message": ""
}

Event ID 1542: IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = I...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
NeighborRundown

Description

IP: neighbor rundown: Interface = IfIndex, Compartment = CompartmentId, IpAddress = IPAddress, DlAddress = DLAddress, State = Neighbor State, LastReachable = LastReachableInMs ms, IsUnreachable = IsUnreachable, Flags = Flags.

Message #

IP: neighbor rundown: Interface = %1, Compartment = %2, IpAddress = %4, DlAddress = %6, State = %7, LastReachable = %8 ms, IsUnreachable = %9, Flags = %10.

Fields #

NameDescription
IfIndex UInt32
CompartmentId UInt32
IpAddrLength UInt32
IPAddress Binary
DlAddrLength UInt32
DLAddress Binary
NeighborState UInt32
LastReachableInMs UInt32
IsUnreachable UInt32
Flags UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1542",
    "version": "0",
    "level": "4",
    "task": "1497",
    "opcode": "0",
    "keywords": 9223372586610589728,
    "time_created": "2026-03-16T00:21:34.295470700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}"
    },
    "execution": {
      "process_id": "9132",
      "thread_id": "4236"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "IfIndex": "       1",
    "CompartmentId": "       1",
    "IpAddrLength": "      16",
    "IPAddress": "224.0.0.22",
    "DlAddrLength": "       0",
    "DLAddress": "",
    "Neighbor State": "       6",
    "LastReachableInMs": "57839000",
    "IsUnreachable": "       0",
    "Flags": "0xAC"
  },
  "message": ""
}

Example keys not documented in the fields table: Neighbor State

Event ID 1543: TCPIP: An ARP request was dropped on interface IfIndex.

#
Channel
Diagnostic
Task
ArpPacketDrops
Opcode
Info

Description

TCPIP: An ARP request was dropped on interface IfIndex. Physical address = DlSourceAddress, IP source address = IpSourceAddress, IP target address = IpTargetAddress, Reason = DropReason.

Message #

TCPIP: An ARP request was dropped on interface %1. Physical address = %3, IP source address = %4, IP target address = %5, Reason = %6.

Fields #

NameDescription
IfIndex UInt32
DlAddrLength UInt32
DlSourceAddress Binary
IpSourceAddress UInt32
IpTargetAddress UInt32
DropReason UInt32

Event ID 1544: Endpoint Endpoint socket option set with level Level, name Name, value Value.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipSetSockOpt

Message #

Endpoint %1 socket option set with level %2, name %3, value %5.

Fields #

NameDescription
Endpoint Pointer
Level UInt32
Name UInt32
Length UInt32
Value Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1544",
    "version": "0",
    "level": "4",
    "task": "1498",
    "opcode": "0",
    "keywords": 9223372036854775936,
    "time_created": "2026-03-16T00:21:40.064415100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15f74b50-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "7552"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Endpoint": "0xFFFF980A15F74B50",
    "Level": "      41",
    "Name": "      27",
    "Length": "       4",
    "Value": "0x00000000"
  },
  "message": ""
}

Event ID 1545: TCP: connection = Tcb RACK timeout expired.

#
Channel
Diagnostic
Task
TcpRackTimeout

Description

TCP: connection = Tcb RACK timeout expired. SndUna = SndUna, SndMax = SndMax, SackedBytes = SackedBytes, LossDetected = LossDetected, InRecovery = InRecovery.

Message #

TCP: connection = %1 RACK timeout expired. SndUna = %2, SndMax = %3, SackedBytes = %4, LossDetected = %5, InRecovery = %6.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
SackedBytes UInt32
LossDetected UInt32
InRecovery UInt32

Event ID 1546: TCP: connection = Tcb armed RACK timer.

#
Channel
Diagnostic
Level
Informational
Task
TcpArmRackTimer

Description

TCP: connection = Tcb armed RACK timer. SndUna = SndUna, SndMax = SndMax, SackedBytes = SackedBytes, LossDetected = LossDetected, InRecovery = InRecovery, DeltaTicks = DeltaTicks.

Message #

TCP: connection = %1 armed RACK timer. SndUna = %2, SndMax = %3, SackedBytes = %4, LossDetected = %5, InRecovery = %6, DeltaTicks = %7.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
SackedBytes UInt32
LossDetected UInt32
InRecovery UInt32
DeltaTicks UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1546",
    "version": "0",
    "level": "4",
    "task": "1501",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.488186800+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "SndUna": "155002622",
    "SndMax": "155007102",
    "SackedBytes": "    1440",
    "LossDetected": "       0",
    "InRecovery": "       0",
    "DeltaTicks": "      18"
  },
  "message": ""
}

Event ID 1547: TCP: connection = Tcb received a SACK block.

#
Channel
Diagnostic
Level
Verbose
Task
TcpReceiveSackBlock

Description

TCP: connection = Tcb received a SACK block. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE.

Message #

TCP: connection = %1 received a SACK block. SndUna = %2, SndMax = %3, Ack = %4, SLE = %5, SRE = %6.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Ack UInt32
SLE UInt32
SRE UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1547",
    "version": "0",
    "level": "5",
    "task": "1502",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.488113200+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "SndUna": "155002622",
    "SndMax": "155007102",
    "Ack": "155002622",
    "SLE": "155004100",
    "SRE": "155005540"
  },
  "message": ""
}

Event ID 1548: TCP: connection = Tcb received a SACK.

#
Channel
Diagnostic
Level
Informational
Task
TcpReceiveSack

Description

TCP: connection = received a SACK. SndUna = , SndMax = , Ack = , SackedBytes = , LossDetected = , InRecovery = , NumSackBlocks = , DSackCount = , NewSackInfo = , RecoveryMax = .

Message #

TCP: connection = %1 received a SACK. SndUna = %2, SndMax = %3, Ack = %4, SackedBytes = %5, LossDetected = %6, InRecovery = %7, NumSackBlocks = %8, DSackCount = %9, NewSackInfo = %10, RecoveryMax = %11.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Ack UInt32
SackedBytes UInt32
LossDetected UInt32
InRecovery UInt32
NumSackBlocks UInt32
DSackCount UInt32
NewSackInfo UInt32
RecoveryMax UInt32
NewSackedBytes UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1548",
    "version": "0",
    "level": "4",
    "task": "1503",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:27:12.440654000+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{fd182260-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFD182260",
    "SndUna": "4068749001",
    "SndMax": "4068767248",
    "Ack": "4068749001",
    "SackedBytes": "    1460",
    "LossDetected": "       1",
    "InRecovery": "       0",
    "NumSackBlocks": "       1",
    "DSackCount": "       0",
    "NewSackInfo": "       1",
    "RecoveryMax": "4068565828"
  },
  "message": ""
}

Event ID 1549: TCP: connection = Tcb enabled send tracker.

#
Channel
Diagnostic
Level
Informational
Task
TcpSendTrackerEnabled

Message #

TCP: connection = %1 enabled send tracker.

Fields #

NameDescription
Tcb Pointer

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1549",
    "version": "0",
    "level": "4",
    "task": "1504",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.119290700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6ae0-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "3688",
      "thread_id": "12888"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0"
  },
  "message": ""
}

Event ID 1550: TCP: connection = Tcb send tracker acked a transmit.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendTrackerAck

Description

TCP: connection = Tcb send tracker acked a transmit. AckNo = AckNo, Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.

Message #

TCP: connection = %1 send tracker acked a transmit. AckNo = %2, Start = %3, End = %4, Timestamp = %5, EverTransmitted = %6, SackedBytes = %7, BytesInFlight = %8.

Fields #

NameDescription
Tcb Pointer
AckNo UInt32
Start UInt32
End UInt32
Timestamps UInt32
EverRetransmitted UInt32
SackedBytes UInt32
BytesInFlight UInt32
State UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1550",
    "version": "0",
    "level": "5",
    "task": "1505",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:26:13.268229900+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4200",
      "thread_id": "7084"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFF7AF7E0",
    "AckNo": "644687492",
    "Start": "644684595",
    "End": "644687492",
    "Timestamps": "2483305555",
    "EverRetransmitted": "       0",
    "SackedBytes": "       0",
    "BytesInFlight": "       0"
  },
  "message": ""
}

Event ID 1551: TCP: connection = Tcb send tracker enqueued a transmit.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendTrackerSend

Description

TCP: connection = Tcb send tracker enqueued a transmit. Start = Start, End = End, Timestamp = Timestamps, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.

Message #

TCP: connection = %1 send tracker enqueued a transmit. Start = %2, End = %3, Timestamp = %4, SackedBytes = %5, BytesInFlight = %6.

Fields #

NameDescription
Tcb Pointer
Start UInt32
End UInt32
Timestamps UInt32
SackedBytes UInt32
BytesInFlight UInt32
NoNewTransmitCreated UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1551",
    "version": "0",
    "level": "5",
    "task": "1506",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-15T23:26:13.267679100+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{ff7afb40-d78f-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "4200",
      "thread_id": "7948"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFFD78FFF7AF7E0",
    "Start": "644684595",
    "End": "644687492",
    "Timestamps": "2483305555",
    "SackedBytes": "       0",
    "BytesInFlight": "    2897"
  },
  "message": ""
}

Event ID 1552: TCP: connection = Tcb send tracker marked a transmit as lost.

#
Channel
Diagnostic
Level
Verbose
Task
TcpSendTrackerDetectLoss

Description

TCP: connection = Tcb send tracker marked a transmit as lost. Start = Start, End = End, Timestamp = Timestamps, EverTransmitted = EverRetransmitted, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.

Message #

TCP: connection = %1 send tracker marked a transmit as lost. Start = %2, End = %3, Timestamp = %4, EverTransmitted = %5, InFlightCount = %6, SackedBytes = %7, BytesInFlight = %8.

Fields #

NameDescription
Tcb Pointer
Start UInt32
End UInt32
Timestamps UInt32
EverRetransmitted UInt32
InFlightCount UInt32
SackedBytes UInt32
BytesInFlight UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1552",
    "version": "0",
    "level": "5",
    "task": "1507",
    "opcode": "0",
    "keywords": 9223372041149743104,
    "time_created": "2026-03-16T00:21:40.490313500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{15ce6eb8-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF980A15CE6AE0",
    "Start": "155004062",
    "End": "155004100",
    "Timestamps": "1924745937",
    "EverRetransmitted": "       0",
    "InFlightCount": "       0",
    "SackedBytes": "    3002",
    "BytesInFlight": "    2804"
  },
  "message": ""
}

Event ID 1553: TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAdd...

#
Channel
Diagnostic
Level
Verbose
Task
TcpAcceptRedirect

Description

TCP: accept redirection: original listener = OriginalListener, redirected listener = RedirectedListener, succeeded = Succeeded, redirected = Redirected, codepath = CodePath, local address = SockAddrLength, remote address = LocalSockAddr, redirected address = RemoteSockAddr.

Message #

TCP: accept redirection: original listener = %1, redirected listener = %2, succeeded = %3, redirected = %4, codepath = %5, local address = %6, remote address = %7, redirected address = %8

Fields #

NameDescription
OriginalListener Pointer
RedirectedListener Pointer
Succeeded UInt32
Redirected UInt32
CodePath UInt32
SockAddrLength UInt32
LocalSockAddr Binary
RemoteSockAddr Binary
RedirectSockAddr Binary

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": "1553",
    "version": "0",
    "level": "5",
    "task": "1508",
    "opcode": "0",
    "keywords": 9223372045444710528,
    "time_created": "2026-03-16T00:21:38.718862500+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{0ef4b580-980a-ffff-0000-000000000000}"
    },
    "execution": {
      "process_id": "0",
      "thread_id": "0"
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "OriginalListener": "0xFFFF980A0EF4B580",
    "RedirectedListener": "0x0",
    "Succeeded": "       1",
    "Redirected": "       0",
    "CodePath": "       2",
    "SockAddrLength": "      16",
    "LocalSockAddr": "10.2.10.21:5985",
    "RemoteSockAddr": "10.2.10.11:51201",
    "RedirectSockAddr": "0x00000000000000000000000000000000"
  },
  "message": ""
}

Event ID 1554: TCP: connection = Tcb dropped a SACK block due to SACK limit reached.

#
Channel
Diagnostic
Task
TcpSendTrackerSackLimitReached

Description

TCP: connection = Tcb dropped a SACK block due to SACK limit reached. SndUna = SndUna, SndMax = SndMax, Ack = Ack, SLE = SLE, SRE = SRE, NumSackedTransmits = NumSackTransmits, limit = Limit.

Message #

TCP: connection = %1 dropped a SACK block due to SACK limit reached. SndUna = %2, SndMax = %3, Ack = %4, SLE = %5, SRE = %6, NumSackedTransmits = %7, limit = %8.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
Ack UInt32
SLE UInt32
SRE UInt32
NumSackTransmits UInt32
Limit UInt32

Event ID 1555: TCP: connection Tcb terminated by NSI.

#
Channel
Diagnostic
Task
TcpConnectionTerminatedByNsi

Description

TCP: connection Tcb terminated by NSI. State = State, PID = Pid, ProcessSeqNum = ProcessStartKey, Shutdown = Shutdown.

Message #

TCP: connection %1 terminated by NSI. State = %2, PID = %3, ProcessSeqNum = %4, Shutdown = %5.

Fields #

NameDescription
Tcb Pointer
State UInt32
Pid UInt32
ProcessStartKey UInt64
Shutdown UInt32

Event ID 1556: TCP: connection = Tcb rate-based pacing timeout expired.

#
Channel
Diagnostic
Task
TcpRateBasedPacingTimeout

Description

TCP: connection = Tcb rate-based pacing timeout expired. SndUna = SndUna, SndMax = SndMax, PacingAllowance = PacingAllowance B, PacingRate = PacingRate B/ms.

Message #

TCP: connection = %1 rate-based pacing timeout expired. SndUna = %2, SndMax = %3, PacingAllowance = %4 B, PacingRate = %5 B/ms.

Fields #

NameDescription
Tcb Pointer
SndUna UInt32
SndMax UInt32
PacingAllowance UInt32
PacingRate UInt32

Event ID 1557: TCP RLedbat connection = Tcb.

#
Channel
Diagnostic
Task
TcpRLedbatState

Description

TCP RLedbat connection = . Type = , SSThresh = , Wnd = , WndWs = , DrainedBytes = , ReceiveHigh = , TsHigh = , LastRollOverTimeMs = , EndReductionTimeMs = , MinDelaySampleMs = , MinBaseDelayMs =.

Message #

TCP RLedbat connection = %1. Type = %2, SSThresh = %3, Wnd = %4, WndWs = %5, DrainedBytes = %6, ReceiveHigh = %7, TsHigh = %8, LastRollOverTimeMs = %9, EndReductionTimeMs = %10, MinDelaySampleMs = %11, MinBaseDelayMs = %12

Fields #

NameDescription
Tcb Pointer
EventType UInt32
SsThresh UInt32
Wnd UInt32
WndWs UInt32
DrainedBytes UInt32
ReceiveHigh UInt32
TsHigh UInt32
LastRollOverTimeMs UInt32
EndReductionTimeMs UInt32
MinDelaySampleMs UInt32
MinBaseDelayMs UInt32

Event ID 1558: UDP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.

#
Channel
Diagnostic
Task
UdpRebindEndpointInit

Message #

UDP: endpoint %5 rebind initiated: current address = %2, modified address = %4

Fields #

NameDescription
CurrentLocalAddressLength UInt32
CurrentLocalAddress Binary
ModifiedLocalAddressLength UInt32
ModifiedLocalAddress Binary
Endpoint Pointer
Status UInt32NTSTATUS reference
EndpointRestored Boolean

Event ID 1559: UDP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.

#
Channel
Diagnostic
Task
UdpRebindEndpointFailure

Message #

UDP: endpoint %5 rebind failed: current address = %2, modified address = %4, port-switch status = %6, endpoint-restored = %7

Fields #

NameDescription
CurrentLocalAddressLength UInt32
CurrentLocalAddress Binary
ModifiedLocalAddressLength UInt32
ModifiedLocalAddress Binary
Endpoint Pointer
Status UInt32NTSTATUS reference
EndpointRestored Boolean

Event ID 1560: TCP: endpoint Endpoint rebind initiated: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress.

#
Channel
Diagnostic
Task
TcpRebindEndpointInit

Message #

TCP: endpoint %5 rebind initiated: current address = %2, modified address = %4

Fields #

NameDescription
CurrentLocalAddressLength UInt32
CurrentLocalAddress Binary
ModifiedLocalAddressLength UInt32
ModifiedLocalAddress Binary
Endpoint Pointer
Status UInt32NTSTATUS reference
EndpointRestored Boolean

Event ID 1561: TCP: endpoint Endpoint rebind failed: current address = CurrentLocalAddress, modified address = ModifiedLocalAddress, port-switch status = Status, endpoint-restored = EndpointRestored.

#
Channel
Diagnostic
Task
TcpRebindEndpointFailure

Message #

TCP: endpoint %5 rebind failed: current address = %2, modified address = %4, port-switch status = %6, endpoint-restored = %7

Fields #

NameDescription
CurrentLocalAddressLength UInt32
CurrentLocalAddress Binary
ModifiedLocalAddressLength UInt32
ModifiedLocalAddress Binary
Endpoint Pointer
Status UInt32NTSTATUS reference
EndpointRestored Boolean

Event ID 1562: TCP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.

#
Channel
Diagnostic
Task
TcpCreateEndpointAccessFailure

Message #

TCP: endpoint (PID=%4 ProcessSeqNum=%7) create failed: access denied.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1563: UDP: endpoint (PID=ProcessId ProcessSeqNum=ProcessStartKey) create failed: access denied.

#
Channel
Diagnostic
Task
UdpCreateEndpointAccessFailure

Message #

UDP: endpoint (PID=%3 ProcessSeqNum=%6) create failed: access denied.

Fields #

NameDescription
Endpoint Pointer
Status UInt32NTSTATUS reference
ProcessId UInt32
CompartmentId UInt32
AddressFamily UInt32
ProcessStartKey UInt64

Event ID 1564: TCP: connection Tcb (local=LocalAddress remote=RemoteAddress PID=ProcessId ProcessSeqNum=ProcessStartKey) connect failed: access denied.

#
Channel
Diagnostic
Task
TcpConnectTcbFailedAccess

Message #

TCP: connection %8 (local=%2 remote=%4 PID=%6 ProcessSeqNum=%9) connect failed: access denied.

Fields #

NameDescription
LocalAddressLength UInt32
LocalAddress Binary
RemoteAddressLength UInt32
RemoteAddress Binary
Status UInt32NTSTATUS reference
ProcessId UInt32
Compartment UInt32
Tcb Pointer
ProcessStartKey UInt64

Event ID 1565: TCP: Congestion state changed for connection = Tcb from OldState = OldState to NewState = NewState.

#
Channel
Diagnostic
Level
Verbose
Task
TcpCongestionStateChange

Message #

TCP: Congestion state changed for connection = %1 from OldState = %2 to NewState = %3.

Fields #

NameDescription
Tcb Pointer
OldState UInt32
NewState UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1565,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-22 06:30:35.523Z",
    "version": 0
  },
  "event_data": {
    "NewState": 1,
    "OldState": 0,
    "Tcb": "0xFFFFC807C759AAB0"
  },
  "message": ""
}

Event ID 1566: TCP: connection = Tcb detected reordering.

#
Channel
Diagnostic
Level
Verbose
Task
TcpSendTrackerSackReorderingDetected

Description

TCP: connection = Tcb detected reordering. MaxReorderingBytes = MaxReorderingBytes, Fack = Fack, EndSeq = EndSeq.

Message #

TCP: connection = %1 detected reordering. MaxReorderingBytes = %2, Fack = %3, EndSeq = %4.

Fields #

NameDescription
Tcb Pointer
MaxReorderingBytes UInt32
Fack UInt32
EndSeq UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1566,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:11:21.735Z",
    "version": 0
  },
  "event_data": {
    "EndSeq": 1605190890,
    "Fack": 1605193156,
    "MaxReorderingBytes": 2266,
    "Tcb": "0xFFFFC807CC998010"
  },
  "message": ""
}

Event ID 1577: TCP: connection = Tcb updated reownd.

#
Channel
Diagnostic
Level
Verbose
Task
TcpSendTrackerUpdateReoWnd

Description

TCP: connection = updated reownd. Multiplier = , Persist = , Reownd = , ReorderingSeen = , DSackSeenOnLatestAck = , InLossRecovery = , DupAckCountReached = , DSackRound = , DSackRoundValid = .

Message #

TCP: connection = %1 updated reownd. Multiplier = %2, Persist = %3, Reownd = %4, ReorderingSeen = %5, DSackSeenOnLatestAck = %6, InLossRecovery = %7, DupAckCountReached = %8, DSackRound = %9, DSackRoundValid = %10.

Fields #

NameDescription
Tcb Pointer
Multiplier UInt32
Persist UInt32
Reownd UInt32
ReorderingSeen UInt32
DSackSeenOnLatestAck UInt32
InLossRecovery UInt32
DupAckCountReached UInt32
DSackRound UInt32
DSackRoundValid UInt32

Example Event #

{
  "system": {
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "10.2.10.21",
    "correlation": {},
    "event_id": 1577,
    "event_record_id": 0,
    "event_source_name": "",
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "guid": "",
    "keywords": 0,
    "level": 4,
    "opcode": 0,
    "provider": "Microsoft-Windows-TCPIP",
    "security": {
      "user_id": ""
    },
    "task": 0,
    "time_created": "2026-07-21 22:11:21.733Z",
    "version": 0
  },
  "event_data": {
    "DSackRound": 0,
    "DSackRoundValid": 0,
    "DSackSeenOnLatestAck": 0,
    "DupAckCountReached": 0,
    "InLossRecovery": 0,
    "Multiplier": 1,
    "Persist": 0,
    "ReorderingSeen": 0,
    "Reownd": 21554,
    "Tcb": "0xFFFFC807CC998010"
  },
  "message": ""
}

Event ID 1578: IP: Injecting NBL Nbl on send path.

#
Channel
Diagnostic
Task
IpInjectNbl

Description

IP: Injecting NBL Nbl on send path. Family = AddressFamily, Compartment = CompartmentId, Protocol = IPTransportProtocol.

Message #

IP: Injecting NBL %1 on send path. Family = %2, Compartment = %3, Protocol = %5

Fields #

NameDescription
Nbl Pointer
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
IPTransportProtocol UInt32

Event ID 1579: IP: Injecting NBL Nbl on raw send path.

#
Channel
Diagnostic
Task
IpInjectNbl

Description

IP: Injecting NBL Nbl on raw send path. Family = AddressFamily, Compartment = CompartmentId.

Message #

IP: Injecting NBL %1 on raw send path. Family = %2, Compartment = %3

Fields #

NameDescription
Nbl Pointer
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
IPTransportProtocol UInt32

Event ID 1580: IP: Injecting NBL Nbl on receive path.

#
Channel
Diagnostic
Task
IpInjectNbl

Description

IP: Injecting NBL Nbl on receive path. Family = AddressFamily, Compartment = CompartmentId, Interface = Interface.

Message #

IP: Injecting NBL %1 on receive path. Family = %2, Compartment = %3, Interface = %4

Fields #

NameDescription
Nbl Pointer
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
IPTransportProtocol UInt32

Event ID 1581: IP: Injecting NBL Nbl on forward path.

#
Channel
Diagnostic
Task
IpInjectNbl

Description

IP: Injecting NBL Nbl on forward path. Family = AddressFamily, Compartment = CompartmentId, Interface = Interface.

Message #

IP: Injecting NBL %1 on forward path. Family = %2, Compartment = %3, Interface = %4

Fields #

NameDescription
Nbl Pointer
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
IPTransportProtocol UInt32

Event ID 1582: IP: Indication filtered because destination interface IfIndex is not contained in IF list.

#
Channel
Diagnostic
Task
TcpipIndicationFilteredForIflist

Message #

IP: Indication filtered because destination interface %1 is not contained in IF list

Fields #

NameDescription
IfIndex UInt32

Event ID 1583: BBR2: TCB Tcb bbr_bw bbr_bw min_rtt_us min_rtt_us mode mode cycle_idx cycle_idx CWnd CWnd PacingRate PacingRate BytesSent BytesSent SRtt SRtt.

#
Channel
Diagnostic
Task
TcpBbr2

Message #

BBR2: TCB %1 bbr_bw %2 min_rtt_us %3 mode %4 cycle_idx %5 CWnd %6 PacingRate %7 BytesSent %8 SRtt %9

Fields #

NameDescription
Tcb Pointer
bbr_bw UInt32
min_rtt_us UInt32
mode UInt32
cycle_idx UInt32
CWnd UInt32
PacingRate UInt32
BytesSent UInt32
SRtt UInt32

Event ID 1584: TCP: connection = Tcb send tracker marked a transmit as rexmit.

#
Channel
Diagnostic
Level
Verbose
Task
TcpSendTrackerMarkRexmit

Description

TCP: connection = Tcb send tracker marked a transmit as rexmit. Start = Start, End = End, Timestamp = Timestamps, InFlightCount = InFlightCount, SackedBytes = SackedBytes, BytesInFlight = BytesInFlight.

Message #

TCP: connection = %1 send tracker marked a transmit as rexmit. Start = %2, End = %3, Timestamp = %4, InFlightCount = %5, SackedBytes = %6, BytesInFlight = %7.

Fields #

NameDescription
Tcb Pointer
Start UInt32
End UInt32
Timestamps UInt32
InFlightCount UInt32
SackedBytes UInt32
BytesInFlight UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1584,
    "version": 0,
    "level": 5,
    "task": 1526,
    "opcode": 0,
    "keywords": "0x8000000100000000",
    "time_created": "2026-07-19T03:41:09.448180400+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "10910A08-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 0,
      "thread_id": 0
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF800A10910630",
    "Start": "805692011",
    "End": "805692012",
    "Timestamps": "2947447236",
    "InFlightCount": "1",
    "SackedBytes": "0",
    "BytesInFlight": "1"
  },
  "message": "TCP: connection = 0xFFFF800A10910630 send tracker marked a transmit as rexmit. Start = 805692011, End = 805692012, Timestamp = 2947447236, InFlightCount = 1, SackedBytes = 0, BytesInFlight = 1."
}

Event ID 1585: TCP: connection = Tcb send tracker update RACK info.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpSendTrackerRackUpdate
Opcode
win:Info

Description

TCP: connection = Tcb send tracker update RACK info. RackXmitTimeStampValid = RackXmitTimeStampValid, RackXmitTimeStampInUs = RackXmitTimeStampInUs, RackEndSeq = RackEndSeq, RackRttInUs = RackRttInUs, NowInUs = NowInUs, TimeStampInUs = TimeStampInUs.

Message #

TCP: connection = %1 send tracker update RACK info. RackXmitTimeStampValid = %2, RackXmitTimeStampInUs = %3, RackEndSeq = %4, RackRttInUs = %5, NowInUs = %6, TimeStampInUs = %7.

Fields #

NameDescription
Tcb Pointer
RackXmitTimeStampValid UInt32
RackXmitTimeStampInUs UInt32
RackEndSeq UInt32
RackRttInUs UInt32
NowInUs UInt32
TimeStampInUs UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1585,
    "version": 0,
    "level": 5,
    "task": 1527,
    "opcode": 0,
    "keywords": "0x0000000100000000",
    "time_created": "2026-06-02T06:03:34.154+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F76423D8-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 2764,
      "thread_id": 812
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "NowInUs": 3164724227,
    "RackEndSeq": 2424967783,
    "RackRttInUs": 1236,
    "RackXmitTimeStampInUs": 3164722991,
    "RackXmitTimeStampValid": 1,
    "Tcb": "0xFFFFBD09F7642010",
    "TimeStampInUs": 3164722991
  },
  "message": "TcpSendTrackerRackUpdate"
}

Event ID 1586: IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily.

#
Channel
Diagnostic
Task
IpInterfaceChange

Description

IP: Prefix sharing now PrefixSharing on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily. Updating shared prefixes and resetting autoconfigured state, such as addresses and routes.

Message #

IP: Prefix sharing now %4 on Interface = %3, Compartment = %2, Family = %1. Updating shared prefixes and resetting autoconfigured state, such as addresses and routes.

Fields #

NameDescription
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
PrefixSharing UInt32

Event ID 1587: TCP: connection Tcb received a careful ACK.

#
Channel
Diagnostic
Level
Informational
Task
TcpCarefulAck

Description

TCP: connection Tcb received a careful ACK. ThAck = ThAck, SndUna = SndUna, SndMax = SndMax, RecoveryMax = RecoveryMax, SndWnd = SndWnd, SndWndChanged = SndWndChanged, SackUpdated = SackUpdated, State = TcpState, CongestionState = CongestionState, F-RTO = Frto.

Message #

TCP: connection %1 received a careful ACK. ThAck = %2, SndUna = %3, SndMax = %4, RecoveryMax = %5, SndWnd = %6, SndWndChanged = %7, SackUpdated = %8, State = %9, CongestionState = %10, F-RTO = %11.

Fields #

NameDescription
Tcb Pointer
ThAck UInt32
SndUna UInt32
SndMax UInt32
RecoveryMax UInt32
SndWnd UInt32
SndWndChanged UInt32
SackUpdated UInt32
TcpState UInt32
CongestionState UInt32
Frto UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2f07e2ee-15db-40f1-90ef-9d7ba282188a}",
    "event_source_name": "",
    "event_id": 1587,
    "version": 0,
    "level": 4,
    "task": 1529,
    "opcode": 0,
    "keywords": "0x8000000100000000",
    "time_created": "2026-07-19T03:41:08.919179700+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "118C6320-800A-FFFF-0000-000000000000"
    },
    "execution": {
      "process_id": 1500,
      "thread_id": 12200
    },
    "channel": "Microsoft-Windows-TCPIP/Diagnostic",
    "computer": "",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Tcb": "0xFFFF800A118C6320",
    "ThAck": "3866540906",
    "SndUna": "3866540906",
    "SndMax": "3866540906",
    "RecoveryMax": "0",
    "SndWnd": "2161152",
    "SndWndChanged": "0",
    "SackUpdated": "0",
    "TcpState": "4",
    "CongestionState": "0",
    "Frto": "0"
  },
  "message": "TCP: connection 0xFFFF800A118C6320 received a careful ACK. ThAck = 3866540906, SndUna = 3866540906, SndMax = 3866540906, RecoveryMax = 0, SndWnd = 2161152, SndWndChanged = FALSE , SackUpdated = FALSE , State = EstablishedState , CongestionState = 0, F-RTO = 0."
}

Event ID 1588: IP: Forwarding tag on Interface = Interface, Compartment = CompartmentId, Family = AddressFamily changed from OldForwardingTag to NewForwardingTag.

#
Channel
Diagnostic
Task
IpInterfaceChange

Message #

IP: Forwarding tag on Interface = %3, Compartment = %2, Family = %1 changed from %4 to %5.

Fields #

NameDescription
AddressFamily UInt32
CompartmentId UInt32
Interface UInt32
OldForwardingTag UInt32
NewForwardingTag UInt32

Event ID 1589: TCP: AF AddressFamily, RssEnabled = RssEnabled .

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpAfRundown
Opcode
win:Info

Message #

TCP: AF %1, RssEnabled = %2 .

Fields #

NameDescription
AddressFamily UInt32
RssEnabled UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1589,
    "version": 0,
    "level": 4,
    "task": 1530,
    "opcode": 0,
    "keywords": "0x0000000000000080",
    "time_created": "2026-06-02T06:03:32.469+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{E27FDE20-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 11500,
      "thread_id": 16068
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressFamily": 23,
    "RssEnabled": 1
  },
  "message": "TcpAfRundown"
}

Event ID 1590: TCP: connection = Tcb send completion failed.

#
Channel
Diagnostic
Task
TcpSendCompletionFailure

Description

TCP: connection = Tcb send completion failed. NBL = Nbl, Status = Status.

Message #

TCP: connection = %1 send completion failed. NBL = %2, Status = %3.

Fields #

NameDescription
Tcb Pointer
Nbl Pointer
Status UInt32NTSTATUS reference

Event ID 1591: TCPIP: Alloc hooks setup: Status = Status.

#
Channel
Diagnostic
Task
TcpipAllocHooksSetup

Message #

TCPIP: Alloc hooks setup: Status = %1.

Fields #

NameDescription
Status UInt32NTSTATUS reference

Event ID 1592: IP: Neighbor with IpAddress = IPAddress DlAddress = DLAddress on Interface = Interface was reset while in state OldNeighborState due to Reason = ResetReason.

#
Channel
Diagnostic
Task
IpNeighborReset

Message #

IP: Neighbor with IpAddress = %3 DlAddress = %5 on Interface = %1 was reset while in state %6 due to Reason = %7.

Fields #

NameDescription
Interface UInt32
IpAddrLength UInt32
IPAddress Binary
DlAddrLength UInt32
DLAddress Binary
OldNeighborState UInt32
ResetReason UInt32
CompartmentId UInt32

Event ID 1593: TCP: Global timer fired, Processor = Processor, Tick = Tick.

#
Channel
Diagnostic
Task
TcpGlobalTimerFired

Message #

TCP: Global timer fired, Processor = %1, Tick = %2

Fields #

NameDescription
Processor UInt32
Tick UInt32

Event ID 1594: TCP: Global timer armed, NextToExpire = NextToExpire, Period = Period.

#
Channel
Diagnostic
Task
TcpGlobalTimerArmed

Message #

TCP: Global timer armed, NextToExpire = %1, Period = %2

Fields #

NameDescription
NextToExpire UInt32
Period UInt32

Event ID 1595: TCP: Global timer cancelled

#
Channel
Diagnostic
Task
TcpGlobalTimerCancelled

Event ID 1596: TCP: Updating Fastopen Key

#
Channel
Diagnostic
Task
TcpFastopenKeyUpdate

Event ID 1597: TCP: paused receive buffer growth for high memory usage, AF = AddressFamily, TCB = Tcb, TotalBytesBuffered = TotalBytesBuffered, UpperLimit = UpperLimit.

#
Channel
Diagnostic
Task
TcpAutoTuningPausedForMemoryUsage

Message #

TCP: paused receive buffer growth for high memory usage, AF = %1, TCB = %2, TotalBytesBuffered = %3, UpperLimit = %4

Fields #

NameDescription
AddressFamily UInt32
Tcb Pointer
TotalBytesBuffered UInt64
UpperLimit UInt64

Event ID 1598: IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = IPv4Address IPProtocol IPv6Address, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.

#
Channel
Diagnostic
Task
IpAddressAutoConfigurationLimitFailure

Message #

IP: Autoconfigured address creation failed due to autoconfiguration limit, Address = %5 %7 %6, Interface = %1, Compartment = %2, Protocol = %3

Fields #

NameDescription
Interface UInt32
CompartmentId UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
IpAddrLength UInt32
IPv4Address UInt32
IPv6Address Binary
IPProtocol UInt32

Event ID 1599: IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddres...

#
Channel
Diagnostic
Task
IpRouteAutoConfigurationLimitFailure

Description

IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = IPv4DestinationPrefix IPProtocol DestinationPrefix /DestinationPrefixLength, Nexthop = IPv4NextHopAddress IPProtocol NextHopAddress, Interface = Interface, Compartment = CompartmentId, Protocol = Protocol.

Message #

IP: Autoconfigured route creation failed due to autoconfiguration limit, DestinationPrefix = %9 %11 %7 /%6, Nexthop = %10 %11 %8, Interface = %1, Compartment = %2, Protocol = %3

Fields #

NameDescription
Interface UInt32
CompartmentId UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
DestinationPrefixAddressLength UInt32
NextHopAddressLength UInt32
DestinationPrefixLength UInt32
DestinationPrefix Binary
NextHopAddress Binary
IPv4DestinationPrefix UInt32
IPv4NextHopAddress UInt32
IPProtocol UInt32

Event ID 1600: IP: Policy based routing failed - Compartment: Compartment DstAddr: DestinationAddress SrcAddr: SourceAddress TransProto: TransportProtocol IcmpType: IcmpType IcmpCode: IcmpCode PolicySrcAddr: Poli...

#
Channel
Diagnostic
Task
TcpipPBRFailure

Description

IP: Policy based routing failed - Compartment: DstAddr: SrcAddr: TransProto: IcmpType: IcmpCode: PolicySrcAddr: PolicyNextHopAddr: PolicyIfIndex: FailureReason: Status.

Message #

IP: Policy based routing failed - Compartment: %1 DstAddr: %3 SrcAddr: %5 TransProto: %6 IcmpType: %7 IcmpCode: %8 PolicySrcAddr: %10 PolicyNextHopAddr: %12 PolicyIfIndex: %13 FailureReason: %14 Status: %15

Fields #

NameDescription
Compartment UInt32
DestinationAddrLength UInt32
DestinationAddress Binary
SourceAddrLength UInt32
SourceAddress Binary
TransportProtocol UInt32
IcmpType UInt8
IcmpCode UInt8
PolicySourceAddrLength UInt32
PolicySourceAddress Binary
PolicyNextHopAddrLength UInt32
PolicyNextHopAddress Binary
PolicyInterfaceLuid UInt64
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference

Event ID 1601: TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestam...

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpRx
Opcode
win:Info

Description

TCP: connection Tcb in NewState received NBL NBL in FastPath = FastPath Seq = ThSeq Ack = ThAck Flags = ThFlags RSC = RSC CoalescedSegCount = CoalescedSegCount RscTcpTimestampDelta = RscTcpTimestampDelta EcnCePresent = EcnCePresent.

Message #

TCP: connection %1 in %2 received NBL %4 in FastPath = %3 Seq = %5 Ack = %6 Flags = %7 RSC = %8 CoalescedSegCount = %9 RscTcpTimestampDelta = %10 EcnCePresent = %11.

Fields #

NameDescription
Tcb Pointer
NewState UInt32
FastPath UInt32
NBL Pointer
ThSeq UInt32
ThAck UInt32
ThFlags UInt8
RSC UInt32
CoalescedSegCount UInt16
RscTcpTimestampDelta UInt32
EcnCePresent UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1601,
    "version": 0,
    "level": 5,
    "task": 1601,
    "opcode": 0,
    "keywords": "0x0000000200000000",
    "time_created": "2026-06-02T06:03:34.154+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 2764,
      "thread_id": 812
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CoalescedSegCount": 1,
    "EcnCePresent": 0,
    "FastPath": 1,
    "NBL": "0xFFFFBD09F35BD070",
    "NewState": 4,
    "RSC": 0,
    "RscTcpTimestampDelta": 0,
    "Tcb": "0xFFFFBD09F7642010",
    "ThAck": 2424967783,
    "ThFlags": 16,
    "ThSeq": 3278916547
  },
  "message": "TcpRx"
}

Event ID 1602: TCP: connection Tcb process fast RX batch SegmentCount = SegmentCount NumBytes = NumBytes NblHead = NblHead NblTail = NblTail Inspect = Inspect.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpProcessFastRxBatch
Opcode
win:Info

Message #

TCP: connection %1 process fast RX batch SegmentCount = %2 NumBytes = %3 NblHead = %4 NblTail = %5 Inspect = %6.

Fields #

NameDescription
Tcb Pointer
SegmentCount UInt32
NumBytes UInt32
NblHead Pointer
NblTail Pointer
Inspect UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1602,
    "version": 0,
    "level": 5,
    "task": 1602,
    "opcode": 0,
    "keywords": "0x0000000200000000",
    "time_created": "2026-06-02T06:03:34.157+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 10696,
      "thread_id": 5148
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Inspect": 1,
    "NblHead": "0xFFFFBD09F35BD070",
    "NblTail": "0xFFFFBD09F3386D20",
    "NumBytes": 4874,
    "SegmentCount": 5,
    "Tcb": "0xFFFFBD09F7642010"
  },
  "message": "TcpProcessFastRxBatch"
}

Event ID 1603: TCP: connection Tcb in State Injected disconnect DataLength=DataLength.

#
Channel
Diagnostic
Task
TcpDisconnect

Message #

TCP: connection %1 in %2 %3 disconnect DataLength=%4.

Fields #

NameDescription
Tcb Pointer
State UInt32
Injected UnicodeString
DataLength UInt64

Event ID 1604: NDKPI Disconnect Event CallbackEx: DisconnectEventContext DisconnectEventContext ProviderDisconnectReason ProviderDisconnectReason.

#
Channel
Diagnostic
Task
Ndkpi_Disconnect_Event_Callback_Ex

Message #

NDKPI Disconnect Event CallbackEx: DisconnectEventContext %1 ProviderDisconnectReason %2

Fields #

NameDescription
DisconnectEventContext Pointer
ProviderDisconnectReason UInt32

Event ID 1605: NDKPI AcceptEx: RequestContext RequestContext Connector NdkConnector QP NdkQp IRD IRD ORD ORD PrivateDataLength PrivateDataLength DisconnectEventContext DisconnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Accept_Ex

Message #

NDKPI AcceptEx: RequestContext %6 Connector %1 QP %2 IRD %3 ORD %4 PrivateDataLength %7 DisconnectEventContext %5

Fields #

NameDescription
NdkConnector Pointer
NdkQp Pointer
IRD UInt32
ORD UInt32
DisconnectEventContext Pointer
RequestContext Pointer
PrivateDataLength UInt32

Event ID 1606: NDKPI CompleteConnectEx: RequestContext RequestContext Connector NdkConnector DisconnectEventContext DisconnectEventContext.

#
Channel
Diagnostic
Task
Ndkpi_Complete_Connect_Ex

Message #

NDKPI CompleteConnectEx: RequestContext %3 Connector %1 DisconnectEventContext %2

Fields #

NameDescription
NdkConnector Pointer
DisconnectEventContext Pointer
RequestContext Pointer

Event ID 1607: NDKPI Open Adapter Version Override: IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.

#
Channel
Diagnostic
Task
Ndkpi_Open_Adapter_Version_Override

Description

NDKPI Open Adapter Version Override: IF_INDEX ProviderSupportedNDKVersion {.} FlConfiguredNdkpiVersion {.} ActualSupportedVersion {.}.

Message #

NDKPI Open Adapter Version Override: IF_INDEX %7 ProviderSupportedNDKVersion {%1.%2} FlConfiguredNdkpiVersion {%3.%4} ActualSupportedVersion {%5.%6}

Fields #

NameDescription
ProviderSupportedNDKVersionMajor UInt16
ProviderSupportedNDKVersionMinor UInt16
FlConfiguredNdkpiVersionMajor UInt16
FlConfiguredNdkpiVersionMinor UInt16
ActualSupportedNDKVersionMajor UInt16
ActualSupportedNDKVersionMinor UInt16
IF_INDEX UInt32

Event ID 1608: Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.

#
Channel
Diagnostic
Task
Ndkpi_Fl_Version_Config_Registry_Override

Description

Fl Reload Registry Config: Override Status: OverrideStatus OldFlConfiguredVersion {OldFlVersionMajor.OldFlVersionMinor} NewFlConfiguredVersion {NewFlVersionMajor.NewFlVersionMinor}.

Message #

Fl Reload Registry Config: Override Status: %5 OldFlConfiguredVersion {%1.%2} NewFlConfiguredVersion {%3.%4}

Fields #

NameDescription
OldFlVersionMajor UInt16
OldFlVersionMinor UInt16
NewFlVersionMajor UInt16
NewFlVersionMinor UInt16
OverrideStatus UnicodeString

Event ID 1609: NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.

#
Channel
Diagnostic
Task
Ndkpi_Open_Adapter_Unexpected_Provider_Version

Description

NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX IF_INDEX ProviderSupportedNDKVersion {ProviderSupportedNDKVersionMajor.ProviderSupportedNDKVersionMinor} ConsumerSpecifiedVersion {ConsumerSpecifiedNdkpiVersionMajor.ConsumerSpecifiedNdkpiVersionMinor}.

Message #

NDKPI Open Adapter: Unexpected version returned by provider, IF_INDEX %5 ProviderSupportedNDKVersion {%1.%2} ConsumerSpecifiedVersion {%3.%4}

Fields #

NameDescription
ProviderSupportedNDKVersionMajor UInt16
ProviderSupportedNDKVersionMinor UInt16
ConsumerSpecifiedNdkpiVersionMajor UInt16
ConsumerSpecifiedNdkpiVersionMinor UInt16
IF_INDEX UInt32

Event ID 1610: TCPIP: Disconnected Standby traffic.

#
Channel
Diagnostic
Task
TcpipDsDetectTraffic

Description

TCPIP: Disconnected Standby traffic. Event = StandbyEvent AddressFamily = AddressFamily.

Message #

TCPIP: Disconnected Standby traffic. Event = %1 AddressFamily = %2

Fields #

NameDescription
StandbyEvent UInt32
AddressFamily UInt32

Event ID 1611: TCPIP: Disconnected Standby (DS) transition detected.

#
Channel
Diagnostic
Task
TcpipDsStateChange

Description

TCPIP: Disconnected Standby (DS) transition detected. IsSystemInDs=DSState.

Message #

TCPIP: Disconnected Standby (DS) transition detected. IsSystemInDs=%1

Fields #

NameDescription
DSState UInt32

Event ID 1612: ResetResolve API call: ProcessName API.

#
Channel
Diagnostic
Task
TcpipDsResolveApi

Message #

ResetResolve API call: ProcessName %1

Fields #

NameDescription
API AnsiString

Event ID 1613: USO global disabled mask = UdpUsoDisabledMask.

#
Channel
Operational
Also via
realtime ETW trace
Level
Informational
Task
SendOffloadGlobalState
Opcode
win:Info

Message #

USO global disabled mask = %1.

Fields #

NameDescription
UdpUsoDisabledMask Int32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1613,
    "version": 0,
    "level": 4,
    "task": 1613,
    "opcode": 0,
    "keywords": "0x0000008000000080",
    "time_created": "2026-06-02T06:03:32.471+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
    },
    "execution": {
      "process_id": 11500,
      "thread_id": 16068
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "UdpUsoDisabledMask": 0
  },
  "message": "SendOffloadGlobalState"
}

Event ID 1614: Framing: SW URO SwUroEnabled, HW URO HwUroEnabled.

#
Channel
Diagnostic
Task
TcpipFramingUroStatus

Message #

Framing: SW URO %1, HW URO %2

Fields #

NameDescription
SwUroEnabled UInt32
HwUroEnabled UInt32

Event ID 1615: Tcpip Power Policy set to: PowerPolicy.

#
Channel
Diagnostic
Task
TcpipGlobalPowerPolicyChange

Message #

Tcpip Power Policy set to: %1

Fields #

NameDescription
PowerPolicy UInt32

Event ID 1616: Router Solicitation sent.

#
Channel
Diagnostic
Task
TcpipGlobalPowerPolicySendRS

Description

Router Solicitation sent. Interface: InterfaceIndex, Reason: RouterSolicitationReason, Tcpip Power Policy: PowerPolicy.

Message #

Router Solicitation sent. Interface: %1, Reason: %2, Tcpip Power Policy: %3

Fields #

NameDescription
InterfaceIndex UInt32
RouterSolicitationReason UInt32
PowerPolicy UInt32

Event ID 1617: Router Solicitation requested on dormant interface.

#
Channel
Diagnostic
Task
TcpipGlobalPowerPolicyRequestRS

Description

Router Solicitation requested on dormant interface. Interface: InterfaceIndex, Reason: RouterSolicitationReason, Tcpip Power Policy: PowerPolicy.

Message #

Router Solicitation requested on dormant interface. Interface: %1, Reason: %2, Tcpip Power Policy: %3

Fields #

NameDescription
InterfaceIndex UInt32
RouterSolicitationReason UInt32
PowerPolicy UInt32

Event ID 1618: IP: Route lifetime refresh.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipIpRouteLifetime
Opcode
win:Info

Description

IP: Route lifetime refresh. Interface = Interface, Protocol = Protocol, Compartment = Compartment, Prefix = DestinationPrefix/DestinationPrefixLength, NextHop = NextHopAddress, Metric = Metric, Origin = Origin, CurrentTime = CurrentTime, Old BaseTime = OldBasetime, Old ValidTime = OldValidTime, Old PreferredTime = OldPreferredTime, New BaseTime = NewBasetime, New ValidTime = NewValidTime, New PreferredTime = NewPreferredTime.

Message #

IP: Route lifetime refresh. Interface = %1, Protocol = %2, Compartment = %3, Prefix = %5/%6, NextHop = %8, Metric = %9, Origin = %10, CurrentTime = %11, Old BaseTime = %12, Old ValidTime = %13, Old PreferredTime = %14, New BaseTime = %15, New ValidTime = %16, New PreferredTime = %17.

Fields #

NameDescription
Interface UInt32
Protocol AnsiString
Known values
0
HOPOPT
1
ICMP
2
IGMP
6
TCP
17
UDP
41
IPv6
43
IPv6-Route
44
IPv6-Frag
47
GRE
50
ESP
51
AH
58
ICMPv6
89
OSPF
103
PIM
132
SCTP
Compartment UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
DestinationPrefixLength UInt32
NextHopAddressLength UInt32
NextHopAddress Binary
Metric UInt32
Origin UInt32
CurrentTime UInt32
OldBasetime UInt32
OldValidTime UInt32
OldPreferredTime UInt32
NewBasetime UInt32
NewValidTime UInt32
NewPreferredTime UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1618,
    "version": 0,
    "level": 4,
    "task": 1618,
    "opcode": 0,
    "keywords": "0x0000008000000020",
    "time_created": "2026-06-02T06:03:39.063+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
    },
    "execution": {
      "process_id": 17168,
      "thread_id": 16688
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "Compartment": 1,
    "CurrentTime": 246857,
    "DestinationPrefix": "02000000000000000000000000000000",
    "DestinationPrefixAddressLength": 16,
    "DestinationPrefixLength": 0,
    "Interface": 11,
    "Metric": 256,
    "New Basetime": 246857,
    "New PreferredTime": 4294967295,
    "New ValidTime": 4294967295,
    "NextHopAddress": "020000000A020AFE0000000000000000",
    "NextHopAddressLength": 16,
    "Old Basetime": 246797,
    "Old PreferredTime": 4294967295,
    "Old ValidTime": 4294967295,
    "Origin": 0,
    "Protocol": "IPv4"
  },
  "message": "TcpipIpRouteLifetime"
}

Example keys not documented in the fields table: New Basetime, New PreferredTime, New ValidTime, Old Basetime, Old PreferredTime, Old ValidTime

Event ID 1619: IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason...

#
Channel
Diagnostic
Task
IpSourceAddressSelection

Description

IP: Constraint computation (unused) - Source address PreferredSourceIPAddress is preferred over NonPreferredSourceIPAddress for Destination DestinationIPAddress in Compartment CompartmentId, Reason: RuleName (Rule Rule.RuleExtension).

Message #

IP: Constraint computation (unused) - Source address %2 is preferred over %3 for Destination %4 in Compartment %5, Reason: %8 (Rule %6.%7).

Fields #

NameDescription
IpAddrLength UInt32
PreferredSourceIPAddress Binary
NonPreferredSourceIPAddress Binary
DestinationIPAddress Binary
CompartmentId UInt32
Rule UInt32
RuleExtension UInt32
RuleName UInt32

Event ID 1620: WFP-ALE: RemoteEndPoint Cleanup: (local=LocalAddress remote=RemoteAddress) currentTick=CurrentTick lastTick=LastTick lifeTime=LifeTime LifetimeFactor=LifetimeFactor.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
RemoteEndpointCleanup
Opcode
win:Info

Message #

WFP-ALE: RemoteEndPoint Cleanup: (local=%2 remote=%3) currentTick=%4 lastTick=%5 lifeTime=%6 LifetimeFactor=%7

Fields #

NameDescription
AddressLength UInt32
LocalAddress Binary
RemoteAddress Binary
CurrentTick UInt64
LastTick UInt64
LifeTime UInt32
LifetimeFactor UInt16

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1620,
    "version": 0,
    "level": 4,
    "task": 1620,
    "opcode": 0,
    "keywords": "0x0000000000008000",
    "time_created": "2026-06-02T06:03:37.765+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
    },
    "execution": {
      "process_id": 9180,
      "thread_id": 17448
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "AddressLength": 16,
    "CurrentTick": 123427397,
    "LastTick": 123307081,
    "LifeTime": 60,
    "LifetimeFactor": 1,
    "LocalAddress": "020000000A020A6F0000000000000000",
    "RemoteAddress": "02000001080808080000000000000000"
  },
  "message": "RemoteEndpointCleanup"
}

Event ID 1621: FL: Virtual interface creation.

#
Channel
Diagnostic
Task
FlVirtualInterfaceCreation

Description

FL: Virtual interface creation. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.

Message #

FL: Virtual interface creation. Interface = %1, Family = %2, CompartmentGuid = %3, CompartmentId = %4, IsolationMode = %5, IsolationId = %6, Origin = %7, VirtualIfLuid = %8, VirtualIfIndex = %9

Fields #

NameDescription
IfLuid UInt64
AddressFamily UInt32
CompartmentGuid GUID
CompartmentId UInt32
IsolationMode UInt32
IsolalationId UInt32
Origin UInt32
VirtualIfLuid UInt64
VirtualIfIndex UInt32

Event ID 1622: FL: Virtual interface deletion.

#
Channel
Diagnostic
Task
FlVirtualInterfaceDeletion

Description

FL: Virtual interface deletion. Interface = IfLuid, Family = AddressFamily, CompartmentGuid = CompartmentGuid, CompartmentId = CompartmentId, IsolationMode = IsolationMode, IsolationId = IsolalationId, Origin = Origin, VirtualIfLuid = VirtualIfLuid, VirtualIfIndex = VirtualIfIndex.

Message #

FL: Virtual interface deletion. Interface = %1, Family = %2, CompartmentGuid = %3, CompartmentId = %4, IsolationMode = %5, IsolationId = %6, Origin = %7, VirtualIfLuid = %8, VirtualIfIndex = %9

Fields #

NameDescription
IfLuid UInt64
AddressFamily UInt32
CompartmentGuid GUID
CompartmentId UInt32
IsolationMode UInt32
IsolalationId UInt32
Origin UInt32
VirtualIfLuid UInt64
VirtualIfIndex UInt32

Event ID 1623: Tcpip Power Policy Standby-to-Full-Power transition detected.

#
Channel
Diagnostic
Task
TcpipGlobalPowerPolicyTransitionAdjustment

Description

Tcpip Power Policy Standby-to-Full-Power transition detected. Lifetimes adjusted for Interface:InterfaceIndex, DestinationPrefix:DestinationPrefix/DestinationPrefixLength, NextHopAddress:NextHopAddress, EnteredStandbySystemTickCount:EnteredStandbySystemTickCount, CurrentTickCount:CurrentTickCount, ValidLifetimeHighWaterTickCount:ValidLifetimeHighWaterTickCount

Message #

Tcpip Power Policy Standby-to-Full-Power transition detected. Lifetimes adjusted for Interface:%1, DestinationPrefix:%3/%4, NextHopAddress:%6, EnteredStandbySystemTickCount:%7, CurrentTickCount:%8, ValidLifetimeHighWaterTickCount:%9

Fields #

NameDescription
InterfaceIndex UInt32
DestinationPrefixAddressLength UInt32
DestinationPrefix Binary
DestinationPrefixLength UInt32
NextHopAddressLength UInt32
NextHopAddress Binary
EnteredStandbySystemTickCount UInt64
CurrentTickCount UInt32
ValidLifetimeHighWaterTickCount UInt32

Event ID 1624: TCP: connection Tcb: flow label refreshed, old = OldFlowLabel new = NewFlowLabel.

#
Channel
Diagnostic
Task
TcpFlowLabelRefresh

Message #

TCP: connection %1: flow label refreshed, old = %2 new = %3.

Fields #

NameDescription
Tcb Pointer
OldFlowLabel UInt32
NewFlowLabel UInt32

Event ID 1625: TCP: Connection Tcb send idle triggered.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpCwndRestart
Opcode
win:Info

Description

TCP: Connection Tcb send idle triggered. OldCwnd = OldCwnd, NewCwnd = NewCwnd, CurrentTick = CurrentTick, IdleTick = IdleTick, RTO = Rto.

Message #

TCP: Connection %1 send idle triggered. OldCwnd = %2, NewCwnd = %3, CurrentTick = %5, IdleTick = %6, RTO = %7

Fields #

NameDescription
Tcb Pointer
OldCwnd UInt32
NewCwnd UInt32
Processor UInt32
CurrentTick UInt32
IdleTick UInt32
Rto UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1625,
    "version": 0,
    "level": 4,
    "task": 1221,
    "opcode": 0,
    "keywords": "0x0000000100000000",
    "time_created": "2026-06-02T06:03:34.152+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 2940,
      "thread_id": 13708
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CurrentTick": 123423807,
    "IdleTick": 123421941,
    "NewCwnd": 269440,
    "OldCwnd": 269440,
    "Processor": 0,
    "Rto": 300,
    "Tcb": "0xFFFFBD09F7642010"
  },
  "message": "TcpCwndRestart"
}

Event ID 1626: TCP: connection Tcb: bytes limited by sender = SenderLimitedBytes receiver = ReceiverLimitedBytes congestion = CongestionLimitedBytes.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Verbose
Task
TcpLimitingFactor
Opcode
win:Info

Message #

TCP: connection %1: bytes limited by sender = %2 receiver = %3 congestion = %4.

Fields #

NameDescription
Tcb Pointer
SenderLimitedBytes UInt64
ReceiverLimitedBytes UInt64
CongestionLimitedBytes UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1626,
    "version": 0,
    "level": 5,
    "task": 1626,
    "opcode": 0,
    "keywords": "0x0000000100000000",
    "time_created": "2026-06-02T06:03:34.153+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 2940,
      "thread_id": 13708
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "CongestionLimitedBytes": 0,
    "ReceiverLimitedBytes": 0,
    "SenderLimitedBytes": 2328397,
    "Tcb": "0xFFFFBD09F7642010"
  },
  "message": "TcpLimitingFactor"
}

Event ID 1627: UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid.

#
Channel
Diagnostic
Task
UdpOffloadHwUroChangeScheduled

Description

UDP: ChangeReason scheduled HW URO to be NewUroState on interface IfLuid. CurrentState:CurrentUroState. Last scheduled state: LastScheduledState.

Message #

UDP: %2 scheduled HW URO to be %3 on interface %1. CurrentState:%4. Last scheduled state: %5

Fields #

NameDescription
IfLuid UInt64
ChangeReason UInt32
NewUroState UInt32
CurrentUroState UInt32
LastScheduledState UInt32
FailureReasonFlags UInt32

Event ID 1628: UDP: ChangeReason NewUroState HW URO on interface IfLuid.

#
Channel
Diagnostic
Task
UdpOffloadHwUroChangeComplete

Description

UDP: ChangeReason NewUroState HW URO on interface IfLuid. Status: Status.

Message #

UDP: %2 %3 HW URO on interface %1. Status: %4

Fields #

NameDescription
IfLuid UInt64
ChangeReason UInt32
NewUroState UInt32
Status UInt32NTSTATUS reference
FailureReasonFlags UInt32

Event ID 1629: FL: FLSNPI client attach.

#
Channel
Diagnostic
Task
FlsnpiClientAttach

Description

FL: FLSNPI client attach. Client: ClientName, AddressFamily: AddressFamily, NpiVersion: ClientNpiVersion, NblContextSize: NblContextSize, FailureReason: FailureReason, Status: Status.

Message #

FL: FLSNPI client attach. Client: %1, AddressFamily: %2, NpiVersion: %3, NblContextSize: %4, FailureReason: %5, Status: %6.

Fields #

NameDescription
ClientName UnicodeString
AddressFamily UInt32
ClientNpiVersion UInt32
NblContextSize UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference

Event ID 1630: FL: FLSNPI client detach.

#
Channel
Diagnostic
Task
FlsnpiClientDetach

Description

FL: FLSNPI client detach. Client: ClientName, AddressFamily: AddressFamily.

Message #

FL: FLSNPI client detach. Client: %1, AddressFamily: %2.

Fields #

NameDescription
ClientName UnicodeString
AddressFamily UInt32

Event ID 1631: FL: FLSNPI client interface attach.

#
Channel
Diagnostic
Task
FlsnpiClientInterfaceAttach

Description

FL: FLSNPI client interface attach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.

Message #

FL: FLSNPI client interface attach. Client: %1, AddressFamily: %2, CompartmentId: %3, IfIndex: %4, VirtualIfId: %5, Flags: %6, FailureReason: %7, Status: %8.

Fields #

NameDescription
ClientName UnicodeString
AddressFamily UInt32
CompartmentId UInt32
IfIndex UInt32
VirtualIfId UInt32
Flags UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference

Event ID 1632: FL: FLSNPI client interface detach.

#
Channel
Diagnostic
Task
FlsnpiClientInterfaceDetach

Description

FL: FLSNPI client interface detach. Client: ClientName, AddressFamily: AddressFamily, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, FailureReason: FailureReason, Status: Status.

Message #

FL: FLSNPI client interface detach. Client: %1,  AddressFamily: %2, CompartmentId: %3, IfIndex: %4, VirtualIfId: %5, Flags: %8, FailureReason: %6, Status: %7.

Fields #

NameDescription
ClientName UnicodeString
AddressFamily UInt32
CompartmentId UInt32
IfIndex UInt32
VirtualIfId UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference
Flags UInt32

Event ID 1633: FL: FLSNPI datapath failure.

#
Channel
Diagnostic
Task
FlsnpiDataPathFailure

Description

FL: FLSNPI datapath failure. Operation: Operation, AddressFamily: AddressFamily, Direction: PathDirection, Client:ClientName, CompartmentId: CompartmentId, IfIndex: IfIndex, VirtualIfId: VirtualIfId, Flags: Flags, InjectIfIndex: InjectionIfIndex, FailureReason: FailureReason, Status: Status.

Message #

FL: FLSNPI datapath failure. Operation: %1, AddressFamily: %2, Direction: %3, Client:%4, CompartmentId: %5, IfIndex: %6, VirtualIfId: %7, Flags: %8, InjectIfIndex: %11, FailureReason: %9, Status: %10

Fields #

NameDescription
Operation UInt32
Known values
%%2456
Open key file.
%%2457
Delete key file.
%%2458
Read persisted key from file.
%%2459
Write persisted key to file.
%%2464
Export of persistent cryptographic key.
%%2465
Import of persistent cryptographic key.
%%2480
Open Key.
%%2481
Create Key.
%%2482
Delete Key.
%%2483
Encrypt.
%%2484
Decrypt.
%%2485
Sign hash.
%%2486
Secret agreement.
%%2487
Domain settings.
%%2488
Local settings.
%%2489
Add provider.
%%2490
Remove provider.
%%2491
Add context.
%%2492
Remove context.
%%2493
Add function.
%%2494
Remove function.
%%2495
Add function provider.
%%2496
Remove function provider.
%%2497
Add function property.
%%2498
Remove function property.
%%2499
Machine key.
%%2500
User key.
%%2501
Key Derivation.
%%2502
Claim Creation.
%%2503
Claim Verification.
AddressFamily UInt32
PathDirection UInt32
ClientName UnicodeString
CompartmentId UInt32
IfIndex UInt32
VirtualIfId UInt32
Flags UInt32
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.
Status UInt32NTSTATUS reference
InjectionIfIndex UInt32

Event ID 1634: FL: FLSNPI client silent drop.

#
Channel
Diagnostic
Task
FlsnpiClientSilentDrop

Description

FL: FLSNPI client silent drop. Direction: PathDirection, AddressFamily:AddressFamily, Client: ClientName, CompartmentId: CompartmentId, IfIndex: InterfaceIndex, VirtualIfId: VirtualIfId, PacketCount: PacketCount.

Message #

FL: FLSNPI client silent drop. Direction: %1, AddressFamily:%2, Client: %3, CompartmentId: %4, IfIndex: %5, VirtualIfId: %6, PacketCount: %7.

Fields #

NameDescription
PathDirection UInt32
AddressFamily UInt32
ClientName UnicodeString
CompartmentId UInt32
InterfaceIndex UInt32
VirtualIfId UInt32
PacketCount UInt32

Event ID 1635: FL: FLSNPI indication stats.

#
Channel
Diagnostic
Task
FlsnpiPacketStats

Description

FL: FLSNPI indication stats. Direction: Direction, AddressFamily:AddressFamily, CompartmentId: CompartmentId, IfIndex: InterfaceIndex, VirtualIfId: VirtualIfId, PacketsIndicated: PacketsIndicated, PacketsReturned: PacketsReturned, PacketsInjected: PacketsInjected, PacketsCloned: PacketsCloned, PacketsClonedForSplitNB: PacketsClonedWithNBSplit, PacketsDropped: PacketsDropped, PacketsSilentlyDropped: PacketsSilentlyDropped.

Message #

FL: FLSNPI indication  stats. Direction: %1, AddressFamily:%2, CompartmentId: %3, IfIndex: %4, VirtualIfId: %5, PacketsIndicated: %6, PacketsReturned: %7, PacketsInjected: %8, PacketsCloned: %9, PacketsClonedForSplitNB: %10, PacketsDropped: %11, PacketsSilentlyDropped: %12.

Fields #

NameDescription
Direction UInt32
Known values
%%14592
Inbound
%%14593
Outbound
%%14594
Forward
%%14595
Bidirectional
AddressFamily UInt32
CompartmentId UInt32
InterfaceIndex UInt32
VirtualIfId UInt32
PacketsIndicated UInt32
PacketsReturned UInt32
PacketsInjected UInt32
PacketsCloned UInt32
PacketsClonedWithNBSplit UInt32
PacketsDropped UInt32
PacketsSilentlyDropped UInt32

Event ID 1636: TCPIP: Current Power Policy : PowerPolicy.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpipPowerPolicyRundown
Opcode
win:Info

Message #

TCPIP: Current Power Policy : %1.

Fields #

NameDescription
PowerPolicy UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1636,
    "version": 0,
    "level": 4,
    "task": 1636,
    "opcode": 0,
    "keywords": "0x0000008000000000",
    "time_created": "2026-06-02T06:03:32.471+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}"
    },
    "execution": {
      "process_id": 11500,
      "thread_id": 16068
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "PowerPolicy": 1
  },
  "message": "TcpipPowerPolicyRundown"
}

Event ID 1637: TCP: connection Tcb send acked NumBytes bytes starting from SndNxt ActivityID = ActivityID.

#
Channel
Diagnostic
Also via
realtime ETW trace
Level
Informational
Task
TcpSendAcked
Opcode
win:Info

Message #

TCP: connection %1 send acked %2 bytes starting from %3 ActivityID = %4.

Fields #

NameDescription
Tcb Pointer
NumBytes UInt32
SndNxt UInt32
ActivityID Pointer
SndLimBytesSnd UInt64
SndLimBytesRwin UInt64
SndLimBytesCwnd UInt64
CWnd UInt32
SRtt UInt32
LossRecoveryEpisodes UInt32
RtoEpisodes UInt32
PtoEpisodes UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-TCPIP",
    "guid": "{2F07E2EE-15DB-40F1-90EF-9D7BA282188A}",
    "event_source_name": "",
    "event_id": 1637,
    "version": 0,
    "level": 4,
    "task": 1637,
    "opcode": 0,
    "keywords": "0x0000400100000000",
    "time_created": "2026-06-02T06:03:34.154+00:00",
    "event_record_id": 0,
    "correlation": {
      "ActivityID": "{F7642010-BD09-FFFF-0000-000000000000}"
    },
    "execution": {
      "process_id": 2764,
      "thread_id": 812
    },
    "channel": "ETW Trace",
    "computer": "DESKTOP-FF3N5XK",
    "security": {
      "user_id": ""
    }
  },
  "event_data": {
    "ActivityID": "0xFFFFBD09E5A7D5B0",
    "CWnd": 269440,
    "LossRecoveryEpisodes": 0,
    "NumBytes": 1564,
    "PtoEpisodes": 0,
    "RtoEpisodes": 0,
    "SRtt": 2444,
    "SndLimBytesCwnd": 0,
    "SndLimBytesRwin": 0,
    "SndLimBytesSnd": 2328397,
    "SndNxt": 2424966219,
    "Tcb": "0xFFFFBD09F7642010"
  },
  "message": "TcpSendAcked"
}

Event ID 1638: IP: Event.

#
Channel
Diagnostic
Task
IpRaPref64Event

Description

IP: Event. Interface = Interface, Compartment = CompartmentId, RouterAddress = RouterAddress, Prefix = Prefix/PrefixLength, Lifetime = Lifetime.

Message #

IP: %1. Interface = %2, Compartment = %3, RouterAddress = %5, Prefix = %7/%8, Lifetime = %9.

Fields #

NameDescription
Event UInt32
Interface UInt32
CompartmentId UInt32
RouterAddrLength UInt32
RouterAddress Binary
PrefixAddrLength UInt32
Prefix Binary
PrefixLength UInt32
Lifetime UInt32

Event ID 1638: IP:

#
Channel
Operational
Task
IpRaPref64Event

Description

IP: . Interface = , Compartment = , RouterAddress = , Prefix = /, Lifetime = .

Fields #

NameDescription
Event UInt32
Interface UInt32
CompartmentId UInt32
RouterAddrLength UInt32
RouterAddress Binary
PrefixAddrLength UInt32
Prefix Binary
PrefixLength UInt32
Lifetime UInt32

Event ID 1639: IP: Destination cache invalidated

#
Channel
Diagnostic, Operational
Task
IpDestinationCacheInvalidation

Description

IP: Destination cache invalidated. Compartment = CompartmentId, Family = AddressFamily, RoutingEpoch = RoutingEpoch.

Message #

IP: Destination cache invalidated. Compartment = %1, Family = %2, RoutingEpoch = %3.

Fields #

NameDescription
CompartmentId UInt32
AddressFamily UInt32
RoutingEpoch Int32

Event ID 1640: FL: Virtual interface set failed

#
Channel
Diagnostic, Operational
Task
FlVirtualIfSetError

Description

FL: Virtual interface set failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.

Message #

FL: Virtual interface set failed. NsiAction = %1, Family %2, IfLuid = %3, CompartmentGuid = %4, VirtualIfId = %5, IsolationMode = %6, Status = %7, Reason = %8

Fields #

NameDescription
NsiAction UInt32
AddressFamily UInt32
IfLuid UInt64
CompartmentGuid GUID
VirtualIfId UInt32
IsolationMode UInt32
Status UInt32NTSTATUS reference
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 1641: FL: Virtual interface get failed

#
Channel
Diagnostic, Operational
Task
FlVirtualIfGetError

Description

FL: Virtual interface get failed. NsiAction = NsiAction, Family AddressFamily, IfLuid = IfLuid, CompartmentGuid = CompartmentGuid, VirtualIfId = VirtualIfId, IsolationMode = IsolationMode, Status = Status, Reason = FailureReason.

Message #

FL: Virtual interface get failed. NsiAction = %1, Family %2, IfLuid = %3, CompartmentGuid = %4, VirtualIfId = %5, IsolationMode = %6, Status = %7, Reason = %8

Fields #

NameDescription
NsiAction UInt32
AddressFamily UInt32
IfLuid UInt64
CompartmentGuid GUID
VirtualIfId UInt32
IsolationMode UInt32
Status UInt32NTSTATUS reference
FailureReason UInt32
Known values
%%2304
An Error occured during Logon.
%%2305
The specified user account has expired.
%%2306
The NetLogon component is not active.
%%2307
Account locked out.
%%2308
The user has not been granted the requested logon type at this machine.
%%2309
The specified account's password has expired.
%%2310
Account currently disabled.
%%2311
Account logon time restriction violation.
%%2312
User not allowed to logon at this computer.
%%2313
Unknown user name or bad password.
%%2314
Domain sid inconsistent.
%%2315
Smartcard logon is required and was not used.

Event ID 1642: IP: Received Prefix Option in Router Advertisement

#
Channel
Diagnostic, Operational
Task
IpRecvPrefixOptionInRouterAdvertisement

Description

IP: Received Prefix Option in Router Advertisement. Interface(Index/GUID) = InterfaceIndex/InterfaceGuid, Compartment = CompartmentId, SourceIpAddress = SourceIpAddress, Prefix(Value/Length) = PrefixValue/PrefixLength, Lifetimes(Valid/Preferred) = ValidLifetime/PreferredLifetime, Flags = FlagsValue (Route = IsRoute, SitePrefix = IsSitePrefix, RouterAddress = IsRouterAddress, Autonomous = IsAutonomous, OnLink = IsOnLink)

Message #

IP: Received Prefix Option in Router Advertisement. Interface(Index/GUID) = %1/%2, Compartment = %3, SourceIpAddress = %5, Prefix(Value/Length) = %6/%7, Lifetimes(Valid/Preferred) = %8/%9, Flags = %10 (Route = %11, SitePrefix = %12, RouterAddress = %13, Autonomous = %14, OnLink = %15)

Fields #

NameDescription
InterfaceIndex UInt32
InterfaceGuid GUID
CompartmentId UInt32
AddressLength UInt32
SourceIpAddress Binary
PrefixValue Binary
PrefixLength UInt32
ValidLifetime UInt32
PreferredLifetime UInt32
FlagsValue UInt8
IsRoute Boolean
IsSitePrefix Boolean
IsRouterAddress Boolean
IsAutonomous Boolean
IsOnLink Boolean

Provenance

ETW provider GUID {2F07E2EE-15DB-40F1-90EF-9D7BA282188A}

Defined in tcpip.sys, the binary that emits these events.

  • WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.4297, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.4297, captured 2026-06-02 — Manifest XML pack, 1.9 MB
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02 — Manifest XML pack, 2.0 MB
  • JD-WIN11-22H2-1, sample captured from a live trace, binary version 10.0.22621.6060, captured 2026-07-19

    Sealighter user-mode ETW capture of a loopback TCP listener activation.

  • JD-WIN11-22H2-1-etl, sample captured from a live trace, binary version 10.0.22621.6060, captured 2026-07-19

    Native ETL capture of a loopback TCP listener/client exchange grounding Diagnostic event 1194.

  • JD-WIN11-22H2-1-native-20260719, sample captured from a live trace, binary version 10.0.22621.6060, captured 2026-07-19

    Native ETL capture of loopback TCP/UDP lifecycle, bind conflict, and failed-connection activity.